Skip to main content

National Authentication Service for Health (NASH)

NASH SHA-1 to SHA-2 transition update

More than 70% of all NASH PKI certificates have transitioned to SHA-2. Sites with SHA-2 compatible software are now able to revoke their SHA-1 certificate and upgrade to a SHA-2. See our guide to checking your certificate type in HPOS.

SHA-1 to SHA-2 transition

NASH SHA-2 certificates are available in Healthcare Provider Online Services (HPOS) to request and download. All healthcare provider organisations must transition to NASH SHA-2 by 31 December 2022 to meet Australian Government cyber security requirements.

What NASH certificate type do I have?

To manage a NASH PKI certificate, an Organisation Maintenance Officer (OMO) needs to log in to their individual PRODA account, then: 

  1. Select Go to service on the HPOS tile.You may need to complete the linking process to proceed.Proceed as individual only
  2. Select My programs. 
  3. Select Healthcare Identifiers and My Health Record tile.
  4. Select Healthcare Identifiers - Manage existing records. 
  5. Select My organisation details.Note: If connected to multiple organisations you will first need to select the required organisation record.
  6. Select the Certificates tab. On this page you will be able to see what certificates have been requested for your organisation, including the Certificate Type and Expiry Date. 

If you have a NASH SHA-1 certificate and your software product is compatible with NASH SHA-2, follow the guide to revoke your NASH SHA-1 and upgrade to a SHA-2 (PDF, 1.76 MB)

How to revoke your NASH SHA-1 and upgrade to SHA-2

Follow these steps if your organisation has a software product compatible with NASH SHA-2 and you are ready to upgrade from your SHA-1 certificate. 

To revoke your NASH SHA-1 certificate and upgrade to SHA-2, an Organisational Maintenance Officer (OMO) needs to log in to their individual PRODA account. 

  1. Select Go to service on the HPOS tile. 
    You may need to complete the linking process to proceed.
    Proceed as individual only
  2. Select My programs.
  3. Select Healthcare Identifiers and My Health Record.
  4. Select Healthcare Identifiers - Manage existing records.
  5. Select My organisation details.
    Note: If connected to multiple organisations you will first need to select the required organisation record.
  6. Select the Certificates tab. 
  7. Under the Action columns click the Revoke hyperlink next to the NASH SHA-1 certificate you wish to revoke.
  8. You should get a warning notification. To continue read the notification and click OK.
  9. Complete the form and select your reason for revocation as ‘transitioning to a NASH SHA-2 Certificate’.
  10. Tick the Terms and Conditions box and click Save changes.
  11. Click the Submit button.

Once Service Australia have processed the revocation request, the OMO will be advised that they can now request a NASH SHA-2 certificate, follow the guide to request or renew your NASH PKI certificate (PDF, 1.8 MB).

    Not ready to transition to SHA-2?

    Sites that require a new NASH SHA-1 certificate after 7 May 2022 (because they have not yet updated to SHA-2-ready software) will be required to submit their plans to update to SHA-2-ready software and obtain approval to be issued with an interim NASH SHA-1 certificate.

    All sites must be using NASH SHA-2 certificates by 31 December 2022 to comply with Australian Government cyber security requirements.

    What is NASH?

    Introduced in 2012, NASH is a Public Key Infrastructure (PKI) solution used to access digital health services such as:

    • Electronic prescribing
    • My Health Record
    • Secure messaging
    • Healthcare Identifiers (HI) Service

    NASH is used by healthcare provider organisations and supporting organisations to:

    • authenticate and securely access digital health services
    • digitally sign documents and other transactions
    • encrypt health information for secure exchange
    Diagram: National Authentication Service for Health

     

    NASH SHA-2 Readiness Register

    The Agency has developed a register so that healthcare organisations can check whether their existing software product and version are SHA-2 ready. Before logging into HPOS to request a new NASH certificate, check the register below to see if your software product is SHA-2 ready.

    Last updated: 31 August 2022

    How to request or renew a NASH PKI certificate

    To request or renew a NASH PKI certificate, an Organisation Maintenance Officer (OMO) needs to log on to their individual PRODA account, then: 

    1. Select Go to service on the HPOS tile.
      You may need to complete the linking process to proceed.
      Proceed as individual only
    2. Select  My programs
    3. Select Healthcare Identifiers and My Health Record tile.
    4. Select Healthcare Identifiers - Manage existing records
    5. Select My organisation details.
      Note: If connected to multiple organisations you will first need to select the required organisation record.
    6. Select the Certificates tab. 
    7. If your certificate has not expired click Renew, otherwise select Request a NASH PKI certificate from the task list.
    8. Select your software product version from the first drop down list. This list contains software product versions that are SHA-2 ready. If you cannot locate your software from the drop down list, please select the most appropriate reason from the second drop down list:
      • I don’t know my product: if you are unsure of what software product or version is used in your organisation.
      • My product is not on the list: if your product version is not listed as SHA-2 ready.
      • I have multiple products: if your organisation has multiple products that require a NASH certificate, select this option to proceed.
      • I wish to select my SHA level explicitly: only when you have been advised by your software developer or you are certain which SHA level you need.
    9. Enter a mobile number. When the certificate is ready to download you will receive a text message to the mobile number provided.
    10. Tick the check box to confirm you have read and understood the terms and conditions. 
    11. Save changes and submit.
    12. Once you have received a text message, your certificate is ready to download. Log into HPOS to download the certificate. The PIC is used during the installing of the certificate.
    13. Import your NASH certificate into your software. (Check software provider website for further instructions) 

    Additional steps that may be required

    Your software provider may advise that additional files must be downloaded and installed when you renew or request a new certificate. These may have already been installed by your software provider. If your software provider has advised you to install these additional files, please refer to their product instructions or guides.

    The additional files are available on the Certificates Australia website.

    • For a NASH SHA-1 certificate, download and install SHA-1 Root CA Certificate and SHA-1 OCA Certificate
    • For a NASH SHA-2 certificate, download and install SHA-2 Root CA Certificate and SHA-2 OCA Certificate

    For assistance with HPOS or requesting a NASH PKI certificate, please contact eBusiness Service Centre.

     

    Chat