Hospitals face significant challenges in protecting patient data

Insights
Hospitals face significant challenges in protecting patient data
Posted on: 14/01/2026

    Vietnam's health sector, especially hospitals, will face many difficulties in complying with the new provisions of the Law on Personal Data Protection 2025 (the Law on PDP) which takes effect from January 1, 2026. This confusion stems not only from the shift from traditional management systems to digitalized models, where data is easily exposed, leaked, or abused, but also from the important nature of the type of data that hospitals are collecting and holding.

     

     

    One of the biggest challenges hospitals face is the identification and processing of sensitive personal data under the PDP Law 2025. The law classifies personal data into two groups: basic and sensitive.

    Basic data includes common personal information such as full name, date of birth, address, phone number, which is commonly used in medical registration. Sensitive data is information associated with privacy, which, when infringed upon, will directly affect the legitimate interests of individuals, agencies or organizations. According to the Draft Decree guiding the Law on PDP 2025 (Draft Decree), most patient data falls into the category of sensitive data, from health status, biometric data, genetic characteristics, data on sex life or sexual orientation, a type of information that may appear in psychological counseling or related pathologies, and even the patient's geolocation through the mobile app.

    Embarrassment in collection and storage

    The collection of sensitive data requires explicit consent from the patient, the subject of the data. Specifically, according to Article 6 of the Draft Decree, consent must be expressed in writing, voice, message, email or through digital platforms with verification and proof mechanisms. Hospitals must also not default to consent or create misleading ambiguity and must clearly communicate that this is a special type of data when collecting sensitive data, and patients have the right to withdraw their "consent" at any time.

    However, many hospitals now still collect data in the traditional way: patients sign and tick registration forms without understanding what data is being collected and what is being used. As when a patient provides genetic test results to diagnose a genetic disease, the hospital must clearly explain that this is sensitive data and is used only for therapeutic purposes, not shared without permission.

    Embarrassment increases when storing data. The law requires hospitals to conduct a one-time personal data processing impact assessment (DPIA) for the entire operation, updated every 6 months or immediately if there is a change. The DPIA must include risk analysis, security measures such as encryption, data anonymization, and access decentralization. For sensitive data, the Draft Decree emphasizes the need for physical security measures for secure and technical storage devices such as encryption of transmitted data. The hospital must appoint a dedicated data protection department or staff, with a university degree and at least 2 years of experience, or outsource the service.

    In fact, many public hospitals in Vietnam still use outdated paper storage systems or software, which lack integration and lack security. A survey by the Ministry of Health in 2024 shows that only 40% of large hospitals have a fully digitized data management system, while small hospitals face difficulties in terms of budget and human resources[1].

    Moreover, for patients in vulnerable groups such as children under 7 years old, people who have lost their civil act capacity, the law requires consent from their legal representatives. This complicates the collection process, especially in the event of an emergency, where the hospital has to balance treatment and compliance with the law.

    Embarrassment in transferring data to stakeholders

    The transfer of personal data is a complex process and Vietnamese hospitals are embarrassed when it comes to complying with Article 17 of the Law on PDP 2025. The law stipulates that the transfer can only be carried out with the consent of the subject or in cases permitted by law, with the requirement to assess the impact of data transfer to a third party or cross-border data transfer.

    In healthcare, data transfer often occurs in situations such as transferring hospitals (from the lower line to the upper line), transferring (between provinces and cities), or sharing with partners such as health insurance companies, health insurance, and life insurance. According to the Draft Decree, the transfer must have a clear written agreement, stating the purpose, type of data, processing period, and protection responsibilities. For sensitive data such as health status, encryption and anonymization must be applied to reduce the risk of exposure.

    The first embarrassment in transferring data is determining when to consent. For example, when transferring patients from the Provincial General Hospital to Cho Ray Hospital (Ho Chi Minh City), data must be shared to ensure continued case handling. The Law on PDP allows transfer without consent if "the agreement of the data subject is carried out with the relevant authority in accordance with the law" or "in case of emergency", but the hospital must prove that this is a necessary case. However, many hospitals currently do not have a mechanism to record consent after the emergency period when the patient passes the emergency period, leading to the possibility of the risk of disputes with the patient.

    For insurance partners, the situation is even more complicated. Insurance companies often require medical record data to pay insurance premiums or assess the risk and medical history of the insured. According to regulations, the transfer to a third party must have a personal data transfer agreement and DPIA, stating that the recipient must not use the data for other purposes, as well as the purpose of the transfer in accordance with the industry of the transferee.

     

    Source: University Medical Center

     

    In fact, hospitals often share data via paper, email or insecure systems, lacking in assessing the risk of exposing or leaking patient data to the outside. In 2023, the disclosure of personal data of many pregnant women at Tu Du Hospital to a third party providing postpartum services[2] or the fact that a doctor in Ho Chi Minh City was administratively sanctioned for disclosing all patients' medical records online shows the complexity of transferring and disclosing patient data from the disease institute[3].

    Confusion about being exempt from the use of patients' personal data

    Article 19 of the Law on PDP 2025 stipulates a number of exceptions for the processing of personal data without the consent of the data subject. In particular, there are cases that hospitals can completely consider to conduct data collection, processing and transfer activities without the patient's consent.

    First, the case to protect life and health in urgent cases.

    In case of urgency for the life and health of the patient, the hospital may not need to ask for the patient's consent at all. As in the case of emergency referral, the hospital does not need the patient's consent to collect and transfer to another hospital. However, the hospital must pay attention to prove that this is an urgent case to treat the disease and save lives. Because if not, there is a possibility that the hospital will be sued by the patient if it does not preserve or prove this urgency.

    Secondly, implement the patient's agreement with relevant agencies, organizations and individuals in accordance with the law

    This is a case that the hospital can completely apply to transfer patient data to health and life insurance to perform the contract that the patient has signed with these agencies and organizations. At this time, the hospital does not need the patient's prior consent to transfer the data. However, in these cases, the competent authority requires the hospital to establish data monitoring and protection mechanisms to avoid the disclosure and leakage of sensitive patient information to the outside. 

    Thirdly, there are other cases in accordance with the provisions of specialized laws

    These other cases are quite broad, it can be cases in course research, in medical training. However, this data transfer is mandatory by specific specialized laws as another exception and exemption in obtaining the patient's consent during the processing and transfer of data to another party.

    The Law on PDP 2025 protects the legitimate interests of patients but also poses many embarrassments for medical facilities. To overcome these initial challenges, we believe that the hospital needs to implement specific plans from reviewing the collection, storage, processing and transfer of data to third parties. It is also very necessary to learn and consult experts who are knowledgeable about the law and techniques in this context to minimize the risks of information disclosure and leakage as well as being sued by patients in the coming time.