Regional Architectures & Security: Australia and New Zealand
The Australian digital health environment provides a unique architectural case study, characterized by massive, state-wide procurement strategies and sweeping regional integrations.
New Zealand's health sector provides an exemplary comprehensive architectural case study for enterprise security controls within EHR/HIS environments through the HISO 10029 standards.
Regional Context
Understanding regional architectures is critical for solution architects working in the Asia-Pacific healthcare market, where state-wide deployments and national frameworks differ significantly from US models.
Asia-Pacific Health IT
HIMSS Asia-Pacific healthcare IT resources and regional insights
View HIMSS APACGlobal EHR Deployments
KLAS research on global EHR deployment patterns and vendor performance
Explore KLAS GlobalAustralian State-by-State Architectures
Australia's healthcare IT landscape is defined by state-level procurement rather than fragmented independent hospital purchases.
State Deployments
Australian state healthcare IT deployments
| State | Platform | Architecture |
|---|---|---|
| New South Wales (NSW) | Cerner Millennium → Epic SDPR | AWS cloud migration, AWS Landing Zone for Epic |
| Queensland | Cerner Millennium (ieMR) | The Viewer for statewide data aggregation |
| Victoria | Epic Systems | Parkville Precinct unified Epic database |
| South Australia | Sunrise (Altera Digital Health) | State-wide rollout replacing legacy systems |
NSW Health: Cloud Migration
- Historically relied on Cerner Millennium via eMR Connect
- Successfully migrated production Cerner to AWS public cloud
- Transitioning to Epic SDPR (Single Digital Patient Record)
- Completed advanced AWS Landing Zone infrastructure
eHealth NSW on AWS
Specific AWS public-sector case study relevant to Australian state-scale healthcare cloud migration.
Read case studyQueensland and Victoria Deployments
Queensland and Victoria represent distinct architectural approaches to statewide EMR deployment.
Queensland Health: ieMR
- Cerner Millennium framework branded as ieMR
- The Viewer aggregates data statewide
- Collates patient data from multiple distinct state systems
- Provides unified longitudinal record regardless of source EMR
Victoria: Parkville Precinct
- Strong Epic Systems adoption
- Royal Melbourne Hospital
- Royal Children's Hospital
- Single unified Epic database across precinct
- Drastically reduces duplicate data entry
Victorian digital health programs
Victorian public health digital health initiatives and safety resources
Explore Vic HealthNational Interoperability: My Health Record
At the federal level, Australian healthcare interoperability is governed by the Australian Digital Health Agency (ADHA).
Healthcare Identifiers (HI) Service
The HI Service resolves demographic fragmentation nationally by issuing three distinct, mandatory identifiers:
HI Service identifiers
| Identifier | Name | Issued To |
|---|---|---|
| IHI | Individual Healthcare Identifier | Patients |
| HPI-I | Healthcare Provider Identifier-Individual | Clinicians |
| HPI-O | Healthcare Provider Identifier-Organisation | Healthcare facilities |
HI Service integration with NASH authentication
Loading diagram...
NASH PKI Certificates
To securely authenticate and integrate with the HI Service, local EMR systems must utilize National Authentication Service for Health (NASH) Public Key Infrastructure (PKI) certificates.
HI Service Specification
Australian Digital Health Agency Healthcare Identifiers Service documentation
View HI ServiceNASH PKI Certificates
NASH certificate registration and management for healthcare providers
Learn NASH PKIMy Health Record Architecture
My Health Record (MHR) is Australia's national opt-out EHR platform.
B2B Gateway Evolution
- Historical: SOAP web services + CDA payloads
- Clinical documents: Discharge summaries, pathology reports
- FHIR-aligned interoperability programs are expanding alongside the legacy model
- Benefit: clearer migration path toward more granular APIs where national programs support them
National Modernization Pattern
A safer way to teach this is that Australia is broadening FHIR-based interoperability programs while My Health Record still depends heavily on established B2B and document-exchange pathways. Treat FHIR as an expanding modernization direction, not as a blanket replacement claim for every current MHR interaction.
CDA to FHIR Australia
ADHA guidance on transitioning from CDA to FHIR for Australian implementations
Learn CDA MigrationNew Zealand: HISO 10029 Security Framework
In New Zealand, the protection of clinical data is legally governed by the Privacy Act 2020 and the Health Information Privacy Code 2020.
Health Information Security Framework (HISF)
Te Whatu Ora (Health New Zealand) enforces the HISF, published under the HISO 10029 standard. The framework outlines rigid, comprehensive cyber security requirements spanning the entire clinical data lifecycle.
HISF Functional Phases
HISF functional phases and requirements
| Phase | Architectural Security Requirements |
|---|---|
| Plan (Governance) | Establish acceptable use policies, design secure systems, define resilience/BCDR policies |
| Identify (Risk Assessment) | Evaluate supplier security, perform risk assessments on EHR/HIS acquisitions, scan medical devices |
| Protect (Access & Crypto) | Enforce IAM, mandate MFA, implement robust cryptography for data at rest and in transit |
| Detect (Monitoring) | Implement application logging, monitor network traffic, conduct independent security reviews |
| Respond (Incident Mgt) | Report incidents immediately, notify impacted customers, preserve forensic evidence |
HISO 10029: Protect Phase Requirements
Within the Protect phase, the framework mandates strict architectural controls.
Identity and Access Management (IAM)
- Complete, auditable lifecycle governance of user accounts
- Absolute enforcement of Multi-Factor Authentication (MFA)
- MFA required for all privileged or administrative access
Network Topology
- Active separation of sensitive processing systems
- Dedicated, isolated network segments
- Insulation from general corporate traffic
Cryptographic Standards
- All electronic health information encrypted at rest
- All electronic health information encrypted in transit
- Transmission of unencrypted clinical payloads banned
- Raw MLLP over open networks prohibited
HISO 10029 Standard
New Zealand HISO 10029 Health Information Security Framework standard
View HISO 10029Healthcare MFA Requirements
NIST guidelines on multi-factor authentication for healthcare systems
Learn MFA StandardsHISO 10029: Detect and Respond
Operational resilience and security monitoring are critical pillars of the HISF.
Detect Phase: Monitoring
- Comprehensive application logging
- Continuous network traffic monitoring
- Independent security reviews prior to system upgrades
- All access and modification events aggressively logged
- Secure log storage for forensic audit integrity
Respond Phase: Incident Management
- Report all security incidents immediately to governance boards
- Notify impacted customers
- Strictly preserve forensic evidence
- Documented incident response procedures
Security Incident Response
Australian Cyber Security Centre incident response guidance
View ACSC GuideHealthcare Audit Logging
HIPAA audit logging requirements for healthcare information systems
Learn Audit RequirementsCloud Modernization: Hybrid Multi-Cloud Strategy
Historically, healthcare institutions relied exclusively on heavily fortified, isolated, on-premises data centers.
Cloud First Policy
Te Whatu Ora has adopted an aggressive modernization mandate rooted in the New Zealand Government's Cloud First policy, pushing the healthcare sector away from localized, aging physical infrastructure toward highly resilient, scalable public cloud environments.
Hybrid Multi-Cloud Programme
Cloud modernization initiatives
| Initiative | Description |
|---|---|
| Cloud First Policy | NZ Government policy pushing healthcare toward public cloud |
| Hybrid Multi-Cloud Programme | Enterprise-grade cloud landing zones (AWS, Azure) |
| Legacy Migration | Migrate EMR databases and integration engines to managed cloud |
| Advanced Integration | Prepare data layer for regional HIE frameworks and AI-driven CDS |
Modernization Benefits
By migrating to managed cloud infrastructure, healthcare organizations achieve extreme availability, automated geographic failover, and advanced cryptographic protections required by HISO 10029 standards.
NZ Cloud First Policy
New Zealand Government Cloud First policy and implementation guidance
View Cloud FirstHealthcare Cloud Security
AWS HIPAA compliance and healthcare cloud security best practices
Explore Cloud SecurityAustralian Privacy Principles (APPs)
The Australian Privacy Principles (APPs) are the cornerstone of privacy protection in Australia, governing how healthcare organizations must handle personal information including sensitive health data.
The 13 Australian Privacy Principles
Australian Privacy Principles for healthcare organizations
| Principle Group | Requirements |
|---|---|
| APP 1-5: Transparency & Collection | Open management, anonymity, collection notices, unsolicited information, use/disclosure |
| APP 6-9: Use & Disclosure | Purpose limitation, direct marketing, cross-border disclosure, government identifiers |
| APP 10-13: Data Quality & Access | Data accuracy, security, access rights, correction rights |
Notifiable Data Breaches (NDB) Scheme
- Mandatory notification of eligible data breaches to affected individuals
- Notification to Office of the Australian Information Commissioner (OAIC) required
- Applies to all entities covered by the Privacy Act 1988
- Healthcare organizations must have breach response procedures in place
- Failure to notify can result in significant penalties and enforcement action
NDB Compliance
Healthcare organizations must assess suspected breaches within 30 days and notify affected individuals and OAIC when there is likely to be serious harm.
Australian Privacy Principles
OAIC guidance on the 13 Australian Privacy Principles for healthcare organizations
View APPs GuideNDB Scheme Guide
OAIC Notifiable Data Breaches scheme requirements and notification process
Learn NDB RequirementsIRAP PROTECTED Certification
The Information Security Registered Assessors Program (IRAP) provides independent assessment of cloud services against the Australian Signals Directorate (ASD) Information Security Manual (ISM) controls.
IRAP PROTECTED Requirements
IRAP PROTECTED security controls for healthcare cloud services
| Control Area | Requirement |
|---|---|
| ASD ISM Compliance | Implement Information Security Manual controls for PROTECTED data |
| Data Sovereignty | Australian health data must remain within Australian borders |
| Encryption | Encryption at rest and in transit using approved algorithms |
| Access Control | Multi-factor authentication, role-based access, audit logging |
AWS IRAP Certification
- Multiple AWS Australian regions achieved IRAP PROTECTED certification
- Enables Australian government and healthcare agencies to host PROTECTED data
- Includes controls for encryption, access management, and incident response
- Regular independent assessments ensure ongoing compliance
Data Sovereignty Requirements
- Australian health data must remain within Australian borders
- Cross-border data transfer requires explicit consent or legal authorization
- Cloud providers must guarantee data residency in Australian regions
- Backup and disaster recovery sites must also comply with sovereignty requirements
AWS IRAP Assessment
AWS IRAP PROTECTED certification for Australian government and healthcare workloads
View AWS IRAPASD Information Security Manual
Australian Signals Directorate ISM controls for PROTECTED data classification
Explore ASD ISMState-Specific Healthcare Privacy Compliance
In addition to federal Privacy Act requirements, Australian states have enacted specific legislation governing health information privacy and access.
State Health Privacy Legislation
Australian state health privacy legislation and enforcement
| State | Legislation | Enforcement |
|---|---|---|
| New South Wales (NSW) | Health Records and Information Privacy Act (HRIP Act) | NSW Privacy Commissioner |
| Victoria (VIC) | Health Records Act 2001 | Health Services Commissioner |
| Queensland (QLD) | Information Privacy Act 2009 | Office of the Information Commissioner QLD |
| South Australia (SA) | Health Care Act 2008 | SA Health |
NSW: Health Records and Information Privacy Act
- HRIP Act provides additional protections beyond Privacy Act 1988
- Health Privacy Principles (HPPs) specific to health information
- Applies to both public and private sector health organizations in NSW
- Enforced by NSW Privacy Commissioner
Victoria: Health Records Act 2001
- Health Privacy Principles (HPPs) govern collection, use, and disclosure
- Right of access to health records
- Applies to all health service providers in Victoria
- Enforced by Health Services Commissioner
Queensland & South Australia
- QLD: Information Privacy Act 2009 includes specific health privacy provisions
- SA: Health Care Act 2008 governs health information handling
- Both states align with federal Privacy Act requirements
- State commissioners handle complaints and enforcement
NSW HRIP Act
NSW Health Records and Information Privacy Act requirements and Health Privacy Principles
View NSW HRIP ActVictoria Health Records Act
Victoria Health Records Act 2001 and Health Privacy Principles guidance
Explore Vic Health RecordsHISO 10029: Security Framework Overview
The New Zealand Health Information Security Framework (HISF) under HISO 10029 provides a comprehensive five-phase approach to healthcare security.
Security Framework Phases
HISO 10029 security framework phases and focus areas
| Phase | Focus | Key Controls |
|---|---|---|
| Plan | Governance & Policies | Acceptable use, BCDR, system design |
| Identify | Risk Assessment | Supplier evaluation, device scanning, risk assessments |
| Protect | Access & Crypto | IAM, MFA, encryption, network segmentation |
| Detect | Monitoring | Logging, network monitoring, security reviews |
| Respond | Incident Management | Incident reporting, notification, forensics |
Framework Application
HISO 10029 applies to all organizations handling New Zealand health information, including cloud providers, software vendors, and healthcare facilities.
HISO 10029 Standards
Te Whatu Ora HISO 10029 Health Information Security Framework standards
View HISO StandardsHISF Guidance Documents
HISO 10029 guidance for healthcare suppliers and cloud providers
Download HISF GuideSummary & Key Takeaways
Australian and New Zealand healthcare architectures demonstrate state-wide deployment strategies and comprehensive security frameworks.
Core Concepts Recap
- NSW: Cerner → Epic SDPR on AWS
- Queensland: ieMR with The Viewer aggregation
- Victoria: Epic Parkville Precinct
- South Australia: Sunrise state-wide rollout
- My Health Record: National opt-out EHR
- HI Service: IHI, HPI-I, HPI-O identifiers
- HISO 10029: NZ security framework (Plan, Identify, Protect, Detect, Respond)
- APPs: 13 Australian Privacy Principles
- IRAP PROTECTED: ASD ISM certification for cloud services
Security Requirements
- MFA for all privileged access
- Encryption at rest and in transit
- Network segmentation for clinical systems
- Comprehensive audit logging
- BCDR plans with tested restoration
- Data sovereignty: Australian/NZ data must remain in-country
Compliance Frameworks
- Federal: Privacy Act 1988, NDB scheme
- State: HRIP Act (NSW), Health Records Act (VIC), Information Privacy Act (QLD)
- NZ: HISO 10029, Privacy Act 2020, Health Information Privacy Code
- Cloud: IRAP PROTECTED certification
Australian Health Security
Australian Department of Health cybersecurity and data protection resources
View Health SecurityOAIC Notifiable Data Breaches
Office of the Australian Information Commissioner NDB scheme guidance
Learn NDB SchemeExternal References
For further reading on Australian and New Zealand health IT architectures, privacy, and security:
Australian Digital Health Agency
ADHA - governs My Health Record and national healthcare interoperability standards
Visit ADHANSW Health Digital
NSW Health Single Digital Patient Record (SDPR) program and cloud migration
Explore NSW Health DigitalTe Whatu Ora HISO Standards
New Zealand Health Information Standards Organisation - HISO 10029 security framework
View HISO StandardsAWS Australia (IRAP)
AWS IRAP Assessment for Australian government and healthcare workloads with sovereign cloud capabilities
Learn AWS IRAPOAIC Privacy Principles
Office of the Australian Information Commissioner - 13 Australian Privacy Principles guidance
View APPs GuideASD Information Security Manual
Australian Signals Directorate ISM controls for PROTECTED data and IRAP certification
Explore ASD ISMKnowledge Check
Test your understanding with this quiz. You need to answer all questions correctly to mark this section as complete.