Notes ·

Patient lists in the wrong inbox

PDPA posters in reception do not stop a day’s appointment book leaving through a personal email. The copies are the audit.

Clinician at a desk with a stethoscope and notes

Malaysian clinics are not short of privacy notices. They are short of a clear picture of how a patient list leaves the building. The usual path is ordinary: a spreadsheet export for 'tomorrow’s reminder calls', forwarded to a phone that also holds family photographs.

The Personal Data Protection Act 2010 cares about purpose, security, and disclosure. An application audit cannot replace legal advice, but it can show the operator the exits. We ask to see the last export, the last print pile at reception, and the last time a vendor logged in 'just to check a ticket'.

Shared inboxes are a particular habit in small centres. One Gmail address, four people, no logging, and a password on a sticky note inside a drawer that does not lock. Replacing that with named accounts is unglamorous work. It is also the difference between a contained mistake and a list of identity numbers sitting in a former clerk’s phone.

We do not collect those lists. We record that they exist, who can make them, and whether the application offers a narrower report — for example, first name and time slot without identification numbers. Often it does, and nobody uses it because the wide export was the one shown at training.

If your privacy file is a folder of policies, add one more page: a dated note of the last time someone followed an export from screen to inbox. That page is more honest than a poster.

If this sounds like your site, request a scoping call →