Privacy and data protection

Healthcare and Privacy Legislation

Privacy in healthcare legally in order

Healthcare organizations process special categories of personal data and, in addition to the GDPR, must comply with healthcare-specific laws such as the WGBO and the Wabvpz. Our lawyers and in-house counsel help you demonstrably get this in order.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

What we do

The General Data Protection Regulation (GDPR) stipulates that healthcare institutions must comply with additional rules when processing personal data. In addition, specific legislation and regulations for the healthcare sector include extra rules regarding privacy. Examples of such laws include the Medical Treatment Agreement Act, the Act on Supplementary Provisions on the Processing of Personal Data in Healthcare, or the Act on General Provisions regarding the Citizen Service Number.

The processing of personal data within a healthcare institution or organization must be in order and comply with laws and regulations. Within our Privacy and Data Protection practice group, we can provide legal advice in this regard.

Questions regarding care and privacy? Please contact us.

Privacy and data protection in healthcare: the legal framework

This page is part of our Privacy and Data Protection. Within that main area of ​​expertise, the healthcare sector requires a specific approach. In addition to the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG), a layer of sectoral legislation applies in the healthcare sector that is stricter than the general rules. Under Article 9 of the GDPR, health data are considered special categories of personal data: processing such data is prohibited in principle, unless a specific exception applies. Therefore, for every processing activity, a healthcare organization must be able to identify both a legal basis (Article 6 of the GDPR) and an exception to the processing prohibition (Article 9 of the GDPR).

Our mixed teams of lawyers and in-house counsel are familiar with both privacy law and health law. Whether you are a university hospital, a mental healthcare institution, a healthcare group, or an independent GP or physiotherapist: from international corporations to the baker on the corner, we translate complex regulations into workable policy.

Medical professional secrecy and the WGBO

Medical professional secrecy is regulated in the Medical Treatment Agreement Act (WGBO), which is included in Book 7, Title 7, Section 5 of the Dutch Civil Code (Articles 7:446 to 7:468 BW). The healthcare provider's duty of confidentiality follows from Article 7:457 BW: without the patient's consent, no information or access to the file may be provided to anyone other than the patient. In addition, the WGBO regulates, among other things, the duty to maintain a file (Article 7:454 BW), the patient's right of access (Article 7:456 BW), and the right to destruction of data (Article 7:455 BW).

Medical professional secrecy exists alongside the GDPR and is therefore not amended. In cases of overlap, professional secrecy takes precedence as a lex specialis; the GDPR further specifies the rules regarding lawful processing. We advise healthcare professionals and healthcare organizations on the scope of professional secrecy, on when breaching is permitted (consent, statutory obligation, or conflict of duties), and on the position of locum tenens and directly involved healthcare professionals.

Sharing health data with third parties

The exchange of patient data is a common bottleneck. The general rule is that healthcare providers may share data among themselves insofar as this is necessary for the execution of their own treatment agreement with the patient; professional secrecy does not apply to persons directly involved in the treatment (Article 7:457 paragraph 2 of the Dutch Civil Code). If information is shared with parties outside the care provider, explicit consent from the patient is required in principle, unless there is a statutory obligation (for example, reporting an infectious disease). Furthermore, for electronic exchange, the Act on Supplementary Provisions on the Processing of Personal Data in Healthcare (Wabvpz) sets additional requirements, including specified consent for making data available via an electronic exchange system and the use of the citizen service number (BSN) pursuant to the Act on Supplementary Provisions on the Processing of Personal Data in Healthcare and the Act on General Provisions on the Citizen Service Number. We assess partnerships, integrated care systems, and registries against these rules and record agreements.

Obligations for healthcare organizations

The GDPR imposes concrete obligations on healthcare organizations, which we implement in practice:

  • Data Protection Officer (DPO) – mandatory for large-scale processing of health data, which in practice applies to hospitals, pharmacies, healthcare groups, and GP out-of-hours services, among others. Read more about the Data Protection Officer (DPO).
  • DPIA – for high-risk processing, a Data Protection Impact Assessment is mandatory. See our page on the DPIA.
  • Data Processing Agreements – we establish the appropriate agreements with ICT suppliers, EHR providers, and other processors.
  • Policies and protocols – privacy policy, authorization management, and retention periods.
  • Data breaches – setting up the reporting and registration process. See data breaches.

With a privacy audit , we map out where your organization stands.

Supervision: Dutch Data Protection Authority and IGJ

The Dutch Data Protection Authority (AP) monitors compliance with the GDPR and the UAVG; the AP can impose substantial fines for violations. In the healthcare sector, the Health and Youth Care Inspectorate (IGJ) additionally supervises quality and safety, including information security. We assist healthcare organizations in supervisory investigations, enforcement, and data breaches that may need to be reported, and act as counsel in objection and appeal proceedings where necessary.

New developments: electronic exchange and AI

The digitalization of healthcare brings new obligations. The Healthcare Electronic Data Exchange Act (Wegiz) mandates a phased implementation of standardized, secure electronic exchange between healthcare providers. In addition, AI applications are being deployed increasingly often for diagnosis and treatment support; in this regard, alongside the GDPR, the European AI Regulation and, for medical devices, the Medical Device Regulation (MDR) are relevant. We monitor these developments and advise on a future-proof setup.

Frequently asked questions about healthcare and privacy legislation

Does medical confidentiality take precedence over the GDPR?

Medical professional secrecy under the WGBO (Article 7:457 of the Dutch Civil Code) continues to apply alongside the GDPR and is not amended by the GDPR. In practice, both regimes complement each other; in the event of overlap, professional secrecy takes precedence as a special provision.

When is a Data Protection Officer mandatory in healthcare?

A Data Protection Officer is mandatory when special categories of personal data are processed on a large scale. As a rule, this applies to hospitals, pharmacies, healthcare groups, and GP out-of-hours services, among others.

May I share patient data with another healthcare provider?

With healthcare providers directly involved in the treatment, this is permitted to the extent necessary for your own treatment agreement. For parts beyond that, explicit consent is in principle required, or a legal basis.

Questions about healthcare and privacy legislation?

Our lawyers and in-house counsel help healthcare organizations of all sizes to demonstrably get their data processing in order. Privacy and data protection is our home base; for the healthcare sector, we provide tailored advice. Please feel free to contact us.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law · Lawyer

In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.

What we do for you

We combine privacy law and health law in practical advice.

  • Drafting privacy policy, protocols, and authorization management
  • Data processing agreements with EHR and ICT suppliers
  • FG appointment and DPIA guidance
  • Advice on medical confidentiality and data sharing
  • Guidance on data breaches and supervisory investigations

Risks of insufficient compliance

Careless handling of health data directly affects patient privacy and trust in your organization. The legal and business risks are substantial.

  • Fines from the Dutch Data Protection Authority for violations of the GDPR
  • Violation of medical confidentiality and disciplinary consequences
  • Measures by the IGJ in case of inadequate information security
  • Reputational damage and loss of patient trust following a data breach
  • Liability for unlawful data processing

Our approach

We begin with a pragmatic analysis of your processing activities and assess them against both the GDPR and healthcare-specific laws. We then translate this into workable policies, binding agreements, and clear protocols tailored to the scale of your organization. Our mixed teams of lawyers and in-house counsel liaise with healthcare and employment law where necessary.

This is how we work

From inventory to a demonstrably compliant organization.

01

Intake

We discuss your organization, your processing activities, and your question, and review existing agreements and protocols.

02

Analysis

We assess your situation against the GDPR, the UAVG, and healthcare laws such as the WGBO and the Wabvpz, and map out the legal bases and risks.

03

Execution

We draft policies, data processing agreements, and protocols, and guide the appointment of the DPO and DPIA.

04

Assistance

We assist you with data breaches and supervision by the Dutch Data Protection Authority or the IGJ.

Specialists for entrepreneurs

We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.

Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.

Frequently Asked Questions

Answers to questions that healthcare organizations often ask us.

When is legal advice advisable?

Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.

Can MKB Juristen also help if there is already a conflict?

Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.

How much does specialist legal advice cost?

Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.

Can I have a no-obligation consultation first?

Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.

Is privacy in healthcare legally in order?

Our lawyers and in-house counsel are happy to assist you. Please feel free to contact us.

Contact us

Contact us

Leave your details. We will contact you to briefly discuss your situation.

Contact us

Jaime Boogaers

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation