EXPLANATORY STATEMENT
Personally Controlled Electronic Health Records Act 2012
Proclamation
Item 2 of the table in subsection 2(1) of the Personally Controlled Electronic Health Records Act 2012 (the Act) provides that sections 3 to 112 commence on a day or days to be fixed by Proclamation. However, if any of the provisions do not commence by the later of 1 July 2012 and the day the Act receives the Royal Assent, they commence on the day after the later of those days. The Act received the Royal Assent on 26 June 2012.
The purpose of the Proclamation is to fix 29 June 2012 as the day on which sections 3 to 112 commence.
The Act provides for the establishment and operation of a national personally controlled electronic health record (PCEHR) system which will provide access to health information relating to consumers’ healthcare. From 1 July 2012, it is anticipated that consumers will be able to apply to register for a PCEHR, if they choose to do so, and registered consumers will be able to control access to their PCEHR by healthcare provider organisations.
This Proclamation enables real data testing of the PCEHR system to be undertaken before the system goes live on 1 July 2012. To date, all testing of the PCEHR system has been undertaken using test data which comprises fictitious demographic and healthcare identifier details. Testing the system with data on real persons cannot occur until sections 3 to 112 of the Act commence.
The Department has consulted with agencies involved in developing and operating the PCEHR system, namely the Department of Human Services and the National Infrastructure Partner.
Sections 1 and 2 of the Act, which relate to the short title and commencement of the Act, commenced on the day the Act received the Royal Assent.
The Proclamation is a legislative instrument for the purposes of the Legislative Instruments Act 2003.
STATEMENT OF COMPATIBILITY FOR A BILL OR LEGISLATIVE INSTRUMENT THAT DOES NOT RAISE ANY HUMAN RIGHTS ISSUES
Overview
The Personally Controlled Electronic Health Records Act 2012 was enacted to establish and regulate the operation of a national system for personally controlled electronic health records (PCEHR). This Act was introduced to address the need for a secure, accessible, and efficient means of managing and accessing health information for consumers across Australia. The Act received the Royal Assent on 26 June 2012 and was proclaimed to commence on 29 June 2012, allowing for real data testing of the PCEHR system before its official launch on 1 July 2012. The objective of this legislation is to facilitate consumer control over their health records, enabling them to manage access to their personal health information by healthcare providers. The Act was enacted by the Parliament of Australia, reflecting a commitment to enhancing the accessibility and security of health information for Australian citizens.
Scope and Application
The Personally Controlled Electronic Health Records Act 2012 applies to all Australian residents who may wish to establish and control their own personally controlled electronic health records (PCEHR). The Act facilitates the creation and operation of a national PCEHR system that provides consumers with access to their healthcare information, thereby allowing them to manage who can access their health data, including healthcare providers. The Act applies on a national scale, affecting various healthcare providers, organisations, and systems involved in the management and dissemination of health information. The legislation also extends to the development and operation of the PCEHR system by the Department of Human Services and the National Infrastructure Partner. The Act’s jurisdictional reach is comprehensive, covering the entire Commonwealth of Australia, and it provides the framework for the national PCEHR system to operate effectively and securely.
The Act sets out the parameters for the commencement of its provisions, with sections 3 to 112 set to commence on 29 June 2012, as fixed by the Proclamation. Sections 1 and 2 of the Act, concerning the short title and commencement, came into effect on the day the Act received the Royal Assent on 26 June 2012. The Act does not specify exclusions, exemptions, or thresholds for its application, and its provisions are primarily operational, focusing on the establishment and management of the PCEHR system. Subordinate instruments may be used to further detail the operational aspects of the Act, but the primary scope and application are outlined within the Act itself.
Key Provisions
The main operative sections of the Personally Controlled Electronic Health Records Act 2012 (sections 3 to 112) establish the framework for the creation and operation of a national personally controlled electronic health record (PCEHR) system. This system aims to provide consumers with access to their own health information and allows them to control who can access this information from their healthcare providers. From 1 July 2012, consumers can apply to register for a PCEHR if they wish, and once registered, they can manage who has access to their records from healthcare provider organisations (section 3). The Act also sets out the functions of the PCEHR System Operator, including managing the system and ensuring the security and privacy of health information (section 11). The PCEHR system is designed to be accessible to authorised healthcare providers, allowing them to view and contribute to a consumer's health record (section 10).
The Act imposes several obligations on the parties involved. Firstly, the PCEHR System Operator is responsible for managing the system, ensuring its operational efficiency, and maintaining the security and privacy of health information (section 11). The Act also mandates that healthcare provider organisations must comply with the access protocols established by the Act, ensuring that they only access a consumer's PCEHR with the consumer's consent (section 10). Consumers, on the other hand, have the right to control access to their health records and can choose to register for a PCEHR and manage their information (section 3). Furthermore, the Act requires the PCEHR System Operator to establish and maintain a privacy policy that outlines how health information will be collected, used, disclosed, and protected (section 16).
The Act includes provisions for offences and penalties to ensure compliance and protect the integrity of the PCEHR system. For instance, unauthorised access to a consumer's PCEHR is strictly prohibited, and offenders may face criminal charges, including fines and imprisonment (section 101). Specifically, section 101(1) outlines that an individual who commits an unauthorised access offence may be subject to a fine of up to $210,000 or imprisonment for up to two years, or both. Additionally, section 102(1) specifies that a corporation found guilty of an unauthorised access offence may be fined up to $1,050,000. These penalties underscore the seriousness of breaches and aim to deter unauthorised actions that compromise the privacy and security of health information. Furthermore, the Act provides for civil remedies for individuals whose health information has been misused, allowing them to seek compensation for any harm caused by unauthorised access or disclosure (section 104).