Rxflow

eScript compliance guide

The Complete Guide to eScript Compliance in Australia

Electronic prescribing in Australia is not a single feature you bolt onto your software. It's a regulated, multi-agency, multi-system infrastructure with strict conformance requirements, external approval queues, and ongoing compliance obligations. This guide covers every step from HI Service registration to ADHA conformance to state-based monitoring.

· 15 min read

Section 01

How Electronic Prescribing Works in Australia

Electronic prescribing in Australia isn't simply digitising a paper script. It's a federally regulated system that securely connects prescribing software, a national delivery infrastructure, patients, and dispensing pharmacies through a chain of cryptographically verified transactions.

At the centre of this system is the National Prescription Delivery Service (NPDS), operated by Fred IT Group via the eRx Script Exchange under contract with the Australian Government. The NPDS processes nearly 300 million prescriptions per year and is the sole infrastructure through which electronic prescriptions are legally transmitted in Australia.

The end-to-end flow works as follows:

  1. Script createdPrescriber generates an eScript using conformant software
  2. Sent to NPDSEncrypted and securely transmitted to the national delivery service
  3. Token deliveredPatient receives a QR code via SMS or email
  4. Pharmacy fillsScans the token, retrieves the script from NPDS, dispenses

Every system that touches the prescription (the prescribing software, the delivery service, and the dispensing software) must be independently conformant and listed on the ADHA's register. This isn't optional. An electronic prescription generated by non-conformant software is not legally valid.

Section 02

The Agencies and Systems You'll Deal With

One of the most underestimated aspects of eScript compliance is the sheer number of separate government bodies, infrastructure operators, and commercial providers involved. Each has its own processes, timelines, and queues, and you'll need to coordinate across all of them.

OrganisationRole in ePrescribing
Australian Digital Health Agency (ADHA)The governing authority. Sets conformance standards, publishes the Technical Framework (Solution Architecture, Conformance Profile, Assessment Scheme), manages the conformance assessment process, and maintains the public Conformance Register of approved software.
Services AustraliaAdministers PBS claim-for-payment systems. Issues NASH certificates through PRODA/HPOS. Manages Healthcare Identifier registration (HPI-O, HPI-I, IHI). Processes are bureaucratic and queue-dependent, so factor in wait times.
Fred IT Group / eRx Script ExchangeOperates the NPDS under government contract. Conducts the observed conformance assessment sessions. They are the gatekeeper for your software going live, and their assessment capacity directly impacts your timeline.
MIMS AustraliaCommercial provider of the standard medication database used across Australian healthcare. Not required for ADHA conformance, but widely used for drug information, interaction checking, and dosage validation. Paid subscription with monthly updates.
State Health DepartmentsEach state operates its own Real-Time Prescription Monitoring (RTPM) system with its own compliance requirements and monitored medicine lists. The National Data Exchange (NDE), built by Fred IT, provides a centralised data transport layer, but state-specific regulatory logic still applies.
Section 03

Healthcare Identifiers (HI) Service Conformance

This is where everything begins, and where many organisations underestimate the complexity involved.

Before you can pursue ePrescribing conformance, your software must first be independently conformant with the Healthcare Identifier (HI) Service. This is a separate conformance process, assessed and managed by the ADHA, and it is a hard prerequisite. There is no way to skip, fast-track, or work around it.

The HI Service is Australia's national infrastructure for uniquely identifying every patient, practitioner, and healthcare organisation in the system. It provides three identifiers that are foundational to electronic prescribing:

IHI

Individual Healthcare Identifier

A unique 16-digit identifier for every patient in Australia. Your software must validate a patient's IHI using their Medicare number and demographics before any eScript can be created. An eScript without a validated IHI is not valid. This single requirement is the reason HI conformance exists as a prerequisite.

HPI-I

Provider Identifier: Individual

Uniquely identifies each healthcare practitioner. Every prescription must be attributed to a specific prescriber via their HPI-I. Your software needs to look up and validate practitioner identifiers and maintain the linkage throughout the prescribing workflow.

HPI-O

Provider Identifier: Organisation

Uniquely identifies your clinic, pharmacy, or healthcare organisation. It's required for obtaining your NASH certificate, connecting to the NPDS, and participating in any national digital health service.

The process: getting HI Service conformant

This is a multi-step process that involves both organisational registration and technical software development. Both tracks run in parallel, but both must be complete before you can move to ePrescribing.

  1. Register your organisation with the HI Service

    Apply for an HPI-O through PRODA/HPOS. You'll need to designate a Responsible Officer (RO) — someone with authority to act on behalf of the organisation — and an Organisation Maintenance Officer (OMO) who handles day-to-day administration. This is a bureaucratic process through Services Australia, not a technical one. Allow time for processing and potential back-and-forth on documentation.

  2. Obtain your NASH certificate

    The National Authentication Service for Health (NASH) certificate is your organisation's cryptographic credential for accessing national digital health systems. Your OMO requests it through HPOS, receives a Personal Identification Code (PIC) via SMS, and downloads the certificate. The download link expires after 30 days. Your IT team or software vendor then installs it. The certificate must be renewed before expiry — if it lapses, your connection to national systems stops working immediately.

  3. Build the HI Service integration

    This is the development work. Your software must implement real-time lookups against the HI Service API to validate IHIs using patient demographics (name, date of birth, sex, Medicare number), resolve HPI-Is for practitioners, and verify HPI-Os for organisations. You need to handle every response scenario: successful validation, no match found, deceased or retired flags, and multiple matches requiring disambiguation.

  4. Pass HI Service conformance assessment

    Once built, your software goes through the ADHA's conformance process specifically for the HI Service: self-assessment, documentation, and verification by the ADHA. You must pass this before you can even begin ePrescribing conformance.

Estimated total: 2–4 months

Section 04

IHI Validation in Practice

Understanding how IHI validation works at a practical level is critical, because this is the single most important integration in the entire ePrescribing chain. Every electronic prescription starts here.

When a practitioner is ready to prescribe electronically, your software must first validate the patient's identity against the national HI Service, in real time, during the clinical workflow:

  1. Collect detailsName, DOB, sex, Medicare number, address
  2. Call HI ServiceAPI request with patient demographics
  3. IHI returnedUnique 16-digit identifier validated

Example · patient IHI lookup

Full name
Jane Mitchell
Date of birth
12/03/1988
Medicare no.
2951 48371 6
IHI (validated)
8003 6080 1234 5678

Your software must handle all three possible outcomes from the HI Service:

  • IHI validated Patient is verified. The eScript can proceed.
  • IHI not found Details don't match the national record. Cannot prescribe electronically.
  • Deceased / retired IHI The identifier is no longer active. Prescription blocked.
Section 05

eRx Integration & ADHA Conformance Process

With HI Service conformance behind you, you can build the actual ePrescribing capability and pursue formal ADHA conformance. This is the longest, most complex, and most resource-intensive phase of the entire process.

What you're building

Your software must integrate with the NPDS via the eRx Script Exchange to create, transmit, and manage electronic prescriptions. This includes prescription creation workflows, secure NPDS communication protocols, token generation and delivery (QR codes, SMS, email), prescription status tracking, and error handling for transmission failures. You must also register your organisation with the eRx Script Exchange and configure Electronic Transfer of Prescriptions (ETP) in your software before any live testing can begin.

The conformance process

The ADHA publishes a detailed Technical Framework (currently v3.3) made up of three documents: the Solution Architecture (how all components connect), the Conformance Profile (every requirement your software must meet), and the Conformance Assessment Scheme (how you'll be tested). These are your blueprint. Study them thoroughly before writing a line of code.

  1. Study the Technical Framework documents

    Download the full ADHA Electronic Prescribing Technical Framework package. Map every requirement in the Conformance Profile to your software architecture and identify the gaps. The Conformance Profile is dense, and missed requirements surface during assessment, causing costly rework.

    2–4 weeks

  2. Core ePrescribing build

    The major development effort: prescription creation, NPDS/eRx integration, token generation (QR codes, SMS/email delivery), secure transmission protocols, prescription status management, error handling, retry logic, and the full prescribing workflow within your clinical software. Every interaction must comply with the Conformance Profile.

    4–8 months depending on team size and starting point

  3. Self-assessment: Conformance Test Specification (CTS)

    The CTS is a detailed self-assessment document published by the ADHA. You work through every test case, execute them against your software, record the results with evidence, and compile the full submission. Incomplete or poorly documented CTS submissions get rejected and sent back, adding weeks to your timeline.

    1–2 months

  4. Submit to the NPDS Provider (Fred IT / eRx)

    Your completed CTS is submitted to the NPDS Provider for review. They assess the quality and completeness of your submission before scheduling an observed assessment session. Gaps, missing evidence, or failed test cases are returned for remediation.

    2–6 weeks (submission review) + queue wait for an assessment slot

  5. Observed conformance assessment

    The live examination. The NPDS Provider watches you run through test cases in real time, verifies your CTS results, and validates that your software meets every requirement in the Conformance Profile. They will probe edge cases, test failure scenarios, and may request additional evidence. If issues are found, you'll need to remediate and potentially rebook an assessment slot.

    20+ business days (assessment). Plan for 2–4 months total

  6. Vendor declaration & Conformance Register listing

    After passing the observed assessment, you complete the Electronic Prescribing Conformance Vendor Declaration form. The ADHA notifies Services Australia, the NPDS operator, and other infrastructure operators, and your software is published on the Electronic Prescribing Conformance Register. Only at this point can your software issue legally valid electronic prescriptions.

    Conformance achieved. You're live.

Section 06

State-Based Real-Time Prescription Monitoring

On top of national ePrescribing conformance, your software must also integrate with Real-Time Prescription Monitoring (RTPM) systems: state-operated databases that track the prescribing and dispensing of high-risk medicines (opioids, benzodiazepines, sedatives, and stimulants) in real time.

This is directly relevant to cannabis clinics. Prescribers must check the relevant RTPM system before writing a prescription for any monitored medicine. In most states this is now mandatory, and failure to check carries significant financial penalties.

Victoria

SafeScript

Live since 2019. Mandatory since April 2020. Must check before prescribing or dispensing any monitored medicine.

Mandatory · 100 penalty units
New South Wales

SafeScript NSW

Launched May 2022. Real-time prescription history access for prescribers and pharmacists. Use is strongly recommended but not currently enforced by law.

Recommended · not yet mandatory
Queensland

QScript

Real-time monitoring for controlled substances prescribed and dispensed in Queensland.

Mandatory
Western Australia

ScriptCheckWA

Launched March 2023. Monitors Schedule 8 medicines.

Mandatory
Northern Territory

NTScript

Launched March 2022. Real-time monitoring active.

Operational
South Australia

ScriptCheck SA

Real-time monitoring for controlled substances.

Operational
ACT

Local monitoring

Non-mandatory local prescription monitoring.

Non-mandatory
Tasmania

Local monitoring

Non-mandatory local prescription monitoring.

Non-mandatory
Section 07

MIMS Integration

MIMS (Monthly Index of Medical Specialities) is the standard medication database used across Australian healthcare. While it is not a formal requirement of the ADHA ePrescribing Conformance Profile, most prescribing software integrates with it for clinical safety:

  • Drug information lookup: dosage, administration, indications
  • Interaction and contraindication checking: flagging dangerous combinations in real time
  • Dosage validation: ensuring prescribed quantities are within safe ranges
  • Product identification and mapping: linking branded and generic products

MIMS is a commercial, licensed product with an ongoing subscription fee, updated monthly. You can technically achieve ePrescribing conformance without it, but running a prescribing platform without a drug reference database would be a significant clinical risk.

Section 08

The Full Picture: Timeline & Checklist

Here is the realistic end-to-end timeline for building eScript compliance into your software from scratch, assuming a dedicated development team, no major technical blockers, and normal processing times from government agencies.

  1. HI Service2–4 mo
  2. Core build4–8 mo
  3. Self-test1–2 mo
  4. Submit + queue1–2 mo
  5. Assessment1–2 mo
  6. Live✓

Realistic total: 12–18+ months from start to live ePrescribing

Milestone breakdown

MilestoneWhat's involvedDuration
HI Service ConformanceHPI-O registration, NASH certificate, IHI/HPI-I/HPI-O validation build, HI conformance testing with ADHA2–4 months
Technical Framework ReviewStudy ADHA Solution Architecture, Conformance Profile, Assessment Scheme2–4 weeks
Core ePrescribing BuildPrescription creation, NPDS integration, eRx connection, token generation, secure transmission4–8 months
RTPM IntegrationVia eRx/NDE for data transport, plus state-specific compliance logic (can run in parallel with the core build)2–4 months
MIMS IntegrationLicence agreement, medication database integration, interaction checking1–2 months
Self-Assessment (CTS)Complete all test cases, document results, compile evidence1–2 months
CTS Submission + QueueSubmit to NPDS Provider, review, queue for assessment slot1–2 months
Observed AssessmentLive assessment, ADHA processing, potential rework1–2 months
Registration & Go-LiveVendor Declaration, Conformance Register listing, production rollout, stabilisation1–2 months

Complete requirements checklist

  • HPI-O Registration · Organisation registered with the Healthcare Identifiers Service via PRODA/HPOS
  • NASH Certificate · Issued by Services Australia, installed, renewal tracked
  • HI Service Conformance · Software conformant for IHI, HPI-I and HPI-O validation (ADHA assessed)
  • eRx Script Exchange Registration · Organisation registered, ETP configured in software
  • NPDS Integration · Software connected to the National Prescription Delivery Service
  • ePrescribing Conformance · Software listed on the ADHA Electronic Prescribing Conformance Register
  • RTPM Integration · Connected via eRx/NDE with state-specific compliance logic for each state you operate in
  • MIMS Licence & Integration (recommended) · Medication database for clinical safety, not required for conformance
  • Privacy Act Compliance · Healthcare-grade data handling, encryption, access controls, audit logging

Official sources & documentation