Australia has spent hundreds of millions planning and starting the build on a health data architecture for a world that no longer exists. So why aren’t we stopping to ask if it still makes sense?
Australia is amid a major program of building a genuinely significant health data infrastructure, including an ambitious associated regulatory agenda.
But we have a problem now: AI.
It’s worth quickly outlining the scale of what’s currently either committed, funded or in active construction, because taken together it’s a lot of money and a lot now locked and loaded in via the tender pipeline for something that, on the ground, is still mostly unbuilt.
Start with the strategy layer.
The National Digital Health Strategy 2023-2028 and its accompanying five-year Delivery Roadmap set the overarching vision.
Sitting alongside it is the Digital Health Blueprint 2023-2033, the National Healthcare Interoperability Plan 2023-2028 (44 separate actions), the National Framework for Digital Health Standards, and the National Healthcare Identifiers Roadmap.
That’s five major strategy documents, each with its own priority areas, outcomes and delivery milestones, all still officially current, and none developed with the current massive disruptive wave of AI, both provider- and patient-side, in mind.
Then there’s the actual build.
In August 2025, the Australian Digital Health Agency awarded Telstra Health a three-year, $33 million contract – backed by a further $144 million allocated in the federal budget for the broader project – to rebuild My Health Record’s data architecture around FHIR, working alongside Smile Digital Health and Leidos Australia.
It’s a big commitment: essentially atomising a record system built on older clinical document architecture into modular, FHIR-native components capable of real-time exchange rather than static document uploads.
We are assuming this project, if it’s on timetable, is still nowhere near complete.
Add to that the $598.3 million committed over two years from 2026-27 for My Health Record’s own ongoing operation and enhancement, a further $13.3 million over two years for Sparked, the CSIRO-led national FHIR accelerator program, and the Australian Digital Health Agency’s own annual operating budget of roughly $350-400 million.
The ADHA is also currently developing a new cybersecurity strategy and roadmap, and has separately flagged outsourcing the creation of its next corporate IT strategy.
That’s several hundred million dollars of active commitment, five overlapping strategy documents, and one major systems rebuild still under construction.
That’s an enormous amount of planning, funding and architecture, most of it locked in, very little of it yet delivered.
But here’s the thing: almost all of it was conceived, funded or contracted before generative and agentic AI became the dominant force reshaping how health data might be better able to move.
The National Digital Health Strategy, for instance, name-checks AI exactly the way you’d expect a 2023 document to – as one line in a list of “emerging technologies”, alongside genomics and spatial data, that the system should eventually “embrace”.
That’s the full extent of AI’s treatment in the foundational strategy document underpinning all of this. It isn’t a plan for AI. It’s an acknowledgment that AI exists.
Meanwhile, actual legislation has moved forward in a genuinely useful, if piecemeal, way – the pathology and imaging sharing mandate, the November 2025 identifiers reform.
But it was drafted for the big “sharing by default” plan, and for a pre-agentic-AI world, and nothing in the public record to date suggests ADHA or the Department of Health, Disability and Ageing (DOHDA) has gone back to test any of this hundreds-of-millions-of-dollars architecture, roadmap suite or in-flight Telstra rebuild against what AI actually now demands of a health data system.
No review has been flagged. No public statement has acknowledged the question needs asking. The infrastructure spend keeps rolling forward on its pre-AI assumptions, even as AI reshapes the environment it’s rolling into in real time.
The 2026-27 Budget has already locked in the next expansion of the original plan – medicines information and GP chronic condition management plans – with more document types flagged to follow. Each piece has its own consultation process, its own commencement date, its own rules.
All of it is running on pre-AI health infrastructure development timelines and protocols.
Is all of it out of date already?
No one knows because no one has paused to ask whether this is the right architecture for the environment it’s soon to operate in – one where AI systems, not just clinicians and patients logging into a portal, are becoming primary readers and writers of health data.
In one respect the timing of this AI revolution is bad luck.
But that’s how this cookie is crumbling, everyone: we can’t just sit back and ignore it because we’ve done so much work – a lot of it good – for what is now “the old plan”. Sit back and hope it works in this new world. Because it almost certainly won’t. At least not in a manner that patients and providers deserve.
Related
Two tracks that don’t meet
Dealing with the speed of AI is a new paradigm and we need to think about getting our heads around it from a leadership and management perspective fast.
Our National AI Plan landed on 2 December 2025, six days after the Regulatory Reform Omnibus Act passed parliament.
The two documents were developed by different parts of government, on different timelines, for different purposes, and it shows.
The AI Plan is a horizontal, economy-wide document: it explicitly avoided a standalone AI Act, opting instead to lean on existing sector regulators and general reforms to privacy and consumer law.
It’s generic and not fit for purpose for health.
It said nothing about My Health Record’s architecture, or about whether a document-by-document, MyHR-first sharing model still makes sense once AI tools are doing a meaningful share of the reading, writing and reasoning over that data.
The privacy reforms most relevant to AI are moving on their own separate schedule too.
A second tranche of Privacy Act reforms, aimed specifically at generative AI’s effect on personal information, was still being prepared for cabinet as of mid-2025, with the Attorney-General publicly conceding the current framework is “not fit for the digital age”.
From December 2026, organisations will need to disclose when AI is used in decisions that significantly affect someone’s rights, a real and useful obligation, but again, a horizontal one, arriving on top of health data architecture rather than helping to shape it.
The clearest sign of how reactive this all is sits with the Therapeutic Goods Administration, which spent 2026 shifting from “education” to compliance action against AI scribe vendors after finding scope creep, weak post-market monitoring and a lack of transparency in how some products manage their own risks.
The TGA’s processes and culture can’t manage AI.
AI scribes, as an example, have gotten away from the TGA in a manner that is demonstrative of the much larger problem that DOHDA and the ADHA are creating for themselves by so far putting their head in the sand and hoping that their once seemingly good plans will work in an AI health world.
The TGA can’t stop AI scribes now. It is chasing its tail trying to keep up. That’s not good and it’s likely to get worse.
The framework that’s been ‘in development’ since 2018
Interestingly, there is one piece of existing machinery that might have been the natural home for thinking about AI and health data: the framework for secondary use of My Health Record data.
This framework governs exactly the kind of research, analysis and (implicitly) AI training use that a data asset like MyHR would be valuable for. It was first legislated for in 2018. But as of the government’s own current published guidance, it still isn’t finalised.
Seven years, and counting, without an operational answer to how MyHR data can be used for research or public health purposes at all, let alone a considered position on AI specifically.
None of this is an abstract governance nicety. The shape of “sharing by default” assumes a fairly stable model of how data moves: a provider generates a report, uploads it to a central government record, and a person (patient or clinician) eventually logs in and reads it.
That model, albeit the centralised distribution mechanism isn’t great, was reasonable when the alternative was a fax machine.
But it’s a much shakier assumption in a world where patients are increasingly likely to hand their symptoms, results and questions to a general-purpose AI assistant and expect it to reason over their actual, current medical picture – not a periodically updated summary sitting behind a separate login.
The timing matters now
This shift is not just coming. If you talk to clinicians on the ground, it’s here, and many are struggling with it.
This is probably a case for direct, real-time, API-based access between the data source and the tool actually using it.
That’s actually the architectural principle underneath the US Cures Act model. Nothing in Australia’s current legislative program engages with this question directly.
We are building to solve a 2023 problem with 2018-era secondary-use governance, arriving into a 2026 AI seismic event.
MISA’s Emma Hossack gets it
Emma Hossack, CEO of the Medical Software Industry Association (MSIA), made a version of this point at the AIDH’s HIC26 conference last week – not about “sharing by default” specifically, but about Australia’s AI regulatory posture generally.
She said that Australia already has “hundreds of laws and regulations” that apply to AI without exemption, and that the real danger isn’t too little law – it’s regulating, or architecting infrastructure, “before you actually have a grasp of AI and what it’s going to do”.
Her most important point might have been: “There’s a lot of ideas and suppositions, but no one will actually know.”
Her proposed alternative is that rather than layering on more mandates, we urgently need to develop a national AI infrastructure performance profile that any product would need to meet before connecting to the healthcare system, paired with genuine sandboxes for experimentation rather than a “regulation holiday”.
Does that framework ring a bell for anyone?
It should because it’s the idea that we mandate every vendor and provider onto one set of common standards rather than deal with things piecemeal, but she’s quickly adapting the thinking to add AI to the standards mix.
It’s a framework built around testing and adapting as understanding improves, not locking in architecture years ahead of the technology actually landing.
“Sharing by default” was an amazing leap of thinking, faith and funding commitment.
It’s no one’s fault that it’s now effectively redundant because it was planned with old-school locked-in fixed architecture thinking.
There’s a lot to retrieve from the plan, including reharnessing the energy of everyone who has been involved.
But we need to shift the bones of the whole thing now into an appropriate adaptive and agile framework.
If we don’t, there will be people to blame. Because the problem is so obvious for everyone to see.
Yes, it must be disheartening and hugely frustrating to go back to the drawing board here, do a very quick review of our new world and re-strategise.
But that’s just adaptation.
It’s something the best leaders do in these days of significant technology change and disruption.
If we don’t at least try to do this, we are doomed to a version of the My Health Record debacle that will make its massive miss and money suck look tame.
When cloud technology was telling everyone to move to distributed architecture, security and data sharing, we stuck with the centralised model of the MHR.
Two more centralised pieces of architectural thinking to think on
While we’re rethinking the bones of “sharing by default”, two more pieces of the old architecture deserve the same scrutiny.
The first is the national Health Information Exchange plan, branded Health Connect Australia, which ADHA has been building out as the connective layer underneath the National Healthcare Interoperability Plan.
It’s still only at roadmap and early-build stage, which might be a convenient moment to pause ask whether it’s still needed in the form it is being thought about.
The logic of a centralised exchange hub is that it sits in the middle, brokering requests between systems that can’t otherwise find or trust each other.
But if AI agents and cloud-native, FHIR-based APIs can already query multiple provider systems directly, in real time, with proper authentication and consent handled at the edges, a chunk of what a central HIE hub is for starts to look like it could be done without the hub at all.
I’m genuinely not certain how far that argument goes, or whether there’s a coordination or trust function the exchange still needs to perform that distributed AI-driven querying can’t replicate. But it’s a live question, and it’s another one the government appears not to be asking in the context of our AI disruption so far.
The second is the National Healthcare Provider Directory, which ADHA is in the process of taking over from Services Australia, with the transfer proposed for February 2027, as part of the same FHIR-based consolidation drive.
It’s another old, centralised theme: one master directory, sitting centrally, that everything else is meant to check against. Maybe a single source of truth for provider identity is necessary; there’s a reasonable case that some things, like knowing who a provider actually is, should stay centralised no matter how distributed everything else becomes.
But it’s still worth asking, now, whether AI can help deliver that directory role better or differently than the old model assumes, rather than just pouring the same static, centrally administered directory into a new FHIR wrapper.
A directory that AI tools can help keep continuously verified, deduplicated and current is a different proposition to a directory one agency manually administers and everyone else queries.
Neither of these is a call to scrap anything. It’s a call to ask the question before, not after, we finish planning them and then building them the old way.
Also in today’s edition:
- Some Support at Home waits fall, but journey to care still takes 10 months
- Not reform, it’s neglect: Disability advocates
- Device price war erupts as MTAA challenges insurer claims
- ANMF calls for care minutes to be scrapped as staffing gaps persist
- Which PHN has the biggest bulk-billing increase?
- Vulnerable communities bear the brunt of our healthcare gap
- Support at Home provider margins hit record low
‘Sharing by default’ 2.0
Are we going to stick with the first version of “sharing by default” when the technology disruption from AI in health is something like two-to-three-fold the technology shift that we saw when cloud technology became a thing?
Our thinking is going to need to be comprehensive here: not just on our plans and our current builds mid-stream (hold up Telstra on that MHR atomisation thing for now) but on co-ordinating legislation as well.
Each new Act – the 2025 pathology mandate, the November identifiers reform, the medicines expansion already funded for 2026-27 – adds another layer to a structure that was substantially designed before agentic, patient-facing AI was a live consideration.
None of it is necessarily wrong.
But the longer each piece gets legislated separately, the harder – and more expensive – it becomes to change course if the underlying assumption about how people and systems will actually access health data turns out to be the wrong one for the environment it’s landing in.
None of this change is actually a problem.
It’s nearly all opportunity, and a series of very big ones, if you’re a strong digital health leader who is committed in the way I think many are.
Picture Tim Kelsey weighing up whether he could turn the momentum of the already $1.5 billion sunk cost of the My Health Record and all that was politically riding on its success upside down when he started at the ADHA as CEO in 2016.
At least Kelsey had a good excuse to double down and give his ill-fated opt out plan a go.
If our leaders come out and announce a comprehensive and very fast review of “sharing by default” in the context of the massively disruptive effect of AI in healthcare, who is going to say to any of them, that’s a bad idea?
Get on with building that old stuff despite AI?
Sure, we’ve spent a fortune on the ADHA making the plans, but it’s no one’s fault that those plans are almost certainly not fit for purpose now and have to be revised.
There’s no one to be embarrassed and the politics of it seem entirely manageable. In fact, handled the right way, this sort of challenge is a career maker, not destroyer.
The ADHA is full of committed people who have proven they’re good at planning (they aren’t good at building, but that’s another op-ed) and who clearly have a lot of energy and heart.
Let’s not squander this huge opportunity to remould “sharing by default” to deliver a much more agile and efficient healthcare system into the future for our providers and our patients.



