Skip to Content
Login or Sign Up

Working with our delivery partners, we have made significant progress in operationalising and enhancing the essential foundations and infrastructure required to enable a truly national electronic health system.

Implementation Resources

National eHealth Security and Access Framework v4.0

Name
EP-1544:2014 National eHealth Security and Access Framework v4.0
Identifier
EP-1544:2014
Version
4.0
Published Date
06-06-2014
Contact
NEHTA

The National eHealth Security and Access Framework (NESAF) provides standards, tools, and guides for the Australian healthcare sector to build and implement secure systems that protect patient data and eHealth-related assets, while providing the provenance required for ensuring patient safety and privacy. (For more details and to download factsheets, see Our Work/Security.)

NESAF v4.0 is derived directly from previous releases and includes refinements and minor inclusions to improve the value of the current product set.  

This release consolidates stakeholder feedback from independent reviews by reputable security firms as well as updates based on lessons learned during the application of the framework from the March 2012 release.

The NESAF has also been updated to reflect changes to:

  • Processes relating to online registration for the PCEHR
  • The use of NASH certificates
  • Australian privacy legislation.

The clinical, consumer and business fact sheets published in the NESAF v3.1 bundle are still available from https://www.nehta.gov.au/our-work/security. No changes have been made to these factsheets since their last release.

Future release: Three industry guides have been developed for NESAF v4 to address security for healthcare organisations looking at implementing:

  • Bring your own device (BYOD)
  • Cloud computing
  • Secure mobile applications

These guides are currently undergoing industry consultation and will be published in a future minor release.

Product Components of National eHealth Security and Access Framework v4.0

Product Components of National eHealth Security and Access Framework v4.0
Identifier Name Published Date
NEHTA-1546:2014 NESAF v4 - Business Blueprint v1.0 06-06-2014
NEHTA-1549:2014 NESAF v4 - Framework Model and Controls v1.0 06-06-2014
NEHTA-1550:2014 NESAF v4 - Implementer Blueprint v1.0 06-06-2014
NEHTA-1545:2014 NESAF v4 - Overview v1.0 06-06-2014
NEHTA-1553:2014 NESAF v4 - Release Note v4.0 06-06-2014
NEHTA-1552:2014 NESAF v4 - Standards Mapping v1.0 06-06-2014