Quantum readiness for health boards and executives: what to do now, what can wait
READ TIME 8 MIN
From 30 November 2026, private sector organisations can join the Australian Government Digital ID System (AGDIS) for the first time. For most businesses the path is to become a relying party: you confirm a customer's or staff member's identity through an accredited provider, without handling or storing their identity documents yourself. The government side already runs at national scale, the benefit to customers is real, and the unglamorous preparation, your cyber and privacy artefacts, is worth starting now. There is a genuine first-mover advantage.
As a former CIO and CDO across billion-dollar health systems, I have spent more time than most on an unglamorous problem: proving that a person is who they say they are, quickly, safely, and without building a vault of documents that becomes a target. On 30 November 2026 that problem gets materially easier for Australian business, and the change has barely registered outside identity circles.
This is a short brief on what is changing, what it is worth to companies and their customers, a hypothesis on what it could mean for private hospitals, and how to apply.
Until now, only Commonwealth, state and territory government entities could participate in the AGDIS. From 30 November 2026, accredited private sector entities can apply to the Digital ID Regulator, the ACCC, to join. This is the final phase of the staged rollout under the Digital ID Act 2024, which commenced on 1 December 2024.
There are two roles, and the one you choose sets the entire workload. A relying party verifies its customers or staff through an accredited provider and does not need to be accredited itself. This is the likely path for most service businesses, including healthcare providers and their patient and staff portals. An accredited provider issues identity, attribute or exchange services, and must clear a heavier two-stage process. The rest of this brief assumes the relying party path, because that is where most organisations will sit.
One principle is built into the law and worth stating early: participation is voluntary. A relying party cannot force anyone to create a Digital ID, and must keep an alternative verification method available. Any customer journey that assumes universal adoption needs a fallback.
This is not a pilot waiting to find out if anyone will use it. In its first year of operation, the AGDIS has reached real scale.
The myID app, formerly myGovID and operated by the Australian Taxation Office, is what most people already use. The design point behind those numbers is the part that matters for business: a person proves their identity once and reuses it, and the service confirms who they are without collecting and storing the underlying documents. Share less, store less. That is not a side effect. It is the whole idea.
For the people you serve, the benefit is immediate and felt. Onboarding stops being a hunt for the passport, the licence and a recent utility bill, followed by an anxious upload of all three to yet another company's database. Instead they confirm their identity through a provider they already trust, hand over less, and stay in control of what is shared.
That matters against a real backdrop. Identity crime costs Australians around $3.1 billion a year, and roughly one in four of us will be affected in our lifetime. Every copy of a driver licence sitting in a company file is part of that exposure. A verification model that confirms identity without spreading documents around reduces the harm to your customers when, not if, the next breach happens somewhere in the chain.
Three benefits stand out, and one of them is quietly the largest.
Lower friction, lower cost. Faster onboarding means less abandonment and less manual identity checking. Less fraud. Government-grade, biometrically verified identity is a far harder target than a scanned licence. And the quiet one: a smaller honeypot. If you verify through an accredited provider and never store the underlying documents, you simply hold less of the data that turns a breach into a catastrophe. The average data breach in Australia now costs around $4 million and takes roughly 200 days to detect. The cheapest data to protect is the data you chose not to collect.
There is a bigger-picture case too, though it should be read as projection rather than promise. Economic modelling by McKinsey has estimated that comprehensive digital ID could unlock value worth between 3 and 13 per cent of GDP by 2030, through lower onboarding costs, less fraud and faster services. Treat that as the direction of the prize, not a number to bank. The realised Australian benefit, for now, is the 80 million transactions already running through the system.
This is where I would be looking if I were advising a private hospital group, offered as a hypothesis rather than a settled answer, because the rules are still moving and Digital ID complements rather than replaces clinical identification at the bedside.
The shared thread is the same one that benefits any business: confirm identity to a high standard while holding fewer documents, which is precisely the posture a health service under constant cyber pressure should want.
Applications to participate open on 30 November 2026. You do not have to wait to start, and there is a first-mover advantage for those who prepare. The testing pilot is open now: you can lodge a registration of interest with the System Administrator via the Digital ID System website and begin technical integration testing in the test environment.
The relying party path is three steps: register interest in testing, complete integration testing against the AGDIS Data Standards, then apply to the ACCC for approval to participate. The Regulator must be satisfied you meet the criteria, and approval can carry conditions. The accredited provider path adds a full accreditation stage in front of those three steps.
The long pole for either path is not the application. It is the cyber and privacy work. Both paths require a risk assessment covering cyber security and Digital ID fraud, and written management plans for prevention, detection and response. These are substantive documents, not box-ticking, and they should be owned and started now. One watch-item: the statutory review of the Digital ID Act lands on the same 30 November 2026 date, and the data standards and redress framework are still settling, so scope against current rules and expect to re-check before you lodge.
Deciding your role, standing up the cyber and privacy artefacts, and scoping an early application is exactly the kind of work I do with executive teams and boards. If you want a frank conversation about whether this is worth moving on now, book a call.
Book a callFrom 30 November 2026, accredited private sector entities can apply to the Digital ID Regulator (the ACCC) to participate in the Australian Government Digital ID System, as either a relying party or an accredited provider. A testing pilot is open before then through a registration of interest with the System Administrator.
A relying party verifies its customers or staff through an accredited provider and does not need to be accredited itself; it registers, tests, and applies for approval. An accredited provider issues identity, attribute or exchange services and must complete accreditation before seeking approval to participate. Most service businesses, including healthcare providers, will be relying parties.
No, and that is the point. A relying party receives a verified result from an accredited provider without collecting and storing the underlying identity documents, which reduces both onboarding friction and the data a breach could expose.
No. Participation is voluntary under the Digital ID Act 2024. A relying party cannot mandate a Digital ID and must keep an alternative verification method available.
An occasional brief, no more than once a month, for senior leaders in health, government and defence: field-tested frameworks, the thinking behind my client work, and first access to new tools and dispatches. No selling, no noise.