The Office of the Australian Information Commissioner ordered Australian Digital Health Agency contractors to rerun privacy impact assessments and commission fresh API penetration tests after a red-team exercise showed My Health Record FHIR gateways sometimes logged patient consent decisions without matching the scopes clinical software vendors actually requested, a gap that could let authorised apps read more document types than a consumer believed they had approved.

What broke

Investigators hired under the OAIC’s health-sector audit program simulated three registered clinical apps calling production-like gateways in a controlled environment. In two scenarios, consent banners displayed a narrow set of categories—pathology and discharge summaries—while access tokens still carried broader resource scopes until a secondary policy engine caught the mismatch. The third scenario failed to write an immutable audit row when a user revoked access mid-session, leaving downstream analytics with a stale “active consent” flag for eleven minutes.

ADHA said no production patient data were touched and that the findings came from a September retest mandated after an earlier penetration report flagged inconsistent scope propagation between the national consent service and vendor sandboxes. The agency paused onboarding of two prospective app publishers while engineers patch token minting and tighten correlation IDs across consent, authorisation, and audit subsystems.

Who has the file

The OAIC holds the regulatory file because My Health Record is a nationally significant dataset under the Privacy Act. Commissioner staff told ADHA to deliver updated privacy impact assessments for each API tier, independent retests by an accredited provider, and a public summary of scope-mapping fixes before new vendors receive production keys. State health departments that rely on the gateways for shared care plans were copied on the direction so their own privacy officers can reassess local integrations.

Clinical software vendors argued the failures sat in national infrastructure, not their code, but the OAIC noted publishers remain accountable for how their apps present consent screens. At least one major practice-management vendor said it would ship a forced upgrade that blocks launches if token scopes exceed what the user ticked on screen.

What is still unknown

Investigators have not said whether any live patient experienced over-broad access during routine care, and ADHA declined to publish counts of mismatched tokens in production logs, citing active forensics. Cybersecurity advisers want clarity on whether the stale-consent window could combine with shared clinic workstations—a common pattern in rural multipurpose rooms—to let a subsequent clinician session inherit access the prior patient thought they had revoked.

Parliament’s health technology inquiry, which resumes hearings in October, will likely ask whether consent artefacts should move to patient-held wallets rather than vendor-hosted banners. That debate predates this retest, but the scope mismatch gives privacy advocates a concrete example beyond abstract “trust us” assurances.

What agencies will measure

ADHA committed to monthly OAIC briefings on retest milestones, including time-to-revoke metrics and percentage of API calls rejected for scope drift. The Australian Cyber Security Centre will review whether gateway hardening guidance for health SaaS needs explicit consent-state checks akin to financial-services step-up rules.

For practices, the practical impact is paperwork and patch Tuesday: expect vendor emails asking administrators to revalidate app registrations and to rerun staff training on what each integration can see. The OAIC said it is not proposing to switch off My Health Record APIs, but it will escalate to enforceable undertakings if retests fail again.

Privacy officers in Queensland and Victoria said they are pulling local audit trails to see whether hospital portals mirrored the national consent flags during the test window. ADHA urged clinics not to disable integrations preemptively, arguing that disconnected records create their own safety risks when specialists cannot see recent imaging.

Consumer Health Forum representatives welcomed the retest order while asking for a patient-facing dashboard that shows live scopes, not static PDF consent forms. Until that ships, the OAIC’s demand for independent penetration retests is the clearest signal that API convenience will not outrun auditability in Australia’s digital health stack.

Medical software industry groups said they will publish a shared checklist for consent-screen wording so vendors cannot blame ambiguous national labels when scopes widen silently. ADHA promised to host a technical webinar for developers once patched gateways reach staging, a small step toward the transparency patients expect when records leave the surgery desktop.