Patient privacy should be a priority for the hospital

Insights
Patient privacy should be a priority for the hospital
Posted on: 04/03/2026

    According to the Law on Personal Data Protection 2025 (Law on PDP), medical data is classified as sensitive personal data "associated with the privacy of individuals, when infringed upon, will directly affect legitimate rights and interests". This reflects the importance of protecting health records,  personal information of patients. In a healthcare setting, patient trust in information confidentiality is crucial. If patients suspect that their information has been disclosed or used unauthorized, they may lose trust, not cooperate fully with treatment, or be afraid to honestly declare sensitive matters.

     

    In a healthcare setting, patient trust in information confidentiality is crucial.

     

    IMH Singapore case

    On March 20, 2024, a patient at the Institute of Mental Health of Singapore (IMH) was waiting to be examined when he was identified by the research staff as the correct name and invited to participate in a medical study. The patient later complained, claiming that the doctor had disclosed his name and health status to the research staff without consent. The investigation determined that IMH doctors provided the research team with the names and appointments of some patients who were suitable for the study, and then the research staff used that information to find patients in the waiting room. The patient, when invited, refused to participate and immediately complained. The Personal Data Protection Commission of Singapore (PDPC) noted that IMH has posted notices at registration counters and pharmacies stating: "We may use your personal data to solicit you to participate in appropriate care programmes or to recruit you to participate in relevant scientific studies".[1]

    Singapore's environmental protection legislation requires the consent of individuals before using their personal data, except in exceptional circumstances. This case clarifies the role of explicit consent, implied consent, and default consent of data subjects. In terms of regulation, explicit consent requires the individual to actively express consent for a specific use. Meanwhile, the PDPC acknowledged that the patient did not provide explicit consent for the study, but the agency held that the patient had implied consent when continuing to visit and did not object after being reasonably informed. Specifically, IMH's public announcement years ago about the possibility of using personal data for studies is a "reasonable measure" to inform patients about this purpose. According to the PDPC, since the patient continues to provide the information and does not refuse when he or she has seen the notification, it can be considered that the patient has given permission to use the personal data for the study (implied consent). Therefore, PDPC concluded that IMH did not violate PDPA's obligation to obtain consent in this case. However, the PDPC notes that  a notified default consent is only considered valid if the organization has clearly communicated the manner and time limit for the individual to opt out before the organization uses the data. In the IMH case, although the patient can contact the hospital's DPO or respond directly, the PDPC believes that the existing measures still place too great a burden on the individual to understand the rejection mechanism. Therefore, IMH has not met the conditions to apply the default consent case; The PDPC does not consider the patient to have been "tacitly consented by default" simply by observing the general notice. Finally, the PDPC emphasizes that explicit consent is the best practice, especially with sensitive medical data. It also recommends that future IMHs collect specific consent in writing from patients for the study, rather than relying solely on implied consent.

    Comparison with Vietnam's Law on PDP

    The Law on PDP also lays the same foundation on the privacy and security of personal information. According to this Law, the collection and processing of medical information of individuals must be "with the consent of the subject" throughout the process, except for emergency cases specified in Clause 1, Article 19. This clause lists cases that do not require consent such as protecting the patient's life and health in an urgent situation or following the patient's agreement in accordance with the law. However, these situations only apply when absolutely necessary, such as a medical emergency or at the request of a competent authority, and do not extend to routine research activities. That means medical research is not an exception. Therefore, in order to use medical information for research purposes in conventional treatment, the hospital still needs to have the patient's valid written consent.

    The law also strictly stipulates the form of consent: it must be "clear, specific, and can be printed in writing (including electronic form)". It also states that "silence or non-response is not considered consent." This completely excludes the concept of implied or default consent as in the case mentioned above. Therefore, only if the patient actively signs the confirmation (or consent in writing electronically) when the purpose is explained is it considered valid consent. Thus, legally, the Vietnamese framework requires the medical facility to collect the explicit consent of the patient before using any health information for the study. This shows that Vietnamese law has stricter regulations on the protection of sensitive personal data, especially in the field of healthcare.

     

    Patient information needs to be protected at the highest level such as encryption at rest, internal access restrictions, access log monitoring, and regular security risk assessments.

     

    Recommendations for Vietnamese health facilities

    Stemming from the lessons learned from the IMH and the provisions of the Law on PDP, Vietnamese medical facilities should strengthen the mechanism to protect patient privacy with clear and effective plans to bring trust from patients.

    Firstly, transparency and clarity in the collection and processing of personal data

    Healthcare facilities should clearly communicate in the hospital's communication channels and at hospitals and treatment rooms about the purpose of collecting and using patient data, including invitations to participate in clinical studies and the use of personal information for treatment. All notices should be specific and easy to understand, and clearly state the patient's choices.

    Before using patients' personal information for research purposes, their own written consent must be obtained. The consent collection process should follow a well-reviewed and evaluated standard form such as a commitment letter, research declaration, or electronic tool with a check mark. Any changes in the research content should also be notified and consulted.

    Secondly, there are technical and legal measures to protect information security

    Patient information needs to be protected at the highest level such as encryption at rest, internal access restrictions, access log monitoring, and regular security risk assessments. Health information systems need to comply with the State's security standards and data protection regulations. In addition, it is necessary to clearly stipulate the form of handling when there is a violation against relevant individuals and organizations.

    Thirdly, always provide the patient's right of refusal

    Patients should be facilitated to readily refuse to provide personal information for an inappropriate purpose or withdraw their right to consent to the use of this information at. Healthcare organizations need to establish a public process for patient feedback (by email, phone, or in person) if they do not wish to provide information for the study. The right to refuse must be respected without causing trouble or interfering with the patient's other medical services.

    In conclusion, raising the legal and ethical awareness of healthcare workers, establishing transparency policies, gathering formal consents, and strengthening technical safeguards will help Vietnamese healthcare facilities ensure patient privacy even when conducting scientific research or conducting medical examinations. to treat common diseases. Applying these recommendations is not only to comply with the new legal framework on health care but also to strengthen patient trust and improve the quality of health care in Vietnam.

    Lawyer Nguyen Van Phuc

    HM&P Law Firm