Private hospital groupSample
PDPA readiness across a multi-site hospital network
A hospital group needed to understand how patient data moved between sites, laboratories and partners before the Personal Data Protection Act's obligations applied.
The challenge
Patient information flowed between hospitals, outsourced laboratories, insurers and IT vendors. Nobody held a complete map, retention practices differed by site and data subject requests were handled informally.
Our approach
- 01Clinical walkthroughsWe followed patient journeys from admission to discharge across every site.
- 02Map and assessProcessing activities were recorded and risk-assessed, with special-category data flagged.
- 03Fix the flowsVendor contracts, transfer safeguards and retention rules were updated.
- 04OperationaliseRequests and breaches moved into tracked workflows with trained owners.
The solution
The group runs its privacy programme in ENKAYT Privacy, with vendors assessed in ENKAYT Vendor and a supporting DPO service from our team.
- ENKAYT Privacy
- ENKAYT Vendor
- PDPA No. 9 of 2022
- ISO 27799
Results
Sample- processing activities recorded
- 180+
- weeks from kickoff to operating programme
- 16
- of critical vendors assessed
- 100%
- Complete record of processing across all sites
- Consistent retention rules for clinical records
- Requests tracked against statutory timelines
“The mapping exercise alone changed how our clinicians think about patient data.”
Facing something similar?
Tell us where you are today. We'll show you what a comparable programme would look like for your organisation.