[Regulatory Guide] UU 27/2022 PDP

Medical Record Data Security.

Health data is the most sensitive personal data there is. Here is a concrete explanation of the security controls — not just 'secure & encrypted' — mapped to the obligations of UU 27/2022 on Personal Data Protection, complete with an honest boundary of responsibility.

Legal standing

The hospital is the personal-data controller.

Patient health data qualifies as specific (sensitive) personal data under UU 27/2022 on Personal Data Protection. A hospital generally acts as the data controller — responsible for the lawful basis of processing, security, fulfilment of data-subject rights, and handling of breach incidents.

A good information system does not remove that responsibility, but provides the technical controls that make it achievable and provable. Here is what Adievia provides — as it is.

Technical controls

Concrete, with honest status.

Every control is labeled with its status as it is — Live, Partial, or Maturing. We do not mark everything "done".

[01]
Live

Tamper-resistant audit trail

Medical-record operations are logged to a SHA-256 hash-chain audit trail, so data changes are traceable and hard to alter silently.

[02]
Partial

Field-level AES-256-GCM encryption

Sensitive data is encrypted at the column level at rest; transport is secured with TLS 1.2/1.3. Full coverage across every sensitive field is still being matured.

[03]
Live

Granular RBAC

Access rights per role and per module, kept in sync between the application and the database — supporting the need-to-know principle over patient data.

[04]
Maturing

MFA (TOTP/WebAuthn)

Multi-factor options (TOTP RFC 6238, passkey/WebAuthn, backup codes) are being matured; accounts can be required to use MFA once finalized.

An honest boundary

Technology handles the controls; organizational compliance still belongs to the hospital.

Appointing a DPO, drafting data-protection policies, the lawful basis of processing (consent), and the obligation to notify the authority and data subjects of a breach are the hospital's responsibility as the data controller. Adievia provides the audit trail, encryption, and access controls that support meeting those obligations — not a replacement for them. An honest vendor does not promise that "PDP compliance is handled automatically".

FAQ

Questions about data security & the PDP Law.

Because hospitals process patient data, including health data that qualifies as specific (sensitive) personal data. Under UU 27/2022, a hospital generally acts as the personal-data controller — responsible for the lawful basis of processing, security, fulfilment of data-subject rights, and incident handling.

Not just "secure and encrypted": a tamper-resistant SHA-256 hash-chain audit trail, field-level AES-256-GCM encryption for sensitive data at rest, TLS 1.2/1.3 in transit, and granular RBAC. For MFA and full encryption coverage, some parts are still being matured toward launch — we state this as it is.

The system supports logging and traceability (audit trail) that help detect and investigate incidents. However, the legal obligation to notify the authority and data subjects of a breach, along with appointing a DPO, remains the hospital's responsibility as the data controller. We provide the technical controls, not a replacement for organizational compliance.

Yes. Data portability is one of the rights set out in the PDP Law. Adievia lets you export data to standard formats (CSV, FHIR R4 JSON, SQL) at any time — with no vendor lock-in.

Next step

Build medical records that are secure and auditable?