(1) A person must not collect from the My Health Record system health information included in a healthcare recipient's My Health Record if the collection by the person is not authorised under Division 2, and the person knows or is reckless as to that fact.
(2) A person must not use or disclose health information included in a healthcare recipient's My Health Record if:
(a) the person obtained the information by using or gaining access to the My Health Record system; and
(b) the use or disclosure is not authorised under Division 2, and the person knows or is reckless as to that fact.
Fault - based offence
(3) A person commits an offence if the person contravenes subsection (1) or (2).
Penalty: Imprisonment for 5 years or 300 penalty units, or both.
Civil penalty
(4) A person is liable to a civil penalty if the person contravenes subsection (1) or (2).
Civil penalty: 1,500 penalty units.