Services / Health data privacy review

PDPA-aligned fieldwork

Health data privacy review

A privacy notice can be tidy while a receptionist still emails a full day’s appointment list to a personal Gmail. This review follows the data, not the policy binder.

Clinician reviewing records on a laptop in a consultation room

Who it is for

Clinics, diagnostic centres, and health-software vendors handling Malaysian patient data

How long it usually takes

Ten to fifteen working days

Where we look

We trace patient data from registration through billing and onward to laboratories, insurers, and the application vendor. We ask who can export, who can print, who can impersonate a user for 'support', and how long those copies live. Malaysian Personal Data Protection Act 2010 duties sit in the background; the fieldwork is about the copies you did not know you had.

Vendor and support access

Remote support accounts, shared 'admin' users, and overnight vendor windows are common in clinic software. We record who holds them, whether access is logged, and whether a patient record can be opened without a named clinical reason. Findings are written so an operator can change a setting, not so a lawyer can quote a statute.

What you receive

An inventory of data exits we could evidence, a risk-ordered list of changes, and language you can use with staff — short, specific, and free of scare tactics. We are not your Data Protection Officer and we do not issue legal opinions.

Included in a typical engagement

  • Data-exit inventory from the live application and adjacent tools
  • Review of export, print, and vendor-support paths
  • Staff interview notes (roles, not named individuals in the report)
  • Written findings and a practical change list

Ask for a scoping call about this work