PDPA Code of Practice for Private Hospitals (Healthcare)

Private hospitals handle more sensitive personal data than almost any other organisation: diagnoses, test results, images, next-of-kin details and insurance claims, touched by nurses, specialists, laboratories, insurers and third-party administrators. The Association of Private Hospitals of Malaysia, designated as the data user forum, developed a Code of Practice for Private Hospitals under section 23 of the PDPA, and it applies to every facility licensed as a private hospital under the Private Healthcare Facilities and Services Act 1998. The code sets out how the principles work in a hospital, from registration to discharge and destruction of records, and states typical retention periods, such as seven years for adult patient records and twenty-five years for newborns, counted from the last visit. Non-compliance with a registered code is an offence under section 29 of the Act.

This one-day course is for hospital DPOs, medical records, admissions, nursing leadership, IT, quality and legal teams. It works through the code in the order data moves through a hospital, and gives particular attention to the issues the code singles out: explicit consent and the medical-purpose exceptions for sensitive data, the status of visiting medical specialists as data processors with access across hospitals, next of kin and guardians, and permitted disclosures to insurers, panel lawyers and authorities. Clinics and other healthcare providers not licensed as private hospitals are outside the code but will find the same framework useful. For other sectors see PDPA Codes of Practice for Regulated Sectors.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

9:15 AM - 10:15 AM

The Code, Its Status and Who It Covers

APHM's designation as data user forum, the code's application to private hospitals licensed under Act 586, the stakeholders it treats as data subjects, from patients and staff to specialists, vendors, next of kin and visitors, and the rule that the higher standard prevails where the code, the Act, Malaysian Medical Council guidance and Ministry of Health standards overlap.

03

10:15 AM - 10:30 AM

Break

04

10:30 AM - 11:30 AM

Following Patient Data From Registration to Destruction

The principles applied at each stage: collection at admission, notices and consent forms, use for treatment and billing, disclosure, retention and destruction, including CCTV and visitor records.

05

11:30 AM - 12:30 PM

Sensitive Data, Consent and the Medical-Purpose Exceptions

Explicit consent for health data, the section 40 conditions that allow processing without it, such as vital interests, medical purposes by a healthcare professional, legal proceedings and functions under written law, and worked examples from emergency admissions, psychiatric care and notifiable diseases.

06

12:30 PM - 1:30 PM

Lunch

07

1:30 PM - 2:20 PM

Medical Specialists, Next of Kin and Third Parties

Specialists engaged under a contract for service as data processors, the contractual safeguards the code requires, the ban on moving patient data between hospitals without consent, encrypted portable devices, and handling requests from next of kin, guardians, employers, insurers and panel lawyers.

08

2:20 PM - 3:15 PM

Retention, Security and Patient Rights

The code's typical retention periods for patient, employee, visitor and CCTV data and for paper forms after digitisation, security controls for records and systems, and handling access and correction requests, including requests made on behalf of children.

09

3:15 PM - 3:30 PM

Break

10

3:30 PM - 4:45 PM

Breaches, Staff and Evidence of Compliance

Breach notification under the amended Act in a hospital setting, staff policies and training the code expects, and a clause-by-clause evidence map. Workshop: three scenarios, a misdirected lab result, a relative demanding records, and a specialist's lost laptop.

11

4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Explain who the private hospital code binds and how it interacts with medical and health regulations
  • Apply the principles at every stage of a patient's data lifecycle
  • Decide when explicit consent is required and when a medical-purpose exception applies
  • Manage medical specialists as data processors and control disclosures to third parties
  • Apply the code's retention periods and handle patient rights requests
  • Respond to hospital data breaches and evidence code compliance

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Foundation. For DPOs, medical records, admissions, nursing leadership, IT, quality, legal and patient services teams in private hospitals, and healthcare groups that operate them.

Duration   1 Day (8 Hours)  |  9:00 AM to 5:00 PM

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   Three hospital breach and disclosure scenarios worked in the session, plus a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. PDPA Code of Practice for Private Hospitals (Healthcare) is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

PDPA Code of Practice for Private Hospitals (Healthcare) runs for 1 day (8 hours) | 9:00 AM to 5:00 PM. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Foundation. For DPOs, medical records, admissions, nursing leadership, IT, quality, legal and patient services teams in private hospitals, and healthcare groups that operate them. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.