Public Key Infrastructure

Human Services Public Key Infrastructure (PKI) certificates are one way health professionals can get secure access to our online services.

From 7 December 2020, you won't be able to log on to HPOS using a PKI certificate. You’ll need to set up a PRODA account so that you can continue to access HPOS. Your PKI site certificate will still allow access to our digital health claiming channels, for example Medicare Online, until March 2022.

We issue PKI certificates to healthcare organisations and in special circumstances, individual healthcare providers.

Secure Hash Algorithm

PKI certificates use secure hash algorithm (SHA) technology to send secure messages and other transactions online.

  • Transactions through your practice management or patient administration software use SHA-1 technology. As these transactions also need PKI site certificates, we give users SHA-1 PKI site certificates
  • The latest version of some web browsers need SHA-2 technology to send messages and transactions. We automatically send SHA-2 PKI individual certificates to users

If you need a specific SHA version of a PKI certificate, contact the eBusiness Service Centre.

National Authentication Service for Health PKI certificates

Healthcare providers and supporting organisations must have a National Authentication Service for Health (NASH) PKI certificate to access the My Health Record system.


Healthcare providers and supporting organisations can use a PKI certificate to do business with us online.

How to apply

Use these forms to apply for a Human Services PKI certificate:

Make sure you download the latest registration forms so your application isn't delayed. There are recent changes to the evidence of identity criteria.

To find out more information go to:


Human Services PKI certificates expire every 2 or 5 years, depending on which policy your certificate was issued under.

Some software automatically renews your PKI certificate.

If your software doesn’t automatically renew your PKI certificate, we’ll send you a letter 60 days before your certificate expires. Complete the renewal confirmation and return it to us, then we can renew your PKI certificate.

PKI policy documents

PKI certificate policies are the rules for how we issue and use Human Services PKI certificates. Read the PKI policies and terms and conditions before you use your PKI certificate.

Healthcare Public Directory

The Healthcare Public Directory lists individuals and organisations with active or revoked PKI certificates. For more information go to Certificates Australia.


We have IT standards for electronic transmission, scanning and storage of:

  • referrals to specialists or consultant physicians, and
  • requests for pathology and diagnostic imaging services.

Read about these standards in the Notice of Information Technology (IT) Requirements.

Our PKI certificates meet the Gatekeeper (Public Key Infrastructure) framework under the International Organisation for Standardisation Health Informatics - Public Key Infrastructure technical specification (ISO/TS 17090).

PKI supporting documents, tools and software

Read how to install a PKI individual certificate and the PKI Certificate Manager.


If you need help with your PKI certificate contact us.

Page last updated: 6 April 2021