secure messaging standards

Interoperability in 2026: what the government’s secure messaging standards mean for your practice

If you work in an Australian healthcare practice, you already rely on secure messaging to send and receive referrals, results and clinical correspondence. What you may not realise is that the rules governing how these systems work together are changing, and those changes will affect the technology choices your practice makes over the next few years. 

Here is what is happening, what it means for you and what to look for when choosing or reviewing your secure messaging provider. 

Over two decades later, we’re still here – and still one of only three healthcare secure messaging providers in Australia that meet the highest interoperability and security standards. 

The interoperability problem 

For years, Australian healthcare has operated with multiple secure messaging providers that do not always communicate seamlessly with each other. If your practice uses one provider and a specialist or hospital uses another, messages may not flow as easily as they should. This fragmentation has been one of the biggest barriers to the kind of connected, paperless healthcare that government policy has been pushing toward for more than a decade. 

The result? Practices maintaining multiple provider accounts, keeping fax machines as a backup, or manually re-entering information that should have arrived digitally. It is a waste of clinical time and an unnecessary source of risk. 

What the government is doing about it 

The Australian Digital Health Agency (ADHA) has been working with software vendors, secure messaging providers and clinical system developers to establish national interoperability standards for secure messaging. This work sits within the National Digital Health Strategy 2023-28, which identifies secure messaging as a foundational capability for a digitally connected health system. 

Two key changes are central to this initiative. 

A federated provider directory. Rather than each messaging provider maintaining its own siloed address book, the ADHA has been building toward a model where clinical systems can search across multiple directories to find accurate, validated electronic addresses for healthcare providers. Provider Connect Australia (PCA) is the national platform underpinning this. It gives practices a single place to update their business details, which then flow automatically to connected partners including secure messaging providers, PHNs and service directories. 

Standardised message formats. The ADHA has also been working with industry to agree on standardised specifications for message content and exchange. The goal is that messages sent from one provider’s system arrive correctly formatted and usable in the recipient’s system, regardless of which messaging vendor either party uses. 

Mandatory standards in government procurement 

State, territory and Commonwealth governments have jointly confirmed that future procurements for applicable systems will reference these interoperability standards as mandatory requirements. In practical terms, this means that when a state health department or PHN selects technology for referral management, eReferrals or clinical communication, compliance with these standards will be a baseline requirement rather than an optional extra. 

For practices, this matters because it signals the direction of the entire sector. Systems that already meet these standards are better positioned for the long term. Systems that do not will face increasing pressure to comply or risk being left out of government-connected workflows. 

The three standards that matter 

When evaluating a secure messaging provider, there are three core interoperability standards to understand. 

HL7 v2 is the most widely used messaging standard in Australian healthcare today. It is the format used for the majority of pathology results, radiology reports and clinical correspondence flowing between systems. Any provider that handles day-to-day clinical messaging needs robust HL7 v2 support. 

Clinical Document Architecture (CDA) is an XML-based standard for structuring clinical documents such as discharge summaries, referral letters and shared health summaries. CDA compliance is particularly relevant for practices that interact with hospital systems and government programs. 

FHIR (Fast Healthcare Interoperability Resources) is the newer, web-based standard that is expected to become increasingly important over the coming years. FHIR enables more modern, API-driven approaches to data sharing and is central to the ADHA’s longer-term interoperability vision. Not all messaging providers currently support FHIR, but those that do are better prepared for the transition ahead. 

A provider that meets all three standards gives your practice the broadest compatibility today and the lowest risk of needing to switch as government requirements evolve.

What this means for your practice right now 

If you are reviewing your secure messaging setup, there are a few practical steps worth taking. 

Check your provider’s standards compliance. Ask whether they meet HL7 v2, CDA and FHIR standards. Not all providers support all three, and partial compliance can create gaps in your connectivity. 

Register with Provider Connect Australia. PCA is free and reduces the administrative burden of keeping your practice details up to date across multiple directories and partners. If you have not registered yet, your PHN can help you get started. 

Consider your provider’s pricing model. The secure messaging landscape has seen pricing changes recently, with some providers introducing or restructuring subscription fees. Understand what you are paying for, whether there are per-page or per-document charges, and whether pricing is transparent and predictable. 

Think about what happens to your provider’s roadmap. Ownership changes and investment priorities in the secure messaging market can affect product development, pricing and support. Understanding who owns your provider and what their strategic priorities are can help you assess long-term reliability. 

Looking ahead

The Digital Health Festival in Melbourne on 20-21 May will feature sessions on interoperability, secure messaging and the future of connected care across Australia. If your practice is navigating these decisions, it is worth following the conversation. The direction set at events like DHF often shapes the procurement standards and policy settings that affect every practice in the country within the following 12 to 18 months. 

ReferralNet is one of Australia’s three compliant secure messaging providers, meeting HL7 v2, CDA and FHIR standards. We offer transparent pricing from $15 per month with no per-page charges, and we integrate directly with clinical systems including Best Practice, Medical Director, Genie and Zedmed. As a product of ASX-listed Global Health Limited, ReferralNet is Australian owned and supported by a local team. 

If you would like to understand how ReferralNet fits your practice, contact our team or view our pricing. 

About ReferralNet

ReferralNet Secure Messaging is a platform developed by Global Health Ltd designed to facilitate secure and efficient communication between healthcare professionals.

It seamlessly integrates with existing Electronic Health Records (EHR) and other healthcare systems, and enables real-time data exchange between providers, ensuring that patient information is shared quickly and accurately.

Follow us