My Health Record Deadline – Transition to TLS v1.2 & Compliant Cipher Suites by 31 March 2026
This is a final reminder that the Australian Digital Health Agency will be decommissioning Transport Layer Security (TLS) v1.0 and all non‑compliant cipher suites on 31 March 2026. To maintain access to My Health Record and ensure patient information remains safe and secure, all general practices must update their systems to TLS v1.2 with compliant cipher suites before the deadline.
Recent checks indicate that some practices may still be using outdated server configurations or older Windows Server versions that do not support the required security settings. These systems will lose access to My Health Record after 31 March unless updated. We encourage you to review your current setup as soon as possible and complete any required upgrades. If your practice uses external IT support or relies on a software vendor, please contact them promptly to confirm your compliance status.
Key Date
- 31 March 2026 – Final deadline to transition to TLS v1.2 and compliant cipher suites
- After this date, My Health Record access will be disconnected until compliance is achieved.
Cipher Suite Requirements
Non‑Compliant:
- ECDHE‑RSA‑AES256‑SHA384
- ECDHE‑RSA‑AES128‑SHA256
- ECDHE‑RSA‑AES256‑SHA
Compliant:
- ECDHE‑RSA‑AES256‑GCM‑SHA384
- ECDHE‑RSA‑AES128‑GCM‑SHA256
Why This Matters
- Protects patient data using modern, secure encryption
- Prevents service interruptions that may affect clinical workflows
- Maintains a safe and reliable digital health environment for clinicians and patients
If you need support or have questions about the upgrade, please contact your software vendor, IT provider, or your PHN team.