Vietnam's health sector has implemented digitalization in the management and operation of electronic medical records, online health insurance payments, patient identification with chip-based citizen identification cards, and even the application of AI in diagnosing and monitoring patient health. This leads to medical examination and treatment facilities ("hospitals") collecting and processing more and more personal data of patients. However, compliance with data security and privacy in this field in Vietnam has not been given proper attention.

Medical examination and treatment facilities collecting and processing more and more personal data of patients
Biometric data is being widely used by hospitals
According to the provisions of the Law on Personal Data Protection 2025 ("Law on PDP"), Biometric data is data about a person's physical attributes, unique and stable biological characteristics to identify that person[1]. Easily recognizable biometric data such as fingerprints, eyenails, facial images,... Unlike conventional identifiers, biometric data is unique and cannot be replaced. In other words, when biometric data is exposed, individuals cannot be "re-issued" or create new data to replace them such as phone numbers and passwords,... Therefore, world law and even Vietnam consider this as one of the groups of data that needs to be protected at the strictest level.
In practice, biometric data is applied in many stages of medical examination and treatment activities, from the reception stage to patient identification such as authentication with chip-attached citizen ID, facial recognition to monitoring and treatment through CT image analysis, etc MRI contains the patient's biological characteristics or serves to manage and control personnel entering and exiting restricted areas, storing and processing electronic medical records containing biometric data. These activities are being implemented in many hospitals in Vietnam such as Dong Da General Hospital and Xanh Pon General Hospital (Hanoi) that have piloted self-service kiosks using chip-attached citizen IDs and facial recognition to register and pay hospital[2] fees. This application helps to identify patients more accurately, shorten waiting times and reduce administrative procedures, but at the same time sets very strict security and legal compliance requirements.
How is the law regulated?
Due to the sensitive nature of biometric data, in addition to the basic obligations that organizations collecting and processing personal data must comply with such as ensuring the rights of personal data subjects, implementing appropriate management and technical measures to protect personal data, etc. The Law on PDP requires agencies, organizations and individuals that collect and process biometric data to (i) take physical security measures for their biometric data storage and transmission devices; (ii) restrict access to biometric data; (iii) have a monitoring system to prevent and detect acts of infringement of biometric data; (iv) comply with relevant laws and international standards. In case the processing of biometric data causes damage to the personal data subject, the organization or individual collecting and processing the biometric data must notify the personal data subject. Therefore, in the case of hospitals, when collecting or processing biometric data, they must apply a comprehensive system of protection measures at both physical and technical levels. This includes hospitals having to ensure the safety of data storage and transmission devices such as servers, kiosk devices, biometric scanners,... Avoid unauthorized access or theft of the device. In addition, hospitals need to limit access to biometric data, allowing only individuals with related duties to access this data. At the same time, hospitals must establish a continuous monitoring and monitoring system to detect early and prevent data intrusion, theft or leakage. All these measures must fully comply with the law and in accordance with international standards in the field of data security. Therefore, to ensure compliance, hospitals need to actively review, update and comply with legal regulations related to personal data protection, especially the new provisions in the Law on PDP.
In the event that the collection or processing of biometric data causes damage to the person having the data, the hospital must proactively notify them. This means that if biometric data is leaked, illegally accessed or misused, affecting the patient's rights, the hospital must promptly inform them so that they know in order to proactively prevent, change personal security measures or take necessary steps to protect their rights. This regulation aims to ensure transparency and accountability in the processing of the most sensitive types of data by individuals. However, at present, the law on PDP does not specify the form of notification, what the content of the notification must include, as well as the time limit for notifying. Therefore, in fact, hospitals need to proactively build internal processes to ensure that notifications are fully and promptly implemented when incidents related to biometric data occur.

Hospitals need to proactively apply a number of practical measures to ensure compliance with the law as well as minimize risks in operation.
What are the recommendations for hospitals?
From considering biometric data as sensitive personal data under the Law on PDP, hospitals need to proactively apply a number of practical measures to ensure compliance with the law as well as minimize risks in operation.
First, build an internal data governance framework
It is very important to implement the process of collecting and processing sensitive personal data such as biometric data, which clarifies the purpose, scope and responsibilities, and ensures the principle of only collecting the right – sufficient – necessary information.
Second, strengthen technical security
Biometric data should be encrypted and stored in a safe, highly secure area to limit the risk of unauthorized access.
Thirdly, note the signing of agreements on the security and processing of personal data with technology solution providers
Most of the technology solutions for management in hospitals are mainly provided by information technology businesses. Therefore, hospitals need to pay attention to asking service providers to commit to agreements on the handling of personal data, security responsibilities and how to handle incidents related to personal data.
Fourth, be transparent with patients and train staff to properly implement the process of protecting personal data
Hospitals need to clearly inform patients about the purpose of use of their biometric data and the scope of the data being processed. At the same time, hospital staff need to be trained and trained periodically to raise awareness and strictly comply with measures and procedures to protect personal data during the performance of their duties.
In conclusion, biometric data plays a particularly important role in the digital transformation process of the healthcare industry, helping to accurately identify patients, and improve the quality of medical examination and treatment. However, it is the sensitivity and irreplaceability of this type of data that makes protection and safety management a mandatory requirement rather than just an option. Full compliance with the law on biometric data not only helps hospitals avoid legal, reputational and information security risks, but is also a key factor in building patient trust in the digitized environment of medical data. Only when data is properly protected can hospitals effectively exploit new technologies, optimize operations and develop sustainably in the digital era.
Lawyer Nguyen Ngoc Tra My
HM&P Law Firm
Read more: Sử dụng dữ liệu sinh trắc học trong khám chữa bệnh - Cần bảo mật ở mức cao nhất
[1] Clause 2, Article 31 of the Law on PDP
[2] https://dantri.com.vn/suc-khoe/ha-noi-thi-diem-kham-chua-benh-su-dung-sinh-trac-hoc-20240530150255665.htm?utm_source=chatgpt.com, last accessed on 30/11/2025.
