Instagram is under investigation over handling of children’s data
Instagram is being investigated by Ireland’s Data Protection Commissioner (DPC) over its handling of children’s personal data on the platform. […]
Since General Data Protection Regulation (GDPR) entered into force, the personal data protection has become more challenging to the Healthcare sector. Meaning that patient data must be managed with more of a holistic approach. Organizations must have certain procedures in place that can be acted upon immediately in order to meet the requirements. Starting with being more cautious with patient information, knowing where it is being stored and how it is being processed. This applies for both, public and private sector: hospitals and clinics, dental care, pharmacies, nursing homes, diagnostic laboratories, e-shops that sells pharmaceuticals, and every other company or organization that processes data concerning health.
The GDPR defines personal data processed in the Healthcare sector as “sensitive data”. Therefore, standards for its protection are much higher and GDPR mentions three special references to data concerning health:
The processing of mentioned forms of data is allowed under certain conditions only, which are:
However, according to the GDPR, Member States may maintain or introduce further conditions, including limitations in regard to processing personal data, like genetic data, biometric data or data concerning health. With the GDPR, data subjects gain more rights. For the Healthcare sector, the most important ones are the right to access that allows data subjects to access their health data that is processed also known as subject access requests.
The right to data portability allows data subjects to transmit their health data to any other healthcare provider more easily. The right to be forgotten – the most difficult one to operationalize. It allows data subjects to request for termination on health data processing and it’s deletion.
According to the Data Protection Act, the GDPR that Healthcare sector should have a Data Protection Officer (DPO) to achieve GDPR compliance, since sensitive data being processed on a large scale. Carrying out a Data Protection Impact Assessment (DPIA) helps to evaluate the origin, nature, particularity, and severity of a risk to the rights and freedoms of individuals that processing operations are likely to result.
The Healthcare sector has an obligation to comply with data protection laws by reporting security breaches as well as data breaches (within 72 hours) not only to the local data protection authority but also to individuals whose personal data might be compromised.
To maintain data security, clear, practical and effective procedures in the case of the breach should be thought through. Breach notification procedure, including detection and response capabilities, must be put in place by healthcare providers to protect patient data against data breaches. Therefore, training and fire drills should be done every once in a while, to keep the staff and the system ready.
In the case of a data breach that could expose patient information, fines can reach up to 20 mln € or 4% of the global annual turnover, whichever amount is higher. These fines are imposed by the Information Commissioner’s Office under the GDPR. The most recent breach in the Healthcare sector happened in Portuguese Hospital. The fine of 400 000€ was initially imposed for accessing patient data through false profiles. Read more about GDPR fines.
EU Member states may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State.
In order to avoid any breaches, organizations must implement compliance points mentioned above, including reviewing contracts – DPA (Data Processing Agreements). This is in addition to updating policies, procedures, documentation, and records of data processing activities in order to be ready for inspections, maintain compliance, and ensure data protection of patient information. Therefore, data processing activity records and data retention and deletion periods also should be in place.
Due to aging critical IT infrastructure and weak IT security practices, the Healthcare sector is one of the greatest targets for cyber-attacks. Meaning that technical security measures must be set in order to avoid unauthorized access to patient data, mishandling and loss of personal data kept in the server or cloud.
More on:
https://eur-lex.europa.eu/legal-content/EN/TXT/?qid=1543321123665&uri=CELEX:32016R0679
https://ico.org.uk/for-organisations/health
http://www.eu-patient.eu/globalassets/policy/data-protection/data-protection-guide-for-patients-organisations.pdf