PDPA Code of Practice for Private Hospitals (Healthcare)
Private hospitals handle more sensitive personal data than almost any other organisation: diagnoses, test results, images, next-of-kin details and insurance claims, touched by nurses, specialists, laboratories, insurers and third-party administrators. The Association of Private Hospitals of Malaysia, designated as the data user forum, developed a Code of Practice for Private Hospitals under section 23 of the PDPA, and it applies to every facility licensed as a private hospital under the Private Healthcare Facilities and Services Act 1998. The code sets out how the principles work in a hospital, from registration to discharge and destruction of records, and states typical retention periods, such as seven years for adult patient records and twenty-five years for newborns, counted from the last visit. Non-compliance with a registered code is an offence under section 29 of the Act.
This one-day course is for hospital DPOs, medical records, admissions, nursing leadership, IT, quality and legal teams. It works through the code in the order data moves through a hospital, and gives particular attention to the issues the code singles out: explicit consent and the medical-purpose exceptions for sensitive data, the status of visiting medical specialists as data processors with access across hospitals, next of kin and guardians, and permitted disclosures to insurers, panel lawyers and authorities. Clinics and other healthcare providers not licensed as private hospitals are outside the code but will find the same framework useful. For other sectors see PDPA Codes of Practice for Regulated Sectors.
HRD Corp SBL-Khas Claimable
Programme Agenda
9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
9:15 AM - 10:15 AM
The Code, Its Status and Who It Covers
APHM's designation as data user forum, the code's application to private hospitals licensed under Act 586, the stakeholders it treats as data subjects, from patients and staff to specialists, vendors, next of kin and visitors, and the rule that the higher standard prevails where the code, the Act, Malaysian Medical Council guidance and Ministry of Health standards overlap.
10:15 AM - 10:30 AM
Break
10:30 AM - 11:30 AM
Following Patient Data From Registration to Destruction
The principles applied at each stage: collection at admission, notices and consent forms, use for treatment and billing, disclosure, retention and destruction, including CCTV and visitor records.
11:30 AM - 12:30 PM
Sensitive Data, Consent and the Medical-Purpose Exceptions
Explicit consent for health data, the section 40 conditions that allow processing without it, such as vital interests, medical purposes by a healthcare professional, legal proceedings and functions under written law, and worked examples from emergency admissions, psychiatric care and notifiable diseases.
12:30 PM - 1:30 PM
Lunch
1:30 PM - 2:20 PM
Medical Specialists, Next of Kin and Third Parties
Specialists engaged under a contract for service as data processors, the contractual safeguards the code requires, the ban on moving patient data between hospitals without consent, encrypted portable devices, and handling requests from next of kin, guardians, employers, insurers and panel lawyers.
2:20 PM - 3:15 PM
Retention, Security and Patient Rights
The code's typical retention periods for patient, employee, visitor and CCTV data and for paper forms after digitisation, security controls for records and systems, and handling access and correction requests, including requests made on behalf of children.
3:15 PM - 3:30 PM
Break
3:30 PM - 4:45 PM
Breaches, Staff and Evidence of Compliance
Breach notification under the amended Act in a hospital setting, staff policies and training the code expects, and a clause-by-clause evidence map. Workshop: three scenarios, a misdirected lab result, a relative demanding records, and a specialist's lost laptop.
4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Explain who the private hospital code binds and how it interacts with medical and health regulations
- Apply the principles at every stage of a patient's data lifecycle
- Decide when explicit consent is required and when a medical-purpose exception applies
- Manage medical specialists as data processors and control disclosures to third parties
- Apply the code's retention periods and handle patient rights requests
- Respond to hospital data breaches and evidence code compliance
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Foundation. For DPOs, medical records, admissions, nursing leadership, IT, quality, legal and patient services teams in private hospitals, and healthcare groups that operate them.
Duration 1 Day (8 Hours) | 9:00 AM to 5:00 PM
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment Three hospital breach and disclosure scenarios worked in the session, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance