Why is healthcare particularly vulnerable?
Health data falls under special categories of personal data (Art. 9 GDPR). Processing is prohibited unless a specific exception applies, such as:
- Explicit consent of the data subject (Art. 9(2)(a))
- Necessary for healthcare purposes (Art. 9(2)(h)) — the most commonly used basis in healthcare
- Public interest in public health (Art. 9(2)(i))
Additionally, sector-specific legislation and standards apply, such as information security standards (e.g. NEN 7510 in the Netherlands, ISO 27799 internationally).
The situation
A medium-sized care provider (home care, nursing home care and rehabilitation) with approximately 800 staff works with dozens of vendors with access to patient data:
- EHR vendor: the electronic health record system containing all medical data
- Pharmacy/medication system: medication overviews and prescriptions
- Laboratory: blood test results and diagnostics
- IT administrator: manages servers, workstations and network
- Payroll: employee data including sick leave records
- Video consultation platform: video calls with patients
Healthcare-specific challenges
Security certification
Vendors with access to health data must demonstrate appropriate security through certifications or equivalent measures. Tracking certificate validity is an ongoing task.
Enhanced DPA requirements
DPAs for health data processing must include additional provisions covering access logging, enhanced security measures, incident notification aligned with clinical procedures, and data deletion after the statutory retention period (20 years for medical records in the Netherlands).
DPIAs for new health technology
The healthcare sector innovates rapidly. Many new applications (telehealth, remote monitoring, AI-assisted diagnostics) require a DPIA due to large-scale processing of special category data.
The approach
Step 1: Vendor inventory by risk classification
- High risk: access to patient data
- Medium risk: access to employee data
- Low risk: no access to special category data
Step 2: Tailored DPAs
High-risk vendors receive DPAs with healthcare-specific provisions. Medium and low risk vendors receive standard or basic agreements.
Step 3: Evidence vault
Security certificates and audit reports are stored per vendor with expiry alerts.
Step 4: Processing register linked to the EHR
The processing register is extended to cover all processing via the electronic health record, linking vendors and sub-processors.
The result
- All vendors classified by risk level
- Tailored DPAs per risk category
- Security certificates centrally managed with automatic expiry alerts
- Processing register linked to vendors and agreements
- DPIAs for new health technology conducted in a structured way
- Audit-ready for health inspectorates and external auditors
Tips for healthcare organisations
- Classify vendors by data type, not just contract value
- Require security certification from vendors with access to patient data
- Conduct DPIAs before deploying new health technology
- Account for the 20-year retention period for medical records in DPAs
- Use DPAkit to centrally manage DPAs, certificates and the processing register