MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Health data is “special category of personal data” under the GDPR and enjoys extra protection: you may only process it if strict requirements are met, usually with explicit consent. Furthermore, medical professionals are bound by professional secrecy (regulated by law or by a code of conduct). If you engage support staff, establish their confidentiality contractually. Those who handle medical data carefully avoid exorbitant fines.
The discussion surrounding medical data brought the careful handling of it into sharp focus — but even before the pandemic, the Dutch Data Protection Authority (AP) was already paying extra attention to this. Nothing is more personal than our health, so anyone working in healthcare must handle it with care.
Protection of medical personal data
Health data is highly sensitive; the GDPR refers to it as special personal data, which organizations may only process if specific requirements are met. For example, a daycare center may only process health information about a child (risk of illness, vaccination status) with the explicit consent of the parents, must be able to demonstrate that consent, and may not share the information without consent; parents must also be able to withdraw their consent.
Anonymous data may be shared — for example, “80% of the children are vaccinated”. Please note: at 100% or 0%, there is no longer any anonymity, because then it is traceable for each child whether they have been vaccinated.
Duty of confidentiality and professional secrecy
Medical professionals have a duty of confidentiality: in principle, they may not disclose medical data to others. Statutory medical professional secrecy applies to, among others, nurses, physiotherapists, psychotherapists, healthcare psychologists, pharmacists, dentists, and doctors; for other professions (such as social workers), a code of professional conduct governs this.
If a dentist engages support staff, such as a secretary or financial assistant, they are not bound by a code of professional conduct or legal confidentiality. It is therefore important to contractually oblige them to maintain confidentiality.
Breaking professional secrecy
Professional secrecy may be breached only in limited cases: with the (fully informed) consent of the patient, or pursuant to a statutory provision (such as in the Public Health Act or the Funeral Services Act, or for disclosure to the health insurer). Furthermore, it may be done in the event of a conflict of duties, or for disclosure to directly involved parties or the patient's legal representative.
Frequently Asked Questions
Am I allowed to process health data?
Only under strict conditions, because it concerns special personal data. Usually, explicit, demonstrable consent is required, which the data subject must also be able to withdraw.
Does professional secrecy also apply to my support staff?
Not automatically. A secretary or financial employee is often not covered by statutory professional secrecy. Therefore, stipulate their confidentiality contractually.
May professional secrecy be breached?
Only in limited cases, such as with the informed consent of the patient, pursuant to a statutory provision, or in the event of a conflict of duties.
Properly regulating privacy in healthcare
Carelessness with medical data leads to heavy fines, as was the case at the Haga Hospital. The privacy lawyers at MKB Juristen review your collaboration and employment agreements via the ContractCheck. View our expertise in privacy and data protection or schedule an intake meeting .