We are Guardians of Patient Privacy
What to do when a data breach happens (March 2025)
In a healthcare environment like Mediclinic, the protection of personal data and sensitive health data is paramount. Like adverse events in a clinical context or security incidents in ICT, events or incidents may occur when handling personal data. Such incidents are called “data breach” or “personal data breach”. According to UAE Federal Law No. 45 of 2021 (Personal Data Protection Law) and to DOH and DHA regulations, data breach incidents need to be managed and notified to the internal Data Protection Officer.
How to identify a data breach?
A data breach (or personal data breach) is a breach of security or a non-compliance with security measures, leading to Personal Data being stolen or lost, Personal Data is corrupted or altered unlawfully or Personal Data is disclosed to or accessed by unauthorised persons.
Examples:
- An employee accidentally sends an email containing a patient's medical report to the wrong recipient outside of Mediclinic.
- A computer system storing patient records crashes, resulting in the loss of access to crucial patient information for several days. During this time, medical staff cannot retrieve necessary data for patient care.
- During a data entry process, a patient’s medical record is altered by entering incorrect treatment dates or uploaded reports of another patient.
How to notify a data breach?
When a data breach occurs, it’s crucial to notify the right people immediately to ensure swift action.
- Inform your line or duty manager.
- Send an email to the Data Protection Officer (DPO) at dataprivacy@mediclinic.ae.
- If the breach affects any ICT system or device, reach out to the ICT Service Desk by phone or email.
- Report the event in the TPSC system (if applicable).
The notification to the DPO should include the following information:
- Date and time of the incident.
- Facility and unit where the incident took place.
- Description of the incident.
- Description of actions taken or planned.
- Your contact details.
- In case you have captured the incident in TPSC, add the TPSC case number.
What action to take if it’s urgent?
Depending on the type and severity of the incident, you may need to take immediate actions right away to protect the personal data of patients and employees, as well as safeguard yourself and the company. Consult with your line or duty manager to discuss the best course of action. Additionally, you may reach out to the Data Protection Officer or the ICT Service Desk for further guidance, especially if the breach involves technical issues or requires specialised assistance.
Additional information for line and duty managers
- Inform the next line manager if appropriate
- Ensure that ICT service desk is informed – do it yourself or assign somebody
- Ensure that the DPO is informed – do it yourself or assign somebody
- Inform other staff only as far as necessary excluding personal information i.e. patient effected
- Take ownership of actions and communication if your team member has caused the incident.
eLearning Data breach
The company has developed an eLearning to provide guidance the employees how to deal with data breach incidents. The eLearning is available in Mediclinic’s Learning Academy.
Remember, our dedication to patient well-being extends beyond medical care; it includes safeguarding their privacy. Let us all contribute to fostering an environment where patients can trust that their information is handled with the utmost care and respect.
Thank you for your commitment to upholding the values that make Mediclinic a trusted healthcare provider.