You thought you were registering with your GP. The government is linking that registration — with your name attached — to your hospital visits, aged care records, and other government data. A "registration form" becomes a dossier. The agency holding your MyMedicare data had 82 data breaches last year. The national auditor found they have no privacy risk plan and take more than 50 days to report most breaches. They call themselves a "high-risk privacy environment." They are correct.
What they claim: MyMedicare collects only registration information to formalise patient-GP relationship.
What we found: Privacy Notice: voluntary data "may also be linked to other information such as hospital, aged care or other government sector data to get a fuller picture of the health needs of Australians. The information you provide in this section will also be identifiable." A simple registration becomes a comprehensive identifiable health profile via cross-linkage.
What they claim: Information only shared with relevant agencies where patient has agreed or law requires.
What we found: Privacy Notice permits use for "reporting, compliance, audit, and evaluation; routine monitoring and reporting for MBS and DVA claims; data sharing to inform policy and strategic outcomes across government initiatives under secure data sharing arrangements." De-identified data shared with "tertiary institutions or peak bodies." The scope of permitted uses is far wider than what patients understand from a consent form signed at the GP.
What they claim: MyMedicare is voluntary and patients can withdraw at any time.
What we found: The official Privacy Notice states: "Information collected as part of your MyMedicare registration will continue to be held by Services Australia and the entities it has been shared with... even if you withdraw from the MyMedicare Program." Withdrawal is cosmetic — data already shared with Department of Health, DVA, and Australian Digital Health Agency cannot be recalled.
What they claim: MyMedicare is voluntary and will remain so.
What we found: Australian Doctors Federation chair warned: "GPs are rightly concerned that this is going to be the thin edge of the wedge." Scope of Practice Review recommended making MyMedicare participation required for blended payment models. Dr Chris Irwin: "if voluntary patient enrolment contains capitated payments, you can call it whatever you like; it is a capitated system. You can't '1984 your way out' of that fact."
What they claim: Services Australia keeps MyMedicare personal information secure to maintain privacy.
What we found: ANAO December 2025 audit found Services Australia "partly effective in managing the privacy of client information" with "deficiencies with risk management, data matching, record-keeping, privacy impact assessments, transparency and reporting." Notifiable data breaches rose from 7 in 2022-23 to 82 in 2024-25. 71% of breaches reported more than 50 days late. No enterprise-level privacy risk management plan despite operating in a "high-risk privacy environment."
What they claim: MyMedicare data managed consistent with Privacy Act 1988 protections as described at registration.
What we found: The Regulatory Reform Omnibus Act 2025 (passed 27 November 2025) introduced "tell-us-once" cross-system data sharing, amended the healthcare identifier framework, My Health Record Act, and Australian Immunisation Register legislation. Data-sharing powers expanded AFTER most patients signed consent — without requiring renewed consent from registrants.
What they claim: MyMedicare is separate from My Health Record and does not hold clinical information.
What we found: "As part of your MyMedicare registration, your chosen practice and GP will appear on your My Health Record." This is automatic — visible to all healthcare providers accessing that record — unless the patient takes separate action to suppress it within My Health Record settings.
What they claim: MyMedicare uses a "dual consent" model requiring informed agreement from both practice and patient.
What we found: Practices initiate registrations via paper form signed during consults — a power-imbalanced setting. Best Practice Software documentation shows practices "register patients on their behalf" via PRODA, with "Triple bulk billing incentive for longer MBS telehealth consultations" available ONLY for MyMedicare-registered patients. Longer MBS-funded telephone calls also require registration. Financial benefits flow to practices who maximise registrations.
What they claim: MyMedicare is a patient-centred voluntary system giving patients control of their healthcare relationships.
What we found: Practices can unilaterally withdraw a patient's registration: "You can withdraw registrations for patients who no longer attend your practice." No patient notification or consent required. Patients need consent to join but can be removed without it.