Our first edition of 2022 focuses on Healthcare and Life Sciences. It is a sector that will once again have the spotlight on it this year as we continue to tackle COVID-19 and its subsequent variants. While the pandemic continues to challenge the sector, governments across the region forge ahead with their plans to expand and upgrade healthcare systems and develop robust world-class healthcare infrastructure.
For the region, healthcare is a vital pillar in diversifying its economies, both locally and as medical tourism hubs. To underpin this, healthcare authorities across the region continue to implement frameworks and regulations that provide structure and accountability.
In this edition, you have unique access to great insights and expert commentary on a number of pertinent healthcare regulatory developments. You will find a topical mix of articles; for example, our lawyers discuss vaccines and returning to work during the pandemic. They take you through several other areas, including stem cell research in Bahrain, clinical research laws in Egypt, and Saudi medical device and pharmaceutical laws.Take a read of the edition
How patient data is processed in the Kingdom of Bahrain has been altered by Law No. 30 of 2018 promulgating the Personal Data Protection Law (PDPL), which came into effect on 1st of August 2019. While the PDPL affects almost all businesses in the Kingdom, the health sector will be particularly impacted as, by its very nature, healthcare involves the collection of significant amounts of personal data to deliver services to patients.
Our Law Update article regarding the PDPL’s general applicability can be found here. In this alert, we focus on the healthcare sector.
Under PDPL any data related to a person’s health is categorised as “sensitive personal data” and is subject to specific processing conditions.
The PDPL expressly allows sensitive personal data to be processed without the consent of the data subject where the processing is necessary for “preventive medicine, medical diagnosis, provision of healthcare or treatment, or for the management of healthcare services which is carried out by a licensed member of a medical profession, or by any other person who is bound by a duty of confidentiality as imposed by law”.
However, this exception is not a complete exemption from the PDPL’s requirements. Here are some examples of the PDPL’s requirements with which health organisations in Bahrain now need to comply.
The PDPL includes provisions that require a data controller to, amongst other things, notify data subjects of certain information, including the purpose and location of any data that is collected. Further, the data subject now has a statutory right to access their personal information and to object to processing of their data in certain circumstances.
With patient health data collected at points ranging from doctor’s surgeries to specialised healthcare facilities, the data footprint of an individual patient can be highly fragmented. Under the PDPL, healthcare organisations must better understand how their patient information is collected and where it is stored.
Under the PDPL even where a data subject has consented to the processing of their personal data, for consent of the data subject to be considered to be valid, the consent has to meet certain perquisites including that:
Data controllers are legally compelled to have in place appropriate technical and organisational measures to protect the patient data against unauthorised or unlawful processing and against accidental loss or destruction of, or damage. Such measures have to be appropriate to the harm that might result and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures.
If they have not already done so, health organisations in Bahrain must review their policies, procedures, and practices for how they process patient data in order to comply with the PDPL.
Al Tamimi’s specialist healthcare and TMT lawyers, and members of our Bahrain office, can assist you with the necessary steps you need to take to comply with the new law. For more details on our offering and how we can assist you, please contact us at email@example.com.