{
 "name": "Who Holds the Record",
 "version": "1.0",
 "asOf": "2026-10-02",
 "license": "CC BY 4.0",
 "creator": "SuperTruth Inc.",
 "weights": {
  "access": 20,
  "control": 20,
  "privacy": 15,
  "journey": 15,
  "commercial": 10,
  "clinical": 10,
  "research": 5,
  "ai": 5
 },
 "countries": [
  {
   "iso3": "FIN",
   "name": "Finland",
   "region": "Europe",
   "overall": 71,
   "rank": "1",
   "likelyRank": "1 to 2",
   "band": "Strong",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Finns read a national record in OmaKanta and decide by permit who outside their region sees it, but public bodies cannot yet be fined.",
   "categories": {
    "access": {
     "score": 76,
     "summary": "OmaKanta shows visit notes, lab and imaging results, vaccinations and prescriptions from public and private care, and 3.3 million people used it in 2025. Records start only when a provider joined Kanta (from 2013), and no app can yet download them.",
     "sources": [
      {
       "title": "Kantaan tallentuvat tiedot näkyvät OmaKannassa (Kanta.fi)",
       "url": "https://www.kanta.fi/tiedot-kannassa",
       "date": "2026-05-21",
       "publisherClass": "official"
      },
      {
       "title": "Tilastot (Kanta.fi)",
       "url": "https://www.kanta.fi/tilastot",
       "date": "2026-06-10",
       "publisherClass": "official"
      },
      {
       "title": "Näin pyydät sinusta tallennettuja tietoja (Kanta.fi)",
       "url": "https://www.kanta.fi/nain-pyydat-tietojasi",
       "date": "2026-03-19",
       "publisherClass": "official"
      },
      {
       "title": "Kantaan liitetyt hyvinvointisovellukset (Kanta.fi)",
       "url": "https://www.kanta.fi/kantaan-liitetyt-hyvinvointisovellukset",
       "date": "2026-01-29",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 74,
     "summary": "Records leave the region or provider where they were written only if the patient gives a revocable permit, which can be narrowed by visit, register or all data, even in emergencies. OmaKanta shows which units fetched data, but staff names need a log request.",
     "sources": [
      {
       "title": "Laki sosiaali- ja terveydenhuollon asiakastietojen käsittelystä 703/2023 (Finlex, säädöskokoelma PDF)",
       "url": "https://www.finlex.fi/api/media/statute/691372/mainPdf/main.pdf?timestamp=2023-04-13T21%3A00%3A00.000Z",
       "date": "2023-04-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Potilastietojen luvat ja kiellot (Kanta.fi)",
       "url": "https://www.kanta.fi/potilastietojen-luvat-ja-kiellot",
       "date": "2025-11-12",
       "publisherClass": "official"
      },
      {
       "title": "Näin tarkistat, missä tietojasi on käsitelty (Kanta.fi)",
       "url": "https://www.kanta.fi/nain-tarkistat-missa-tietojasi-on-kasitelty",
       "date": "2026-02-13",
       "publisherClass": "official"
      },
      {
       "title": "Näin pyydät sinusta tallennettuja tietoja (Kanta.fi)",
       "url": "https://www.kanta.fi/nain-pyydat-tietojasi",
       "date": "2026-03-19",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "GDPR and the Data Protection Act apply, and the ombudsman acts on health cases, but section 24 of the Act bars fines on state and municipal bodies, including the wellbeing counties that hold most records. The government proposed fines for public bodies in April 2026.",
     "sources": [
      {
       "title": "Tietosuojarikkomuksista määrättävät seuraamusmaksut koskemaan myös julkista sektoria (Valtioneuvosto)",
       "url": "https://valtioneuvosto.fi/-/1410853/tietosuojarikkomuksista-maarattavat-seuraamusmaksut-koskemaan-myos-julkista-sektoria",
       "date": "2026-04-09",
       "publisherClass": "official"
      },
      {
       "title": "Apulaistietosuojavaltuutettu: hyvinvointialueella puutteita potilastietojen käytön valvonnassa (Tietosuojavaltuutetun toimisto)",
       "url": "https://tietosuoja.fi/-/apulaistietosuojavaltuutettu-hyvinvointialueella-puutteita-potilastietojen-kayton-valvonnassa",
       "date": "2026-03-04",
       "publisherClass": "official"
      },
      {
       "title": "Hallinto-oikeudelta päätös Yliopiston Apteekille määrätystä seuraamusmaksusta (Tietosuojavaltuutetun toimisto)",
       "url": "https://tietosuoja.fi/-/hallinto-oikeudelta-paatos-yliopiston-apteekille-maaratysta-seuraamusmaksusta-lakiuudistus-julkisen-sektorin-seuraamusmaksuista-lisaisi-yhdenmukaisuutta",
       "date": "2026-06-02",
       "publisherClass": "official"
      },
      {
       "title": "Kova tuomio vie Vastaamo-hakkeri Aleksanteri Kivimäen takaisin vankilaan (Yle)",
       "url": "https://yle.fi/a/74-20211792",
       "date": "2026-02-26",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 82,
     "summary": "All public health care, all pharmacies and two thirds of private health firms use Kanta, which stores over two million new documents a day. Health and social care data still cross only locally until March 2027, and the national medication list waits until October 2027.",
     "sources": [
      {
       "title": "Tilastot (Kanta.fi)",
       "url": "https://www.kanta.fi/tilastot",
       "date": "2026-06-10",
       "publisherClass": "official"
      },
      {
       "title": "Tietojen luovuttaminen sosiaali- ja terveydenhuollossa (Kanta.fi, ammattilaiset)",
       "url": "https://www.kanta.fi/ammattilaiset/tietojen-luovuttaminen-ja-valittaminen",
       "date": "2026-04-21",
       "publisherClass": "official"
      },
      {
       "title": "Informationsgången är kärnan i reformen av apoteksverksamheten (Valtioneuvosto)",
       "url": "https://valtioneuvosto.fi/sv/-/1271139/informationsgangen-ar-karnan-i-reformen-av-apoteksverksamheten?languageId=fi_FI",
       "date": "2026-02-13",
       "publisherClass": "official"
      },
      {
       "title": "Kanta services in 2026: Developing Kanta data to better aid the work of professionals (Kanta.fi)",
       "url": "https://www.kanta.fi/en/ajankohtaista/kanta-services-in-2026-developing-kanta-data-to-better-aid-the-work-of-professionals",
       "date": "2026-01-19",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 68,
     "summary": "The Secondary Use Act bans using social and health data for marketing or for pricing individual services such as insurance, and innovation users get only anonymous statistics. But a pharmacy's EUR 1.1 million fine for sending data to Google and Meta was annulled in 2026.",
     "sources": [
      {
       "title": "Lainsäädäntö (Findata)",
       "url": "https://findata.fi/palvelut-ja-ohjeet/lainsaadanto/",
       "date": "2026-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Oikeudet tietoihisi (Findata)",
       "url": "https://findata.fi/tietoa-findatasta/oikeudet-tietoihisi/",
       "date": "2026-09-18",
       "publisherClass": "official"
      },
      {
       "title": "Vuosikatsaus 2025 (Findata)",
       "url": "https://findata.fi/tietoa-findatasta/vuosikatsaus-2025/",
       "date": "2026-03-17",
       "publisherClass": "official"
      },
      {
       "title": "Hallinto-oikeudelta päätös Yliopiston Apteekille määrätystä seuraamusmaksusta (Tietosuojavaltuutetun toimisto)",
       "url": "https://tietosuoja.fi/-/hallinto-oikeudelta-paatos-yliopiston-apteekille-maaratysta-seuraamusmaksusta-lakiuudistus-julkisen-sektorin-seuraamusmaksuista-lisaisi-yhdenmukaisuutta",
       "date": "2026-06-02",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 76,
     "summary": "Clinicians see all records inside their own wellbeing county or provider, and records from elsewhere through Kanta when the patient has given a permit. An emergency rule allows access to an unconscious patient's records unless the patient has forbidden it.",
     "sources": [
      {
       "title": "Laki sosiaali- ja terveydenhuollon asiakastietojen käsittelystä 703/2023 (Finlex, säädöskokoelma PDF)",
       "url": "https://www.finlex.fi/api/media/statute/691372/mainPdf/main.pdf?timestamp=2023-04-13T21%3A00%3A00.000Z",
       "date": "2023-04-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Potilastietojen luvat ja kiellot (Kanta.fi)",
       "url": "https://www.kanta.fi/potilastietojen-luvat-ja-kiellot",
       "date": "2025-11-12",
       "publisherClass": "official"
      },
      {
       "title": "Reseptitietojen luvat ja kiellot (Kanta.fi)",
       "url": "https://www.kanta.fi/reseptitietojen-luvat-ja-kiellot",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Tietojen luovuttaminen sosiaali- ja terveydenhuollossa (Kanta.fi, ammattilaiset)",
       "url": "https://www.kanta.fi/ammattilaiset/tietojen-luovuttaminen-ja-valittaminen",
       "date": "2026-04-21",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 58,
     "summary": "Findata grants time-limited permits to pseudonymised data in a secure environment, under an opt-out model with no individual consent. The opt-out is fragmented, so the score sits low in its band: each controller must be asked separately, and Findata received 181 objections in 2025.",
     "sources": [
      {
       "title": "Lainsäädäntö (Findata)",
       "url": "https://findata.fi/palvelut-ja-ohjeet/lainsaadanto/",
       "date": "2026-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Vuosikatsaus 2025 (Findata)",
       "url": "https://findata.fi/tietoa-findatasta/vuosikatsaus-2025/",
       "date": "2026-03-17",
       "publisherClass": "official"
      },
      {
       "title": "Tietojen käyttö tutkimuksessa (Kanta.fi)",
       "url": "https://www.kanta.fi/tietojen-kaytto-tutkimuksessa",
       "date": "2026-05-25",
       "publisherClass": "official"
      },
      {
       "title": "Findata supports many of the solutions proposed for the national implementation of the EHDS (Findata)",
       "url": "https://findata.fi/en/news/findata-supports-many-of-the-solutions-proposed-for-the-national-implementation-of-the-ehds/",
       "date": "2026-08-14",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI is governed by EU device law and the AI Act, whose duties for AI in medical devices now start 2 August 2028. Finland's 2025 law only names supervisors, with Fimea for medical devices, and adds no clinical AI rules.",
     "sources": [
      {
       "title": "Tekoälyn käyttö lääkinnällisissä laitteissa (Fimea)",
       "url": "https://fimea.fi/laakinnalliset_laitteet/tekoalyn-kaytto-laakinnallisissa-laitteissa",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Uudet säännöt vahvistavat luottamusta tekoälyyn Euroopassa (Traficom)",
       "url": "https://traficom.fi/fi/uutiset/uudet-saannot-vahvistavat-luottamusta-tekoalyyn-euroopassa",
       "date": "2026-01-07",
       "publisherClass": "official"
      },
      {
       "title": "Laki eräiden tekoälyjärjestelmien valvonnasta 1377/2025 (Finlex)",
       "url": "https://www.finlex.fi/fi/lainsaadanto/saadoskokoelma/2025/1377",
       "date": "2025",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Omnibus on AI has been published (Cuatrecasas)",
       "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published",
       "date": "2026-07-24",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Act on the Processing of Client Data in Healthcare and Social Welfare (703/2023)",
     "level": "National",
     "year": "2023",
     "what": "Runs Kanta and OmaKanta: disclosure permits, targeted denials, emergency access and logging.",
     "url": "https://www.finlex.fi/api/media/statute/691372/mainPdf/main.pdf?timestamp=2023-04-13T21%3A00%3A00.000Z"
    },
    {
     "name": "Act on the Secondary Use of Health and Social Data (552/2019), amended by 1159/2025",
     "level": "National",
     "year": "2019",
     "what": "Permit-based secondary use with GDPR opt-out; bans marketing and insurance pricing uses.",
     "url": "https://www.finlex.fi/fi/lainsaadanto/2019/552"
    },
    {
     "name": "Data Protection Act (1050/2018)",
     "level": "National",
     "year": "2018",
     "what": "Supplements GDPR; section 24 bars administrative fines on state and municipal bodies.",
     "url": "https://www.finlex.fi/fi/lainsaadanto/2018/1050"
    },
    {
     "name": "Act on the Supervision of Certain AI Systems (1377/2025)",
     "level": "National",
     "year": "2025",
     "what": "Names AI Act supervisors from 2026, with Fimea for medical devices.",
     "url": "https://www.finlex.fi/fi/lainsaadanto/saadoskokoelma/2025/1377"
    },
    {
     "name": "Regulation (EU) 2025/327 (European Health Data Space)",
     "level": "Supranational",
     "year": "2025",
     "what": "In force March 2025; secondary-use rules apply from March 2029.",
     "url": "https://findata.fi/faq/mika-on-toisiolaki/"
    },
    {
     "name": "Regulation (EU) 2026/1744 (Digital Omnibus on AI)",
     "level": "Supranational",
     "year": "2026",
     "what": "Moves AI Act high-risk duties for AI in medical devices to 2 August 2028.",
     "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-02-10",
     "headline": "Provider said its system could not show who opened a patient's record and when",
     "paraphrase": "A patient asked a health provider for log data showing who had viewed their records over two years, with times and reasons. The provider said its system could not produce usable logs. The deputy ombudsman ordered it to supply them.",
     "source": "Tietosuojavaltuutettu (Office of the Data Protection Ombudsman), decision TSV/1507/2024",
     "url": "https://www.edilex.fi/tsv/20252464",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2026-07-13",
     "headline": "Sentence final for hacker who published about 33,000 people's patient records",
     "paraphrase": "An attacker broke into a private health provider's system, downloaded its patient database and published the data of about 33,000 people online. The Supreme Court refused his appeal, so the appeal court's sentence of six years and 11 months stands.",
     "source": "Yle",
     "url": "https://yle.fi/a/74-20236144",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-09-24",
     "headline": "Patient's log request revealed two staff had viewed about 150 people's records",
     "paraphrase": "A patient obtained the log of who had opened their record and reported it to police. The wellbeing region found two employees had viewed nearly 150 people's records without a care relationship, and its chief medical officer apologised.",
     "source": "Yle",
     "url": "https://yle.fi/a/74-20184732",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-09-28",
     "headline": "About 50 health workers charged with reading a colleague's patient record",
     "paraphrase": "A doctor treated at his own workplace learned colleagues knew details of his care when one raised it in a shop. About 50 nurses and doctors are charged with unlawfully reading his record. He said he lost faith in healthcare.",
     "source": "Yle",
     "url": "https://yle.fi/a/74-20248250",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-02-11",
     "headline": "Doctors in a university study say the capital region's record system buries patient information",
     "paraphrase": "In interviews for a university study, 25 doctors said the region's patient record system makes information hard to find, slows their work and endangers patient safety, and that their correction requests often go unanswered.",
     "source": "Helsingin Sanomat",
     "url": "https://www.hs.fi/helsinki/art-2000011807677.html",
     "theme": "other",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "DNK",
   "name": "Denmark",
   "region": "Europe",
   "overall": 70,
   "rank": "2",
   "likelyRank": "1 to 3",
   "band": "Strong",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Danes see hospital records, labs and medicines on sundhed.dk and can block lookups, but GP notes are only now arriving and registers have no opt-out.",
   "categories": {
    "access": {
     "score": 78,
     "summary": "The Commission gave Denmark a 98% eHealth maturity score for 2025, and over 3 million Danes use sundhed.dk or MinSundhed each year. GP notes are only starting to appear, and the full hospital record still needs an access request.",
     "sources": [
      {
       "title": "Adgang til egen sundhedsjournal (Indenrigs- og Sundhedsministeriet)",
       "url": "https://www.ism.dk/sundhed/patientrettigheder/adgang-til-egen-sundhedsjournal",
       "date": "2024-09-23",
       "publisherClass": "official"
      },
      {
       "title": "Bekendtgørelse af sundhedsloven, LBK nr. 275 af 12. marts 2025 (Retsinformation)",
       "url": "https://www.retsinformation.dk/eli/lta/2025/275",
       "date": "2025-03-12",
       "publisherClass": "legal_text"
      },
      {
       "title": "2026 Digital Decade eHealth Indicator Study, final report (European Commission)",
       "url": "https://data.europa.eu/doi/10.2759/1486195",
       "date": "2026-06-17",
       "publisherClass": "intergov"
      },
      {
       "title": "Millioner har deres sundhedsdata i lommen: Danskerne har taget MinSundhed-appen til sig (sundhed.dk via Ritzau)",
       "url": "https://via.ritzau.dk/pressemeddelelse/14744026/millioner-har-deres-sundhedsdata-i-lommen-danskerne-har-taget-minsundhed-appen-til-sig?publisherId=10524793&lang=da",
       "date": "2026-01-08",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 70,
     "summary": "Patients can refuse lookups by named staff, units or time periods, and can block access on sundhed.dk. A log on sundhed.dk shows who looked, but treatment lookups need no consent and refusals give way to overriding interests.",
     "sources": [
      {
       "title": "Bekendtgørelse af sundhedsloven, LBK nr. 275 af 12. marts 2025 (Retsinformation)",
       "url": "https://www.retsinformation.dk/eli/lta/2025/275",
       "date": "2025-03-12",
       "publisherClass": "legal_text"
      },
      {
       "title": "Opslag i patientjournalen, praksissammenfatning (Styrelsen for Patientklager)",
       "url": "https://www.stpk.dk/viden/praksissammenfatninger/opslag-i-patientjournalen/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Din journal: spørgsmål og svar om opslag i patientjournaler (Region Sjælland)",
       "url": "https://www.regionsjaelland.dk/sundhed/digitale-loesninger/din-journal",
       "date": "2025-04-22",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "GDPR applies, but the Data Protection Agency cannot fine and must go through police and courts. A court fined Region Syddanmark DKK 500,000 in March 2026, and a 2025 research platform error exposed data on about 260,000 people to regional staff.",
     "sources": [
      {
       "title": "Bødesager (Datatilsynet)",
       "url": "https://www.datatilsynet.dk/afgoerelser/boedesager",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Region Syddanmark frikendt i en sag og idømt bøde i en anden sag om brud på GDPR-reglerne (Region Syddanmark)",
       "url": "https://regionsyddanmark.dk/om-region-syddanmark/presse-og-nyheder/nyhedsarkiv/2026/marts-2026/region-syddanmark-frikendt-i-en-sag-og-idomt-bode-i-en-anden-sag-om-brud-pa-gdpr-reglerne",
       "date": "2026-03-23",
       "publisherClass": "official"
      },
      {
       "title": "Stort antal borgere får besked om databrud (Region Midtjylland via Ritzau)",
       "url": "https://via.ritzau.dk/pressemeddelelse/14290783/stort-antal-borgere-far-besked-om-databrud?publisherId=13561276&lang=da",
       "date": "2025-03-04",
       "publisherClass": "official"
      },
      {
       "title": "AI har haft adgang til over 100.000 beskeder med fortrolig data om danske patienter (Radar/Ingeniøren)",
       "url": "https://radar.dk/artikel/ai-har-haft-adgang-til-over-100000-beskeder-med-fortrolig-data-om-danske-patienter-de-overtraeder",
       "date": "2026-09-29",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 82,
     "summary": "The Shared Medication Record links GPs, hospitals, home care and pharmacies, and all doctors must use it. GP journal notes and in-clinic lab results are still being connected, and EU cross-border exchange was not yet live.",
     "sources": [
      {
       "title": "Baggrund for Fælles Medicinkort (Sundhedsdatastyrelsen)",
       "url": "https://sundhedsdatastyrelsen.dk/digitale-loesninger/faelles-medicinkort/baggrund-og-organisering/baggrund-for-fmk",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Opkobling af almen praksis, Sundhedsjournalen (MedCom)",
       "url": "https://medcom.dk/projekter/basisaktiviteter/sundhedsjournalen/opkobling-af-almen-praksis/",
       "date": "2026-07-13",
       "publisherClass": "official"
      },
      {
       "title": "2026 Digital Decade eHealth Indicator Study, final report (European Commission)",
       "url": "https://data.europa.eu/doi/10.2759/1486195",
       "date": "2026-06-17",
       "publisherClass": "intergov"
      },
      {
       "title": "MyHealth@EU (Danish Health Data Authority)",
       "url": "https://english.sundhedsdatastyrelsen.dk/health-data-and-registers/european-health-data-space/myhealth@eu",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 58,
     "summary": "Disclosure of record data for non-treatment purposes needs consent, normally written, and register access is limited to authorised research environments. A 2025 law creates one entry point to research data. No Danish ban on selling health data or marketing use beyond GDPR was found.",
     "sources": [
      {
       "title": "Bekendtgørelse af sundhedsloven, LBK nr. 275 af 12. marts 2025 (Retsinformation)",
       "url": "https://www.retsinformation.dk/eli/lta/2025/275",
       "date": "2025-03-12",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lov nr. 717 af 20. juni 2025 om ændring af sundhedsloven m.fl. (Retsinformation)",
       "url": "https://www.retsinformation.dk/eli/lta/2025/717",
       "date": "2025-06-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ansøg om autorisation til Forskermaskinen (Sundhedsdatastyrelsen)",
       "url": "https://sundhedsdatastyrelsen.dk/data-og-registre/forskerservice/ansoeg-om-data/autorisation-til-forskermaskinen",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "clinical": {
     "score": 78,
     "summary": "Treating clinicians can look up hospital e-journals, labs and the medication record across providers without asking, within the Health Act's treatment rule. GP notes will reach hospital clinicians only after patients get them, and patient refusals limit lookups.",
     "sources": [
      {
       "title": "Bekendtgørelse af sundhedsloven, LBK nr. 275 af 12. marts 2025 (Retsinformation)",
       "url": "https://www.retsinformation.dk/eli/lta/2025/275",
       "date": "2025-03-12",
       "publisherClass": "legal_text"
      },
      {
       "title": "Opslag i patientjournalen, praksissammenfatning (Styrelsen for Patientklager)",
       "url": "https://www.stpk.dk/viden/praksissammenfatninger/opslag-i-patientjournalen/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Baggrund for Fælles Medicinkort (Sundhedsdatastyrelsen)",
       "url": "https://sundhedsdatastyrelsen.dk/digitale-loesninger/faelles-medicinkort/baggrund-og-organisering/baggrund-for-fmk",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "PLO'rientering 2/2026: status på deling af journalnotater (Praktiserende Lægers Organisation)",
       "url": "https://laeger.dk/foreninger/plo/plorientering/plorientering-22026",
       "date": "2026-01-30",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "Register research runs without individual consent and with no general opt-out, inside ethics approval and a secure server for authorised teams. The only personal opt-out covers tissue samples and genetic data.",
     "sources": [
      {
       "title": "Bekendtgørelse af sundhedsloven, LBK nr. 275 af 12. marts 2025 (Retsinformation)",
       "url": "https://www.retsinformation.dk/eli/lta/2025/275",
       "date": "2025-03-12",
       "publisherClass": "legal_text"
      },
      {
       "title": "Brug af data til forskning (Sundhedsdatastyrelsen)",
       "url": "https://sundhedsdatastyrelsen.dk/borger/om-sundhedsdata/brug-til-forskning",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ansøg om autorisation til Forskermaskinen (Sundhedsdatastyrelsen)",
       "url": "https://sundhedsdatastyrelsen.dk/data-og-registre/forskerservice/ansoeg-om-data/autorisation-til-forskermaskinen",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Brug af biologisk materiale og genetiske oplysninger (Sundhedsdatastyrelsen)",
       "url": "https://sundhedsdatastyrelsen.dk/borger/selvbetjening-og-services/brug-af-vaevsproever",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device law and the AI Act, whose duties for AI in regulated products now start 2 August 2028. Denmark has named AI Act authorities and published patient safety guidance, but no binding national clinical-AI rules were verified.",
     "sources": [
      {
       "title": "AI Omnibus (Digitaliseringsstyrelsen)",
       "url": "https://digst.dk/tilsyn/ai-forordningen/ai-omnibus/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Tilsyn med AI-forordningen (Digitaliseringsstyrelsen)",
       "url": "https://digst.dk/tilsyn/ai-forordningen/tilsyn-med-ai-forordningen/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Digital sundhedsfaglig behandling: ansvar og pligter (Styrelsen for Patientsikkerhed)",
       "url": "https://stps.dk/sundhedsfaglig/ansvar-og-retningslinjer/sundhedsfaglig-vejledning/digital-sundhedsfaglig-behandling",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Danish Health Act (Sundhedsloven), LBK 275 of 2025",
     "level": "National",
     "year": "2025",
     "what": "Right of access within 7 working days, treatment lookups, right to refuse lookups, research disclosure rules.",
     "url": "https://www.retsinformation.dk/eli/lta/2025/275"
    },
    {
     "name": "Act no. 717 of 20 June 2025 amending the Health Act",
     "level": "National",
     "year": "2025",
     "what": "Lets providers withhold staff names from access requests; Ét Kontaktpunkt research data entry starts on a ministerial date.",
     "url": "https://www.retsinformation.dk/eli/lta/2025/717"
    },
    {
     "name": "L 44 (2025-26) amending the Health Act, adopted 16 December 2025",
     "level": "National",
     "year": "2025",
     "what": "Moves Health Data Authority tasks to Digital Sundhed Danmark; lets pharmacy staff look up prescriptions.",
     "url": "https://www.folketingstidende.dk/samling/20251/lovforslag/L44/20251_L44_som_vedtaget.pdf"
    },
    {
     "name": "Regulation (EU) 2025/327 (European Health Data Space)",
     "level": "Supranational",
     "year": "2025",
     "what": "Free access, restriction rights, access logs and secondary-use opt-out; key parts apply from March 2029.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "EU AI Act as amended by the AI Omnibus",
     "level": "Supranational",
     "year": "2026",
     "what": "High-risk duties for AI in regulated products such as medical devices start 2 August 2028.",
     "url": "https://digst.dk/tilsyn/ai-forordningen/ai-omnibus/"
    }
   ],
   "dti": {
    "grade": 83,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-03-27",
     "headline": "Clinic told a patient abroad to fetch their record in person on USB",
     "paraphrase": "A patient living outside Denmark asked a general practice for an electronic copy of their record. The clinic said it could only hand it over on a new USB stick the patient brought in person. The board criticised the clinic.",
     "source": "Styrelsen for Patientklager (Danish Patient Complaints Board), 26SFP21",
     "url": "https://www.stpk.dk/afgorelser-og-domme/afgorelser-fra-styrelsen-for-patientklager/26sfp21/",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2025-03-19",
     "headline": "Women found in their access logs that a doctor had looked up their records",
     "paraphrase": "Women checked the access log for their records on sundhed.dk and saw that a doctor with no part in their care had looked them up. The regions found many more unauthorised lookups and reported him to police.",
     "source": "TV 2 Øst",
     "url": "https://www.tv2east.dk/region-sjaelland/laege-snagede-i-journaler-fik-sit-livs-chok",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2025-09-08",
     "headline": "Millions of hospital records used for AI research without a prior risk check",
     "paraphrase": "Experts said two regions gave a research project access to 3.65 million people's hospital records without first assessing data protection risks. A regional director said the analysis perhaps should have been done. The regulator opened an inquiry.",
     "source": "DR",
     "url": "https://www.dr.dk/nyheder/indland/datatilsynet-gaar-ind-i-sag-om-brug-af-millioner-af-danskeres-sygehusjournaler-til",
     "theme": "sold_or_shared",
     "status": "alleged"
    },
    {
     "date": "2025-01-21",
     "headline": "Hackers posted patients' health details from a GP chain online",
     "paraphrase": "After a cyberattack on a nationwide chain of GP practices, hackers posted patient information including illness history, hospital referrals and medication. The chain had confirmed personal data on an unknown number of patients was compromised.",
     "source": "DR",
     "url": "https://www.dr.dk/nyheder/indland/dybt-foelsomme-patientoplysninger-fra-alles-laegehus-laekket-online",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2024-10-04",
     "headline": "Regulator criticised a university for passing on research participants' health data without permission",
     "paraphrase": "After inspecting eight research projects using health information, the data protection authority gave serious criticism: the university had several times passed personal data on without the required permission and supervised partners poorly. The university said it takes the criticism seriously.",
     "source": "DR",
     "url": "https://www.dr.dk/nyheder/seneste/efter-kritik-fra-datatilsynet-universitet-lover-passe-bedre-paa-folks",
     "theme": "sold_or_shared",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "EST",
   "name": "Estonia",
   "region": "Europe",
   "overall": 68,
   "rank": "3=",
   "likelyRank": "2 to 6",
   "band": "Strong",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Every provider must feed one national record that patients can read, log-check and close, but police and security services can query it without consent.",
   "categories": {
    "access": {
     "score": 80,
     "summary": "The Health Portal shows documents, prescriptions, invoices and access logs, kept without time limit, and 60% of people aged 16 to 74 read records online in 2024 (EU 28%). Export was not verified, so the score sits in the lower half of its band.",
     "sources": [
      {
       "title": "Tervishoiuteenuste korraldamise seadus (Health Services Organisation Act), consolidated text from 01.10.2026, sections 59¹ to 59³",
       "url": "https://www.riigiteataja.ee/akt/130062026132",
       "date": "2026-06-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Tervise infosüsteemi põhimäärus (Government Regulation No. 138 on the health information system), sections 16 to 21",
       "url": "https://www.riigiteataja.ee/akt/128032026002",
       "date": "2026-03-28",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kontaktid ja korduma kippuvad küsimused (Terviseportaal)",
       "url": "https://www.terviseportaal.ee/kontaktid-ja-kkk",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Individuals, internet activities: accessing personal health records online (Eurostat dataset isoc_ci_ac_i, 2024)",
       "url": "https://ec.europa.eu/eurostat/databrowser/view/isoc_ci_ac_i/default/table",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "control": {
     "score": 68,
     "summary": "Patients can close their whole record or single documents in the portal and read a logbook of who viewed each document. Uploads need no consent, prescription views are not in the portal log, and police can obtain data for criminal proceedings without consent.",
     "sources": [
      {
       "title": "Tervishoiuteenuste korraldamise seadus, consolidated text from 01.10.2026, sections 4¹(1), 59²(1), 59³",
       "url": "https://www.riigiteataja.ee/akt/130062026132",
       "date": "2026-06-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Terviseportaali KKK (TEHIK)",
       "url": "https://www.tehik.ee/terviseportaali-kkk",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Tervishoid, KKK (Andmekaitse Inspektsioon)",
       "url": "https://www.aki.ee/isikuandmed/kkk/tervishoid",
       "date": "2026-03-20",
       "publisherClass": "official"
      },
      {
       "title": "Social minister butts heads with doctors over doctor-patient confidentiality (ERR News)",
       "url": "https://news.err.ee/1610151619/social-minister-butts-heads-with-doctors-over-doctor-patient-confidentiality",
       "date": "2026-09-30",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 55,
     "summary": "The regulator's EUR 3 million fine over a pharmacy loyalty breach was upheld in court in September 2026. Against that, the security service queried health data on about 13,000 people in 13 months, and a dental IT breach touched over 300 providers.",
     "sources": [
      {
       "title": "Allium UPI-le määratud 3 miljoni euro suurune trahv oli kohtu hinnangul põhjendatud (Andmekaitse Inspektsioon)",
       "url": "https://www.aki.ee/uudised/allium-upi-le-maaratud-3-miljoni-euro-suurune-trahv-oli-kohtu-hinnangul-pohjendatud",
       "date": "2026-09-02",
       "publisherClass": "official"
      },
      {
       "title": "Estonian police and ISS say most health data queries are lawful (ERR News)",
       "url": "https://news.err.ee/1610104594/estonian-police-and-iss-say-most-health-data-queries-are-lawful",
       "date": "2026-08-07",
       "publisherClass": "news"
      },
      {
       "title": "Patient health data leaked from dentists' information system (ERR News)",
       "url": "https://news.err.ee/1610127079/patient-health-data-leaked-from-dentists-information-system",
       "date": "2026-09-03",
       "publisherClass": "news"
      },
      {
       "title": "Tervise infosüsteemi põhimäärus (Government Regulation No. 138), section 8",
       "url": "https://www.riigiteataja.ee/akt/128032026002",
       "date": "2026-03-28",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 80,
     "summary": "One national system receives mandatory uploads from every provider and serves waiting lists, medical images and state registries. The National Audit Office found in December 2025 that 79% of discharge summaries still arrive in an outdated format and some are never sent.",
     "sources": [
      {
       "title": "Tervishoiuteenuste korraldamise seadus, consolidated text from 01.10.2026, sections 59¹ and 59²",
       "url": "https://www.riigiteataja.ee/akt/130062026132",
       "date": "2026-06-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Terviseandmete õigsuse, täpsuse ja ajakohasuse tagamine (Riigikontroll audit)",
       "url": "https://www.riigikontroll.ee/auditiaruanded/terviseandmete-oigsuse-tapsuse-ja-ajakohasuse-tagamine",
       "date": "2025-12-05",
       "publisherClass": "official"
      },
      {
       "title": "Cross-border data exchange (TEHIK)",
       "url": "https://www.tehik.ee/en/cross-border-data-exchange",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Estonia: Country Health Profile 2025 (OECD and European Observatory)",
       "url": "https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/12/country-health-profile-2025-country-notes_7e72146d/estonia_8621837c/0eb3b75b-en.pdf",
       "date": "2025-12",
       "publisherClass": "intergov"
      }
     ]
    },
    "commercial": {
     "score": 58,
     "summary": "From 1 October 2026 the state may charge EUR 58 an hour to release health system data for research, development and innovation, inside a secure environment. Insurers may not seek genetic data, but no Estonian ban on selling health data beyond GDPR was found.",
     "sources": [
      {
       "title": "Andmepäringud: miks, kellele ja mis tingimustel? (TEHIK Teabekeskus)",
       "url": "https://teabekeskus.tehik.ee/et/andmeparing",
       "date": "2026-04-29",
       "publisherClass": "official"
      },
      {
       "title": "2025 andmeväljastused (TEHIK Teabekeskus)",
       "url": "https://teabekeskus.tehik.ee/et/andmeparing/2025",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Inimgeeniuuringute seadus (Human Genes Research Act), adopted 25.02.2026",
       "url": "https://www.riigiteataja.ee/akt/117032026001",
       "date": "2026-03-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Tervishoiuteenuste korraldamise seadus, consolidated text from 01.10.2026, section 59³(9) to (15)",
       "url": "https://www.riigiteataja.ee/akt/130062026132",
       "date": "2026-06-30",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 75,
     "summary": "Any treating provider may read the national record without consent unless the patient has closed it, and a national dashboard pulls tests and visits from many providers. Gaps in what providers send limit what clinicians actually see.",
     "sources": [
      {
       "title": "Tervishoiuteenuste korraldamise seadus, consolidated text from 01.10.2026, sections 4¹(1), 59³",
       "url": "https://www.riigiteataja.ee/akt/130062026132",
       "date": "2026-06-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Estonia plans 7 million upgrade to centralized health specialist dashboard (ERR News)",
       "url": "https://news.err.ee/1610059153/estonia-plans-7-million-upgrade-to-centralized-health-specialist-dashboard",
       "date": "2026-06-19",
       "publisherClass": "news"
      },
      {
       "title": "Terviseportaali KKK (TEHIK)",
       "url": "https://www.tehik.ee/terviseportaali-kkk",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Terviseandmete õigsuse, täpsuse ja ajakohasuse tagamine (Riigikontroll audit)",
       "url": "https://www.riigikontroll.ee/auditiaruanded/terviseandmete-oigsuse-tapsuse-ja-ajakohasuse-tagamine",
       "date": "2025-12-05",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Health system data can be used for research without consent and with no general opt-out, mainly in pseudonymised form after ethics committee review. Safeguards are documented: a secure processing environment, a public list of data releases, and opt-in consent for the biobank.",
     "sources": [
      {
       "title": "Isikuandmete kaitse seadus (Personal Data Protection Act), consolidated text from 01.10.2026, section 6",
       "url": "https://www.riigiteataja.ee/akt/130062026052",
       "date": "2026-06-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Tervishoiuteenuste korraldamise seadus, consolidated text from 01.10.2026, sections 59³ and 59⁴",
       "url": "https://www.riigiteataja.ee/akt/130062026132",
       "date": "2026-06-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Inimgeeniuuringute seadus (Human Genes Research Act), sections 18 and 20",
       "url": "https://www.riigiteataja.ee/akt/117032026001",
       "date": "2026-03-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "2025 andmeväljastused (TEHIK Teabekeskus)",
       "url": "https://teabekeskus.tehik.ee/et/andmeparing/2025",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device law and the AI Act, whose duties for AI built into products such as medical devices now start 2 August 2028. The data regulator has warned clinicians about ChatGPT and scribes, but that guidance is not binding.",
     "sources": [
      {
       "title": "Tehisintellektisüsteemid (Tarbijakaitse ja Tehnilise Järelevalve Amet)",
       "url": "https://ttja.ee/ariklient/ohutus/tooted-teenused/tehisintellektisusteemid",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Tähelepanu juhtimine: üldotstarbelise tehisintellekti kasutamine tervishoius (Andmekaitse Inspektsioon)",
       "url": "https://www.aki.ee/sites/default/files/documents/2026-06/Tahelepanu%20juhtimine.%20%C3%9Cldotstarbelise%20tehisintellekti%20kasutamine%20tervishoius_0.pdf",
       "date": "2026-05-07",
       "publisherClass": "official"
      },
      {
       "title": "Seisukohad (Andmekaitse Inspektsioon decisions and opinions list)",
       "url": "https://www.aki.ee/kiirelt-katte/aki-otsused/seisukohad",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Health Services Organisation Act (Tervishoiuteenuste korraldamise seadus)",
     "level": "National",
     "year": "2001",
     "what": "Mandatory uploads to the national record, patient access and right to block providers, consent exceptions, research fees.",
     "url": "https://www.riigiteataja.ee/akt/130062026132"
    },
    {
     "name": "Government Regulation No. 138, Statute of the Health Information System",
     "level": "National",
     "year": "2016",
     "what": "Portal contents, closing records, representatives, 30-year logs and the patient's view of access logs.",
     "url": "https://www.riigiteataja.ee/akt/128032026002"
    },
    {
     "name": "Personal Data Protection Act (Isikuandmete kaitse seadus)",
     "level": "National",
     "year": "2018",
     "what": "Applies GDPR; section 6 allows research without consent, mainly pseudonymised, with ethics committee checks.",
     "url": "https://www.riigiteataja.ee/akt/130062026052"
    },
    {
     "name": "Human Genes Research Act (Inimgeeniuuringute seadus)",
     "level": "National",
     "year": "2026",
     "what": "Opt-in biobank consent, donor rights, and a ban on insurers using genetic data.",
     "url": "https://www.riigiteataja.ee/akt/117032026001"
    },
    {
     "name": "Regulation (EU) 2025/327 (European Health Data Space)",
     "level": "Supranational",
     "year": "2025",
     "what": "Access, restriction and access-log rights, and a secondary-use opt-out; main parts apply from March 2029.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "Regulation (EU) 2024/1689 (AI Act), as amended by Regulation (EU) 2026/1744",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk-based AI rules; high-risk duties for AI in products such as medical devices from 2 August 2028.",
     "url": "https://ttja.ee/ariklient/ohutus/tooted-teenused/tehisintellektisusteemid"
    }
   ],
   "dti": {
    "grade": 84,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-09-02",
     "headline": "Court upholds 3 million euro fine over pharmacy loyalty data leak including health data",
     "paraphrase": "Customer data from a pharmacy chain's loyalty programme, including health data, was taken in an attack. The regulator fined the company running it 3 million euros for weak security. A county court upheld the fine; it can still be appealed.",
     "source": "Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)",
     "url": "https://www.aki.ee/uudised/allium-upi-le-maaratud-3-miljoni-euro-suurune-trahv-oli-kohtu-hinnangul-pohjendatud",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-12-05",
     "headline": "Provider ignored a patient's request to correct entries in the national health system",
     "paraphrase": "A patient asked a provider to correct data it had sent to the national health system. The provider said the entries were right and would not discuss it. The audit office said this broke the provider's complaints rules.",
     "source": "Riigikontroll (National Audit Office of Estonia), report to the Riigikogu",
     "url": "https://www.riigikontroll.ee/sites/default/files/documents/2025-12/19886_RKTR_6609_2-1.4_2352_002-1.pdf",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-12-05",
     "headline": "Patient found portal entries from a doctor they were not registered with",
     "paraphrase": "Checking the national patient portal, a patient found that a family doctor whose list they were not on had recorded a diagnosis and treatment for them. The audit office warned that a misleading history can affect later care decisions.",
     "source": "Riigikontroll (National Audit Office of Estonia), report to the Riigikogu",
     "url": "https://www.riigikontroll.ee/sites/default/files/documents/2025-12/19886_RKTR_6609_2-1.4_2352_002-1.pdf",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-12-05",
     "headline": "One wrong letter in a code put a false diagnosis on record",
     "paraphrase": "For years, documents sent to the national system carried a diagnosis code one letter away from the right one, recording an unrelated finding. The audit office noted such errors can mislead treatment and harm a person's reputation and job prospects.",
     "source": "Riigikontroll (National Audit Office of Estonia), report to the Riigikogu",
     "url": "https://www.riigikontroll.ee/sites/default/files/documents/2025-12/19886_RKTR_6609_2-1.4_2352_002-1.pdf",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2026-09-03",
     "headline": "Patient health data downloaded from a dental records system used by 300 providers",
     "paraphrase": "Someone repeatedly entered a records system used by over 300 Estonian dental and health providers and downloaded patients' ID codes, emails and health data. Police arrested a suspect; prosecutors said the data appears not to have been shared.",
     "source": "ERR",
     "url": "https://www.err.ee/1610127001/hambaarstide-infosusteemist-lekkisid-patsientide-terviseandmed",
     "theme": "breach",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "HUN",
   "name": "Hungary",
   "region": "Europe",
   "overall": 68,
   "rank": "3=",
   "likelyRank": "2 to 6",
   "band": "Strong",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Hungary's EESZT links every GP, hospital and pharmacy, and patients can block doctors and read an access log, though very few use those controls.",
   "categories": {
    "access": {
     "score": 72,
     "summary": "Through the EESZT portal and the EgészségAblak app, patients can see documents from their care, prescriptions and referrals, and the EU scored Hungary 85.98 on record access in 2024. Medical images are not yet shown to citizens, so the score stays inside the portal band.",
     "sources": [
      {
       "title": "Lakosság (EESZT Információs portál)",
       "url": "https://e-egeszsegugy.gov.hu/en/lakossagi-szolgaltatasok",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "1997. évi CLIV. törvény az egészségügyről, 24. § (Jogtár)",
       "url": "https://net.jogtar.hu/jogszabaly?docid=99700154.tv",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "2025 Country Report Hungary, SWD(2025) 294 final, Part 13/27 (European Commission)",
       "url": "https://ec.europa.eu/newsroom/dae/redirection/document/116912",
       "date": "2025-06-16",
       "publisherClass": "intergov"
      },
      {
       "title": "Több millióan használják már az EgészségAblakot (Világgazdaság)",
       "url": "https://www.vg.hu/vilaggazdasag-magyar-gazdasag/2025/11/e-egeszsegugy-magyarorszag-egeszsegablak-eeszt-rekord",
       "date": "2025-11-28",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 72,
     "summary": "Patients can open their record to all, block whole specialties, block a single doctor or hospital, or block everyone, and they can read a log of every query. Only about 0.6 percent of people have changed the default.",
     "sources": [
      {
       "title": "Önrendelkezés (EESZT Információs portál)",
       "url": "https://e-egeszsegugy.gov.hu/en/onrendelkezes",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Önrendelkezés: GYIK (EESZT Információs portál)",
       "url": "https://e-egeszsegugy.gov.hu/en/onrendelkezes-gyik",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Az önrendelkezési beállítások típusai az EESZT-ben (Tisztességes Adatkezelés)",
       "url": "https://www.tisztessegesadatkezeles.org/2025/08/az-onrendelkezesi-beallitasok-tipusai-az-eeszt-ben/",
       "date": "2025-08-09",
       "publisherClass": "blog_vendor"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "A dedicated health data act and the GDPR apply, and the regulator NAIH has fined providers that withheld records, including HUF 10 million in a 2024 case. We found no major Hungarian health breach reported in the last 12 months.",
     "sources": [
      {
       "title": "NAIH-4137-8/2022: döntés egészségügyi dokumentáció másolatának kiadásáról (NAIH)",
       "url": "https://www.naih.hu/hatarozatok-vegzesek?download=570%3Aegeszsegugyi-dokumentacio-masolatanak-kiadasa",
       "date": "2022",
       "publisherClass": "official"
      },
      {
       "title": "1997. évi XLVII. törvény (Eüak) (Jogtár)",
       "url": "https://net.jogtar.hu/jogszabaly?docid=99700047.tv",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Önrendelkezés: GYIK (EESZT Információs portál)",
       "url": "https://e-egeszsegugy.gov.hu/en/onrendelkezes-gyik",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Analysis of the NAIH 2024 Cases with Fines (DMP)",
       "url": "https://dmp.hu/en/data-protection/analysis-of-the-naih-2024-cases-with-fines/",
       "date": "2025-04-22",
       "publisherClass": "law_firm"
      }
     ]
    },
    "journey": {
     "score": 78,
     "summary": "Since November 2017 every GP service, outpatient clinic, hospital and pharmacy has been on EESZT, and private doctors joined from 2020. About 19 million e-prescriptions and 17 million reports appear in it each month.",
     "sources": [
      {
       "title": "Lakosság (EESZT Információs portál)",
       "url": "https://e-egeszsegugy.gov.hu/en/lakossagi-szolgaltatasok",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "1997. évi XLVII. törvény (Eüak), 36/A. § (Jogtár)",
       "url": "https://net.jogtar.hu/jogszabaly?docid=99700047.tv",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Bővül az EESZT-ben rögzítendő adatok köre (Jogkövető)",
       "url": "https://jogkoveto.hu/tudastar/bovul-az-eeszt-ben-rogzitendo-adatok-kore",
       "date": "2026-07-22",
       "publisherClass": "news"
      },
      {
       "title": "Több millióan használják már az EgészségAblakot (Világgazdaság)",
       "url": "https://www.vg.hu/vilaggazdasag-magyar-gazdasag/2025/11/e-egeszsegugy-magyarorszag-egeszsegablak-eeszt-rekord",
       "date": "2025-11-28",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 55,
     "summary": "The 2023 national data asset law lets public health data be reused by outside users, for a fee, once pseudonymised or anonymised in a secure environment. The EU health data space will ban marketing uses of reused data from 2029.",
     "sources": [
      {
       "title": "2023. évi CI. törvény a nemzeti adatvagyon hasznosításáról (Jogtár)",
       "url": "https://net.jogtar.hu/jogszabaly?docid=a2300101.tv",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "1997. évi XLVII. törvény (Eüak), 35/W. § (Jogtár)",
       "url": "https://net.jogtar.hu/jogszabaly?docid=99700047.tv",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 76,
     "summary": "Any new GP or specialist treating a patient becomes a treating doctor in EESZT and can see everything except the most sensitive categories. In an emergency, doctors can override a patient's blocks, and each override is logged.",
     "sources": [
      {
       "title": "Önrendelkezés: GYIK (EESZT Információs portál)",
       "url": "https://e-egeszsegugy.gov.hu/en/onrendelkezes-gyik",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Önrendelkezés (EESZT Információs portál)",
       "url": "https://e-egeszsegugy.gov.hu/en/onrendelkezes",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "1997. évi XLVII. törvény (Eüak), 3. § (Jogtár)",
       "url": "https://net.jogtar.hu/jogszabaly?docid=99700047.tv",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "research": {
     "score": 47,
     "summary": "Health data can be reused through the national data asset system without individual consent, and we found no general opt-out. Safeguards include a permit body, a secure processing environment and pseudonymisation, and Hungary has already named its EHDS access body in law.",
     "sources": [
      {
       "title": "1997. évi XLVII. törvény (Eüak), 21/A. § and 35/W. § (Jogtár)",
       "url": "https://net.jogtar.hu/jogszabaly?docid=99700047.tv",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 54,
     "summary": "Act LXXV of 2025, Hungary's first AI law, took effect mostly on 1 December 2025 and sets up AI notifying and market surveillance authorities, an AI Council and a sandbox. We found no national rule written for clinical AI.",
     "sources": [
      {
       "title": "2025. évi LXXV. törvény az EU MI-rendelet végrehajtásáról (Jogtár)",
       "url": "https://net.jogtar.hu/jogszabaly?docid=a2500075.tv",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Az EU mesterséges intelligencia rendeletének végrehajtása Magyarországon (GDPR blog)",
       "url": "https://gdpr.blog.hu/2025/11/05/az_eu_mesterseges_intelligencia_rendeletenek_vegrehajtasa_magyarorszagon",
       "date": "2025-11-05",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "Mesterséges intelligencia: ilyen törvény még nem volt Magyarországon (Világgazdaság)",
       "url": "https://www.vg.hu/vilaggazdasag-magyar-gazdasag/2025/11/mesterseges-intelligencia-torveny-magyarorszag-kormany",
       "date": "2025-11-01",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Act CLIV of 1997 on Health (Eütv.)",
     "level": "National",
     "year": "1997",
     "what": "Patient right to know the contents of their medical documentation; discharge and outpatient reports on completion.",
     "url": "https://net.jogtar.hu/jogszabaly?docid=99700154.tv"
    },
    {
     "name": "Act XLVII of 1997 on Health Data (Eüak.)",
     "level": "National",
     "year": "1997",
     "what": "Legal base for EESZT, digital self-determination, emergency access, and health data asset reuse.",
     "url": "https://net.jogtar.hu/jogszabaly?docid=99700047.tv"
    },
    {
     "name": "EMMI Decree 39/2016 on EESZT detailed rules",
     "level": "National",
     "year": "2016",
     "what": "What providers must upload to EESZT and when; school health added from July 2026.",
     "url": "https://net.jogtar.hu/jogszabaly?docid=a1600039.emm"
    },
    {
     "name": "Act CI of 2023 on the National Data Asset System (Nahtv.)",
     "level": "National",
     "year": "2023",
     "what": "Fee-based reuse of public data, including health data; implements Data Governance Act and EHDS.",
     "url": "https://net.jogtar.hu/jogszabaly?docid=a2300101.tv"
    },
    {
     "name": "Act LXXV of 2025 implementing the EU AI Act",
     "level": "National",
     "year": "2025",
     "what": "Creates AI authorities, an AI Council and a regulatory sandbox; mostly in force 1 December 2025.",
     "url": "https://net.jogtar.hu/jogszabaly?docid=a2500075.tv"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Free access, restriction and access-log rights, opt-out from secondary use; key parts apply from 2029.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    }
   ],
   "dti": {
    "grade": 88,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-03-20",
     "headline": "Former family doctor opened an ex-patient's national health record 47 times",
     "paraphrase": "A patient checked the access log in the national health record system and found a doctor they had left kept viewing their results and prescriptions for 19 months. The doctor also ignored their access request. The regulator imposed a fine.",
     "source": "Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), decision NAIH-273-7/2026",
     "url": "https://www.naih.hu/hatarozatok-vegzesek?download=1450%3Ajogalap-nelkuli-hozzaferes-az-eeszt-rendszerehez-es-hozzaferesi-kerelem-nemteljesitese",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-03",
     "headline": "Clinic charged per page for a patient's records, regulator rules access is free",
     "paraphrase": "A patient asked a health institution to email all their outpatient records. It demanded a per-page fee and said records could only be collected in person. It sent them free months later, after the regulator opened a case.",
     "source": "Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2025, case NAIH-2306-1/2025",
     "url": "https://www.naih.hu/eves-beszamolok?download=1431:naih-beszamolo-a-2025-evi-tevekenysegrol",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2026-03",
     "headline": "Stranger's visit record filed in a patient's national health record by name mix-up",
     "paraphrase": "A health institution uploaded another person's outpatient visit sheet into a patient's national record because they shared a name. The regulator found the record inaccurate and faulted the institution for not reporting the resulting breach.",
     "source": "Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2025, case NAIH-9859/2025",
     "url": "https://www.naih.hu/eves-beszamolok?download=1431:naih-beszamolo-a-2025-evi-tevekenysegrol",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-03",
     "headline": "Patient files left in a closed health building after repeated break-ins",
     "paraphrase": "A health institution left large volumes of patient records in a closed building that intruders kept entering, scattering files inside. It did not remove them or tell patients for over nine months. The regulator fined it two million forints.",
     "source": "Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), annual report on 2024, case NAIH-295/2024",
     "url": "https://www.naih.hu/eves-beszamolok?download=1167:naih-beszamolo-a-2024-evi-tevekenysegrol",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-04-10",
     "headline": "Ransomware group claims it stole a private clinic's patient files",
     "paraphrase": "A ransomware group said it took about 178,000 files from a private clinic, including invoices and treatment reports, and threatened to publish them. The clinic had not answered press questions when the report appeared.",
     "source": "Pénzcentrum (citing Telex)",
     "url": "https://www.penzcentrum.hu/egeszseg/20250410/dobbenetes-hekkertamadas-erhette-a-sasszemklinikat-ez-mar-tenyleg-a-legalja-1177280",
     "theme": "breach",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "SWE",
   "name": "Sweden",
   "region": "Europe",
   "overall": 67,
   "rank": "5",
   "likelyRank": "3 to 8",
   "band": "Strong",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Swedes read nearly all their record in 1177 and must consent before another provider looks, but registers have no opt-out and consent may soon go.",
   "categories": {
    "access": {
     "score": 77,
     "summary": "Every region shows records in 1177, and the Commission found all 13 data types it checks available in all 21 regions, with images only on request. About 8 million people have logged in, but 1177 offers reading and paper copies, not a download.",
     "sources": [
      {
       "title": "Patientdatalag (2008:355) (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/patientdatalag-2008355_sfs-2008-355/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "1177 journal (Inera)",
       "url": "https://www.inera.se/tjanster/journalen/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "2026 Digital Decade eHealth Indicator Study, Annex: Country Factsheets (European Commission)",
       "url": "https://op.europa.eu/en/publication-detail/-/publication/53637948-66ce-11f1-9b18-01aa75ed71a1/language-en",
       "date": "2026-06-15",
       "publisherClass": "intergov"
      },
      {
       "title": "Öppen info: 1177 journal, Statistik och användning (Inera)",
       "url": "https://inera.atlassian.net/wiki/spaces/OIJ/pages/442106604",
       "date": "2025-03-04",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 72,
     "summary": "Another provider may read shared records only with the patient's consent, patients can object and have data blocked at once, and some regions show the access log in 1177. A June 2026 proposal would drop the consent rule from July 2027; it is not yet law.",
     "sources": [
      {
       "title": "Lag (2022:913) om sammanhållen vård- och omsorgsdokumentation (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2022913-om-sammanhallen-vard-och_sfs-2022-913/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Patientdatalag (2008:355) (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/patientdatalag-2008355_sfs-2008-355/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Din journal (1177)",
       "url": "https://www.1177.se/sa-fungerar-varden/sa-skyddas-och-hanteras-dina-uppgifter/din-journal/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ett första steg i genomförandet av en nationell digital infrastruktur på hälsodataområdet, S2026/01360 (Regeringen)",
       "url": "https://www.regeringen.se/rattsliga-dokument/departementsserien-och-promemorior/2026/06/ett-forsta-steg-i-genomforandet-av-en-nationell-digital-infrastruktur-pa-halsodataomradet/",
       "date": "2026-06-18",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 64,
     "summary": "IMY can fine public health bodies up to SEK 10 million and fined pharmacy chain Apoteket SEK 37 million in 2024. But fines on five hospitals and regions were overturned in court in 2022, and police can get some patient data.",
     "sources": [
      {
       "title": "Lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2018218-med-kompletterande-bestammelser_sfs-2018-218/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Regioner och sjukhus slipper att betala miljoner i sanktionsavgifter (Läkartidningen)",
       "url": "https://lakartidningen.se/nyheter/regioner-och-sjukhus-slipper-att-betala-miljoner-i-sanktionsavgifter/",
       "date": "2022-05-17",
       "publisherClass": "news"
      },
      {
       "title": "Sanktionsavgifter mot Apoteket och Apohem för överföring av personuppgifter till Meta (IMY)",
       "url": "https://www.imy.se/nyheter/sanktionsavgifter-mot-apoteket-och-apohem-for-overforing-av-personuppgifter-till-meta/",
       "date": "2024-08-30",
       "publisherClass": "official"
      },
      {
       "title": "Dom: Sjukhus tvingas lämna ut uppgifter om papperslös (Dagens Samhälle)",
       "url": "https://www.dagenssamhalle.se/styrning-och-beslut/juridik/dom-sjukhus-tvingas-lamna-ut-uppgifter-om-papperslos/",
       "date": "2026-07-10",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 66,
     "summary": "Sweden has no single national record: regions run their own systems, joined by the NPÖ viewer that every region and municipality uses. The National Medicines List links all pharmacies, but four regions, including Stockholm, Skåne and Västra Götaland, are connected only to read it, or still connecting.",
     "sources": [
      {
       "title": "NPÖ, Nationell patientöversikt (Inera)",
       "url": "https://www.inera.se/tjanster/nationell-patientoversikt-npo/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Följ anslutningen till Nationella läkemedelslistan (E-hälsomyndigheten)",
       "url": "https://www.ehalsomyndigheten.se/verksamhet/nationella-lakemedelslistan/folj-anslutningen-till-nationella-lakemedelslistan/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "2026 Digital Decade eHealth Indicator Study, Annex: Country Factsheets (European Commission)",
       "url": "https://op.europa.eu/en/publication-detail/-/publication/53637948-66ce-11f1-9b18-01aa75ed71a1/language-en",
       "date": "2026-06-15",
       "publisherClass": "intergov"
      },
      {
       "title": "Ett första steg i genomförandet av en nationell digital infrastruktur på hälsodataområdet, S2026/01360 (Regeringen)",
       "url": "https://www.regeringen.se/rattsliga-dokument/departementsserien-och-promemorior/2026/06/ett-forsta-steg-i-genomforandet-av-en-nationell-digital-infrastruktur-pa-halsodataomradet/",
       "date": "2026-06-18",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 60,
     "summary": "The Patient Data Act limits care records to a closed list of care, quality and statistics purposes, and IMY fined Apoteket SEK 37 million for leaking customer health data to Meta. No Swedish ban on selling health data or using it for marketing beyond GDPR was found.",
     "sources": [
      {
       "title": "Patientdatalag (2008:355) (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/patientdatalag-2008355_sfs-2008-355/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lag (1998:543) om hälsodataregister (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-1998543-om-halsodataregister_sfs-1998-543/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Sekretessprövning hos Socialstyrelsen (Socialstyrelsen)",
       "url": "https://bestalladata.socialstyrelsen.se/data-for-forskning/sekretessprovning/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Sanktionsavgifter mot Apoteket och Apohem för överföring av personuppgifter till Meta (IMY)",
       "url": "https://www.imy.se/nyheter/sanktionsavgifter-mot-apoteket-och-apohem-for-overforing-av-personuppgifter-till-meta/",
       "date": "2024-08-30",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 64,
     "summary": "A clinician at another provider can see records through NPÖ and the national medicines list, but only with a care relationship and the patient's active consent. An emergency rule covers patients who cannot consent, and what NPÖ shows varies by provider.",
     "sources": [
      {
       "title": "Lag (2022:913) om sammanhållen vård- och omsorgsdokumentation (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2022913-om-sammanhallen-vard-och_sfs-2022-913/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "NPÖ, Nationell patientöversikt (Inera)",
       "url": "https://www.inera.se/tjanster/nationell-patientoversikt-npo/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Samtycken och spärrar (E-hälsomyndigheten)",
       "url": "https://www.ehalsomyndigheten.se/verksamhet/nationella-lakemedelslistan/samtycken-och-sparrar/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ett första steg i genomförandet av en nationell digital infrastruktur på hälsodataområdet, S2026/01360 (Regeringen)",
       "url": "https://www.regeringen.se/rattsliga-dokument/departementsserien-och-promemorior/2026/06/ett-forsta-steg-i-genomforandet-av-en-nationell-digital-infrastruktur-pa-halsodataomradet/",
       "date": "2026-06-18",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "All providers must report to national health registers, which are used for research without consent or a general opt-out, under ethics approval and absolute secrecy. Quality registers are the exception: a person can object and have their data erased.",
     "sources": [
      {
       "title": "Lag (1998:543) om hälsodataregister (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-1998543-om-halsodataregister_sfs-1998-543/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Sekretessprövning hos Socialstyrelsen (Socialstyrelsen)",
       "url": "https://bestalladata.socialstyrelsen.se/data-for-forskning/sekretessprovning/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Lag (2003:460) om etikprövning av forskning som avser människor (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2003460-om-etikprovning-av-forskning-som_sfs-2003-460/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Patientdatalag (2008:355) (Sveriges riksdag)",
       "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/patientdatalag-2008355_sfs-2008-355/",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI is governed by EU device law and the AI Act, whose duties for AI in medical devices now start 2 August 2028. Sweden has named AI Act authorities and issued guidance, but no binding national clinical-AI rules were verified.",
     "sources": [
      {
       "title": "Digital Omnibus on AI has been published (Cuatrecasas)",
       "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published",
       "date": "2026-07-24",
       "publisherClass": "law_firm"
      },
      {
       "title": "AI-förordningen (PTS)",
       "url": "https://pts.se/ai/ai-forordningen/",
       "date": "2026-07-31",
       "publisherClass": "official"
      },
      {
       "title": "Ny version av Läkemedelsverkets AI-vägledning till sjukvården (Läkemedelsverket, via TT)",
       "url": "https://via.tt.se/pressmeddelande/4319887/ny-version-av-lakemedelsverkets-ai-vagledning-till-sjukvarden?publisherId=3235477&lang=sv",
       "date": "2026-04-08",
       "publisherClass": "official"
      },
      {
       "title": "Granskning av Region Gävleborgs användning av AI-transkribering i primärvården (IMY)",
       "url": "https://www.imy.se/nyheter/granskning-av-region-gavleborgs-anvandning-av-ai-transkribering-i-primarvarden/",
       "date": "2026-05-07",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Patient Data Act (Patientdatalag 2008:355)",
     "level": "National",
     "year": "2008",
     "what": "Record duties, closed purpose list, blocks within a provider, access logs, quality register opt-out.",
     "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/patientdatalag-2008355_sfs-2008-355/"
    },
    {
     "name": "Act on coordinated care and social care documentation (2022:913)",
     "level": "National",
     "year": "2022",
     "what": "Sharing between providers: patient may object; reading another provider's data needs consent.",
     "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2022913-om-sammanhallen-vard-och_sfs-2022-913/"
    },
    {
     "name": "Data Protection Act (2018:218)",
     "level": "National",
     "year": "2018",
     "what": "Supplements GDPR; lets IMY fine public authorities up to SEK 10 million.",
     "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2018218-med-kompletterande-bestammelser_sfs-2018-218/"
    },
    {
     "name": "Health Data Registers Act (1998:543)",
     "level": "National",
     "year": "1998",
     "what": "Mandatory reporting to national health registers for statistics, follow-up and research.",
     "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-1998543-om-halsodataregister_sfs-1998-543/"
    },
    {
     "name": "Ethical Review Act (2003:460)",
     "level": "National",
     "year": "2003",
     "what": "Research on sensitive personal data needs ethics approval.",
     "url": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/lag-2003460-om-etikprovning-av-forskning-som_sfs-2003-460/"
    },
    {
     "name": "Regulation (EU) 2025/327 (European Health Data Space)",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient access, restriction and opt-out rights; exchange and secondary use from March 2029 and 2031.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "Regulation (EU) 2026/1744 (Digital Omnibus on AI)",
     "level": "Supranational",
     "year": "2026",
     "what": "Delays AI Act high-risk duties for AI in medical devices to 2 August 2028.",
     "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published"
    }
   ],
   "dti": {
    "grade": 86,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2024-11-26",
     "headline": "Region reports new record system to regulator after patient notes went missing",
     "paraphrase": "Within days of a large region switching record systems, staff reported record information that was missing or disappeared, plus failures registering and finding patients. The region reported the system to the medical products regulator and paused it.",
     "source": "SVT Nyheter",
     "url": "https://www.svt.se/nyheter/lokalt/vast/journalsystemet-millennium-anmals-till-lakemedelsverket-igen",
     "theme": "record_wrong",
     "status": "admitted"
    },
    {
     "date": "2025-02-12",
     "headline": "Patient identity numbers, some linked to diagnosis codes, offered for sale after hack",
     "paraphrase": "A ransomware attack hit a private hospital's administrative systems. The clinical record system was not affected, but personal identity numbers, in some cases linked to diagnosis codes, were stolen and put up for sale. The hospital refused to pay.",
     "source": "Läkartidningen",
     "url": "https://lakartidningen.se/aktuellt/nyheter/2025/02/chefslakare-om-hackerattacken-det-var-dramatiskt/",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2025-11-18",
     "headline": "Region's own review recommends scrapping its troubled patient record system",
     "paraphrase": "A region's 90-page internal report found unclear saving of notes, wrong sample labels, medication lists that could not be printed and prescriptions failing to send. The region had filed ten serious-incident reports and the review recommended dropping the system.",
     "source": "Vårdfokus",
     "url": "https://www.vardfokus.se/nyheter/rapport-uppmanar-vastra-gotaland-att-skrota-millennium-krangligt-och-ologiskt/",
     "theme": "other",
     "status": "admitted"
    },
    {
     "date": "2026-05-28",
     "headline": "Another patient's health declaration was filed in the wrong patient's record",
     "paraphrase": "A health declaration belonging to one patient was placed in another patient's record ahead of planned care. The error was found later. The region reported it under the serious-incident law, saying the wrong information could have affected safety.",
     "source": "Skillingaryd.nu",
     "url": "https://skillingaryd.nu/vaggeryd/nyheter/halsodeklaration-infor-operation-bifogades-i-fel-journal/",
     "theme": "record_wrong",
     "status": "admitted"
    },
    {
     "date": "2026-06-04",
     "headline": "Nurse convicted for years of unauthorised lookups in patients' records",
     "paraphrase": "A district court convicted a former nurse of data intrusion for unauthorised record lookups over several years, ordering a conditional sentence and 115,000 kronor in damages. Nineteen cases were tried; about 60 people had reported her to police.",
     "source": "SVT Nyheter",
     "url": "https://www.svt.se/nyheter/lokalt/orebro/efter-otillatna-journalslagningar-sjukskoterskan-doms-till-villkorlig-dom",
     "theme": "breach",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "AUS",
   "name": "Australia",
   "region": "Oceania",
   "overall": 66,
   "rank": "6=",
   "likelyRank": "3 to 10",
   "band": "Strong",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Australia's opt-out national record holds over 25 million records patients can lock and audit, and test results now upload to it by default.",
   "categories": {
    "access": {
     "score": 70,
     "summary": "My Health Record held 25.16 million records in July 2026, and from 1 July 2026 pathology and imaging reports must be uploaded by default. It is a summary, not the full chart, and copies from providers may carry a fee.",
     "sources": [
      {
       "title": "My Health Record statistics and insights, July 2026 (Australian Digital Health Agency)",
       "url": "https://www.digitalhealth.gov.au/sites/default/files/documents/my-health-record-statistics-july-2026-landscape.pdf",
       "date": "2026-07",
       "publisherClass": "official"
      },
      {
       "title": "Australians already seeing the benefits of sharing health information by default (Australian Digital Health Agency)",
       "url": "https://www.digitalhealth.gov.au/newsroom/media/australians-already-seeing-the-benefits-of-sharing-health-information-by-default",
       "date": "2026-07-08",
       "publisherClass": "official"
      },
      {
       "title": "Access your health information (OAIC)",
       "url": "https://www.oaic.gov.au/privacy/your-privacy-rights/health-information/access-your-health-information",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "About My Health Record (healthdirect, Australian Government)",
       "url": "https://www.healthdirect.gov.au/my-health-record",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 68,
     "summary": "People can cancel the record, lock it or single documents with access codes, stop uploads, and read an access log with alerts. But the default lets every treating provider see everything, and only about 72,000 people use advanced access controls.",
     "sources": [
      {
       "title": "My Health Record access controls (OAIC)",
       "url": "https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/my-health-record/my-health-record-access-controls",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Manage your My Health Record (OAIC)",
       "url": "https://www.oaic.gov.au/privacy/your-privacy-rights/health-information/my-health-record/manage-your-my-health-record",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "My Health Records Act 2012 (compilation C2026C00277, 1 July 2026)",
       "url": "https://www.legislation.gov.au/C2012A00063/latest/text",
       "date": "2026-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "My Health Record statistics and insights, July 2026 (Australian Digital Health Agency)",
       "url": "https://www.digitalhealth.gov.au/sites/default/files/documents/my-health-record-statistics-july-2026-landscape.pdf",
       "date": "2026-07",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million, the first civil penalties under the Privacy Act, for a pathology breach. Yet health providers led 2025 breach notifications with 225 of a record 1,205.",
     "sources": [
      {
       "title": "Australian Clinical Labs ordered to pay penalties in relation to Medlab Pathology data breach (OAIC)",
       "url": "https://www.oaic.gov.au/news/media-centre/australian-clinical-labs-ordered-to-pay-penalties-in-relation-to-medlab-pathology-data-breach-in-first-for-privacy-act",
       "date": "2025-10-09",
       "publisherClass": "official"
      },
      {
       "title": "Data breach notifications increase to all-time high in 2025, new NDB stats show (OAIC)",
       "url": "https://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025,-new-ndb-stats-show",
       "date": "2026-07-06",
       "publisherClass": "official"
      },
      {
       "title": "Annual report of the Australian Information Commissioner's activities in relation to digital health 2024-25 (OAIC)",
       "url": "https://www.oaic.gov.au/about-the-OAIC/our-corporate-information/digital-health-annual-reports/annual-report-of-the-australian-information-commissioners-activities-in-relation-to-digital-health-202425",
       "date": "2025-10-20",
       "publisherClass": "official"
      },
      {
       "title": "Australia publishes initial proposals for second wave of Privacy Act reforms (IAPP)",
       "url": "https://iapp.org/news/a/australia-publishes-initial-proposals-for-second-wave-of-privacy-act-reforms",
       "date": "2026-08-31",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 70,
     "summary": "One national record links GPs, pharmacies, public hospitals, labs and imaging: 99% of GPs and pharmacies and 97% of public hospitals are registered. Specialists and aged care lag, and the national exchange program is still being built.",
     "sources": [
      {
       "title": "My Health Record statistics and insights, July 2026 (Australian Digital Health Agency)",
       "url": "https://www.digitalhealth.gov.au/sites/default/files/documents/my-health-record-statistics-july-2026-landscape.pdf",
       "date": "2026-07",
       "publisherClass": "official"
      },
      {
       "title": "Health Connect Australia (Australian Digital Health Agency)",
       "url": "https://www.digitalhealth.gov.au/health-connect-australia",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Understanding the Exploration of Electronic Prescriptions in Australia (Australian Digital Health Agency)",
       "url": "https://www.digitalhealth.gov.au/newsroom/blogs/understanding-the-exploration-of-electronic-prescriptions-in-australia",
       "date": "2025-10-10",
       "publisherClass": "official"
      },
      {
       "title": "My Health Record (Share by Default) Rules 2025 (F2025L01569)",
       "url": "https://www.legislation.gov.au/F2025L01569/asmade/text",
       "date": "2025-12-12",
       "publisherClass": "legal_text"
      }
     ]
    },
    "commercial": {
     "score": 65,
     "summary": "The My Health Records Act bans use of record data for insurance underwriting or employment, with civil penalties of 1,500 penalty units. In June 2026 the regulator ruled that health websites need consent before tracking pixels feed advertising.",
     "sources": [
      {
       "title": "My Health Records Act 2012 (compilation C2026C00277, 1 July 2026)",
       "url": "https://www.legislation.gov.au/C2012A00063/latest/text",
       "date": "2026-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Privacy Commissioner finds privacy breaches in third-party tracking pixel investigation (OAIC)",
       "url": "https://www.oaic.gov.au/news/media-centre/privacy-commissioner-finds-privacy-breaches-in-third-party-tracking-pixel-investigation",
       "date": "2026-06-24",
       "publisherClass": "official"
      },
      {
       "title": "Secondary use of data (Australian Digital Health Agency)",
       "url": "https://www.digitalhealth.gov.au/initiatives-and-programs/my-health-record/manage-your-record/privacy-and-access/secondary-use-of-data",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 66,
     "summary": "GPs, pharmacists and public hospital staff can open a patient's national record at the point of care, with an emergency override. But it holds summaries and reports, not each provider's full notes, and specialist use is low.",
     "sources": [
      {
       "title": "My Health Record access controls (OAIC)",
       "url": "https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/health-service-providers/my-health-record/my-health-record-access-controls",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "My Health Records Act 2012 (compilation C2026C00277, 1 July 2026)",
       "url": "https://www.legislation.gov.au/C2012A00063/latest/text",
       "date": "2026-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "My Health Record statistics and insights, July 2026 (Australian Digital Health Agency)",
       "url": "https://www.digitalhealth.gov.au/sites/default/files/documents/my-health-record-statistics-july-2026-landscape.pdf",
       "date": "2026-07",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "People can switch off research use of their My Health Record, but that data has not yet been released and other health data has no general opt-out. Ethics committees can approve use without consent under NHMRC guidelines, inside a registered data-sharing scheme.",
     "sources": [
      {
       "title": "Secondary use of data (Australian Digital Health Agency)",
       "url": "https://www.digitalhealth.gov.au/initiatives-and-programs/my-health-record/manage-your-record/privacy-and-access/secondary-use-of-data",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Guidelines approved under Section 95A of the Privacy Act 1988 (NHMRC)",
       "url": "https://www.nhmrc.gov.au/about-us/publications/guidelines-approved-under-section-95a-privacy-act-1988",
       "date": "2024",
       "publisherClass": "official"
      },
      {
       "title": "The DATA Scheme safeguards (Office of the National Data Commissioner)",
       "url": "https://www.datacommissioner.gov.au/data-scheme/data-scheme-safeguards",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "My Health Records Act 2012 (compilation C2026C00277, 1 July 2026)",
       "url": "https://www.legislation.gov.au/C2012A00063/latest/text",
       "date": "2026-07-01",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 55,
     "summary": "The TGA regulates AI software that meets the device definition, requires notice of significant changes, and is starting compliance action on AI scribes. But change control for adaptive AI is case by case, no human oversight mandate exists, and mandatory AI guardrails were dropped.",
     "sources": [
      {
       "title": "Report: Clarifying and strengthening the regulation of Medical Device Software including AI, v1.0 (TGA)",
       "url": "https://consultations.tga.gov.au/tga/clarifying-and-strengthening-the-regulation-of-ai/supporting_documents/tga-report-clarifying-and-strengthening-the-regulation-of-medical-device-software-including-artificial-intelligence-aipdf",
       "date": "2025-07",
       "publisherClass": "official"
      },
      {
       "title": "TGA AI Review: Outcomes report published (TGA)",
       "url": "https://www.tga.gov.au/news/news-articles/tga-ai-review-outcomes-report-published",
       "date": "2025-07-30",
       "publisherClass": "official"
      },
      {
       "title": "TGA flags compliance action on AI scribes as review finds safety concerns (Medical Republic)",
       "url": "https://www.medicalrepublic.com.au/tga-flags-compliance-action-on-ai-scribes-as-review-finds-safety-concerns/127888",
       "date": "2026-08-04",
       "publisherClass": "news"
      },
      {
       "title": "Government drops AI 'mandatory guardrails', reveals road map on data centres (ABC News)",
       "url": "https://www.abc.net.au/news/2025-12-02/national-artificial-intelligence-plan-growth-existing-laws/106086474",
       "date": "2025-12-02",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "My Health Records Act 2012",
     "level": "National",
     "year": "2012",
     "what": "Opt-out national record; access controls, cancellation, insurance and employment bans, court order for agency access.",
     "url": "https://www.legislation.gov.au/C2012A00063/latest/text"
    },
    {
     "name": "Health Legislation Amendment (Modernising My Health Record, Sharing by Default) Act 2025",
     "level": "National",
     "year": "2025",
     "what": "Requires prescribed providers to share key information to My Health Record by default.",
     "url": "https://www.legislation.gov.au/C2025A00008/asmade/text"
    },
    {
     "name": "Privacy Act 1988",
     "level": "National",
     "year": "1988",
     "what": "Health data is sensitive information; right of access (APP 12), breach notification, civil penalties.",
     "url": "https://www.legislation.gov.au/C2004A03712/latest/text"
    },
    {
     "name": "Privacy and Other Legislation Amendment Act 2024",
     "level": "National",
     "year": "2024",
     "what": "First tranche of reform: new OAIC enforcement powers, automated decision transparency, statutory privacy tort.",
     "url": "https://www.legislation.gov.au/C2024A00128/asmade/text"
    },
    {
     "name": "Data Availability and Transparency Act 2022",
     "level": "National",
     "year": "2022",
     "what": "Accredited sharing of public sector data with registered agreements and a re-identification ban.",
     "url": "https://www.legislation.gov.au/C2022A00011/latest/text"
    },
    {
     "name": "Therapeutic Goods Act 1989",
     "level": "National",
     "year": "1989",
     "what": "Regulates medical devices, including software and AI that meet the device definition.",
     "url": "https://www.legislation.gov.au/C2004A03952/latest/text"
    },
    {
     "name": "Health Records and Information Privacy Act 2002 (NSW)",
     "level": "State/Provincial",
     "year": "2002",
     "what": "Right to access health information held by NSW public and private providers.",
     "url": "https://legislation.nsw.gov.au/view/html/inforce/current/act-2002-071"
    }
   ],
   "dti": {
    "grade": 86,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-08-14",
     "headline": "AI note-taker put a false statement into a patient's specialist letter",
     "paraphrase": "A patient agreed to have a specialist appointment transcribed by an AI tool. She later found a letter to her GP claimed something she says she never said. After she complained, the specialist apologised and corrected it.",
     "source": "ABC News",
     "url": "https://www.abc.net.au/news/2026-08-14/ai-medical-scribe-error-leaves-patient-devastated/107031672",
     "theme": "record_wrong",
     "status": "alleged"
    },
    {
     "date": "2026-07-22",
     "headline": "Another woman's hospital history merged into a patient's record; family told she died",
     "paraphrase": "Months of another woman's appointments and tests were added to a Victorian woman's health record. The other woman flagged wrong details four times. After she died, police told the patient's family she was dead. Mercy Health apologised.",
     "source": "ABC News",
     "url": "https://www.abc.net.au/news/2026-07-22/mistaken-identity-data-hospital-error-death-notice-police/106936454",
     "theme": "record_wrong",
     "status": "admitted"
    },
    {
     "date": "2025-11-21",
     "headline": "Doctor passed a patient's record details to her estranged partner, tribunal finds",
     "paraphrase": "A doctor in Western Australia opened a patient's records on 12 days and passed details to her estranged partner despite a restraining order. The State Administrative Tribunal found misconduct and the doctor was deregistered.",
     "source": "ABC News",
     "url": "https://www.abc.net.au/news/2025-11-21/perth-doctor-suspended-for-patient-confidentiality-breach/106034508",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-06-30",
     "headline": "Former patients still locked out of their records months after clinic closed",
     "paraphrase": "A general practice in regional Victoria closed without warning. More than five months later its former patients still could not get their medical records, which remained under the closed practice's control while health agencies sought a fix.",
     "source": "South Gippsland Sentinel-Times",
     "url": "https://www.sgst.com.au/leongatha-patients-still-locked-out-of-medical-records/",
     "theme": "lost_between_providers",
     "status": "alleged"
    },
    {
     "date": "2026-03-10",
     "headline": "Minister's office accused of giving a patient's health details to journalists",
     "paraphrase": "After a South Australian patient spoke publicly about her care, the state health minister's office shared confidential details about her with journalists, the opposition claimed. She says she did not consent.",
     "source": "InDaily (South Australia)",
     "url": "https://www.indailysa.com.au/news/just-in/2026/03/10/second-labor-govt-patient-information-leak-liberals-claim",
     "theme": "sold_or_shared",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "FRA",
   "name": "France",
   "region": "Europe",
   "overall": 66,
   "rank": "6=",
   "likelyRank": "3 to 11",
   "band": "Strong",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Nearly everyone has an opt-out Mon espace santé with blocking and an access history, but only a third use it and vendors leak.",
   "categories": {
    "access": {
     "score": 70,
     "summary": "French law gives a free right to the whole record within 8 days, and Mon espace santé exists for about 97% of people by default. It holds documents providers deposit, not the full chart, and only 33.6% of accounts are activated.",
     "sources": [
      {
       "title": "Accès au dossier médical (Service-Public.fr, vérifié le 28 février 2025)",
       "url": "https://www.service-public.gouv.fr/particuliers/vosdroits/F12210",
       "date": "2025-02-28",
       "publisherClass": "official"
      },
      {
       "title": "Mon espace santé (Service-Public.fr, vérifié le 31 décembre 2025)",
       "url": "https://www.service-public.gouv.fr/particuliers/vosdroits/F10872",
       "date": "2025-12-31",
       "publisherClass": "official"
      },
      {
       "title": "En 2026, Mon espace santé amorce un nouveau virage (ARS Nouvelle-Aquitaine, communiqué)",
       "url": "https://www.nouvelle-aquitaine.ars.sante.fr/communique-de-presse-en-2026-mon-espace-sante-amorce-un-nouveau-virage-pour-devenir-loutil-central",
       "date": "2026-02-06",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 68,
     "summary": "Mon espace santé is opt-out, but inside it patients can block named professionals, hide documents, get a notification when a professional connects and read an activity history. Emergency staff can open the record unless the patient objected.",
     "sources": [
      {
       "title": "Mon espace santé (Service-Public.fr, vérifié le 31 décembre 2025)",
       "url": "https://www.service-public.gouv.fr/particuliers/vosdroits/F10872",
       "date": "2025-12-31",
       "publisherClass": "official"
      },
      {
       "title": "Mon Espace Santé, le service public numérique (ARS Centre-Val de Loire)",
       "url": "https://www.centre-val-de-loire.ars.sante.fr/mon-espace-sante-le-service-public-numerique-pour-faciliter-les-echanges-entre-patient-et-3",
       "date": "2026-09-09",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 58,
     "summary": "CNIL enforces in health, with a 5 million euro fine on IQVIA and a 500,000 euro fine on a private hospital in 2026. But a software attack may have exposed data of about 15 million patients, about 164,000 with sensitive data (not necessarily health data).",
     "sources": [
      {
       "title": "Violation de données en matière de santé : sanction de 500 000 euros à l'encontre de l'Hôpital privé de la Loire (CNIL)",
       "url": "https://www.cnil.fr/fr/sanction-hopital-prive-loire",
       "date": "2026-09-03",
       "publisherClass": "official"
      },
      {
       "title": "Cegedim : l'État acte l'ampleur de la fuite (Caducée.net)",
       "url": "https://www.caducee.net/actualite-medicale/16822/cegedim-l-etat-acte-l-ampleur-de-la-fuite-et-precise-le-risque-donnees-sensibles-pour-164-000-personnes.html",
       "date": "2026-02-28",
       "publisherClass": "news"
      },
      {
       "title": "Code de la santé publique, article L1111-8 (copy of the official text, Espace éthique Hauts-de-France)",
       "url": "https://www.ethique-hdf.fr/fileadmin/user_upload/Article_L1111-8_CSP_-_Hebergement_des_donnees_de_sante_a_caractere_personnel.pdf",
       "date": "2017-01-12",
       "publisherClass": "legal_text"
      },
      {
       "title": "Scaleway devient l'hébergeur du Health Data Hub (Le Monde Informatique)",
       "url": "https://www.lemondeinformatique.fr/actualites/lire-scaleway-devient-l-hebergeur-du-health-data-hub-99998.html",
       "date": "2026-04-23",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 72,
     "summary": "The SNDS links insurance claims, hospital stays, causes of death and disability data nationally, and providers must deposit key documents in Mon espace santé. Feeding is high but uneven, and software for reading the record is being upgraded.",
     "sources": [
      {
       "title": "SNDS : Système national des données de santé (CNIL)",
       "url": "https://www.cnil.fr/fr/snds-systeme-national-des-donnees-de-sante",
       "date": "2017-03-30",
       "publisherClass": "official"
      },
      {
       "title": "Mon espace santé (Service-Public.fr, vérifié le 31 décembre 2025)",
       "url": "https://www.service-public.gouv.fr/particuliers/vosdroits/F10872",
       "date": "2025-12-31",
       "publisherClass": "official"
      },
      {
       "title": "En 2026, Mon espace santé amorce un nouveau virage (ARS Nouvelle-Aquitaine, communiqué)",
       "url": "https://www.nouvelle-aquitaine.ars.sante.fr/communique-de-presse-en-2026-mon-espace-sante-amorce-un-nouveau-virage-pour-devenir-loutil-central",
       "date": "2026-02-06",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 66,
     "summary": "French law bans selling identifying health data even with consent, and bars using the national claims database to promote health products or price insurance. Yet IQVIA built warehouses on tens of millions of people from pharmacy data customers were not told about.",
     "sources": [
      {
       "title": "Code de la santé publique, article L1111-8 (copy of the official text, Espace éthique Hauts-de-France)",
       "url": "https://www.ethique-hdf.fr/fileadmin/user_upload/Article_L1111-8_CSP_-_Hebergement_des_donnees_de_sante_a_caractere_personnel.pdf",
       "date": "2017-01-12",
       "publisherClass": "legal_text"
      },
      {
       "title": "SNDS : Système national des données de santé (CNIL)",
       "url": "https://www.cnil.fr/fr/snds-systeme-national-des-donnees-de-sante",
       "date": "2017-03-30",
       "publisherClass": "official"
      },
      {
       "title": "Données de santé : sanction de 5 millions d'euros à l'encontre de la société IQVIA (CNIL)",
       "url": "https://www.cnil.fr/fr/donnees-sante-sanction-5-millions-iqvia",
       "date": "2026-05-28",
       "publisherClass": "official"
      },
      {
       "title": "Mon Espace Santé, le service public numérique (ARS Centre-Val de Loire)",
       "url": "https://www.centre-val-de-loire.ars.sante.fr/mon-espace-sante-le-service-public-numerique-pour-faciliter-les-echanges-entre-patient-et-3",
       "date": "2026-09-09",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 62,
     "summary": "Treating professionals the patient has not blocked can read the shared record, and emergency access applies unless refused. About 70,000 professionals, 38,000 of them private doctors, consult records each month, and software ease of use is still poor.",
     "sources": [
      {
       "title": "Mon espace santé (Service-Public.fr, vérifié le 31 décembre 2025)",
       "url": "https://www.service-public.gouv.fr/particuliers/vosdroits/F10872",
       "date": "2025-12-31",
       "publisherClass": "official"
      },
      {
       "title": "En 2026, Mon espace santé amorce un nouveau virage (ARS Nouvelle-Aquitaine, communiqué)",
       "url": "https://www.nouvelle-aquitaine.ars.sante.fr/communique-de-presse-en-2026-mon-espace-sante-amorce-un-nouveau-virage-pour-devenir-loutil-central",
       "date": "2026-02-06",
       "publisherClass": "official"
      },
      {
       "title": "Mon Espace Santé, le service public numérique (ARS Centre-Val de Loire)",
       "url": "https://www.centre-val-de-loire.ars.sante.fr/mon-espace-sante-le-service-public-numerique-pour-faciliter-les-echanges-entre-patient-et-3",
       "date": "2026-09-09",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 60,
     "summary": "People can object to research use of their SNDS data, private users need CNIL authorisation and every project is listed publicly. The opt-out is exercised by writing to one's insurance fund and does not cover state public health missions.",
     "sources": [
      {
       "title": "SNDS : Système national des données de santé (CNIL)",
       "url": "https://www.cnil.fr/fr/snds-systeme-national-des-donnees-de-sante",
       "date": "2017-03-30",
       "publisherClass": "official"
      },
      {
       "title": "Protection de la donnée (snds.gouv.fr)",
       "url": "https://www.snds.gouv.fr/SNDS/Protection-de-la-donnee",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Tous les projets, répertoire public (Plateforme des données de santé)",
       "url": "https://www.health-data-hub.fr/projets",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Publication de la stratégie nationale sur l'intelligence artificielle et les données de santé (Health Data Hub)",
       "url": "https://www.health-data-hub.fr/actualites/publication-de-la-strategie-nationale-sur-lintelligence-artificielle-et-les-donnees-de",
       "date": "2025-11-27",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 54,
     "summary": "Clinical AI falls under EU device law and the AI Act, plus HAS hospital certification criteria on AI risk since September 2025. A 2021 law requires patients be told when AI devices are used, but its implementing order was not found.",
     "sources": [
      {
       "title": "Digital Omnibus on AI has been published (Cuatrecasas)",
       "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published",
       "date": "2026-07-24",
       "publisherClass": "law_firm"
      },
      {
       "title": "Certification des établissements de santé : lancement officiel du 6e cycle (HAS)",
       "url": "https://www.has-sante.fr/jcms/p_3643724/fr/certification-des-etablissements-de-sante-lancement-officiel-du-6e-cycle-au-1er-septembre-2025",
       "date": "2025-09-04",
       "publisherClass": "official"
      },
      {
       "title": "Principaux textes réglementant l'intelligence artificielle (Conseil national de l'Ordre des médecins)",
       "url": "https://www.conseil-national.medecin.fr/medecin/exercice/principaux-textes-reglementant-lintelligence-artificielle",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Guide HAS/CNIL, bon usage des systèmes d'IA en contexte de soins (AP-HP, Direction des affaires juridiques)",
       "url": "https://affairesjuridiques.aphp.fr/textes/guide-has-cnil-accompagner-le-bon-usage-des-systemes-dintelligence-artificielle-en-contexte-de-soins-fevrier-2026/",
       "date": "2026-02-18",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Code de la santé publique, L1110-4 and R1111-1 to R1111-7",
     "level": "National",
     "year": "2004",
     "what": "Medical secrecy and free patient access to health information within 8 days, 2 months if older.",
     "url": "https://www.service-public.gouv.fr/particuliers/vosdroits/F12210"
    },
    {
     "name": "Code de la santé publique, article L1111-8 (health data hosting)",
     "level": "National",
     "year": "2017",
     "what": "Certified hosting of health data; bans paid transfer of identifying health data, even with consent.",
     "url": "https://www.ethique-hdf.fr/fileadmin/user_upload/Article_L1111-8_CSP_-_Hebergement_des_donnees_de_sante_a_caractere_personnel.pdf"
    },
    {
     "name": "Loi de modernisation de notre système de santé (SNDS)",
     "level": "National",
     "year": "2016",
     "what": "Created the SNDS; bans product promotion and insurance pricing uses; research opt-out.",
     "url": "https://www.cnil.fr/fr/snds-systeme-national-des-donnees-de-sante"
    },
    {
     "name": "Code de la santé publique, article L4001-3 (bioethics law)",
     "level": "National",
     "year": "2021",
     "what": "Patients informed when AI-based medical devices are used; designers must ensure explicability.",
     "url": "https://www.conseil-national.medecin.fr/medecin/exercice/principaux-textes-reglementant-lintelligence-artificielle"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health data is a special category (Art. 9); access right, breach notification, large fines.",
     "url": "https://www.cnil.fr/fr/reglement-europeen-protection-donnees"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Access logs, restriction rights and secondary-use opt-out; key parts apply from March 2029.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "AI Act (EU) 2024/1689, amended by (EU) 2026/1744",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk rules for AI; high-risk AI in regulated products applies from 2 August 2028.",
     "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published"
    }
   ],
   "dti": {
    "grade": 89,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-02-13",
     "headline": "Top court upholds fine over patient data passed on without true anonymisation",
     "paraphrase": "Doctors' software gathered patients' health data, such as prescriptions and sick leave, with identifiers that allowed care pathways to be traced. The court agreed the data were not anonymous and rejected the company's challenge to an 800,000 euro fine.",
     "source": "Conseil d'État",
     "url": "https://www.conseil-etat.fr/fr/arianeweb/CE/decision/2026-02-13/498628",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-02-20",
     "headline": "Court backs family's right to see hospital's adverse-event report on a relative",
     "paraphrase": "A hospital refused to give a woman the serious adverse-event report it filed after her brother died. The courts ordered release of the parts about his health and care, and the hospital's appeal was rejected.",
     "source": "Conseil d'État",
     "url": "https://www.conseil-etat.fr/fr/arianeweb/CE/decision/2025-02-20/493519",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2024-11-19",
     "headline": "Hospital records of about 750,000 people posted online after stolen login used",
     "paraphrase": "A hacker posted a database of about 758,000 people taken from hospital management software, including contact details, treating doctor, prescriptions and death declarations. The software maker said a privileged account at a client hospital was misused.",
     "source": "Clubic",
     "url": "https://www.clubic.com/actualite-544139-fichiers-et-dossiers-patients-sensibles-francais-en-fuite-sur-le-dark-web-que-se-passe-t-il.html",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-02-27",
     "headline": "Doctors' private notes on patients exposed in attack on medical software",
     "paraphrase": "Attackers reached files of 1,500 doctors using one practice software. Administrative data on 15 million patients leaked, and the health minister said sensitive doctor annotations on 164,000 patients were exposed. The vendor said structured medical records were intact.",
     "source": "franceinfo",
     "url": "https://www.franceinfo.fr/internet/securite-sur-internet/cyberattaques/quinze-millions-de-patients-concernes-1-500-medecins-vises-une-enquete-ouverte-ce-que-l-on-sait-de-la-cyberattaque-qui-a-cible-un-logiciel-medical_7833611.html",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-03-30",
     "headline": "Lab network says attackers reached patient analysis reports and social security numbers",
     "paraphrase": "A national lab network reported unauthorised access, through a server run by an outside IT supplier, to patient names, emails, encrypted passwords, analysis reports and social security numbers. It was the network's second attack in about a year.",
     "source": "Le Moniteur des pharmacies",
     "url": "https://www.lemoniteurdespharmacies.fr/business/numerique/digitalisation/cerballiance-une-cyberattaque-expose-les-donnees-de-millions-de-patients",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "NOR",
   "name": "Norway",
   "region": "Europe",
   "overall": 66,
   "rank": "6=",
   "likelyRank": "3 to 10",
   "band": "Strong",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Norwegians control a national core record with opt-out, blocks and a lookup log, but full notes rarely follow them between GP, hospital and municipality.",
   "categories": {
    "access": {
     "score": 68,
     "summary": "Norway has a statutory right to see and copy the whole record, and Helsenorge logged 104.7 million logins in 2025. But GP records are not on Helsenorge, and the Commission found imaging reports and images are not online at all.",
     "sources": [
      {
       "title": "Lov om pasient- og brukerrettigheter (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/1999-07-02-63/KAPITTEL_5",
       "date": "2026-06-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Om Pasientjournal (Helsenorge)",
       "url": "https://www.helsenorge.no/pasientjournal/om/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "2026 Digital Decade eHealth Indicator Study, Annex: Country Factsheets (European Commission)",
       "url": "https://op.europa.eu/en/publication-detail/-/publication/53637948-66ce-11f1-9b18-01aa75ed71a1/language-en",
       "date": "2026-06-17",
       "publisherClass": "intergov"
      },
      {
       "title": "Antall innlogginger på Helsenorge (Helsedirektoratet)",
       "url": "https://www.helsedirektoratet.no/statistikk/nasjonal-digitaliseringsmonitor/antall-innlogginger-pa-helsenorge--selvbetjeningslosninger",
       "date": "2026-04-28",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 74,
     "summary": "Patients can opt out of the national Kjernejournal, block all or some items, block named staff even in emergencies, and read a log of who looked. A 2026 law adds a right to see which data were shared, while widening direct access between providers.",
     "sources": [
      {
       "title": "Kjernejournal: spørsmål og svar (Norsk helsenett)",
       "url": "https://www.nhn.no/tjenester/kjernejournal/sporsmal-og-svar",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Lov om behandling av helseopplysninger ved ytelse av helsehjelp (pasientjournalloven) (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/2014-06-20-42",
       "date": "2026-01-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lov om pasient- og brukerrettigheter (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/1999-07-02-63/KAPITTEL_5",
       "date": "2026-06-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lov 23. januar 2026 nr. 1 om endringer i helsepersonelloven og pasientjournalloven mv. (Lovdata)",
       "url": "https://lovdata.no/dokument/LTI/lov/2026-01-23-1",
       "date": "2026-01-23",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "GDPR applies through the EEA, and the regulator found major gaps in the Helseplattformen record system in December 2025 after many breach reports. Health enforcement is mostly orders and reprimands: in 2025 an online pharmacy and a doctor service got reprimands for tracking pixels.",
     "sources": [
      {
       "title": "Varsel om pålegg om retting til Helseplattformen AS (Datatilsynet)",
       "url": "https://www.datatilsynet.no/aktuelt/aktuelle-nyheter-2025/varsel-om-palegg-til-helseplattformen-as/",
       "date": "2025-12-02",
       "publisherClass": "official"
      },
      {
       "title": "Ulovlig deling av personopplysninger gjennom sporingspiksler hos seks nettsteder (Datatilsynet)",
       "url": "https://www.datatilsynet.no/regelverk-og-verktoy/lover-og-regler/avgjorelser-fra-datatilsynet/2025/ulovlig-deling-av-personopplysninger-gjennom-sporingspiksler-hos-seks-nettsteder/",
       "date": "2025-06-12",
       "publisherClass": "official"
      },
      {
       "title": "Lov om helseregistre og behandling av helseopplysninger (helseregisterloven) (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/2014-06-20-43",
       "date": "2025-12-22",
       "publisherClass": "legal_text"
      },
      {
       "title": "Statsforvalteren åpner tilsyn etter snoking i pasientjournal ved Helgelandssykehuset (Dagens Medisin/NTB)",
       "url": "https://www.dagensmedisin.no/arbeidsliv-helgelandssykehuset-pasientjournal/statsforvalteren-apner-tilsyn-etter-snoking-i-pasientjournal-ved-helgelandssykehuset/726961",
       "date": "2026-01-12",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 66,
     "summary": "Kjernejournal is available in all hospitals and 90% of GP offices, and about 93% of prescriptions are electronic. But the shared medication list only began national rollout in 2026, Central Norway has not started it, and GP records do not feed the core record.",
     "sources": [
      {
       "title": "Kjernejournal: spørsmål og svar (Norsk helsenett)",
       "url": "https://www.nhn.no/tjenester/kjernejournal/sporsmal-og-svar",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Om e-resept (Norsk helsenett)",
       "url": "https://www.nhn.no/tjenester/e-resept/om-e-resept",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Plan og status for innføring av pasientens legemiddelliste (Helsedirektoratet)",
       "url": "https://www.helsedirektoratet.no/digitalisering-og-e-helse/pasientens-legemiddelliste/plan-for-utproving",
       "date": "2026-09-30",
       "publisherClass": "official"
      },
      {
       "title": "Det europeiske helsedataområdet: høring av gjennomføringsregelverk (Stortinget EU/EØS-nytt)",
       "url": "https://www.stortinget.no/no/Hva-skjer-pa-Stortinget/EU-EOS-informasjon/EU-EOS-nytt/2026/eueos-nytt---16.-april-2026/det-europeiske-helsedataomradet--horing-av-gjennomforingsregelverk/",
       "date": "2026-04-16",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 64,
     "summary": "The Health Registry Act bars registry data from going to employers, insurers or prosecutors even with the person's consent, and a 2026 law limits what insurers can get from records. We found no Norwegian ban on selling health data beyond GDPR.",
     "sources": [
      {
       "title": "Lov om helseregistre og behandling av helseopplysninger (helseregisterloven) (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/2014-06-20-43",
       "date": "2025-12-22",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lov om helsepersonell (helsepersonelloven) (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/1999-07-02-64",
       "date": "2026-01-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lov 23. januar 2026 nr. 1 om endringer i helsepersonelloven og pasientjournalloven mv. (Lovdata)",
       "url": "https://lovdata.no/dokument/LTI/lov/2026-01-23-1",
       "date": "2026-01-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ulovlig deling av personopplysninger gjennom sporingspiksler hos seks nettsteder (Datatilsynet)",
       "url": "https://www.datatilsynet.no/regelverk-og-verktoy/lover-og-regler/avgjorelser-fra-datatilsynet/2025/ulovlig-deling-av-personopplysninger-gjennom-sporingspiksler-hos-seks-nettsteder/",
       "date": "2025-06-12",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 68,
     "summary": "Any clinician with a work need can open Kjernejournal at every hospital and most GP offices, with an emergency override for blocks. Full notes from other providers stay hard to reach, since GP records are not shared and document sharing is early.",
     "sources": [
      {
       "title": "Kjernejournal: spørsmål og svar (Norsk helsenett)",
       "url": "https://www.nhn.no/tjenester/kjernejournal/sporsmal-og-svar",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Lov om helsepersonell (helsepersonelloven) (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/1999-07-02-64",
       "date": "2026-01-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Pasientens journaldokumenter: status og ambisjoner for innføring (Helsedirektoratet)",
       "url": "https://www.helsedirektoratet.no/digitalisering-og-e-helse/pasientens-journaldokumenter-pjd/status-og-ambisjoner-for-innforing",
       "date": "2026-03-18",
       "publisherClass": "official"
      },
      {
       "title": "Pasientens prøvesvar (Norsk helsenett)",
       "url": "https://www.nhn.no/tjenester/pasientens-provesvar",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Central health registries are used for research without consent or a general opt-out, inside permits, secrecy rules and criminal penalties. Some registries allow a partial opt-out, and the Health Data Service delivered data to 513 applicants and projects in 2025.",
     "sources": [
      {
       "title": "Lov om helseregistre og behandling av helseopplysninger (helseregisterloven) (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/2014-06-20-43",
       "date": "2025-12-22",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lov om medisinsk og helsefaglig forskning (helseforskningsloven) (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/2008-06-20-44",
       "date": "2025-06-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Reservasjonsrett i Kommunalt pasient- og brukerregister (FHI)",
       "url": "https://www.fhi.no/he/kpr/reservasjonsrett-i-kpr/",
       "date": "2024-03-05",
       "publisherClass": "official"
      },
      {
       "title": "Kortere behandlingstid og økt utlevering av helsedata i 2025 (FHI)",
       "url": "https://www.fhi.no/nyheter/2026/kortere-behandlingstid-og-okt-utlevering-av-data-i-2025/",
       "date": "2026-01-23",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device rules applied through the 2020 Medical Devices Act, but the EU AI Act is not yet part of the EEA Agreement. A Norwegian AI bill is planned for spring 2027, and health agencies offer guidance, not binding rules.",
     "sources": [
      {
       "title": "Lov om medisinsk utstyr (Lovdata)",
       "url": "https://lovdata.no/dokument/NL/lov/2020-05-07-37",
       "date": "2026-06-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Nye krav til KI-merking i EU: hva betyr dette for Norge? (Nkom)",
       "url": "https://nkom.no/ki/regulering/nye-krav-til-ki-merking-i-eu--hva-betyr-dette-for-norge",
       "date": "2026-08-10",
       "publisherClass": "official"
      },
      {
       "title": "Kunstig intelligens (Helsedirektoratet)",
       "url": "https://www.helsedirektoratet.no/digitalisering-og-e-helse/kunstig-intelligens",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Patient and User Rights Act (pasient- og brukerrettighetsloven)",
     "level": "National",
     "year": "1999",
     "what": "Right to see and copy the whole record (section 5-1); right to object to sharing (section 5-3).",
     "url": "https://lovdata.no/dokument/NL/lov/1999-07-02-63/KAPITTEL_5"
    },
    {
     "name": "Patient Records Act (pasientjournalloven)",
     "level": "National",
     "year": "2014",
     "what": "Basis for Kjernejournal with opt-out (sections 13, 17); disclosure log patients can see (section 22 a).",
     "url": "https://lovdata.no/dokument/NL/lov/2014-06-20-42"
    },
    {
     "name": "Health Registry Act (helseregisterloven)",
     "level": "National",
     "year": "2014",
     "what": "Central registries without consent; 30 or 60 working day release deadlines; no data to employers or insurers.",
     "url": "https://lovdata.no/dokument/NL/lov/2014-06-20-43"
    },
    {
     "name": "Act of 23 January 2026 no. 1 on secrecy and sharing of patient data",
     "level": "National",
     "year": "2026",
     "what": "From 1 July 2026, widens direct access between providers and requires logs of shared data.",
     "url": "https://lovdata.no/dokument/LTI/lov/2026-01-23-1"
    },
    {
     "name": "Health Research Act (helseforskningsloven)",
     "level": "National",
     "year": "2008",
     "what": "Consent as main rule for health research; public list of projects; amendments in force 1 November 2026.",
     "url": "https://lovdata.no/dokument/NL/lov/2008-06-20-44"
    },
    {
     "name": "Medical Devices Act (lov om medisinsk utstyr)",
     "level": "National",
     "year": "2020",
     "what": "Applies the EU device regulations (MDR, IVDR) in Norway, covering medical AI software.",
     "url": "https://lovdata.no/dokument/NL/lov/2020-05-07-37"
    },
    {
     "name": "General Data Protection Regulation (via EEA Agreement)",
     "level": "Supranational",
     "year": "2016",
     "what": "Health data as special category; access rights; fines enforced by Datatilsynet.",
     "url": "https://lovdata.no/dokument/NL/lov/2018-06-15-38"
    }
   ],
   "dti": {
    "grade": 86,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-06-11",
     "headline": "Doctors warn records moved to new system arrive with missing documents and wrong dates",
     "paraphrase": "Doctors said moving 25 years of patient records into a new system produced missing documents, absent operation notes and wrong dates. The regional health authority confirmed only about half of 200 million documents had been moved.",
     "source": "NRK",
     "url": "https://www.nrk.no/mr/legar-i-midt-noreg-fryktar-overforing-av-data-til-helseplattforma-trugar-pasient-tryggleiken-1.17437171",
     "theme": "record_wrong",
     "status": "admitted"
    },
    {
     "date": "2025-06-16",
     "headline": "System change missed messages from outside hospitals in thousands of patient cases",
     "paraphrase": "A record-system change made in 2023 failed to flag certain messages about discharge reports from other hospitals and specialists. Hospitals identified 3,445 cases needing review. The hospital said an early check found some needed follow-up.",
     "source": "VG",
     "url": "https://www.vg.no/nyheter/i/kw9yaX/to-aar-gammel-endring-i-helseplattformen-kan-ha-rammet-pasienter",
     "theme": "lost_between_providers",
     "status": "admitted"
    },
    {
     "date": "2025-09-10",
     "headline": "Municipal employee read patient records without reason for about 15 years",
     "paraphrase": "A random audit found an employee had looked into municipal care records without a work reason for around 15 years, affecting about 2,100 residents. The municipality reported it to police and said it saw no sign of onward sharing.",
     "source": "NRK",
     "url": "https://www.nrk.no/nordland/vefsn-kommune_-ansatt-snek-i-pasientjournaler-i-15-ar-1.17565826",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-04-15",
     "headline": "Patient spotted repeated snooping in their own access log; regulator found breaches",
     "paraphrase": "A patient saw in the national health portal that a hospital worker had opened their record on several dates without reason. The county governor found clear breaches of confidentiality but closed the case without sanction.",
     "source": "NRK",
     "url": "https://www.nrk.no/sorlandet/sykehusansatt-snoket-i-pasientjournal---slipper-straff-1.17846230",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-12-02",
     "headline": "Regulator finds significant privacy failings in a regional patient record system",
     "paraphrase": "After complaints and breach reports, the data protection authority inspected the record system used by hospitals and municipalities in central Norway. It found significant deficiencies, privacy breaches and unclear responsibilities, and gave notice of a correction order.",
     "source": "Dagens Medisin (NTB)",
     "url": "https://www.dagensmedisin.no/datatilsynet-e-helse-helse-midt-norge-rhf/datatilsynet-kritiserer-helseplattformen-etter-tilsyn-varsler-palegg-om-retting/720948",
     "theme": "other",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "AUT",
   "name": "Austria",
   "region": "Europe",
   "overall": 65,
   "rank": "9",
   "likelyRank": "5 to 13",
   "band": "Strong",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Austria's opt-out ELGA record gives strong controls and a full access log, but holds reports and medicines, not complete charts, and few use it.",
   "categories": {
    "access": {
     "score": 63,
     "summary": "Patients have a statutory right to see their records and get a free first copy, and the ELGA portal shows discharge letters, lab and radiology reports and 18 months of medicines. Images, GP notes and documents from before 2016 are missing, and uptake is low.",
     "sources": [
      {
       "title": "Ärztegesetz 1998 § 51 Dokumentationspflicht und Auskunftserteilung (RIS)",
       "url": "https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10011138&Paragraf=51",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "ELGA-Portal FAQ (ELGA GmbH)",
       "url": "https://www.elga.gv.at/faq/elga-portal/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Mit einer App die eigenen Befunde und Röntgenbilder sehen (Die Presse)",
       "url": "https://www.diepresse.com/20620100/mit-einer-app-die-eigenen-befunde-und-roentgenbilder-sehen",
       "date": "2026-02-24",
       "publisherClass": "news"
      },
      {
       "title": "ELGA soll aus Dornröschenschlaf erwachen (Kronen Zeitung)",
       "url": "https://www.krone.at/3791556",
       "date": "2025-05-22",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 72,
     "summary": "Everyone is in ELGA unless they opt out, fully or for e-reports or e-medication, and patients can hide or delete single documents, block a provider and read a full access log. There is no opt-out from the e-vaccination record or e-prescriptions.",
     "sources": [
      {
       "title": "Gesundheitstelematikgesetz 2012, consolidated text (RIS)",
       "url": "https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=20008120",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "ELGA-Portal FAQ (ELGA GmbH)",
       "url": "https://www.elga.gv.at/faq/elga-portal/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "ELGA: Login und Teilnahme gestalten (Gesundheitsportal)",
       "url": "https://www.gesundheit.gv.at/gesundheitsleistungen/elga/elga-login-teilnahme.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Elektronische Gesundheitsakte ELGA und ELGA GmbH, Bericht 2024/32 (Rechnungshof)",
       "url": "https://www.rechnungshof.gv.at/rh/home/home/2024_32_ELGA.pdf",
       "date": "2024-10-31",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 63,
     "summary": "ELGA data may be used only for treatment, insurers and employers are barred by law, and unauthorised access carries fines up to EUR 10,000. But Austrian law forbids GDPR fines on public bodies and bodies acting under a legal mandate, and the regulator reports fewer staff.",
     "sources": [
      {
       "title": "Gesundheitstelematikgesetz 2012, consolidated text (RIS)",
       "url": "https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=20008120",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Datenschutzgesetz, consolidated text (RIS)",
       "url": "https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10001597",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Newsletter der Datenschutzbehörde Nr. 1/2026 (DSB)",
       "url": "https://dsb.gv.at/sites/site0344/media/downloads/nl0126bf.pdf",
       "date": "2026",
       "publisherClass": "official"
      },
      {
       "title": "DSB Bescheid 2025-0.745.017, video surveillance in operating theatres (RIS)",
       "url": "https://ris.bka.gv.at/Dokumente/Dsk/DSBT_20260225_2025_0_745_017_00/DSBT_20260225_2025_0_745_017_00.pdf",
       "date": "2026-02-25",
       "publisherClass": "official"
      }
     ]
    },
    "journey": {
     "score": 68,
     "summary": "Public hospitals, care homes, pharmacies and contracted doctors use ELGA, e-prescriptions replaced paper prescriptions, and outpatient labs and radiology must upload since July 2025. Specialist reports are not due until 2030 and there is no patient summary yet.",
     "sources": [
      {
       "title": "Radiologie- und Laborbefunde ab Juli in der ELGA verfügbar (Sozialministerium)",
       "url": "https://www.sozialministerium.gv.at/Services/Aktuelles/Archiv-2025/ELGA-befunde.html",
       "date": "2025-01-28",
       "publisherClass": "official"
      },
      {
       "title": "Ärztegesetz 1998 § 49 (RIS)",
       "url": "https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10011138&Paragraf=49",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "ELGA-News: EU-Rezept, e-Impfpass, e-Bilddaten (ELGA GmbH)",
       "url": "https://www.elga.gv.at/news/",
       "date": "2026-02",
       "publisherClass": "official"
      },
      {
       "title": "Patient Summary soll Versorgung erleichtern (medianet)",
       "url": "https://medianet.at/news/health-economy/patient-summary-soll-versorgung-erleichtern-76589.html",
       "date": "2026-09-07",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 66,
     "summary": "Austrian law bars insurers and employers from using genetic test results, restricts how private insurers gather health data, and bans demands for ELGA data. No Austrian rule specific to health data brokers or consumer health apps was found.",
     "sources": [
      {
       "title": "Gentechnikgesetz § 67 (RIS)",
       "url": "https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10010826&Paragraf=67",
       "date": "2017-01-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Versicherungsvertragsgesetz § 11a (RIS)",
       "url": "https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10001979&Artikel=&Paragraf=11a&Anlage=&Uebergangsrecht=",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Gesundheitstelematikgesetz 2012, consolidated text (RIS)",
       "url": "https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=20008120",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Der EHDS: Neue Regeln für Gesundheitsdaten (Haslinger / Nagele)",
       "url": "https://www.haslinger-nagele.com/der-ehds-neue-regeln-fuer-gesundheitsdaten-ueberblick-und-ausblick/",
       "date": "undated",
       "publisherClass": "law_firm"
      }
     ]
    },
    "clinical": {
     "score": 66,
     "summary": "Once a patient's e-card is read, doctors, hospitals and care homes can open ELGA for 90 days, and pharmacies and ambulance services see the medication list for 28 days. They see reports and medicines, not other providers' full charts.",
     "sources": [
      {
       "title": "Allgemeines zu ELGA (oesterreich.gv.at, Sozialministerium)",
       "url": "https://www.oesterreich.gv.at/de/themen/gesundheit/elektronisches-gesundheitssystem/elga_elektronische_gesundheitsakte/Seite.3110001",
       "date": "2026-08-26",
       "publisherClass": "official"
      },
      {
       "title": "Gesundheitstelematikgesetz 2012, consolidated text (RIS)",
       "url": "https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=20008120",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "ELGA-News: EU-Rezept, e-Impfpass, e-Bilddaten (ELGA GmbH)",
       "url": "https://www.elga.gv.at/news/",
       "date": "2026-02",
       "publisherClass": "official"
      },
      {
       "title": "Patient Summary soll Versorgung erleichtern (medianet)",
       "url": "https://medianet.at/news/health-economy/patient-summary-soll-versorgung-erleichtern-76589.html",
       "date": "2026-09-07",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "Registers are opened for research by decree, without consent or a general opt-out, through a secure Statistik Austria data centre with accredited institutions and a public project list. ELGA data are barred from research, and the health ministry has not opened its registers.",
     "sources": [
      {
       "title": "Anfragebeantwortung 4833/AB zu Registerdaten im AMDC (Bundeskanzler)",
       "url": "https://www.parlament.gv.at/dokument/XXVIII/AB/4833/imfname_1758088.pdf",
       "date": "2026-05-19",
       "publisherClass": "official"
      },
      {
       "title": "Austrian Micro Data Center (Statistik Austria)",
       "url": "https://www.statistik.at/services/tools/datenzugang/center-wissenschaft/austrian-micro-data-center-amdc",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Registerforschung (Wissenschaftsministerium BMFWF)",
       "url": "https://www.bmfwf.gv.at/forschung/forschung-oesterreich/strategische-ausrichtung-beratende-gremien/leitthemen/registerforschung.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI in Austria falls under EU device law and the EU AI Act only. No national clinical-AI rule was found, and the data protection authority wrote in 2026 that Austria had not yet named its AI Act market surveillance authorities.",
     "sources": [
      {
       "title": "AI Act: regulatory framework for AI (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "KI-Verordnung (Digital Austria, Bundeskanzleramt)",
       "url": "https://www.digitalaustria.gv.at/themen/kuenstliche-intelligenz/ai-act.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Newsletter der Datenschutzbehörde Nr. 1/2026 (DSB)",
       "url": "https://dsb.gv.at/sites/site0344/media/downloads/nl0126bf.pdf",
       "date": "2026",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Gesundheitstelematikgesetz 2012 (GTelG 2012)",
     "level": "National",
     "year": "2012",
     "what": "ELGA legal base: opt-out, document hiding, access log, ban on non-care use, fines up to EUR 10,000.",
     "url": "https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=20008120"
    },
    {
     "name": "Datenschutzgesetz (DSG)",
     "level": "National",
     "year": "2018",
     "what": "Austrian GDPR companion law; research rules in § 7; no fines on public bodies under § 30(5).",
     "url": "https://www.ris.bka.gv.at/GeltendeFassung.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10001597"
    },
    {
     "name": "Ärztegesetz 1998, §§ 49 and 51",
     "level": "National",
     "year": "1998",
     "what": "Doctors must give a free first copy of records and use ELGA by 1 January 2026.",
     "url": "https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10011138&Paragraf=51"
    },
    {
     "name": "Krankenanstalten- und Kuranstaltengesetz (KAKuG) § 10, with state hospital acts",
     "level": "National",
     "year": "2018",
     "what": "Federal framework: states must make hospitals keep records 30 years and grant patients inspection and copies.",
     "url": "https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10010285&Paragraf=10"
    },
    {
     "name": "Wiener Krankenanstaltengesetz 1987, § 17a",
     "level": "State/Provincial",
     "year": "1987",
     "what": "Vienna patient rights in hospitals, including inspection and a copy of the record against cost.",
     "url": "https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=LrW&Gesetzesnummer=20000282&Paragraf=17a"
    },
    {
     "name": "Gentechnikgesetz § 67",
     "level": "National",
     "year": "1994",
     "what": "Bars employers and insurers from requesting or using genetic test results.",
     "url": "https://www.ris.bka.gv.at/NormDokument.wxe?Abfrage=Bundesnormen&Gesetzesnummer=10010826&Paragraf=67"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient access and control rights, opt-out from secondary use; key parts apply from March 2029.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    }
   ],
   "dti": {
    "grade": 88,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-10-20",
     "headline": "Hospital security manager copied a patient's record and emailed it to police",
     "paraphrase": "A patient learned during a court case that a hospital report about them had reached third parties. The regulator found the hospital's security manager had copied the electronic record and emailed it to police. The court upheld that finding.",
     "source": "Federal Administrative Court (Bundesverwaltungsgericht), W108 2276075-1, upholding a Datenschutzbehörde decision",
     "url": "https://www.ris.bka.gv.at/Dokumente/Bvwg/BVWGT_20251020_W108_2276075_1_00/BVWGT_20251020_W108_2276075_1_00.html",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-08-21",
     "headline": "Doctor opened an employee's national e-health record without consent; regulator fined her",
     "paraphrase": "A practice assistant found through the ELGA access log that her employer, a doctor, had opened her stored results and medication data without her consent. The regulator found a violation and imposed a 1,000 euro fine.",
     "source": "Datenschutzbehörde (Austrian Data Protection Authority), penal decision 2025-0.625.944",
     "url": "https://www.ris.bka.gv.at/Dokumente/Dsk/DSBT_20250821_2025_0_625_944_00/DSBT_20250821_2025_0_625_944_00.html",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-01-09",
     "headline": "Therapy centre left handwritten notes out of a patient's access request",
     "paraphrase": "A patient asked a therapy centre for all data held about them. The centre left out notes a staff member kept by hand. The regulator found this breached the right of access and ordered full disclosure within four weeks.",
     "source": "Datenschutzbehörde (Austrian Data Protection Authority), decision 2026-0.018.391",
     "url": "https://www.ris.bka.gv.at/Dokumente/Dsk/DSBT_20260109_2026_0_018_391_00/DSBT_20260109_2026_0_018_391_00.html",
     "theme": "access_refused",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "PRT",
   "name": "Portugal",
   "region": "Europe",
   "overall": 64,
   "rank": "10",
   "likelyRank": "6 to 15",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Portugal's SNS 24 shows patients who opened their record and asks consent before clinicians look; a May 2026 credential theft tested both.",
   "categories": {
    "access": {
     "score": 70,
     "summary": "Portugal scored 88.1 on the EU 2025 record-access indicator against an EU average of 82.7, and SNS 24 shows prescriptions, lab results, vaccines and five years of care history. Lei 12/2005 gives a right to the whole record, but the portal is not the full chart.",
     "sources": [
      {
       "title": "Portugal 2025 Digital Decade country report (Council of the EU, ST 10407/25 ADD 23)",
       "url": "https://data.consilium.europa.eu/doc/document/ST-10407-2025-ADD-23/en/pdf",
       "date": "2025-06-18",
       "publisherClass": "intergov"
      },
      {
       "title": "State of Health in the EU: Portugal Country Health Profile 2025 (OECD and European Observatory)",
       "url": "https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/12/country-health-profile-2025-country-notes_7e72146d/portugal_6d4acb43/56041c8e-en.pdf",
       "date": "2025-12",
       "publisherClass": "intergov"
      },
      {
       "title": "Lei n.º 12/2005, informação genética pessoal e informação de saúde (PGD Lisboa, consolidated)",
       "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=1660&tabela=leis&ficha=1&pagina=1",
       "date": "2005-01-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Direito de acesso à informação de saúde e à proteção de dados pessoais (ERS)",
       "url": "https://www.ers.pt/pt/utentes/perguntas-frequentes/faq/direito-de-acesso-a-informacao-de-saude-e-a-protecao-de-dados-pessoais/",
       "date": "2025-02-26",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 70,
     "summary": "Clinicians cannot open the national record without the patient's authorisation, set in SNS 24 or given at the visit, and patients can see every access. Lei 58/2019 requires that people be notified of any access to their health data.",
     "sources": [
      {
       "title": "Lei n.º 58/2019, execução do RGPD (Diário da República)",
       "url": "https://files.diariodarepublica.pt/1s/2019/08/15100/0000300040.pdf",
       "date": "2019-08-08",
       "publisherClass": "legal_text"
      },
      {
       "title": "Manual do Utilizador: acesso à Área do Profissional do RSE para médicos e enfermeiros (ACSS/SPMS)",
       "url": "https://www.acss.min-saude.pt/wp-content/uploads/2016/12/Manual-de-Utilizador-RSE-PCPMACNO_VF.pdf",
       "date": "2025-04-15",
       "publisherClass": "official"
      },
      {
       "title": "SNS 24: saiba quem teve acesso às suas informações e como gerir autorizações (Pplware)",
       "url": "https://pplware.sapo.pt/internet/sns-24-saiba-quem-teve-acesso-as-suas-informacoes-e-como-gerir-autorizacoes/",
       "date": "2026-05-26",
       "publisherClass": "news"
      },
      {
       "title": "ULS do Alto Minho admite roubo de credenciais médicas para aceder a dados de utentes (HealthNews)",
       "url": "https://healthnews.pt/2026/05/22/uls-do-alto-minho-admite-roubo-de-credenciais-medicas-para-aceder-a-dados-de-utentes/",
       "date": "2026-05-22",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 56,
     "summary": "Health data has strong statutory protection, but in May 2026 a doctor's stolen credentials were used to improperly access data of more than 100,000 SNS users. The regulator CNPD opened an inquiry and reported possible crimes to prosecutors.",
     "sources": [
      {
       "title": "Lei n.º 58/2019, execução do RGPD (Diário da República)",
       "url": "https://files.diariodarepublica.pt/1s/2019/08/15100/0000300040.pdf",
       "date": "2019-08-08",
       "publisherClass": "legal_text"
      },
      {
       "title": "Comissão Nacional de Proteção de Dados averigua acesso indevido a dados de saúde (ECO)",
       "url": "https://eco.sapo.pt/2026/05/26/comissao-nacional-de-protecao-de-dados-averigua-acesso-indevido-a-dados-de-saude/",
       "date": "2026-05-26",
       "publisherClass": "news"
      },
      {
       "title": "ULS do Alto Minho admite roubo de credenciais médicas para aceder a dados de utentes (HealthNews)",
       "url": "https://healthnews.pt/2026/05/22/uls-do-alto-minho-admite-roubo-de-credenciais-medicas-para-aceder-a-dados-de-utentes/",
       "date": "2026-05-22",
       "publisherClass": "news"
      },
      {
       "title": "Hospital do Barreiro multado em 400 mil euros por não proteger dados clínicos dos doentes (Jornal de Negócios)",
       "url": "https://www.jornaldenegocios.pt/economia/saude/detalhe/hospital-do-barreiro-multado-em-400-mil-euros-por-nao-proteger-dados-clinicos-dos-doentes",
       "date": "2018-10-18",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 68,
     "summary": "A central agency, SPMS, gives every public provider and most private ones a common data centre, network and software, and the RSE timeline lists episodes from all SNS institutions. Private providers have no legal duty to share records.",
     "sources": [
      {
       "title": "State of Health in the EU: Portugal Country Health Profile 2025 (OECD and European Observatory)",
       "url": "https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/12/country-health-profile-2025-country-notes_7e72146d/portugal_6d4acb43/56041c8e-en.pdf",
       "date": "2025-12",
       "publisherClass": "intergov"
      },
      {
       "title": "Manual do Utilizador: acesso à Área do Profissional do RSE para médicos e enfermeiros (ACSS/SPMS)",
       "url": "https://www.acss.min-saude.pt/wp-content/uploads/2016/12/Manual-de-Utilizador-RSE-PCPMACNO_VF.pdf",
       "date": "2025-04-15",
       "publisherClass": "official"
      },
      {
       "title": "Lei n.º 95/2019, Lei de Bases da Saúde (PGD Lisboa)",
       "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=3197&tabela=leis&ficha=1",
       "date": "2019-09-04",
       "publisherClass": "legal_text"
      }
     ]
    },
    "commercial": {
     "score": 62,
     "summary": "Lei 12/2005 says health information may be used only for care, health research and other uses set by law, and bans insurers from using genetic data. A 2021 law stops lenders and insurers using past cancer and other overcome conditions.",
     "sources": [
      {
       "title": "Lei n.º 12/2005, informação genética pessoal e informação de saúde (PGD Lisboa, consolidated)",
       "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=1660&tabela=leis&ficha=1&pagina=1",
       "date": "2005-01-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lei n.º 75/2021, direito ao esquecimento no crédito e nos seguros (PGD Lisboa)",
       "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=3478&tabela=leis",
       "date": "2021-11-18",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 64,
     "summary": "With the patient's authorisation, a doctor or nurse sees a timeline of episodes from every SNS institution and can open each source record over the health network. Data held only by private providers is often missing.",
     "sources": [
      {
       "title": "Manual do Utilizador: acesso à Área do Profissional do RSE para médicos e enfermeiros (ACSS/SPMS)",
       "url": "https://www.acss.min-saude.pt/wp-content/uploads/2016/12/Manual-de-Utilizador-RSE-PCPMACNO_VF.pdf",
       "date": "2025-04-15",
       "publisherClass": "official"
      },
      {
       "title": "Lei n.º 12/2005, informação genética pessoal e informação de saúde (PGD Lisboa, consolidated)",
       "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=1660&tabela=leis&ficha=1&pagina=1",
       "date": "2005-01-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "State of Health in the EU: Portugal Country Health Profile 2025 (OECD and European Observatory)",
       "url": "https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/12/country-health-profile-2025-country-notes_7e72146d/portugal_6d4acb43/56041c8e-en.pdf",
       "date": "2025-12",
       "publisherClass": "intergov"
      }
     ]
    },
    "research": {
     "score": 48,
     "summary": "Anonymised health data may be used for research without individual consent under Lei 12/2005, and no general opt-out exists yet. Trials need informed consent and ethics approval, and Portugal was first to list a dataset on HealthData@EU.",
     "sources": [
      {
       "title": "Lei n.º 12/2005, informação genética pessoal e informação de saúde (PGD Lisboa, consolidated)",
       "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=1660&tabela=leis&ficha=1&pagina=1",
       "date": "2005-01-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lei n.º 58/2019, execução do RGPD (Diário da República)",
       "url": "https://files.diariodarepublica.pt/1s/2019/08/15100/0000300040.pdf",
       "date": "2019-08-08",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lei n.º 21/2014, lei da investigação clínica (PGD Lisboa)",
       "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=2089&tabela=leis",
       "date": "2014-04-16",
       "publisherClass": "legal_text"
      },
      {
       "title": "European Health Data Space Regulation (EHDS) (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Portugal relies on EU law for clinical AI, with no national AI law. ANACOM supervises the AI Act and the health regulator ERS protects fundamental rights for high-risk AI, both EU-required roles.",
     "sources": [
      {
       "title": "Regulamento da Inteligência Artificial (ERS)",
       "url": "https://www.ers.pt/pt/atividade/regulamento-da-inteligencia-artificial/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Anacom escolhida pelo Governo para regular inteligência artificial em Portugal (ECO)",
       "url": "https://eco.sapo.pt/2025/09/19/anacom-escolhida-pelo-governo-para-regular-inteligencia-artificial-em-portugal/",
       "date": "2025-09-19",
       "publisherClass": "news"
      },
      {
       "title": "State of Health in the EU: Portugal Country Health Profile 2025 (OECD and European Observatory)",
       "url": "https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/12/country-health-profile-2025-country-notes_7e72146d/portugal_6d4acb43/56041c8e-en.pdf",
       "date": "2025-12",
       "publisherClass": "intergov"
      },
      {
       "title": "Digital Omnibus on AI has been published (Regulation (EU) 2026/1744) (Cuatrecasas)",
       "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published",
       "date": "2026-07-24",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Lei n.º 12/2005, informação genética pessoal e informação de saúde",
     "level": "National",
     "year": "2005",
     "what": "Health data belongs to the person; right to the whole record; insurers barred from genetic data.",
     "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=1660&tabela=leis&ficha=1&pagina=1"
    },
    {
     "name": "Lei n.º 58/2019, execução do RGPD",
     "level": "National",
     "year": "2019",
     "what": "Applies GDPR; health data need to know, secrecy duty, and notice to people of every access.",
     "url": "https://files.diariodarepublica.pt/1s/2019/08/15100/0000300040.pdf"
    },
    {
     "name": "Lei n.º 95/2019, Lei de Bases da Saúde",
     "level": "National",
     "year": "2019",
     "what": "Health information is the person's property; SNS systems must interoperate.",
     "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=3197&tabela=leis&ficha=1"
    },
    {
     "name": "Lei n.º 75/2021, direito ao esquecimento",
     "level": "National",
     "year": "2021",
     "what": "Lenders and linked insurers may not use overcome serious health conditions after set periods.",
     "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=3478&tabela=leis"
    },
    {
     "name": "Lei n.º 21/2014, lei da investigação clínica",
     "level": "National",
     "year": "2014",
     "what": "Clinical studies need informed consent, ethics approval, withdrawal rights and insurance.",
     "url": "https://www.pgdlisboa.pt/leis/lei_mostra_articulado.php?nid=2089&tabela=leis"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Access logs, restrictions and secondary-use opt-out; exchange from March 2029 and 2031.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "EU AI Act (EU) 2024/1689, amended by (EU) 2026/1744",
     "level": "Supranational",
     "year": "2024",
     "what": "High-risk AI duties now apply from December 2027, and August 2028 for medical devices.",
     "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj"
    }
   ],
   "dti": {
    "grade": 93,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-07-29",
     "headline": "Hospital admitted staff outside the care team opened a patient's record",
     "paraphrase": "A family member with power of attorney obtained the record's access log and found entries by staff outside the care team. The hospital admitted improper access but withheld names; the commission said the names must be given.",
     "source": "Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 392/2026",
     "url": "https://www.cada.pt/files/pareceres/2026/392.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-07-29",
     "headline": "Hospital demanded an ID card copy before releasing a patient's records to their lawyer",
     "paraphrase": "A patient's lawyer asked for certified copies of the full record with a signed special power of attorney. The hospital insisted on a copy of the patient's ID card and ignored the commission; it ruled the demand unjustified.",
     "source": "Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 406/2026",
     "url": "https://www.cada.pt/files/pareceres/2026/406.pdf",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2026-01-28",
     "headline": "Patient says hospital resent the same report with only a new date",
     "paraphrase": "A patient in the Algarve asked for a clinical report needed to seek care abroad. After no reply, the hospital resent an earlier report with only the date changed; the commission told it to supply anything missing.",
     "source": "Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 48/2026",
     "url": "https://www.cada.pt/files/pareceres/2026/048.pdf",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-12-17",
     "headline": "Hospital ignored repeated requests for a patient's own records and the regulator",
     "paraphrase": "A patient asked a public hospital group several times for her own clinical records without success. The hospital did not answer the commission either; it ruled the records must be released, or their absence explained.",
     "source": "Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 481/2025",
     "url": "https://www.cada.pt/files/pareceres/2025/481.pdf",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2025-11-19",
     "headline": "Part of a patient's file stayed missing despite repeated requests",
     "paraphrase": "A patient in Madeira received some records but, after repeated requests, a key part of the file was still missing. The health service did not reply to the commission, which ruled it must provide the records or justify refusal.",
     "source": "Comissão de Acesso aos Documentos Administrativos (CADA), Parecer 437/2025",
     "url": "https://www.cada.pt/files/pareceres/2025/437.pdf",
     "theme": "access_delay_or_cost",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "BEL",
   "name": "Belgium",
   "region": "Europe",
   "overall": 63,
   "rank": "11=",
   "likelyRank": "8 to 20",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Belgian records are indexed unless patients object, providers need consent to open them, and patients can block named doctors and see who looked.",
   "categories": {
    "access": {
     "score": 68,
     "summary": "The law gives a free first copy, paper or electronic, within 15 days, and the EU rates Belgian record access 100 out of 100. The federal portal shows linked documents, not one full record, and French speakers cannot see vaccines or test results in the app.",
     "sources": [
      {
       "title": "Loi du 22 août 2002 relative aux droits du patient, version consolidée (Justel)",
       "url": "https://www.ejustice.just.fgov.be/eli/loi/2002/08/22/2002022737/justel",
       "date": "2002-08-22",
       "publisherClass": "legal_text"
      },
      {
       "title": "Masanté : consultez et gérez vos données de santé en ligne et via notre application mobile (INAMI)",
       "url": "https://www.inami.fgov.be/fr/themes/esante/masante-consultez-et-gerez-vos-donnees-de-sante-en-ligne-et-via-notre-application-mobile",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Digital Decade 2026 country report, Belgium, SWD(2026) 155 (European Commission)",
       "url": "https://ec.europa.eu/newsroom/dae/redirection/document/128636",
       "date": "2026-06-17",
       "publisherClass": "intergov"
      },
      {
       "title": "Abrumet soupçonne une volonté fédérale de centraliser les réseaux de santé (Le Spécialiste)",
       "url": "https://www.lespecialiste.be/fr/actualites/e-health/abrumet-soupconne-une-volonte-federale-de-centraliser-les-reseaux-de-sante.html",
       "date": "2026-06-23",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 72,
     "summary": "The national index lists where a patient's data sits unless the patient objects, but another provider may open it only with revocable consent. Patients can exclude named providers and see who consulted their data; exclusion works only name by name.",
     "sources": [
      {
       "title": "Loi du 22 avril 2019 relative à la qualité de la pratique des soins de santé (Justel)",
       "url": "https://www.ejustice.just.fgov.be/eli/loi/2019/04/22/2019041141/justel",
       "date": "2019-04-22",
       "publisherClass": "legal_text"
      },
      {
       "title": "Wet van 21 augustus 2008 houdende oprichting en organisatie van het eHealth-platform, gecoördineerde tekst (eHealth-platform)",
       "url": "https://www.ehealth.fgov.be/ehealthplatform/nl/wet-van-21-augustus-2008-houdende-oprichting-en-organisatie-van-het-ehealth-platform",
       "date": "2023-12-06",
       "publisherClass": "official"
      },
      {
       "title": "Privacy Notice (eHealth-platform)",
       "url": "https://www.ehealth.fgov.be/ehealthplatform/nl/privacy-notice",
       "date": "2021-06",
       "publisherClass": "official"
      },
      {
       "title": "Retrait de l'AR sur l'accès aux données de santé (ABSyM)",
       "url": "https://www.absym-bvas.be/fr/actualite/retrait-de-lar-sur-lacces-aux-donnees-de-sante-confirmation-de-preoccupations-legitimes",
       "date": "2026-04-27",
       "publisherClass": "blog_vendor"
      }
     ]
    },
    "privacy": {
     "score": 54,
     "summary": "The data protection authority acts on hospital cases, but in 2025 it imposed only four fines totalling 75,700 euros, and a court cut a hospital ransomware fine from 200,000 to 50,000 euros. In January 2026 a supplier flaw exposed identity data of about 71,000 hospital patients.",
     "sources": [
      {
       "title": "Loi du 30 juillet 2018 relative à la protection des personnes physiques à l'égard des traitements de données à caractère personnel (etaamb)",
       "url": "https://etaamb.openjustice.be/fr/loi-du-30-juillet-2018_n2018040581.html",
       "date": "2018-07-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Rapport annuel 2025 (Autorité de protection des données)",
       "url": "https://www.autoriteprotectiondonnees.be/index.php/publications/rapport-annuel-2025.pdf",
       "date": "2026-03-04",
       "publisherClass": "official"
      },
      {
       "title": "Décision quant au fond 209/2025 du 18 décembre 2025 (Chambre Contentieuse, APD)",
       "url": "https://autoriteprotectiondonnees.be/publications/decision-quant-au-fond-n0-209-2025.pdf",
       "date": "2025-12-18",
       "publisherClass": "official"
      },
      {
       "title": "Ook bij 3 andere Vlaamse ziekenhuizen lag toegang tot patiëntengegevens open voor hackers (VRT NWS)",
       "url": "https://www.vrt.be/vrtnws/nl/2026/01/14/ziekenhuizen-cyberaanval-impact/",
       "date": "2026-01-14",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 68,
     "summary": "A national metahub indexes which regional hub holds a patient's documents, and electronic prescribing is mandatory for most outpatient prescriptions. Data stays decentralised and largely document-based, and the structured integrated record is planned for 2027 to 2029.",
     "sources": [
      {
       "title": "Verwijzingsrepertorium (Metahub) (eHealth-platform)",
       "url": "https://www.ehealth.fgov.be/ehealthplatform/nl/service-verwijzingsrepertorium-metahub",
       "date": "2025-10-09",
       "publisherClass": "official"
      },
      {
       "title": "Geneesmiddelen verplicht elektronisch voorschrijven (RIZIV)",
       "url": "https://www.riziv.fgov.be/nl/thema-s/verzorging-kosten-en-terugbetaling/wat-het-ziekenfonds-terugbetaalt/geneesmiddelen/geneesmiddel-voorschrijven/geneesmiddelen-verplicht-elektronisch-voorschrijven",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "BIHR (Belgian Integrated Health Record) : un système d'information intégré pour des soins de qualité (INAMI)",
       "url": "https://www.inami.fgov.be/fr/themes/esante/bihr-belgian-integrated-health-record-un-systeme-d-information-integre-pour-des-soins-de-qualite",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "E-gezondheid: het plan wordt al uitgevoerd zonder te wachten op de formele goedkeuring (Medi-Sfeer)",
       "url": "https://www.medi-sfeer.be/nl/nieuws/e-health/e-gezondheid-het-plan-wordt-al-uitgevoerd-zonder-te-wachten-op-de-formele-goedkeuring.html",
       "date": "2026-06-04",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 54,
     "summary": "Insurers may not receive genetic data or use genetic tests to predict future health, but the 2023 Health Data Agency law covers reuse for commercial as well as non-commercial purposes. A Belgian ban on selling health data beyond the GDPR was not verified.",
     "sources": [
      {
       "title": "Loi du 4 avril 2014 relative aux assurances, articles 58 et 61 (etaamb)",
       "url": "https://etaamb.openjustice.be/fr/loi-du-04-avril-2014_n2014011239.html",
       "date": "2014-04-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "Wet van 14 maart 2023 houdende oprichting en organisatie van het Gezondheids(zorg)data-agentschap (etaamb)",
       "url": "https://etaamb.openjustice.be/nl/wet-van-14-maart-2023_n2023041135.html",
       "date": "2023-03-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Loi du 30 juillet 2018 relative à la protection des personnes physiques à l'égard des traitements de données à caractère personnel (etaamb)",
       "url": "https://etaamb.openjustice.be/fr/loi-du-30-juillet-2018_n2018040581.html",
       "date": "2018-07-30",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 62,
     "summary": "With consent and a therapeutic relationship, a clinician can reach relevant data held in hospitals, labs and imaging centres across Belgium, with emergency access in law. No official usage figure was found, and what a clinician sees depends on profession and on what providers publish.",
     "sources": [
      {
       "title": "Loi du 22 avril 2019 relative à la qualité de la pratique des soins de santé (Justel)",
       "url": "https://www.ejustice.just.fgov.be/eli/loi/2019/04/22/2019041141/justel",
       "date": "2019-04-22",
       "publisherClass": "legal_text"
      },
      {
       "title": "Verwijzingsrepertorium (Metahub) (eHealth-platform)",
       "url": "https://www.ehealth.fgov.be/ehealthplatform/nl/service-verwijzingsrepertorium-metahub",
       "date": "2025-10-09",
       "publisherClass": "official"
      },
      {
       "title": "L'échange d'informations électroniques dans les soins de santé en Belgique (Frank Robben, eHealth platform head, personal site)",
       "url": "https://www.frankrobben.be/fr/lechange-dinformations-electroniques-dans-les-soins-de-sante-en-belgique/",
       "date": "2025-03-11",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "Décision quant au fond 209/2025 du 18 décembre 2025 (Chambre Contentieuse, APD)",
       "url": "https://autoriteprotectiondonnees.be/publications/decision-quant-au-fond-n0-209-2025.pdf",
       "date": "2025-12-18",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "Secondary use runs through authorisations of the Information Security Committee, which lists 1,093 public deliberations, recent ones largely on pseudonymised data. There is no individual consent or general opt-out for secondary use today; the EHDS opt-out arrives from 2029.",
     "sources": [
      {
       "title": "Het IVC in het kort (Kruispuntbank van de Sociale Zekerheid)",
       "url": "https://www.ksz-bcss.fgov.be/nl/page/ivc-in-het-kort",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Beraadslagingen van het Informatieveiligheidscomité (eHealth-platform)",
       "url": "https://www.ehealth.fgov.be/ehealthplatform/nl/sectoraal-comite/documenten",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Wet van 14 maart 2023 houdende oprichting en organisatie van het Gezondheids(zorg)data-agentschap (etaamb)",
       "url": "https://etaamb.openjustice.be/nl/wet-van-14-maart-2023_n2023041135.html",
       "date": "2023-03-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Loi du 7 mai 2004 relative aux expérimentations sur la personne humaine (Justel)",
       "url": "https://www.ejustice.just.fgov.be/eli/loi/2004/05/07/2004022376/justel",
       "date": "2004-05-07",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "EU device law and the AI Act govern clinical AI; rules for AI in medical devices apply from 2 August 2028. Belgium's 2022 AI plan has a health objective, but no binding national clinical AI rules were found.",
     "sources": [
      {
       "title": "AI Omnibus enters into force (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force",
       "date": "2026-07-27",
       "publisherClass": "intergov"
      },
      {
       "title": "Digital Decade 2026 country report, Belgium, SWD(2026) 155 (European Commission)",
       "url": "https://ec.europa.eu/newsroom/dae/redirection/document/128636",
       "date": "2026-06-17",
       "publisherClass": "intergov"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Loi du 22 août 2002 relative aux droits du patient",
     "level": "National",
     "year": "2002",
     "what": "Right to a kept file, consultation within 15 days, free first copy on paper or electronically.",
     "url": "https://www.ejustice.just.fgov.be/eli/loi/2002/08/22/2002022737/justel"
    },
    {
     "name": "Loi du 22 avril 2019 relative à la qualité de la pratique des soins de santé",
     "level": "National",
     "year": "2019",
     "what": "Access to others' records needs consent and a therapeutic link; emergency access; patients can see who accessed.",
     "url": "https://www.ejustice.just.fgov.be/eli/loi/2019/04/22/2019041141/justel"
    },
    {
     "name": "Loi du 30 juillet 2018 relative à la protection des données",
     "level": "National",
     "year": "2018",
     "what": "Implements the GDPR; extra duties for health data: named access categories and confidentiality.",
     "url": "https://etaamb.openjustice.be/fr/loi-du-30-juillet-2018_n2018040581.html"
    },
    {
     "name": "Loi du 4 avril 2014 relative aux assurances (articles 58 and 61)",
     "level": "National",
     "year": "2014",
     "what": "Genetic data may not be given to insurers; no genetic tests to predict future health.",
     "url": "https://etaamb.openjustice.be/fr/loi-du-04-avril-2014_n2014011239.html"
    },
    {
     "name": "Wet van 14 maart 2023 Gezondheids(zorg)data-agentschap",
     "level": "National",
     "year": "2023",
     "what": "Creates the Health Data Agency to facilitate commercial and non-commercial reuse of health data.",
     "url": "https://etaamb.openjustice.be/nl/wet-van-14-maart-2023_n2023041135.html"
    },
    {
     "name": "Decreet van 8 juli 2022 tot oprichting van het platform Vitalink",
     "level": "Regional",
     "year": "2022",
     "what": "Flemish sharing platform; consent required for sharing, revocable; research gets pseudonymised data only.",
     "url": "https://codex.vlaanderen.be/PrintDocument.ashx?id=1037408&datum=&geannoteerd=true&print=false"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient summaries and e-prescriptions from March 2029, labs and imaging 2031; secondary-use opt-out.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    }
   ],
   "dti": {
    "grade": 80,
    "tier": "Silver",
    "tierCapped": true
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-12-18",
     "headline": "Access list showed a therapist opened a patient's test results without a care reason",
     "paraphrase": "A patient asked her hospital group who had opened her electronic record. The list showed a therapist working there had viewed her test results three times. The regulator reprimanded the hospital for weak access controls; an appeal is pending.",
     "source": "Gegevensbeschermingsautoriteit (Belgian Data Protection Authority), Litigation Chamber decision 209/2025",
     "url": "https://www.gegevensbeschermingsautoriteit.be/publications/beslissing-ten-gronde-nr.-209-2025.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2024-12-17",
     "headline": "Ransomware hit a hospital whose patient record system had weak password protection",
     "paraphrase": "An attacker locked a hospital's servers and exported about 5 gigabytes of data. The regulator found security failings, including weak protection of access to the electronic patient record, and fined the hospital 390,000 euros. An appeal court later reduced it.",
     "source": "Gegevensbeschermingsautoriteit (Belgian Data Protection Authority), Litigation Chamber decision 166/2024",
     "url": "https://www.gegevensbeschermingsautoriteit.be/publications/beslissing-ten-gronde-nr.-166-2024.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-01-14",
     "headline": "After one hospital hack, experts found three more hospitals' patient data open to intruders",
     "paraphrase": "Following a cyberattack on one Flemish hospital, security researchers said a shared service provider let them obtain passwords for three other hospitals' platforms, exposing about 71,000 patients' identity details. They said the data did not appear to have been stolen.",
     "source": "VRT NWS",
     "url": "https://www.vrt.be/vrtnws/nl/2026/01/14/ziekenhuizen-cyberaanval-impact/",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2024-10-04",
     "headline": "Hackers took 53,900 sick-leave check files including doctors' comments",
     "paraphrase": "A company that runs employer-requested sick-leave checks said hackers had taken 53,900 files, including names, addresses, incapacity levels and examining doctors' comments, and published them a week later. It warned of phishing using the data.",
     "source": "RTBF",
     "url": "https://www.rtbf.be/article/la-societe-medicheck-informe-que-des-hackers-ont-mis-la-main-sur-53-900-dossiers-de-medecins-controle-11444168",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-06-25",
     "headline": "Overheated outside server took a hospital's electronic patient record offline",
     "paraphrase": "A hospital's electronic patient record went down after an external server abroad overheated. Planned appointments and operations were cancelled, and patients could not consult their own medical file until the system came back.",
     "source": "Medi-Sfeer",
     "url": "https://www.medi-sfeer.be/nl/nieuws/hitte-storing-bij-elektronisch-patientendossier-in-az-sint-lucas-van-de-baan.html",
     "theme": "other",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "DEU",
   "name": "Germany",
   "region": "Europe",
   "overall": 63,
   "rank": "11=",
   "likelyRank": "8 to 20",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "About 73 million Germans have an opt-out ePA with an access log and blocking options, but only 5.1 million have the ID to open it.",
   "categories": {
    "access": {
     "score": 64,
     "summary": "Since 6 February 2026 the BGB gives a free first copy of the complete treatment record, including electronic copies, and insurers have created about 73 million ePAs. Only 5.1 million people had the GesundheitsID needed to read theirs.",
     "sources": [
      {
       "title": "§ 630g BGB Einsichtnahme in die Behandlungsakte (gesetze-im-internet.de)",
       "url": "https://www.gesetze-im-internet.de/bgb/__630g.html",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Merkblatt: Einsichtnahme in ärztliche Behandlungsunterlagen (Ärztekammer Berlin)",
       "url": "https://www.aekb.de/fileadmin/migration/pdf/25_Merkblatt_Einsichtsrechte_in_Patientenunterlagen.pdf",
       "date": "2026-02",
       "publisherClass": "official"
      },
      {
       "title": "Ein Jahr ePA für alle: mehr als 100 Millionen hinterlegte Dokumente (gematik)",
       "url": "https://www.gematik.de/newsroom/news-detail/ein-jahr-epa-fuer-alle-mehr-als-100-millionen-hinterlegte-dokumente-verbessern-behandlung-und-versorgung-in-deutschland",
       "date": "2026-04-15",
       "publisherClass": "official"
      },
      {
       "title": "Elektronische Patientenakte: Datenschutz stärkt Vertrauen und Nutzung (BfDI Datenbarometer)",
       "url": "https://www.bfdi.bund.de/SharedDocs/Pressemitteilungen/DE/2025/18_Datenbarometer-ePA.html",
       "date": "2025-12-18",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 66,
     "summary": "Patients can object to the whole ePA, to single uses, or to named facilities, hide documents, change access periods and read an access log. Hiding is all-or-nothing: a document cannot be hidden from one practice only.",
     "sources": [
      {
       "title": "§ 353 SGB V Erklärung des Widerspruchs; Erteilung der Einwilligung",
       "url": "https://www.gesetze-im-internet.de/sgb_5/__353.html",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "§ 342 SGB V Angebot und Nutzung der elektronischen Patientenakte",
       "url": "https://www.gesetze-im-internet.de/sgb_5/__342.html",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Wie verwalte ich meine ePA? (gesund.bund.de, BMG)",
       "url": "https://gesund.bund.de/wie-verwalte-ich-meine-epa",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Seit dem freiwilligen ePA-Start stagniert die Zahl der Widersprüche (zm-online)",
       "url": "https://www.zm-online.de/news/detail/seit-dem-freiwilligen-epa-start-stagniert-die-zahl-der-widersprueche",
       "date": "2025-10-22",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 58,
     "summary": "Strong law and an active federal regulator sit beside real failures: an April 2026 attack on billing firm Unimed exposed patient data at many university hospitals, and researchers say ePA identity checks remain weak.",
     "sources": [
      {
       "title": "Datenschutzaufsicht 2025: BfDI stellt 34. Tätigkeitsbericht vor (BfDI)",
       "url": "https://www.bfdi.bund.de/SharedDocs/Pressemitteilungen/DE/2026/06_TB34.html",
       "date": "2026-05",
       "publisherClass": "official"
      },
      {
       "title": "Cyberangriff auf Abrechnungsdienstleister betrifft viele Kliniken (heise online)",
       "url": "https://www.heise.de/news/Patientendaten-betroffen-Cyberangriff-auf-Abrechnungsdienstleister-von-Kliniken-11304982.html",
       "date": "2026-05-22",
       "publisherClass": "news"
      },
      {
       "title": "39C3: Ein Jahr elektronische Patientenakte, hat sich die Lage verbessert? (heise online)",
       "url": "https://www.heise.de/news/39C3-Ein-Jahr-elektronische-Patientenakte-hat-sich-die-Lage-verbessert-11126272.html",
       "date": "2025-12-30",
       "publisherClass": "news"
      },
      {
       "title": "§ 9 GDNG Strafvorschriften (gesetze-im-internet.de)",
       "url": "https://www.gesetze-im-internet.de/gdng/__9.html",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 66,
     "summary": "Practices, pharmacies and hospitals share one telematics network, e-prescriptions passed one billion in October 2025, and ePA use is mandatory for providers since 1 October 2025. Hospitals still lag behind practices.",
     "sources": [
      {
       "title": "Ein Jahr ePA für alle: mehr als 100 Millionen hinterlegte Dokumente (gematik)",
       "url": "https://www.gematik.de/newsroom/news-detail/ein-jahr-epa-fuer-alle-mehr-als-100-millionen-hinterlegte-dokumente-verbessern-behandlung-und-versorgung-in-deutschland",
       "date": "2026-04-15",
       "publisherClass": "official"
      },
      {
       "title": "Eine Milliarde eingelöste E-Rezepte (gematik)",
       "url": "https://www.gematik.de/newsroom/news-detail/eine-milliarde-eingeloeste-e-rezepte",
       "date": "2025-10-17",
       "publisherClass": "official"
      },
      {
       "title": "ePA für alle (Bundesministerium für Gesundheit)",
       "url": "https://www.bundesgesundheitsministerium.de/themen/digitalisierung/elektronische-patientenakte/epa-fuer-alle",
       "date": "2026-03-04",
       "publisherClass": "official"
      },
      {
       "title": "DEMIS: Deutsches Elektronisches Melde- und Informationssystem (RKI)",
       "url": "https://www.rki.de/DE/Themen/Infektionskrankheiten/Meldewesen/DEMIS/demis-node.html",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 70,
     "summary": "German law bans using research health data for marketing, advertising or insurance decisions and punishes misuse for gain with up to three years in prison. Companies may still apply for pseudonymised data when the purpose qualifies.",
     "sources": [
      {
       "title": "§ 303e SGB V Datenverarbeitung (Forschungsdatenzentrum)",
       "url": "https://www.gesetze-im-internet.de/sgb_5/__303e.html",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "§ 9 GDNG Strafvorschriften (gesetze-im-internet.de)",
       "url": "https://www.gesetze-im-internet.de/gdng/__9.html",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "§ 4 DiGAV Anforderungen an Datenschutz und Datensicherheit",
       "url": "https://www.gesetze-im-internet.de/digav/__4.html",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "§ 25b SGB V Datengestützte Erkennung individueller Gesundheitsrisiken",
       "url": "https://www.gesetze-im-internet.de/sgb_5/__25b.html",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 62,
     "summary": "Reading the patient's card gives a practice 90 days of access to the whole unhidden ePA, but doctors are not required to look and the record only holds documents uploaded since 2025.",
     "sources": [
      {
       "title": "Elektronische Patientenakte (KBV)",
       "url": "https://www.kbv.de/praxis/digitalisierung/anwendungen/elektronische-patientenakte",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Wie verwalte ich meine ePA? (gesund.bund.de, BMG)",
       "url": "https://gesund.bund.de/wie-verwalte-ich-meine-epa",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ein Jahr ePA für alle: mehr als 100 Millionen hinterlegte Dokumente (gematik)",
       "url": "https://www.gematik.de/newsroom/news-detail/ein-jahr-epa-fuer-alle-mehr-als-100-millionen-hinterlegte-dokumente-verbessern-behandlung-und-versorgung-in-deutschland",
       "date": "2026-04-15",
       "publisherClass": "official"
      },
      {
       "title": "Kliniken fremdeln mit der elektronischen Patientenakte (Süddeutsche Zeitung)",
       "url": "https://www.sueddeutsche.de/bayern/nuernberg-kliniken-patientenakte-erler-epa-li.3391093",
       "date": "2026-02-22",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "The only research flow running today, claims data of all statutory insured to the FDZ, has no opt-out, which a lawsuit challenges. An opt-out for ePA data exists in law but its transfers only start in mid-December 2026.",
     "sources": [
      {
       "title": "§ 363 SGB V Verarbeitung von Daten der ePA zu Forschungszwecken",
       "url": "https://www.gesetze-im-internet.de/sgb_5/__363.html",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Daten aus der elektronischen Patientenakte (FDZ Gesundheit, BfArM)",
       "url": "https://www.forschungsdatenzentrum-gesundheit.de/infoportal/datensatz-des-fdz-gesundheit/daten-aus-der-epa",
       "date": "2026-09-30",
       "publisherClass": "official"
      },
      {
       "title": "Klage gegen zentrale Speicherung von Gesundheitsdaten geht weiter (netzpolitik.org)",
       "url": "https://netzpolitik.org/2026/gesellschaft-fuer-freiheitsrechte-klage-gegen-zentrale-speicherung-von-gesundheitsdaten-geht-weiter/",
       "date": "2026-02-25",
       "publisherClass": "news"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI is governed by EU device law and the AI Act, whose duties for AI in medical devices now start 2 August 2028. Germany's KI-MIG of July 2026 mainly designates authorities, which earns no national credit.",
     "sources": [
      {
       "title": "KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG)",
       "url": "https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html",
       "date": "2026-07-22",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Omnibus on AI, Regulation (EU) 2026/1744 (AI Act Explorer)",
       "url": "https://artificialintelligenceact.eu/ai-act-explorer/digital-omnibus/",
       "date": "2026-07",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "EU AI Act News: Digital Omnibus on AI (Mayer Brown)",
       "url": "https://www.mayerbrown.com/en/insights/publications/2026/07/eu-ai-act-news-digital-omnibus-on-ai-new-guidance-on-risk-classification-gpai-and-transparency-obligations",
       "date": "2026-07-30",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Bürgerliches Gesetzbuch § 630g (as amended 2026)",
     "level": "National",
     "year": "2026",
     "what": "Right to inspect the complete treatment record, electronic copies, free first copy since 6 February 2026.",
     "url": "https://www.gesetze-im-internet.de/bgb/__630g.html"
    },
    {
     "name": "SGB V ePA provisions §§ 337-363 (Digital-Gesetz)",
     "level": "National",
     "year": "2025",
     "what": "Opt-out ePA created early 2025; objections per use or provider, access log, research opt-out.",
     "url": "https://www.gesetze-im-internet.de/sgb_5/__353.html"
    },
    {
     "name": "Gesundheitsdatennutzungsgesetz (GDNG)",
     "level": "National",
     "year": "2024",
     "what": "Secrecy duty for research health data users; up to three years prison for misuse for gain.",
     "url": "https://www.gesetze-im-internet.de/gdng/"
    },
    {
     "name": "Digitale Gesundheitsanwendungen-Verordnung (DiGAV)",
     "level": "National",
     "year": "2020",
     "what": "Reimbursed health apps process data only with consent and for a closed list of purposes.",
     "url": "https://www.gesetze-im-internet.de/digav/__4.html"
    },
    {
     "name": "KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG)",
     "level": "National",
     "year": "2026",
     "what": "Implements the EU AI Act in Germany; names supervisory authorities and sets up an AI sandbox.",
     "url": "https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient summaries and e-prescriptions exchange from March 2029; secondary-use rules apply from 2029.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "EU AI Act (EU) 2024/1689, amended by (EU) 2026/1744",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk rules for AI; duties for AI in medical devices apply from 2 August 2028.",
     "url": "https://artificialintelligenceact.eu/ai-act-explorer/digital-omnibus/"
    }
   ],
   "dti": {
    "grade": 89,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-05-20",
     "headline": "Practices answered online reviews by publishing patients' names and record details",
     "paraphrase": "Patients left anonymous negative reviews online. Medical practices replied in public, naming the patients and disclosing details from their records. The state regulator listed these among cases where it imposed fines in 2024.",
     "source": "Hessian Commissioner for Data Protection and Freedom of Information (HBDI)",
     "url": "https://datenschutz.hessen.de/presse/hbdi-stellt-taetigkeitsberichte-zum-datenschutz-und-zur-informationsfreiheit-fuer-das-jahr-2024-vor",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-05-20",
     "headline": "Practice manager took patient files home where guests could read them",
     "paraphrase": "The state regulator reported a practice manager who took patient records home and left them unsecured, where party guests could see them, and who also sent photos of patient files to a partner by messaging app.",
     "source": "Hessian Commissioner for Data Protection and Freedom of Information (HBDI)",
     "url": "https://datenschutz.hessen.de/presse/hbdi-stellt-taetigkeitsberichte-zum-datenschutz-und-zur-informationsfreiheit-fuer-das-jahr-2024-vor",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-10-24",
     "headline": "Man switching insurers found diagnoses in his ePA that he says he never had",
     "paraphrase": "Seeking private insurance, a man opened his electronic patient record and found three diagnoses he says do not apply to him, billed during routine visits. Insurers saw him as high risk. Only the treating doctor can correct them.",
     "source": "t-online",
     "url": "https://www.t-online.de/gesundheit/aktuelles/id_100965028/elektronische-patientenakte-epa-versicherte-entdecken-falsche-diagnosen.html",
     "theme": "record_wrong",
     "status": "self_reported"
    },
    {
     "date": "2025-07-21",
     "headline": "Hospital group says patient data may have been taken in a cyberattack",
     "paraphrase": "After an attack disrupted all its German facilities, a hospital group said data on patients, staff and partners may have been accessed without authorisation and could be misused or passed to others.",
     "source": "heise online",
     "url": "https://www.heise.de/news/Hacker-Angriff-auf-Kliniken-Moeglicherweise-Patientendaten-betroffen-10495015.html",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2025-02-20",
     "headline": "Former patient found a rehab app exposed medical reports without a login",
     "paraphrase": "A former patient noticed a rehabilitation provider's app talked to its servers unencrypted, and that patient files, including medical reports, could be opened without authentication. The provider said the gap was closed and it saw no sign of data outflow.",
     "source": "c't (heise)",
     "url": "https://www.heise.de/select/ct/2025/5/2503112000914901106",
     "theme": "breach",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "ITA",
   "name": "Italy",
   "region": "Europe",
   "overall": 63,
   "rank": "11=",
   "likelyRank": "8 to 22",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Italians can hide documents and read who opened their regional record, but fewer than half let doctors see it.",
   "categories": {
    "access": {
     "score": 68,
     "summary": "Law 24/2017 obliges providers to release records within seven days, and every regional FSE shows lab, discharge and ER reports. Italy scored 84.1 on the EU record-access indicator (EU 82.7), but the full hospital chart is online in only 6 of 21 regions.",
     "sources": [
      {
       "title": "Legge 8 marzo 2017, n. 24 (Gelli-Bianco), art. 4 (Gazzetta Ufficiale)",
       "url": "https://www.gazzettaufficiale.it/eli/id/2017/03/17/17G00041/sg",
       "date": "2017-03-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Decreto 7 settembre 2023, Fascicolo sanitario elettronico 2.0 (Gazzetta Ufficiale n. 249)",
       "url": "https://www.gazzettaufficiale.it/eli/id/2023/10/24/23A05829/sg",
       "date": "2023-10-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "I numeri del Fascicolo: utilizzo e documenti del FSE (Ministero della Salute monitoring site; consent data to 31 Aug 2026)",
       "url": "https://monitopen.fse.salute.gov.it/usage",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Italy 2025 Digital Decade country report (Council of the EU, ST 10407/25 ADD 16)",
       "url": "https://data.consilium.europa.eu/doc/document/ST-10407-2025-ADD-16/en/pdf",
       "date": "2025-06-18",
       "publisherClass": "intergov"
      }
     ]
    },
    "control": {
     "score": 72,
     "summary": "Clinicians may consult the FSE only after the patient gives explicit, revocable consent, and patients can hide any document online and read the access log, both available in all 21 regions. Documents still flow into the FSE automatically without consent.",
     "sources": [
      {
       "title": "Decreto 7 settembre 2023, Fascicolo sanitario elettronico 2.0 (Gazzetta Ufficiale n. 249)",
       "url": "https://www.gazzettaufficiale.it/eli/id/2023/10/24/23A05829/sg",
       "date": "2023-10-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Fascicolo sanitario elettronico (FSE): FAQ (Garante Privacy)",
       "url": "https://www.garanteprivacy.it/temi/fse",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "I numeri del Fascicolo: utilizzo e documenti del FSE (Ministero della Salute monitoring site; consent data to 31 Aug 2026)",
       "url": "https://monitopen.fse.salute.gov.it/usage",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 56,
     "summary": "Italian law bans publishing health data, makes harmful misuse a crime, and the Garante fines hospitals for snooping. But cyberattacks on health bodies doubled to 57 in 2024, and by January 2026 the Garante's board was under criminal investigation.",
     "sources": [
      {
       "title": "Codice in materia di protezione dei dati personali, testo coordinato V 12.0 (Garante Privacy)",
       "url": "https://www.garanteprivacy.it/documents/10160/0/Codice+in+materia+di+protezione+dei+dati+personali+%28Testo+coordinato%29",
       "date": "2026-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "Relazione sull'attività 2025, sintesi per la stampa (Garante Privacy)",
       "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10266612",
       "date": "2026-07-02",
       "publisherClass": "official"
      },
      {
       "title": "Newsletter n. 551 dell'11 settembre 2026: Azienda sanitaria di Udine sanzionata per 24mila euro (Garante Privacy)",
       "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10294220",
       "date": "2026-09-11",
       "publisherClass": "official"
      },
      {
       "title": "Si dimette Guido Scorza, componente del Garante della Privacy (Rainews)",
       "url": "https://www.rainews.it/articoli/2026/01/si-dimette-guido-scorza-componente-del-garante-della-privacy-3ce8bda7-3ced-4e6d-8b94-ce4fb7de8298.html",
       "date": "2026-01-18",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 66,
     "summary": "Hospitals, labs and GPs feed the regional FSEs at near full rates, 98.7% of lab, radiology, pathology, discharge and ER events in June 2026, and e-prescriptions run on one national system. The national health data ecosystem (EDS) that should link it all is not yet live.",
     "sources": [
      {
       "title": "I numeri del Fascicolo: utilizzo e documenti del FSE (Ministero della Salute monitoring site; consent data to 31 Aug 2026)",
       "url": "https://monitopen.fse.salute.gov.it/usage",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Adozione e utilizzo da parte della Regione Sardegna del FSE, relazione (Corte dei conti, Sezione di controllo Sardegna, delibera 373/2026)",
       "url": "https://cmsras.regione.sardegna.it/api/assets/redazionaleras/9c56d81c-9a7b-47da-8a02-857485a05120/allegato-delibera-373-2026-pnrr-marcato.pdf?version=0",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ricetta elettronica: come funziona (Sistema Tessera Sanitaria, MEF)",
       "url": "https://sistemats1.sanita.finanze.it/portale/ricetta-elettronica-come-funziona",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Fascicolo sanitario elettronico (FSE): FAQ (Garante Privacy)",
       "url": "https://www.garanteprivacy.it/temi/fse",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 60,
     "summary": "Italian law bans publishing health data and bars insurers and banks from asking about cancer cured over ten years earlier. No ban on selling health data beyond GDPR was found, and Law 132/2025 lets private firms in public research projects reuse de-identified data without consent.",
     "sources": [
      {
       "title": "Codice in materia di protezione dei dati personali, testo coordinato V 12.0 (Garante Privacy)",
       "url": "https://www.garanteprivacy.it/documents/10160/0/Codice+in+materia+di+protezione+dei+dati+personali+%28Testo+coordinato%29",
       "date": "2026-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "Legge 7 dicembre 2023, n. 193, diritto all'oblio oncologico (Gazzetta Ufficiale)",
       "url": "https://www.gazzettaufficiale.it/eli/id/2023/12/18/23G00206/sg",
       "date": "2023-12-18",
       "publisherClass": "legal_text"
      },
      {
       "title": "Legge 23 settembre 2025, n. 132, disposizioni in materia di intelligenza artificiale (Gazzetta Ufficiale)",
       "url": "https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00143/SG",
       "date": "2025-09-25",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 50,
     "summary": "Treating doctors, nurses and pharmacists can read the FSE only if the patient has consented, and nationally 43.5% had by August 2026. Consent ranges from 3.8% in Calabria to 90.3% in Trento, so access depends heavily on region.",
     "sources": [
      {
       "title": "Decreto 7 settembre 2023, Fascicolo sanitario elettronico 2.0 (Gazzetta Ufficiale n. 249)",
       "url": "https://www.gazzettaufficiale.it/eli/id/2023/10/24/23A05829/sg",
       "date": "2023-10-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "I numeri del Fascicolo: utilizzo e documenti del FSE (Ministero della Salute monitoring site; consent data to 31 Aug 2026)",
       "url": "https://monitopen.fse.salute.gov.it/usage",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Health data can be used for research without consent when a law or regulation provides for it or informing people is impossible, and there is no general opt-out. Ethics review and Garante notification, criminal penalties and FSE masking give three safeguard classes, at the band cap.",
     "sources": [
      {
       "title": "Codice in materia di protezione dei dati personali, testo coordinato V 12.0 (Garante Privacy)",
       "url": "https://www.garanteprivacy.it/documents/10160/0/Codice+in+materia+di+protezione+dei+dati+personali+%28Testo+coordinato%29",
       "date": "2026-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "Legge 23 settembre 2025, n. 132, disposizioni in materia di intelligenza artificiale (Gazzetta Ufficiale)",
       "url": "https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00143/SG",
       "date": "2025-09-25",
       "publisherClass": "legal_text"
      },
      {
       "title": "Fascicolo sanitario elettronico (FSE): FAQ (Garante Privacy)",
       "url": "https://www.garanteprivacy.it/temi/fse",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (EHDS) (European Commission, DG SANTE)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 54,
     "summary": "Italy's AI law, in force since 10 October 2025, gives patients a right to be told when AI is used and keeps every clinical decision with the doctor. That is one national addition to EU law; the follow-up ministerial decree was not verified.",
     "sources": [
      {
       "title": "Legge 23 settembre 2025, n. 132, disposizioni in materia di intelligenza artificiale (Gazzetta Ufficiale)",
       "url": "https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00143/SG",
       "date": "2025-09-25",
       "publisherClass": "legal_text"
      },
      {
       "title": "Assistenza primaria: al via la sperimentazione nazionale della Piattaforma di Intelligenza Artificiale (Panorama della Sanità)",
       "url": "https://panoramadellasanita.it/site/assistenza-primaria-al-via-la-sperimentazione-nazionale-della-piattaforma-di-intelligenza-artificiale/",
       "date": "2025-11-17",
       "publisherClass": "news"
      },
      {
       "title": "Digital Omnibus on AI has been published (Regulation (EU) 2026/1744) (Cuatrecasas)",
       "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published",
       "date": "2026-07-24",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Legge 8 marzo 2017, n. 24 (Gelli-Bianco), art. 4",
     "level": "National",
     "year": "2017",
     "what": "Facilities must supply the patient's records within seven days, additions within 30 days.",
     "url": "https://www.gazzettaufficiale.it/eli/id/2017/03/17/17G00041/sg"
    },
    {
     "name": "Decreto-legge 18 ottobre 2012, n. 179, art. 12, as amended by DL 19 maggio 2020, n. 34, art. 11",
     "level": "National",
     "year": "2012",
     "what": "Creates the FSE; since 2020 it is fed continuously by all treating professionals.",
     "url": "https://www.gazzettaufficiale.it/eli/id/2020/05/19/20G00052/sg"
    },
    {
     "name": "Decreto 7 settembre 2023, Fascicolo sanitario elettronico 2.0",
     "level": "National",
     "year": "2023",
     "what": "Consent to consultation, masking, access log, notifications and emergency access rules for the FSE.",
     "url": "https://www.gazzettaufficiale.it/eli/id/2023/10/24/23A05829/sg"
    },
    {
     "name": "Decreto legislativo 30 giugno 2003, n. 196 (Codice privacy)",
     "level": "National",
     "year": "2003",
     "what": "Health data safeguards, ban on dissemination, research rules (art. 110), criminal penalties (art. 167).",
     "url": "https://www.garanteprivacy.it/documents/10160/0/Codice+in+materia+di+protezione+dei+dati+personali+%28Testo+coordinato%29"
    },
    {
     "name": "Legge 23 settembre 2025, n. 132 (AI law)",
     "level": "National",
     "year": "2025",
     "what": "Right to know about AI in care; doctor decides; consent-free de-identified data for AI research.",
     "url": "https://www.gazzettaufficiale.it/eli/id/2025/09/25/25G00143/SG"
    },
    {
     "name": "Legge 7 dicembre 2023, n. 193 (oblio oncologico)",
     "level": "National",
     "year": "2023",
     "what": "Banks and insurers may not ask about cancer cured over ten years ago.",
     "url": "https://www.gazzettaufficiale.it/eli/id/2023/12/18/23G00206/sg"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Access, restriction and access-log rights; secondary-use opt-out; key parts apply from March 2029.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    }
   ],
   "dti": {
    "grade": 90,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-09-11",
     "headline": "Health authority fined after a colleague opened a staff member's patient record",
     "paraphrase": "A hospital worker who was also a patient complained that a colleague viewed their health record to plan work shifts. The regulator found the record system let staff see files without a care reason and fined the authority 24,000 euros.",
     "source": "Garante per la protezione dei dati personali",
     "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10294220",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-12-18",
     "headline": "Clinic warned after sending a patient's test report to the wrong email address",
     "paraphrase": "A patient learned his report had gone to an address one letter different from his, carrying his name, birth date and tax code. The regulator found no address check was in place and issued a formal warning.",
     "source": "Garante per la protezione dei dati personali",
     "url": "https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/10210247",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-03-13",
     "headline": "Private clinic warned after a patient's full medical file was lost in archiving",
     "paraphrase": "A clinic could not produce a patient's medical file when investigators asked for it; the archive company said it never received the file. The regulator found the clinic failed to report the loss in time and issued a warning.",
     "source": "Garante per la protezione dei dati personali",
     "url": "https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/10132289",
     "theme": "other",
     "status": "finding"
    },
    {
     "date": "2024-11-13",
     "headline": "Hospital warned after hiding a report in a patient's e-record changed its date",
     "paraphrase": "A patient said a hospital put a report in her electronic health record without telling her. When she asked for it to be hidden, the system created a replacement dated the day of the change. The regulator issued a warning.",
     "source": "Garante per la protezione dei dati personali",
     "url": "https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10087191",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-12-31",
     "headline": "Prescriptions of about 90,000 Lombardy patients offered for sale after software breach",
     "paraphrase": "Data stolen in March from the company running a portal family doctors use to send prescriptions went on sale online: prescriptions, sick notes, exemption certificates, emails, phones and addresses. The company reported it to police and warned patients of phishing.",
     "source": "Il Post",
     "url": "https://www.ilpost.it/2025/12/31/dati-sanitari-90mila-pazienti-vendita-dark-web/",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "TWN",
   "name": "Taiwan",
   "region": "Asia",
   "overall": 63,
   "rank": "11=",
   "likelyRank": "8 to 23",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Taiwan's single insurer offers every insured person three years of claims-based records online, with 12.48 million registered users, but full charts stay in each hospital.",
   "categories": {
    "access": {
     "score": 68,
     "summary": "The Medical Care Act gives a right to a copy of the record, and My Health Bank shows three years of visits, medicines, lab results and imaging reports to 12.48 million registered users. Copies cost the patient, and Liberty Times reported only 1 to 3 million regular users.",
     "sources": [
      {
       "title": "Medical Care Act, full text (Laws & Regulations Database)",
       "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0020021",
       "date": "2026-09-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Use My Health Bank to care for your father (MOHW)",
       "url": "https://www.mohw.gov.tw/cp-3797-43159-1.html",
       "date": "2018-08-06",
       "publisherClass": "official"
      },
      {
       "title": "My Health Bank queries pass 600 million at NHI's 31st anniversary (NHIA)",
       "url": "https://www.nhi.gov.tw/ch/cp-19750-2913e-3255-1.html",
       "date": "2026-03-28",
       "publisherClass": "official"
      },
      {
       "title": "My Health Bank passes 600 million uses; to shift toward daily health behaviour (Liberty Times)",
       "url": "https://health.ltn.com.tw/article/breakingnews/5385491",
       "date": "2026-03-28",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 52,
     "summary": "A person can set an NHI card password that stops all contracted doctors and pharmacists from viewing their MediCloud data, and a separate opt-out covers research use. The block is a single switch that must be set in person at an NHIA or district office.",
     "sources": [
      {
       "title": "NHI MediCloud: how does it help my care? Card password option (NHIA medical quality portal)",
       "url": "https://med.nhi.gov.tw/ihqe0000/pepM1825_1.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Can I keep some test results from doctors? MediCloud FAQ 22 (NHIA)",
       "url": "https://www.nhi.gov.tw/ch/cp-7638-9581a-2727-1.html",
       "date": "2023-11-29",
       "publisherClass": "official"
      },
      {
       "title": "Request to stop use of NHI data beyond its specified purpose (NHIA)",
       "url": "https://www.nhi.gov.tw/ch/np-4049-1.html",
       "date": "2025-08-07",
       "publisherClass": "official"
      },
      {
       "title": "National Health Insurance Data Management Act, full text (Laws & Regulations Database)",
       "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0060042",
       "date": "2025-12-19",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 50,
     "summary": "Medical records are a special category under the Personal Data Protection Act, but the independent commission named in the law still does not exist, and sector ministries enforce with fines of NT$50,000 to 500,000. Ransomware attacks in 2025 exposed about 16.6 million patient records.",
     "sources": [
      {
       "title": "Personal Data Protection Act, version in force (amended 31 May 2023), Laws & Regulations Database",
       "url": "https://law.moj.gov.tw/LawClass/LawOldVer.aspx?pcode=I0050021",
       "date": "2023-05-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "PDPA amendment promulgated 11 November 2025; start date to be set by the Executive Yuan (PDPC Preparatory Office)",
       "url": "https://www.pdpc.gov.tw/News_Content/20/1010/",
       "date": "2025-11-11",
       "publisherClass": "official"
      },
      {
       "title": "Which government bodies are being stalled? PDPC organic act frozen over 300 days (Watchout)",
       "url": "https://watchout.tw/reports/DMubi9rCnYi0TRNXD2ZA",
       "date": "2026-08-05",
       "publisherClass": "news"
      },
      {
       "title": "Two charged for buying Mackay and Changhua Christian patient data from hackers (Mirror Media)",
       "url": "https://www.mirrormedia.mg/story/20260615edi016",
       "date": "2026-06-15",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 72,
     "summary": "One insurer contracts with about 93% of providers, including every hospital, and NHI MediCloud pools 13 types of data plus CT and MRI images from all of them. Full hospital charts are only now being linked through FHIR, with clinics due in 2028.",
     "sources": [
      {
       "title": "Taiwan Can Help: NHI's contribution in COVID-19 (NHIA)",
       "url": "https://www.nhi.gov.tw/en/np-47-2.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Introduction to NHI MediCloud (NHIA)",
       "url": "https://www.nhi.gov.tw/ch/np-2722-1.html",
       "date": "2026-03-27",
       "publisherClass": "official"
      },
      {
       "title": "MOHW pushes FHIR, 'no penalties first', aims to link all medical centres this year (Storm Media)",
       "url": "https://www.storm.mg/article/11120658",
       "date": "2026-04-13",
       "publisherClass": "news"
      },
      {
       "title": "RxNorm Taiwan 2025, part 3: Taiwan's e-prescription plan (MOHW AI centres)",
       "url": "https://aicenter.mohw.gov.tw/AC/cp-7200-85622-208.html",
       "date": "2026-02-23",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 62,
     "summary": "The NHI Data Management Act bars secondary use of insurance data for commercial profit and limits applicants to government, hospitals, universities and research bodies. Hospital records and consumer apps outside the NHI database fall back on the general privacy law and its small fines.",
     "sources": [
      {
       "title": "National Health Insurance Data Management Act, full text (Laws & Regulations Database)",
       "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0060042",
       "date": "2025-12-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Personal Data Protection Act, version in force (amended 31 May 2023), Laws & Regulations Database",
       "url": "https://law.moj.gov.tw/LawClass/LawOldVer.aspx?pcode=I0050021",
       "date": "2023-05-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "clinical": {
     "score": 78,
     "summary": "Any contracted doctor or pharmacist can see a patient's medicines, results, discharge summaries and images from other providers through MediCloud once the patient's card is inserted. Results and images go back only 12 months, and full notes from other hospitals are not yet shared.",
     "sources": [
      {
       "title": "Does viewing test results need the patient's signed consent? MediCloud FAQ 15 (NHIA)",
       "url": "https://www.nhi.gov.tw/ch/cp-7631-ccbac-2727-1.html",
       "date": "2026-06-03",
       "publisherClass": "official"
      },
      {
       "title": "Can my 10 years of hospital tests be viewed elsewhere? MediCloud FAQ 10 (NHIA)",
       "url": "https://www.nhi.gov.tw/ch/cp-7626-18210-2727-1.html",
       "date": "2026-06-03",
       "publisherClass": "official"
      },
      {
       "title": "Introduction to NHI MediCloud (NHIA)",
       "url": "https://www.nhi.gov.tw/ch/np-2722-1.html",
       "date": "2026-03-27",
       "publisherClass": "official"
      },
      {
       "title": "Electronic record integration from May; no discs needed across hospitals (PTS)",
       "url": "https://news.pts.org.tw/article/803567",
       "date": "2026-04-14",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 66,
     "summary": "Researchers keep access to near-national insurance data, but since August 2026 the law lets anyone opt out of all or part of it, with public lists of approved projects. By September 2026, 24,511 people, about 1 in 1,000, had opted out.",
     "sources": [
      {
       "title": "National Health Insurance Data Management Act, full text (Laws & Regulations Database)",
       "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0060042",
       "date": "2025-12-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Request to stop use of NHI data beyond its specified purpose (NHIA)",
       "url": "https://www.nhi.gov.tw/ch/np-4049-1.html",
       "date": "2025-08-07",
       "publisherClass": "official"
      },
      {
       "title": "MOHW: nearly 25,000 apply to opt out of NHI data secondary use (CNA)",
       "url": "https://www.cna.com.tw/news/ahel/202609160155.aspx",
       "date": "2026-09-16",
       "publisherClass": "news"
      },
      {
       "title": "Human Subjects Research Act, full text (Laws & Regulations Database)",
       "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0020176",
       "date": "2019-01-02",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 58,
     "summary": "Clinical AI software is a medical device that needs TFDA approval, and changes to listed items need approval too. The AI-specific change plan route (2024) and machine learning principles (2026) are guidance, not law, so Taiwan sits low in the device-regulation band.",
     "sources": [
      {
       "title": "Medical Devices Act, full text (Laws & Regulations Database)",
       "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0030106",
       "date": "2020-01-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Notice: predetermined change control plan guide for AI/ML medical device software (TFDA)",
       "url": "https://www.fda.gov.tw/TC/siteListContent.aspx?sid=11652&id=47477",
       "date": "2024-09-25",
       "publisherClass": "official"
      },
      {
       "title": "Notice: good machine learning practice for AI medical devices (TFDA)",
       "url": "https://www.fda.gov.tw/TC/siteListContent.aspx?id=50868&sid=310",
       "date": "2026-06-08",
       "publisherClass": "official"
      },
      {
       "title": "Guideline on generative AI in medical institutions (MOHW)",
       "url": "https://www.mohw.gov.tw/dl-100614-c7d35394-0a6b-448e-9d90-295294596d98.html",
       "date": "2026-05-29",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "National Health Insurance Data Management Act",
     "level": "National",
     "year": "2025",
     "what": "Opt-out from secondary use, no commercial-profit use, fines up to NT$10 million; in force 10 August 2026.",
     "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0060042"
    },
    {
     "name": "Personal Data Protection Act",
     "level": "National",
     "year": "1995",
     "what": "Health data special category; rights to copy and delete; 2025 amendment creating breach reporting not yet in force.",
     "url": "https://law.moj.gov.tw/LawClass/LawOldVer.aspx?pcode=I0050021"
    },
    {
     "name": "Medical Care Act",
     "level": "National",
     "year": "1986",
     "what": "Patients may get a copy of their record at their own cost; privacy duties; last amended September 2026.",
     "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0020021"
    },
    {
     "name": "Human Subjects Research Act",
     "level": "National",
     "year": "2011",
     "what": "Ethics committee approval and withdrawable informed consent for research on people.",
     "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0020176"
    },
    {
     "name": "Medical Devices Act",
     "level": "National",
     "year": "2020",
     "what": "Software is a medical device; registration and approval of designated changes required.",
     "url": "https://law.moj.gov.tw/LawClass/LawAll.aspx?pcode=L0030106"
    },
    {
     "name": "Artificial Intelligence Basic Act",
     "level": "National",
     "year": "2026",
     "what": "Seven AI principles including human oversight; warnings required on AI deemed high risk.",
     "url": "https://www.president.gov.tw/File/Doc/d961e5b2-f8c4-424b-8993-4a52702ae8c7"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-03-06",
     "headline": "Mackay Memorial Hospital apologises after ransomware attack that may have taken patient data",
     "paraphrase": "After a ransomware attack, the hospital issued statements apologising and saying hackers may have stolen data while encrypting its systems. Millions of patient records were reportedly offered for sale; the ministry said the source still needed checking.",
     "source": "Knews (知新聞)",
     "url": "https://www.knews.com.tw/news/8A16D5DBB40F177A4BECE981103631A9",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-06-15",
     "headline": "Two men charged with buying hacked hospital patient records to resell online",
     "paraphrase": "Prosecutors charged two men with paying cryptocurrency for a file of about 20,000 hospital patients' visit and health records stolen by hackers, then advertising hospital data for sale on a messaging app. Prosecutors asked for heavy sentences.",
     "source": "Central News Agency (中央社)",
     "url": "https://www.cna.com.tw/news/asoc/202606150041.aspx",
     "theme": "sold_or_shared",
     "status": "alleged"
    },
    {
     "date": "2026-09-21",
     "headline": "Doctor charged with looking up other doctors' patients' records to win their business",
     "paraphrase": "Prosecutors charged a hospital doctor with opening the records and contact details of three patients under other doctors' care, then texting them to criticise their doctors and urge them to switch to him. He has not been convicted.",
     "source": "Central News Agency (中央社)",
     "url": "https://www.cna.com.tw/news/asoc/202609210043.aspx",
     "theme": "other",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "TUR",
   "name": "Turkey",
   "region": "Europe",
   "overall": 63,
   "rank": "11=",
   "likelyRank": "6 to 19",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "e-Nabız gives nearly every Turk one national record with an access log and SMS-code consent, but the state holds the data centrally.",
   "categories": {
    "access": {
     "score": 74,
     "summary": "The Patient Rights Regulation gives a right to examine the file and take a copy, and the national e-Nabız portal shows labs, imaging, prescriptions, diagnoses and reports. The minister said it served over 79 million citizens in 2025.",
     "sources": [
      {
       "title": "Hasta Hakları Yönetmeliği (mevzuat.gov.tr)",
       "url": "https://www.mevzuat.gov.tr/File/GeneratePdf?mevzuatNo=4847&mevzuatTur=KurumVeKurulusYonetmeligi&mevzuatTertip=5",
       "date": "1998-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "e-Nabız Yardım (Sağlık Bakanlığı)",
       "url": "https://enabiz.gov.tr/Yardim/Index",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Bakan Memişoğlu'ndan sağlıkta dijital dönüşüm çalışmalarına ilişkin paylaşım (Hürriyet)",
       "url": "https://www.hurriyet.com.tr/gundem/bakan-memisoglundan-saglikta-dijital-donusum-calismalarina-iliskin-paylasim-43070060",
       "date": "2025-12-28",
       "publisherClass": "news"
      },
      {
       "title": "Milyonlarca kişiyi ilgilendiren güncelleme: e-Nabız yenilendi (Ekonomim)",
       "url": "https://www.ekonomim.com/gundem/milyonlarca-kisiyi-ilgilendiren-guncelleme-e-nabiz-yenilendi-haberi-825172",
       "date": "2025-06-18",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 62,
     "summary": "Patients can see every access to their e-Nabız account by date and time, and can require an SMS code before most doctors see their past data. Family, emergency and inpatient doctors keep access, and records held by the ministry cannot be deleted.",
     "sources": [
      {
       "title": "e-Nabız Yardım (Sağlık Bakanlığı)",
       "url": "https://enabiz.gov.tr/Yardim/Index",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "e-Nabız (Sağlık Bakanlığı)",
       "url": "https://enabiz.gov.tr/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Kişisel Sağlık Verileri Hakkında Yönetmelik (Resmî Gazete)",
       "url": "https://www.resmigazete.gov.tr/eskiler/2019/06/20190621-3.htm",
       "date": "2019-06-21",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kişisel Sağlık Verileri Hakkında Yönetmelikte Değişiklik Yapılmasına Dair Yönetmelik (Resmî Gazete 33096)",
       "url": "https://www.resmigazete.gov.tr/eskiler/2025/12/20251203-2.htm",
       "date": "2025-12-03",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 50,
     "summary": "Law 6698 (KVKK) treats health data as special-category data, and the regulator has fined clinics for snooping in e-Nabız. The European Commission's 2025 report says the law is not adequate and enforcement has serious gaps.",
     "sources": [
      {
       "title": "Kişisel Verilerin Korunması Kanunu No. 6698 (mevzuat.gov.tr)",
       "url": "https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf",
       "date": "2016-04-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "KVKK Board decision 2023/695: unlawful access to e-Nabız by a private medical center",
       "url": "https://www.kvkk.gov.tr/Icerik/7754/2023-695",
       "date": "2023-05-02",
       "publisherClass": "official"
      },
      {
       "title": "Türkiye 2025 Report, SWD(2025) 756 (European Commission)",
       "url": "https://enlargement.ec.europa.eu/document/download/4bb4ddd1-4f20-4ee0-92db-926996ec8dd1_en?filename=t%C3%BCrkiye-report-2025.pdf",
       "date": "2025-11-04",
       "publisherClass": "intergov"
      },
      {
       "title": "Sağlık Verilerinin Güvenli Olarak Toplanması ve Paylaşımı Çalıştayı raporu (TÜSEB, İTÜ)",
       "url": "https://bm.itu.edu.tr/docs/librariesprovider92/default-document-library/svg-rapor.pdf?sfvrsn=1cb04587_2",
       "date": "2025-10",
       "publisherClass": "academic"
      }
     ]
    },
    "journey": {
     "score": 80,
     "summary": "Since 2019 the social security fund (SGK) will not pay for a service unless the provider has sent it to e-Nabız, which ties public and private hospitals to one record. A central teleradiology archive stores images nationwide.",
     "sources": [
      {
       "title": "e-Nabız SGK (Medula) veri doğrulaması hk. (Sağlık Bakanlığı)",
       "url": "https://e-saglik.gov.tr/TR,53387/e-nabiz-sgk-medula-veri-dogrulamasi-hk.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Sağlık Verilerinin Güvenli Olarak Toplanması ve Paylaşımı Çalıştayı raporu (TÜSEB, İTÜ)",
       "url": "https://bm.itu.edu.tr/docs/librariesprovider92/default-document-library/svg-rapor.pdf?sfvrsn=1cb04587_2",
       "date": "2025-10",
       "publisherClass": "academic"
      },
      {
       "title": "Milyonlarca kişiyi ilgilendiren güncelleme: e-Nabız yenilendi (Ekonomim)",
       "url": "https://www.ekonomim.com/gundem/milyonlarca-kisiyi-ilgilendiren-guncelleme-e-nabiz-yenilendi-haberi-825172",
       "date": "2025-06-18",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 55,
     "summary": "Health data needs explicit consent or a legal basis, and the regulator ruled that even consent cannot let a private hospital use patient data for advertising. No Turkish rule on selling de-identified health data was verified.",
     "sources": [
      {
       "title": "KVKK Board decision 2023/787: hospital advertising using patient health data",
       "url": "https://www.kvkk.gov.tr/Icerik/7692/2023-787",
       "date": "2023-05-11",
       "publisherClass": "official"
      },
      {
       "title": "Kişisel Verilerin Korunması Kanunu No. 6698 (mevzuat.gov.tr)",
       "url": "https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf",
       "date": "2016-04-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kişisel Sağlık Verileri Hakkında Yönetmelik (Resmî Gazete)",
       "url": "https://www.resmigazete.gov.tr/eskiler/2019/06/20190621-3.htm",
       "date": "2019-06-21",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 64,
     "summary": "The family doctor sees the record without limit, and emergency and inpatient doctors see it until discharge. Other access to past records needs the patient's phone code, so the score stays in the mixed band despite a broad shared record.",
     "sources": [
      {
       "title": "Kişisel Sağlık Verileri Hakkında Yönetmelik (Resmî Gazete)",
       "url": "https://www.resmigazete.gov.tr/eskiler/2019/06/20190621-3.htm",
       "date": "2019-06-21",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kişisel Sağlık Verileri Hakkında Yönetmelikte Değişiklik Yapılmasına Dair Yönetmelik (Resmî Gazete 33096)",
       "url": "https://www.resmigazete.gov.tr/eskiler/2025/12/20251203-2.htm",
       "date": "2025-12-03",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kişisel Sağlık Verileri Hakkında Yönetmelik'te yapılan son değişiklikler (Acar Ergönen)",
       "url": "https://acarergonen.av.tr/tr/yayinlar/duyurular/kisisel-saglik-verileri-hakkinda-yonetmelik-te-yapilan-son-degisiklikler",
       "date": "2025-12-24",
       "publisherClass": "law_firm"
      },
      {
       "title": "KVKK Board decision 2021/962: hospital doctor accessed e-Nabız without consent",
       "url": "https://www.kvkk.gov.tr/Icerik/7074/-Ilgili-kisinin-talebi-ya-da-rizasi-olmaksizin-ozel-bir-hastane-calisani-hekim-tarafindan-e-nabiz-sistemine-erisim-saglanmasi-hakkinda-Kisisel-Verileri-Koruma-Kurulunun-21-09-2021-tarihli-ve-2021-962-sayili-Karari",
       "date": "2021-09-21",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 44,
     "summary": "The health data regulation allows research on anonymised data without consent, and on identifiable data if safeguards exist. No general opt-out or public register was verified, though drug trials need written consent and ethics approval.",
     "sources": [
      {
       "title": "Kişisel Sağlık Verileri Hakkında Yönetmelik (Resmî Gazete)",
       "url": "https://www.resmigazete.gov.tr/eskiler/2019/06/20190621-3.htm",
       "date": "2019-06-21",
       "publisherClass": "legal_text"
      },
      {
       "title": "Beşeri Tıbbi Ürünlerin Klinik Araştırmaları Hakkında Yönetmelik (Resmî Gazete)",
       "url": "https://www.resmigazete.gov.tr/eskiler/2023/05/20230527-5.htm",
       "date": "2023-05-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Türkiye 2025 Report, SWD(2025) 756 (European Commission)",
       "url": "https://enlargement.ec.europa.eu/document/download/4bb4ddd1-4f20-4ee0-92db-926996ec8dd1_en?filename=t%C3%BCrkiye-report-2025.pdf",
       "date": "2025-11-04",
       "publisherClass": "intergov"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Medical AI software falls under Turkey's 2021 Medical Device Regulation, which mirrors EU MDR 2017/745. Turkey has no AI law yet; an AI Action Plan for 2026 to 2030 was published in August 2026.",
     "sources": [
      {
       "title": "Tıbbi Cihaz Mevzuatı (TİTCK)",
       "url": "https://www.titck.gov.tr/faaliyetalanlari/tibbicihaz/tibbi-cihaz-mevzuati",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Türkiye 2025 Report, SWD(2025) 756 (European Commission)",
       "url": "https://enlargement.ec.europa.eu/document/download/4bb4ddd1-4f20-4ee0-92db-926996ec8dd1_en?filename=t%C3%BCrkiye-report-2025.pdf",
       "date": "2025-11-04",
       "publisherClass": "intergov"
      },
      {
       "title": "Türkiye Yapay Zeka Eylem Planı Genelgesi Resmi Gazete'de (Memurlar.net)",
       "url": "https://www.memurlar.net/haber/1175670/turkiye-yapay-zeka-eylem-plani-genelgesi-resmi-gazete-de.html",
       "date": "2026-08-18",
       "publisherClass": "news"
      },
      {
       "title": "TBMM'nin Yapay Zekâ Komisyonu raporuna ilişkin TMMOB görüşü (BMO)",
       "url": "https://www.bmo.org.tr/2026/04/01/tbmmnin-yapay-zeka-komisyonu-raporuna-iliskin-tmmob-gorusu/",
       "date": "2026-03-30",
       "publisherClass": "blog_vendor"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Law No. 6698 on the Protection of Personal Data (KVKK)",
     "level": "National",
     "year": "2016",
     "what": "Health is special-category data; access rights; breach notice; amended 2024 by Law 7499.",
     "url": "https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf"
    },
    {
     "name": "Regulation on Personal Health Data (Kişisel Sağlık Verileri Hakkında Yönetmelik)",
     "level": "National",
     "year": "2019",
     "what": "Sets who may access e-Nabız data, privacy settings, and research use of anonymised data.",
     "url": "https://www.resmigazete.gov.tr/eskiler/2019/06/20190621-3.htm"
    },
    {
     "name": "Amendment to the Regulation on Personal Health Data (Official Gazette 33096)",
     "level": "National",
     "year": "2025",
     "what": "Past data needs a patient phone code; lists doctors who keep access without one.",
     "url": "https://www.resmigazete.gov.tr/eskiler/2025/12/20251203-2.htm"
    },
    {
     "name": "Patient Rights Regulation (Hasta Hakları Yönetmeliği)",
     "level": "National",
     "year": "1998",
     "what": "Right to examine and copy one's health records and ask for corrections.",
     "url": "https://www.mevzuat.gov.tr/File/GeneratePdf?mevzuatNo=4847&mevzuatTur=KurumVeKurulusYonetmeligi&mevzuatTertip=5"
    },
    {
     "name": "Medical Device Regulation (Tıbbi Cihaz Yönetmeliği)",
     "level": "National",
     "year": "2021",
     "what": "Harmonised with EU MDR 2017/745; covers medical device software including AI.",
     "url": "https://www.titck.gov.tr/faaliyetalanlari/tibbicihaz/tibbi-cihaz-mevzuati"
    },
    {
     "name": "Regulation on Clinical Trials of Human Medicinal Products",
     "level": "National",
     "year": "2023",
     "what": "Written informed consent, withdrawal at any time, ethics and agency approval.",
     "url": "https://www.resmigazete.gov.tr/eskiler/2023/05/20230527-5.htm"
    }
   ],
   "dti": {
    "grade": 86,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-06-23",
     "headline": "Ministry inspectors penalise hospital staff who sold patient details to claims firms",
     "paraphrase": "Staff at a public hospital copied patients' identity and contact details from the hospital information system and passed them to unlicensed insurance claims firms for commission. Health Ministry inspectors dismissed staff and suspended a doctor; a criminal investigation continues.",
     "source": "Bizim Sakarya",
     "url": "https://www.bizimsakarya.com.tr/seahta-veri-sizintisi-skandali-hasta-bilgilerini-satan-saglikcilara-ihrac-yagdi",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2026-04-04",
     "headline": "Ransomware attack on a private hospital exposes highly sensitive patient data",
     "paraphrase": "Attackers encrypted servers at a private hospital. The breach notice published by the data protection authority lists patients, staff and visitors among those affected, with data including sexual life and biometric details. The number affected was not yet known.",
     "source": "T24",
     "url": "https://t24.com.tr/gundem/ozel-hastaneye-siber-saldiri-hastalarin-cinsel-yasam-bilgileri-dahil-verileri-sizdirildi,1312070",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-08-03",
     "headline": "Records of about 20,000 private hospital patients reportedly posted for free download",
     "paraphrase": "A user claiming to hold a private hospital's database reportedly posted patients' identity numbers, addresses, diagnoses, prescriptions and insurance details online. The leak was unconfirmed and neither the hospital nor authorities had commented when reported.",
     "source": "Pamukkale Haber",
     "url": "https://www.pamukkalehaber.com/denizliyi-sarsan-iddia-hasta-verileri-internete-dustu",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-09-09",
     "headline": "Health services company tells regulator ransomware encrypted its systems; affected people still unknown",
     "paraphrase": "A health services company notified the data protection authority that a ransomware attack encrypted its data over two days. It could not yet say which people or data categories were affected. The board ordered the notice published.",
     "source": "Kişisel Verileri Koruma Kurumu (KVKK)",
     "url": "https://www.kvkk.gov.tr/Icerik/8956/kamuoyu-duyurusu-veri-ihlali-bildirimi-ada-mert-saglik-hizmetleri-ticaret-as",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "ISL",
   "name": "Iceland",
   "region": "Europe",
   "overall": 62,
   "rank": "16=",
   "likelyRank": "8 to 23",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Iceland's records are linked across nearly all public care and patients can block sharing, but the Heilsuvera portal shows only part of the record.",
   "categories": {
    "access": {
     "score": 62,
     "summary": "The Medical Records Act gives a right to a copy of the whole record, clarified by a 2025 amendment. Heilsuvera shows prescriptions, vaccinations and dates of hospital and clinic visits, but not clinical notes or lab results.",
     "sources": [
      {
       "title": "Lög um sjúkraskrár nr. 55/2009 (Alþingi)",
       "url": "https://www.althingi.is/lagas/nuna/2009055.html",
       "date": "2026-09-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Breytingar á lögum um sjúkraskrár samþykktar á Alþingi (Stjórnarráðið)",
       "url": "https://www.stjornarradid.is/efst-a-baugi/frettir/stok-frett/2025/11/21/Breytingar-a-logum-um-sjukraskrar-samthykktar-a-Althingi/",
       "date": "2025-11-21",
       "publisherClass": "official"
      },
      {
       "title": "Persónuverndarstefna Heilsuveru",
       "url": "https://www.heilsuvera.is/personuverndarstefna/",
       "date": "2025-06-03",
       "publisherClass": "official"
      },
      {
       "title": "Aðgangur að sjúkraskrá (island.is)",
       "url": "https://island.is/sjukraskra",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 55,
     "summary": "Patients can ban sharing through linked record systems, for a whole provider, a department or a named party, and have a legal right to learn who looked at their record. Bans need a signed form, and the access log comes on request only.",
     "sources": [
      {
       "title": "Lög um sjúkraskrár nr. 55/2009 (Alþingi)",
       "url": "https://www.althingi.is/lagas/nuna/2009055.html",
       "date": "2026-09-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Access to health records: FAQ (island.is)",
       "url": "https://island.is/en/access-to-health-records/faq-health-records",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Persónuverndarstefna Heilsuveru",
       "url": "https://www.heilsuvera.is/personuverndarstefna/",
       "date": "2025-06-03",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "GDPR applies through the EEA and Act 90/2018, and the regulator has fined health bodies. In 2023 it fined the Directorate of Health 12 million kr after a Heilsuvera flaw left messages and maternity attachments open to other logged-in users.",
     "sources": [
      {
       "title": "Sekt vegna öryggisveikleika í Heilsuveru (Persónuvernd)",
       "url": "https://island.is/s/personuvernd/urskurdir-akvardanir-og-alit/sekt-vegna-oryggisveikleika-i-heilsuveru",
       "date": "2023-06-27",
       "publisherClass": "official"
      },
      {
       "title": "Sekt á hendur Heilsugæslu höfuðborgarsvæðisins (Persónuvernd)",
       "url": "https://island.is/s/personuvernd/urskurdir-akvardanir-og-alit/sekt-a-hendur-heilsugaeslu-hofudborgarsvaedisins-vegna-vinnslu-personuupplysinga-i-sameiginlegu-sjukraskrarkerfi",
       "date": "2025-02-17",
       "publisherClass": "official"
      },
      {
       "title": "Lög um persónuvernd og vinnslu persónuupplýsinga nr. 90/2018 (Alþingi)",
       "url": "https://www.althingi.is/lagas/nuna/2018090.html",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 76,
     "summary": "A 2019 Nordic Council of Ministers report says all hospitals and primary care clinics share records over the national HealthNet, and every pharmacy is linked for e-prescriptions. Some private providers still keep non-digital records until a December 2026 deadline.",
     "sources": [
      {
       "title": "eHealth standardisation in the Nordic countries (TemaNord 2019:537)",
       "url": "https://norden.diva-portal.org/smash/get/diva2:1340369/FULLTEXT01.pdf",
       "date": "2019",
       "publisherClass": "intergov"
      },
      {
       "title": "Breytingar á lögum um sjúkraskrár samþykktar á Alþingi (Stjórnarráðið)",
       "url": "https://www.stjornarradid.is/efst-a-baugi/frettir/stok-frett/2025/11/21/Breytingar-a-logum-um-sjukraskrar-samthykktar-a-Althingi/",
       "date": "2025-11-21",
       "publisherClass": "official"
      },
      {
       "title": "Heilbrigðisþjónusta yfir landamæri (island.is)",
       "url": "https://island.is/heilbrigdisthjonusta-yfir-landamaeri",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 58,
     "summary": "The Medical Records Act bars any access to records without a legal basis, which shuts out insurers and employers by default. No Iceland-specific ban on selling health data or using it for marketing beyond GDPR was verified.",
     "sources": [
      {
       "title": "Lög um sjúkraskrár nr. 55/2009 (Alþingi)",
       "url": "https://www.althingi.is/lagas/nuna/2009055.html",
       "date": "2026-09-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Sekt á hendur Heilsugæslu höfuðborgarsvæðisins (Persónuvernd)",
       "url": "https://island.is/s/personuvernd/urskurdir-akvardanir-og-alit/sekt-a-hendur-heilsugaeslu-hofudborgarsvaedisins-vegna-vinnslu-personuupplysinga-i-sameiginlegu-sjukraskrarkerfi",
       "date": "2025-02-17",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 74,
     "summary": "Treating staff can reach records at other providers through linked systems unless the patient has banned it, and every doctor can see all prescriptions and dispensings. Patients can pre-authorise sharing of key data for emergency care elsewhere in the EEA.",
     "sources": [
      {
       "title": "Lög um sjúkraskrár nr. 55/2009 (Alþingi)",
       "url": "https://www.althingi.is/lagas/nuna/2009055.html",
       "date": "2026-09-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Aðgangur að lyfjagagnagrunni (island.is)",
       "url": "https://island.is/adgangur-ad-lyfjagagnagrunni",
       "date": "2026-09-11",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Research on health records can proceed without individual consent once an ethics committee approves, and each research look into a record is logged in it. Patients can bar identifiable storage in research health-data collections, but no general opt-out from record research was found.",
     "sources": [
      {
       "title": "Lög um vísindarannsóknir á heilbrigðissviði nr. 44/2014 (Alþingi)",
       "url": "https://www.althingi.is/lagas/nuna/2014044.html",
       "date": "2026-09-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lífsýni (island.is)",
       "url": "https://island.is/lifsyni",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Lög nr. 34/2025 um breytingu á lögum um landlækni og lýðheilsu og lögum um sjúkraskrár",
       "url": "https://www.althingi.is/altext/stjt/2025.034.html",
       "date": "2025-06-19",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "EU medical device rules apply through Act 132/2020, but the EU AI Act is not yet law in Iceland. The minister said on 27 September 2026 that a consultation on adopting it would open this autumn.",
     "sources": [
      {
       "title": "Lög um lækningatæki nr. 132/2020 (Alþingi)",
       "url": "https://www.althingi.is/lagas/nuna/2020132.html",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Boðar fyrstu lögin og reglurnar gagnvart gervigreind (Vísir)",
       "url": "https://www.visir.is/g/20262939826d/bodar-fyrstu-login-og-reglurnar-gagnvart-gervigreind",
       "date": "2026-09-27",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Medical Records Act (lög um sjúkraskrár) no. 55/2009",
     "level": "National",
     "year": "2009",
     "what": "Right to a copy, who-accessed information, bans on linked sharing, research storage ban, penalties.",
     "url": "https://www.althingi.is/lagas/nuna/2009055.html"
    },
    {
     "name": "Act no. 81/2025 amending the Medical Records Act",
     "level": "National",
     "year": "2025",
     "what": "Clarifies right to copies, sets copy fees and appeals, requires digital records by 1 December 2026.",
     "url": "https://www.althingi.is/altext/stjt/2025.081.html"
    },
    {
     "name": "Act no. 34/2025 on health registries and quality registries",
     "level": "National",
     "year": "2025",
     "what": "Sets Directorate of Health registries and quality registries; de-identified data for research and planning.",
     "url": "https://www.althingi.is/altext/stjt/2025.034.html"
    },
    {
     "name": "Data Protection Act no. 90/2018 (GDPR via EEA)",
     "level": "National",
     "year": "2018",
     "what": "Gives GDPR force in Iceland; health data sensitive; independent regulator Persónuvernd.",
     "url": "https://www.althingi.is/lagas/nuna/2018090.html"
    },
    {
     "name": "Health Research Act (lög um vísindarannsóknir á heilbrigðissviði) no. 44/2014",
     "level": "National",
     "year": "2014",
     "what": "Consent rules for health research; ethics committee may approve record use without consent.",
     "url": "https://www.althingi.is/lagas/nuna/2014044.html"
    },
    {
     "name": "Medical Devices Act (lög um lækningatæki) no. 132/2020",
     "level": "National",
     "year": "2020",
     "what": "Gives EU MDR and IVDR legal force in Iceland from 26 May 2021.",
     "url": "https://www.althingi.is/lagas/nuna/2020132.html"
    }
   ],
   "dti": {
    "grade": 90,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-05-12",
     "headline": "Specialist doctor's repeated look-ups in a patient's record ruled unlawful",
     "paraphrase": "A specialist doctor opened an adult's health record six times over several years without a treatment relationship or consent. The data protection authority ruled those look-ups unlawful but imposed no fine.",
     "source": "Persónuvernd (Icelandic Data Protection Authority)",
     "url": "https://island.is/s/personuvernd/urskurdir-akvardanir-og-alit/uppflettingar-landspitala-og-serfraedilaeknis-i-sjukraskra",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-11-17",
     "headline": "National hospital sent a patient's health data to the wrong primary care clinic",
     "paraphrase": "The national hospital sent an adult patient's sensitive health information to a primary care clinic she was not registered with. The data protection authority ruled the disclosure unlawful; the hospital said it regretted the mistake.",
     "source": "Persónuvernd (Icelandic Data Protection Authority)",
     "url": "https://island.is/s/personuvernd/urskurdir-akvardanir-og-alit/uppflettingar-laeknis-i-sjukraskra-og-midlun-landspitalans-a-vidkvaemum-personuupplysingum-17-11-2025",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-11-03",
     "headline": "Hospital employee's look-ups in a patient's record ruled unlawful",
     "paraphrase": "A hospital employee opened an adult patient's health record twice with no work reason. The data protection authority held the employee personally responsible and ruled the look-ups unlawful.",
     "source": "Persónuvernd (Icelandic Data Protection Authority)",
     "url": "https://island.is/s/personuvernd/urskurdir-akvardanir-og-alit/oheimilar-uppflettingar-starfsmanns-landspitala-i-sjukraskra-3-11-2025",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-06-11",
     "headline": "Court upholds fine over patient portal flaw that exposed other people's health files",
     "paraphrase": "A district court confirmed the data protection authority's finding that the national patient portal had a serious security weakness letting users open others' health files and messages. It cut the fine on the Directorate of Health to ISK 8 million.",
     "source": "Persónuvernd (Icelandic Data Protection Authority), on Reykjavík District Court case E-2571/2024",
     "url": "https://island.is/en/news/akvoerdun-personuverndar-um-oeryggisveikleika-i-heilsuveru-stadfest-i",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-12-29",
     "headline": "Patient alleges doctors falsified record entries as complaint waits over three years",
     "paraphrase": "A patient told the parliamentary ombudsman that two doctors entered false information in their health record and that access requests were mishandled. A complaint to the Directorate of Health had been pending since November 2022.",
     "source": "DV",
     "url": "https://www.dv.is/frettir/2025/12/29/laeknar-sakadir-um-ad-falsa-sjukraskyrslu-til-rannsoknar-hja-landlaekni-thrju-ar/",
     "theme": "record_wrong",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "ISR",
   "name": "Israel",
   "region": "Middle East",
   "overall": 62,
   "rank": "16=",
   "likelyRank": "10 to 26",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Every Israeli can read most of their record in their health fund's app, but the national exchange offers only an all-or-nothing opt-out.",
   "categories": {
    "access": {
     "score": 66,
     "summary": "The Patient's Rights Act gives a right to the record and a copy, and a 2019 ministry circular makes all four health funds show members structured and free-text data online. No fixed deadline was found and no official usage figure was verified.",
     "sources": [
      {
       "title": "Chok Zchuyot HaCholeh, 1996 (Patient's Rights Act), sections 18 to 20, consolidated text (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%96%D7%9B%D7%95%D7%99%D7%95%D7%AA_%D7%94%D7%97%D7%95%D7%9C%D7%94",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Takanot Zchuyot HaCholeh (maximum fee for a copy of a medical record or viewing it), 2019 (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%AA%D7%A7%D7%A0%D7%95%D7%AA_%D7%96%D7%9B%D7%95%D7%99%D7%95%D7%AA_%D7%94%D7%97%D7%95%D7%9C%D7%94_(%D7%AA%D7%A9%D7%9C%D7%95%D7%9D_%D7%9E%D7%A8%D7%91%D7%99_%D7%91%D7%A2%D7%93_%D7%9E%D7%A1%D7%99%D7%A8%D7%AA_%D7%94%D7%A2%D7%AA%D7%A7_%D7%A8%D7%A9%D7%95%D7%9E%D7%94_%D7%A8%D7%A4%D7%95%D7%90%D7%99%D7%AA_%D7%90%D7%95_%D7%A2%D7%99%D7%95%D7%9F_%D7%91%D7%94)",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Director-General Circular 8/2019: giving patients access to personal health data, 'Health in the palm of your hand' (Ministry of Health)",
       "url": "https://www.gov.il/BlobFolder/policy/mk08-2019/he/files_circulars_mk_mk08_2019.pdf",
       "date": "2019-11-11",
       "publisherClass": "official"
      },
      {
       "title": "Clalit app: your medical information (Clalit Health Services)",
       "url": "https://www.clalit.co.il/he/info/services/Pages/new_app.aspx",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 50,
     "summary": "Everyone is in the national Eitan exchange by default and can leave only completely, by a request at a health fund branch that is handled within 30 days. Every view is logged, but no patient-facing view of that log was found.",
     "sources": [
      {
       "title": "HaReshet HaLeumit LeShituf Meida Refui, Eitan (Ministry of Health)",
       "url": "https://www.gov.il/he/pages/shared-medical-info",
       "date": "2026-09-10",
       "publisherClass": "official"
      },
      {
       "title": "Director-General Circular 8/2019: giving patients access to personal health data, 'Health in the palm of your hand' (Ministry of Health)",
       "url": "https://www.gov.il/BlobFolder/policy/mk08-2019/he/files_circulars_mk_mk08_2019.pdf",
       "date": "2019-11-11",
       "publisherClass": "official"
      },
      {
       "title": "Chok Zchuyot HaCholeh, 1996 (Patient's Rights Act), sections 18 to 20, consolidated text (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%96%D7%9B%D7%95%D7%99%D7%95%D7%AA_%D7%94%D7%97%D7%95%D7%9C%D7%94",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Chok Niyud Meida Refui, 2024 (Medical Information Portability Law), consolidated with Amendment 2 of 2025 (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%A0%D7%99%D7%95%D7%93_%D7%9E%D7%99%D7%93%D7%A2_%D7%A8%D7%A4%D7%95%D7%90%D7%99",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 58,
     "summary": "Amendment 13, in force since 14 August 2025, makes health data specially sensitive and forces hospitals and health funds to appoint data protection officers. In July 2026 the regulator fined Meuhedet NIS 256,000 for reporting a breach two months late.",
     "sources": [
      {
       "title": "Chok Haganat HaPratiut, 1981 (Protection of Privacy Law), consolidated with Amendment 13 (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%94%D7%92%D7%A0%D7%AA_%D7%94%D7%A4%D7%A8%D7%98%D7%99%D7%95%D7%AA",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Israel: Significant Amendment to the Privacy Law Takes Effect (Pearl Cohen)",
       "url": "https://www.pearlcohen.com/israel-significant-amendment-to-the-privacy-law-takes-effect/",
       "date": "2025-09-03",
       "publisherClass": "law_firm"
      },
      {
       "title": "Meuhedet fined NIS 256,000, first fine since the privacy law amendment (NWS News)",
       "url": "https://nws.report/health-and-environment/151313/",
       "date": "2026-07-21",
       "publisherClass": "news"
      },
      {
       "title": "Clalit probes suspected cyberattack after Iranian-linked hackers leak patient files (Ynet News)",
       "url": "https://www.ynetnews.com/health_science/article/ry0gesnobl",
       "date": "2026-02-25",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 78,
     "summary": "Eitan links hospitals, health funds, mother and child clinics, district health offices and prison medicine, and health funds receive emergency and discharge summaries every day. Each health fund keeps primary care, labs and pharmacy in one record.",
     "sources": [
      {
       "title": "HaReshet HaLeumit LeShituf Meida Refui, Eitan (Ministry of Health)",
       "url": "https://www.gov.il/he/pages/shared-medical-info",
       "date": "2026-09-10",
       "publisherClass": "official"
      },
      {
       "title": "Digital prescriptions (Maccabi Healthcare Services)",
       "url": "https://www.maccabi4u.co.il/31276/digital-services/medication/digital_prescriptions/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Chok Niyud Meida Refui, 2024 (Medical Information Portability Law), consolidated with Amendment 2 of 2025 (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%A0%D7%99%D7%95%D7%93_%D7%9E%D7%99%D7%93%D7%A2_%D7%A8%D7%A4%D7%95%D7%90%D7%99",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Publication of the National Health Registries Draft Bill (2025) for public comment (Gornitzky)",
       "url": "https://www.gornitzky.com/publication-of-the-national-health-registries-draft-bill-2025-for-public-comment/",
       "date": "2025-12-28",
       "publisherClass": "law_firm"
      }
     ]
    },
    "commercial": {
     "score": 56,
     "summary": "Ministry circulars bar exclusive data deals beyond 18 months, require a stated public benefit and forbid uses aimed at insurance or employment discrimination. These are circulars, not statute, and they regulate commercial collaborations rather than ban them.",
     "sources": [
      {
       "title": "Director-General Circular 2/2018: collaborations based on secondary use of health data (Ministry of Health)",
       "url": "https://www.gov.il/BlobFolder/policy/mk02-2018/he/files_circulars_mk_MK02_2018.pdf",
       "date": "2018-01-17",
       "publisherClass": "official"
      },
      {
       "title": "Director-General Circular 1/2018: secondary uses of health data (Ministry of Health)",
       "url": "https://www.gov.il/BlobFolder/policy/mk01-2018/he/files_circulars_mk_MK01_2018.pdf",
       "date": "2018-01-17",
       "publisherClass": "official"
      },
      {
       "title": "Chok Meida Geneti, 2000 (Genetic Information Law), insurer provisions (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%9E%D7%99%D7%93%D7%A2_%D7%92%D7%A0%D7%98%D7%99",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Chok Haganat HaPratiut, 1981 (Protection of Privacy Law), consolidated with Amendment 13 (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%94%D7%92%D7%A0%D7%AA_%D7%94%D7%A4%D7%A8%D7%98%D7%99%D7%95%D7%AA",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 75,
     "summary": "Authorised clinicians at any member hospital or health fund can view a patient's data from other members during the visit, without asking for consent. Highly confidential items are never shown, and patients who opted out appear with no data.",
     "sources": [
      {
       "title": "HaReshet HaLeumit LeShituf Meida Refui, Eitan (Ministry of Health)",
       "url": "https://www.gov.il/he/pages/shared-medical-info",
       "date": "2026-09-10",
       "publisherClass": "official"
      },
      {
       "title": "Chok Zchuyot HaCholeh, 1996 (Patient's Rights Act), sections 18 to 20, consolidated text (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%96%D7%9B%D7%95%D7%99%D7%95%D7%AA_%D7%94%D7%97%D7%95%D7%9C%D7%94",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Director-General Circular 8/2019: giving patients access to personal health data, 'Health in the palm of your hand' (Ministry of Health)",
       "url": "https://www.gov.il/BlobFolder/policy/mk08-2019/he/files_circulars_mk_mk08_2019.pdf",
       "date": "2019-11-11",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "Identifiable data needs specific consent for research, but Helsinki ethics committees may waive consent for properly de-identified data, and there is no general opt-out. Ministry rules push research into secure research rooms inside each organisation.",
     "sources": [
      {
       "title": "Director-General Circular 1/2018: secondary uses of health data (Ministry of Health)",
       "url": "https://www.gov.il/BlobFolder/policy/mk01-2018/he/files_circulars_mk_MK01_2018.pdf",
       "date": "2018-01-17",
       "publisherClass": "official"
      },
      {
       "title": "Chok Zchuyot HaCholeh, 1996 (Patient's Rights Act), sections 18 to 20, consolidated text (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%96%D7%9B%D7%95%D7%99%D7%95%D7%AA_%D7%94%D7%97%D7%95%D7%9C%D7%94",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Psifas: Israeli National Genomic Medicine Initiative",
       "url": "https://psifas.org.il/en/%D7%93%D7%A3-%D7%94%D7%91%D7%99%D7%AA-english/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Israel's health ministry plans controversial genetic mega-database (Calcalist Ctech)",
       "url": "https://www.calcalistech.com/ctechnews/article/kiutzefjf",
       "date": "2026-01-25",
       "publisherClass": "news"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "The Medical Equipment Law requires registration of devices and the software that runs them, with approval for every change. The ministry's February 2026 AI trial principles are guidance for ethics committees, so the cell sits at the top of the guidance-only band.",
     "sources": [
      {
       "title": "Chok Tziud Refui, 2012 (Medical Equipment Law), consolidated text (Hebrew Wikisource)",
       "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%A6%D7%99%D7%95%D7%93_%D7%A8%D7%A4%D7%95%D7%90%D7%99",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Key Principles for Evaluating AI-Driven Interventional Trials (Ministry of Health)",
       "url": "https://www.gov.il/BlobFolder/rfp/key-principles-for-evaluating-ai-driven-interventional-trials/he/subjects_Digital_Medical_Technology_Key-Principles-for-Evaluating-AI-Driven-Interventional-Trials-en.pdf",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Israel Life Sciences & Healthcare: Regulatory Overview (2026) (Arnon, Tadmor-Levy)",
       "url": "https://arnontl.com/news/israel-life-sciences-healthcare-regulatory-overview-2026/",
       "date": "2026-04-21",
       "publisherClass": "law_firm"
      },
      {
       "title": "Israel blocks public AI tools on government hospital computers over data leak fears (Ynet News)",
       "url": "https://www.ynetnews.com/health_science/article/bkqtty2fze",
       "date": "2026-06-26",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Patient's Rights Act 1996",
     "level": "National",
     "year": "1996",
     "what": "Right to record information and a copy; confidentiality; disclosure to other clinicians for treatment without consent.",
     "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%96%D7%9B%D7%95%D7%99%D7%95%D7%AA_%D7%94%D7%97%D7%95%D7%9C%D7%94"
    },
    {
     "name": "Patient's Rights Regulations (maximum fee for a medical record copy) 2019",
     "level": "National",
     "year": "2019",
     "what": "Free online viewing; computerised copy capped at NIS 10; free discharge letters and test results.",
     "url": "https://he.wikisource.org/wiki/%D7%AA%D7%A7%D7%A0%D7%95%D7%AA_%D7%96%D7%9B%D7%95%D7%99%D7%95%D7%AA_%D7%94%D7%97%D7%95%D7%9C%D7%94_(%D7%AA%D7%A9%D7%9C%D7%95%D7%9D_%D7%9E%D7%A8%D7%91%D7%99_%D7%91%D7%A2%D7%93_%D7%9E%D7%A1%D7%99%D7%A8%D7%AA_%D7%94%D7%A2%D7%AA%D7%A7_%D7%A8%D7%A9%D7%95%D7%9E%D7%94_%D7%A8%D7%A4%D7%95%D7%90%D7%99%D7%AA_%D7%90%D7%95_%D7%A2%D7%99%D7%95%D7%9F_%D7%91%D7%94)"
    },
    {
     "name": "Protection of Privacy Law 1981, Amendment 13",
     "level": "National",
     "year": "2024",
     "what": "Health data specially sensitive; mandatory officers for hospitals and health funds; regulator fines; in force August 2025.",
     "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%94%D7%92%D7%A0%D7%AA_%D7%94%D7%A4%D7%A8%D7%98%D7%99%D7%95%D7%AA"
    },
    {
     "name": "Medical Information Portability Law 2024",
     "level": "National",
     "year": "2024",
     "what": "Consent-based transfer of 16 data baskets between providers via a ministry permission system, starting July 2027.",
     "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%A0%D7%99%D7%95%D7%93_%D7%9E%D7%99%D7%93%D7%A2_%D7%A8%D7%A4%D7%95%D7%90%D7%99"
    },
    {
     "name": "Genetic Information Law 2000",
     "level": "National",
     "year": "2000",
     "what": "Insurers and health funds may not request genetic tests or use identified genetic data, with narrow exceptions.",
     "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%9E%D7%99%D7%93%D7%A2_%D7%92%D7%A0%D7%98%D7%99"
    },
    {
     "name": "Medical Equipment Law 2012",
     "level": "National",
     "year": "2012",
     "what": "Devices, including software needed to run them, must be registered; changes need approval.",
     "url": "https://he.wikisource.org/wiki/%D7%97%D7%95%D7%A7_%D7%A6%D7%99%D7%95%D7%93_%D7%A8%D7%A4%D7%95%D7%90%D7%99"
    },
    {
     "name": "Director-General Circulars 1/2018 and 2/2018",
     "level": "National",
     "year": "2018",
     "what": "Consent or de-identification for secondary use; limits on exclusivity and discriminatory uses in data deals.",
     "url": "https://www.gov.il/BlobFolder/policy/mk02-2018/he/files_circulars_mk_MK02_2018.pdf"
    }
   ],
   "dti": {
    "grade": 80,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-07-21",
     "headline": "Health fund fined for slow reporting of a fault exposing members' medical files",
     "paraphrase": "A member reported he could open a relative's medical file because of a system fault. The regulator found the fund knew in November 2025 but reported only in January, and fined it 256,000 shekels. The fund plans to appeal.",
     "source": "Calcalist (reporting a Privacy Protection Authority decision)",
     "url": "https://www.calcalist.co.il/local_news/article/hjnnojpezl",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-10-03",
     "headline": "Health ministry confirms patients' medical information leaked in hospital cyberattack",
     "paraphrase": "The health ministry said initial checks showed emails sent to and from the hospital on one day had leaked, including medical information in them. It said there was no sign so far of a leak from the central record system.",
     "source": "Walla News",
     "url": "https://news.walla.co.il/item/3784752",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-02-25",
     "headline": "Hackers claim they published thousands of patient documents taken from a health fund",
     "paraphrase": "A hacker group claimed to have stolen and posted documents of more than 10,000 patients, including referrals and sick-leave notes. The fund said it was checking the claim with national cyber authorities and had reported to the privacy regulator.",
     "source": "Channel 14 (C14)",
     "url": "https://www.c14.co.il/article/1472789",
     "theme": "breach",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "LVA",
   "name": "Latvia",
   "region": "Europe",
   "overall": 62,
   "rank": "16=",
   "likelyRank": "11 to 25",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "The E-veselība record, with an access log and patient bans, covers prescriptions, labs and discharges, but staff snooping persists and the portal is being rebuilt.",
   "categories": {
    "access": {
     "score": 64,
     "summary": "The free national E-veselība portal shows prescriptions, referrals, discharge summaries and lab results (from 2024), and the law gives one free copy within three working days. Export and full history depth were not verified, so the score sits in the lower half of its band.",
     "sources": [
      {
       "title": "Pacientu tiesību likums (Patient Rights Law), Article 9",
       "url": "https://likumi.lv/ta/id/203008-pacientu-tiesibu-likums",
       "date": "2009-12-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kādi dati pieejami E-veselības sistēmā, un kas tiem var piekļūt? (LV portāls)",
       "url": "https://lvportals.lv/skaidrojumi/388343-kadi-dati-pieejami-e-veselibas-sistema-un-kas-tiem-var-pieklut-2026",
       "date": "2026-04-17",
       "publisherClass": "official"
      },
      {
       "title": "Latvijas Digitālās veselības centrs: pirmajā darbības gadā paveikts būtisks darbs",
       "url": "https://ldvc.lv/latvijas-digitalas-veselibas-centrs-pirmaja-darbibas-gada-paveikts-butisks-darbs-digitalas-veselibas-attistiba/",
       "date": "2026-02-02",
       "publisherClass": "official"
      },
      {
       "title": "State of Health in the EU: Latvia Country Health Profile 2025 (OECD and European Commission)",
       "url": "https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/12/country-health-profile-2025-country-notes_7e72146d/latvia_49bcb16d/acdd6b03-en.pdf",
       "date": "2025-12",
       "publisherClass": "intergov"
      }
     ]
    },
    "control": {
     "score": 62,
     "summary": "Patients can see an audit log of who opened their record, ban all access or block chosen providers and data, and delegate access. Records are open to treating staff by default, and repeated snooping cases keep the score in the lower half of the band.",
     "sources": [
      {
       "title": "Noteikumi par vienoto veselības nozares elektronisko informācijas sistēmu (Cabinet Regulation No. 134)",
       "url": "https://likumi.lv/ta/id/264943",
       "date": "2014-03-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kādi dati pieejami E-veselības sistēmā, un kas tiem var piekļūt? (LV portāls)",
       "url": "https://lvportals.lv/skaidrojumi/388343-kadi-dati-pieejami-e-veselibas-sistema-un-kas-tiem-var-pieklut-2026",
       "date": "2026-04-17",
       "publisherClass": "official"
      },
      {
       "title": "Doctor raises alarm over unauthorized patient data access (LSM)",
       "url": "https://eng.lsm.lv/article/society/health/29.01.2024-doctor-raises-alarm-over-unauthorized-patient-data-access.a540705/",
       "date": "2024-01-29",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 58,
     "summary": "Patient data may be disclosed only with written consent or under listed exceptions, and an independent regulator oversees GDPR. Health-sector enforcement is mild: staff snooping in E-veselība drew mostly warnings in 2025 and one EUR 250 fine.",
     "sources": [
      {
       "title": "Pacientu tiesību likums (Patient Rights Law), Article 10",
       "url": "https://likumi.lv/ta/id/203008-pacientu-tiesibu-likums",
       "date": "2009-12-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Fizisko personu datu apstrādes likums (Personal Data Processing Law)",
       "url": "https://likumi.lv/ta/id/300099-fizisko-personu-datu-apstrades-likums",
       "date": "2018-06-21",
       "publisherClass": "legal_text"
      },
      {
       "title": "E-veselības dati skatīti bez iemesla: DVI atklāj pārkāpumus Latvijā (BNN)",
       "url": "https://bnn.lv/e-veselibas-dati-skatiti-bez-iemesla-dvi-atklaj-parkapumus-latvija/",
       "date": "2026-03-20",
       "publisherClass": "news"
      },
      {
       "title": "Damaged cable leaves patients without meds in Latvia (LSM)",
       "url": "https://eng.lsm.lv/article/society/health/30.06.2026-damaged-cable-leaves-patients-without-meds-in-latvia.a653205/",
       "date": "2026-06-30",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 70,
     "summary": "Prescriptions, lab reports, imaging, discharge summaries and referrals flow into one national system: in August 2026 pharmacies filled about 1.1 million e-prescriptions and 30 paper ones. Low ICT investment and a fragile network link hold the score down.",
     "sources": [
      {
       "title": "E-veselības un e-vakcinācijas lietojuma pārskats, 2026 augusts (LDVC)",
       "url": "https://ldvc.lv/wp-content/uploads/2026/09/EVES_EVAK_2026_augusts.pdf",
       "date": "2026-09",
       "publisherClass": "official"
      },
      {
       "title": "Noteikumi par vienoto veselības nozares elektronisko informācijas sistēmu (Cabinet Regulation No. 134)",
       "url": "https://likumi.lv/ta/id/264943",
       "date": "2014-03-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital referrals now mandatory in Latvia's healthcare system (LSM)",
       "url": "https://eng.lsm.lv/article/society/health/05.05.2026-digital-referrals-now-mandatory-in-latvias-healthcare-system.a645708/",
       "date": "2026-05-05",
       "publisherClass": "news"
      },
      {
       "title": "State of Health in the EU: Latvia Country Health Profile 2025 (OECD and European Commission)",
       "url": "https://www.oecd.org/content/dam/oecd/en/publications/reports/2025/12/country-health-profile-2025-country-notes_7e72146d/latvia_49bcb16d/acdd6b03-en.pdf",
       "date": "2025-12",
       "publisherClass": "intergov"
      }
     ]
    },
    "commercial": {
     "score": 55,
     "summary": "Providers may release patient data only with written consent or under a closed legal list, and research access is permit-based. No Latvia-specific ban on selling health data or on health apps beyond GDPR was verified.",
     "sources": [
      {
       "title": "Pacientu tiesību likums (Patient Rights Law), Article 10",
       "url": "https://likumi.lv/ta/id/203008-pacientu-tiesibu-likums",
       "date": "2009-12-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kārtība, kādā atļauj izmantot pacienta datus konkrētā pētījumā (Cabinet Regulation No. 446)",
       "url": "https://likumi.lv/ta/id/275747-kartiba-kada-atlauj-izmantot-pacienta-datus-konkreta-petijuma",
       "date": "2015-08-04",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 66,
     "summary": "Treating staff can see nearly all of a patient's national record, apart from psychiatric and addiction data that only specially authorised staff can open. The structured patient summary is rarely filled in, and patient bans can hide data.",
     "sources": [
      {
       "title": "Kādi dati pieejami E-veselības sistēmā, un kas tiem var piekļūt? (LV portāls)",
       "url": "https://lvportals.lv/skaidrojumi/388343-kadi-dati-pieejami-e-veselibas-sistema-un-kas-tiem-var-pieklut-2026",
       "date": "2026-04-17",
       "publisherClass": "official"
      },
      {
       "title": "Noteikumi par vienoto veselības nozares elektronisko informācijas sistēmu (Cabinet Regulation No. 134)",
       "url": "https://likumi.lv/ta/id/264943",
       "date": "2014-03-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "E-veselības un e-vakcinācijas lietojuma pārskats, 2026 augusts (LDVC)",
       "url": "https://ldvc.lv/wp-content/uploads/2026/09/EVES_EVAK_2026_augusts.pdf",
       "date": "2026-09",
       "publisherClass": "official"
      },
      {
       "title": "Latvia will start exchanging laboratory data with other EU states (LSM)",
       "url": "https://eng.lsm.lv/article/society/health/04.06.2026-latvia-will-start-exchanging-laboratory-data-with-other-eu-states.a650077/",
       "date": "2026-06-04",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Identifiable records can be used for research without consent if a state permit is granted and the patient has not filed a written ban. The ban is filed with each provider, not as one general opt-out, so the score tops the no-opt-out band.",
     "sources": [
      {
       "title": "Pacientu tiesību likums (Patient Rights Law), Article 10(7) to 10(9)",
       "url": "https://likumi.lv/ta/id/203008-pacientu-tiesibu-likums",
       "date": "2009-12-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kārtība, kādā atļauj izmantot pacienta datus konkrētā pētījumā (Cabinet Regulation No. 446)",
       "url": "https://likumi.lv/ta/id/275747-kartiba-kada-atlauj-izmantot-pacienta-datus-konkreta-petijuma",
       "date": "2015-08-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "2026-07-08",
       "publisherClass": "intergov"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device law and the EU AI Act, which Latvia applies through administrative measures with no national AI Act law. No Latvia-specific clinical AI rules or guidance were verified.",
     "sources": [
      {
       "title": "Latvija sper soli pretī drošam un atbildīgam mākslīgajam intelektam (VARAM)",
       "url": "https://www.varam.gov.lv/lv/jaunums/latvija-sper-soli-preti-drosam-un-atbildigam-maksligajam-intelektam-valdiba-izskata-mi-akta-ieviesanas-planu",
       "date": "2025-02-25",
       "publisherClass": "official"
      },
      {
       "title": "Mākslīgā intelekta (MI) akts (VARAM)",
       "url": "https://www.varam.gov.lv/lv/maksliga-intelekta-mi-akts",
       "date": "2026-09-29",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Patient Rights Law (Pacientu tiesību likums)",
     "level": "National",
     "year": "2009",
     "what": "Right to see and copy records, written consent for disclosure, research rules with a written ban right.",
     "url": "https://likumi.lv/ta/id/203008-pacientu-tiesibu-likums"
    },
    {
     "name": "Cabinet Regulation No. 134 on the unified health sector information system",
     "level": "National",
     "year": "2014",
     "what": "Runs E-veselība: upload deadlines, access logs, patient full or partial access bans, retention periods.",
     "url": "https://likumi.lv/ta/id/264943"
    },
    {
     "name": "Cabinet Regulation No. 446 on permits to use patient data in research",
     "level": "National",
     "year": "2015",
     "what": "Disease control centre grants research permits and publishes each permit within five working days.",
     "url": "https://likumi.lv/ta/id/275747-kartiba-kada-atlauj-izmantot-pacienta-datus-konkreta-petijuma"
    },
    {
     "name": "Personal Data Processing Law (Fizisko personu datu apstrādes likums)",
     "level": "National",
     "year": "2018",
     "what": "Applies GDPR in Latvia and names the independent Data State Inspectorate as regulator.",
     "url": "https://likumi.lv/ta/id/300099-fizisko-personu-datu-apstrades-likums"
    },
    {
     "name": "Regulation (EU) 2025/327 (European Health Data Space)",
     "level": "Supranational",
     "year": "2025",
     "what": "Cross-border record access and a secondary-use opt-out; main duties apply from March 2029 and 2031.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "Regulation (EU) 2024/1689 (AI Act)",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk-based AI rules, including high-risk duties; Latvia applies it through designated agencies.",
     "url": "https://www.varam.gov.lv/lv/maksliga-intelekta-mi-akts"
    }
   ],
   "dti": {
    "grade": 90,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-08-03",
     "headline": "Manager reprimanded for checking an employee's sick-leave record in the national health system",
     "paraphrase": "A health worker who supervised a colleague opened the colleague's national health record to check whether sick leave was open. The person had restricted access to their health data. The regulator still found the lookup unlawful and issued a reprimand.",
     "source": "Datu valsts inspekcija (Data State Inspectorate of Latvia)",
     "url": "https://www.dvi.gov.lv/lv/media/5032/download?attachment",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-11-03",
     "headline": "Health worker fined for reading a grown daughter's national health record",
     "paraphrase": "A health worker used work access to read an adult daughter's national health record for personal reasons. The person said the information reached a former spouse. The regulator found no lawful basis and fined the worker 250 euros.",
     "source": "Datu valsts inspekcija (Data State Inspectorate of Latvia)",
     "url": "https://www.dvi.gov.lv/lv/media/4310/download?attachment",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-09-22",
     "headline": "Hospital reprimanded after a software supplier's breach exposed patient and staff data",
     "paraphrase": "Attackers reached a municipal system the hospital used, taking names, personal codes and addresses of its staff and clients. The regulator found the hospital had not supervised the supplier or reported on time, and reprimanded it. The hospital appealed.",
     "source": "Datu valsts inspekcija (Data State Inspectorate of Latvia)",
     "url": "https://www.dvi.gov.lv/lv/media/4403/download?attachment",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-02-21",
     "headline": "Regulator rejects mistyped-code excuse after a person's health record was opened",
     "paraphrase": "A person complained that staff at a family practice they did not use had opened their record and prescriptions. The practice blamed a mistyped personal code. The regulator found the lookup unrelated to care and issued a reprimand.",
     "source": "Datu valsts inspekcija (Data State Inspectorate of Latvia)",
     "url": "https://www.dvi.gov.lv/lv/media/4112/download?attachment",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2024-12-03",
     "headline": "Hospital physician assistant fined for repeatedly viewing three people's health records",
     "paraphrase": "Over several years a physician assistant used work logins to the national health system and two hospital systems to view three people's health data for personal reasons. The regulator found no care purpose and fined him 500 euros.",
     "source": "Datu valsts inspekcija (Data State Inspectorate of Latvia)",
     "url": "https://www.dvi.gov.lv/lv/media/4259/download?attachment",
     "theme": "breach",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "SGP",
   "name": "Singapore",
   "region": "Asia",
   "overall": 62,
   "rank": "16=",
   "likelyRank": "11 to 25",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "A 2026 law, not yet in force, makes every provider feed one national record without consent; patients can block access, but very few do.",
   "categories": {
    "access": {
     "score": 62,
     "summary": "Patients can view medications, immunisations and lab results from the national record in HealthHub, and the PDPA gives a right to request the rest from each provider. But providers may charge a fee and need not hand over copies of doctors' notes.",
     "sources": [
      {
       "title": "NEHR FAQ (Synapxe, operator of the NEHR)",
       "url": "https://www.synapxe.sg/healthtech/national-programmes/national-electronic-health-record-nehr/faq",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Overview of the Health Information Act (HIA) (healthinfo.gov.sg, MOH)",
       "url": "https://www.healthinfo.gov.sg/hia/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Advisory Guidelines for the Healthcare Sector, revised 20 September 2023 (PDPC)",
       "url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/advisory-guidelines-for-the-healthcare-sector-sep-2023.pdf",
       "date": "2023-09-20",
       "publisherClass": "official"
      },
      {
       "title": "Personal Data Protection Act 2012, sections 4, 21, 26D and 48J (Singapore Statutes Online)",
       "url": "https://sso.agc.gov.sg/Act/PDPA2012",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "control": {
     "score": 58,
     "summary": "Data flows into the NEHR without consent, but a person can block all provider access and can see a one-year log of which institutions opened their record. Only about 2,300 people have placed a block since 2011, and finer choices in HealthHub are planned from 2027.",
     "sources": [
      {
       "title": "Health Information Act 2026 (No. 1 of 2026), Singapore Statutes Online",
       "url": "https://sso.agc.gov.sg/Act/HIA2026/Uncommenced/20260624040946?DocDate=20260212",
       "date": "2026-02-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Overview of the Health Information Act (HIA) (healthinfo.gov.sg, MOH)",
       "url": "https://www.healthinfo.gov.sg/hia/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "NEHR FAQ (Synapxe, operator of the NEHR)",
       "url": "https://www.synapxe.sg/healthtech/national-programmes/national-electronic-health-record-nehr/faq",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Health Information Bill to support coordinated care across Singapore's healthcare ecosystem (MOH)",
       "url": "https://www.moh.gov.sg/newsroom/health-information-bill-to-support-coordinated-care-across-singapore-s-healthcare-ecosystem/",
       "date": "2026-01-12",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "PDPA requires breach notice within 3 days, and PDPC fined SingHealth and IHiS S$1 million in total over the 2018 breach of 1.5 million patients' data. The Health Information Act, not yet in force, adds MOH incident reporting and up to 2 years' jail for improper record access.",
     "sources": [
      {
       "title": "Grounds of Decision: Singapore Health Services Pte Ltd and others (PDPC)",
       "url": "https://www.pdpc.gov.sg/-/media/Files/PDPC/PDF-Files/Commissions-Decisions/Grounds-of-Decision---SingHealth-IHiS---150119.pdf",
       "date": "2019-01-14",
       "publisherClass": "official"
      },
      {
       "title": "Personal Data Protection Act 2012, sections 4, 21, 26D and 48J (Singapore Statutes Online)",
       "url": "https://sso.agc.gov.sg/Act/PDPA2012",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Health Information Act 2026 (No. 1 of 2026), Singapore Statutes Online",
       "url": "https://sso.agc.gov.sg/Act/HIA2026/Uncommenced/20260624040946?DocDate=20260212",
       "date": "2026-02-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Extra safeguards for more sensitive medical info like mental health conditions: MOH (The Straits Times)",
       "url": "https://www.straitstimes.com/singapore/health/added-safeguards-for-medical-records-that-are-more-sensitive-such-as-mental-health-conditions-moh",
       "date": "2026-01-16",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 64,
     "summary": "Public hospitals, which handle 90% of acute care, have used the NEHR since 2011, and about 70% of over 2,000 GP clinics had joined by October 2025. Three of nine private hospitals, many specialists, labs and dental clinics were still outside.",
     "sources": [
      {
       "title": "Health Information Bill to support coordinated care across Singapore's healthcare ecosystem (MOH)",
       "url": "https://www.moh.gov.sg/newsroom/health-information-bill-to-support-coordinated-care-across-singapore-s-healthcare-ecosystem/",
       "date": "2026-01-12",
       "publisherClass": "official"
      },
      {
       "title": "All healthcare service providers must contribute and share patients' key health information (The Straits Times)",
       "url": "https://www.straitstimes.com/singapore/politics/all-healthcare-service-providers-must-contribute-and-share-patients-key-health-information",
       "date": "2026-01-12",
       "publisherClass": "news"
      },
      {
       "title": "Overview of the Health Information Act (HIA) (healthinfo.gov.sg, MOH)",
       "url": "https://www.healthinfo.gov.sg/hia/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 62,
     "summary": "Using the NEHR for insurance or employment is an offence carrying up to S$100,000 and four years in jail, and insurers cannot use most genetic test results. Outside the NEHR, health data held by firms and apps falls under the general PDPA.",
     "sources": [
      {
       "title": "Health Information Bill to support coordinated care across Singapore's healthcare ecosystem (MOH)",
       "url": "https://www.moh.gov.sg/newsroom/health-information-bill-to-support-coordinated-care-across-singapore-s-healthcare-ecosystem/",
       "date": "2026-01-12",
       "publisherClass": "official"
      },
      {
       "title": "Patients must be notified, give consent for their health information to be shared with insurers (The Straits Times)",
       "url": "https://www.straitstimes.com/singapore/health/patients-need-to-be-notified-and-consent-sought-for-sharing-of-relevant-information-with-insurers",
       "date": "2026-01-26",
       "publisherClass": "news"
      },
      {
       "title": "Moratorium on Genetic Testing and Insurance (MOH)",
       "url": "https://www.moh.gov.sg/others/resources-and-statistics/moratorium-on-genetic-testing-and-insurance/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Advisory Guidelines for the Healthcare Sector, revised 20 September 2023 (PDPC)",
       "url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/advisory-guidelines/advisory-guidelines-for-the-healthcare-sector-sep-2023.pdf",
       "date": "2023-09-20",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 68,
     "summary": "Treating doctors, nurses, pharmacists and allied health staff can open the NEHR by default, and a 'break glass' feature works even past a restriction. Gaps in private specialist, lab and dental data limit what they see until mandatory contribution starts.",
     "sources": [
      {
       "title": "Health Information Bill to support coordinated care across Singapore's healthcare ecosystem (MOH)",
       "url": "https://www.moh.gov.sg/newsroom/health-information-bill-to-support-coordinated-care-across-singapore-s-healthcare-ecosystem/",
       "date": "2026-01-12",
       "publisherClass": "official"
      },
      {
       "title": "Health Information Act 2026 (No. 1 of 2026), Singapore Statutes Online",
       "url": "https://sso.agc.gov.sg/Act/HIA2026/Uncommenced/20260624040946?DocDate=20260212",
       "date": "2026-02-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Extra safeguards for more sensitive medical info like mental health conditions: MOH (The Straits Times)",
       "url": "https://www.straitstimes.com/singapore/health/added-safeguards-for-medical-records-that-are-more-sensitive-such-as-mental-health-conditions-moh",
       "date": "2026-01-16",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "The Health Information Act lets the Minister release NEHR-derived data for public health or public interest purposes without consent, and a restriction does not block it. Safeguards include ethics review, a secure research platform and fines up to S$50,000.",
     "sources": [
      {
       "title": "Health Information Act 2026 (No. 1 of 2026), Singapore Statutes Online",
       "url": "https://sso.agc.gov.sg/Act/HIA2026/Uncommenced/20260624040946?DocDate=20260212",
       "date": "2026-02-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "NEHR FAQ (Synapxe, operator of the NEHR)",
       "url": "https://www.synapxe.sg/healthtech/national-programmes/national-electronic-health-record-nehr/faq",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Regulation of human biomedical research (MOH)",
       "url": "https://www.moh.gov.sg/others/health-regulation/regulation-of-human-biomedical-research/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "How TRUST ensures data is safe (TRUST Platform)",
       "url": "https://www.trustplatform.sg/about-us/how-trust-ensures-data-is-safe/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 62,
     "summary": "HSA regulates AI software as medical devices, with ML labelling and a change management program for planned model updates. MOH's March 2026 guidelines call human oversight mandatory for clinical AI but are guidance, not law, so the cell sits mid-band.",
     "sources": [
      {
       "title": "GL-04 Revision 4: Regulatory Guidelines for Software Medical Devices including Machine Learning-Enabled Medical Devices (HSA)",
       "url": "https://isomer-user-content.by.gov.sg/409/26808a93-6a7a-4551-8c66-13046c6124c5/gl-04-r4-regulatory-guidelines-for-software-medical-devices---a-life-cycle-approach-(2025-dec)-pub.pdf",
       "date": "2025-12",
       "publisherClass": "official"
      },
      {
       "title": "Artificial Intelligence in Healthcare Guidelines (AIHGle) Version 2.0 (MOH and HSA)",
       "url": "https://isomer-user-content.by.gov.sg/3/23fb5b36-56b4-4abb-9370-75c9ddcaf3ed/AIHGle%202.0.pdf",
       "date": "2026-03",
       "publisherClass": "official"
      },
      {
       "title": "Singapore: MOH and HSA Launch Refreshed AI in Healthcare Guidelines (Baker McKenzie)",
       "url": "https://www.bakermckenzie.com/en/insight/publications/2026/03/singapore-moh-and-hsa-launch-refreshed-ai-in-healthcare-guidelines",
       "date": "2026-03-31",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Health Information Act 2026",
     "level": "National",
     "year": "2026",
     "what": "Mandatory NEHR contribution without consent, access restrictions, insurance and employment ban, breach notification; not yet in force.",
     "url": "https://sso.agc.gov.sg/Act/HIA2026/Uncommenced/20260624040946?DocDate=20260212"
    },
    {
     "name": "Personal Data Protection Act 2012",
     "level": "National",
     "year": "2012",
     "what": "General privacy law: access right, consent, breach duties, fines up to 10% of turnover; excludes public agencies.",
     "url": "https://sso.agc.gov.sg/Act/PDPA2012"
    },
    {
     "name": "Human Biomedical Research Act 2015",
     "level": "National",
     "year": "2015",
     "what": "Requires appropriate consent for human biomedical research and tissue use, with regulated exemptions.",
     "url": "https://sso.agc.gov.sg/Act/HBRA2015"
    },
    {
     "name": "HSA GL-04 Revision 4, software and ML medical devices",
     "level": "National",
     "year": "2025",
     "what": "Life-cycle rules for AI and ML devices: labelling, change notification, change management program.",
     "url": "https://isomer-user-content.by.gov.sg/409/26808a93-6a7a-4551-8c66-13046c6124c5/gl-04-r4-regulatory-guidelines-for-software-medical-devices---a-life-cycle-approach-(2025-dec)-pub.pdf"
    },
    {
     "name": "Artificial Intelligence in Healthcare Guidelines (AIHGle) 2.0",
     "level": "National",
     "year": "2026",
     "what": "MOH and HSA guidance: duties for developers, deployers, clinicians; human oversight for clinical AI.",
     "url": "https://isomer-user-content.by.gov.sg/3/23fb5b36-56b4-4abb-9370-75c9ddcaf3ed/AIHGle%202.0.pdf"
    },
    {
     "name": "Moratorium on Genetic Testing and Insurance (2025)",
     "level": "National",
     "year": "2025",
     "what": "MOH and insurer agreement barring use of most genetic test results in underwriting.",
     "url": "https://www.moh.gov.sg/others/resources-and-statistics/moratorium-on-genetic-testing-and-insurance/"
    }
   ],
   "dti": {
    "grade": 88,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-05-21",
     "headline": "Patient's record used to approach them for research without express consent",
     "paraphrase": "A patient complained that a hospital researcher, given the patient's name by their doctor, approached them in a waiting area to join a study. The regulator found implied consent sufficed but said express consent would have been better practice.",
     "source": "Personal Data Protection Commission Singapore",
     "url": "https://www.pdpc.gov.sg/-/media/files/pdpc/pdf-files/commissions-decisions/gd_institute-of-mental-health_21052025.pdf",
     "theme": "other",
     "status": "finding"
    },
    {
     "date": "2025-04-11",
     "headline": "Hospital worker fined for looking up a former patient's record without reason",
     "paraphrase": "A hospital staff member opened a former patient's record on the hospital system for personal reasons and filmed the screen showing their ID number, address and contacts. The patient complained; she pleaded guilty and was fined.",
     "source": "HRD Asia (HCA Magazine)",
     "url": "https://www.hcamag.com/asia/specialisation/employment-law/nuh-employee-fined-for-unauthorised-access-of-patient-information-reports/531778",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-06-13",
     "headline": "Former specialist centre employee charged with accessing patients' data without authorisation",
     "paraphrase": "A former public specialist centre employee was charged with accessing personal data of 18 patients without authorisation and downloading photos of 42 patients from its systems. The centre said it began an internal probe and filed a police report.",
     "source": "Malay Mail (citing CNA)",
     "url": "https://www.malaymail.com/news/singapore/2025/06/13/former-national-dental-centre-singapore-staff-accused-of-taking-illicit-photos-of-female-patients-breasts/180231",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-09-20",
     "headline": "Specialist centre's email error let 467 invitees see each other's addresses",
     "paraphrase": "A public specialist centre emailed an invitation to a patient event using CC instead of BCC, so all 467 recipients could see each other's addresses. The centre apologised and reported the incident to the health ministry and the privacy regulator.",
     "source": "AsiaOne",
     "url": "https://www.asiaone.com/singapore/national-cancer-centre-email-leak",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "SVN",
   "name": "Slovenia",
   "region": "Europe",
   "overall": 62,
   "rank": "16=",
   "likelyRank": "10 to 23",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Slovenia's zVEM portal shows patients their reports, prescriptions and an access log, but data flows to the central register without consent.",
   "categories": {
    "access": {
     "score": 66,
     "summary": "The Patients' Rights Act gives a right to see and copy the record within five working days, and the national zVEM portal shows test results, prescriptions, referrals and appointments. Some providers still send less than they should, so the portal is not the full chart.",
     "sources": [
      {
       "title": "41. clen ZPacP: Nacin seznanitve z zdravstveno dokumentacijo (zakonodaja.com)",
       "url": "https://zakonodaja.com/zakon/zpacp/41-clen-nacin-seznanitve-z-zdravstveno-dokumentacijo",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Portal in mobilna aplikacija zVEM (NIJZ)",
       "url": "https://nijz.si/informatika-v-zdravstvu/ezdravje/portal-in-mobilna-aplikacija-zvem-vase-zdravje-na-dosegu-roke/",
       "date": "2026-08-26",
       "publisherClass": "official"
      },
      {
       "title": "Kateri izvajalci zdravstvene dejavnosti posredujejo podatke v CRPP? (eZdravje podpora)",
       "url": "https://podpora.ezdrav.si/faq/kateri-izvajalci-zdravstvene-dejavnosti-posredujejo-podatke-v-crpp/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 60,
     "summary": "Patients can block viewing of their Patient Data Summary for one provider or all providers and can see which institution opened their records. They cannot stop data going to the central register, and the log names institutions, not staff.",
     "sources": [
      {
       "title": "Zakon o spremembah in dopolnitvah ZZPPZ (ZZPPZ-A), Uradni list RS 47/2015",
       "url": "https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2015-01-1933?sop=2015-01-1933",
       "date": "2015-06-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Na kaksen nacin lahko prepovem vpogled v svoj Povzetek podatkov o pacientu? (eZdravje podpora)",
       "url": "https://podpora.ezdrav.si/faq/na-kaksen-nacin-lahko-prepovem-vpogled-v-svoj-povzetek-podatkov-o-pacientu/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Na koga naj se obrnem za natancnejse podatke o vpogledih v svojo zdravstveno dokumentacijo? (eZdravje podpora)",
       "url": "https://podpora.ezdrav.si/faq/na-koga-naj-se-obrnem-za-natancnejse-podatke-o-vpogledih-v-svojo-zdravstveno-dokumentacijo-ali-lahko-pridobim-poimenske-podatke-oseb-zdravstvenih-delavcev-ki-dostopajo-do-mojih-podatkov/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Kateri zdravstveni delavci imajo vpogled v CRPP in pod kaksnimi pogoji? (eZdravje podpora)",
       "url": "https://podpora.ezdrav.si/faq/kateri-zdravstveni-delavci-imajo-vpogled-v-crpp-in-pod-kaksnimi-pogoji/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "Health data is covered by the GDPR and the 2022 Personal Data Protection Act (ZVOP-2), enforced by the Information Commissioner. In January 2025 the Commissioner opened a priority inspection after patient records from Celje General Hospital were found in the trash.",
     "sources": [
      {
       "title": "Zakon o varstvu osebnih podatkov (ZVOP-2), Uradni list RS 163/2022",
       "url": "https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2022-01-4187?sop=2022-01-4187",
       "date": "2022-12-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Malomarno ravnanje: obcutljivi podatki bolnikov v smeteh (24ur)",
       "url": "https://www.24ur.com/novice/slovenija/malomarno-ravnanje-obcutljivi-podatki-bolnikov-v-smeteh.html",
       "date": "2025-01-15",
       "publisherClass": "news"
      },
      {
       "title": "41. clen ZPacP: Nacin seznanitve z zdravstveno dokumentacijo (zakonodaja.com)",
       "url": "https://zakonodaja.com/zakon/zpacp/41-clen-nacin-seznanitve-z-zdravstveno-dokumentacijo",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 66,
     "summary": "eZdravje links providers through a central patient register, e-prescriptions, e-referrals, e-booking and a vaccination register, built since 2008. Every provider must send documents, but some do not, so coverage is uneven.",
     "sources": [
      {
       "title": "eHealth (eZdravje)",
       "url": "https://ezdrav.si/en/ehealth/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Kateri izvajalci zdravstvene dejavnosti posredujejo podatke v CRPP? (eZdravje podpora)",
       "url": "https://podpora.ezdrav.si/faq/kateri-izvajalci-zdravstvene-dejavnosti-posredujejo-podatke-v-crpp/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Elektronska komunikacija z zdravnikom po novem: kaj moram storiti (N1)",
       "url": "https://n1info.si/novice/slovenija/elektronska-komunikacija-z-zdravnikom-po-novem-kaj-moram-storiti/",
       "date": "2026-01-07",
       "publisherClass": "news"
      },
      {
       "title": "Patient information notices: Slovenia (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/digital-health-and-care/electronic-cross-border-health-services/patient-information-notices-slovenia_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "commercial": {
     "score": 60,
     "summary": "Commercial use of health data is limited by the GDPR and ZVOP-2, and the EU health data space will bar marketing and decisions that harm people from 2029. No Slovenia-specific ban on health data brokers or app data sales was verified.",
     "sources": [
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "Data protection (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection_en",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "Zakon o varstvu osebnih podatkov (ZVOP-2), Uradni list RS 163/2022",
       "url": "https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2022-01-4187?sop=2022-01-4187",
       "date": "2022-12-27",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 68,
     "summary": "The chosen GP sees the full central record, other doctors see it with a referral or consent, and emergency units get automatic access. Elsewhere a doctor can open an 8-hour emergency window, which is logged.",
     "sources": [
      {
       "title": "Kateri zdravstveni delavci imajo vpogled v CRPP in pod kaksnimi pogoji? (eZdravje podpora)",
       "url": "https://podpora.ezdrav.si/faq/kateri-zdravstveni-delavci-imajo-vpogled-v-crpp-in-pod-kaksnimi-pogoji/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Na kaksen nacin lahko zdravnik pridobi dostop do dokumentacije v izrednih primerih? (eZdravje podpora)",
       "url": "https://podpora.ezdrav.si/faq/na-kaksen-nacin-lahko-zdravnik-pridobi-dostop-do-dokumentacije-v-izrednih-primerih/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Zakon o spremembah in dopolnitvah ZZPPZ (ZZPPZ-A), Uradni list RS 47/2015",
       "url": "https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2015-01-1933?sop=2015-01-1933",
       "date": "2015-06-30",
       "publisherClass": "legal_text"
      }
     ]
    },
    "research": {
     "score": 45,
     "summary": "ZVOP-2 allows research reuse when another law permits it or the person has not prohibited it; professional secrets need written consent. A central way to register that prohibition was not verified, and the national health data access body is still being built.",
     "sources": [
      {
       "title": "Zakon o varstvu osebnih podatkov (ZVOP-2), Uradni list RS 163/2022",
       "url": "https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2022-01-4187?sop=2022-01-4187",
       "date": "2022-12-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Podpora institucijam za dostop do zdravstvenih podatkov v Sloveniji (NIJZ)",
       "url": "https://nijz.si/projekti/podpora-institucijam-za-dostop-do-zdravstvenih-podatkov-v-sloveniji/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device law and the AI Act, which Slovenia implemented with a national law in force since 21 November 2025. That law names authorities but adds no new duties, and AI Act rules for medical devices start 2 August 2028.",
     "sources": [
      {
       "title": "Zakon o izvajanju uredbe (EU) o dolocitvi harmoniziranih pravil o umetni inteligenci (ZIUDHPUI), Uradni list RS 85/2025",
       "url": "https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2025-01-3035/zakon-o-izvajanju-uredbe-eu-o-dolocitvi-harmoniziranih-pravil-o-umetni-inteligenci-ziudhpui",
       "date": "2025-11-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kaj prinasa Zakon o izvajanju Akta o umetni inteligenci? (Jadek & Pensa)",
       "url": "https://www.jadek-pensa.si/kaj-prinasa-zakon-o-izvajanju-akta-o-umetni-inteligenci/",
       "date": "2025-12-05",
       "publisherClass": "law_firm"
      },
      {
       "title": "AI Act: regulatory framework for AI (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
       "date": "2026-08-03",
       "publisherClass": "intergov"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Patients' Rights Act (Zakon o pacientovih pravicah, ZPacP)",
     "level": "National",
     "year": "2008",
     "what": "Right to view and copy records within five working days; Information Commissioner hears access disputes.",
     "url": "https://zakonodaja.com/zakon/zpacp/41-clen-nacin-seznanitve-z-zdravstveno-dokumentacijo"
    },
    {
     "name": "Health Data Collections Act amendment (ZZPPZ-A)",
     "level": "National",
     "year": "2015",
     "what": "Sets up eZdravje and the CRPP register; patients may block viewing of their Patient Data Summary.",
     "url": "https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2015-01-1933?sop=2015-01-1933"
    },
    {
     "name": "Personal Data Protection Act (ZVOP-2)",
     "level": "National",
     "year": "2022",
     "what": "Supplements the GDPR; Article 69 sets conditions for research reuse, including a right to prohibit it.",
     "url": "https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2022-01-4187?sop=2022-01-4187"
    },
    {
     "name": "Act implementing the EU AI Regulation (ZIUDHPUI)",
     "level": "National",
     "year": "2025",
     "what": "Names AI Act authorities; JAZMP is notifying authority for AI in medical devices.",
     "url": "https://www.uradni-list.si/glasilo-uradni-list-rs/vsebina/2025-01-3035/zakon-o-izvajanju-uredbe-eu-o-dolocitvi-harmoniziranih-pravil-o-umetni-inteligenci-ziudhpui"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "EU data protection law applicable since 25 May 2018; health is special-category data.",
     "url": "https://commission.europa.eu/law/law-topic/data-protection_en"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient summaries and e-prescriptions from 2029; opt-out from secondary use; bans marketing use.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "EU Artificial Intelligence Act (EU) 2024/1689",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk-based AI rules; high-risk duties for AI in medical devices from 2 August 2028.",
     "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
    }
   ],
   "dti": {
    "grade": 85,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-09-18",
     "headline": "Hospital confirms employee shared photos of patients and a document with personal data",
     "paraphrase": "A hospital employee photographed patients and a document holding sensitive personal data and shared the images outside the hospital. The hospital confirmed it, disciplined the worker and reported the case to the data protection authority and police.",
     "source": "N1 Slovenija",
     "url": "https://n1info.si/novice/slovenija/zaposlena-v-ukc-ljubljana-fotografirala-bolnike-med-zdravljenjem-in-delila-slike/",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2024-10-05",
     "headline": "Clinic confirms a nurse repeatedly opened a former patient's record without authorisation",
     "paraphrase": "A former patient complained that a staff member had viewed her health record while she was not in care there. The clinic confirmed repeated unauthorised access and misuse of login details, and notified police and the data protection authority.",
     "source": "Žurnal24",
     "url": "https://www.zurnal24.si/slovenija/ljubljana-vohljala-je-za-zdravjem-pacientke-univerzitetna-psihiatricna-klinika-bojan-zalar-ministrica-izredni-nadzor-430457",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2025-01-15",
     "headline": "Patient test results and operation lists reported found in the rubbish",
     "paraphrase": "A TV programme received a bag of patients' results, operation lists and doctors' notes said to have been thrown out by a hospital. The hospital disputed where the bag came from; the data protection authority opened an inspection.",
     "source": "RTV Slovenija",
     "url": "https://www.rtvslo.si/zdravje/v-smeteh-koncali-izvidi-pacientov-in-druga-obcutljiva-dokumentacija-iz-celjske-bolnisnice/733409",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2025-12-29",
     "headline": "Patient receives two wrong scan reports, one apparently belonging to someone else",
     "paraphrase": "A patient says his first imaging report described the wrong part of the body and a corrected report mentioned a procedure that was never done, suggesting a mix-up with another patient. He says staff told him mistakes happen.",
     "source": "Necenzurirano.si",
     "url": "https://necenzurirano.si/clanek/preiskave/radiologi-preiskava-magnetna-resonanca-napaka-zzzs-ukc-maribor-zdravniki-1870449",
     "theme": "record_wrong",
     "status": "alleged"
    },
    {
     "date": "2026-01-15",
     "headline": "Patient handed another person's test result, which reported a serious illness",
     "paraphrase": "A patient received a test report carrying another person's name and findings, and only learned of the mistake when his doctor pointed it out. The Ministry of Health called this kind of mix-up a serious safety incident.",
     "source": "Svet24",
     "url": "https://svet24.si/novice/slovenija/bolnik-izvid-napaka-incident-bolezen-1873740",
     "theme": "record_wrong",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "LIE",
   "name": "Liechtenstein",
   "region": "Europe",
   "overall": 61,
   "rank": "21=",
   "likelyRank": "11 to 27",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Every insured person has an opt-out eGD with access logs and patient-unlocked doctor access, but active use is unproven and EU health-data rules lag.",
   "categories": {
    "access": {
     "score": 64,
     "summary": "By law every insured person has an eGD they can read in full, holding letters, reports, labs, imaging findings and medicines since 2023. Older records and full charts stay with each doctor, and no official figure on active use was found.",
     "sources": [
      {
       "title": "Gesetz über das elektronische Gesundheitsdossier (EGDG), Fassung 01.02.2026",
       "url": "https://www.gesetze.li/konso/pdf/2021213000?version=4",
       "date": "2026-02-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Weiterentwicklung des elektronischen Gesundheitsdossiers (Regierung des Fürstentums Liechtenstein)",
       "url": "https://www.regierung.li/medienportal-medium/16182/234283/0/medienmitteilung",
       "date": "2026-03-03",
       "publisherClass": "official"
      },
      {
       "title": "Gesetz über die Ärzte (Ärztegesetz), Fassung 01.01.2026",
       "url": "https://www.gesetze.li/konso/pdf/2003239000?version=14",
       "date": "2026-01-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "eGD: Akzeptanz-Problem (lie:zeit)",
       "url": "https://www.lie-zeit.li/2026/04/egd-akzeptanz-problem/",
       "date": "2026-04-19",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 74,
     "summary": "Patients can opt out at any time, hide or delete single documents, see an access log, and must unlock each provider before access. The opt-out is all or nothing: it deletes the whole dossier.",
     "sources": [
      {
       "title": "Gesetz über das elektronische Gesundheitsdossier (EGDG), Fassung 01.02.2026",
       "url": "https://www.gesetze.li/konso/pdf/2021213000?version=4",
       "date": "2026-02-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Verordnung über das elektronische Gesundheitsdossier (EGDV), Fassung 01.03.2024",
       "url": "https://www.gesetze.li/konso/pdf/2022365000?version=2",
       "date": "2024-03-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kleine Anfrage Elektronisches Gesundheitsdossier (eGD) (Landtag)",
       "url": "https://www.landtag.li/printkleineanfrage/25139/?t=638267490026099788",
       "date": "2023-06-02",
       "publisherClass": "official"
      },
      {
       "title": "Volksabstimmungen zu den beiden Energievorlagen und dem E-Gesundheitsdossier vom 21. Januar 2024 (Liechtenstein-Institut)",
       "url": "https://s3.eu-central-1.amazonaws.com/ext-linst-c5-web-liechtenstein-institut.li-2019/4717/0800/9706/LI_Aktuell_2024_1_Energie_eGD_final.pdf",
       "date": "2024",
       "publisherClass": "academic"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "The GDPR applies through the EEA, and the eGD law adds fines up to CHF 50,000 for unlawful access. The regulator reports rising complaints and limited capacity, and has issued only one recent fine, not health-related.",
     "sources": [
      {
       "title": "EEA-Lex factsheet: Regulation (EU) 2016/679 (EFTA)",
       "url": "https://www.efta.int/eea-lex/32016r0679",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "Gesetz über das elektronische Gesundheitsdossier (EGDG), Fassung 01.02.2026",
       "url": "https://www.gesetze.li/konso/pdf/2021213000?version=4",
       "date": "2026-02-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Tätigkeitsbericht 2025 (Datenschutzstelle Liechtenstein)",
       "url": "https://www.datenschutzstelle.li/aktuelles/taetigkeitsbericht-2025",
       "date": "2026-09-04",
       "publisherClass": "official"
      },
      {
       "title": "IT-Sicherheit beim elektronischen Gesundheitsdossier im Fürstentum Liechtenstein (Pentagrid)",
       "url": "https://www.pentagrid.ch/en/blog/it-sicherheit-beim-elektronischen-gesundheitsdossier-im-fuerstentum-liechtenstein/",
       "date": "2023-09-14",
       "publisherClass": "blog_vendor"
      }
     ]
    },
    "journey": {
     "score": 54,
     "summary": "Since July 2023 the hospital, doctors, pharmacists, dentists and care homes must upload key documents within 90 days, and Swiss hospitals began uploading in 2026. Actual upload compliance and links to claims and public health were not verified.",
     "sources": [
      {
       "title": "Gesetz über das elektronische Gesundheitsdossier (EGDG), Fassung 01.02.2026",
       "url": "https://www.gesetze.li/konso/pdf/2021213000?version=4",
       "date": "2026-02-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Verordnung über das elektronische Gesundheitsdossier (EGDV), Fassung 01.03.2024",
       "url": "https://www.gesetze.li/konso/pdf/2022365000?version=2",
       "date": "2024-03-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Weiterentwicklung des elektronischen Gesundheitsdossiers (Regierung des Fürstentums Liechtenstein)",
       "url": "https://www.regierung.li/medienportal-medium/16182/234283/0/medienmitteilung",
       "date": "2026-03-03",
       "publisherClass": "official"
      },
      {
       "title": "Anbindung an das elektronische Gesundheitsdossier (eGD) des Fürstentums Liechtenstein (HOCH Health Ostschweiz)",
       "url": "https://www.h-och.ch/ueber-uns/news/anbindung-an-das-elektronische-gesundheitsdossier-e-gd-des-fuerstentums-liechtenstein-2026-04-14/",
       "date": "2026-04-14",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 54,
     "summary": "GDPR rules on health data apply through the EEA, and eGD data may only be used for the law's care purposes. The EU health data space bans on advertising and insurance uses do not yet apply, as it is not in the EEA Agreement.",
     "sources": [
      {
       "title": "EEA-Lex factsheet: Regulation (EU) 2016/679 (EFTA)",
       "url": "https://www.efta.int/eea-lex/32016r0679",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "EEA-Lex factsheet: Regulation (EU) 2025/327, European Health Data Space (EFTA)",
       "url": "https://www.efta.int/eea-lex/32025r0327",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "Gesetz über das elektronische Gesundheitsdossier (EGDG), Fassung 01.02.2026",
       "url": "https://www.gesetze.li/konso/pdf/2021213000?version=4",
       "date": "2026-02-01",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 63,
     "summary": "Once a patient unlocks access, treating doctors see all eGD documents for 28 days, trusted providers for 365 days, and pharmacists see medicines for 24 hours. The dossier holds key documents, not full charts.",
     "sources": [
      {
       "title": "Verordnung über das elektronische Gesundheitsdossier (EGDV), Fassung 01.03.2024",
       "url": "https://www.gesetze.li/konso/pdf/2022365000?version=2",
       "date": "2024-03-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Gesetz über das elektronische Gesundheitsdossier (EGDG), Fassung 01.02.2026",
       "url": "https://www.gesetze.li/konso/pdf/2021213000?version=4",
       "date": "2026-02-01",
       "publisherClass": "legal_text"
      }
     ]
    },
    "research": {
     "score": 42,
     "summary": "eGD data may only be used for the law's care purposes, so it is not a research source, and ethics review runs through the Zurich cantonal ethics committee. A Liechtenstein human research law and any general opt-out were not verified.",
     "sources": [
      {
       "title": "Summary Report of the Coordination Office for Human Research (Kofam) 2021 (FOPH / swissethics)",
       "url": "https://swissethics.ch/assets/swissethics/jahresberichte/bag_jahresbericht_2021_a4_en.pdf",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Gesetz über das elektronische Gesundheitsdossier (EGDG), Fassung 01.02.2026",
       "url": "https://www.gesetze.li/konso/pdf/2021213000?version=4",
       "date": "2026-02-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "EEA-Lex factsheet: Regulation (EU) 2025/327, European Health Data Space (EFTA)",
       "url": "https://www.efta.int/eea-lex/32025r0327",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "Verwaltungsvereinbarung Amt für Gesundheit und Swissmedic (LGBl. 2024 Nr. 74)",
       "url": "https://gesetze.li/konso/html/2024074000?search_loc=&search_text=&version=1",
       "date": "2024-02-27",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "The EU medical device regulation has applied through the EEA since June 2020, but the EU AI Act is not yet in the EEA Agreement. A government legal expert hopes it is adopted in the course of 2027, and no national clinical AI rules were verified.",
     "sources": [
      {
       "title": "EEA-Lex factsheet: Regulation (EU) 2017/745 (EFTA)",
       "url": "https://www.efta.int/eea-lex/32017r0745",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "EEA-Lex factsheet: Regulation (EU) 2024/1689, AI Act (EFTA)",
       "url": "https://www.efta.int/eea-lex/32024r1689",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "Verwaltungsvereinbarung Amt für Gesundheit und Swissmedic (LGBl. 2024 Nr. 74)",
       "url": "https://gesetze.li/konso/html/2024074000?search_loc=&search_text=&version=1",
       "date": "2024-02-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Der AI-Act ist gestaffelt anwendbar (digital-liechtenstein.li)",
       "url": "https://digital-liechtenstein.li/der-ai-act-ist-gestaffelt-anwendbar/",
       "date": "2026-07-27",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Gesetz über das elektronische Gesundheitsdossier (EGDG)",
     "level": "National",
     "year": "2021",
     "what": "Opt-out eGD for all insured; read, hide, delete rights; mandatory uploads; access logs; fines up to CHF 50,000.",
     "url": "https://www.gesetze.li/konso/pdf/2021213000?version=4"
    },
    {
     "name": "Verordnung über das elektronische Gesundheitsdossier (EGDV)",
     "level": "National",
     "year": "2022",
     "what": "Patient unlock of provider access; 28-day, 365-day and 24-hour windows; notice of unauthorised access.",
     "url": "https://www.gesetze.li/konso/pdf/2022365000?version=2"
    },
    {
     "name": "Gesetz über die Ärzte (Ärztegesetz), Art. 14",
     "level": "National",
     "year": "2003",
     "what": "Doctors must keep records ten years and give patients information and a copy on request.",
     "url": "https://www.gesetze.li/konso/pdf/2003239000?version=14"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Applies in Liechtenstein through the EEA since 20 July 2018; health is special-category data.",
     "url": "https://www.efta.int/eea-lex/32016r0679"
    },
    {
     "name": "Medical Device Regulation (EU) 2017/745",
     "level": "Supranational",
     "year": "2017",
     "what": "Covers medical device software including AI; in force in the EEA since 12 June 2020.",
     "url": "https://www.efta.int/eea-lex/32017r0745"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Under EEA scrutiny; no Joint Committee Decision, so not yet applicable in Liechtenstein.",
     "url": "https://www.efta.int/eea-lex/32025r0327"
    },
    {
     "name": "EU Artificial Intelligence Act (EU) 2024/1689",
     "level": "Supranational",
     "year": "2024",
     "what": "Under EEA scrutiny; not yet applicable in Liechtenstein; implementing law planned.",
     "url": "https://www.efta.int/eea-lex/32024r1689"
    }
   ],
   "dti": "pending",
   "asOf": "2026-10-01",
   "stories": []
  },
  {
   "iso3": "ESP",
   "name": "Spain",
   "region": "Europe",
   "overall": 61,
   "rank": "21=",
   "likelyRank": "12 to 27",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Spaniards can read key reports from any region and hide them from other doctors, but the national record is summaries, not the chart.",
   "categories": {
    "access": {
     "score": 66,
     "summary": "Ley 41/2002 gives a free right to the clinical record, and the national HCDSNS shows up to nine report types from any region. Spain scored 88.3 on the EU record-access indicator (Digital Decade 2025, 2024 data; EU 82.7), but what each region publishes varies.",
     "sources": [
      {
       "title": "Ley 41/2002, básica reguladora de la autonomía del paciente (BOE, texto consolidado)",
       "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2002-22188",
       "date": "2002-11-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Historia Clínica Digital del SNS: preguntas frecuentes (Ministerio de Sanidad)",
       "url": "https://www.sanidad.gob.es/profesionales/hcdsns/Preguntas_frecuentes.htm",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Digital Decade 2025 country report: Spain (European Commission, published by the Spanish government)",
       "url": "https://digital.gob.es/content/dam/portal-mtdfp/comunicacion/comunicacion_sedia/2025/06/16-06-2025/20250616InformeEspanaDecadaDigitalSDD25.pdf",
       "date": "2025-06-16",
       "publisherClass": "intergov"
      },
      {
       "title": "La AEPD sanciona a un centro médico por cobrar 30 euros por entregar una historia clínica (Iberley)",
       "url": "https://www.iberley.es/noticias/la-aepd-sanciona-cobrar-30-euros-acceder-historia-clinica-36403",
       "date": "2026-04-30",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 64,
     "summary": "Patients can hide individual reports from other doctors in HCDSNS and see every access, with a form to complain about unjustified ones. Choice covers only the shared national layer; inside each region clinicians treating the patient read the record by law.",
     "sources": [
      {
       "title": "Historia Clínica Digital del SNS: preguntas frecuentes (Ministerio de Sanidad)",
       "url": "https://www.sanidad.gob.es/profesionales/hcdsns/Preguntas_frecuentes.htm",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Historia Clínica Digital del Sistema Nacional de Salud (Comunidad de Madrid)",
       "url": "https://www.comunidad.madrid/salud/historia-clinica-digital-sistema-nacional-salud",
       "date": "2025-11-20",
       "publisherClass": "official"
      },
      {
       "title": "Preguntas frecuentes, La Meva Salut (Generalitat de Catalunya)",
       "url": "https://lamevasalut.gencat.cat/es/web/cps/ajuda/preguntes-frequents",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Trazabilidad de los accesos a datos de salud: la AEPD anticipa el estándar del EHDS (Cuatrecasas)",
       "url": "https://www.cuatrecasas.com/es/spain/farmaceutico-sanitario/art/trazabilidad-accesos-datos-salud",
       "date": "2026-07-13",
       "publisherClass": "law_firm"
      }
     ]
    },
    "privacy": {
     "score": 56,
     "summary": "GDPR and the LOPDGDD protect health data and the AEPD fines private providers, including 1.2 million euros against a Quirón hospital company. But public health services cannot be fined under LOPDGDD Article 77, only declared in breach.",
     "sources": [
      {
       "title": "Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales (BOE, texto consolidado)",
       "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673",
       "date": "2018-12-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Un hospital del Grupo Quirón recibe una multa de 1,2 millones de euros por perder el CD de un paciente (Infobae)",
       "url": "https://www.infobae.com/espana/2026/02/12/un-hospital-del-grupo-quiron-recibe-una-multa-de-12-millones-de-euros-por-perder-el-cd-de-un-paciente-que-aporto-resonancias-hechas-en-otros-centros/",
       "date": "2026-02-12",
       "publisherClass": "news"
      },
      {
       "title": "El software para psicólogos Eholo sufre una grave filtración de datos (Escudo Digital)",
       "url": "https://www.escudodigital.com/ciberseguridad/eholo-startup-filtracion-datos-pacientes.html",
       "date": "2026-03-05",
       "publisherClass": "news"
      },
      {
       "title": "Un grupo de hackers asegura haber robado datos médicos y financieros de pacientes de Quirón en España (La Voz del Sur)",
       "url": "https://www.lavozdelsur.es/actualidad/salud/un-grupo-de-hackers-asegura-haber-robado-datos-medicos-y-financieros-de-pacientes-de-quiron-en-espana.html",
       "date": "2026-08-11",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 64,
     "summary": "HCDSNS links nine report types across the regional health services, and e-prescriptions can be filled in any region's pharmacy. Spain has no nationwide longitudinal record; the Ministry commissioned a 2026 roadmap toward one.",
     "sources": [
      {
       "title": "Historia Clínica Digital del SNS: preguntas frecuentes (Ministerio de Sanidad)",
       "url": "https://www.sanidad.gob.es/profesionales/hcdsns/Preguntas_frecuentes.htm",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Receta Electrónica del Sistema Nacional de Salud (RESNS) (Ministerio de Sanidad)",
       "url": "https://www.sanidad.gob.es/areas/saludDigital/recetaElectronicaSNS/home.htm",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Recommendations for a national electronic health record in Spain: a Delphi study (The Lancet Digital Health, via University of Edinburgh)",
       "url": "https://www.research.ed.ac.uk/en/publications/recommendations-for-a-national-electronic-health-record-in-spain-/",
       "date": "2026-08-19",
       "publisherClass": "academic"
      },
      {
       "title": "Presentado el Espacio Nacional de Datos de Salud (Ministerio para la Transformación Digital y de la Función Pública)",
       "url": "https://digital.gob.es/digitalizacion/la-economia-del-dato/actualidad/2026/01/presentado-el-espacio-nacional-de-datos-de-salud",
       "date": "2026-01-29",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 60,
     "summary": "Ley 41/2002 ties the clinical record to care, and since 2023 life insurers may not consider cancer five years after treatment ends. No Spanish ban on selling health data beyond GDPR was found, and the 2026 national data space is open to companies.",
     "sources": [
      {
       "title": "Ley 41/2002, básica reguladora de la autonomía del paciente (BOE, texto consolidado)",
       "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2002-22188",
       "date": "2002-11-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Real Decreto-ley 5/2023, art. 209: derecho al olvido oncológico en el contrato de seguro (BOE)",
       "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2023-15135",
       "date": "2023-06-28",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales (BOE, texto consolidado)",
       "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673",
       "date": "2018-12-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Presentado el Espacio Nacional de Datos de Salud (Ministerio para la Transformación Digital y de la Función Pública)",
       "url": "https://digital.gob.es/digitalizacion/la-economia-del-dato/actualidad/2026/01/presentado-el-espacio-nacional-de-datos-de-salud",
       "date": "2026-01-29",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 60,
     "summary": "Inside each region clinicians usually share one record; Catalonia's HC3 reaches every public hospital and primary care centre. Across regions, a doctor sees only the HCDSNS report types, needs the patient's authorisation outside emergencies, and is told when reports are hidden.",
     "sources": [
      {
       "title": "Ley 41/2002, básica reguladora de la autonomía del paciente (BOE, texto consolidado)",
       "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2002-22188",
       "date": "2002-11-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "La història clínica compartida, present a tots els hospitals i els CAP de la xarxa sanitària pública (Govern de Catalunya)",
       "url": "https://govern.cat/gov/notes-premsa/275211/la-historia-clinica-compartida-present-a-tots-els-hospitals-i-els-cap-de-la-xarxa-sanitaria-publica",
       "date": "2014-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Historia Clínica Digital del SNS: preguntas frecuentes (Ministerio de Sanidad)",
       "url": "https://www.sanidad.gob.es/profesionales/hcdsns/Preguntas_frecuentes.htm",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Pseudonymised health data may be used for research without consent under the LOPDGDD, with no general opt-out, but with ethics review, separation of identity and a penalty for re-identification. The EHDS opt-out from secondary use starts in 2029.",
     "sources": [
      {
       "title": "Ley Orgánica 3/2018 de Protección de Datos Personales y garantía de los derechos digitales (BOE, texto consolidado)",
       "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673",
       "date": "2018-12-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Real Decreto 1090/2015, ensayos clínicos con medicamentos (BOE)",
       "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2015-14082",
       "date": "2015-12-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "European Health Data Space Regulation (EHDS) (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "Consulta pública previa sobre el Anteproyecto de Ley de Salud Digital (Ministerio de Sanidad)",
       "url": "https://www.sanidad.gob.es/normativa/docs/2025.09.22_CPP_CPP_APL_Salud_Digital1_.pdf",
       "date": "2025-09-22",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Spain relies on EU law for clinical AI. AESIA, the national AI supervisor, is an authority designation, and the national AI bill approved by the Council of Ministers in May 2026 was not yet law.",
     "sources": [
      {
       "title": "¿Qué es la AESIA? (Agencia Española de Supervisión de Inteligencia Artificial)",
       "url": "https://aesia.digital.gob.es/es",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "El Gobierno regula la inteligencia artificial para asegurar un uso confiable, ético y garantista (La Moncloa, Consejo de Ministros 26.5.2026)",
       "url": "https://www.lamoncloa.gob.es/consejodeministros/resumenes/paginas/2026/260526-rueda-prensa-ministros.aspx",
       "date": "2026-05-26",
       "publisherClass": "official"
      },
      {
       "title": "Consulta pública previa sobre el Anteproyecto de Ley de Salud Digital (Ministerio de Sanidad)",
       "url": "https://www.sanidad.gob.es/normativa/docs/2025.09.22_CPP_CPP_APL_Salud_Digital1_.pdf",
       "date": "2025-09-22",
       "publisherClass": "official"
      },
      {
       "title": "Digital Omnibus on AI has been published (Cuatrecasas)",
       "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published",
       "date": "2026-07-24",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Ley 41/2002, básica reguladora de la autonomía del paciente",
     "level": "National",
     "year": "2002",
     "what": "Right to access and copy the clinical record; limits record use to care; anonymity for secondary uses.",
     "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2002-22188"
    },
    {
     "name": "Ley Orgánica 3/2018 (LOPDGDD)",
     "level": "National",
     "year": "2018",
     "what": "Applies GDPR; pseudonymised research rules; re-identification offence; no fines for public bodies.",
     "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673"
    },
    {
     "name": "Real Decreto-ley 5/2023 (derecho al olvido oncológico)",
     "level": "National",
     "year": "2023",
     "what": "Life insurers may not consider cancer five years after treatment ends; bars health-condition discrimination.",
     "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2023-15135"
    },
    {
     "name": "Real Decreto 1090/2015, ensayos clínicos con medicamentos",
     "level": "National",
     "year": "2015",
     "what": "Informed consent and ethics committee rules for clinical trials, applying EU Regulation 536/2014.",
     "url": "https://www.boe.es/buscar/act.php?id=BOE-A-2015-14082"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient access, access logs and EU exchange from 2029 and 2031; secondary-use rules and opt-out.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health data is a special category; free first copy within one month; breach notification and fines.",
     "url": "https://www.boe.es/buscar/doc.php?id=DOUE-L-2016-80807"
    },
    {
     "name": "EU AI Act (EU) 2024/1689, amended by (EU) 2026/1744",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk-based AI rules; duties for AI in medical devices apply from 2 August 2028.",
     "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published"
    }
   ],
   "dti": {
    "grade": 91,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-04-20",
     "headline": "Clinic charged a patient 30 euros for a first copy of her record",
     "paraphrase": "After leaving her private insurer, a patient had to request her record in person and pay 30 euros in cash for a one-page copy. The regulator found the charge unlawful; the clinic accepted responsibility and paid a reduced fine.",
     "source": "Agencia Española de Protección de Datos (AEPD), PS-00560-2025 (EXP202503617)",
     "url": "https://www.aepd.es/documento/ps-00560-2025.pdf",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2026-07-07",
     "headline": "Employer's health service ignored a request for a medical record for three years",
     "paraphrase": "A police employee asked the force's medical service for their full record in 2022 and 2025 with no answer; copies came only after a complaint. The regulator upheld it, citing the right to know who holds the data.",
     "source": "Agencia Española de Protección de Datos (AEPD), PD-00068-2026 (EXP202518019)",
     "url": "https://www.aepd.es/documento/pd-00068-2026.pdf",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2025-01-28",
     "headline": "Specialist could not see a report held by another public hospital",
     "paraphrase": "After a long wait for an appointment, a patient was told the specialist could not see a report held at another public hospital and was asked to fetch it herself. The ombudsman recommended records be reachable from every public centre.",
     "source": "Síndic de Greuges de la Comunitat Valenciana (regional ombudsman), complaint 2403790",
     "url": "https://www.elsindic.com/Resoluciones/expedientes/2024/202403790/12238270.pdf",
     "theme": "lost_between_providers",
     "status": "finding"
    },
    {
     "date": "2025-02-07",
     "headline": "Doctor convicted for opening a colleague's clinical record three times",
     "paraphrase": "A primary care doctor used her own login to open a colleague's clinical record three times, though the colleague was not her patient. A provincial court gave her a suspended prison term, six years' disqualification and 50,000 euros in damages.",
     "source": "Salud y Medicina",
     "url": "https://saludymedicina.org/post/seis-anos-de-inhabilitacion-y-dos-de-carcel-por-tres-visitas-a-la-historia-clinica-de-su-colega",
     "theme": "breach",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "HRV",
   "name": "Croatia",
   "region": "Europe",
   "overall": 60,
   "rank": "23=",
   "likelyRank": "14 to 29",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Croatians can see labs, prescriptions and hospital letters online and block whole groups of doctors, but private clinics stay outside CEZIH until 2027.",
   "categories": {
    "access": {
     "score": 62,
     "summary": "The 2004 patient rights law gives a right to the whole record, with copies at the patient's cost. Portal zdravlja shows lab results, prescriptions, referrals and hospital letters, but its user count was not verified, so the score sits in the lower half of the band.",
     "sources": [
      {
       "title": "Zakon o zastiti prava pacijenata (NN 169/04)",
       "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/full/2004_12_169_2953.html",
       "date": "2004-12-03",
       "publisherClass": "legal_text"
      },
      {
       "title": "HZZO za e-Gradane",
       "url": "https://hzzo.hr/e-gradani/hzzo-za-e-gradane",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Portal zdravlja dostupan i na mobilnim uredajima (gov.hr)",
       "url": "https://gov.hr/hr/portal-zdravlja-dostupan-i-na-mobilnim-uredjajima/2340",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Pravilnik o opsegu i sadrzaju podataka te nacinu vodenja e-Kartona (NN 74/2023)",
       "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/2023_07_74_1210.html",
       "date": "2023-07-06",
       "publisherClass": "legal_text"
      }
     ]
    },
    "control": {
     "score": 66,
     "summary": "In Portal zdravlja patients can allow or block access by whole groups, such as all family doctors, emergency doctors or hospital specialists. A law-backed log shows who viewed which data and when, but sharing is on by default.",
     "sources": [
      {
       "title": "eKarton pravila privatnosti (Ministarstvo zdravstva)",
       "url": "https://mobilne.portal.zdravlje.hr/ek/ekarton-pravila-privatnosti.html",
       "date": "2026-06-24",
       "publisherClass": "official"
      },
      {
       "title": "Pravilnik o opsegu i sadrzaju podataka te nacinu vodenja e-Kartona (NN 74/2023)",
       "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/2023_07_74_1210.html",
       "date": "2023-07-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Zakon o podacima i informacijama u zdravstvu (NN 14/19)",
       "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/full/2019_02_14_269.html",
       "date": "2019-02-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "HZZO za e-Gradane",
       "url": "https://hzzo.hr/e-gradani/hzzo-za-e-gradane",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 52,
     "summary": "The regulator AZOP has fined hospitals, including EUR 190,000 for lost radiology images. But Croatian law bars fines on public authorities, fines on public services must not disrupt them, and hospitals and the ministry have been hacked.",
     "sources": [
      {
       "title": "Zakon o provedbi Opce uredbe o zastiti podataka (NN 42/18)",
       "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/2018_05_42_805.html",
       "date": "2018-05-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Izdane nove upravne novcane kazne u ukupnom iznosu od 270.700 eura (AZOP)",
       "url": "https://azop.hr/izdane-nove-upravne-novcane-kazne-u-ukupnom-iznosu-od-270-700-eura/",
       "date": "2024-09-13",
       "publisherClass": "official"
      },
      {
       "title": "Izreceno novih sedam upravnih novcanih kazni u iznosu od 169.000 eura (AZOP)",
       "url": "https://azop.hr/sedam-novih-upravnih-novcanih-kazni-u-iznosu-od-169-000-eura/",
       "date": "2025-03-24",
       "publisherClass": "official"
      },
      {
       "title": "KBC Zagreb je kontaktirao AZOP, ali pacijente i dalje nije obavijestio (Faktograf)",
       "url": "https://faktograf.hr/2024/07/08/kbc-zagreb-je-kontaktirao-azop-ali-pacijente-i-dalje-nije-obavijestio-o-mogucoj-kradi-podataka/",
       "date": "2024-07-08",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 68,
     "summary": "By law every provider must exchange data through CEZIH, which carries e-prescriptions, e-referrals, lab results and hospital letters. Private clinics outside HZZO contracts got two extensions and now have until 1 January 2027.",
     "sources": [
      {
       "title": "Zakon o podacima i informacijama u zdravstvu (NN 14/19, HLK copy)",
       "url": "https://www.hlk.hr/EasyEdit/UserFiles/propisi/zakon-o-podacima-i-informacijama-u-zdravstvu-nn-14-2019.pdf",
       "date": "2019-02-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Developing an integrated e-health system in Croatia (WHO Europe)",
       "url": "https://www.integratedcare4people.org/practices/327/developing-an-integrated-e-health-system-in-croatia-to-drive-care-improvements/",
       "date": "2016",
       "publisherClass": "intergov"
      },
      {
       "title": "Introduction of electronic health records in hospitals (WHO European Observatory)",
       "url": "https://eurohealthobservatory.who.int/monitors/health-systems-monitor/updates/hspm/croatia-2022/introduction-of-electronic-health-records-in-hospitals",
       "date": "2022-10-21",
       "publisherClass": "intergov"
      },
      {
       "title": "Rok za prikljucivanje produljen (Glas Slavonije)",
       "url": "https://www.glas-slavonije.hr/novosti/hrvatska/2026/08/13/rok-za-prikljucivanje-produljen-nalazi-privatnih-lijecnika-tek-od-1-sijecnja-iduce-godine-u-cezih-u-779594/",
       "date": "2026-08-13",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 56,
     "summary": "Croatia relies on the GDPR, and its health data law bars collecting health data from secondary sources unless another law allows it. No Croatian ban on selling de-identified health data was verified, and the same law lists commercial use among legitimate data users.",
     "sources": [
      {
       "title": "Zakon o podacima i informacijama u zdravstvu (NN 14/19, HLK copy)",
       "url": "https://www.hlk.hr/EasyEdit/UserFiles/propisi/zakon-o-podacima-i-informacijama-u-zdravstvu-nn-14-2019.pdf",
       "date": "2019-02-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Regulation (EU) 2016/679 (GDPR)",
       "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
       "date": "2016-04-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 64,
     "summary": "The chosen family doctor, the paediatrician and clinicians who start treatment can see the e-Karton through CEZIH. Patients can block groups such as emergency doctors, and private findings will be missing until 2027.",
     "sources": [
      {
       "title": "Pravilnik o opsegu i sadrzaju podataka te nacinu vodenja e-Kartona (NN 74/2023)",
       "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/2023_07_74_1210.html",
       "date": "2023-07-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "eKarton pravila privatnosti (Ministarstvo zdravstva)",
       "url": "https://mobilne.portal.zdravlje.hr/ek/ekarton-pravila-privatnosti.html",
       "date": "2026-06-24",
       "publisherClass": "official"
      },
      {
       "title": "Rok za prikljucivanje produljen (Glas Slavonije)",
       "url": "https://www.glas-slavonije.hr/novosti/hrvatska/2026/08/13/rok-za-prikljucivanje-produljen-nalazi-privatnih-lijecnika-tek-od-1-sijecnja-iduce-godine-u-cezih-u-779594/",
       "date": "2026-08-13",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 45,
     "summary": "The 2019 law allows further processing of health data for research and statistics, with no individual consent or general opt-out found. A national health data access body (CHDC) is being built by the HZJZ institute until November 2027.",
     "sources": [
      {
       "title": "Zakon o podacima i informacijama u zdravstvu (NN 14/19, HLK copy)",
       "url": "https://www.hlk.hr/EasyEdit/UserFiles/propisi/zakon-o-podacima-i-informacijama-u-zdravstvu-nn-14-2019.pdf",
       "date": "2019-02-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Hrvatski centar za zdravstvene podatke (CHDC) (HZJZ)",
       "url": "https://www.hzjz.hr/en/projekti/hrvatski-centar-za-zdravstvene-podatke-eng-croatian-health-data-centre-chdc/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Zakon o zastiti prava pacijenata (NN 169/04)",
       "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/full/2004_12_169_2953.html",
       "date": "2004-12-03",
       "publisherClass": "legal_text"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU law only: the AI Act and the medical device rules. Croatia named fundamental-rights bodies in 2024, but no national AI law or health-AI rule was verified as adopted.",
     "sources": [
      {
       "title": "Objavljen popis nadleznih tijela sukladno Uredbi o umjetnoj inteligenciji (MPUDT)",
       "url": "https://mpudt.gov.hr/vijesti/objavljen-popis-nadleznih-tijela-sukladno-uredbi-o-umjetnoj-inteligenciji/29657?lang=hr",
       "date": "2024-12-05",
       "publisherClass": "official"
      },
      {
       "title": "Hrvatska priprema zakonski okvir za nadzor primjene umjetne inteligencije (financije.hr)",
       "url": "https://financije.hr/hrvatska-priprema-zakonski-okvir-za-nadzor-primjene-umjetne-inteligencije/",
       "date": "2025-07-21",
       "publisherClass": "news"
      },
      {
       "title": "AI Act: regulatory framework for AI (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Zakon o podacima i informacijama u zdravstvu (NN 14/19)",
     "level": "National",
     "year": "2019",
     "what": "Creates e-Karton, limits access to treating clinicians, obliges every provider to exchange data via CEZIH.",
     "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/full/2019_02_14_269.html"
    },
    {
     "name": "Zakon o zastiti prava pacijenata (NN 169/04)",
     "level": "National",
     "year": "2004",
     "what": "Right to the whole medical record, copies at own cost; written consent for research.",
     "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/full/2004_12_169_2953.html"
    },
    {
     "name": "Pravilnik o opsegu i sadrzaju podataka te nacinu vodenja e-Kartona (NN 74/2023)",
     "level": "National",
     "year": "2023",
     "what": "Sets e-Karton contents and access; portal must show who viewed which data and when.",
     "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/2023_07_74_1210.html"
    },
    {
     "name": "Zakon o provedbi Opce uredbe o zastiti podataka (NN 42/18)",
     "level": "National",
     "year": "2018",
     "what": "Implements GDPR; public authorities cannot be fined by AZOP.",
     "url": "https://narodne-novine.nn.hr/clanci/sluzbeni/2018_05_42_805.html"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health is special-category data; fines up to EUR 20M or 4% of turnover.",
     "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Free access, access log, restriction rights and secondary-use opt-out; main parts apply from 2029.",
     "url": "https://eur-lex.europa.eu/eli/reg/2025/327/oj/eng"
    },
    {
     "name": "Artificial Intelligence Act (EU) 2024/1689",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk-based AI rules; high-risk duties for AI in medical devices from August 2028.",
     "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng"
    }
   ],
   "dti": {
    "grade": 88,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-04",
     "headline": "Patients asked a private hospital for their scans; the images had been lost",
     "paraphrase": "Several patients complained that a private hospital never sent copies of their records. The regulator found imaging files had been irretrievably lost, no backups existed, the loss was never reported, and fined the hospital 190,000 euros.",
     "source": "Agencija za zaštitu osobnih podataka (AZOP), final decision UP/I-034-01/24-01/23",
     "url": "https://azop.hr/wp-content/uploads/2026/04/AZOP_Rjesenje-pravomocno_Medico.pdf",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2025-07",
     "headline": "Hospital worker photographed a patient's test result on screen and it reached the media",
     "paraphrase": "An unknown hospital employee photographed a patient's result in the hospital system and it was published by the media. The hospital neither reported the breach nor told the patient until their lawyer wrote. The regulator fined it.",
     "source": "Agencija za zaštitu osobnih podataka (AZOP), anonymised decision 567-UP/I-034-01/24-01/31",
     "url": "https://azop.hr/wp-content/uploads/2025/07/bolnica2-clanak-32-33-13-34.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-07",
     "headline": "Ransomware attacker spent a week inside a hospital network and copied data out",
     "paraphrase": "After a ransomware attack, the regulator found a hospital's weak technical safeguards let an attacker roam its systems unnoticed for about seven days and copy at least 3 GB out. The hospital was fined 20,000 euros.",
     "source": "Agencija za zaštitu osobnih podataka (AZOP), anonymised decision 567-UP/I-034-01/24-01/34",
     "url": "https://azop.hr/wp-content/uploads/2025/07/bolnica1-clanak-32.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-08-23",
     "headline": "Hackers claim to have posted thousands of patient records from a Croatian practice",
     "paraphrase": "A hacking group claimed it broke into a private medical practice and posted about 9,400 records for free download, including names, national ID numbers, addresses, medicines, doctors' notes and scanned medical documents. The practice was not named.",
     "source": "Dnevnik.hr (Nova TV)",
     "url": "https://dnevnik.hr/vijesti/hrvatska/udar-na-privatnost-pod-zastitom-gdpr-a-hakeri-besplatno-dijele-medicinsku-dokumentaciju-hrvatskih-gradjana---997427.html",
     "theme": "breach",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "LTU",
   "name": "Lithuania",
   "region": "Europe",
   "overall": 60,
   "rank": "23=",
   "likelyRank": "14 to 30",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "A national e-health record with per-document hiding and a visible view history, undercut by weak clinician logins and a shaky central system.",
   "categories": {
    "access": {
     "score": 67,
     "summary": "The law gives patients their records and certified copies, and the national E. sveikata portal shows diagnoses, prescriptions, referrals, images and vaccinations. An EC study scored Lithuania 95% on eHealth maturity, but lab results were only being added from October 2025.",
     "sources": [
      {
       "title": "Lietuvos Respublikos pacientų teisių ir žalos sveikatai atlyginimo įstatymas I-1562 (suvestinė redakcija nuo 2025-07-01)",
       "url": "https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/TAIS.31932/asr",
       "date": "2025-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "E. sveikata (E. sveikatos portalas)",
       "url": "https://www.esveikata.lt/e-sveikata",
       "date": "2025-10-14",
       "publisherClass": "official"
      },
      {
       "title": "2025 Digital Decade eHealth indicator study, final report (European Commission, DG CNECT)",
       "url": "http://espanadigital.gob.es/sites/espanadigital/files/2025-12/Estudio%20de%20Indicadores%20de%20eHealth%20de%20la%20D%C3%A9cada%20Digital%202025.pdf",
       "date": "2025",
       "publisherClass": "intergov"
      },
      {
       "title": "Pacientų laboratorinių tyrimų duomenys bus keliami į E. sveikatą",
       "url": "https://www.esveikata.lt/naujiena/259",
       "date": "2025-10-07",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 62,
     "summary": "Patients can hide individual documents and see who viewed each one, when and on what basis. Hiding does not stop primary care doctors, emergency doctors or representatives, and uploads need no consent.",
     "sources": [
      {
       "title": "4.21 Peržiūrėti ESI įrašą (E. sveikatos paciento portalo pagalba)",
       "url": "https://pacientas.esveikata.lt/help/pages/perzireti-esi-irasa.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Overview of the national laws on electronic health records in the EU Member States: Lithuania (European Commission)",
       "url": "https://ec.europa.eu/health/system/files/2016-11/laws_lithuania_en_0.pdf",
       "date": "2016-11",
       "publisherClass": "intergov"
      },
      {
       "title": "Siurbiami ne tik Registrų centro duomenys: jūsų sveikatos duomenis gali perskaityti ir valytoja (15min)",
       "url": "https://www.15min.lt/verslas/naujiena/bendroves/siurbiami-ne-tik-registru-centro-duomenys-jusu-sveikatos-duomenis-gali-perskaityti-ir-valytoja-663-2698800",
       "date": "2026-06-05",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 50,
     "summary": "Patient information is confidential by law and GDPR applies, but clinician access to E. sveikata relies on a username and password. In June 2026 the ministry tabled a cybersecurity law package after an intrusion into a health agency subsystem.",
     "sources": [
      {
       "title": "Lietuvos Respublikos pacientų teisių ir žalos sveikatai atlyginimo įstatymas I-1562 (suvestinė redakcija nuo 2025-07-01)",
       "url": "https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/TAIS.31932/asr",
       "date": "2025-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Atsakas kibernetinėms grėsmėms: Seime registruoti strateginiai įstatymų pakeitimai E. sveikatos stiprinimui",
       "url": "https://www.esveikata.lt/naujiena/318",
       "date": "2026-06-10",
       "publisherClass": "official"
      },
      {
       "title": "Siurbiami ne tik Registrų centro duomenys: jūsų sveikatos duomenis gali perskaityti ir valytoja (15min)",
       "url": "https://www.15min.lt/verslas/naujiena/bendroves/siurbiami-ne-tik-registru-centro-duomenys-jusu-sveikatos-duomenis-gali-perskaityti-ir-valytoja-663-2698800",
       "date": "2026-06-05",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 68,
     "summary": "One national system, ESPBI IS, holds visits, diagnoses, e-prescriptions and referrals, and since October 2025 labs are moving onto it in a structured format. A November 2025 upgrade left clinicians unable to work properly.",
     "sources": [
      {
       "title": "Pacientų laboratorinių tyrimų duomenys bus keliami į E. sveikatą",
       "url": "https://www.esveikata.lt/naujiena/259",
       "date": "2025-10-07",
       "publisherClass": "official"
      },
      {
       "title": "Lietuvoje išrašytus e. receptus pripažins daugiau ES valstybių",
       "url": "https://www.esveikata.lt/naujiena/210",
       "date": "2024-09-04",
       "publisherClass": "official"
      },
      {
       "title": "Registrų centras tęsia E. sveikatos trikdžių šalinimą",
       "url": "https://www.esveikata.lt/naujiena/274",
       "date": "2025-11-10",
       "publisherClass": "official"
      },
      {
       "title": "Data Resource Profile: The Lithuanian health data reuse pathway (International Journal of Epidemiology)",
       "url": "https://academic.oup.com/ije/article/54/4/dyaf118/8186979",
       "date": "2025-07-06",
       "publisherClass": "academic"
      }
     ]
    },
    "commercial": {
     "score": 54,
     "summary": "The 2021 health data reuse law limits reuse to six purposes, and marketing is not one of them, but businesses may get permits for innovation. No explicit ban on selling health data or using it for advertising was found.",
     "sources": [
      {
       "title": "Lietuvos Respublikos pakartotinio sveikatos duomenų naudojimo įstatymas XIV-789 (suvestinė redakcija nuo 2023-09-01)",
       "url": "https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/72c77a52626411ecb2fe9975f8a9e52e/asr",
       "date": "2023-09-01",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 64,
     "summary": "Clinicians use a national specialist portal to read records from other providers, and patient hiding cannot block emergency or primary care doctors. Cross-provider lab results only began arriving in late 2025.",
     "sources": [
      {
       "title": "4.21 Peržiūrėti ESI įrašą (E. sveikatos paciento portalo pagalba)",
       "url": "https://pacientas.esveikata.lt/help/pages/perzireti-esi-irasa.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Pacientų laboratorinių tyrimų duomenys bus keliami į E. sveikatą",
       "url": "https://www.esveikata.lt/naujiena/259",
       "date": "2025-10-07",
       "publisherClass": "official"
      },
      {
       "title": "Registrų centras tęsia E. sveikatos trikdžių šalinimą",
       "url": "https://www.esveikata.lt/naujiena/274",
       "date": "2025-11-10",
       "publisherClass": "official"
      },
      {
       "title": "Premjerė e.sveikatą vadina anekdotu, tikisi IT progreso viešajame sektoriuje (tv3.lt, BNS)",
       "url": "https://www.tv3.lt/naujiena/lietuva/premjere-e-sveikata-vadina-anekdotu-tikisi-it-progreso-viesajame-sektoriuje-n1468966",
       "date": "2025-11-12",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 48,
     "summary": "Data collected for care can be reused for research under a State Data Agency permit without the person's consent, and no general opt-out exists. Safeguards include a public register of permitted uses and checks that published results are anonymised.",
     "sources": [
      {
       "title": "Lietuvos Respublikos pakartotinio sveikatos duomenų naudojimo įstatymas XIV-789 (suvestinė redakcija nuo 2023-09-01)",
       "url": "https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/72c77a52626411ecb2fe9975f8a9e52e/asr",
       "date": "2023-09-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Biomedicininių tyrimų etikos įstatymo Nr. VIII-1679 pakeitimo įstatymas XIII-2758",
       "url": "https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/b34677de288611ea8f0dfdc2b5879561/asr",
       "date": "2019-12-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Data Resource Profile: The Lithuanian health data reuse pathway (International Journal of Epidemiology)",
       "url": "https://academic.oup.com/ije/article/54/4/dyaf118/8186979",
       "date": "2025-07-06",
       "publisherClass": "academic"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device law and the AI Act, whose duties for medical devices now start 2 August 2028. Lithuania has named the regulators the AI Act requires, but no national clinical AI rules were verified.",
     "sources": [
      {
       "title": "AI Act Service Desk: national resources (European Commission)",
       "url": "https://ai-act-service-desk.ec.europa.eu/en/national-resources",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "EU Digital Omnibus on AI enters into force (K&L Gates, Cyber Law Watch)",
       "url": "https://www.cyberlawwatch.com/2026/07/31/eu-digital-omnibus-on-ai-enters-into-force/",
       "date": "2026-07-31",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Law on the Rights of Patients and Compensation for Damage to Health (I-1562)",
     "level": "National",
     "year": "1996",
     "what": "Right to see records and get certified copies; confidentiality of patient information; consent for disclosure.",
     "url": "https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/TAIS.31932/asr"
    },
    {
     "name": "Law on the Reuse of Health Data (XIV-789)",
     "level": "National",
     "year": "2021",
     "what": "Permit-based reuse by the State Data Agency for six purposes; no consent needed for care data.",
     "url": "https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/72c77a52626411ecb2fe9975f8a9e52e/asr"
    },
    {
     "name": "Law on Biomedical Research Ethics (VIII-1679), amended by XIII-2758",
     "level": "National",
     "year": "2019",
     "what": "Informed written consent for biomedical research and biobank participation.",
     "url": "https://e-seimas.lrs.lt/portal/legalAct/lt/TAD/b34677de288611ea8f0dfdc2b5879561/asr"
    },
    {
     "name": "Regulation (EU) 2025/327 (European Health Data Space)",
     "level": "Supranational",
     "year": "2025",
     "what": "Free access, restriction rights, access logs and secondary-use opt-out; main duties apply from March 2029 and 2031.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "Regulation (EU) 2026/1744 (Digital Omnibus on AI)",
     "level": "Supranational",
     "year": "2026",
     "what": "Delays AI Act duties for AI in medical devices to 2 August 2028.",
     "url": "https://www.cyberlawwatch.com/2026/07/31/eu-digital-omnibus-on-ai-enters-into-force/"
    }
   ],
   "dti": {
    "grade": 89,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-09-03",
     "headline": "Regulator reprimands sanatorium for opening a patient's unrelated national e-health documents",
     "paraphrase": "A patient saw in the national e-health log that a sanatorium's staff had opened a referral written for a different specialist. The regulator found no lawful basis for viewing it and reprimanded the sanatorium.",
     "source": "Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)",
     "url": "https://vdai.lrv.lt/public/canonical/1788937777/1540/2026-09-03%20sprendimas%20Nr.%203R-1575%20(2.13-1.E).pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-06-19",
     "headline": "Private clinic group fined 450,000 euros after two breaches of patient records",
     "paraphrase": "A leaked staff login let an outsider open 63 patients' files, and a later ransomware attack hit systems holding records of about 383,000 patients. The regulator found security was inadequate and fined the company 450,000 euros.",
     "source": "Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)",
     "url": "https://vdai.lrv.lt/public/canonical/1782465015/1462/2026-06-19%20sprendimas%20Nr.%203R-1143%20",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-06-05",
     "headline": "Doctor fined for opening 1,231 patients' files and contacting them without a lawful basis",
     "paraphrase": "While on sick leave and about to leave a public primary care centre, a doctor viewed 1,231 patients' files in its records system and used their contacts to email and text them. The regulator fined the doctor 1,153 euros.",
     "source": "Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)",
     "url": "https://vdai.lrv.lt/public/canonical/1780997432/1430/2026-06-05%20sprendimas%20Nr.%203R-1040%20",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-08-20",
     "headline": "Nurse logged a visit that never happened in a patient's national e-health record",
     "paraphrase": "While handling a records transfer, a nurse at a health centre registered a visit the patient never made, then deleted it. The regulator accepted the centre's fixes and rejected the complaint as posing no real risk.",
     "source": "Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate of Lithuania)",
     "url": "https://vdai.lrv.lt/public/canonical/1755688163/1060/2025-08-20%20sprendimas%20Nr.%203R-1087%20(2.13-1.E).pdf",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2026-06-22",
     "headline": "Clinic's system error sent health check invitations to women registered with other providers",
     "paraphrase": "Women received text invitations from a clinic they had never used. The clinic blamed a backend fault in an information system shared with other providers, could not say how many people were reached, and said no data left the system.",
     "source": "Respublika.lt (Vakaro žinios)",
     "url": "https://www.respublika.lt/lt/naujienos/lietuva/kitos-lietuvos-zinios/ne-jiems-skirtas-sms-gave-pacientai-baiminasi-ar-nenutekejo-ju-duomenys/",
     "theme": "record_wrong",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "NLD",
   "name": "Netherlands",
   "region": "Europe",
   "overall": 60,
   "rank": "23=",
   "likelyRank": "16 to 32",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Dutch records move between providers only with the patient's explicit opt-in, but few people use their copy apps and an EHDS opt-out is planned.",
   "categories": {
    "access": {
     "score": 55,
     "summary": "Dutch law gives a copy of the whole file and free electronic access, and about 93% of GPs connect to certified apps. Only 571,000 people fetched records that way in 2024, and the EU scores Dutch record access 69.35 against an 86.51 average.",
     "sources": [
      {
       "title": "Burgerlijk Wetboek Boek 7, art. 7:454-7:458 (WGBO), geldende versie (wetten.overheid.nl)",
       "url": "https://wetten.overheid.nl/BWBR0005290/2026-01-01/0",
       "date": "2026-01-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg (Wabvpz), art. 15a-15f (wetten.overheid.nl)",
       "url": "https://wetten.overheid.nl/BWBR0023864/2025-07-05/0",
       "date": "2025-07-05",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Decade 2026 country report, the Netherlands, SWD(2026) 155 (European Commission)",
       "url": "https://ec.europa.eu/newsroom/dae/redirection/document/128656",
       "date": "2026-06-17",
       "publisherClass": "intergov"
      },
      {
       "title": "Ruim half miljoen Nederlanders haalden in 2024 via MedMij gegevens op (Stichting MedMij)",
       "url": "https://medmij.nl/media/ruim-half-miljoen-nederlanders-haalden-in-2024-via-medmij-gegevens-op/",
       "date": "2025-02-13",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 72,
     "summary": "Under the Wabvpz a provider may share data through an exchange system only with the patient's explicit consent, and patients can see on Volgjezorg who viewed their data via the national switch point. Consent is split across several systems, and the government plans an EHDS opt-out.",
     "sources": [
      {
       "title": "Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg (Wabvpz), art. 15a-15f (wetten.overheid.nl)",
       "url": "https://wetten.overheid.nl/BWBR0023864/2025-07-05/0",
       "date": "2025-07-05",
       "publisherClass": "legal_text"
      },
      {
       "title": "Vragen & antwoorden (Mitz, Stichting GVvZ / VZVZ)",
       "url": "https://www.mitz-toestemming.nl/kennis-en-ondersteuning/vragen-antwoorden",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Volgjezorg: grip op je medische gegevens (VZVZ)",
       "url": "https://www.volgjezorg.nl/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "MijnMitz: toestemmingskeuzes voor het delen van medische gegevens (Mitz)",
       "url": "https://www.mijnmitz.nl",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 52,
     "summary": "The 2025 hack of lab Clinical Diagnostics exposed data of up to 850,000 people, and the health inspectorate found the lab had not met the required NEN 7510 security norm but cannot fine it. Health and welfare filed over 6,800 breach reports in 2024.",
     "sources": [
      {
       "title": "Clinical Diagnostics voldeed niet aan wettelijke norm voor informatiebeveiliging (IGJ)",
       "url": "https://www.igj.nl/actueel/nieuws/2026/05/13/clinical-diagnostics-voldeed-niet-aan-wettelijke-norm-voor-informatiebeveiliging",
       "date": "2026-05-13",
       "publisherClass": "official"
      },
      {
       "title": "AP gaat databeveiliging in de zorg controleren (Autoriteit Persoonsgegevens)",
       "url": "https://www.autoriteitpersoonsgegevens.nl/actueel/ap-gaat-databeveiliging-in-de-zorg-controleren",
       "date": "2025-12-03",
       "publisherClass": "official"
      },
      {
       "title": "Boete OLVG (Autoriteit Persoonsgegevens)",
       "url": "https://www.autoriteitpersoonsgegevens.nl/documenten/boete-olvg",
       "date": "2021-02-11",
       "publisherClass": "official"
      },
      {
       "title": "Hackers laboratorium hadden toegang tot gegevens 850.000 mensen (NOS)",
       "url": "https://nos.nl/artikel/2580363-hackers-laboratorium-hadden-toegang-tot-gegevens-850-000-mensen",
       "date": "2025-08-29",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 60,
     "summary": "The national switch point carries more than a billion messages a year, mainly between GPs and pharmacies, and the Wegiz can make set data flows electronic by law. The Commission still calls Dutch health digitalisation fragmented, with no overview of which hospitals share data.",
     "sources": [
      {
       "title": "Jaarterugblik AORTA-LSP 2025 (VZVZ)",
       "url": "https://www.vzvz.nl/nieuws/jaarterugblik-aorta-lsp-2025",
       "date": "2026-02-03",
       "publisherClass": "official"
      },
      {
       "title": "Wegiz: uitleg over de wet (Data voor gezondheid, ministerie van VWS)",
       "url": "https://www.datavoorgezondheid.nl/onderwerpen/w/wegiz/uitleg-over-de-wet",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Digital Decade 2026 country report, the Netherlands, SWD(2026) 155 (European Commission)",
       "url": "https://ec.europa.eu/newsroom/dae/redirection/document/128656",
       "date": "2026-06-17",
       "publisherClass": "intergov"
      },
      {
       "title": "European Health Data Space Regulation (EHDS) (European Commission, DG SANTE)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "commercial": {
     "score": 62,
     "summary": "Dutch law bars health insurers, company doctors and insurance doctors from the electronic exchange systems, and limits genetic questions in insurance medical checks. Certified patient apps are contractually barred from selling data, and the EHDS bans marketing use of research data from 2029.",
     "sources": [
      {
       "title": "Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg (Wabvpz), art. 15a-15f (wetten.overheid.nl)",
       "url": "https://wetten.overheid.nl/BWBR0023864/2025-07-05/0",
       "date": "2025-07-05",
       "publisherClass": "legal_text"
      },
      {
       "title": "Wet op de medische keuringen, art. 5 (wetten.overheid.nl)",
       "url": "https://wetten.overheid.nl/BWBR0008819/2025-01-01/0",
       "date": "2025-01-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Veelgestelde vragen van zorggebruikers (Stichting MedMij)",
       "url": "https://medmij.nl/zorggebruikers/vragen-van-zorggebruikers/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (EHDS) (European Commission, DG SANTE)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "clinical": {
     "score": 58,
     "summary": "A treating clinician can see GP and pharmacy data through the national switch point once the patient has consented, and pharmacists say most patients do. What is shared is limited by professional rules, such as six months of dispensed medication.",
     "sources": [
      {
       "title": "Burgerlijk Wetboek Boek 7, art. 7:454-7:458 (WGBO), geldende versie (wetten.overheid.nl)",
       "url": "https://wetten.overheid.nl/BWBR0005290/2026-01-01/0",
       "date": "2026-01-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Vragen & antwoorden (Mitz, Stichting GVvZ / VZVZ)",
       "url": "https://www.mitz-toestemming.nl/kennis-en-ondersteuning/vragen-antwoorden",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Landelijk Schakelpunt (LSP), dossier medicatieoverdracht (KNMP)",
       "url": "https://www.knmp.nl/dossiers/medicatieoverdracht/landelijk-schakelpunt-lsp",
       "date": "2026-07-31",
       "publisherClass": "official"
      },
      {
       "title": "Mijlpaal: 1 miljoen bezoekers op MijnMitz.nl (VZVZ)",
       "url": "https://www.vzvz.nl/nieuws/mijlpaal-1-miljoen-bezoekers-op-mijnmitznl",
       "date": "2025-11-21",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 57,
     "summary": "Records may go to health research without consent only when asking is not feasible or data are de-identified, and never if the patient has expressly objected. Objection is made at each provider, with no national register.",
     "sources": [
      {
       "title": "Burgerlijk Wetboek Boek 7, art. 7:454-7:458 (WGBO), geldende versie (wetten.overheid.nl)",
       "url": "https://wetten.overheid.nl/BWBR0005290/2026-01-01/0",
       "date": "2026-01-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Privacybescherming Nivel Zorgregistraties Eerste Lijn (Nivel)",
       "url": "https://www.nivel.nl/nl/panels-en-registraties/nivel-zorgregistraties-eerste-lijn/deelnemen-en-deelnemers/privacybescherming",
       "date": "undated",
       "publisherClass": "academic"
      },
      {
       "title": "Internetconsultatie Wet op het Gezondheidsinformatiestelsel gestart (Data voor gezondheid, ministerie van VWS)",
       "url": "https://www.datavoorgezondheid.nl/actueel/nieuws/2026/06/09/internetconsultatie-wet-op-het-gezondheidsinformatiestelsel-gestart",
       "date": "2026-06-09",
       "publisherClass": "official"
      },
      {
       "title": "Kamerbrief over de implementatie van de EHDS, Kamerstuk 27 529 nr. 356 (Minister van VWS)",
       "url": "https://www.tweedekamer.nl/downloads/document?id=2026D02216",
       "date": "2026-01-20",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device law and the AI Act, whose duties for AI in medical devices now start 2 August 2028. Dutch national guidance on AI in care is voluntary, so no national credit is given.",
     "sources": [
      {
       "title": "Leidraad kwaliteit AI in de zorg nader onderzocht (Data voor gezondheid, ministerie van VWS)",
       "url": "https://www.datavoorgezondheid.nl/actueel/nieuws/2025/09/08/leidraad-kwaliteit-ai-in-de-zorg-nader-onderzocht",
       "date": "2025-09-08",
       "publisherClass": "official"
      },
      {
       "title": "Digital Omnibus on AI, Regulation (EU) 2026/1744, text and dates (AI Act Explorer, artificialintelligenceact.eu)",
       "url": "https://artificialintelligenceact.eu/ai-act-explorer/digital-omnibus/",
       "date": "undated",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "Digital Decade 2026 country report, the Netherlands, SWD(2026) 155 (European Commission)",
       "url": "https://ec.europa.eu/newsroom/dae/redirection/document/128656",
       "date": "2026-06-17",
       "publisherClass": "intergov"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Burgerlijk Wetboek Boek 7, afdeling 5 (WGBO)",
     "level": "National",
     "year": "1994",
     "what": "Right to access and copy the file, 20-year retention, secrecy, research without consent unless the patient objects.",
     "url": "https://wetten.overheid.nl/BWBR0005290/2026-01-01/0"
    },
    {
     "name": "Wet aanvullende bepalingen verwerking persoonsgegevens in de zorg (Wabvpz)",
     "level": "National",
     "year": "2008",
     "what": "Explicit consent for electronic exchange, free electronic copies, access log on request, insurers barred.",
     "url": "https://wetten.overheid.nl/BWBR0023864/2025-07-05/0"
    },
    {
     "name": "Wet elektronische gegevensuitwisseling in de zorg (Wegiz)",
     "level": "National",
     "year": "2023",
     "what": "Framework law making named data flows electronic and standardised, with certified software.",
     "url": "https://www.datavoorgezondheid.nl/onderwerpen/w/wegiz/uitleg-over-de-wet"
    },
    {
     "name": "Wet op de medische keuringen (Wmk)",
     "level": "National",
     "year": "1997",
     "what": "Bans genetic and hereditary disease questions in insurance medical checks below a set amount.",
     "url": "https://wetten.overheid.nl/BWBR0008819/2025-01-01/0"
    },
    {
     "name": "Wet op het Gezondheidsinformatiestelsel (Wet GIS), bill",
     "level": "National",
     "year": "2026",
     "what": "First EHDS implementing law; creates the Health Data Authority. In consultation from 27 May 2026.",
     "url": "https://www.datavoorgezondheid.nl/actueel/nieuws/2026/06/09/internetconsultatie-wet-op-het-gezondheidsinformatiestelsel-gestart"
    },
    {
     "name": "Regulation (EU) 2025/327, European Health Data Space",
     "level": "Supranational",
     "year": "2025",
     "what": "Access, restriction and secondary-use opt-out rights; key parts apply from March 2029 and 2031.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "Regulation (EU) 2026/1744, Digital Omnibus on AI",
     "level": "Supranational",
     "year": "2026",
     "what": "Sets 2 August 2028 for AI Act duties on high-risk AI in products such as medical devices.",
     "url": "https://artificialintelligenceact.eu/ai-act-explorer/digital-omnibus/"
    }
   ],
   "dti": {
    "grade": 78,
    "tier": "Silver",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-04-14",
     "headline": "Nurse reprimanded for repeatedly opening patient files with no care reason",
     "paraphrase": "A hospital's log checks showed a nurse had opened the electronic files of several patients he was not treating, more than once and over a long period. He admitted it, citing curiosity and boredom. The tribunal reprimanded him.",
     "source": "Regionaal Tuchtcollege voor de Gezondheidszorg Amsterdam",
     "url": "https://tuchtrecht.overheid.nl/ECLI_NL_TGZRAMS_2026_80",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-02-03",
     "headline": "Appeal tribunal upholds complaint that a surgeon refused to hand over a medical file",
     "paraphrase": "A patient complained that her surgeon refused to provide her medical file, among other complaints. On appeal, the national disciplinary tribunal found the complaint about the file partly justified, and the reprimand stayed in place.",
     "source": "Centraal Tuchtcollege voor de Gezondheidszorg",
     "url": "https://tuchtrecht.overheid.nl/zoeken/resultaat/uitspraak/2025/ECLI_NL_TGZCTG_2025_19",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2024-11-13",
     "headline": "Doctor reprimanded for giving a patient's records to an outside expert without consent",
     "paraphrase": "During a civil case he brought against a patient, a doctor passed her medical data to an outside expert without asking her. The tribunal found confidentiality was breached and reprimanded him.",
     "source": "Regionaal Tuchtcollege voor de Gezondheidszorg 's-Hertogenbosch",
     "url": "https://tuchtrecht.overheid.nl/ECLI:NL:TGZRSHE:2024:125",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-08-11",
     "headline": "Hackers took screening results and addresses of 485,000 women from a lab",
     "paraphrase": "A lab running part of a national screening programme confirmed it was hacked. Test results, names, addresses, provider names and GP referrals of about 485,000 women, going back years, were stolen. The screening organisation said several years were involved.",
     "source": "NOS",
     "url": "https://nos.nl/artikel/2578296-gegevens-honderdduizenden-vrouwen-gehackt-bij-bevolkingsonderzoek-baarmoederhalskanker",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2025-09-11",
     "headline": "One in ten hospital patients hit a near miss because records were missing",
     "paraphrase": "A patient survey found more than one in ten people treated in hospital in 2024 experienced something going, or nearly going, wrong because a provider lacked their medical information. Reported harms included repeat scans and medication errors.",
     "source": "ICT&health",
     "url": "https://www.icthealth.nl/nieuws/patientenfederatie-nationale-aanpak-gebrekkige-gegevensuitwisseling",
     "theme": "lost_between_providers",
     "status": "self_reported"
    }
   ]
  },
  {
   "iso3": "KOR",
   "name": "South Korea",
   "region": "Asia",
   "overall": 60,
   "rank": "23=",
   "likelyRank": "13 to 29",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Koreans can copy their whole record and see 10 years of claims online, and clinical records move only with opt-in consent.",
   "categories": {
    "access": {
     "score": 66,
     "summary": "The Medical Service Act lets patients view or copy their whole record, though copies carry a fee and we found no deadline. Since May 2026 NHIS lets every insured person view and download up to 10 years of claims-based treatment history online.",
     "sources": [
      {
       "title": "Medical Service Act, current text (CaseNote mirror of Korean statute)",
       "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EC%9D%98%EB%A3%8C%EB%B2%95",
       "date": "2026-03-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Standard on certificate fees of medical institutions (MOHW notice, hosted by HIRA)",
       "url": "https://www.hira.or.kr/cms/inform/01/__icsFiles/afieldfile/2017/09/19/1.pdf",
       "date": "2017-09-19",
       "publisherClass": "official"
      },
      {
       "title": "All 47 tertiary hospitals now visible in My Health Record app (MOHW via korea.kr)",
       "url": "https://www.korea.kr/news/policyNewsView.do?newsId=148948286",
       "date": "2025-08-27",
       "publisherClass": "official"
      },
      {
       "title": "NHIS starts mobile issuance of 10 years of treatment history (Edaily via Daum)",
       "url": "https://v.daum.net/v/20260511101017677",
       "date": "2026-05-11",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 55,
     "summary": "Records move between hospitals, or to apps and firms, only with the patient's opt-in consent, chosen by institution, item and period and revocable. We found no way for patients to see who opened their chart, which holds control at the top of the 40 to 55 band.",
     "sources": [
      {
       "title": "Medical Service Act, current text (CaseNote mirror of Korean statute)",
       "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EC%9D%98%EB%A3%8C%EB%B2%95",
       "date": "2026-03-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "What is the Health Information Highway service? (MOHW / KHIS portal)",
       "url": "https://www.myhealthway.go.kr/portal/index?page=Individual/Portal/MediMyData/MydataService",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Health-sector data transmitters expanded to general hospitals (PIPC press release)",
       "url": "https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=11899",
       "date": "2026-03-18",
       "publisherClass": "official"
      },
      {
       "title": "Even viewing an EMR will leave an access record from December (Korean Nurses Association news)",
       "url": "https://www.nursenews.co.kr/news/articleView.html?idxno=44048",
       "date": "2026-09-09",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 65,
     "summary": "PIPA treats health data as sensitive, and the independent PIPC has sanctioned hospitals with administrative fines and improvement orders rather than revenue-based penalties. Since 11 September 2026 serious violations can cost up to 10% of revenue, and the EU confirmed Korea's GDPR adequacy in July 2026.",
     "sources": [
      {
       "title": "PIPC sanctions 17 general hospitals over patient data leak (PIPC press release)",
       "url": "https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=9056",
       "date": "2023-07-27",
       "publisherClass": "official"
      },
      {
       "title": "Personal Information Protection Act, current text in force 11 Sep 2026 (CaseNote mirror of Korean statute)",
       "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4_%EB%B3%B4%ED%98%B8%EB%B2%95",
       "date": "2026-03-10",
       "publisherClass": "legal_text"
      },
      {
       "title": "PIPC decides sanctions on Coupang and affiliates for leak and rights violations (PIPC press release)",
       "url": "https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12171",
       "date": "2026-06-11",
       "publisherClass": "official"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "2026-07-23",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 62,
     "summary": "Claims, medication and vaccination data are national, and the consent-based exchange links 10,332 facilities. Clinical records still sit in each provider's system, only about 600 facilities can share CT or MRI images, and a merged national platform is planned for 2029.",
     "sources": [
      {
       "title": "All 47 tertiary hospitals now visible in My Health Record app (MOHW via korea.kr)",
       "url": "https://www.korea.kr/news/policyNewsView.do?newsId=148948286",
       "date": "2025-08-27",
       "publisherClass": "official"
      },
      {
       "title": "Records follow you when you change hospitals: exchange passes 10,000 facilities (MOHW press release)",
       "url": "https://www.mohw.go.kr/board.es?mid=a10503010100&bid=0027&act=view&list_no=1489085&tag=&nPage=4",
       "date": "2026-02-12",
       "publisherClass": "official"
      },
      {
       "title": "Is DUR really checked by 99% of providers? (Medigate News)",
       "url": "https://www.medigatenews.com/news/3461624456",
       "date": "2025-10-17",
       "publisherClass": "news"
      },
      {
       "title": "Government to merge exchange and Health Information Highway by 2029 (Electronic Times)",
       "url": "https://www.etnews.com/20251020000130",
       "date": "2025-10-20",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 55,
     "summary": "Providers who release records face criminal penalties, and health data needs separate consent. But PIPA lets companies use pseudonymised health data without consent for research that includes private investment research, and patients can send records to commercial apps.",
     "sources": [
      {
       "title": "Medical Service Act, current text (CaseNote mirror of Korean statute)",
       "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EC%9D%98%EB%A3%8C%EB%B2%95",
       "date": "2026-03-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Personal Information Protection Act, current text in force 11 Sep 2026 (CaseNote mirror of Korean statute)",
       "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4_%EB%B3%B4%ED%98%B8%EB%B2%95",
       "date": "2026-03-10",
       "publisherClass": "legal_text"
      },
      {
       "title": "PIPC sanctions 17 general hospitals over patient data leak (PIPC press release)",
       "url": "https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=9056",
       "date": "2023-07-27",
       "publisherClass": "official"
      },
      {
       "title": "What is the Health Information Highway service? (MOHW / KHIS portal)",
       "url": "https://www.myhealthway.go.kr/portal/index?page=Individual/Portal/MediMyData/MydataService",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 58,
     "summary": "A doctor can pull records from another provider through the national exchange with the patient's consent, and without it for unconscious or emergency patients. Use is thin: about 1.81 million exchanges in 2025, and medication safety checks rarely change prescriptions.",
     "sources": [
      {
       "title": "Medical Service Act, current text (CaseNote mirror of Korean statute)",
       "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EC%9D%98%EB%A3%8C%EB%B2%95",
       "date": "2026-03-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Records follow you when you change hospitals: exchange passes 10,000 facilities (MOHW press release)",
       "url": "https://www.mohw.go.kr/board.es?mid=a10503010100&bid=0027&act=view&list_no=1489085&tag=&nPage=4",
       "date": "2026-02-12",
       "publisherClass": "official"
      },
      {
       "title": "Is DUR really checked by 99% of providers? (Medigate News)",
       "url": "https://www.medigatenews.com/news/3461624456",
       "date": "2025-10-17",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Pseudonymised health data can be used for research without consent and with no general opt-out. Safeguards cap the cell at 50: data review boards, secure analysis centres, a 5-year prison penalty for re-identification, and a consent route for data donation.",
     "sources": [
      {
       "title": "Personal Information Protection Act, current text in force 11 Sep 2026 (CaseNote mirror of Korean statute)",
       "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4_%EB%B3%B4%ED%98%B8%EB%B2%95",
       "date": "2026-03-10",
       "publisherClass": "legal_text"
      },
      {
       "title": "MOHW revises Health and Medical Data Utilisation Guideline (Korea Medical & Pharmaceutical News)",
       "url": "https://www.kmpnews.co.kr/news/articleView.html?idxno=68913",
       "date": "2026-01-01",
       "publisherClass": "news"
      },
      {
       "title": "Safe Use Centres for health data (K-CURE, MOHW)",
       "url": "https://k-cure.mohw.go.kr/portal/pfm/kif/use/viewPfmKifUse.do",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "What is the Health Information Highway service? (MOHW / KHIS portal)",
       "url": "https://www.myhealthway.go.kr/portal/index?page=Individual/Portal/MediMyData/MydataService",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 66,
     "summary": "Korea's Digital Medical Products Act, in force since January 2025, requires change approval for significant software changes, and the AI Basic Act names healthcare AI high-impact and requires human oversight. MFDS issued generative AI device guidance and approved the first such device in April 2026.",
     "sources": [
      {
       "title": "Digital Medical Products Act (CaseNote mirror of Korean statute)",
       "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EB%94%94%EC%A7%80%ED%84%B8%EC%9D%98%EB%A3%8C%EC%A0%9C%ED%92%88%EB%B2%95",
       "date": "2024-01-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Framework Act on AI Development and Trust (AI Basic Act), current text (CaseNote mirror)",
       "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5_%EB%B0%9C%EC%A0%84%EA%B3%BC_%EC%8B%A0%EB%A2%B0_%EA%B8%B0%EB%B0%98_%EC%A1%B0%EC%84%B1_%EB%93%B1%EC%97%90_%EA%B4%80%ED%95%9C_%EA%B8%B0%EB%B3%B8%EB%B2%95",
       "date": "2026-01-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "MFDS publishes world-first approval and review guideline for generative AI medical devices (MFDS press release)",
       "url": "https://www.mfds.go.kr/brd/m_99/view.do?seq=48833",
       "date": "2025-01-24",
       "publisherClass": "official"
      },
      {
       "title": "MFDS approves Korea's first generative-AI digital medical device (MFDS press release)",
       "url": "https://www.mfds.go.kr/brd/m_99/view.do?seq=49815",
       "date": "2026-04-01",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Medical Service Act (2024 amendment; Articles 21, 21-2, 21-3, 88)",
     "level": "National",
     "year": "2024",
     "what": "Right to view and copy records, consent-based transfer between providers, criminal penalty for unlawful disclosure.",
     "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EC%9D%98%EB%A3%8C%EB%B2%95"
    },
    {
     "name": "Personal Information Protection Act (2026 amendment)",
     "level": "National",
     "year": "2026",
     "what": "Separate consent for health data, consent-free pseudonymised research, data transfer right, fines up to 10% of revenue.",
     "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4_%EB%B3%B4%ED%98%B8%EB%B2%95"
    },
    {
     "name": "Digital Medical Products Act",
     "level": "National",
     "year": "2024",
     "what": "Dedicated law for digital and AI medical devices with change approval, real-world evaluation and certification; in force 2025.",
     "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EB%94%94%EC%A7%80%ED%84%B8%EC%9D%98%EB%A3%8C%EC%A0%9C%ED%92%88%EB%B2%95"
    },
    {
     "name": "Framework Act on AI Development and Trust (AI Basic Act)",
     "level": "National",
     "year": "2025",
     "what": "Healthcare AI is high-impact; requires risk management, explanation and human oversight; in force 22 Jan 2026.",
     "url": "https://casenote.kr/%EB%B2%95%EB%A0%B9/%EC%9D%B8%EA%B3%B5%EC%A7%80%EB%8A%A5_%EB%B0%9C%EC%A0%84%EA%B3%BC_%EC%8B%A0%EB%A2%B0_%EA%B8%B0%EB%B0%98_%EC%A1%B0%EC%84%B1_%EB%93%B1%EC%97%90_%EA%B4%80%ED%95%9C_%EA%B8%B0%EB%B3%B8%EB%B2%95"
    },
    {
     "name": "EU adequacy decision for the Republic of Korea",
     "level": "Supranational",
     "year": "2021",
     "what": "Lets personal data flow from the EU to Korea; confirmed after first review on 23 July 2026.",
     "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en"
    }
   ],
   "dti": {
    "grade": 82,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-03-19",
     "headline": "Rights commission finds a hospital routinely wrote false entries in a patient's record",
     "paraphrase": "After a patient died in hospital, the commission found staff had, as a routine practice, recorded a doctor as giving orders that the doctor never gave. It referred hospital staff to prosecutors and recommended changes to the law.",
     "source": "National Human Rights Commission of Korea",
     "url": "https://www.humanrights.go.kr/base/board/read?boardManagementNo=24&boardNo=7611008&searchCategory=&page=4&searchType=&searchWord=&menuLevel=3&menuNo=91",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2026-09-14",
     "headline": "Doctor took thousands of patients' details; hospital fined for late notice, not the leak",
     "paraphrase": "A doctor deliberately took 3,976 patients' personal data while preparing to open a practice. The privacy regulator fined the hospital for late notification and weak supervision of staff, but found no breach of security duties.",
     "source": "Hankyung (Korea Economic Daily)",
     "url": "https://www.hankyung.com/article/202609143107H",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2024-12-27",
     "headline": "Hospital doctors passed patients' prescription records to a drug company, court rules",
     "paraphrase": "Three senior doctors at a Seoul hospital gave drug company staff patients' prescription records, more than 17,000 entries, at the company's request. A court fined the doctors and the hospital's operator for failing to prevent it.",
     "source": "Pharmnews",
     "url": "https://www.pharmnews.com/news/articleView.html?idxno=256304",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2026-09-07",
     "headline": "Court fines dentist for writing false entries in a patient's record",
     "paraphrase": "A court fined a dentist one million won for writing a smaller medication amount in a patient's record than was actually given, and for recording health checks that were never carried out.",
     "source": "Law Issue (로이슈)",
     "url": "https://www.lawissue.co.kr/view.php?ud=2026090617253378379a8c8bf58f_12",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2026-09-14",
     "headline": "Staff at public health agencies looked up personal data for private reasons, files show",
     "paraphrase": "Disciplinary files that the public health insurer and claims review agency gave a lawmaker show staff viewing relatives' and an ex-partner's data, querying colleagues, and emailing sensitive screening files home. Penalties ranged from reprimand to dismissal.",
     "source": "Money Today (머니투데이)",
     "url": "https://www.mt.co.kr/thebio/2026/09/14/2026091409464048356",
     "theme": "breach",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "BGR",
   "name": "Bulgaria",
   "region": "Europe",
   "overall": 59,
   "rank": "27=",
   "likelyRank": "17 to 32",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Bulgaria's national health information system records every visit, prescription and hospital stay, with consent rules and an access history, but few patients use it.",
   "categories": {
    "access": {
     "score": 62,
     "summary": "The Health Act gives a right to copies, and the national record shows exams, referrals, lab results, vaccines, prescriptions and hospital stays. Use is low: about 500,000 records were reachable through the eZdrave app in February 2026, so the score sits low in its band.",
     "sources": [
      {
       "title": "Закон за здравето (consolidated text, Health Act)",
       "url": "https://asp.government.bg/uploaded/files/7032-zakon-za-zdraveto-28032025.pdf",
       "date": "2025-04-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Наредба № Н-6 от 21 декември 2022 г. за функционирането на НЗИС (Държавен вестник)",
       "url": "https://dv.parliament.bg/DVWeb/showMaterialDV.jsp?idMat=182160",
       "date": "2022-12-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Личните лекари вече имат достъп до електронните здравни досиета на пациентите си (МЗ)",
       "url": "https://www.mh.government.bg/bg/novini/aktualno/4340",
       "date": "2024-12-20",
       "publisherClass": "official"
      },
      {
       "title": "Близо 500 000 граждани имат достъп до здравните си досиета чрез еЗдраве (БТА)",
       "url": "https://www.bta.bg/bg/news/bulgaria/1065556-blizo-500-000-grazhdani-imat-dostap-do-zdravnite-si-dosieta-chrez-mobilnoto-pril",
       "date": "2026-02-17",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 62,
     "summary": "Access by providers, the health fund and insurers needs the patient's express written consent, which can be limited and withdrawn, and patients can check an access history in the app. The patient's own GP has standing access.",
     "sources": [
      {
       "title": "Наредба № Н-6 от 21 декември 2022 г. за функционирането на НЗИС (Държавен вестник)",
       "url": "https://dv.parliament.bg/DVWeb/showMaterialDV.jsp?idMat=182160",
       "date": "2022-12-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Здравните досиета на близо 15 000 пациенти са били прегледани от личните им лекари за месец (НЗИС)",
       "url": "https://his.bg/bg/news/89",
       "date": "2025-01-23",
       "publisherClass": "official"
      },
      {
       "title": "Закон за здравето (consolidated text, Health Act)",
       "url": "https://asp.government.bg/uploaded/files/7032-zakon-za-zdraveto-28032025.pdf",
       "date": "2025-04-09",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 55,
     "summary": "GDPR applies and the data protection commission (CPDP) watches the health sector, which drew 23 complaints in 2025. Fines are small: in 2025 they ranged from BGN 500 to BGN 100,000.",
     "sources": [
      {
       "title": "Годишен отчет на КЗЛД за 2025 г.",
       "url": "https://cpdp.bg/wp-content/uploads/2026/04/corrected-Annual-report_2025_CPDP-12.03.2026-%D1%84%D0%B8%D0%BD%D0%B0%D0%BB.pdf",
       "date": "2026-03-12",
       "publisherClass": "official"
      },
      {
       "title": "Хакерска атака спря работата на онкоболницата в Хасково (Утро Русе)",
       "url": "https://utroruse.com/article/987626/",
       "date": "2023-12-18",
       "publisherClass": "news"
      },
      {
       "title": "Data protection in the EU (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/data-protection-eu_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "journey": {
     "score": 70,
     "summary": "Every provider, public or private, must send a signed electronic record of each activity to the national system. In January to July 2025 it logged nearly 29 million e-exams, and it links prescriptions, labs, hospitals and the health fund.",
     "sources": [
      {
       "title": "Закон за здравето (consolidated text, Health Act)",
       "url": "https://asp.government.bg/uploaded/files/7032-zakon-za-zdraveto-28032025.pdf",
       "date": "2025-04-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Близо 29 млн. е-прегледа регистрирани в НЗИС от началото на 2025 г. (zdrave.net)",
       "url": "https://www.zdrave.net/%D0%9D%D0%BE%D0%B2%D0%B8%D0%BD%D0%B8/%D0%91%D0%BB%D0%B8%D0%B7%D0%BE-29-%D0%BC%D0%BB%D0%BD.-%D0%B5-%D0%BF%D1%80%D0%B5%D0%B3%D0%BB%D0%B5%D0%B4%D0%B0-%D1%80%D0%B5%D0%B3%D0%B8%D1%81%D1%82%D1%80%D0%B8%D1%80%D0%B0%D0%BD%D0%B8-%D0%B2-%D0%9D%D0%97%D0%98%D0%A1-%D0%BE%D1%82-%D0%BD%D0%B0%D1%87%D0%B0%D0%BB%D0%BE%D1%82%D0%BE-%D0%BD%D0%B0-2025-%D0%B3.,-%D0%BD%D0%B0%D0%B4-%D0%BF%D0%BE%D0%BB%D0%BE%D0%B2%D0%B8%D0%BD%D0%B0%D1%82%D0%B0-%D1%81%D0%B0-%D0%BF%D1%80%D0%B8-%D0%B4%D0%B6%D0%B8%D0%BF%D0%B8%D1%82%D0%B0/n34757",
       "date": "2025-07-25",
       "publisherClass": "news"
      },
      {
       "title": "План за развитие (НЗИС)",
       "url": "https://his.bg/bg/info/roadmap",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Спешното пациентско досие влиза в Е-здраве (zdrave.to)",
       "url": "https://zdrave.to/saveti-ot-spetsialisti/speshnoto-pacientsko-dosie-vliza-v-e-zdrave",
       "date": "2026-08-04",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 50,
     "summary": "GDPR limits commercial use of health data, but the Health Act names licensed health insurers among those who may access the national record, with the patient's written consent. No Bulgaria-specific ban on selling health data was verified.",
     "sources": [
      {
       "title": "Закон за здравето (consolidated text, Health Act)",
       "url": "https://asp.government.bg/uploaded/files/7032-zakon-za-zdraveto-28032025.pdf",
       "date": "2025-04-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Наредба № Н-6 от 21 декември 2022 г. за функционирането на НЗИС (Държавен вестник)",
       "url": "https://dv.parliament.bg/DVWeb/showMaterialDV.jsp?idMat=182160",
       "date": "2022-12-24",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 62,
     "summary": "Since December 2024 about 4,000 GPs can see their patients' full national record, specialists get 30 days after an exam, and emergency staff can see key data without consent. Ordinance N-6 ties routine access to the patient's consent rules.",
     "sources": [
      {
       "title": "Личните лекари вече имат достъп до електронните здравни досиета на пациентите си (МЗ)",
       "url": "https://www.mh.government.bg/bg/novini/aktualno/4340",
       "date": "2024-12-20",
       "publisherClass": "official"
      },
      {
       "title": "Наредба № Н-6 от 21 декември 2022 г. за функционирането на НЗИС (Държавен вестник)",
       "url": "https://dv.parliament.bg/DVWeb/showMaterialDV.jsp?idMat=182160",
       "date": "2022-12-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Спешното пациентско досие влиза в Е-здраве (zdrave.to)",
       "url": "https://zdrave.to/saveti-ot-spetsialisti/speshnoto-pacientsko-dosie-vliza-v-e-zdrave",
       "date": "2026-08-04",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 44,
     "summary": "The Health Act allows health data to be used for statistics and research once identifying data are removed, with no individual consent or opt-out. A public transparency register was not verified; the EU EHDS adds an opt-out from 2029.",
     "sources": [
      {
       "title": "Закон за здравето (consolidated text, Health Act)",
       "url": "https://asp.government.bg/uploaded/files/7032-zakon-za-zdraveto-28032025.pdf",
       "date": "2025-04-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Наредба № Н-6 от 21 декември 2022 г. за функционирането на НЗИС (Държавен вестник)",
       "url": "https://dv.parliament.bg/DVWeb/showMaterialDV.jsp?idMat=182160",
       "date": "2022-12-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device law and the AI Act, whose duties for AI in medical devices apply from 2 August 2028. Bulgaria has no national AI law in force; a draft bill reached parliament in September 2026.",
     "sources": [
      {
       "title": "AI Act: regulatory framework for AI (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "България все още няма надзор над високорисковите системи с изкуствен интелект (Дебати)",
       "url": "https://debati.bg/zakonodatelen-akt-za-izkustveniya-intelekt-balgariya-vse-osthe-nyama-nadzor-nad-visokoriskovite-sistemi/",
       "date": "2026-01-09",
       "publisherClass": "news"
      },
      {
       "title": "Нов Закон за използването и развитието на изкуствения интелект (novini247)",
       "url": "https://novini247.com/novini/nov-zakon-za-izpolzvaneto-i-razvitieto-na-izkustveniya-intelekt-e_11238882.html",
       "date": "2026-09-26",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "EU-wide data protection law, in force since 24 May 2016 and applying since 25 May 2018.",
     "url": "https://commission.europa.eu/law/law-topic/data-protection/data-protection-eu_en"
    },
    {
     "name": "Health Act (Закон за здравето)",
     "level": "National",
     "year": "2004",
     "what": "Right to copies; creates the national health information system; consent needed for third-party access since 2024.",
     "url": "https://asp.government.bg/uploaded/files/7032-zakon-za-zdraveto-28032025.pdf"
    },
    {
     "name": "Ordinance N-6 of 21 December 2022 on the National Health Information System",
     "level": "National",
     "year": "2022",
     "what": "Sets patient access, consent and withdrawal, access logging, emergency access and anonymised reuse.",
     "url": "https://dv.parliament.bg/DVWeb/showMaterialDV.jsp?idMat=182160"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Access and restriction rights, opt-out from secondary use; main rules apply from March 2029.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "AI Act (EU) 2024/1689",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk-based AI rules; duties for AI in medical devices apply from 2 August 2028.",
     "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
    }
   ],
   "dti": {
    "grade": 88,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2024-10-23",
     "headline": "Health fund sanctions providers after patients spot unperformed care in their records",
     "paraphrase": "Insured people using the eZdrave app found medical activities in their electronic records that had never been carried out. After checks, the national health fund imposed fines, partly ended contracts and recovered money paid.",
     "source": "zdrave.net",
     "url": "https://www.zdrave.net/%D0%9D%D0%BE%D0%B2%D0%B8%D0%BD%D0%B8/%D0%A1%D0%B0%D0%BD%D0%BA%D1%86%D0%B8%D0%B8-%D0%B7%D0%B0-%D0%BE%D1%82%D1%87%D0%B5%D1%82%D0%B5%D0%BD%D0%B8-%D0%BD%D0%B5%D0%B8%D0%B7%D0%B2%D1%8A%D1%80%D1%88%D0%B5%D0%BD%D0%B8-%D0%B4%D0%B5%D0%B9%D0%BD%D0%BE%D1%81%D1%82%D0%B8-%D0%BD%D0%B0%D0%BB%D0%BE%D0%B6%D0%B8-%D0%9D%D0%97%D0%9E%D0%9A-%D0%BF%D0%BE-%D1%81%D0%B8%D0%B3%D0%BD%D0%B0%D0%BB%D0%B8-%D0%BD%D0%B0-%D0%BF%D0%BE%D1%82%D1%80%D0%B5%D0%B1%D0%B8%D1%82%D0%B5%D0%BB%D0%B8-%D0%BD%D0%B0-%D0%B5%D0%97%D0%B4%D1%80%D0%B0%D0%B2%D0%B5-(%D0%9E%D0%B1%D0%BD%D0%BE%D0%B2%D0%B5%D0%BD%D0%B0)/n31819",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2026-09-03",
     "headline": "Patients flag 1,760 record entries they say never happened",
     "paraphrase": "A new eZdrave feature asks patients whether they attended each recorded visit. Within weeks they had sent 1,760 reports of exams, test results and hospital stays they did not recognise, and 560 checks had begun.",
     "source": "Gospodari.com",
     "url": "https://gospodari.com/novini/nov-modul-v-ezdrave-pokazva-dali-na-vashe-ime-sa-otcheteni-fiktivni-medicinski-deynosti",
     "theme": "record_wrong",
     "status": "alleged"
    },
    {
     "date": "2026-09-25",
     "headline": "Complaints about wrong entries in electronic health records rise by two thirds",
     "paraphrase": "Complaints that electronic records list care patients never received rose 68.75 percent in July and August 2026 over a year earlier. The health fund links the rise to wider use of the eZdrave app.",
     "source": "Paragraf.bg",
     "url": "https://paragraf.bg/za-1-g-zhalbite-za-nesaotvetstviya-mezhdu-otrazeni-v-dosieto-i-polzvanite-meditsinski-uslugi-sa-68-75-poveche",
     "theme": "record_wrong",
     "status": "alleged"
    },
    {
     "date": "2026-01-25",
     "headline": "Regulator fined a hospital for revealing a patient's health details on television",
     "paraphrase": "A patient went on television saying her discharge record listed a procedure she never had. A hospital director responded on air with her health details. The data protection commission fined the hospital 10,000 leva, rejecting its consent argument.",
     "source": "Dnes Bulgaria",
     "url": "https://dnesbulgaria.com/%D0%BA%D0%B7%D0%BB%D0%B4-%D0%B3%D0%BB%D0%BE%D0%B1%D0%B8-%D0%B1%D0%BE%D0%BB%D0%BD%D0%B8%D1%86%D0%B0-%D1%81%D1%8A%D1%80%D1%86%D0%B5-%D0%B8-%D0%BC%D0%BE%D0%B7%D1%8A%D0%BA-%D0%B2-%D0%B1%D1%83%D1%80/",
     "theme": "sold_or_shared",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "LUX",
   "name": "Luxembourg",
   "region": "Europe",
   "overall": 59,
   "rank": "27=",
   "likelyRank": "19 to 34",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Every insured person gets a shared record with an access log and blocking tools, but few patients activate it and the EU says access lags.",
   "categories": {
    "access": {
     "score": 64,
     "summary": "The 2014 patient rights law gives a right to a full copy within 15 working days, and a national shared record holds lab, imaging and discharge reports. Patients activate only about 3,257 accounts a month, and the EU rates record access as lagging.",
     "sources": [
      {
       "title": "Loi du 24 juillet 2014 relative aux droits et obligations du patient (Journal officiel)",
       "url": "https://data.legilux.public.lu/file/eli-etat-leg-loi-2014-07-24-n2-jo-fr-html.html",
       "date": "2014-07-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Activation du compte eSanté pour accéder au Dossier de Soins Partagé (Guichet.lu)",
       "url": "https://guichet.public.lu/fr/citoyens/sante/droits-devoirs-patient/droits-devoirs-patient/dsp.html",
       "date": "2026-05-26",
       "publisherClass": "official"
      },
      {
       "title": "Luxembourg's 2026 Digital Decade Country Report (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/factpages/luxembourgs-2026-digital-decade-country-report",
       "date": "2026-08-28",
       "publisherClass": "intergov"
      },
      {
       "title": "Santé numérique : l'année de l'accélération pour l'Agence eSanté (Le Quotidien)",
       "url": "https://lequotidien.lu/politique-societe/sante-numerique-lannee-de-lacceleration-pour-lagence-esante/",
       "date": "2026-07-07",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 70,
     "summary": "The patient can oppose sharing at any time, close the record, block named professionals or mask data, and see a log of every access. The record is created by default, and the referring doctor cannot be blocked.",
     "sources": [
      {
       "title": "Règlement grand-ducal du 6 décembre 2019, dossier de soins partagé (Journal officiel)",
       "url": "https://data.legilux.public.lu/filestore/eli/etat/leg/rgd/2019/12/06/a909/jo/fr/html/eli-etat-leg-rgd-2019-12-06-a909-jo-fr-html.html",
       "date": "2019-12-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Code de la sécurité sociale, Art. 60quater (SECU)",
       "url": "https://www.secu.lu/assurance-maladie/livre-i/chapitre-v-relations-avec-les-prestataires-de-soins/art-60quater/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Activation du compte eSanté pour accéder au Dossier de Soins Partagé (Guichet.lu)",
       "url": "https://guichet.public.lu/fr/citoyens/sante/droits-devoirs-patient/droits-devoirs-patient/dsp.html",
       "date": "2026-05-26",
       "publisherClass": "official"
      },
      {
       "title": "Accès facile au Dossier de soins partagé via MyGuichet.lu (Ministère de la Santé et de la Sécurité sociale)",
       "url": "https://m3s.gouvernement.lu/fr/actualites.gouvernement2024%2Bfr%2Bactualites%2Btoutes_actualites%2Bcommuniques%2B2025%2B12-decembre%2B01-dsp-myguichet.html",
       "date": "2025-12-01",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 54,
     "summary": "Luxembourg applies the GDPR through its law of 1 August 2018, but the regulator's published decisions we reviewed show no health-sector case. An August 2026 attack on an IT provider cut at least 80 medical practices off from patient files.",
     "sources": [
      {
       "title": "Loi du 1er août 2018 portant organisation de la CNPD (Journal officiel)",
       "url": "https://data.legilux.public.lu/file/eli-etat-leg-loi-2018-08-01-a686-jo-fr-html.html",
       "date": "2018-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Décisions (CNPD)",
       "url": "https://cnpd.public.lu/fr/decisions-sanctions.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Au Luxembourg: 80 cabinets médicaux auraient été touchés par une cyberattaque (L'essentiel)",
       "url": "https://www.lessentiel.lu/fr/story/au-luxembourg-80-cabinets-medicaux-auraient-ete-touches-par-une-cyberattaque-103629329",
       "date": "2026-09-07",
       "publisherClass": "news"
      },
      {
       "title": "Exclusif: Une cyberattaque qui fait paniquer les médecins (Reporter.lu)",
       "url": "https://www.reporter.lu/fr/exclusif-sante-digitale-une-cyberattaque-qui-fait-paniquer-les-medecins/",
       "date": "2026-09-07",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 54,
     "summary": "One national record collects hospital, lab and imaging documents, and professionals must upload useful data. National e-prescription use was not verified, and the EU tells Luxembourg to speed up its record rollout.",
     "sources": [
      {
       "title": "Règlement grand-ducal du 6 décembre 2019, dossier de soins partagé (Journal officiel)",
       "url": "https://data.legilux.public.lu/filestore/eli/etat/leg/rgd/2019/12/06/a909/jo/fr/html/eli-etat-leg-rgd-2019-12-06-a909-jo-fr-html.html",
       "date": "2019-12-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Patient Information Notices: Luxembourg (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/digital-health-and-care/electronic-cross-border-health-services/patient-information-notices-luxembourg_en",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "Luxembourg's 2026 Digital Decade Country Report (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/factpages/luxembourgs-2026-digital-decade-country-report",
       "date": "2026-08-28",
       "publisherClass": "intergov"
      },
      {
       "title": "Santé numérique : l'année de l'accélération pour l'Agence eSanté (Le Quotidien)",
       "url": "https://lequotidien.lu/politique-societe/sante-numerique-lannee-de-lacceleration-pour-lagence-esante/",
       "date": "2026-07-07",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 54,
     "summary": "National law bans processing genetic data for employment and insurance purposes, and only anonymised shared-record data may leave care for statistics. No Luxembourg ban on selling health data or on health advertising was verified, so the score stays low in its band.",
     "sources": [
      {
       "title": "Loi du 1er août 2018 portant organisation de la CNPD (Journal officiel)",
       "url": "https://data.legilux.public.lu/file/eli-etat-leg-loi-2018-08-01-a686-jo-fr-html.html",
       "date": "2018-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Code de la sécurité sociale, Art. 60quater (SECU)",
       "url": "https://www.secu.lu/assurance-maladie/livre-i/chapitre-v-relations-avec-les-prestataires-de-soins/art-60quater/",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 56,
     "summary": "Treating professionals can open the shared record within a profession-based access matrix, unless the patient blocks them. Professionals opened only 34,129 documents a month in 2025, so clinical use is still small.",
     "sources": [
      {
       "title": "Code de la sécurité sociale, Art. 60quater (SECU)",
       "url": "https://www.secu.lu/assurance-maladie/livre-i/chapitre-v-relations-avec-les-prestataires-de-soins/art-60quater/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "DSP (Dossier de Soins Partagé) (Agence eSanté)",
       "url": "https://www.esante.lu/portal/en/e-sant-information/services-esante-pour-les-patients-406-574.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Santé numérique : l'année de l'accélération pour l'Agence eSanté (Le Quotidien)",
       "url": "https://lequotidien.lu/politique-societe/sante-numerique-lannee-de-lacceleration-pour-lagence-esante/",
       "date": "2026-07-07",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 46,
     "summary": "Trials need ministry approval after ethics committee review, and the data law requires pseudonymisation or similar safeguards for research. No general opt-out from secondary use exists yet, and the EHDS access body is still being prepared.",
     "sources": [
      {
       "title": "Statuts / Législation (Comité National d'Ethique de Recherche)",
       "url": "https://cner.gouvernement.lu/fr/statuts-legislation.html",
       "date": "2025-11-05",
       "publisherClass": "official"
      },
      {
       "title": "Project HDAB-LU (LNDS)",
       "url": "https://www.lnds.lu/hdab-lu/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Loi du 1er août 2018 portant organisation de la CNPD (Journal officiel)",
       "url": "https://data.legilux.public.lu/file/eli-etat-leg-loi-2018-08-01-a686-jo-fr-html.html",
       "date": "2018-08-01",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device law and the EU AI Act only. Bill 8476, which would name national AI Act authorities, was still in committee after a State Council opinion of 10 July 2026.",
     "sources": [
      {
       "title": "Dossier parlementaire 8476 (Chambre des Députés)",
       "url": "https://www.chd.lu/fr/dossier/8476",
       "date": "2026-07-10",
       "publisherClass": "official"
      },
      {
       "title": "L'AI Act en action (CNPD)",
       "url": "https://cnpd.public.lu/fr/actualites/national/2026/01/ai-act-in-action-cp-jan2026.html",
       "date": "2026-01-20",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Loi du 24 juillet 2014 relative aux droits et obligations du patient",
     "level": "National",
     "year": "2014",
     "what": "Right to a patient file and a copy within 15 working days, at copying cost; ten-year retention.",
     "url": "https://data.legilux.public.lu/file/eli-etat-leg-loi-2014-07-24-n2-jo-fr-html.html"
    },
    {
     "name": "Code de la sécurité sociale, Article 60quater (dossier de soins partagé)",
     "level": "National",
     "year": "2010",
     "what": "Creates the shared record; rights to access, see who accessed, and oppose sharing at any time.",
     "url": "https://www.secu.lu/assurance-maladie/livre-i/chapitre-v-relations-avec-les-prestataires-de-soins/art-60quater/"
    },
    {
     "name": "Règlement grand-ducal du 6 décembre 2019 (dossier de soins partagé)",
     "level": "National",
     "year": "2019",
     "what": "Access matrix, patient blocking and masking levels, full access logs, ten-year retention.",
     "url": "https://data.legilux.public.lu/filestore/eli/etat/leg/rgd/2019/12/06/a909/jo/fr/html/eli-etat-leg-rgd-2019-12-06-a909-jo-fr-html.html"
    },
    {
     "name": "Loi du 1er août 2018 portant organisation de la CNPD",
     "level": "National",
     "year": "2018",
     "what": "Implements the GDPR, sets up the CNPD, research safeguards, bans genetic data use in employment and insurance.",
     "url": "https://data.legilux.public.lu/file/eli-etat-leg-loi-2018-08-01-a686-jo-fr-html.html"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health data is a special category; access right, breach notification, fines up to 4% of turnover.",
     "url": "https://commission.europa.eu/law/law-topic/data-protection/legal-framework-eu-data-protection_en"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient summaries and e-prescriptions exchanged from March 2029, images, labs, discharge reports from 2031; secondary use rules.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "EU AI Act (EU) 2024/1689, amended by the 2026 AI Omnibus",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk-based AI rules; high-risk duties for AI in medical devices apply from 2 August 2028.",
     "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai"
    }
   ],
   "dti": {
    "grade": 89,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-09-09",
     "headline": "Cyberattack on an IT firm serving doctors hit 40 medical practices",
     "paraphrase": "An IT company serving medical practices said a cyberattack affected 40 practices. It filed a police complaint, notified the data protection authority and said experts found no data leak. Services were later restored.",
     "source": "Le Quotidien",
     "url": "https://lequotidien.lu/a-la-une/cyberattaque-dans-des-cabinets-medicaux-40-etablissements-en-ont-ete-victimes/",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "MLT",
   "name": "Malta",
   "region": "Europe",
   "overall": 59,
   "rank": "27=",
   "likelyRank": "18 to 33",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Malta's myHealth portal shows most public-sector records online, but private clinics, hospitals and prescribers are still largely outside the national record.",
   "categories": {
    "access": {
     "score": 72,
     "summary": "Malta scored 93.71 on the EU's 2024 record-access indicator against an EU average of 82.7. myHealth shows public hospital summaries, labs, imaging reports, prescriptions and vaccines, but the Commission found no private-sector data and no mobile app.",
     "sources": [
      {
       "title": "Digital Decade 2025 country report, Malta (European Commission, Council doc 10407/25 ADD 51)",
       "url": "https://data.consilium.europa.eu/doc/document/ST-10407-2025-ADD-51/en/pdf",
       "date": "2025-06-16",
       "publisherClass": "intergov"
      },
      {
       "title": "myHealth (Ministry for Health, archived 1 Aug 2026)",
       "url": "https://web.archive.org/web/20260801073650/https://health.gov.mt/public-facing-services/myhealth/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Digital Health and Health Data Strategy 2030 (Ministry for Health and Active Ageing)",
       "url": "https://web.archive.org/web/20260727061320/https://health.gov.mt/wp-content/uploads/2025/11/Digital-Health-Health-Data-Strategy-Document.pdf",
       "date": "2025-11",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 50,
     "summary": "Patients choose which doctors can see their myHealth data and can remove a link at any time, and they set cross-border consent country by country. No patient-visible access log was found; the 2030 strategy only promises a way to see who contributes to records.",
     "sources": [
      {
       "title": "myHealth User Guide for Patients v2.2 (Information Management Unit)",
       "url": "https://web.archive.org/web/20250712071632/https://health.gov.mt/wp-content/uploads/2024/10/myHealth-User-Guide-for-Patients-v.2.2-19Aug19.pdf",
       "date": "2019-08-19",
       "publisherClass": "official"
      },
      {
       "title": "myHealth: About, disclaimer and privacy policy (archived 1 Aug 2026)",
       "url": "https://web.archive.org/web/20260801073639/https://myhealth.gov.mt/home/about",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Digital Health and Health Data Strategy 2030 (Ministry for Health and Active Ageing)",
       "url": "https://web.archive.org/web/20260727061320/https://health.gov.mt/wp-content/uploads/2025/11/Digital-Health-Health-Data-Strategy-Document.pdf",
       "date": "2025-11",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 62,
     "summary": "GDPR and the Data Protection Act (Cap. 586) apply, and the IDPC has acted on health cases, including a EUR 20,000 fine on a private clinic in April 2025. No major Maltese health-system breach was found for 2025 to 2026.",
     "sources": [
      {
       "title": "The Commissioner imposed an administrative fine of EUR 20,000 on a private clinic (IDPC)",
       "url": "https://idpc.org.mt/news-latest/the-commissioner-imposed-an-administrative-fine-of-e20000-on-a-private-clinic/",
       "date": "2025-04-07",
       "publisherClass": "official"
      },
      {
       "title": "Decisions (Information and Data Protection Commissioner)",
       "url": "https://idpc.org.mt/decisions/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Data Protection Act, Cap. 586 (Legislation Malta)",
       "url": "https://legislation.mt/eli/cap/586/eng",
       "date": "2023-09-19",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 60,
     "summary": "Public hospitals, health centres, public nursing homes and POYC pharmacy data flow to one portal. Private hospitals and private GPs are not connected, and most private-sector prescribing is still on paper.",
     "sources": [
      {
       "title": "Digital Decade 2025 country report, Malta (European Commission, Council doc 10407/25 ADD 51)",
       "url": "https://data.consilium.europa.eu/doc/document/ST-10407-2025-ADD-51/en/pdf",
       "date": "2025-06-16",
       "publisherClass": "intergov"
      },
      {
       "title": "Digital Health and Health Data Strategy 2030 (Ministry for Health and Active Ageing)",
       "url": "https://web.archive.org/web/20260727061320/https://health.gov.mt/wp-content/uploads/2025/11/Digital-Health-Health-Data-Strategy-Document.pdf",
       "date": "2025-11",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 58,
     "summary": "Malta's health secondary-use regulations list permitted purposes and require GDPR consent for anything else, which limits resale. There is no specific ban on selling health data or on health-based advertising.",
     "sources": [
      {
       "title": "S.L. 528.10 Processing of Personal Data (Secondary Processing) (Health Sector) Regulations",
       "url": "https://legislation.mt/eli/sl/528.10/eng",
       "date": "2019-10-08",
       "publisherClass": "legal_text"
      },
      {
       "title": "myHealth: About, disclaimer and privacy policy (archived 1 Aug 2026)",
       "url": "https://web.archive.org/web/20260801073639/https://myhealth.gov.mt/home/about",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Decisions (Information and Data Protection Commissioner)",
       "url": "https://idpc.org.mt/decisions/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 56,
     "summary": "A family doctor the patient has linked in myHealth can see Government hospital summaries, labs, imaging and prescriptions. Records held by private hospitals and clinics are not shared, so the view is public-sector only.",
     "sources": [
      {
       "title": "myHealth (Ministry for Health, archived 1 Aug 2026)",
       "url": "https://web.archive.org/web/20260801073650/https://health.gov.mt/public-facing-services/myhealth/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Digital Health and Health Data Strategy 2030 (Ministry for Health and Active Ageing)",
       "url": "https://web.archive.org/web/20260727061320/https://health.gov.mt/wp-content/uploads/2025/11/Digital-Health-Health-Data-Strategy-Document.pdf",
       "date": "2025-11",
       "publisherClass": "official"
      },
      {
       "title": "myHealth User Guide for Patients v2.2 (Information Management Unit)",
       "url": "https://web.archive.org/web/20250712071632/https://health.gov.mt/wp-content/uploads/2024/10/myHealth-User-Guide-for-Patients-v.2.2-19Aug19.pdf",
       "date": "2019-08-19",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 48,
     "summary": "Research use of health records needs public interest, ethics approval and prior IDPC authorisation, with pseudonymised data where possible. There is no individual consent or general opt-out.",
     "sources": [
      {
       "title": "S.L. 528.10 Processing of Personal Data (Secondary Processing) (Health Sector) Regulations",
       "url": "https://legislation.mt/eli/sl/528.10/eng",
       "date": "2019-10-08",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Health and Health Data Strategy 2030 (Ministry for Health and Active Ageing)",
       "url": "https://web.archive.org/web/20260727061320/https://health.gov.mt/wp-content/uploads/2025/11/Digital-Health-Health-Data-Strategy-Document.pdf",
       "date": "2025-11",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (EHDS) (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI is governed by EU device law and the AI Act. Malta added L.N. 226 of 2025, naming the MDIA as lead AI market surveillance authority with fines up to EUR 350,000 or 1% of turnover.",
     "sources": [
      {
       "title": "L.N. 226 of 2025, Artificial Intelligence Regulations, 2025 (Legislation Malta)",
       "url": "https://legislation.mt/eli/ln/2025/226/eng",
       "date": "2025-10-10",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Health and Health Data Strategy 2030 (Ministry for Health and Active Ageing)",
       "url": "https://web.archive.org/web/20260727061320/https://health.gov.mt/wp-content/uploads/2025/11/Digital-Health-Health-Data-Strategy-Document.pdf",
       "date": "2025-11",
       "publisherClass": "official"
      },
      {
       "title": "Digital Omnibus on AI has been published (Cuatrecasas)",
       "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published",
       "date": "2026-07",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Data Protection Act (Cap. 586)",
     "level": "National",
     "year": "2018",
     "what": "Malta's GDPR implementing law; the IDPC supervises and decides complaints.",
     "url": "https://legislation.mt/eli/cap/586/eng"
    },
    {
     "name": "Processing of Personal Data (Secondary Processing) (Health Sector) Regulations (S.L. 528.10)",
     "level": "National",
     "year": "2019",
     "what": "Lists permitted secondary uses; research needs ethics approval and IDPC authorisation; other uses need consent.",
     "url": "https://legislation.mt/eli/sl/528.10/eng"
    },
    {
     "name": "Artificial Intelligence Regulations, 2025 (L.N. 226 of 2025)",
     "level": "National",
     "year": "2025",
     "what": "Names MDIA as AI Act market surveillance authority; fines up to EUR 350,000 or 1% of turnover.",
     "url": "https://legislation.mt/eli/ln/2025/226/eng"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient access, access logs, restriction rights and secondary-use opt-out, applying mainly from March 2029 and 2031.",
     "url": "https://eur-lex.europa.eu/eli/reg/2025/327/oj/eng"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health data is a special category; right of access, breach notification, fines up to 4% of turnover.",
     "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
    },
    {
     "name": "EU AI Act (EU) 2024/1689, amended by (EU) 2026/1744",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk rules for AI; obligations for AI in medical devices now apply from 2 August 2028.",
     "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng"
    }
   ],
   "dti": {
    "grade": 86,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2025-04-30",
     "headline": "Health provider employee opened a patient's record for personal reasons, regulator finds",
     "paraphrase": "A staff member with no role in the patient's care opened their record for personal reasons. The regulator found the access unauthorised. The provider had dismissed the employee and told the patient, so no further action followed.",
     "source": "Information and Data Protection Commissioner (Malta)",
     "url": "https://idpc.org.mt/wp-content/uploads/2025/05/0547_001.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-04-02",
     "headline": "Clinic kept a wrong address after repeated requests and posted health reports there",
     "paraphrase": "A private provider filled in a patient's file with an address taken from the electoral register, years out of date. Despite repeated requests it did not correct it, and medical reports reached the current occupants. Fines totalled €20,000.",
     "source": "Information and Data Protection Commissioner (Malta)",
     "url": "https://idpc.org.mt/wp-content/uploads/2025/04/0476_001.pdf",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-03-14",
     "headline": "Court protects patient's complaint that a former doctor kept reading her records",
     "paraphrase": "A patient complained to the data protection regulator that a doctor kept accessing her medical records after she left his care. He sued her for libel. A court dismissed the suit, ruling her complaints were privileged.",
     "source": "Newsbook",
     "url": "https://newsbook.com.mt/ginekologu-jitlef-libell-fuq-talbiet-ta-access-ghall-informazzjoni-minn-eks-pazjenta/",
     "theme": "breach",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "POL",
   "name": "Poland",
   "region": "Europe",
   "overall": 59,
   "rank": "27=",
   "likelyRank": "19 to 34",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Over 20 million Poles can see prescriptions, visits and documents in a national patient account and control specialist access, but 2026 vendor leaks hit millions.",
   "categories": {
    "access": {
     "score": 70,
     "summary": "The law gives a right to records and a free first copy, and the national patient account (IKP) shows prescriptions, referrals, visit history, NFZ payments and uploaded documents to 53% of citizens. An EC study finds lab results, discharge reports and images only partly available.",
     "sources": [
      {
       "title": "Ustawa o prawach pacjenta i Rzeczniku Praw Pacjenta, tekst jednolity Dz.U. 2024 poz. 581 (Sejm ELI)",
       "url": "https://api.sejm.gov.pl/eli/acts/DU/2024/581/text.pdf",
       "date": "2024-04-02",
       "publisherClass": "legal_text"
      },
      {
       "title": "O IKP (pacjent.gov.pl, Ministerstwo Zdrowia i NFZ)",
       "url": "https://pacjent.gov.pl/internetowe-konto-pacjenta",
       "date": "2019-09-06",
       "publisherClass": "official"
      },
      {
       "title": "Czy Twoi pacjenci korzystaja z IKP? (ezdrowie.gov.pl, Centrum e-Zdrowia)",
       "url": "https://www.ezdrowie.gov.pl/portal/artykul/czy-twoi-pacjenci-korzystaja-z-ikp-ulatwia-to-prace-lekarzom",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "2026 Digital Decade eHealth Indicator Study, final report (European Commission)",
       "url": "https://op.europa.eu/en/publication-detail/-/publication/7de84d62-66d1-11f1-9b18-01aa75ed71a1/language-en",
       "date": "2026-06-15",
       "publisherClass": "intergov"
      }
     ]
    },
    "control": {
     "score": 55,
     "summary": "Outside a few groups named in law, a clinician can see a patient's records only with consent given in the IKP or mojeIKP, limited in scope and time and revocable. Patients cannot block their family doctor, the record's author or emergency staff.",
     "sources": [
      {
       "title": "Ustawa o systemie informacji w ochronie zdrowia, tekst jednolity Dz.U. 2026 poz. 208 (Sejm ELI)",
       "url": "https://api.sejm.gov.pl/eli/acts/DU/2026/208/text.pdf",
       "date": "2026-02-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Twoje dane medyczne to Twoja wlasnosc (pacjent.gov.pl)",
       "url": "https://pacjent.gov.pl/aktualnosc/twoje-dane-medyczne-twoja-wlasnosc",
       "date": "2025-03-10",
       "publisherClass": "official"
      },
      {
       "title": "O IKP (pacjent.gov.pl, Ministerstwo Zdrowia i NFZ)",
       "url": "https://pacjent.gov.pl/internetowe-konto-pacjenta",
       "date": "2019-09-06",
       "publisherClass": "official"
      },
      {
       "title": "Kto ogladal nasze dane medyczne? Nocne wizyty na koncie pacjenta (Gazeta Prawna)",
       "url": "https://www.gazetaprawna.pl/biznes/zdrowie/artykuly/11153064,kto-ogladal-nasze-dane-medyczne-nocne-wizyty-na-koncie-pacjenta.html",
       "date": "2023-09-21",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 46,
     "summary": "Health data has special GDPR protection and the regulator is active, but UODO says the 2026 leak at software firm MyDr affects 19 million people, and a second attack on Medyc software may reach 5 million. Fines on public bodies are capped at 100,000 zloty.",
     "sources": [
      {
       "title": "Po nowym wycieku danych medycznych PUODO zapowiada kontrole (UODO)",
       "url": "https://uodo.gov.pl/pl/138/4585",
       "date": "2026-09-25",
       "publisherClass": "official"
      },
      {
       "title": "Dodatkowe kontrole UODO w podmiotach sektora ochrony zdrowia (UODO)",
       "url": "https://uodo.gov.pl/pl/138/4570",
       "date": "2026-09-16",
       "publisherClass": "official"
      },
      {
       "title": "Niepowiadomienie o blednym wyslaniu dokumentu: kara 40 tys. zl dla Gyncentrum (UODO)",
       "url": "https://uodo.gov.pl/pl/138/3933",
       "date": "2025-10-27",
       "publisherClass": "official"
      },
      {
       "title": "Ustawa o ochronie danych osobowych, tekst jednolity Dz.U. 2019 poz. 1781 (Sejm ELI)",
       "url": "https://api.sejm.gov.pl/eli/acts/DU/2019/1781/text.pdf",
       "date": "2019-08-30",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 70,
     "summary": "One national platform, P1, links e-prescriptions, e-referrals, medical events and NFZ claims, and the EC counts nearly all provider types as connected. Some document types still arrive late or not at all, and central booking is being made compulsory specialty by specialty.",
     "sources": [
      {
       "title": "Ustawa o systemie informacji w ochronie zdrowia, tekst jednolity Dz.U. 2026 poz. 208 (Sejm ELI)",
       "url": "https://api.sejm.gov.pl/eli/acts/DU/2026/208/text.pdf",
       "date": "2026-02-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Czy Twoi pacjenci korzystaja z IKP? (ezdrowie.gov.pl, Centrum e-Zdrowia)",
       "url": "https://www.ezdrowie.gov.pl/portal/artykul/czy-twoi-pacjenci-korzystaja-z-ikp-ulatwia-to-prace-lekarzom",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "2026 Digital Decade eHealth Indicator Study, final report (European Commission)",
       "url": "https://op.europa.eu/en/publication-detail/-/publication/7de84d62-66d1-11f1-9b18-01aa75ed71a1/language-en",
       "date": "2026-06-15",
       "publisherClass": "intergov"
      },
      {
       "title": "Od 1 sierpnia centralna e-rejestracja rozszerza sie o kolejne swiadczenia (ezdrowie.gov.pl)",
       "url": "https://www.ezdrowie.gov.pl/portal/artykul/od-1-sierpnia-centralna-e-rejestracja-rozszerza-sie-o-kolejne-swiadczenia",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 54,
     "summary": "Only the GDPR's general rules limit commercial use of health data, and no Polish ban on selling or advertising with it was found. In September 2026 UODO asked the pharmacy inspector whether data-sharing modules in over 4,000 pharmacies sent patient data to drug wholesalers.",
     "sources": [
      {
       "title": "Pismo Prezesa UODO do Glownego Inspektora Farmaceutycznego, DKN.5101.480.2026 (UODO)",
       "url": "https://uodo.gov.pl/pl/file/8051",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ponad 900 milionow zlotych kar dla hurtowni farmaceutycznych (UOKiK)",
       "url": "https://uokik.gov.pl/mniej-konkurencji-za-to-wiecej-do-zaplaty-za-leki-w-aptece-ponad-900-milionow-zlotych-kar-dla-hurtowni-farmaceutycznych",
       "date": "2026-09-21",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (EHDS) (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "clinical": {
     "score": 60,
     "summary": "Family doctors, the record's author, the same facility, cancer and cardiac network teams and emergency staff can see the shared record without asking. Other specialists need the patient's consent, and lab and discharge documents are only partly in the system.",
     "sources": [
      {
       "title": "Ustawa o systemie informacji w ochronie zdrowia, tekst jednolity Dz.U. 2026 poz. 208 (Sejm ELI)",
       "url": "https://api.sejm.gov.pl/eli/acts/DU/2026/208/text.pdf",
       "date": "2026-02-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Twoje dane medyczne to Twoja wlasnosc (pacjent.gov.pl)",
       "url": "https://pacjent.gov.pl/aktualnosc/twoje-dane-medyczne-twoja-wlasnosc",
       "date": "2025-03-10",
       "publisherClass": "official"
      },
      {
       "title": "Twoja dokumentacja medyczna w mojeIKP (pacjent.gov.pl)",
       "url": "https://pacjent.gov.pl/aktualnosc/twoja-dokumentacja-medyczna-w-mojeikp",
       "date": "2026-03-11",
       "publisherClass": "official"
      },
      {
       "title": "2026 Digital Decade eHealth Indicator Study, final report (European Commission)",
       "url": "https://op.europa.eu/en/publication-detail/-/publication/7de84d62-66d1-11f1-9b18-01aa75ed71a1/language-en",
       "date": "2026-06-15",
       "publisherClass": "intergov"
      }
     ]
    },
    "research": {
     "score": 46,
     "summary": "Records and registry data may go to researchers only in a form that cannot identify the patient, with no consent and no opt-out. UODO says national law lacks adequate rules for research use, and Poland has not yet set up the EU health data access body.",
     "sources": [
      {
       "title": "Ustawa o systemie informacji w ochronie zdrowia, tekst jednolity Dz.U. 2026 poz. 208 (Sejm ELI)",
       "url": "https://api.sejm.gov.pl/eli/acts/DU/2026/208/text.pdf",
       "date": "2026-02-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Wystapienie Prezesa UODO do Ministra Zdrowia i Ministra Nauki, DPNT.413.39.2025 (UODO)",
       "url": "https://uodo.gov.pl/pl/file/6426",
       "date": "2025-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Wdrozenie EHDS w Polsce i rola Ministerstwa Zdrowia (MZ Departament e-Zdrowia, via UODO)",
       "url": "https://uodo.gov.pl/pl/file/7458",
       "date": "2026-03-25",
       "publisherClass": "official"
      },
      {
       "title": "Ustawa o badaniach klinicznych produktow leczniczych stosowanych u ludzi, Dz.U. 2023 poz. 605 (Sejm ELI)",
       "url": "https://api.sejm.gov.pl/eli/acts/DU/2023/605/text.pdf",
       "date": "2023-03-09",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 54,
     "summary": "Clinical AI falls under EU device law and the AI Act, and Poland's AI Systems Act of 2026 mainly names the regulator. One verified national addition: since January 2025 the medical ethics code lets doctors use AI only with patient consent and certified tools.",
     "sources": [
      {
       "title": "Ustawa z dnia 3 lipca 2026 r. o systemach sztucznej inteligencji, Dz.U. 2026 poz. 1003 (Sejm ELI)",
       "url": "https://api.sejm.gov.pl/eli/acts/DU/2026/1003/text.pdf",
       "date": "2026-07-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Nowelizacja Kodeksu Etyki Lekarskiej, tekst z art. 12 (Naczelna Izba Lekarska)",
       "url": "https://nil.org.pl/izba/krajowy-zjazd-lekarzy/nadzwyczajny-xvi-krajowy-zjazd-lekarzy/8487-nowelizacja-kodeksu-etyki-lekarskiej-kamien-milowy-dla-srodowiska-lekarskiego",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ustawa o izbach lekarskich, tekst jednolity Dz.U. 2021 poz. 1342 (Sejm ELI)",
       "url": "https://api.sejm.gov.pl/eli/acts/DU/2021/1342/text.pdf",
       "date": "2021-06-25",
       "publisherClass": "legal_text"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Act on Patient Rights and the Patient Rights Ombudsman",
     "level": "National",
     "year": "2008",
     "what": "Right to records in paper or electronic form; free first copy; research use only without identifying data.",
     "url": "https://api.sejm.gov.pl/eli/acts/DU/2024/581/text.pdf"
    },
    {
     "name": "Act on the Health Care Information System",
     "level": "National",
     "year": "2011",
     "what": "Creates P1 and the IKP; mandatory electronic records; sets who may access records without consent.",
     "url": "https://api.sejm.gov.pl/eli/acts/DU/2026/208/text.pdf"
    },
    {
     "name": "Act on Personal Data Protection",
     "level": "National",
     "year": "2018",
     "what": "Polish GDPR implementing act; caps fines on public finance sector units at 100,000 zloty.",
     "url": "https://api.sejm.gov.pl/eli/acts/DU/2019/1781/text.pdf"
    },
    {
     "name": "Act on Clinical Trials of Medicinal Products for Human Use",
     "level": "National",
     "year": "2023",
     "what": "Sets trial ethics review, with the national bioethics committee at the Medical Research Agency.",
     "url": "https://api.sejm.gov.pl/eli/acts/DU/2023/605/text.pdf"
    },
    {
     "name": "Act on Artificial Intelligence Systems",
     "level": "National",
     "year": "2026",
     "what": "Names the national AI Act regulator, sets complaints, sandboxes and fines; in force 11 August 2026.",
     "url": "https://api.sejm.gov.pl/eli/acts/DU/2026/1003/text.pdf"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health is special-category data; right of access within one month; fines up to 4% of turnover.",
     "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Access, restriction and secondary-use opt-out rights; bans marketing use; key parts apply from 2029.",
     "url": "https://eur-lex.europa.eu/eli/reg/2025/327/oj/eng"
    }
   ],
   "dti": {
    "grade": 88,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-06-24",
     "headline": "Court backs ombudsman: closed clinic's records must still be released to patients",
     "paraphrase": "After a medical practice closed, the former partner holding its records stopped releasing them to patients during a dispute with the other partner. The ombudsman ordered the practice to stop, and an administrative court rejected the appeal.",
     "source": "Rzecznik Praw Pacjenta (Patient Rights Ombudsman)",
     "url": "https://www.gov.pl/web/rpp/sad-potwierdzil-obowiazek-udostepniania-dokumentacji-medycznej-po-zakonczeniu-dzialalnosci-podmiotu-leczniczego",
     "theme": "lost_between_providers",
     "status": "finding"
    },
    {
     "date": "2025-09-02",
     "headline": "Doctor reprimanded for leaving patient cards readable in a parked car",
     "paraphrase": "A patient saw patient record cards in a clear box on the front seat of a doctor's parked car, with one card's name, address, birth date and ID number readable. The regulator reprimanded the doctor and ordered the patient notified.",
     "source": "Urząd Ochrony Danych Osobowych (UODO)",
     "url": "https://orzeczenia.uodo.gov.pl/document/urn:ndoc:gov:pl:uodo:2025:dkn_5131_6/content",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2024-12-16",
     "headline": "Hospital fined after a patient was handed another person's medical records",
     "paraphrase": "A patient received someone else's medical records, including name, birth date, national ID number and health data. The hospital did not report the breach or tell the affected person in time. The regulator fined it 29,648 zloty.",
     "source": "Urząd Ochrony Danych Osobowych (UODO)",
     "url": "https://uodo.gov.pl/pl/138/3475",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-09-25",
     "headline": "Clinic software flaw exposed patient ID numbers and hospital discharge papers",
     "paraphrase": "Attackers used a flaw in practice software used by hundreds of clinics to take names, national ID numbers, contacts and discharge documents. It went unnoticed for over two weeks. The vendor said it fixed the flaw and forced password changes.",
     "source": "Wprost",
     "url": "https://biznes.wprost.pl/innowacje/12452412/tym-razem-medyc-znow-doszlo-do-poteznego-wycieku-danych-medycznych-polakow.html",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2025-05-09",
     "headline": "National patient portal flaw let a user open other people's medical documents",
     "paraphrase": "A user found that changing a web address in the national patient account showed other patients' documents, with names, national ID numbers, ID card numbers and health data. The ministry confirmed the flaw but would not name the facility.",
     "source": "CyberDefence24",
     "url": "https://cyberdefence24.pl/cyberbezpieczenstwo/blad-w-ikp-mozna-bylo-uzyskac-dokumentacje-pacjentow",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "GBR",
   "name": "United Kingdom",
   "region": "Europe",
   "overall": 59,
   "rank": "27=",
   "likelyRank": "17 to 32",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "In England, 39 million are registered on the NHS App and can opt out of the Summary Care Record, but not the Palantir-built data platform.",
   "categories": {
    "access": {
     "score": 66,
     "summary": "UK GDPR gives a free copy of the record within one month, and 39.1 million people are registered on the NHS App. But the app shows only new GP record entries, not historic or hospital records; a single patient record is promised from 2028.",
     "sources": [
      {
       "title": "Right of access: health information (ICO)",
       "url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/health-information/",
       "date": "2025-12-08",
       "publisherClass": "official"
      },
      {
       "title": "NHS App Management Information, August 2026 (NHS England Digital)",
       "url": "https://digital.nhs.uk/data-and-information/publications/statistical/nhs-app-statistics/august-2026",
       "date": "2026-09-25",
       "publisherClass": "official"
      },
      {
       "title": "Online access to new GP health record information (NHS England)",
       "url": "https://www.england.nhs.uk/long-read/online-access-to-new-gp-health-record-information/",
       "date": "2023-11-01",
       "publisherClass": "official"
      },
      {
       "title": "Health Bill: single patient record fact sheet (GOV.UK, DHSC)",
       "url": "https://www.gov.uk/government/publications/health-bill-single-patient-record-fact-sheet/health-bill-single-patient-record-fact-sheet",
       "date": "2026-05-19",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 52,
     "summary": "Patients can opt out of the national Summary Care Record, and staff must ask permission before viewing it outside emergencies. But there is no opt-out from the Palantir-built Federated Data Platform, and access logs are available only by formal request.",
     "sources": [
      {
       "title": "Summary Care Records (SCR): information for patients (NHS England Digital)",
       "url": "https://digital.nhs.uk/services/summary-care-records-scr/summary-care-records-scr-information-for-patients",
       "date": "2025-05-28",
       "publisherClass": "official"
      },
      {
       "title": "Information Governance Framework: Shared Care Records (NHS England Digital)",
       "url": "https://digital.nhs.uk/data-and-information/information-governance/guidance/information-governance-framework-shared-care-records",
       "date": "2026-05-21",
       "publisherClass": "official"
      },
      {
       "title": "Opt out of sharing your health records (NHS website)",
       "url": "https://www.nhs.uk/using-the-nhs/about-the-nhs/opt-out-of-sharing-your-health-records/",
       "date": "2024-06-06",
       "publisherClass": "official"
      },
      {
       "title": "NHS patients can't opt out of Palantir's data platform, but their hospital can (The Register)",
       "url": "https://www.theregister.com/databases/2026/06/13/nhs-patients-cant-opt-out-of-palantirs-data-platform-but-their-hospital-can/5254766",
       "date": "2026-06-13",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 56,
     "summary": "Health data is protected by UK GDPR and an active regulator that fined an NHS IT supplier 3.07 million pounds. But NHS England admitted its platform impact assessment was wrong, and UK Biobank data on 500,000 people was offered for sale in April 2026.",
     "sources": [
      {
       "title": "Advanced Computer Software Group Limited, monetary penalty (ICO)",
       "url": "https://ico.org.uk/action-weve-taken/enforcement/2025/03/advanced-computer-software-group-limited/",
       "date": "2025-03-26",
       "publisherClass": "official"
      },
      {
       "title": "National Data Guardian statement on NHS Federated Data Platform data access (GOV.UK)",
       "url": "https://www.gov.uk/government/news/national-data-guardian-statement-on-nhs-federated-data-platform-data-access-in-response-to-the-not-with-my-nhs-data-campaign",
       "date": "2026-06-03",
       "publisherClass": "official"
      },
      {
       "title": "UK Biobank health data listed for sale in China, government confirms (BBC News)",
       "url": "https://www.bbc.co.uk/news/articles/cpvxgl3n138o",
       "date": "2026-04-23",
       "publisherClass": "news"
      },
      {
       "title": "Receiving personal information from the EEA: UK adequacy (ICO)",
       "url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/receiving-personal-information-from-the-eea/",
       "date": "2026-01-15",
       "publisherClass": "official"
      }
     ]
    },
    "journey": {
     "score": 62,
     "summary": "Over 95% of prescriptions in England are electronic, and a national Summary Care Record is drawn from GP records at 98% of practices. Hospitals connect through regional shared care records that, the government says, do not link nationally.",
     "sources": [
      {
       "title": "Electronic Prescription Service (NHS England Digital)",
       "url": "https://digital.nhs.uk/services/electronic-prescription-service",
       "date": "2026-09-18",
       "publisherClass": "official"
      },
      {
       "title": "Summary Care Record (SCR) service page (NHS England Digital)",
       "url": "https://digital.nhs.uk/services/summary-care-records-scr",
       "date": "2026-08-27",
       "publisherClass": "official"
      },
      {
       "title": "Health Bill: single patient record fact sheet (GOV.UK, DHSC)",
       "url": "https://www.gov.uk/government/publications/health-bill-single-patient-record-fact-sheet/health-bill-single-patient-record-fact-sheet",
       "date": "2026-05-19",
       "publisherClass": "official"
      },
      {
       "title": "NHS Federated Data Platform uptake and benefits (NHS England)",
       "url": "https://www.england.nhs.uk/digitaltechnology/nhs-federated-data-platform/solution-exchange/fdp-uptake-and-benefits/",
       "date": "2026-09-25",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 60,
     "summary": "The law lets NHS England release patient data only for health care or the promotion of health, and NHS policy bars disclosure for marketing or insurance without explicit consent. A private US firm built the national data platform under a contract worth up to 330 million pounds.",
     "sources": [
      {
       "title": "Health and Social Care Act 2012, section 261 (legislation.gov.uk)",
       "url": "https://www.legislation.gov.uk/ukpga/2012/7/section/261",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Understanding the national data opt-out (NHS England Digital)",
       "url": "https://digital.nhs.uk/services/national-data-opt-out/understanding-the-national-data-opt-out",
       "date": "2023-05-16",
       "publisherClass": "official"
      },
      {
       "title": "Opt out of sharing your health records (NHS website)",
       "url": "https://www.nhs.uk/using-the-nhs/about-the-nhs/opt-out-of-sharing-your-health-records/",
       "date": "2024-06-06",
       "publisherClass": "official"
      },
      {
       "title": "Palantir should not have significant role in NHS and other public services, say MPs (BMJ)",
       "url": "https://www.bmj.com/content/393/bmj-2026-035692",
       "date": "2026-06-04",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 60,
     "summary": "Any authorised clinician in England can view the national Summary Care Record of medicines and allergies, used by about 129,000 staff a month. A fuller cross-provider view depends on which regional shared care record covers the patient.",
     "sources": [
      {
       "title": "Summary Care Record (SCR) service page (NHS England Digital)",
       "url": "https://digital.nhs.uk/services/summary-care-records-scr",
       "date": "2026-08-27",
       "publisherClass": "official"
      },
      {
       "title": "Summary Care Records (SCR): information for patients (NHS England Digital)",
       "url": "https://digital.nhs.uk/services/summary-care-records-scr/summary-care-records-scr-information-for-patients",
       "date": "2025-05-28",
       "publisherClass": "official"
      },
      {
       "title": "The single patient record explained (The King's Fund)",
       "url": "https://www.kingsfund.org.uk/insight-and-analysis/long-reads/the-single-patient-record-explained-what-could-it-mean-for-patients-and-the-health-and-care-system",
       "date": "2026-08-04",
       "publisherClass": "academic"
      },
      {
       "title": "Health Bill: single patient record fact sheet (GOV.UK, DHSC)",
       "url": "https://www.gov.uk/government/publications/health-bill-single-patient-record-fact-sheet/health-bill-single-patient-record-fact-sheet",
       "date": "2026-05-19",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 64,
     "summary": "Patients can block use of their confidential data for research and planning through the national data opt-out, used by 5.69% in July 2026. Exemptions cover public health, legal duties and data NHS England is directed to collect.",
     "sources": [
      {
       "title": "Understanding the national data opt-out (NHS England Digital)",
       "url": "https://digital.nhs.uk/services/national-data-opt-out/understanding-the-national-data-opt-out",
       "date": "2023-05-16",
       "publisherClass": "official"
      },
      {
       "title": "Opt out of sharing your health records (NHS website)",
       "url": "https://www.nhs.uk/using-the-nhs/about-the-nhs/opt-out-of-sharing-your-health-records/",
       "date": "2024-06-06",
       "publisherClass": "official"
      },
      {
       "title": "Using patient data for research: challenges and policy developments (House of Lords Library)",
       "url": "https://lordslibrary.parliament.uk/using-patient-data-for-research-challenges-and-policy-developments/",
       "date": "2026-08-04",
       "publisherClass": "official"
      },
      {
       "title": "Launch of clinical trial reforms (MHRA and HRA, GOV.UK)",
       "url": "https://www.gov.uk/government/news/launch-of-clinical-trial-reforms",
       "date": "2026-04-27",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 55,
     "summary": "AI medical devices fall under the UK Medical Devices Regulations 2002, with new post-market surveillance duties in force since June 2025. Change control plans rest on 2023 guiding principles, and the national AI commission asked the MHRA to clarify them.",
     "sources": [
      {
       "title": "Medical Devices (Post-market Surveillance Requirements) (Amendment) (Great Britain) Regulations 2024, S.I. 2024/1368",
       "url": "https://www.legislation.gov.uk/uksi/2024/1368/made",
       "date": "2024-12-16",
       "publisherClass": "legal_text"
      },
      {
       "title": "Predetermined change control plans for machine learning-enabled medical devices: guiding principles (MHRA, FDA, Health Canada)",
       "url": "https://www.gov.uk/government/publications/predetermined-change-control-plans-for-machine-learning-enabled-medical-devices-guiding-principles/predetermined-change-control-plans-for-machine-learning-enabled-medical-devices-guiding-principles",
       "date": "2023-10-24",
       "publisherClass": "official"
      },
      {
       "title": "National Commission into the Regulation of AI in Healthcare: recommendations for a future regulatory framework (GOV.UK)",
       "url": "https://www.gov.uk/government/publications/national-commission-into-the-regulation-of-ai-in-healthcare-recommendations-for-a-future-regulatory-framework/national-commission-into-the-regulation-of-ai-in-healthcare-recommendations-for-a-future-regulatory-framework",
       "date": "2026-09-10",
       "publisherClass": "official"
      },
      {
       "title": "Advancing AI regulation in healthcare: insights from AI Airlock phase 2 (MHRA MedRegs blog)",
       "url": "https://medregs.blog.gov.uk/2026/06/09/advancing-ai-regulation-in-healthcare-insights-from-ai-airlock-phase-2/",
       "date": "2026-06-09",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "UK GDPR and Data Protection Act 2018",
     "level": "National",
     "year": "2018",
     "what": "Health is special category data; free access copy, usually within one month; ICO enforcement.",
     "url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/right-of-access/health-information/"
    },
    {
     "name": "Data (Use and Access) Act 2025",
     "level": "National",
     "year": "2025",
     "what": "Amends UK data protection, replaces the ICO with an Information Commission, sets binding health IT standards (s.121).",
     "url": "https://www.legislation.gov.uk/ukpga/2025/18/contents"
    },
    {
     "name": "Health and Social Care Act 2012, s.261",
     "level": "National",
     "year": "2012",
     "what": "NHS England may release collected data only for health care, social care or promotion of health.",
     "url": "https://www.legislation.gov.uk/ukpga/2012/7/section/261"
    },
    {
     "name": "Health Service (Control of Patient Information) Regulations 2002 (NHS Act 2006, s.251)",
     "level": "National",
     "year": "2002",
     "what": "Lets confidential patient data be used without consent on CAG approval; national opt-out then applies.",
     "url": "https://www.legislation.gov.uk/uksi/2002/1438/contents/made"
    },
    {
     "name": "Medical Devices Regulations 2002, as amended by S.I. 2024/1368",
     "level": "National",
     "year": "2024",
     "what": "Device rules covering AI software; post-market surveillance duties in force from June 2025.",
     "url": "https://www.legislation.gov.uk/uksi/2024/1368/made"
    },
    {
     "name": "Health Bill (single patient record), before Parliament",
     "level": "National",
     "year": "2026",
     "what": "Would create a national single patient record viewable in the NHS App; no new opt-out.",
     "url": "https://www.gov.uk/government/publications/health-bill-single-patient-record-fact-sheet/health-bill-single-patient-record-fact-sheet"
    }
   ],
   "dti": {
    "grade": 90,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-12-16",
     "headline": "GP surgery sent 23 years of records to an insurer that asked for five",
     "paraphrase": "An insurer asked for five years of records, to go to the patient first for review. The surgery emailed 23 years straight to the insurer. The patient said their payout was cut. The ICO issued a reprimand.",
     "source": "Information Commissioner's Office",
     "url": "https://ico.org.uk/action-weve-taken/enforcement/2025/12/staines-health-group/",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-03-27",
     "headline": "Regulator fines NHS software supplier after hackers took data on 79,404 people",
     "paraphrase": "Hackers entered a supplier's health systems through an account without multi-factor authentication. Data on 79,404 people was taken, including how to enter the homes of 890 people receiving care at home. The ICO fined the supplier £3.07m.",
     "source": "Information Commissioner's Office",
     "url": "https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/03/software-provider-fined-3m-following-2022-ransomware-attack/",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2024-12-13",
     "headline": "Hospital trust missed the legal deadline on nearly a third of access requests",
     "paraphrase": "Over a year, a large hospital trust failed to answer 32% of people's requests for their own personal data within one month. It could not say how many requests were in its backlog. The ICO issued a reprimand.",
     "source": "Information Commissioner's Office",
     "url": "https://ico.org.uk/action-weve-taken/enforcement/2024/12/united-lincolnshire-teaching-hospitals-nhs-trust/",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2025-05-02",
     "headline": "Nearly one in four adults in England found errors in their medical records",
     "paraphrase": "A survey of 1,800 adults for the patient watchdog found 23% had noticed mistakes or gaps in their NHS records, including wrong personal details, wrong medication and conditions they never had. Most said the errors caused problems.",
     "source": "Pharmacy Business",
     "url": "https://www.pharmacy.biz/errors-medical-records-healthwatch-england/",
     "theme": "record_wrong",
     "status": "self_reported"
    },
    {
     "date": "2026-05-27",
     "headline": "Whistleblower says new hospital record system loses referrals and patient information",
     "paraphrase": "A clinician at a London hospital trust said its new electronic record system sent referrals to the wrong place, held missing or unreliable information and left patients lost to follow-up. The trust said the rollout caused a number of issues.",
     "source": "LBC",
     "url": "https://www.lbc.co.uk/article/nhs-east-london-whistleblower-it-system-patients-5HjdZgg_2/",
     "theme": "lost_between_providers",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "SVK",
   "name": "Slovakia",
   "region": "Europe",
   "overall": 58,
   "rank": "32",
   "likelyRank": "25 to 36",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Slovaks can read a national e-health record and see every access, but cannot opt out of clinician sharing, and login needs a chip ID card.",
   "categories": {
    "access": {
     "score": 62,
     "summary": "The law gives patients the right to see their whole record without delay, and the national electronic health book (EZK) is online through the National Health Portal. Login needs a chip ID card with an activated e-signature, minors cannot log in, and usage figures were not verified.",
     "sources": [
      {
       "title": "Zakon c. 576/2004 Z. z. o zdravotnej starostlivosti, section 25 (Slov-Lex, version from 1 Aug 2026)",
       "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2004/576/",
       "date": "2026-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Zakon c. 153/2013 Z. z. o narodnom zdravotnickom informacnom systeme (Slov-Lex, version from 1 Aug 2026)",
       "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2013/153/",
       "date": "2026-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Pristup do elektronickej zdravotnej knizky (NCZI, ezdravotnictvo.sk)",
       "url": "https://www.ezdravotnictvo.sk/en/-/pristup-do-elektronickej-zdravotnej-knizky",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 50,
     "summary": "Patients can see who opened their EZK, when and in what role, and can grant and withdraw extra access. Providers share records without consent by law, and we found no general opt-out from clinician access.",
     "sources": [
      {
       "title": "Zakon c. 153/2013 Z. z., sections 5 and 5a (Slov-Lex)",
       "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2013/153/",
       "date": "2026-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Zakon c. 576/2004 Z. z., section 18 (Slov-Lex)",
       "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2004/576/",
       "date": "2026-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Pristup do elektronickej zdravotnej knizky (NCZI)",
       "url": "https://www.ezdravotnictvo.sk/en/-/pristup-do-elektronickej-zdravotnej-knizky",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Mozem ako pacient zakazat pristup do svojej zdravotnej dokumentacie? (nahradaskody.sk)",
       "url": "https://www.nahradaskody.sk/clanky/zdravotna-dokumentacia/mozem-ako-pacient-zakazat-pristup-do-svojej-zdravotnej-dokumentacie/",
       "date": "2024-10-23",
       "publisherClass": "law_firm"
      }
     ]
    },
    "privacy": {
     "score": 58,
     "summary": "GDPR and Act 18/2018 apply. NCZI may not give EZK data to police, but providers must give record extracts to criminal authorities and courts on written request, and the regulator imposed 542 fines totalling EUR 468,000 in 2025.",
     "sources": [
      {
       "title": "Sprava o stave ochrany osobnych udajov za rok 2025 (UOOU)",
       "url": "https://dataprotection.gov.sk/files/annual-reports/uoou_sprava-stave-ochrany-osobnych-udajov_2025.pdf",
       "date": "2026",
       "publisherClass": "official"
      },
      {
       "title": "CEF 2026: spolocna dozorova akcia EDPB zamerana na transparentnost informovania (UOOU)",
       "url": "https://dataprotection.gov.sk/sk/aktuality/cef-2026-spolocna-dozorova-akcia-edpb-zamerana-transparentnost-informovania-do-ktorej-urad-ochranu-osobnych-udajov-sl.html",
       "date": "2026-03-19",
       "publisherClass": "official"
      },
      {
       "title": "Zakon c. 153/2013 Z. z., section 3a (Slov-Lex)",
       "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2013/153/",
       "date": "2026-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Zakon c. 576/2004 Z. z., section 24 (Slov-Lex)",
       "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2004/576/",
       "date": "2026-08-01",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 66,
     "summary": "The national ezdravie system links 14,400 outpatient clinics, 129 hospitals, 2,193 pharmacies and all 3 health insurers. Electronic lab results (2.5 million in 2025) are still rolling out, and Slovakia is not yet on the EU MyHealth@EU network.",
     "sources": [
      {
       "title": "Vyrocna sprava NCZI 2025",
       "url": "https://www.nczisk.sk/Documents/download/vyrocna_sprava_NCZI_2025.pdf",
       "date": "2026",
       "publisherClass": "official"
      },
      {
       "title": "Zmena pravidiel vo vykazovani zdravotnej starostlivosti od 1. jula 2026 (NCZI)",
       "url": "https://www.nczisk.sk/AKTUALITY/Pages/Zmena-pravidiel-vo-vykazovani-zdravotnej-starostlivosti-od-1-jula-2026.aspx",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "eSluzby: funkcie elektronickeho zdravotnictva (NCZI)",
       "url": "https://www.ezdravotnictvo.sk/en/functions",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 58,
     "summary": "GDPR limits commercial use of identifiable health data, and the EU health data space will ban marketing uses of reused data. Act 153/2013 lets NCZI release anonymised data to anyone on request, and no Slovak ban on selling health data was verified.",
     "sources": [
      {
       "title": "Regulation (EU) 2016/679 (GDPR)",
       "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
       "date": "2016-04-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Zakon c. 153/2013 Z. z., section 3a (Slov-Lex)",
       "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2013/153/",
       "date": "2026-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 60,
     "summary": "The patient's registered GP sees most of the EZK, other treating doctors see parts via referral or the patient's ID card, and any health worker can see the emergency patient summary. Records outside ezdravie, such as paper reports, remain with each provider.",
     "sources": [
      {
       "title": "Zakon c. 153/2013 Z. z., sections 5, 5a and 6 (Slov-Lex)",
       "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2013/153/",
       "date": "2026-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Vyrocna sprava NCZI 2025",
       "url": "https://www.nczisk.sk/Documents/download/vyrocna_sprava_NCZI_2025.pdf",
       "date": "2026",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 45,
     "summary": "NCZI gives researchers modified statistical data under written contract, with no individual consent and no general opt-out found. A Slovak health data access body for the EHDS is still being built.",
     "sources": [
      {
       "title": "Zakon c. 153/2013 Z. z., section 3a and annexes (Slov-Lex)",
       "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2013/153/",
       "date": "2026-08-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Vyrocna sprava NCZI 2025",
       "url": "https://www.nczisk.sk/Documents/download/vyrocna_sprava_NCZI_2025.pdf",
       "date": "2026",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under the EU AI Act and EU device rules only. A Slovak bill naming the ministry MIRRI as AI supervisor advanced in parliament in September 2026 and would apply from 1 January 2027, so it adds no points yet.",
     "sources": [
      {
       "title": "AI Act: regulatory framework for AI (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai",
       "date": "2026-08-03",
       "publisherClass": "official"
      },
      {
       "title": "Dohlad nad umelou inteligenciou preberie MIRRI (Zoznam, openiazoch)",
       "url": "https://openiazoch.zoznam.sk/technologie/dohlad-nad-umelou-inteligenciou-preberie-mirri-poslanci-posunuli-zakon-dalej/",
       "date": "2026-09-17",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Act No. 153/2013 on the National Health Information System",
     "level": "National",
     "year": "2013",
     "what": "Creates the EZK, role-based access, patient access log, revocable consent and NCZI data release rules.",
     "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2013/153/"
    },
    {
     "name": "Act No. 576/2004 on Health Care",
     "level": "National",
     "year": "2004",
     "what": "Right to see the full record without delay; ban on relatives' access; no consent needed for lawful sharing.",
     "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2004/576/"
    },
    {
     "name": "Act No. 18/2018 on Personal Data Protection",
     "level": "National",
     "year": "2018",
     "what": "Supplements the GDPR in Slovakia and sets up the data protection office.",
     "url": "https://www.slov-lex.sk/ezbierky/pravne-predpisy/SK/ZZ/2018/18/"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health is special-category data; right of access; fines up to EUR 20M or 4% of turnover.",
     "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Free access, restriction rights and secondary-use opt-out; main rules apply from 2029.",
     "url": "https://eur-lex.europa.eu/eli/reg/2025/327/oj/eng"
    }
   ],
   "dti": {
    "grade": 90,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2025-04-30",
     "headline": "Patient waits over six months as former doctor holds records after a switch",
     "paraphrase": "A patient who changed general practitioner says the former doctor did not pass his records to the new one for over six months. Other former patients report the same, and a regional complaint is under review.",
     "source": "STVR Správy (Slovak public broadcaster)",
     "url": "https://spravy.stvr.sk/2025/04/pan-peter-ostal-bez-pristupu-k-svojej-zdravotnej-dokumentacii-lekar-na-jeho-ziadost-o-presun-zaznamov-nereaguje/",
     "theme": "lost_between_providers",
     "status": "alleged"
    },
    {
     "date": "2025-12-07",
     "headline": "Dentists say national eHealth record lacks dental charts and images",
     "paraphrase": "The dentists' chamber says dental charts and image files do not reach the national electronic record, so other doctors cannot see them. It warns patients may get duplicate prescriptions or repeat imaging as a result.",
     "source": "Pravda",
     "url": "https://www.pravda.sk/zdravie/zdravie-a-prevencia/clanok/777566-zubni-lekari-si-stazuju-ze-v-ezdravi-chybaju-dolezite-udaje-pre-diagnostiku-a-rozhodovanie-o-liecbe",
     "theme": "lost_between_providers",
     "status": "alleged"
    },
    {
     "date": "2025-01-25",
     "headline": "Cyberattack tried to take patient data from the main state health insurer",
     "paraphrase": "The government said attackers targeted the state health insurer seeking patients' personal and treatment data. The health minister said the attack was repelled, and the insurer stated policyholders' data were safe and had not leaked.",
     "source": "Bratislavak.sk",
     "url": "https://www.bratislavak.sk/clanky/5645/aktualizovane-kyberneticky-utok-na-vszp-sa-podarilo-odrazit-vyhlasil-sasko-k-uniku-dat-nedoslo",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "CZE",
   "name": "Czechia",
   "region": "Europe",
   "overall": 57,
   "rank": "33=",
   "likelyRank": "25 to 36",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Czechia added an opt-out shared record and the EZKarta app in 2026, but the record is still thin and research use needs no consent.",
   "categories": {
    "access": {
     "score": 60,
     "summary": "Patients have a legal right to copy their records, and the first copy has been free since 1 October 2024. The EZKarta app shows labs, prescriptions, vaccinations and some hospital documents, but it is still partial, with about 34,000 daily users.",
     "sources": [
      {
       "title": "Vykladove stanovisko k § 66 odst. 3 zakona o zdravotnich sluzbach (Ministerstvo zdravotnictvi)",
       "url": "https://mzd.gov.cz/wp-content/uploads/2024/11/Vykladove-stanovisko-k-ustanoveni-%C2%A7-66-odst.-3-zakona-o-zdravotnich-sluzbach-ve-zneni-zakona-c.-240-2024-Sb.pdf",
       "date": "2024-11",
       "publisherClass": "official"
      },
      {
       "title": "Ministerstvo zdravotnictvi spousti novou generaci EZKarty (MZ CR)",
       "url": "https://mzd.gov.cz/tiskove-centrum-mz/ministerstvo-zdravotnictvi-spousti-novou-generaci-ezkarty-pripomene-preventivni-vysetreni-a-zpristupni-dulezite-zdravotni-informace/",
       "date": "2026-09-03",
       "publisherClass": "official"
      },
      {
       "title": "Nova EZKarta zpristupni pacientum laboratorni vysledky (DigitalHealth.cz)",
       "url": "https://www.digitalhealth.cz/nova-ezkarta-laboratorni-vysledky-prevence/",
       "date": "2026-09-03",
       "publisherClass": "news"
      },
      {
       "title": "Zdravotnicka dokumentace (NZIP)",
       "url": "https://www.nzip.cz/clanek/1074-zdravotnicka-dokumentace",
       "date": "2024-01-31",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 64,
     "summary": "Clinicians can see the shared health record and the medication record unless the patient objects, and patients can allow named doctors only. The medication record shows patients who viewed it; an access log for the newer shared record was not verified.",
     "sources": [
      {
       "title": "Zakon c. 325/2021 Sb., o elektronizaci zdravotnictvi (zneni od 1. 4. 2026)",
       "url": "https://www.zakonyprolidi.cz/cs/2021-325",
       "date": "2026-04-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Vyjadreni souhlasu/nesouhlasu s nahlizenim na lekovy zaznam (Portal verejne spravy)",
       "url": "https://portal.gov.cz/sluzby-vs/vyjadreni-souhlasunesouhlasu-s-nahlizenim-na-lekovy-zaznam-S11085",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "System Sdileny zdravotni zaznam (NCEZ)",
       "url": "https://ncez.mzcr.cz/cs/node/5545",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Zabezpeceni lekoveho zaznamu (SUKL, epreskripce.gov.cz)",
       "url": "https://epreskripce.gov.cz/zabezpeceni-lekoveho-zaznamu/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 56,
     "summary": "GDPR and the 2019 Data Protection Act apply, but the regulator's 2025 fines went mostly to marketing cases and no health-sector fine was found. Czech law bars GDPR fines on public bodies, and a health database leaked in August 2026.",
     "sources": [
      {
       "title": "Vyrocni zprava UOOU za rok 2025",
       "url": "https://www.ochranaudaju.cz/aktuality/vyrocni-zprava-uoou-za-rok-2025",
       "date": "2026-03-20",
       "publisherClass": "official"
      },
      {
       "title": "Zakon c. 110/2019 Sb., o zpracovani osobnich udaju",
       "url": "https://www.zakonyprolidi.cz/cs/2019-110",
       "date": "2019-04-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kamery v nemocnicich maji sva pravidla (Zdravotnicky denik)",
       "url": "https://www.zdravotnickydenik.cz/2026/08/kamery-v-nemocnicich-maji-sva-pravidla-uoou-vymezil-kde-konci-ochrana-a-zacina-smirovani/",
       "date": "2026-08-18",
       "publisherClass": "news"
      },
      {
       "title": "Kyberneticke incidenty v CR v srpnu (Feedit)",
       "url": "https://feedit.cz/2026/09/14/kyberneticke-incidenty-v-cr-v-srpnu-ransomware-uderil-na-zdravotnictvi-vyrobu-i-it-sluzby-unikla-citliva-data-pacientu/",
       "date": "2026-09-14",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 55,
     "summary": "E-prescriptions have been mandatory since 2018 and feed a national medication record, but the shared hospital record covers just over 30 hospitals. E-referrals started on 2 January 2026 as a voluntary pilot.",
     "sources": [
      {
       "title": "O eReceptu (SUKL, epreskripce.gov.cz)",
       "url": "https://epreskripce.gov.cz/o-ereceptu/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Portal lekare a pacienta: spusteni novych digitalnich sluzeb (MZ CR)",
       "url": "https://mzd.gov.cz/tiskove-centrum-mz/spusteni-nove-digitalni-sluzby-portal-lekare-a-pacienta/",
       "date": "2025-12-31",
       "publisherClass": "official"
      },
      {
       "title": "Zakon c. 236/2025 Sb., novela zakona o elektronizaci zdravotnictvi",
       "url": "https://www.zakonyprolidi.cz/cs/2025-236",
       "date": "2025-06-12",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ministerstvo zdravotnictvi spousti novou generaci EZKarty (MZ CR)",
       "url": "https://mzd.gov.cz/tiskove-centrum-mz/ministerstvo-zdravotnictvi-spousti-novou-generaci-ezkarty-pripomene-preventivni-vysetreni-a-zpristupni-dulezite-zdravotni-informace/",
       "date": "2026-09-03",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 60,
     "summary": "GDPR requires an explicit legal basis for any commercial use of health data, and the EU health data space will bar reuse for marketing. No Czech law specific to health data brokers or consumer health apps was found.",
     "sources": [
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Vyrocni zprava UOOU za rok 2025",
       "url": "https://www.ochranaudaju.cz/aktuality/vyrocni-zprava-uoou-za-rok-2025",
       "date": "2026-03-20",
       "publisherClass": "official"
      },
      {
       "title": "Art. 83 GDPR (gdpr-info.eu)",
       "url": "https://gdpr-info.eu/art-83-gdpr/",
       "date": "undated",
       "publisherClass": "blog_vendor"
      }
     ]
    },
    "clinical": {
     "score": 52,
     "summary": "Any treating clinician can see the emergency record (blood type, allergies, drug reactions, 12 months of medicines) and the medication record unless the patient objects. Full notes from other providers are shared only by the 30-plus hospitals connected so far.",
     "sources": [
      {
       "title": "Zakon c. 325/2021 Sb., o elektronizaci zdravotnictvi (zneni od 1. 4. 2026)",
       "url": "https://www.zakonyprolidi.cz/cs/2021-325",
       "date": "2026-04-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "System Sdileny zdravotni zaznam (NCEZ)",
       "url": "https://ncez.mzcr.cz/cs/node/5545",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "O eReceptu (SUKL, epreskripce.gov.cz)",
       "url": "https://epreskripce.gov.cz/o-ereceptu/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 45,
     "summary": "National health registers collect data without consent and with no opt-out, a design the Constitutional Court upheld in 2020. Safeguards include non-public registers, access limited by law, and synthetic and aggregate data for researchers.",
     "sources": [
      {
       "title": "Vyhlaseni nalezu Ustavniho soudu sp. zn. Pl. US 33/16",
       "url": "https://www.usoud.cz/aktualne/vyhlaseni-nalezu-ustavniho-soudu-sp-zn-pl-us-33-16-dne-18-listopadu-2020-rozhodnuti-zverejnene-s-tiskovou-zpravou",
       "date": "2020-11-18",
       "publisherClass": "official"
      },
      {
       "title": "Zadosti o vystupy NZIS (UZIS CR)",
       "url": "https://www.uzis.cz/index.php?pg=kontakt--zadosti-vystupy-nzis",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under the EU AI Act and EU device rules only. A national AI law naming the telecoms office (CTU) as main supervisor was a draft in February 2026, and we did not verify that it has passed.",
     "sources": [
      {
       "title": "2. srpna 2026 jako klicove datum pro pravidla transparentnosti podle Aktu o AI (CTU)",
       "url": "https://ctu.gov.cz/tiskova-zprava-2.-srpna-2026-jako-klicove-datum-pro-pravidla-transparentnosti-podle-aktu-o-umele",
       "date": "2026-07-31",
       "publisherClass": "official"
      },
      {
       "title": "AI Act v praxi: cesky adaptacni zakon (LeitnerLaw)",
       "url": "https://www.leitnerlaw.cz/novinky/ai-act-v-praxi-cesky-adaptacni-zakon-vymezuje-kompetence-postupy-a-sankce/",
       "date": "2026-02-26",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health is special-category data; free first copy; fines up to EUR 20M or 4% of turnover.",
     "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
    },
    {
     "name": "Act 110/2019 Sb. on Personal Data Processing",
     "level": "National",
     "year": "2019",
     "what": "Czech GDPR implementing act; regulator refrains from fining public bodies under GDPR Art. 83(7).",
     "url": "https://www.zakonyprolidi.cz/cs/2019-110"
    },
    {
     "name": "Act 372/2011 Sb. on Health Services (as amended by Act 240/2024)",
     "level": "National",
     "year": "2011",
     "what": "Right to view and copy records; first copy free since 1 October 2024; basis for NZIS registers.",
     "url": "https://mzd.gov.cz/wp-content/uploads/2024/11/Vykladove-stanovisko-k-ustanoveni-%C2%A7-66-odst.-3-zakona-o-zdravotnich-sluzbach-ve-zneni-zakona-c.-240-2024-Sb.pdf"
    },
    {
     "name": "Act 325/2021 Sb. on the Electronisation of Healthcare",
     "level": "National",
     "year": "2021",
     "what": "Shared health record with patient objection, authorisation register, activity journal, EZKarta.",
     "url": "https://www.zakonyprolidi.cz/cs/2021-325"
    },
    {
     "name": "Act 236/2025 Sb. amending the eHealth Act",
     "level": "National",
     "year": "2025",
     "what": "Adds shared health record, eZadanka e-referrals and EZKarta; in force 1 January 2026.",
     "url": "https://www.zakonyprolidi.cz/cs/2025-236"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Free access, restriction rights, opt-out from secondary use, ban on marketing use; phased from 2027.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2025-07-18",
     "headline": "Court upholds fine on clinic that failed to report a patient data breach",
     "paraphrase": "A cyberattack left a private clinic's patient records unreachable for a week. The clinic, holding data on about 250,000 patients, did not report it in time and could not prove it told patients. The court confirmed a 309,000 crown fine.",
     "source": "oPojištění.cz (reporting a Supreme Administrative Court ruling of 21 May 2025)",
     "url": "https://www.opojisteni.cz/legislativa/zkontrolujte-si-proces-pro-rizeni-incidentu-jinak-vam-hrozi-pokuta/c:29468/",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-07-09",
     "headline": "Hospital warns patients a ransomware attack may have exposed their record data",
     "paraphrase": "After ransomware shut down its systems, a hospital told patients that personal data linked to their medical records may have been stolen. It could not yet confirm whether or how much was taken, and notified the data protection office.",
     "source": "ČT24 (Česká televize)",
     "url": "https://ct24.ceskatelevize.cz/clanek/domaci/pri-kyberutoku-na-nemocnici-nymburk-mohla-uniknout-data-pacientu-362785",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-09-14",
     "headline": "Hackers offer a Czech health facility's patient records for sale",
     "paraphrase": "A security firm reported that a hacking group stole a database from an unnamed Czech health facility and offered it for sale. It reportedly held patient contacts with health records, booking details with payment and insurance data, and staff profiles.",
     "source": "Aktuálně.cz",
     "url": "https://zpravy.aktualne.cz/ekonomika/hackeri-v-srpnu-odcizili-pacientska-data-zdravotnickeho-zarizeni-v-cesku/r~aaa29d5cab5ab9aa374fead6cec97e1a/",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2025-05-28",
     "headline": "Hospital lost control of a computer holding examination images of about 1,900 patients",
     "paraphrase": "A clinic computer storing images and data from nearly two thousand examinations disappeared for four days, then reappeared. The hospital's internal review called it a data incident, its director confirmed it, and it was reported to the data protection office.",
     "source": "Seznam Zprávy",
     "url": "https://www.seznamzpravy.cz/clanek/domaci-kauzy-intimni-snimky-pacientu-nic-se-nedeje-rika-exministr-o-zmizeni-pocitace-277656",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "GRC",
   "name": "Greece",
   "region": "Europe",
   "overall": 57,
   "rank": "33=",
   "likelyRank": "26 to 37",
   "band": "Mixed",
   "keysModel": "State",
   "confidence": "medium",
   "headline": "Greece put one national record in every patient's phone in 2025, but hospital archives are not yet digitised and per-doctor consent is unclear.",
   "categories": {
    "access": {
     "score": 66,
     "summary": "Since May 2025 the national record (EHFY) shows diagnoses, prescriptions, test results and hospital stays in the MyHealth app and citizen portal. The EC still ranks Greece below the EU average, with no imaging reports in its 2024 data.",
     "sources": [
      {
       "title": "Ο Εθνικός Ηλεκτρονικός Φάκελος Υγείας (EHFY overview)",
       "url": "https://ehealthrecord.gov.gr/ehfy-overview-details",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Commencement of the new digital platform for the National Electronic Health Record (NEHR)",
       "url": "https://www.ehealthrecord.gov.gr/en/press-releases/%CE%B7%CE%BC-%CE%B5%CE%B7%CF%86%CF%85-golive",
       "date": "2025-05",
       "publisherClass": "official"
      },
      {
       "title": "2025 Digital Decade eHealth indicator study (European Commission)",
       "url": "https://op.europa.eu/en/publication-detail/-/publication/bb5838fe-4742-11f0-85ba-01aa75ed71a1/language-en",
       "date": "2025",
       "publisherClass": "intergov"
      },
      {
       "title": "State of Health in the EU: Greece Country Health Profile 2025 (European Commission, OECD)",
       "url": "https://health.ec.europa.eu/document/download/b9b4092c-b357-4ae3-8d82-d9a252e7e159_en?filename=2025_chp_gr_english.pdf",
       "date": "2025",
       "publisherClass": "intergov"
      }
     ]
    },
    "control": {
     "score": 46,
     "summary": "Greek law logs every access to the record and lets the patient be told who looked and when. The 2019 law only requires that patients be informed of clinician access; a per-doctor consent or opt-out in the live platform is not verified.",
     "sources": [
      {
       "title": "Νόμος 4600/2019, Άρθρο 84: Ατομικός Ηλεκτρονικός Φάκελος Υγείας (Ministry of Health)",
       "url": "https://www.moh.gov.gr/articles/newspaper/nomothesia-kanonismoi/3246-nomothesia-hlektronikhs-ygeias?fdl=14732",
       "date": "2019-03-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ο Εθνικός Ηλεκτρονικός Φάκελος Υγείας (EHFY overview)",
       "url": "https://ehealthrecord.gov.gr/ehfy-overview-details",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 56,
     "summary": "The Data Protection Authority does act on hospital breaches, fining Thessaloniki's G. Gennimatas hospital 25,000 euros in September 2026 for posting 2,820 patients' diagnoses online. Fines are small and the case took two years.",
     "sources": [
      {
       "title": "Πρόστιμο 25.000 ευρώ στο νοσοκομείο Γ. Γεννηματάς στη Θεσσαλονίκη (To Pontiki)",
       "url": "https://www.topontiki.gr/2026/09/29/prostimo-25-000-evro-sto-nosokomio-g-gennimatas-sti-thessaloniki-gia-diarroi-prosopikon-stichion-2-820-asthenon/",
       "date": "2026-09-29",
       "publisherClass": "news"
      },
      {
       "title": "Δεδομένα υγείας: Συχνές ερωτήσεις (Αρχή Προστασίας Δεδομένων)",
       "url": "https://www.dpa.gr/el/enimerwtiko/thematikes_enotites/eidikeskatigories/dedomenaugeias/faq_dedomena_ugeias",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Νόμος 4600/2019, Άρθρο 84 (Ministry of Health)",
       "url": "https://www.moh.gov.gr/articles/newspaper/nomothesia-kanonismoi/3246-nomothesia-hlektronikhs-ygeias?fdl=14732",
       "date": "2019-03-09",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 62,
     "summary": "National e-prescription and e-referral, run by IDIKA since 2010, feed one record for public and private care. From 1 September 2026 EOPYY-contracted labs must upload results to be paid, but hospital archives remain undigitised.",
     "sources": [
      {
       "title": "Άρθρο 3, Νόμος 3892/2010 (Lawspot)",
       "url": "https://www.lawspot.gr/nomothesia/n3892-2010/arthro-3-nomos-3892-2010/",
       "date": "2010-11-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "Νόμος 4600/2019, Άρθρο 84 (Ministry of Health)",
       "url": "https://www.moh.gov.gr/articles/newspaper/nomothesia-kanonismoi/3246-nomothesia-hlektronikhs-ygeias?fdl=14732",
       "date": "2019-03-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Από τον Σεπτέμβριο οι απεικονιστικές εξετάσεις στο myHealth app (Iatronet)",
       "url": "https://www.iatronet.gr/article/142194/apo-ton-septemvrio-oi-apeikonistikes-exetaseis-sto-myhealth-app-leitoyrgia-kai-prosvash",
       "date": "2026-08-14",
       "publisherClass": "news"
      },
      {
       "title": "Άδωνις Γεωργιάδης: Αλλάζουν όλα στα νοσοκομεία και γίνονται ηλεκτρονικά μέχρι το καλοκαίρι του 2026 (Ethnos)",
       "url": "https://www.ethnos.gr/health/article/401035/adonisgeorgiadhsallazoynolastanosokomeiakaiginontaihlektronikamexritokalokairitoy2026",
       "date": "2026-03-11",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 62,
     "summary": "Law 4600/2019 bans employers, insurers and banks from using record data for other purposes, and the patient cannot waive that ban. The Ministry may still sell aggregate anonymised statistics, and a 2026 bill would open data to companies.",
     "sources": [
      {
       "title": "Νόμος 4600/2019, Άρθρο 84 (Ministry of Health)",
       "url": "https://www.moh.gov.gr/articles/newspaper/nomothesia-kanonismoi/3246-nomothesia-hlektronikhs-ygeias?fdl=14732",
       "date": "2019-03-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Η νέα πραγματικότητα της ψηφιακής υγείας: Ποιος θα έχει πρόσβαση στα δεδομένα (Iatropedia)",
       "url": "https://www.iatropedia.gr/eidiseis/i-nea-pragmatikotita-tis-psifiakis-ygeias-poios-tha-echei-prosvasi-sta-dedomena-ekatommyrion-asthenon-kai-me-poious-orous/227674/",
       "date": "2026-07-31",
       "publisherClass": "news"
      },
      {
       "title": "Εγκρίθηκε από το υπουργικό συμβούλιο το νομοσχέδιο για ελεύθερη πρόσβαση στα δεδομένα υγείας (Ethnos)",
       "url": "https://www.ethnos.gr/health/article/416159/egkrithhkeapotoypoyrgikosymboyliotonomosxediogiaeleytherhprosbashstadedomenaygeiastiallazei",
       "date": "2026-07-30",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 58,
     "summary": "Doctors in public and private care open a patient's national record through a dedicated portal, and emergency doctors can see it when a patient is unconscious. Older hospital records are still missing from it.",
     "sources": [
      {
       "title": "Commencement of the new digital platform for the National Electronic Health Record (NEHR)",
       "url": "https://www.ehealthrecord.gov.gr/en/press-releases/%CE%B7%CE%BC-%CE%B5%CE%B7%CF%86%CF%85-golive",
       "date": "2025-05",
       "publisherClass": "official"
      },
      {
       "title": "Ο Εθνικός Ηλεκτρονικός Φάκελος Υγείας (EHFY overview)",
       "url": "https://ehealthrecord.gov.gr/ehfy-overview-details",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Από τον Σεπτέμβριο οι απεικονιστικές εξετάσεις στο myHealth app (Iatronet)",
       "url": "https://www.iatronet.gr/article/142194/apo-ton-septemvrio-oi-apeikonistikes-exetaseis-sto-myhealth-app-leitoyrgia-kai-prosvash",
       "date": "2026-08-14",
       "publisherClass": "news"
      },
      {
       "title": "Άδωνις Γεωργιάδης: Αλλάζουν όλα στα νοσοκομεία και γίνονται ηλεκτρονικά μέχρι το καλοκαίρι του 2026 (Ethnos)",
       "url": "https://www.ethnos.gr/health/article/401035/adonisgeorgiadhsallazoynolastanosokomeiakaiginontaihlektronikamexritokalokairitoy2026",
       "date": "2026-03-11",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 44,
     "summary": "Today research uses anonymised or pseudonymised data with no individual consent and no general opt-out. A bill creating a Health Data Access Body with an EHDS opt-out passed cabinet in July 2026; its enactment is not verified.",
     "sources": [
      {
       "title": "Δεδομένα υγείας: Συχνές ερωτήσεις (Αρχή Προστασίας Δεδομένων)",
       "url": "https://www.dpa.gr/el/enimerwtiko/thematikes_enotites/eidikeskatigories/dedomenaugeias/faq_dedomena_ugeias",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Φορέας Πρόσβασης στα Δεδομένα Υγείας, GR-HDAB (Υπουργείο Υγείας)",
       "url": "https://www.moh.gov.gr/articles/ehealth/gr-hdab/14291-foreas-prosbashs-sta-dedomena-ygeias",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Νόμος 4600/2019, Άρθρο 84 (Ministry of Health)",
       "url": "https://www.moh.gov.gr/articles/newspaper/nomothesia-kanonismoi/3246-nomothesia-hlektronikhs-ygeias?fdl=14732",
       "date": "2019-03-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Εγκρίθηκε από το υπουργικό συμβούλιο το νομοσχέδιο για ελεύθερη πρόσβαση στα δεδομένα υγείας (Ethnos)",
       "url": "https://www.ethnos.gr/health/article/416159/egkrithhkeapotoypoyrgikosymboyliotonomosxediogiaeleytherhprosbashstadedomenaygeiastiallazei",
       "date": "2026-07-30",
       "publisherClass": "news"
      }
     ]
    },
    "ai": {
     "score": 54,
     "summary": "EU device law and the AI Act apply, and Greece adds Law 4961/2022, which makes public bodies, including public hospitals, assess and register AI systems before use. No health-specific AI rules or authority were verified.",
     "sources": [
      {
       "title": "Νόμος 4961/2022 (Lawspot)",
       "url": "https://www.lawspot.gr/nomothesia/nomos-4961-2022/",
       "date": "2022-07-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "MyHealth Agent: Διαθέσιμος ο Προσωπικός Βοηθός Υγείας Πολίτη (Lawspot)",
       "url": "https://www.lawspot.gr/nomika-nea/myhealth-agent-diathesimos-o-prosopikos-boethos-ugeias-polite-meso-tou-myhealth-app/",
       "date": "2025-12-12",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Law 4600/2019, Article 84 (Individual Electronic Health Record)",
     "level": "National",
     "year": "2019",
     "what": "Lifelong national record; access logging; patient told who accessed; non-waivable ban on employer, insurer, bank use.",
     "url": "https://www.moh.gov.gr/articles/newspaper/nomothesia-kanonismoi/3246-nomothesia-hlektronikhs-ygeias?fdl=14732"
    },
    {
     "name": "Law 3892/2010 (electronic prescriptions and referrals)",
     "level": "National",
     "year": "2010",
     "what": "Doctors must issue prescriptions and referrals electronically through the IDIKA system.",
     "url": "https://www.lawspot.gr/nomothesia/n3892-2010/arthro-3-nomos-3892-2010/"
    },
    {
     "name": "Law 3418/2005 (Code of Medical Ethics), Article 14",
     "level": "National",
     "year": "2005",
     "what": "Patient may see and copy their medical file; files kept 20 years after last visit.",
     "url": "https://www.dpa.gr/el/enimerwtiko/thematikes_enotites/eidikeskatigories/dedomenaugeias/faq_dedomena_ugeias"
    },
    {
     "name": "Law 4624/2019 (GDPR implementing law)",
     "level": "National",
     "year": "2019",
     "what": "Article 22(1) allows research processing of health data if pseudonymised or anonymised (DPA).",
     "url": "https://www.dpa.gr/el/enimerwtiko/thematikes_enotites/eidikeskatigories/dedomenaugeias/faq_dedomena_ugeias"
    },
    {
     "name": "Law 4961/2022 (emerging technologies, AI)",
     "level": "National",
     "year": "2022",
     "what": "Public bodies must assess, disclose and register AI systems before use.",
     "url": "https://www.lawspot.gr/nomothesia/nomos-4961-2022/"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Access logs and EU exchange from March 2029/2031; secondary-use permits and opt-out.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    }
   ],
   "dti": {
    "grade": 86,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-05-07",
     "headline": "Public hospital left its surgery waiting list, with patients' phone numbers, open online",
     "paraphrase": "A member of the public found, through a search engine, a hospital file listing about 2,820 patients' phone numbers and planned operations, online for months. The hospital reported late, never told patients, and was fined 25,000 euros.",
     "source": "Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 13/2026",
     "url": "https://www.dpa.gr/el/enimerwtiko/prakseisArxis/epiboli-prostimoy-se-nosokomeio-gia-mi-tirisi-tehnikon-kai-organotikon",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-04-09",
     "headline": "Private doctor looked up a patient's national health record without permission",
     "paraphrase": "A patient asked a private doctor for her full file and complained the doctor had also searched her electronic health record. The regulator found the lookup unlawful, done without her knowledge, and fined the doctor 5,000 euros.",
     "source": "Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 11/2025",
     "url": "https://www.dpa.gr/el/enimerwtiko/prakseisArxis/exetasi-kataggelias-gia-mi-pliri-ikanopoiisi-dikaiomatos-prosbasis",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2024-12-18",
     "headline": "Doctor kept patient's clinical photos online after she withdrew her consent",
     "paraphrase": "A patient complained that her doctor posted photos taken during her care on his social media page. The regulator ruled that keeping them up after she withdrew consent was unlawful and ordered his consent forms rewritten.",
     "source": "Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 50/2024",
     "url": "https://www.dpa.gr/el/enimerwtiko/prakseisArxis/exetasi-kataggelias-asthenoys-gia-parabiasi-dikaiomaton-ek-meroys-iatroy",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2024-10-11",
     "headline": "Hospital doctor running for parliament texted campaign messages to former patients",
     "paraphrase": "People who had been treated at a public hospital received election text messages from a doctor there who was a candidate. He could not show how he got their numbers; the regulator fined him 15,000 euros.",
     "source": "Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ), decision 37/2024",
     "url": "https://www.dpa.gr/el/enimerwtiko/prakseisArxis/epiboli-prostimoy-se-ypopsifio-boyleyti-iatro-dimosioy-nosokomeioy-gia",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-02-01",
     "headline": "Hospital said it could not supply copies of past scans after a cyberattack",
     "paraphrase": "A man asked a university hospital for copies of his wife's earlier test results. The hospital replied it had no access to its electronic system because of a cyberattack; the outlet reports other patients got the same answer.",
     "source": "in.gr",
     "url": "https://www.in.gr/2025/02/01/health/nosokomeio-axepa-anapantita-erotimata-gia-endexomeni-diarroi-eyaisthiton-prosopikon-dedomenon-asthenon/",
     "theme": "access_refused",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "JPN",
   "name": "Japan",
   "region": "Asia",
   "overall": 56,
   "rank": "35=",
   "likelyRank": "28 to 38",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Japanese patients see five years of claims-based records online and choose at each visit what doctors see, but full charts stay with each provider.",
   "categories": {
    "access": {
     "score": 62,
     "summary": "The privacy law gives a right to a copy, electronic on request, and Mynaportal shows five years of claims-based treatment and medicine data. The law sets no fixed deadline and allows fees, so full charts still come provider by provider.",
     "sources": [
      {
       "title": "Act on the Protection of Personal Information (Act No. 57 of 2003), e-Gov law text",
       "url": "https://laws.e-gov.go.jp/law/415AC0000000057",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "On the guideline for providing medical information: disclosure costs (MHLW notice)",
       "url": "https://www.mhlw.go.jp/web/t_doc?dataId=00tc3511&dataType=1&pageNo=1",
       "date": "2018-07-20",
       "publisherClass": "official"
      },
      {
       "title": "How many years of treatment and medicine data can be viewed? (Mynaportal FAQ 4902)",
       "url": "https://faq.myna.go.jp/faq/show/4902?category_id=107&site_domain=default",
       "date": "2026-05-12",
       "publisherClass": "official"
      },
      {
       "title": "Digital Agency at five years (Digital Agency)",
       "url": "https://www.digital.go.jp/policies/report-2026",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 62,
     "summary": "At each visit the patient chooses, item by item, whether the clinic may see past treatment, medicine and checkup data, and Mynaportal lists who received it. Hospital viewing without consent in emergencies, even for conscious patients, keeps the score low in its band.",
     "sources": [
      {
       "title": "Using the My Number card as a health insurance card (Digital Agency)",
       "url": "https://www.digital.go.jp/policies/mynumber/insurance-card",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Medical insurance information provision history (Mynaportal)",
       "url": "https://myna.go.jp/medical-info-sharing-histories",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Emergency medical information viewing: overview for hospitals (MHLW)",
       "url": "https://www.mhlw.go.jp/content/10200000/001243478.pdf",
       "date": "2026-06",
       "publisherClass": "official"
      },
      {
       "title": "Reference materials, 16th meeting of the review panel on use of medical information (Cabinet Office)",
       "url": "https://www8.cao.go.jp/iryou/studygloup/20260911/pdf/s-2.pdf",
       "date": "2026-09-11",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 58,
     "summary": "Medical history is 'special care-required' data, breaches must be reported, and the commission is independent by law. Most sensitive-data leaks come from hospitals and pharmacies, and the regulator cannot impose administrative fines until the 2026 surcharge takes effect.",
     "sources": [
      {
       "title": "Act on the Protection of Personal Information (Act No. 57 of 2003), e-Gov law text",
       "url": "https://laws.e-gov.go.jp/law/415AC0000000057",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Handling of breach reports, FY2025 Q3 (PPC)",
       "url": "https://www.ppc.go.jp/files/pdf/260311quarter-report_roueihoukoku.pdf",
       "date": "2026-03-11",
       "publisherClass": "official"
      },
      {
       "title": "Report on personal data leak from cyberattack, 2nd report (Nippon Medical School Musashi Kosugi Hospital)",
       "url": "https://www.nms.ac.jp/kosugi-h/news/_28832.html",
       "date": "2026-02-14",
       "publisherClass": "official"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 48,
     "summary": "Claims-based records reach providers through the My Number card, used in 68.15% of visits in April 2026, and 90.5% of pharmacies handle e-prescriptions. Only 29.5% of clinics and 20.9% of hospitals issue them, and the national EHR sharing service was still in model trials.",
     "sources": [
      {
       "title": "Smooth use of the My Number insurance card, Medical Insurance Subcommittee material 3 (MHLW)",
       "url": "https://www.mhlw.go.jp/content/12401000/001712851.pdf",
       "date": "2026-06-18",
       "publisherClass": "official"
      },
      {
       "title": "Progress of electronic prescriptions, Medical Insurance Subcommittee material 4 (MHLW)",
       "url": "https://www.mhlw.go.jp/content/12401000/001742903.pdf",
       "date": "2026-08-27",
       "publisherClass": "official"
      },
      {
       "title": "EHR Information Sharing Service overview v2.1 (MHLW)",
       "url": "https://www.mhlw.go.jp/content/10800000/001457777.pdf",
       "date": "2026-07-21",
       "publisherClass": "official"
      },
      {
       "title": "Report on passage of the Act amending the Medical Care Act (MHLW)",
       "url": "https://www.mhlw.go.jp/content/10801000/001606327.pdf",
       "date": "2025-12-08",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 50,
     "summary": "Health data cannot go to third parties by opt-out, but certified operators and the NDB supply processed data to drug makers and other firms. In August 2026 the regulator warned about municipal claims data reaching pharma marketing and insurance underwriting.",
     "sources": [
      {
       "title": "Act on the Protection of Personal Information (Act No. 57 of 2003), e-Gov law text",
       "url": "https://laws.e-gov.go.jp/law/415AC0000000057",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Material 4, 1st meeting of the review panel on use of medical information (Cabinet Office)",
       "url": "https://www8.cao.go.jp/iryou/studygloup/20250903/pdf/s-4.pdf",
       "date": "2025-09-03",
       "publisherClass": "official"
      },
      {
       "title": "Caution on use of claims data held by local governments (PPC)",
       "url": "https://www.ppc.go.jp/files/pdf/260819_02_houdou.pdf",
       "date": "2026-08-19",
       "publisherClass": "official"
      },
      {
       "title": "Overview of the Act amending the APPI (PPC)",
       "url": "https://www.ppc.go.jp/files/pdf/260717_kaiseihounitsuite.pdf",
       "date": "2026-07-17",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 52,
     "summary": "With consent, providers can see up to five years of claims-based treatment, surgery and medicine data, and hospitals can see it without consent in emergencies. Notes, results and images from other providers are not yet shared nationally.",
     "sources": [
      {
       "title": "Provision of treatment information including surgery in online eligibility checks (MHLW)",
       "url": "https://www.mhlw.go.jp/content/10200000/000992343.pdf",
       "date": "2025-03",
       "publisherClass": "official"
      },
      {
       "title": "Emergency medical information viewing: overview for hospitals (MHLW)",
       "url": "https://www.mhlw.go.jp/content/10200000/001243478.pdf",
       "date": "2026-06",
       "publisherClass": "official"
      },
      {
       "title": "Reference materials, 16th meeting of the review panel on use of medical information (Cabinet Office)",
       "url": "https://www8.cao.go.jp/iryou/studygloup/20260911/pdf/s-2.pdf",
       "date": "2026-09-11",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "The NDB claims database is shared with researchers and companies without consent or opt-out, while certified operators use an opt-out. Expert review, secure cloud analysis and criminal penalties for misuse put Japan at the cap of its band.",
     "sources": [
      {
       "title": "Use of the NDB claims database: third-party provision (MHLW)",
       "url": "https://www.mhlw.go.jp/stf/seisakunitsuite/bunya/kenkou_iryou/iryouhoken/reseputo/index.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Act on Anonymized and Pseudonymized Medical Data for Medical R&D (Act No. 28 of 2017), e-Gov law text",
       "url": "https://laws.e-gov.go.jp/law/429AC0000000028",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Clinical Trials Act (Act No. 16 of 2017), e-Gov law text",
       "url": "https://laws.e-gov.go.jp/law/429AC0000000016",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Overview of the Act amending the APPI (PPC)",
       "url": "https://www.ppc.go.jp/files/pdf/260717_kaiseihounitsuite.pdf",
       "date": "2026-07-17",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 60,
     "summary": "AI software for diagnosis or treatment is regulated as a medical device, and a change-plan route (IDATEN) has covered post-market updates since September 2020. MHLW holds the doctor responsible for AI-assisted decisions, but there is no framework for generative AI.",
     "sources": [
      {
       "title": "Regulation and approval of medical AI as SaMD in Japan (Global Health & Medicine)",
       "url": "https://www.jstage.jst.go.jp/article/ghm/8/3/8_2026.01052/_article",
       "date": "2026-06-30",
       "publisherClass": "academic"
      },
      {
       "title": "Review of medical devices using machine learning (PMDA)",
       "url": "https://www.pmda.go.jp/files/000265866.pdf",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Use of AI diagnostic support programs and Article 17 of the Medical Practitioners Act (MHLW notice)",
       "url": "https://www.pmda.go.jp/files/000227450.pdf",
       "date": "2018-12-19",
       "publisherClass": "official"
      },
      {
       "title": "Full enforcement of the AI Promotion Act (Government of Japan, Highlighting Japan)",
       "url": "https://www.gov-online.go.jp/hlj/ja/november_2025/november_2025-08.html",
       "date": "2025-11",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Act on the Protection of Personal Information (APPI)",
     "level": "National",
     "year": "2003",
     "what": "Medical history is special care-required data; consent for sharing, breach reports, right to an electronic copy.",
     "url": "https://laws.e-gov.go.jp/law/415AC0000000057"
    },
    {
     "name": "Act amending the APPI (2026)",
     "level": "National",
     "year": "2026",
     "what": "Consent-free sharing for statistics and AI development; profit-based surcharges; in force within two years.",
     "url": "https://www.ppc.go.jp/files/pdf/260717_kaiseihounitsuite.pdf"
    },
    {
     "name": "Act on Anonymized and Pseudonymized Medical Data for Medical R&D",
     "level": "National",
     "year": "2017",
     "what": "Hospitals pass data to certified operators after notice, stopping on request; re-identification prohibited.",
     "url": "https://laws.e-gov.go.jp/law/429AC0000000028"
    },
    {
     "name": "Act amending the Medical Care Act and related laws (2025)",
     "level": "National",
     "year": "2025",
     "what": "Puts EHR sharing in law, targets about 100% EHR adoption by 2030, opens pseudonymised public databases.",
     "url": "https://www.mhlw.go.jp/content/10801000/001606327.pdf"
    },
    {
     "name": "Clinical Trials Act",
     "level": "National",
     "year": "2017",
     "what": "Specified clinical trials need prior explanation and informed consent from participants.",
     "url": "https://laws.e-gov.go.jp/law/429AC0000000016"
    },
    {
     "name": "AI Promotion Act",
     "level": "National",
     "year": "2025",
     "what": "Sets up a national AI strategy and basic plan; relies on existing law rather than binding AI rules.",
     "url": "https://laws.e-gov.go.jp/law/507AC0000000053"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-02-18",
     "headline": "Clinic says ransomware attack may have exposed up to 300,000 people's records",
     "paraphrase": "A clinic announced that ransomware hit its servers, possibly exposing about 300,000 patient and staff records, including contact details, medical history and checkup results. It paused new outpatient bookings and said it had consulted police.",
     "source": "Nikkei xTECH",
     "url": "https://xtech.nikkei.com/atcl/nxt/news/24/02182/",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-02-16",
     "headline": "Hospital confirms attackers stole patient details through a maintenance VPN",
     "paraphrase": "A university hospital announced that a ransomware attack, entering through a VPN device used for medical equipment maintenance, led to the theft of names, addresses, birth dates and patient IDs of about 10,000 patients.",
     "source": "INTERNET Watch (Impress)",
     "url": "https://internet.watch.impress.co.jp/docs/news/2086066.html",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-05-01",
     "headline": "Hospital worker suspended for reading an acquaintance's record and telling relatives",
     "paraphrase": "A public hospital's administrative support worker opened an acquaintance's electronic record several times with no work reason and told her own relatives what it showed. The prefectural hospital bureau suspended her for three months.",
     "source": "Too Nippo (東奥日報)",
     "url": "https://www.toonippo.co.jp/articles/-/2264492",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-06-08",
     "headline": "Hospital hard drives meant for shredding turned up for sale at online auction",
     "paraphrase": "Hard drives two public hospitals sent for destruction were listed on internet auctions, holding names, addresses, clinical notes and nursing records for up to 510,000 people. The disposal firm said destroyed and intact drives were kept in identical containers.",
     "source": "Hokkaido Cultural Broadcasting (UHB)",
     "url": "https://www.uhb.jp/news/single.html?id=59930",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-06-11",
     "headline": "University hospital discloses months later that a drive with 1,800 patients' details went missing",
     "paraphrase": "A university hospital announced that a doctor lost a USB drive holding about 1,800 patients' personal details, collected for research, on a business trip in February. It was later recovered; the hospital judged leak risk very low.",
     "source": "CBnews (CBnewsマネジメント)",
     "url": "https://www.cbnews.jp/news/entry/20260611173555",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "ROU",
   "name": "Romania",
   "region": "Europe",
   "overall": 56,
   "rank": "35=",
   "likelyRank": "29 to 38",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Romania opened a national patient portal on 1 September 2026 with 10 years of history, but the older e-health record was largely empty.",
   "categories": {
    "access": {
     "score": 60,
     "summary": "Since 1 September 2026 the CNAS portal eSanatateaMea shows insured people their medical history from the last 10 years and prescriptions from the last 5. Score sits at the bottom of the portal band because the launch is staged and the earlier record was largely empty.",
     "sources": [
      {
       "title": "A fost lansat portalul eSanatateaMea (JURIDICE.ro, preluare comunicat CNAS)",
       "url": "https://www.juridice.ro/848816/a-fost-lansat-portalul-esanatateamea.html",
       "date": "2026-09-02",
       "publisherClass": "news"
      },
      {
       "title": "CNAS finalizeaza modernizarea platformei informatice: 100 de milioane de euro (Economedia)",
       "url": "https://economedia.ro/cnas-finalizeaza-modernizarea-platformei-informatice-100-de-milioane-de-euro-pentru-un-sistem-care-gestioneaza-anual-sute-de-milioane-de-servicii-medicale.html",
       "date": "2026-09-01",
       "publisherClass": "news"
      },
      {
       "title": "Accesul pacientului la datele medicale (Spitalul Negresti Oas)",
       "url": "https://spitalnegrestioas.ro/index.php/ro/pagina-pacientului/accesul-pacientului-la-datele-medicale",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Tu ai obtinut acces la dosarul electronic de sanatate pana acum? (Avocatnet.ro)",
       "url": "https://www.avocatnet.ro/articol_68806/Tu-ai-ob%C8%9Binut-acces-la-dosarul-electronic-de-s%C4%83n%C4%83tate-pan%C4%83-acum-Tot-ce-trebuie-s%C4%83-%C8%99tii-despre-acesta-in-2025.html",
       "date": "2025-04-09",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 62,
     "summary": "The law lets patients choose which doctors can open their e-health record, see the full history of doctor access, and refuse the record without losing care. Whether the new portal offers these controls in practice was not verified.",
     "sources": [
      {
       "title": "Legea 95/2006, Titlul IX^1 Dosarul electronic de sanatate al pacientului (introdus prin Legea 45/2019), lege5.ro",
       "url": "https://lege5.ro/Gratuit/gmzdgmjygy2q/dupa-titlul-ix-cardul-european-si-cardul-national-de-asigurari-sociale-de-sanatate-se-introduce-un-nou-titlu-titlul-ix1-dosarul-electronic-de-sanatate-al-pacientului-continand-articolele-3461-34612-cu?dp=gi4dcmrxgaytgny",
       "date": "2019",
       "publisherClass": "legal_text"
      },
      {
       "title": "Din toamna, pacientii vor avea acces online la dosarul medical prin portalul e-Sanatatea Mea (Gazarul)",
       "url": "https://gazarul.ro/2026/07/16/din-toamna-pacientii-vor-avea-acces-online-la-dosarul-medical-si-isi-vor-putea-face-programari-prin-portalul-e-sanatatea-mea/",
       "date": "2026-07-16",
       "publisherClass": "news"
      },
      {
       "title": "Tu ai obtinut acces la dosarul electronic de sanatate pana acum? (Avocatnet.ro)",
       "url": "https://www.avocatnet.ro/articol_68806/Tu-ai-ob%C8%9Binut-acces-la-dosarul-electronic-de-s%C4%83n%C4%83tate-pan%C4%83-acum-Tot-ce-trebuie-s%C4%83-%C8%99tii-despre-acesta-in-2025.html",
       "date": "2025-04-09",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 50,
     "summary": "Health data is protected by the GDPR and Law 190/2018, but public bodies first get a warning and a remediation plan before any fine. In February 2024 a ransomware attack on one hospital software system took about 100 facilities offline.",
     "sources": [
      {
       "title": "Legea 190/2018 privind masuri de punere in aplicare a GDPR (text publicat)",
       "url": "https://www.spitalleordeni.ro/doc/date%20personale/Legea%20nr.%20190%20din%202018.pdf",
       "date": "2018-07-18",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ransomware Attack Knocks 100 Romanian Hospitals Offline (SecurityWeek)",
       "url": "https://www.securityweek.com/ransomware-attack-knocks-100-romanian-hospitals-offline/",
       "date": "2024-02-13",
       "publisherClass": "news"
      },
      {
       "title": "ANSPDCP sanctioneaza un centru medical (JURIDICE.ro)",
       "url": "https://www.juridice.ro/772254/anspdcp-sanctioneaza-un-centru-medical-2.html",
       "date": "2025-02-20",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 60,
     "summary": "The CNAS platform PIAS links more than 35,000 providers: family doctors, specialists, hospitals, labs and pharmacies, with e-prescriptions and digital referrals. The record itself has been thin, and the EU cross-border health services page has no Romanian patient notice yet.",
     "sources": [
      {
       "title": "CNAS finalizeaza modernizarea platformei informatice: 100 de milioane de euro (Economedia)",
       "url": "https://economedia.ro/cnas-finalizeaza-modernizarea-platformei-informatice-100-de-milioane-de-euro-pentru-un-sistem-care-gestioneaza-anual-sute-de-milioane-de-servicii-medicale.html",
       "date": "2026-09-01",
       "publisherClass": "news"
      },
      {
       "title": "Romania 2025 Digital Decade Country Report (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/factpages/romania-2025-digital-decade-country-report",
       "date": "2025-06-18",
       "publisherClass": "intergov"
      },
      {
       "title": "Electronic cross-border health services (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/digital-health-and-care/electronic-cross-border-health-services_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "commercial": {
     "score": 56,
     "summary": "Law 190/2018 says health data processed for public health cannot later be used by third parties for other purposes. The regulator has fined a clinic for emailing promotions to patients without consent, but we found no law aimed at data brokers or health apps.",
     "sources": [
      {
       "title": "Legea 190/2018 privind masuri de punere in aplicare a GDPR (text publicat)",
       "url": "https://www.spitalleordeni.ro/doc/date%20personale/Legea%20nr.%20190%20din%202018.pdf",
       "date": "2018-07-18",
       "publisherClass": "legal_text"
      },
      {
       "title": "ANSPDCP a amendat Hilmi Medical Center (ANSPDCP)",
       "url": "https://www.dataprotection.ro/index.jsp?lang=ro&page=ANSPDCP_a_amendat_Hilmi_Medical_Center",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 50,
     "summary": "By law any doctor can open the record with the patient's consent, and emergency and family doctors can see an emergency summary without it. In 2025 doctors reported the records were so empty they were of little use.",
     "sources": [
      {
       "title": "Legea 95/2006, Titlul IX^1 Dosarul electronic de sanatate al pacientului (introdus prin Legea 45/2019), lege5.ro",
       "url": "https://lege5.ro/Gratuit/gmzdgmjygy2q/dupa-titlul-ix-cardul-european-si-cardul-national-de-asigurari-sociale-de-sanatate-se-introduce-un-nou-titlu-titlul-ix1-dosarul-electronic-de-sanatate-al-pacientului-continand-articolele-3461-34612-cu?dp=gi4dcmrxgaytgny",
       "date": "2019",
       "publisherClass": "legal_text"
      },
      {
       "title": "Tu ai obtinut acces la dosarul electronic de sanatate pana acum? (Avocatnet.ro)",
       "url": "https://www.avocatnet.ro/articol_68806/Tu-ai-ob%C8%9Binut-acces-la-dosarul-electronic-de-s%C4%83n%C4%83tate-pan%C4%83-acum-Tot-ce-trebuie-s%C4%83-%C8%99tii-despre-acesta-in-2025.html",
       "date": "2025-04-09",
       "publisherClass": "news"
      },
      {
       "title": "Seful CNAS: Dosarul electronic de sanatate va fi disponibil pentru fiecare pacient (AGERPRES)",
       "url": "https://agerpres.ro/sanatate/2026/03/31/seful-cnas-dosarul-electronic-de-sanatate-va-fi-disponibil-pentru-fiecare-pacient-incepand-cu-vara-a--1542731",
       "date": "2026-03-31",
       "publisherClass": "news"
      },
      {
       "title": "Din toamna, pacientii vor avea acces online la dosarul medical prin portalul e-Sanatatea Mea (Gazarul)",
       "url": "https://gazarul.ro/2026/07/16/din-toamna-pacientii-vor-avea-acces-online-la-dosarul-medical-si-isi-vor-putea-face-programari-prin-portalul-e-sanatatea-mea/",
       "date": "2026-07-16",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 44,
     "summary": "The e-health record law lets health authorities use anonymised data for statistics, and we found no individual opt-out from research use. Trials follow the EU Clinical Trials Regulation under the medicines agency ANMDMR.",
     "sources": [
      {
       "title": "Legea 95/2006, Titlul IX^1 Dosarul electronic de sanatate al pacientului (introdus prin Legea 45/2019), lege5.ro",
       "url": "https://lege5.ro/Gratuit/gmzdgmjygy2q/dupa-titlul-ix-cardul-european-si-cardul-national-de-asigurari-sociale-de-sanatate-se-introduce-un-nou-titlu-titlul-ix1-dosarul-electronic-de-sanatate-al-pacientului-continand-articolele-3461-34612-cu?dp=gi4dcmrxgaytgny",
       "date": "2019",
       "publisherClass": "legal_text"
      },
      {
       "title": "Regulament Studii Clinice / Sistem Informatic pentru Studii Clinice (ANMDMR)",
       "url": "https://www.anm.ro/regulament-studii-clinice-sistem-informatic-pentru-studii-clinice/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ce se intampla cu datele tale medicale dupa digitalizare (EVZ)",
       "url": "https://evz.ro/ce-se-intampla-cu-datele-tale-medicale-dupa-digitalizare-frica-legitima-si-ce-spun-documentele-oficiale.html",
       "date": "2026-01-13",
       "publisherClass": "news"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Romania has no verified national rules for clinical AI and relies on EU law. On 24 July 2026 the regulator ANCOM said no authority can sanction breaches of the AI Act until a national law, still being drafted, takes effect.",
     "sources": [
      {
       "title": "Artificial Intelligence Act in Romania: current state of the implementation framework (ANCOM)",
       "url": "https://www.ancom.ro/en/about-us/media-en/press-releases/artificial-intelligence-act-in-romania-current-state-of-the-implementation-framework/",
       "date": "2026-07-24",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health is special-category data; right of access; fines up to EUR 20M or 4% of turnover.",
     "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng"
    },
    {
     "name": "Law 190/2018 implementing the GDPR",
     "level": "National",
     "year": "2018",
     "what": "Limits health-data profiling; bans third-party reuse of public-health data; warning first for public bodies.",
     "url": "https://www.spitalleordeni.ro/doc/date%20personale/Legea%20nr.%20190%20din%202018.pdf"
    },
    {
     "name": "Law 46/2003 on patient rights",
     "level": "National",
     "year": "2003",
     "what": "Patients have access to their personal medical data; confidentiality of medical information.",
     "url": "https://legislatie.just.ro/Public/DetaliiDocument/41483"
    },
    {
     "name": "Law 95/2006 on health reform, Title IX^1 (added by Law 45/2019)",
     "level": "National",
     "year": "2019",
     "what": "Electronic health record: consent for doctor access, emergency summary, patient-visible access history.",
     "url": "https://lege5.ro/Gratuit/gmzdgmjygy2q/dupa-titlul-ix-cardul-european-si-cardul-national-de-asigurari-sociale-de-sanatate-se-introduce-un-nou-titlu-titlul-ix1-dosarul-electronic-de-sanatate-al-pacientului-continand-articolele-3461-34612-cu?dp=gi4dcmrxgaytgny"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Free access, restriction rights and opt-out from secondary use; applies from 2029.",
     "url": "https://eur-lex.europa.eu/eli/reg/2025/327/oj/eng"
    },
    {
     "name": "Artificial Intelligence Act (EU) 2024/1689",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk-based AI rules; most obligations from 2 August 2026; national sanctions law pending in Romania.",
     "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng"
    }
   ],
   "dti": {
    "grade": 82,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-02-20",
     "headline": "Regulator fines dental clinic after ex-employee took patient files to a rival",
     "paraphrase": "A former employee copied every patient's contact details and medical file and used them to invite patients to a competing clinic. The clinic then failed to answer the regulator, which fined it.",
     "source": "ANSPDCP (National Supervisory Authority for Personal Data Processing)",
     "url": "https://www.dataprotection.ro/index.jsp?page=Comunicat_Presa_20_02_2026",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-02-27",
     "headline": "Clinic fined for ignoring a patient's two requests for their own medical file",
     "paraphrase": "A patient asked a clinic twice for their medical data and file documents and got no answer. The regulator found no evidence of any reply, fined the clinic and ordered full responses and staff training.",
     "source": "ANSPDCP (National Supervisory Authority for Personal Data Processing)",
     "url": "https://www.dataprotection.ro/?page=Comunicat_Presa_27.02.2025&lang=ro",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2025-02-20",
     "headline": "Clinic emailed one patient's test results to another patient, regulator finds",
     "paraphrase": "A clinic sent a patient's identity number, contact details and test results to another patient by unsecured email, and sent that patient's data back the other way. It told neither patient nor the regulator, which fined it.",
     "source": "ANSPDCP (National Supervisory Authority for Personal Data Processing)",
     "url": "https://www.dataprotection.ro/?page=Comunicat_Presa_20_02_2025",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-02-19",
     "headline": "Discharge papers listed treatment sessions that never happened, insurer says",
     "paraphrase": "A patient complained that a private clinic kept their health insurance card. When it was returned, the discharge papers recorded treatment sessions the national insurer says were fictitious. The insurer applied a contractual penalty to the clinic.",
     "source": "Stiripesurse.ro",
     "url": "https://www.stiripesurse.ro/cadre-medicale-dintr-o-clinica-din-craiova-acuzate-de-decontari-fictive-cnas-a-amendat-unitatea-dupa-ce-unui-barbat-i-a-fost-retinut-cardul-de-sanatate_3860894",
     "theme": "record_wrong",
     "status": "alleged"
    },
    {
     "date": "2026-09-22",
     "headline": "Weeks after launch, patients still cannot open their online medical record",
     "paraphrase": "Patients trying to use the new national health record portal report waiting about two weeks for identity validation. Those who get in often see only a few prescriptions, not their full medical history.",
     "source": "DeFapt.ro",
     "url": "https://defapt.ro/eveniment/problemele-platformei-e-sanatatea-mea",
     "theme": "access_delay_or_cost",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "CYP",
   "name": "Cyprus",
   "region": "Europe",
   "overall": 55,
   "rank": "37=",
   "likelyRank": "32 to 40",
   "band": "Mixed",
   "keysModel": "State",
   "confidence": "medium",
   "headline": "Cyprus wrote strong patient controls into its 2019 eHealth law, but the national record those controls govern is not due until 2029.",
   "categories": {
    "access": {
     "score": 64,
     "summary": "The eHealth law and GDPR give a right to see and copy the record, and the GeSY portal shows prescriptions, referrals, diagnoses and visits. The Commission's 2025 eHealth indicator study scored Cyprus 75% for 2024, against an EU average of 83%.",
     "sources": [
      {
       "title": "Electronic Health Law of 2019, 59(I)/2019, consolidated with 176(I)/2025 (CyLaw)",
       "url": "http://www.cylaw.org/nomoi/enop/non-ind/2019_1_59/full.html",
       "date": "2019-04-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "2025 Digital Decade eHealth indicator study, annex: country factsheets (European Commission)",
       "url": "https://data.europa.eu/doi/10.2759/8383998",
       "date": "2025-06-16",
       "publisherClass": "intergov"
      },
      {
       "title": "Cyprus's 2026 Digital Decade Country Report (European Commission)",
       "url": "https://digital-strategy.ec.europa.eu/en/factpages/cypruss-2026-digital-decade-country-report",
       "date": "2026-08-24",
       "publisherClass": "intergov"
      },
      {
       "title": "GeSY on your screen: everything you need to know (Offsite, via ink.com)",
       "url": "https://ink.com/articles/545626/gesy-stin-othoni-soy-ola-osa-prepei-na-xereis",
       "date": "2023-11-04",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 46,
     "summary": "The GeSY portal shows patients which health professionals viewed their history. Opt-out, data locking and per-provider permissions are in the 2019 law, but they belong to a national record bank that is not yet built.",
     "sources": [
      {
       "title": "Electronic Health Law of 2019, 59(I)/2019, consolidated with 176(I)/2025 (CyLaw)",
       "url": "http://www.cylaw.org/nomoi/enop/non-ind/2019_1_59/full.html",
       "date": "2019-04-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "eHealth4U: a pathway from the Cyprus eHealth law to a citizen-centred national EHR prototype (Digital Health)",
       "url": "https://pmc.ncbi.nlm.nih.gov/articles/PMC13133457/",
       "date": "2026-04-27",
       "publisherClass": "academic"
      },
      {
       "title": "GeSY: how we stay informed about our medical data (Ygeia Press)",
       "url": "https://ygeia-press.com/%CE%B3%CE%B5%CF%83%CF%85%CF%80%CF%89%CF%82-%CE%B5%CE%BD%CE%B7%CE%BC%CE%B5%CF%81%CF%89%CE%BD%CF%8C%CE%BC%CE%B1%CF%83%CF%84%CE%B5-%CE%B3%CE%B9%CE%B1-%CF%84%CE%B1-%CE%B9%CE%B1%CF%84%CF%81%CE%B9%CE%BA/",
       "date": "2023-11-07",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 58,
     "summary": "GDPR and Law 125(I)/2018 apply, and the regulator has acted in health. The state hospital operator OKYpY was fined 46,500 euros over 13 losses of medical files or emergency department records, but fines on public bodies are capped at 200,000 euros.",
     "sources": [
      {
       "title": "Law 125(I)/2018 on the protection of natural persons with regard to personal data (CyLaw)",
       "url": "http://www.cylaw.org/nomoi/enop/non-ind/2018_1_125/full.html",
       "date": "2018-07-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Electronic Health Law of 2019, 59(I)/2019, consolidated with 176(I)/2025 (CyLaw)",
       "url": "http://www.cylaw.org/nomoi/enop/non-ind/2019_1_59/full.html",
       "date": "2019-04-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Commissioner's report: spam complaints, surveillance and fines on OKYpY (Dialogos)",
       "url": "https://dialogos.com.cy/ekthesi-epitropoy-parapona-gia-spam-kyklomata-parakoloythisis-kai-prostima-ston-okypy/",
       "date": "2025-09-26",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 58,
     "summary": "GeSY's IT system links personal doctors, referrals, labs, pharmacies, hospitals and claims, and MyHealth@EU patient summaries and e-prescriptions went live in 2025. The integrated national record has a 21.1 million euro budget with full operation planned for December 2029.",
     "sources": [
      {
       "title": "Launch of MyHealth@EU cross-border eHealth services (National eHealth Authority)",
       "url": "https://neha.org.cy/enarksi-ilektronikwn-diasinoriakwn/",
       "date": "2025-05-16",
       "publisherClass": "official"
      },
      {
       "title": "GHS Information Technology System (Health Insurance Organisation)",
       "url": "https://www.gesy.org.cy/sites/Sites?d=Desktop&locale=el_GR&lookuphost=%2Fel-gr%2F&lookuppage=hioinformationtechnologysystemghs",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "eHealth4U: a pathway from the Cyprus eHealth law to a citizen-centred national EHR prototype (Digital Health)",
       "url": "https://pmc.ncbi.nlm.nih.gov/articles/PMC13133457/",
       "date": "2026-04-27",
       "publisherClass": "academic"
      },
      {
       "title": "All your health history on one screen: when the digital record comes to Cyprus (Politis)",
       "url": "https://www.politis.com.cy/cyprus/igeia/1033942/telos-ston-fakelo-me-ta-khartia-olo-to-istoriko-ighias-se-mia-othoni-pote-erkhetai-o-psifiakos-fakelos-stin-kypro",
       "date": "2026-09-18",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 54,
     "summary": "Genetic and biometric data cannot be used for health or life insurance, and the eHealth law needs each citizen's consent before record data goes into anonymised databases. The same law expects the state to earn revenue from sharing those databases with third parties.",
     "sources": [
      {
       "title": "Law 125(I)/2018 on the protection of natural persons with regard to personal data (CyLaw)",
       "url": "http://www.cylaw.org/nomoi/enop/non-ind/2018_1_125/full.html",
       "date": "2018-07-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Electronic Health Law of 2019, 59(I)/2019, consolidated with 176(I)/2025 (CyLaw)",
       "url": "http://www.cylaw.org/nomoi/enop/non-ind/2019_1_59/full.html",
       "date": "2019-04-19",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 55,
     "summary": "GeSY professionals can preview a patient's GeSY history, and every view is logged. The Commission found public and private hospitals supplying data to the national access service, but a full national record is not yet built.",
     "sources": [
      {
       "title": "GeSY: how we stay informed about our medical data (Ygeia Press)",
       "url": "https://ygeia-press.com/%CE%B3%CE%B5%CF%83%CF%85%CF%80%CF%89%CF%82-%CE%B5%CE%BD%CE%B7%CE%BC%CE%B5%CF%81%CF%89%CE%BD%CF%8C%CE%BC%CE%B1%CF%83%CF%84%CE%B5-%CE%B3%CE%B9%CE%B1-%CF%84%CE%B1-%CE%B9%CE%B1%CF%84%CF%81%CE%B9%CE%BA/",
       "date": "2023-11-07",
       "publisherClass": "news"
      },
      {
       "title": "Electronic Health Law of 2019, 59(I)/2019, consolidated with 176(I)/2025 (CyLaw)",
       "url": "http://www.cylaw.org/nomoi/enop/non-ind/2019_1_59/full.html",
       "date": "2019-04-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Launch of MyHealth@EU cross-border eHealth services (National eHealth Authority)",
       "url": "https://neha.org.cy/enarksi-ilektronikwn-diasinoriakwn/",
       "date": "2025-05-16",
       "publisherClass": "official"
      },
      {
       "title": "2025 Digital Decade eHealth indicator study, annex: country factsheets (European Commission)",
       "url": "https://data.europa.eu/doi/10.2759/8383998",
       "date": "2025-06-16",
       "publisherClass": "intergov"
      }
     ]
    },
    "research": {
     "score": 45,
     "summary": "On paper, record data can enter anonymised research databases only with each citizen's consent. That rule applies to a bank not yet built, and no general research opt-out for GeSY data was verified.",
     "sources": [
      {
       "title": "Electronic Health Law of 2019, 59(I)/2019, consolidated with 176(I)/2025 (CyLaw)",
       "url": "http://www.cylaw.org/nomoi/enop/non-ind/2019_1_59/full.html",
       "date": "2019-04-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Bioethics (Establishment and Operation of National Committee) Law 150(I)/2001 (CyLaw)",
       "url": "http://www.cylaw.org/nomoi/enop/non-ind/2001_1_150/full.html",
       "date": "2001",
       "publisherClass": "legal_text"
      },
      {
       "title": "Reliable health data and AI the basis of a new era, e-Health Authority head says (CBN)",
       "url": "https://www.cbn.com.cy/article/128614/reliable-health-data-and-ai-the-basis-of-a-new-era-e-health-authority-head-says",
       "date": "2026-04-30",
       "publisherClass": "news"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI is governed by EU device law and the EU AI Act, whose medical device duties now start 2 August 2028. Cyprus has named AI Act authorities, but no national clinical AI rules were verified.",
     "sources": [
      {
       "title": "AI Act Service Desk: national resources (European Commission)",
       "url": "https://ai-act-service-desk.ec.europa.eu/en/national-resources",
       "date": "undated",
       "publisherClass": "intergov"
      },
      {
       "title": "Digital Omnibus on AI has been published, Regulation (EU) 2026/1744 (Cuatrecasas)",
       "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published",
       "date": "2026-07-24",
       "publisherClass": "law_firm"
      },
      {
       "title": "Reliable health data and AI the basis of a new era, e-Health Authority head says (CBN)",
       "url": "https://www.cbn.com.cy/article/128614/reliable-health-data-and-ai-the-basis-of-a-new-era-e-health-authority-head-says",
       "date": "2026-04-30",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Electronic Health Law of 2019, 59(I)/2019 (amended 176(I)/2025)",
     "level": "National",
     "year": "2019",
     "what": "National eHealth Authority, single record bank, opt-out, per-provider permissions, data locking and access logging.",
     "url": "http://www.cylaw.org/nomoi/enop/non-ind/2019_1_59/full.html"
    },
    {
     "name": "Law 125(I)/2018 on processing of personal data",
     "level": "National",
     "year": "2018",
     "what": "Implements GDPR; bans genetic and biometric data use for insurance; caps public body fines at 200,000 euros.",
     "url": "http://www.cylaw.org/nomoi/enop/non-ind/2018_1_125/full.html"
    },
    {
     "name": "Bioethics (Establishment and Operation of National Committee) Law 150(I)/2001",
     "level": "National",
     "year": "2001",
     "what": "Creates the National Bioethics Committee that reviews biomedical research ethics.",
     "url": "http://www.cylaw.org/nomoi/enop/non-ind/2001_1_150/full.html"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient summaries and e-prescriptions exchange from March 2029; images, labs, discharge reports from March 2031.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "EU data protection rules applying since 25 May 2018, including the right of access to personal data.",
     "url": "https://commission.europa.eu/law/law-topic/data-protection/legal-framework-eu-data-protection_en"
    },
    {
     "name": "EU AI Act (EU) 2024/1689, amended by (EU) 2026/1744",
     "level": "Supranational",
     "year": "2024",
     "what": "Risk rules for AI; obligations for AI in medical devices now apply from 2 August 2028.",
     "url": "https://www.cuatrecasas.com/en/global/intellectual-property/art/digital-omnibus-ai-has-been-published"
    }
   ],
   "dti": {
    "grade": 90,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-06-29",
     "headline": "Ombudsman's intervention recovers a patient's missing hospital file",
     "paraphrase": "A patient asked the ombudsman for help after a former state hospital could not locate his medical file. After the ombudsman stepped in, the file was found and he regained access to his key health data.",
     "source": "Επίτροπος Διοικήσεως και Προστασίας Ανθρωπίνων Δικαιωμάτων (Ετήσια Έκθεση 2024)",
     "url": "https://www.ombudsman.gov.cy/ombudsman/ombudsman.nsf/All/687657359C6D02BFC2258E25001A09FD/%24file/%CE%95%CF%84%CE%AE%CF%83%CE%B9%CE%B1%20%CE%88%CE%BA%CE%B8%CE%B5%CF%83%CE%B7%202024%20_new1.pdf?OpenElement",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2025-09",
     "headline": "State hospitals fined after ten patients' medical files went missing",
     "paraphrase": "The state hospital body reported losing ten patients' medical files and three emergency registration forms. The regulator found no safeguards against loss, fined it 46,500 euros in total and ordered it to tell seven patients.",
     "source": "Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Ετήσια Έκθεση 2024)",
     "url": "https://www.gov.cy/media/sites/67/2026/02/Annual-Report-2024.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-09",
     "headline": "Two doctors reprimanded for giving a patient's medical certificates to his former wife",
     "paraphrase": "A man complained that two doctors issued certificates about his past care to his former wife without his knowledge or consent. The regulator found they processed his health data with no legal basis and reprimanded both.",
     "source": "Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Ετήσια Έκθεση 2024)",
     "url": "https://www.gov.cy/media/sites/67/2026/02/Annual-Report-2024.pdf",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-09",
     "headline": "Doctor reprimanded for phoning a patient's next of kin to confirm an appointment",
     "paraphrase": "A doctor's secretary looked up a patient's GeSY account and phoned his father, listed as next of kin, to confirm a booking. The regulator ruled that number was not an alternative contact and reprimanded the doctor.",
     "source": "Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (Ετήσια Έκθεση 2024)",
     "url": "https://www.gov.cy/media/sites/67/2026/02/Annual-Report-2024.pdf",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-12-11",
     "headline": "Specialist hospital confirms hackers stole patient and staff data and threatened publication",
     "paraphrase": "The hospital said attackers took personal data of patients and staff from its systems and threatened to publish it in the media and online. It reported the attack to police, the data regulator and the digital security authority.",
     "source": "Sigmalive",
     "url": "https://www.sigmalive.com/news/local/1296990/kataghghelia-apo-to-oghkologhiko-kentro-ghia-paranomi-dimosiefsi-dedomenon",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "ARE",
   "name": "United Arab Emirates",
   "region": "Middle East",
   "overall": 55,
   "rank": "37=",
   "likelyRank": "30 to 42",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Each emirate runs its own shared record with near-universal reach, but patient copy rights and opt-outs come from emirate regulators, not federal law.",
   "categories": {
    "access": {
     "score": 35,
     "summary": "No federal law gives patients a right to a copy of their record; the right sits in Abu Dhabi and Dubai regulator standards. Three government portals show part of the record by region, which lifts the cell to the top of its band (35) and no further.",
     "sources": [
      {
       "title": "DOH Standard on Patient Healthcare Data Privacy (Department of Health Abu Dhabi, hosted by Malaffi)",
       "url": "https://staticcdn.malaffi.ae/wpblobe9e5523f25/2021/02/2020-09-15-DOH-Standard-on-Patient-Healthcare-Data-Privacy-for-publication-2.pdf",
       "date": "2020-09-16",
       "publisherClass": "official"
      },
      {
       "title": "Policy for Data and Health Information Protection and Confidentiality (Dubai Health Authority)",
       "url": "https://dha.gov.ae/uploads/082022/Health%20Data%20Protection%20and%20Confidentiality%20Policy_EN2022810559.pdf",
       "date": "2022-08-10",
       "publisherClass": "official"
      },
      {
       "title": "Sahatna App FAQ (Department of Health Abu Dhabi)",
       "url": "https://sahatna-app.doh.gov.ae/en/faqs/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Smart Patient Portal (MOHAP, Internet Archive copy of 22 Jan 2026)",
       "url": "https://web.archive.org/web/20260122171056/https://mohap.gov.ae/en/w/smart-patient-portal",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 48,
     "summary": "Each emirate has a different rule: Riayati lets Northern Emirates patients opt out and promises access notices, Dubai's NABIDH takes opt-outs by signed form, and Abu Dhabi's Malaffi makes participation universal. The blend sits mid-band at 48.",
     "sources": [
      {
       "title": "Riayati Healthcare Data Confidentiality and Privacy Policy RYT-PGM-POL-003 v1.2 (MOHAP, Internet Archive copy of 15 Apr 2025)",
       "url": "https://web.archive.org/web/20250415110215/https://mohap.gov.ae/documents/20117/590019/Riayati_Confidentiality_and_data_privacy_policy_V1.2.pdf/114cf9a6-69d8-32a1-53e7-6ef447d1a7f8",
       "date": "2020-06-11",
       "publisherClass": "official"
      },
      {
       "title": "Standards for Health Information Consent and Access Control (Dubai Health Authority)",
       "url": "https://dha.gov.ae/uploads/012025/Standards%20for%20Consnet%20and%20Access%20Control2025129762.pdf",
       "date": "2025-01-02",
       "publisherClass": "official"
      },
      {
       "title": "DOH Policy on the Abu Dhabi Health Information Exchange (Department of Health Abu Dhabi)",
       "url": "https://www.doh.gov.ae/-/media/A78104416DF2440E89AC90FB75F11055.ashx",
       "date": "2020-04-16",
       "publisherClass": "official"
      },
      {
       "title": "DOH Standard on Patient Healthcare Data Privacy (Department of Health Abu Dhabi, hosted by Malaffi)",
       "url": "https://staticcdn.malaffi.ae/wpblobe9e5523f25/2021/02/2020-09-15-DOH-Standard-on-Patient-Healthcare-Data-Privacy-for-publication-2.pdf",
       "date": "2020-09-16",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 50,
     "summary": "The 2019 health ICT law keeps health data in the UAE and fines unlawful export AED 500,000 to 700,000. But health data, and government bodies, fall outside the privacy law, the federal privacy regulator never became fully operational, and courts and health authorities can obtain records without consent.",
     "sources": [
      {
       "title": "Federal Law No. 2 of 2019 on ICT in Health Fields (UAE Legislation portal, Internet Archive copy of 26 Nov 2025)",
       "url": "https://web.archive.org/web/20251126033721/https://uaelegislation.gov.ae/en/legislations/1209/download",
       "date": "2019-02-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE Legislation portal, Internet Archive copy of 7 Sep 2026)",
       "url": "https://web.archive.org/web/20260907034008/https://www.uaelegislation.gov.ae/en/legislations/1972/download",
       "date": "2021-09-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "UAE Establishes Federal Authority for Artificial Intelligence and Data (Morgan Lewis)",
       "url": "https://www.morganlewis.com/pubs/2026/06/uae-establishes-federal-authority-for-artificial-intelligence-and-data",
       "date": "2026-06-15",
       "publisherClass": "law_firm"
      },
      {
       "title": "Millions of patient records hacked in Dubai (Semafor)",
       "url": "https://www.semafor.com/article/06/11/2025/millions-of-dubai-patient-records-hacked",
       "date": "2025-06-11",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 80,
     "summary": "In June 2026 Malaffi connected 100% of Abu Dhabi hospitals and 3,144 facilities, with 4.2 billion records for 14 million patients; NABIDH links over 2,000 Dubai facilities. Riayati is the bridge, and a direct Malaffi to NABIDH link is still a plan.",
     "sources": [
      {
       "title": "Malaffi Progress Report, June 2026 (Malaffi)",
       "url": "https://www.malaffi.ae/malaffi-progress-report/",
       "date": "2026-06",
       "publisherClass": "official"
      },
      {
       "title": "Dubai Health Authority: enabling a future-ready health sector, interview (Economy Middle East)",
       "url": "https://economymiddleeast.com/news/dubai-health-authority-enabling-a-future-ready-health-sector-interview/",
       "date": "2026-02-09",
       "publisherClass": "news"
      },
      {
       "title": "DoH's Malaffi and MOHAP announce completion of latest phase of Riayati integration (Malaffi)",
       "url": "https://www.malaffi.ae/dohs-malaffi-and-mohap-announce-the-completion-of-the-latest-phase-of-riayati-integration/",
       "date": "2023-10",
       "publisherClass": "official"
      },
      {
       "title": "Malaffi FAQ for end users: General (Malaffi, operated by M42's Abu Dhabi Health Data Services)",
       "url": "https://www.malaffi.ae/faq-end-users/general/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 56,
     "summary": "The health ICT law bars non-health use of patient data without written consent, and Abu Dhabi's exchange policy bans commercial or marketing use. Rules for consumer health apps and data brokers were not found, and Malaffi is run by a commercial M42 company.",
     "sources": [
      {
       "title": "Federal Law No. 2 of 2019 on ICT in Health Fields (UAE Legislation portal, Internet Archive copy of 26 Nov 2025)",
       "url": "https://web.archive.org/web/20251126033721/https://uaelegislation.gov.ae/en/legislations/1209/download",
       "date": "2019-02-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "DOH Policy on the Abu Dhabi Health Information Exchange (Department of Health Abu Dhabi)",
       "url": "https://www.doh.gov.ae/-/media/A78104416DF2440E89AC90FB75F11055.ashx",
       "date": "2020-04-16",
       "publisherClass": "official"
      },
      {
       "title": "Data protection laws (The Official Platform of the UAE Government, u.ae)",
       "url": "https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Malaffi reaches 3.5 billion clinical records (Malaffi)",
       "url": "https://www.malaffi.ae/malaffi-reaches-3-5-billion-clinical-records-setting-a-new-standard-for-healthcare-innovation-in-abu-dhabi/",
       "date": "2025-08-14",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 76,
     "summary": "Clinicians in each emirate can open a shared record with labs, radiology images, medicines and documents, with break-the-glass access in emergencies. Cross-emirate views run through Riayati, and VIP flags, opt-outs and Dubai's consent rule limit some views.",
     "sources": [
      {
       "title": "Malaffi FAQ for end users: General (Malaffi, operated by M42's Abu Dhabi Health Data Services)",
       "url": "https://www.malaffi.ae/faq-end-users/general/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Malaffi Media Center (Malaffi)",
       "url": "https://www.malaffi.ae/media-center/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Standards for Health Information Consent and Access Control (Dubai Health Authority)",
       "url": "https://dha.gov.ae/uploads/012025/Standards%20for%20Consnet%20and%20Access%20Control2025129762.pdf",
       "date": "2025-01-02",
       "publisherClass": "official"
      },
      {
       "title": "Riayati Healthcare Data Confidentiality and Privacy Policy RYT-PGM-POL-003 v1.2 (MOHAP, Internet Archive copy of 15 Apr 2025)",
       "url": "https://web.archive.org/web/20250415110215/https://mohap.gov.ae/documents/20117/590019/Riayati_Confidentiality_and_data_privacy_policy_V1.2.pdf/114cf9a6-69d8-32a1-53e7-6ef447d1a7f8",
       "date": "2020-06-11",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 46,
     "summary": "The 2019 law allows research on patient data without consent if identity is not disclosed and research ethics are followed, and no research opt-out exists. Ethics committee review and the law's statutory confidentiality duty add two safeguard classes to a base of 40.",
     "sources": [
      {
       "title": "Federal Law No. 2 of 2019 on ICT in Health Fields (UAE Legislation portal, Internet Archive copy of 26 Nov 2025)",
       "url": "https://web.archive.org/web/20251126033721/https://uaelegislation.gov.ae/en/legislations/1209/download",
       "date": "2019-02-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Riayati Healthcare Data Confidentiality and Privacy Policy RYT-PGM-POL-003 v1.2 (MOHAP, Internet Archive copy of 15 Apr 2025)",
       "url": "https://web.archive.org/web/20250415110215/https://mohap.gov.ae/documents/20117/590019/Riayati_Confidentiality_and_data_privacy_policy_V1.2.pdf/114cf9a6-69d8-32a1-53e7-6ef447d1a7f8",
       "date": "2020-06-11",
       "publisherClass": "official"
      },
      {
       "title": "DOH Standard on Human Subject Research (Department of Health Abu Dhabi)",
       "url": "https://www.doh.gov.ae/-/media/C07A10ADB6504312A601E3A514D43084.ashx",
       "date": "2020-01",
       "publisherClass": "official"
      },
      {
       "title": "New regulation on the use of ICT in healthcare in the UAE (Simmons & Simmons)",
       "url": "https://www.simmons-simmons.com/en/publications/ckcbolcc9l9s90a791x94jrz0/new-regulation-on-the-use-of-ict-in-healthcare-in-the-uae",
       "date": "2020-07-07",
       "publisherClass": "law_firm"
      }
     ]
    },
    "ai": {
     "score": 64,
     "summary": "Decree-Law 38 of 2024 regulates AI-based products as medical devices and requires new approval after fundamental design changes. Abu Dhabi's October 2025 standard adds human oversight, disclosure to patients and an AI opt-out notice, but only for Abu Dhabi.",
     "sources": [
      {
       "title": "Federal Decree-Law No. 38 of 2024 Governing Medical Products, Pharmacists and Pharmaceutical Establishments (UAE Legislation portal, Internet Archive copy of 7 Jan 2026)",
       "url": "https://web.archive.org/web/20260107203406/https://uaelegislation.gov.ae/en/legislations/2751/download",
       "date": "2024-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Responsible Artificial Intelligence (AI) Standard V1 (Department of Health Abu Dhabi)",
       "url": "https://www.doh.gov.ae/-/media/Feature/Resources/Standards/2025/Responsible-AI-Standard-V1.ashx",
       "date": "2025-10",
       "publisherClass": "official"
      },
      {
       "title": "How is AI in healthcare being regulated in the UAE? (International Bar Association)",
       "url": "https://www.ibanet.org/ai-healthcare-regulation-uae",
       "date": "2026-05-11",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Federal Law No. 2 of 2019 on the Use of ICT in Health Fields",
     "level": "National",
     "year": "2019",
     "what": "Confidentiality, central exchange, 25-year retention, health data kept in the UAE, fines and licence sanctions.",
     "url": "https://web.archive.org/web/20251126033721/https://uaelegislation.gov.ae/en/legislations/1209/download"
    },
    {
     "name": "Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data",
     "level": "National",
     "year": "2021",
     "what": "General privacy law; excludes health data with its own law and government entities.",
     "url": "https://web.archive.org/web/20260907034008/https://www.uaelegislation.gov.ae/en/legislations/1972/download"
    },
    {
     "name": "Federal Decree-Law No. 38 of 2024 on Medical Products",
     "level": "National",
     "year": "2024",
     "what": "Regulates medical devices including AI-based products; design changes need new approval.",
     "url": "https://web.archive.org/web/20260107203406/https://uaelegislation.gov.ae/en/legislations/2751/download"
    },
    {
     "name": "DOH Standard on Patient Healthcare Data Privacy (Abu Dhabi)",
     "level": "State/Provincial",
     "year": "2020",
     "what": "Right to review and copy records; written consent for non-health use; 24-hour breach reporting.",
     "url": "https://staticcdn.malaffi.ae/wpblobe9e5523f25/2021/02/2020-09-15-DOH-Standard-on-Patient-Healthcare-Data-Privacy-for-publication-2.pdf"
    },
    {
     "name": "DOH Policy on the Abu Dhabi Health Information Exchange",
     "level": "State/Provincial",
     "year": "2020",
     "what": "Mandatory universal participation in Malaffi; bans commercial and marketing use of exchange data.",
     "url": "https://www.doh.gov.ae/-/media/A78104416DF2440E89AC90FB75F11055.ashx"
    },
    {
     "name": "DHA Standards for Health Information Consent and Access Control (Dubai)",
     "level": "State/Provincial",
     "year": "2025",
     "what": "Consent to view NABIDH, signed-form opt-out, break-the-glass rules for emergencies.",
     "url": "https://dha.gov.ae/uploads/012025/Standards%20for%20Consnet%20and%20Access%20Control2025129762.pdf"
    },
    {
     "name": "DoH Responsible AI Standard V1 (Abu Dhabi)",
     "level": "State/Provincial",
     "year": "2025",
     "what": "Human oversight, disclosure to patients, AI opt-out notice, change logs for healthcare AI.",
     "url": "https://www.doh.gov.ae/-/media/Feature/Resources/Standards/2025/Responsible-AI-Standard-V1.ashx"
    }
   ],
   "dti": {
    "grade": 75,
    "tier": "Silver",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-06-11",
     "headline": "Ransomware group claims it stole patient records from a private hospital",
     "paraphrase": "A ransomware group claimed it took a large volume of patient data, including card numbers and treatment plans, and threatened to publish it. The outlet reported patient systems were still down; the hospital did not respond to questions.",
     "source": "Semafor Gulf",
     "url": "https://www.semafor.com/article/06/11/2025/millions-of-dubai-patient-records-hacked",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2025-05-09",
     "headline": "Regulator closes four clinics that wrote visits that never happened into medical files",
     "paraphrase": "The health regulator closed four facilities that sold sick leave over a messaging app, collecting ID photos and health details, then recorded visits that never happened in people's medical files and forged consent signatures.",
     "source": "Emarat Al Youm",
     "url": "https://www.emaratalyoum.com/local-section/health/2025-05-09-1.1943163",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2026-03-27",
     "headline": "Regulator shuts five health facilities after finding manipulated medical data",
     "paraphrase": "The emirate's health regulator closed five facilities and suspended staff pending referral to prosecutors. Inspections found sick notes issued without examining patients and manipulation of medical data, among other licensing violations.",
     "source": "Emarat Al Youm",
     "url": "https://www.emaratalyoum.com/local-section/health/2026-03-27-1.2029307",
     "theme": "record_wrong",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "CRI",
   "name": "Costa Rica",
   "region": "Americas",
   "overall": 54,
   "rank": "39=",
   "likelyRank": "34 to 43",
   "band": "Mixed",
   "keysModel": "State",
   "confidence": "medium",
   "headline": "Costa Rica runs one national digital record (EDUS) across public care; patients can view and share parts of it but cannot opt out.",
   "categories": {
    "access": {
     "score": 64,
     "summary": "Ley 8239 gives a right to a copy, and the EDUS app lets patients download an authenticated copy showing diagnoses, medicines, allergies and visits, not the full chart. App usage was not verified, so the score sits in the lower half of the portal band.",
     "sources": [
      {
       "title": "Ley 8239, Derechos y deberes de las personas usuarias de los servicios de salud publicos y privados (IAFA copy)",
       "url": "https://iafa.go.cr/wp-content/uploads/2025/01/Derechos-y-deberes-de-las-personas-usuarias-de-los-servicios-de-salud-publicos-y-privados.pdf",
       "date": "2002",
       "publisherClass": "legal_text"
      },
      {
       "title": "Reglamento del Expediente Digital Unico en Salud (CCSS, SINALEVI)",
       "url": "https://sinalevi.go.cr/ResultadosNormativa/Informacion?param1=85915&param2=111286&param3=1&param4=",
       "date": "2018-01-29",
       "publisherClass": "legal_text"
      },
      {
       "title": "EDUS app, App Store Costa Rica",
       "url": "https://apps.apple.com/cr/app/edus/id1042094805",
       "date": "undated",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "El Expediente Digital Unico en Salud de la CCSS (Conferencia Interamericana de Seguridad Social)",
       "url": "https://archivos.juridicas.unam.mx/www/bjv/libros/13/6338/1.pdf",
       "date": "2020-03",
       "publisherClass": "intergov"
      }
     ]
    },
    "control": {
     "score": 48,
     "summary": "EDUS data is collected without patient consent and is visible to any CCSS user with the right access level, with no opt-out. Every action is logged, and a patient can ask their clinic for a certified access record.",
     "sources": [
      {
       "title": "Reglamento del Expediente Digital Unico en Salud (CCSS, SINALEVI)",
       "url": "https://sinalevi.go.cr/ResultadosNormativa/Informacion?param1=85915&param2=111286&param3=1&param4=",
       "date": "2018-01-29",
       "publisherClass": "legal_text"
      },
      {
       "title": "Como saber si alguien reviso su expediente en EDUS (CRHoy)",
       "url": "https://crhoy.com/nacionales/como-saber-si-alguien-reviso-su-expediente-en-edus-asi-puede-solicitar-el-registro-de-accesos/",
       "date": "2026-03-17",
       "publisherClass": "news"
      },
      {
       "title": "Nueva funcion en aplicacion EDUS permite compartir expediente medico con personal de salud privado (Monumental)",
       "url": "https://www.monumental.co.cr/2025/08/07/nueva-funcion-en-aplicacion-edus-permite-compartir-expediente-medico-con-personal-de-salud-privado/",
       "date": "2025-08-07",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 40,
     "summary": "Ley 9162 and Ley 8968 treat health data as sensitive, but fines top out at 30 base salaries. The Comptroller found 8,966 irregular EDUS access permissions in 2022, and a May 2022 cyberattack forced CCSS hospitals back to paper.",
     "sources": [
      {
       "title": "Ley 9162, Expediente Digital Unico de Salud (SINALEVI)",
       "url": "https://sinalevi.go.cr/ResultadosNormativa/Informacion?param1=75700&param2=93998&param3=1&param4=",
       "date": "2013-08-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 8968, Proteccion de la Persona frente al tratamiento de sus datos personales (MICITT)",
       "url": "https://micitt.go.cr/sites/default/files/marco_juridico_legal/08.%20Ley%20n.%C2%B0%208968%20Ley%20de%20Protecci%C3%B3n%20de%20la%20Persona%20frente%20al%20tratamiento%20de%20sus%20datos%20personales..pdf",
       "date": "2011-07-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Pensionados y personas fuera de planilla de la CCSS tienen acceso a datos de EDUS, revela CGR (AmeliaRueda.com)",
       "url": "https://ameliarueda.com/nota/pensionados-personas-fuera-planilla-tienen-acceso-edus-noticias-costa-rica",
       "date": "2022-04-25",
       "publisherClass": "news"
      },
      {
       "title": "Hackeo a la CCSS obliga a pacientes a volver a centros medicos (La Teja)",
       "url": "https://www.lateja.cr/nacional/hackeo-a-la-ccss-obliga-a-pacientes-a-volver-a/OBKTUUCXTRHX5KOIAAFXHCUWFY/story/",
       "date": "2022-05-31",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 68,
     "summary": "EDUS reached all three levels of public care by September 2018, linking 1,040 primary care teams and 29 hospitals with lab, pharmacy and family records. Private hospitals and clinics are not connected beyond the patient's share code.",
     "sources": [
      {
       "title": "El Expediente Digital Unico en Salud de la CCSS (Conferencia Interamericana de Seguridad Social)",
       "url": "https://archivos.juridicas.unam.mx/www/bjv/libros/13/6338/1.pdf",
       "date": "2020-03",
       "publisherClass": "intergov"
      },
      {
       "title": "IAFA avanza en implementacion del EDUS (Ministerio de Salud)",
       "url": "https://www.ministeriodesalud.go.cr/index.php/prensa/67-noticias-2026/2406-iafa-avanza-en-implementacion-del-edus-para-mejorar-la-atencion-en-salud-a-nivel-nacional",
       "date": "2026-04-14",
       "publisherClass": "official"
      },
      {
       "title": "Editorial: El EDUS necesita atencion urgente de la CCSS (La Nacion)",
       "url": "https://www.nacion.com/opinion/editorial/editorial-el-edus-necesita-atencion-urgente-de-la/IPGZZZCK4BEV5ERMQCBXCB2UJA/story/",
       "date": "2025-06-18",
       "publisherClass": "news"
      },
      {
       "title": "Costa Rica lleva el EDUS a dos carceles (Infobae)",
       "url": "https://www.infobae.com/costa-rica/2026/09/15/costa-rica-lleva-el-expediente-digital-unico-en-salud-a-dos-carceles-y-prepara-su-expansion-a-21-centros-mas/",
       "date": "2026-09-15",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 52,
     "summary": "Ley 8968 makes collecting or transmitting sensitive data by private parties its most serious offence, and the EDUS rules require explicit patient authorisation before sensitive data goes to private organisations. No enforcement record on health data sales was found.",
     "sources": [
      {
       "title": "Ley 8968, Proteccion de la Persona frente al tratamiento de sus datos personales (MICITT)",
       "url": "https://micitt.go.cr/sites/default/files/marco_juridico_legal/08.%20Ley%20n.%C2%B0%208968%20Ley%20de%20Protecci%C3%B3n%20de%20la%20Persona%20frente%20al%20tratamiento%20de%20sus%20datos%20personales..pdf",
       "date": "2011-07-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Reglamento del Expediente Digital Unico en Salud (CCSS, SINALEVI)",
       "url": "https://sinalevi.go.cr/ResultadosNormativa/Informacion?param1=85915&param2=111286&param3=1&param4=",
       "date": "2018-01-29",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 65,
     "summary": "The EDUS regulation makes care data automatically available to every CCSS clinician by access level, across all public facilities. Private clinicians see only a summary when the patient shares a code.",
     "sources": [
      {
       "title": "Reglamento del Expediente Digital Unico en Salud (CCSS, SINALEVI)",
       "url": "https://sinalevi.go.cr/ResultadosNormativa/Informacion?param1=85915&param2=111286&param3=1&param4=",
       "date": "2018-01-29",
       "publisherClass": "legal_text"
      },
      {
       "title": "IAFA avanza en implementacion del EDUS (Ministerio de Salud)",
       "url": "https://www.ministeriodesalud.go.cr/index.php/prensa/67-noticias-2026/2406-iafa-avanza-en-implementacion-del-edus-para-mejorar-la-atencion-en-salud-a-nivel-nacional",
       "date": "2026-04-14",
       "publisherClass": "official"
      },
      {
       "title": "EDUS ya le permite compartir su expediente con su medico privado (La Nacion)",
       "url": "https://www.nacion.com/el-pais/edus-ya-le-permite-compartir-su-expediente-con-su/LOHIOEVWN5DYPGT4YT6KKDWLBM/story/",
       "date": "2025-08-06",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 45,
     "summary": "Ley 9234 requires express, written, signed consent for biomedical research, overseen by ethics committees and the national council CONIS. Ethics committees can waive consent for observational studies, and no general opt-out from research use of EDUS data was found.",
     "sources": [
      {
       "title": "Ley Reguladora de Investigacion Biomedica N 9234 (text copy)",
       "url": "https://clsanagustin.com/wp-content/uploads/2017/09/Ley-Investigacion-Biomedica-No9234.pdf",
       "date": "2014-04-22",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 8239, Derechos y deberes de las personas usuarias de los servicios de salud publicos y privados (IAFA copy)",
       "url": "https://iafa.go.cr/wp-content/uploads/2025/01/Derechos-y-deberes-de-las-personas-usuarias-de-los-servicios-de-salud-publicos-y-privados.pdf",
       "date": "2002",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 30,
     "summary": "Medical device registration (Decreto 34482-S) covers software inside devices, but there is no AI-specific clinical rule, and three general AI bills await a plenary vote. The CCSS uses AI on EDUS data with human validation as internal policy.",
     "sources": [
      {
       "title": "Decreto 34482-S, Reglamento para registro, clasificacion, importacion y control de equipo y material biomedico (La Gaceta)",
       "url": "https://www.imprentanacional.go.cr/pub/2008/04/25/ALCA19_25_04_2008.html",
       "date": "2008-04-25",
       "publisherClass": "legal_text"
      },
      {
       "title": "Legislacion de IA en Costa Rica (Observatorio IA)",
       "url": "https://www.observatorioia.org/es/legislacion/",
       "date": "2026-08",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "CCSS incorpora inteligencia artificial para depuracion de listas de espera (Infobae)",
       "url": "https://www.infobae.com/costa-rica/2026/05/08/caja-costarricense-de-seguro-social-incorpora-inteligencia-artificial-para-depuracion-de-listas-de-espera/",
       "date": "2026-05-07",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Ley 8239 (derechos y deberes de las personas usuarias de los servicios de salud)",
     "level": "National",
     "year": "2002",
     "what": "Right to access and copy one's clinical record, confidentiality, and to refuse research.",
     "url": "https://iafa.go.cr/wp-content/uploads/2025/01/Derechos-y-deberes-de-las-personas-usuarias-de-los-servicios-de-salud-publicos-y-privados.pdf"
    },
    {
     "name": "Ley 8968 (proteccion de la persona frente al tratamiento de sus datos personales)",
     "level": "National",
     "year": "2011",
     "what": "General data law; health data sensitive; creates PRODHAB; fines up to 30 base salaries.",
     "url": "https://micitt.go.cr/sites/default/files/marco_juridico_legal/08.%20Ley%20n.%C2%B0%208968%20Ley%20de%20Protecci%C3%B3n%20de%20la%20Persona%20frente%20al%20tratamiento%20de%20sus%20datos%20personales..pdf"
    },
    {
     "name": "Ley 9162 (expediente digital unico de salud)",
     "level": "National",
     "year": "2013",
     "what": "Mandates one national digital health record run by the CCSS; all its data private and sensitive.",
     "url": "https://sinalevi.go.cr/ResultadosNormativa/Informacion?param1=75700&param2=93998&param3=1&param4="
    },
    {
     "name": "Reglamento del Expediente Digital Unico en Salud (CCSS)",
     "level": "National",
     "year": "2018",
     "what": "Patient app copies, access log, no consent for collection, explicit consent for private transfer.",
     "url": "https://sinalevi.go.cr/ResultadosNormativa/Informacion?param1=85915&param2=111286&param3=1&param4="
    },
    {
     "name": "Ley 9234 (reguladora de investigacion biomedica)",
     "level": "National",
     "year": "2014",
     "what": "Written informed consent, ethics committees and CONIS oversight for human health research.",
     "url": "https://clsanagustin.com/wp-content/uploads/2017/09/Ley-Investigacion-Biomedica-No9234.pdf"
    },
    {
     "name": "Decreto 34482-S (equipo y material biomedico)",
     "level": "National",
     "year": "2008",
     "what": "Registration and control of medical devices, including embedded software.",
     "url": "https://www.imprentanacional.go.cr/pub/2008/04/25/ALCA19_25_04_2008.html"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-05-28",
     "headline": "Constitutional court says TV channels breached privacy by airing a person's prescriptions",
     "paraphrase": "Two television channels broadcast images of a public official's medical prescriptions taken from a confidential case file. The constitutional court ruled this violated his privacy, ordered every image removed and made the channels liable for damages.",
     "source": "La Nación",
     "url": "https://www.nacion.com/sucesos/sala-iv-condeno-a-opa-y-trivision-por-difundir/6IR4BIEW4VF4VLQEKAEU4RNGTQ/story/",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2024-11-28",
     "headline": "Public insurer admits staff typing error put a stranger's appointment in a patient's record",
     "paraphrase": "A patient found a specialist appointment he never requested in his digital health record. The public insurer said a clerk mistyped an ID number, cancelled the appointment and said it has no statistics on similar errors.",
     "source": "La Nación",
     "url": "https://www.nacion.com/el-pais/ccss-atribuye-a-error-humano-aislado-cita-en-edus/QE2CEM3GKBFATCIBXONZC7GQV4/story/",
     "theme": "record_wrong",
     "status": "admitted"
    },
    {
     "date": "2025-03-20",
     "headline": "National digital record system outage left patients unable to see records or appointments",
     "paraphrase": "A data centre failure took the public insurer's digital health record and app offline for hours. Users could not view their records or appointments, and the insurer told clinics to contact affected patients and rebook them.",
     "source": "La Nación",
     "url": "https://www.nacion.com/el-pais/ccss-restablece-servicios-de-edus-tras-falla/5BLRWA5MIFCA5GB5ARJHMJX2YU/story/",
     "theme": "access_delay_or_cost",
     "status": "admitted"
    },
    {
     "date": "2025-09-19",
     "headline": "Patient says digital record lists medicines he never received, complaint still unanswered",
     "paraphrase": "A patient found entries in his digital health record showing medicines given in a hospital department he says he never visited. He complained to the hospital, says no clear answer came, and went public. Officials say it is being investigated.",
     "source": "El Observador",
     "url": "https://observador.cr/paciente-del-hospital-mexico-denuncia-registro-falso-de-fentanilo-en-su-expediente/",
     "theme": "record_wrong",
     "status": "alleged"
    },
    {
     "date": "2025-06-15",
     "headline": "Patient says years of paper history never reached the national digital record",
     "paraphrase": "A patient advocate said her earlier care history stayed on paper and was never moved into the national digital record. She also said she cannot easily give a private doctor access to her own record.",
     "source": "La Nación",
     "url": "https://www.nacion.com/el-pais/sirve-el-edus-si-se-cae-a-cada-rato-medicos-y/L4NIDJ6EZVBCDLGOVSRVF2BJSM/story/",
     "theme": "lost_between_providers",
     "status": "self_reported"
    }
   ]
  },
  {
   "iso3": "CHE",
   "name": "Switzerland",
   "region": "Europe",
   "overall": 54,
   "rank": "39=",
   "likelyRank": "34 to 43",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Swiss patients have a free right to their whole record, but the optional e-dossier reached only 136,076 people, so Parliament is building an opt-out replacement.",
   "categories": {
    "access": {
     "score": 55,
     "summary": "The data protection act gives a free copy of the whole record, normally within 30 days, and an official national portal exists. Most people still ask each doctor or hospital, because the portal (the e-dossier, EPD) is optional: only 136,076 were open by end of April 2026.",
     "sources": [
      {
       "title": "Bundesgesetz über den Datenschutz (DSG), SR 235.1, Stand 7. Juli 2025",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2022/491/20250707/de/html/fedlex-data-admin-ch-eli-cc-2022-491-20250707-de-html-1.html",
       "date": "2025-07-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Recht auf Einsicht in das Patientendossier (BAG)",
       "url": "https://www.bag.admin.ch/de/recht-auf-einsicht-in-das-patientendossier",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Aktueller Stand des EPD in der Schweiz (eHealth Suisse)",
       "url": "https://www.e-health-suisse.ch/koordination/elektronisches-patientendossier/aktueller-stand",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Einsicht, Aufbewahrung und Löschung von Patientendaten (EDÖB)",
       "url": "https://www.edoeb.admin.ch/de/einsicht-aufbewahrung-und-loeschung-von-patientendaten",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 60,
     "summary": "Inside the EPD the patient opens it by explicit consent, picks which professionals see what, can block named providers and reads an access log. Few people hold one, so for most patients control rests on doctors' professional secrecy.",
     "sources": [
      {
       "title": "Bundesgesetz über das elektronische Patientendossier (EPDG), SR 816.1, Stand 1. Oktober 2024",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2017/203/20241001/de/html/fedlex-data-admin-ch-eli-cc-2017-203-20241001-de-html-2.html",
       "date": "2024-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Verordnung über das elektronische Patientendossier (EPDV), SR 816.11, Stand 1. Oktober 2024",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2017/204/20241001/de/html/fedlex-data-admin-ch-eli-cc-2017-204-20241001-de-html-2.html",
       "date": "2024-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Schweizerisches Strafgesetzbuch (StGB), SR 311.0, Art. 321, Stand 1. Oktober 2026",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/54/757_781_799/20261001/de/html/fedlex-data-admin-ch-eli-cc-54-757_781_799-20261001-de-html.html",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Aktueller Stand des EPD in der Schweiz (eHealth Suisse)",
       "url": "https://www.e-health-suisse.ch/koordination/elektronisches-patientendossier/aktueller-stand",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 60,
     "summary": "Health data is sensitive data, breaches must be reported to the regulator, and doctors face criminal secrecy rules. The regulator (FDPIC) cannot fine; cantons prosecute individuals for fines up to CHF 250,000, and a radiology network was hacked twice in 2025 and 2026.",
     "sources": [
      {
       "title": "Bundesgesetz über den Datenschutz (DSG), SR 235.1, Stand 7. Juli 2025",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2022/491/20250707/de/html/fedlex-data-admin-ch-eli-cc-2022-491-20250707-de-html-1.html",
       "date": "2025-07-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "33. Tätigkeitsbericht 2025/2026 (EDÖB)",
       "url": "https://www.edoeb.admin.ch/dam/de/sd-web/ZgZZm5CLxIFF/33_T%C3%A4tigkeitsbericht%202025-2026%20DE_Web.pdf",
       "date": "2026-06-30",
       "publisherClass": "official"
      },
      {
       "title": "Update: Westschweizer Radiologienetzwerk bestätigt Datendiebstahl nach Cyberangriff (SwissCybersecurity.net)",
       "url": "https://www.swisscybersecurity.net/news/2026-05-07/cyberangriff-legt-westschweizer-radiologie-netzwerk-erneut-lahm",
       "date": "2026-05-07",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 40,
     "summary": "About 96 percent of hospitals are connected to the EPD, but only about 10 percent of outpatient doctors and 13 percent of pharmacies were in September 2025. Mandatory e-prescription and the opt-out E-GD are still passing through Parliament.",
     "sources": [
      {
       "title": "Faktenblatt: Das elektronische Patientendossier in Zahlen (BAG)",
       "url": "https://www.bag.admin.ch/dam/de/sd-web/KMR8cp6wryyN/Faktenblatt%20EPD%20in%20Zahlen%20(Stand%20Oktober%202025).pdf",
       "date": "2025-11-05",
       "publisherClass": "official"
      },
      {
       "title": "Ende 2026 ist Schluss mit der EPD-Plattform der Post (Netzwoche)",
       "url": "https://www.netzwoche.ch/news/2026-06-25/ende-2026-ist-schluss-mit-der-epd-plattform-der-post",
       "date": "2026-06-25",
       "publisherClass": "news"
      },
      {
       "title": "Bundesrat beschliesst Neuausrichtung: Elektronisches Gesundheitsdossier E-GD löst EPD ab (EDI)",
       "url": "https://www.edi.admin.ch/de/bundesrat-beschliesst-neuausrichtung-elektronisches-gesundheitsdossier-e-gd-loest-epd-ab",
       "date": "2025-11-05",
       "publisherClass": "official"
      },
      {
       "title": "Pflicht für elektronische Arztrezepte nimmt erste Hürde (Parlamentsdienste)",
       "url": "https://www.parlament.ch/de/services/news/Seiten/2026/20260312115534601194158159026_bsd085.aspx",
       "date": "2026-03-12",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 58,
     "summary": "Passing health data to third parties counts as a breach of personality rights unless justified, and health professionals face criminal secrecy rules. No Swiss ban on selling health data or on health data brokers was found, and consumer apps rely on general law.",
     "sources": [
      {
       "title": "Bundesgesetz über den Datenschutz (DSG), SR 235.1, Stand 7. Juli 2025",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2022/491/20250707/de/html/fedlex-data-admin-ch-eli-cc-2022-491-20250707-de-html-1.html",
       "date": "2025-07-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Schweizerisches Strafgesetzbuch (StGB), SR 311.0, Art. 321, Stand 1. Oktober 2026",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/54/757_781_799/20261001/de/html/fedlex-data-admin-ch-eli-cc-54-757_781_799-20261001-de-html.html",
       "date": "2026-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Le PFPDT alerte sur les risques des objets connectés (ICTjournal)",
       "url": "https://www.ictjournal.ch/news/2026-04-21/le-pfpdt-alerte-sur-les-risques-des-objets-connectes",
       "date": "2026-04-21",
       "publisherClass": "news"
      },
      {
       "title": "European Health Data Space Regulation (EHDS) (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "clinical": {
     "score": 38,
     "summary": "A clinician sees another provider's documents only if the patient holds an EPD and grants access, or in an emergency unless the patient excluded it. With few dossiers and about 10 percent of outpatient doctors connected, this is rare.",
     "sources": [
      {
       "title": "Verordnung über das elektronische Patientendossier (EPDV), SR 816.11, Stand 1. Oktober 2024",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2017/204/20241001/de/html/fedlex-data-admin-ch-eli-cc-2017-204-20241001-de-html-2.html",
       "date": "2024-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Bundesgesetz über das elektronische Patientendossier (EPDG), SR 816.1, Stand 1. Oktober 2024",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2017/203/20241001/de/html/fedlex-data-admin-ch-eli-cc-2017-203-20241001-de-html-2.html",
       "date": "2024-10-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Faktenblatt: Das elektronische Patientendossier in Zahlen (BAG)",
       "url": "https://www.bag.admin.ch/dam/de/sd-web/KMR8cp6wryyN/Faktenblatt%20EPD%20in%20Zahlen%20(Stand%20Oktober%202025).pdf",
       "date": "2025-11-05",
       "publisherClass": "official"
      },
      {
       "title": "Aktueller Stand des EPD in der Schweiz (eHealth Suisse)",
       "url": "https://www.e-health-suisse.ch/koordination/elektronisches-patientendossier/aktueller-stand",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 66,
     "summary": "The Human Research Act requires consent to reuse identifiable data and genetic data, while coded non-genetic data may be reused after information unless the person objects. Cancer registration has its own right to object since 2020.",
     "sources": [
      {
       "title": "Bundesgesetz über die Forschung am Menschen (HFG), SR 810.30, Stand 1. September 2023",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2013/617/20230901/de/html/fedlex-data-admin-ch-eli-cc-2013-617-20230901-de-html-10.html",
       "date": "2023-09-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Bundesgesetz über die Registrierung von Krebserkrankungen (KRG), SR 818.33, Stand 1. September 2023",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2018/289/20230901/de/html/fedlex-data-admin-ch-eli-cc-2018-289-20230901-de-html-9.html",
       "date": "2023-09-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Generalkonsent (swissethics)",
       "url": "https://swissethics.ch/documents/generalkonsent",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Revision des Humanforschungsgesetzes und des Stammzellenforschungsgesetzes (BAG)",
       "url": "https://www.bag.admin.ch/de/humanforschung-revision-hfg-stfg",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 56,
     "summary": "Medical software, including AI, is regulated under the Medical Devices Ordinance, which uses EU MDR classification and requires post-market surveillance and incident reporting. Switzerland has no AI law yet and chose in February 2025 to ratify the Council of Europe AI convention.",
     "sources": [
      {
       "title": "Medizinprodukteverordnung (MepV), SR 812.213, Stand 1. Juli 2026",
       "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2020/552/20260701/de/html/fedlex-data-admin-ch-eli-cc-2020-552-20260701-de-html-2.html",
       "date": "2026-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Rahmenbedingungen für KI in Arzneimittelentwicklung und regulatorischem Prozess (Swissmedic)",
       "url": "https://www.swissmedic.ch/swissmedic/de/home/humanarzneimittel/authorisations/artificiel-intelligence.html",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Bundesrat will KI-Konvention des Europarats ratifizieren (Bundesrat)",
       "url": "https://www.admin.ch/gov/de/start/dokumentation/medienmitteilungen.msg-id-104110.html",
       "date": "2025-02-12",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Bundesgesetz über den Datenschutz (DSG)",
     "level": "National",
     "year": "2020",
     "what": "In force 1 Sept 2023. Health is sensitive data; free access within 30 days; breach reports; fines to CHF 250,000.",
     "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2022/491/20250707/de/html/fedlex-data-admin-ch-eli-cc-2022-491-20250707-de-html-1.html"
    },
    {
     "name": "Bundesgesetz über das elektronische Patientendossier (EPDG)",
     "level": "National",
     "year": "2015",
     "what": "Opt-in EPD; patient sets access rights, can exclude providers; all access logged; emergency access unless excluded.",
     "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2017/203/20241001/de/html/fedlex-data-admin-ch-eli-cc-2017-203-20241001-de-html-2.html"
    },
    {
     "name": "Bundesgesetz über das elektronische Gesundheitsdossier (EGDG), bill",
     "level": "National",
     "year": "2025",
     "what": "Opt-out E-GD for every resident, central federal system, mandatory outpatient use. Passed National Council September 2026.",
     "url": "https://www.edi.admin.ch/de/bundesrat-beschliesst-neuausrichtung-elektronisches-gesundheitsdossier-e-gd-loest-epd-ab"
    },
    {
     "name": "Strafgesetzbuch (StGB), Art. 321",
     "level": "National",
     "year": "1937",
     "what": "Professional secrecy: health professionals who disclose patient secrets without consent face up to three years in prison.",
     "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/54/757_781_799/20261001/de/html/fedlex-data-admin-ch-eli-cc-54-757_781_799-20261001-de-html.html"
    },
    {
     "name": "Bundesgesetz über die Forschung am Menschen (HFG)",
     "level": "National",
     "year": "2011",
     "what": "Consent for reuse of identifiable and genetic data; coded non-genetic data reusable unless the person objects.",
     "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2013/617/20230901/de/html/fedlex-data-admin-ch-eli-cc-2013-617-20230901-de-html-10.html"
    },
    {
     "name": "Krebsregistrierungsgesetz (KRG)",
     "level": "National",
     "year": "2016",
     "what": "National cancer registration (in force 2020); data registered only if the informed patient does not object.",
     "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2018/289/20230901/de/html/fedlex-data-admin-ch-eli-cc-2018-289-20230901-de-html-9.html"
    },
    {
     "name": "Medizinprodukteverordnung (MepV)",
     "level": "National",
     "year": "2020",
     "what": "Software as medical device; EU MDR classification; post-market surveillance and incident reports to Swissmedic.",
     "url": "https://fedlex.data.admin.ch/filestore/fedlex.data.admin.ch/eli/cc/2020/552/20260701/de/html/fedlex-data-admin-ch-eli-cc-2020-552-20260701-de-html-2.html"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-07-06",
     "headline": "Practitioner rebuilt a patient file after the fact, leaving out treatments; conviction upheld",
     "paraphrase": "Patients asked a practitioner for their records and did not get them. Before police questioning he created a new electronic file showing one treatment where the original showed three. The court upheld his forgery conviction.",
     "source": "Swiss Federal Supreme Court (Bundesgericht), 6B_310/2025",
     "url": "https://entscheidsuche.ch/docs/CH_BGer/CH_BGer_006_6B-310-2025_2026-07-06.html",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-09-09",
     "headline": "Family refused a deceased relative's hospital record; top court upholds secrecy after death",
     "paraphrase": "After a patient died in hospital, his widow and child sought access to his record. Cantonal authorities refused to release the doctor from secrecy, and the federal court agreed, saying confidentiality outlasts death and applies to relatives too.",
     "source": "Swiss Federal Supreme Court (Bundesgericht), 2C_567/2024",
     "url": "https://entscheidsuche.ch/docs/CH_BGer/CH_BGer_002_2C-567-2024_2025-09-09.html",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2026-05-08",
     "headline": "Radiology network hit by a second cyberattack a year after patient data was stolen",
     "paraphrase": "A radiology network operating in seven cantons was attacked again in April 2026 and postponed some examinations. It could not yet say whether data was taken. In an attack a year earlier, patient data was stolen and a ransom demanded.",
     "source": "Medinside",
     "url": "https://www.medinside.ch/de/ein-jahr-danach-neue-cyberattacke-auf-radiologie-netwerk-20260507",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2025-01-09",
     "headline": "After a cyberattack, over 100 doctors could not open patient files for a month",
     "paraphrase": "A cyberattack on a medical group left more than 100 affiliated doctors without access to patient files, schedules and billing for over a month. Its medical director said doctors had to rebuild files and no data had appeared online.",
     "source": "RTS",
     "url": "https://www.rts.ch/info/regions/vaud/2025/article/cyberattaque-a-lausanne-medecins-sans-acces-aux-dossiers-patients-28750319.html",
     "theme": "other",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "SAU",
   "name": "Saudi Arabia",
   "region": "Middle East",
   "overall": 53,
   "rank": "41",
   "likelyRank": "35 to 44",
   "band": "Mixed",
   "keysModel": "State",
   "confidence": "medium",
   "headline": "A national record links over 30 million people and Sehhaty shows much of it, but patients have no working say over sharing.",
   "categories": {
    "access": {
     "score": 64,
     "summary": "The PDPL gives a right to a copy in a common electronic format within 30 days, and Sehhaty passed 31 million users in 2025. How much of the full chart it displays was not verified, so the cell sits low in its band.",
     "sources": [
      {
       "title": "Personal Data Protection Law, Royal Decree M/19 as amended by M/148 (SDAIA Data Governance Platform, Arabic)",
       "url": "https://dgp.sdaia.gov.sa/wps/portal/pdp/knowledgecenter/details/PDPL",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Implementing Regulation of the Personal Data Protection Law (Umm Al-Qura official gazette, Arabic)",
       "url": "https://www.uqn.gov.sa/details?p=23595",
       "date": "2023-09-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Sehhaty Privacy Policy, issue 3.26 (Sehhaty platform, Ministry of Health)",
       "url": "https://sehhaty.sa/pages/privacy-policy-en.html",
       "date": "2025-07-23",
       "publisherClass": "official"
      },
      {
       "title": "Health Sector Transformation Program 2025 report highlights (Ministry of Health news, Arabic)",
       "url": "https://www.moh.gov.sa/ministry/mediacenter/news/pages/news-2026-06-20-001.aspx",
       "date": "2026-06-20",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 32,
     "summary": "Data flows into the national record by default and no live opt-out was found, so a 2015 policy's opt-out earns nothing. The cell sits at 32, above Egypt's 25, because the PDPL regulation gives that policy force and consent-withdrawal rights exist on paper.",
     "sources": [
      {
       "title": "IS0303 Saudi Health Information Exchange Policies v1.0 (Ministry of Health, National eHealth Strategy and Change Management Office)",
       "url": "https://www.moh.gov.sa/en/Ministry/ehealthstd/Documents/eHealth%20Standards%20Files/Policies/IS0303%20Saudi%20Health%20Information%20Exchange%20Policies%20v1.0.pdf",
       "date": "2015-02-22",
       "publisherClass": "official"
      },
      {
       "title": "Sehhaty Privacy Policy, issue 3.26 (Sehhaty platform, Ministry of Health)",
       "url": "https://sehhaty.sa/pages/privacy-policy-en.html",
       "date": "2025-07-23",
       "publisherClass": "official"
      },
      {
       "title": "Implementing Regulation of the Personal Data Protection Law (Umm Al-Qura official gazette, Arabic)",
       "url": "https://www.uqn.gov.sa/details?p=23595",
       "date": "2023-09-07",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 50,
     "summary": "The PDPL treats health data as sensitive, demands 72-hour breach notice and allows prison for harmful disclosure. But the regulator reports to the Prime Minister, administrative fines reach only private bodies, and no health-sector enforcement decision was found.",
     "sources": [
      {
       "title": "Personal Data Protection Law, Royal Decree M/19 as amended by M/148 (SDAIA Data Governance Platform, Arabic)",
       "url": "https://dgp.sdaia.gov.sa/wps/portal/pdp/knowledgecenter/details/PDPL",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "SDAIA: penalties on entities that violated the Personal Data Protection Law (Okaz, Arabic)",
       "url": "https://www.okaz.com.sa/local/na/2254837",
       "date": "2026-06-30",
       "publisherClass": "news"
      },
      {
       "title": "About SDAIA (Saudi Data and AI Authority, Arabic)",
       "url": "https://sdaia.gov.sa/ar/SDAIA/about/Pages/About.aspx",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 70,
     "summary": "The Ministry of Health reported over 30 million people linked to the nphies unified record in 2024 and 40 million e-prescriptions through Wasfaty. The Saudi Health Council reported 33 million and 1.1 billion data exchanges in 2025, but completeness by facility was not verified.",
     "sources": [
      {
       "title": "Health system achievements in 2024 (Ministry of Health news, Arabic)",
       "url": "https://www.moh.gov.sa/ministry/mediacenter/news/pages/news-2025-01-26-001.aspx",
       "date": "2025-01-26",
       "publisherClass": "official"
      },
      {
       "title": "nphies home page with platform phases (nphies, Internet Archive copy of 10 Jul 2025, Arabic)",
       "url": "https://web.archive.org/web/20250710005755/https://nphies.sa/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "1.1 billion transactions support health transformation: Saudi Health Council 2025 report (Al Watan, Arabic)",
       "url": "https://www.alwatan.com.sa/article/1183044",
       "date": "2026-07-15",
       "publisherClass": "news"
      },
      {
       "title": "Health Sector Transformation Program 2025 report highlights (Ministry of Health news, Arabic)",
       "url": "https://www.moh.gov.sa/ministry/mediacenter/news/pages/news-2026-06-20-001.aspx",
       "date": "2026-06-20",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 54,
     "summary": "The PDPL bars using sensitive data, including health data, for marketing, and SDAIA fined firms in 2026 for marketing without consent. Sehhaty may share data with partners and use masked data for innovation, and no rule on selling de-identified data was found.",
     "sources": [
      {
       "title": "Personal Data Protection Law, Royal Decree M/19 as amended by M/148 (SDAIA Data Governance Platform, Arabic)",
       "url": "https://dgp.sdaia.gov.sa/wps/portal/pdp/knowledgecenter/details/PDPL",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "IS0303 Saudi Health Information Exchange Policies v1.0 (Ministry of Health, National eHealth Strategy and Change Management Office)",
       "url": "https://www.moh.gov.sa/en/Ministry/ehealthstd/Documents/eHealth%20Standards%20Files/Policies/IS0303%20Saudi%20Health%20Information%20Exchange%20Policies%20v1.0.pdf",
       "date": "2015-02-22",
       "publisherClass": "official"
      },
      {
       "title": "SDAIA: penalties on entities that violated the Personal Data Protection Law (Okaz, Arabic)",
       "url": "https://www.okaz.com.sa/local/na/2254837",
       "date": "2026-06-30",
       "publisherClass": "news"
      },
      {
       "title": "Sehhaty Privacy Policy, issue 3.26 (Sehhaty platform, Ministry of Health)",
       "url": "https://sehhaty.sa/pages/privacy-policy-en.html",
       "date": "2025-07-23",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 54,
     "summary": "Clinicians with a treatment relationship can open the unified record, with role-based limits and break-the-glass access, and nphies offers a provider portal and image viewer. No figures on point-of-care use were found, so the cell stays in the mixed band.",
     "sources": [
      {
       "title": "IS0303 Saudi Health Information Exchange Policies v1.0 (Ministry of Health, National eHealth Strategy and Change Management Office)",
       "url": "https://www.moh.gov.sa/en/Ministry/ehealthstd/Documents/eHealth%20Standards%20Files/Policies/IS0303%20Saudi%20Health%20Information%20Exchange%20Policies%20v1.0.pdf",
       "date": "2015-02-22",
       "publisherClass": "official"
      },
      {
       "title": "Sehhaty Privacy Policy, issue 3.26 (Sehhaty platform, Ministry of Health)",
       "url": "https://sehhaty.sa/pages/privacy-policy-en.html",
       "date": "2025-07-23",
       "publisherClass": "official"
      },
      {
       "title": "nphies home page with platform phases (nphies, Internet Archive copy of 10 Jul 2025, Arabic)",
       "url": "https://web.archive.org/web/20250710005755/https://nphies.sa/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 46,
     "summary": "Research may use health data without consent only if identity is removed, and ethics committees approve uses of exchange data case by case. There is no research opt-out and no public register, so two safeguards (ethics review, penalties for misuse) lift a base of 40.",
     "sources": [
      {
       "title": "Personal Data Protection Law, Royal Decree M/19 as amended by M/148 (SDAIA Data Governance Platform, Arabic)",
       "url": "https://dgp.sdaia.gov.sa/wps/portal/pdp/knowledgecenter/details/PDPL",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "IS0303 Saudi Health Information Exchange Policies v1.0 (Ministry of Health, National eHealth Strategy and Change Management Office)",
       "url": "https://www.moh.gov.sa/en/Ministry/ehealthstd/Documents/eHealth%20Standards%20Files/Policies/IS0303%20Saudi%20Health%20Information%20Exchange%20Policies%20v1.0.pdf",
       "date": "2015-02-22",
       "publisherClass": "official"
      },
      {
       "title": "Implementing Regulation of the Law of Ethics of Research on Living Creatures, 3rd edition (National Committee of Bioethics; copy hosted by Prince Sattam bin Abdulaziz University, Arabic)",
       "url": "https://www.psau.edu.sa/drgs//sitesuploads/drgs/2025-10/%D8%A7%D9%84%D9%84%D8%A7%D8%A6%D8%AD%D8%A9%20%D8%A7%D9%84%D8%AA%D9%86%D9%81%D9%8A%D8%B0%D9%8A%D8%A9%20%D9%84%D9%86%D8%B8%D8%A7%D9%85%20%D8%A3%D8%AE%D9%84%D8%A7%D9%82%D9%8A%D8%A7%D8%AA%20%D8%A7%D9%84%D8%A8%D8%AD%D9%88%D8%AB%20%D8%B9%D9%84%D9%89%20%D8%A7%D9%84%D9%85%D8%AE%D9%84%D9%88%D9%82%D8%A7%D8%AA%20%D8%A7%D9%84%D8%AD%D9%8A%D8%A9.pdf",
       "date": "2022",
       "publisherClass": "legal_text"
      },
      {
       "title": "Sehhaty Privacy Policy, issue 3.26 (Sehhaty platform, Ministry of Health)",
       "url": "https://sehhaty.sa/pages/privacy-policy-en.html",
       "date": "2025-07-23",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 58,
     "summary": "SFDA treats AI software as a medical device and its MDS-G010 guidance requires clinical validation, post-market monitoring and change notice. G010 is guidance, the binding change rule was seen only as quoted in it, and SDAIA's AI ethics rules carry no penalties.",
     "sources": [
      {
       "title": "MDS-G010 Guidance on AI and Machine Learning based Medical Devices (Saudi Food and Drug Authority)",
       "url": "https://www.sfda.gov.sa/sites/default/files/2023-01/MDS-G010ML.pdf",
       "date": "2022-11-29",
       "publisherClass": "official"
      },
      {
       "title": "MDS-G27 Guidance on Digital Health Products (Saudi Food and Drug Authority)",
       "url": "https://sfda.gov.sa/sites/default/files/2026-08/MDS-G027_0.pdf",
       "date": "2025-08-10",
       "publisherClass": "official"
      },
      {
       "title": "SFDA grants marketing authorization for AI-powered medical app (Arab News, via SPA)",
       "url": "https://www.arabnews.com/node/2648143/saudi-arabia",
       "date": "2026-06-22",
       "publisherClass": "news"
      },
      {
       "title": "AI Ethics Principles (SDAIA)",
       "url": "https://sdaia.gov.sa/en/SDAIA/about/Documents/ai-principles.pdf",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Personal Data Protection Law (Royal Decree M/19, amended by M/148)",
     "level": "National",
     "year": "2021",
     "what": "Health data is sensitive; access and copy rights; marketing ban for sensitive data; prison and fines.",
     "url": "https://dgp.sdaia.gov.sa/wps/portal/pdp/knowledgecenter/details/PDPL"
    },
    {
     "name": "Implementing Regulation of the Personal Data Protection Law",
     "level": "National",
     "year": "2023",
     "what": "30-day request deadline, electronic copies, 72-hour breach notice, extra health data controls.",
     "url": "https://www.uqn.gov.sa/details?p=23595"
    },
    {
     "name": "IS0303 Saudi Health Information Exchange Policies",
     "level": "National",
     "year": "2015",
     "what": "Opt-out sharing model, disclosure reports, break-the-glass, ethics approval for research, bans market studies.",
     "url": "https://www.moh.gov.sa/en/Ministry/ehealthstd/Documents/eHealth%20Standards%20Files/Policies/IS0303%20Saudi%20Health%20Information%20Exchange%20Policies%20v1.0.pdf"
    },
    {
     "name": "Implementing Regulation of the Law of Ethics of Research on Living Creatures (3rd edition)",
     "level": "National",
     "year": "2022",
     "what": "Informed consent, local ethics committees, exemptions for non-identifiable data, penalties committee.",
     "url": "https://www.psau.edu.sa/drgs//sitesuploads/drgs/2025-10/%D8%A7%D9%84%D9%84%D8%A7%D8%A6%D8%AD%D8%A9%20%D8%A7%D9%84%D8%AA%D9%86%D9%81%D9%8A%D8%B0%D9%8A%D8%A9%20%D9%84%D9%86%D8%B8%D8%A7%D9%85%20%D8%A3%D8%AE%D9%84%D8%A7%D9%82%D9%8A%D8%A7%D8%AA%20%D8%A7%D9%84%D8%A8%D8%AD%D9%88%D8%AB%20%D8%B9%D9%84%D9%89%20%D8%A7%D9%84%D9%85%D8%AE%D9%84%D9%88%D9%82%D8%A7%D8%AA%20%D8%A7%D9%84%D8%AD%D9%8A%D8%A9.pdf"
    },
    {
     "name": "SFDA MDS-G010 Guidance on AI/ML based Medical Devices",
     "level": "National",
     "year": "2022",
     "what": "Clinical validation, post-market monitoring and change notification for AI medical devices.",
     "url": "https://www.sfda.gov.sa/sites/default/files/2023-01/MDS-G010ML.pdf"
    },
    {
     "name": "SFDA MDS-G27 Guidance on Digital Health Products",
     "level": "National",
     "year": "2025",
     "what": "Defines when apps, telemedicine, wearables and AI tools are regulated medical devices.",
     "url": "https://sfda.gov.sa/sites/default/files/2026-08/MDS-G027_0.pdf"
    }
   ],
   "dti": {
    "grade": 75,
    "tier": "Silver",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-09-18",
     "headline": "Ministry penalised practitioners who filmed patients during care and posted the clips",
     "paraphrase": "The paper reported cases documented by the health ministry in which practitioners photographed patients during care and published the images online. In one case the ministry cancelled a licence and imposed a fine.",
     "source": "Al Watan (Saudi Arabia)",
     "url": "https://www.alwatan.com.sa/article/1185817",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2024-11-10",
     "headline": "Health ministry refers practitioners who posted improper clips, including one with an inpatient",
     "paraphrase": "The ministry said it found practitioners posting improper videos on social platforms, one showing a practitioner with a hospital inpatient, and referred them for legal action. It noted rules bar photographing patients outside narrow exceptions.",
     "source": "Okaz",
     "url": "https://www.okaz.com.sa/news/local/2173683",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-05-07",
     "headline": "Patients say hospital call centres abroad asked for their full personal details",
     "paraphrase": "Callers told the paper that hospital booking lines, staffed from outside the kingdom, asked for ID numbers, birth dates and full patient details before sending them to an app. Security specialists warned of leak and misuse risks.",
     "source": "Al Watan",
     "url": "https://www.alwatan.com.sa/article/1180355",
     "theme": "sold_or_shared",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "BRA",
   "name": "Brazil",
   "region": "Americas",
   "overall": 52,
   "rank": "42=",
   "likelyRank": "38 to 44",
   "band": "Mixed",
   "keysModel": "State",
   "confidence": "high",
   "headline": "Brazil's national network holds over 5 billion health records and patients can see part of theirs, but the state decides who else sees them.",
   "categories": {
    "access": {
     "score": 62,
     "summary": "LGPD gives a free right of access with a 15-day deadline, and the national Meu SUS Digital app shows vaccines, exam results, medicines and visit records. It is a partial record: no export was found and patients cannot correct entries themselves.",
     "sources": [
      {
       "title": "Meu SUS Digital: perguntas e respostas, cidadão (Ministério da Saúde)",
       "url": "https://www.gov.br/saude/pt-br/composicao/seidigi/meususdigital/perguntas-e-respostas/cidadao",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Lei 13.709/2018, Lei Geral de Proteção de Dados (texto compilado, Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709compilado.htm",
       "date": "2018-08-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Código de Ética Médica, Resolução CFM 2.217/2018 (CFM)",
       "url": "https://portal.cfm.org.br/images/PDF/cem2019.pdf",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ministério da Saúde inicia jornada para a Nuvem Soberana do SUS (Ministério da Saúde)",
       "url": "https://www.gov.br/saude/pt-br/assuntos/noticias-ms/2026/agosto/ministerio-da-saude-inicia-jornada-para-a-nuvem-soberana-do-sus",
       "date": "2026-08-11",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 35,
     "summary": "Decree 12,560/2025 puts the Ministry of Health in charge of the RNDS and limits clinician access to the care context, but sets no patient consent switch. A published notice offering an opt-out from clinician viewing could not be verified as working today.",
     "sources": [
      {
       "title": "Decreto nº 12.560, de 23 de julho de 2025 (RNDS e Plataformas SUS Digital, Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/decreto/D12560.htm",
       "date": "2025-07-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Implementação de requisitos de privacidade da LGPD e ISO no Conecte SUS (UnB, trabalho de conclusão, reproduz a Nota Informativa)",
       "url": "https://bdm.unb.br/bitstream/10483/39153/1/2023_LucasLopesXavier_tcc.pdf",
       "date": "2023",
       "publisherClass": "academic"
      },
      {
       "title": "Dimensões da privacidade das informações em saúde no Brasil (Direitos Fundamentais & Justiça, n. 47)",
       "url": "https://dfj.emnuvens.com.br/dfj/article/download/1203/1096/5184",
       "date": "2022-12",
       "publisherClass": "academic"
      },
      {
       "title": "Rede Nacional de Dados em Saúde (Ministério da Saúde)",
       "url": "https://www.gov.br/saude/pt-br/composicao/seidigi/rnds",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 58,
     "summary": "LGPD treats health data as sensitive and fines private firms up to R$50 million per violation, but public bodies cannot be fined. The ANPD upheld warnings against the Ministry of Health in December 2025 and opened a case over a 500,000-patient breach in July 2026.",
     "sources": [
      {
       "title": "ANPD instaura processo de sanção contra OS por falha na proteção de dados de 500 mil pacientes (ANPD)",
       "url": "https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-instaura-processo-de-sancao-contra-organizacao-social-por-falha-na-protecao-de-dados-de-500-mil-pacientes-de-unidades-publicas-de-saude",
       "date": "2026-07-08",
       "publisherClass": "official"
      },
      {
       "title": "Processo 00261.001882/2022-73, votos do Conselho Diretor sobre recurso do Ministério da Saúde (ANPD, CD 37/2025)",
       "url": "https://www.gov.br/anpd/pt-br/assuntos/deliberacoes-do-conselho-diretor/circuitos-deliberativos-ano-2025/cd-37-2025-votos.pdf/@@display-file/file",
       "date": "2025-12-24",
       "publisherClass": "official"
      },
      {
       "title": "Lei 13.709/2018, Lei Geral de Proteção de Dados (texto compilado, Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709compilado.htm",
       "date": "2018-08-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Data protection adequacy for non-EU countries (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 55,
     "summary": "The RNDS is the legal national exchange for public and private care and grew to 4.3 billion records by January 2026, over 5 billion by August. Coverage is uneven: hospital, private lab and health plan data are still being added.",
     "sources": [
      {
       "title": "Decreto nº 12.560, de 23 de julho de 2025 (RNDS e Plataformas SUS Digital, Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/decreto/D12560.htm",
       "date": "2025-07-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Resumo executivo, 1ª Reunião Ordinária da Comissão Intergestores Tripartite 2026 (Ministério da Saúde, Conass, Conasems)",
       "url": "https://www.gov.br/saude/pt-br/acesso-a-informacao/gestao-do-sus/articulacao-interfederativa/cit/pautas-de-reunioes-e-resumos/2026/janeiro/resumo-executivo-1a-reuniao-ordinaria-cit.pdf",
       "date": "2026-01-29",
       "publisherClass": "official"
      },
      {
       "title": "Ministério da Saúde inicia jornada para a Nuvem Soberana do SUS (Ministério da Saúde)",
       "url": "https://www.gov.br/saude/pt-br/assuntos/noticias-ms/2026/agosto/ministerio-da-saude-inicia-jornada-para-a-nuvem-soberana-do-sus",
       "date": "2026-08-11",
       "publisherClass": "official"
      },
      {
       "title": "Saúde digital no SUS avança com aumento de telessaúde e registros na RNDS (Futuro da Saúde)",
       "url": "https://futurodasaude.com.br/saude-digital-no-sus-telessaude-rnds/",
       "date": "2026-01-30",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 55,
     "summary": "LGPD bans sharing health data between controllers for economic advantage and bans health plans from using it to select risks. Enforcement is uneven: the ANPD closed a pharmacy data case, while a June 2026 ruling ordered Drogasil to pay R$10 million in collective damages over CPF-for-discount practices.",
     "sources": [
      {
       "title": "Lei 13.709/2018, Lei Geral de Proteção de Dados (texto compilado, Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709compilado.htm",
       "date": "2018-08-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Decreto nº 12.560, de 23 de julho de 2025 (RNDS e Plataformas SUS Digital, Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/decreto/D12560.htm",
       "date": "2025-07-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Compartilhamento de Dados Pessoais (Ministério da Saúde, LGPD)",
       "url": "https://www.gov.br/saude/pt-br/acesso-a-informacao/lgpd/compartilhamento-de-dados-pessoais",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Juiz proíbe Drogasil de exigir CPF de clientes para dar descontos (Conjur)",
       "url": "https://conjur.com.br/2026-jun-02/farmacias-nao-podem-exigir-dados-pessoais-de-clientes-na-oferta-de-descontos/",
       "date": "2026-06-02",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 50,
     "summary": "SUS Digital Profissional, announced in July 2024, lets clinicians open a patient's RNDS history during care anywhere in the country, limited by decree to the care context. The view covers encounters, medicines, vaccines and exams, not full clinical notes.",
     "sources": [
      {
       "title": "Decreto nº 12.560, de 23 de julho de 2025 (RNDS e Plataformas SUS Digital, Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/decreto/D12560.htm",
       "date": "2025-07-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Profissionais do SUS terão acesso a prontuário unificado de pacientes (Agência Brasil)",
       "url": "https://agenciabrasil.ebc.com.br/saude/noticia/2024-07/profissionais-do-sus-terao-acesso-a-prontuario-unificado-de-pacientes",
       "date": "2024-07-16",
       "publisherClass": "news"
      },
      {
       "title": "Resumo executivo, 1ª Reunião Ordinária da Comissão Intergestores Tripartite 2026 (Ministério da Saúde, Conass, Conasems)",
       "url": "https://www.gov.br/saude/pt-br/acesso-a-informacao/gestao-do-sus/articulacao-interfederativa/cit/pautas-de-reunioes-e-resumos/2026/janeiro/resumo-executivo-1a-reuniao-ordinaria-cit.pdf",
       "date": "2026-01-29",
       "publisherClass": "official"
      },
      {
       "title": "SUS Digital recebeu da saúde suplementar 2 bilhões de dados (Mobile Time)",
       "url": "https://www.mobiletime.com.br/noticias/28/01/2026/saude-sus-dados-enviados/",
       "date": "2026-01-28",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Research bodies may use RNDS and other health data without individual consent under LGPD Article 13, with no general opt-out. Safeguards are real: ethics committees under Law 14,874/2024, secure environments, a ban on transfer to third parties and a public register of Ministry data sharing.",
     "sources": [
      {
       "title": "Lei 13.709/2018, Lei Geral de Proteção de Dados (texto compilado, Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709compilado.htm",
       "date": "2018-08-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Lei nº 14.874, de 28 de maio de 2024, pesquisa com seres humanos (Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2024/lei/L14874.htm",
       "date": "2024-05-28",
       "publisherClass": "legal_text"
      },
      {
       "title": "Decreto nº 12.651, de 7 de outubro de 2025, regulamenta a Lei 14.874 (Planalto)",
       "url": "https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/decreto/D12651.htm",
       "date": "2025-10-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Compartilhamento de Dados Pessoais (Ministério da Saúde, LGPD)",
       "url": "https://www.gov.br/saude/pt-br/acesso-a-informacao/lgpd/compartilhamento-de-dados-pessoais",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 57,
     "summary": "Anvisa regulates AI software as a medical device under RDC 657/2022, requiring disclosure of training data and prior approval of significant algorithm changes. CFM Resolution 2,454/2026, in force since August 2026, requires human final decisions and telling patients when AI is used.",
     "sources": [
      {
       "title": "Software como Dispositivo Médico: perguntas e respostas sobre a RDC 657/2022 (Anvisa)",
       "url": "https://www.gov.br/anvisa/pt-br/centraisdeconteudo/publicacoes/produtos-para-a-saude/manuais/software-como-dispositivo-medico-perguntas-e-respostas/@@download/file",
       "date": "2022-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Resolução CFM nº 2.454/2026, normatiza o uso da inteligência artificial na medicina (CFM)",
       "url": "https://sistemas.cfm.org.br/normas/arquivos/resolucoes/BR/2026/2454_2026.pdf",
       "date": "2026-02-27",
       "publisherClass": "official"
      },
      {
       "title": "Norma de IA do CFM chega cercada de dúvidas e desafios de implementação (Futuro da Saúde)",
       "url": "https://futurodasaude.com.br/resolucao-cfm-inteligencia-artificial/",
       "date": "2026-08-19",
       "publisherClass": "news"
      },
      {
       "title": "UE avança na regulação de IA enquanto projeto brasileiro segue parado na Câmara (*desinformante)",
       "url": "https://desinformante.com.br/ue-avanca-regulacao-ia-projeto-brasileiro-parado/",
       "date": "2026-08-12",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Lei Geral de Proteção de Dados (Lei 13.709)",
     "level": "National",
     "year": "2018",
     "what": "Health data is sensitive; free access rights; bans sharing for economic advantage and plan risk selection.",
     "url": "https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709compilado.htm"
    },
    {
     "name": "Decreto 12.560 (RNDS and SUS Digital platforms)",
     "level": "National",
     "year": "2025",
     "what": "Makes the RNDS the national health data exchange; limits uses; restricts clinician access to care context.",
     "url": "https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/decreto/D12560.htm"
    },
    {
     "name": "Lei 13.787 (digital patient records)",
     "level": "National",
     "year": "2018",
     "what": "Rules for digitising records; keep at least 20 years; records may be returned to the patient.",
     "url": "http://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13787.htm"
    },
    {
     "name": "Lei 14.874 (research with human beings)",
     "level": "National",
     "year": "2024",
     "what": "National research ethics system; written informed consent; withdrawal at any time.",
     "url": "https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2024/lei/L14874.htm"
    },
    {
     "name": "Anvisa RDC 657/2022 (software as a medical device)",
     "level": "National",
     "year": "2022",
     "what": "Regulates medical software including AI; significant algorithm changes need approval before market.",
     "url": "https://www.gov.br/anvisa/pt-br/centraisdeconteudo/publicacoes/produtos-para-a-saude/manuais/software-como-dispositivo-medico-perguntas-e-respostas/@@download/file"
    },
    {
     "name": "Resolução CFM 2.454 (AI in medicine)",
     "level": "National",
     "year": "2026",
     "what": "Doctors keep final decisions, record AI use, inform patients; institutions classify AI risk.",
     "url": "https://sistemas.cfm.org.br/normas/arquivos/resolucoes/BR/2026/2454_2026.pdf"
    }
   ],
   "dti": {
    "grade": 85,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-12-24",
     "headline": "Regulator upholds warnings against Health Ministry over exposed health data",
     "paraphrase": "A flaw in a federal health system exposed people's health data. The Ministry of Health told those affected only months later and incompletely. The data authority issued two warnings with corrective orders and rejected the ministry's appeal.",
     "source": "Autoridade Nacional de Proteção de Dados (ANPD), Voto nº 47/2025/DIR-IM/CD",
     "url": "https://www.gov.br/anpd/pt-br/assuntos/deliberacoes-do-conselho-diretor/circuitos-deliberativos-ano-2025/cd-37-2025-votos.pdf/@@display-file/file",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-07-08",
     "headline": "Regulator opens case after attack on health operator affecting 500,000 patients' records",
     "paraphrase": "A ransomware attack on an organisation running public health units in several states affected records of about 500,000 patients. The data authority opened a sanction case, citing poor notice to those affected. The operator denies any data leaked.",
     "source": "CNN Brasil",
     "url": "https://www.cnnbrasil.com.br/nacional/brasil/anpd-investiga-ataque-cibernetico-que-vazou-dados-de-500-mil-pacientes/",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-05-28",
     "headline": "Court upholds damages after a patient's test details appeared in internet search",
     "paraphrase": "Data about a woman's medical test could be opened directly from a major search engine, with no password. A Santa Catarina court found two clinics failed to protect it and upheld R$5,000 in damages, ordering the data removed.",
     "source": "Consultor Jurídico (ConJur)",
     "url": "https://conjur.com.br/2026-mai-28/tj-sc-manda-clinica-indenizar-paciente-por-exposicao-de-dados-sensiveis/",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2024-12-16",
     "headline": "Pharmacy chain fined R$8.4 million for demanding customers' tax ID at checkout",
     "paraphrase": "Minas Gerais consumer authority Procon fined a pharmacy chain over stores requiring customers' CPF at the counter. The decision warned hidden profiling of purchases could expose medicine records, for example to insurers refusing cover.",
     "source": "Hoje em Dia",
     "url": "https://www.hojeemdia.com.br/minas/droga-raia-e-multada-em-r-8-4-milh-es-por-exigir-cpf-de-cliente-na-hora-da-compra-em-bh-1.1044784",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2024-12-18",
     "headline": "Nurse technician fired for opening a colleague's medical record 18 times",
     "paraphrase": "A hospital nursing technician opened the record of her former husband's wife 18 times, though she was not caring for her, over personal disputes. A labour court in Rio Grande do Sul upheld her dismissal for cause.",
     "source": "Tribunal Regional do Trabalho da 4ª Região (Rio Grande do Sul)",
     "url": "https://www.trt4.jus.br/portais/trt4/modulos/noticias/50725782",
     "theme": "breach",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "CAN",
   "name": "Canada",
   "region": "Americas",
   "overall": 52,
   "rank": "42=",
   "likelyRank": "38 to 44",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Provinces grant record access and Quebec and Ontario allow blocking, but records stop at provincial borders and only 13% see core records online.",
   "categories": {
    "access": {
     "score": 50,
     "summary": "Provincial laws give a right to a copy, and the largest provinces run portals with labs and medications. But in 2025 only 13% of adults could see test results, vaccines and medication history online, and Quebec holds results back 30 days.",
     "sources": [
      {
       "title": "Personal Health Information Protection Act, 2004 (Ontario e-Laws)",
       "url": "https://www.ontario.ca/laws/statute/04p03",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Comment les Canadiens accèdent-ils aux services de santé numériques? (How Canadians access digital health services, CIHI)",
       "url": "https://www.cihi.ca/fr/information-numerique-sur-la-sante-au-canada-mesure-de-lacces-et-de-lutilisation/le-point-de-vue-des-canadiens",
       "date": "2026-07-23",
       "publisherClass": "official"
      },
      {
       "title": "Health Gateway (Government of British Columbia)",
       "url": "https://www2.gov.bc.ca/gov/content/health/managing-your-health/health-gateway",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Québec poursuivi pour son Carnet santé (Quebec sued over its Carnet santé, La Presse)",
       "url": "https://www.lapresse.ca/actualites/2026-03-02/quebec-poursuivi-pour-son-carnet-sante.php",
       "date": "2026-03-02",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 55,
     "summary": "Control depends on the province. Quebec lets patients block named providers or categories from chosen items and shows an access log in Carnet santé, while Ontario cut its EHR blocks to whole repositories in February 2026 and gives logs only on request.",
     "sources": [
      {
       "title": "Limiter l'accès aux renseignements de santé et de services sociaux (Limiting access to health information, Gouvernement du Québec)",
       "url": "https://www.quebec.ca/sante/vos-informations-de-sante/loi-renseignements-sante-services-sociaux",
       "date": "2024-07-01",
       "publisherClass": "official"
      },
      {
       "title": "Carnet santé Québec (Gouvernement du Québec)",
       "url": "https://www.quebec.ca/sante/vos-informations-de-sante/carnet-sante-quebec",
       "date": "2026-01-28",
       "publisherClass": "official"
      },
      {
       "title": "Memo: Important Changes to Consent Management in the Electronic Health Record (Ontario Health)",
       "url": "https://www.ontariohealth.ca/news/memo-changes-consent-management-electronic-health-record.html",
       "date": "2026-02-25",
       "publisherClass": "official"
      },
      {
       "title": "Electronic Health Record Request for Access to Personal Health Information policy (Ontario Health)",
       "url": "https://ontariohealth.ca/about/privacy/resources/ehr-request-access-phi.html",
       "date": "2026-08-10",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 58,
     "summary": "Health data has dedicated provincial laws, and Ontario's regulator now fines snoopers. But Ontario logged 785 health breaches in 2025, and the federal commissioner still cannot order compliance; reform with fines up to 3% of global revenue sits at first reading.",
     "sources": [
      {
       "title": "2025 Annual Report: Statistics (IPC Ontario)",
       "url": "https://www.ipc.on.ca/en/2025-annual-report/statistics",
       "date": "2026",
       "publisherClass": "official"
      },
      {
       "title": "IPC issues third administrative monetary penalty under Ontario's health privacy law (IPC Ontario)",
       "url": "https://www.ipc.on.ca/en/decisions/ipc-issues-third-administrative-monetary-penalty-under-ontarios-health-privacy-law",
       "date": "2026-08-26",
       "publisherClass": "official"
      },
      {
       "title": "Third Time's the Charm? Canada's Latest Approach to Reform the Federal Private-Sector Privacy Framework (Blakes)",
       "url": "https://www.blakes.com/insights/third-time-s-the-charm-canada-s-latest-approach-to-reform-the-federal-private-sector-privacy-framew/",
       "date": "2026-09-25",
       "publisherClass": "law_firm"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 50,
     "summary": "Each province links labs, drugs and hospital reports in its own system, but records do not cross provincial lines. In 2024 only 52% of providers shared patient data electronically outside their workplace, from 72% in Alberta to 36% in Quebec.",
     "sources": [
      {
       "title": "Enquête sur l'utilisation des technologies numériques par les fournisseurs de soins de santé, 2025 (Survey on health providers' use of digital technology, Statistics Canada)",
       "url": "https://www150.statcan.gc.ca/n1/daily-quotidien/260330/dq260330b-fra.htm",
       "date": "2026-03-30",
       "publisherClass": "official"
      },
      {
       "title": "Patient Access to Digital Health Services (Ontario Health)",
       "url": "https://ontariohealth.ca/digital/programs-services/patient-access-digital-health.html",
       "date": "2026-06-04",
       "publisherClass": "official"
      },
      {
       "title": "Le point de vue des dispensateurs de soins de santé (The providers' perspective, CIHI)",
       "url": "https://www.cihi.ca/fr/information-numerique-sur-la-sante-au-canada-mesure-de-lacces-et-de-lutilisation/le-point-de-vue-des-dispensateurs-de-soins-de-sante",
       "date": "2026-07-23",
       "publisherClass": "official"
      },
      {
       "title": "S-5 (45-1), Connected Care for Canadians Act, LEGISinfo (Parliament of Canada)",
       "url": "https://www.parl.ca/legisinfo/en/bill/45-1/s-5",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 45,
     "summary": "Ontario's PHIPA bars use of health data for marketing without express consent. Yet a 2025 study found clinic chains and data brokers turning primary care records into products for drug makers, and the federal regulator cannot fine.",
     "sources": [
      {
       "title": "Personal Health Information Protection Act, 2004 (Ontario e-Laws)",
       "url": "https://www.ontario.ca/laws/statute/04p03",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Millions of Canadians' health data available for sale to pharmaceutical industry, study shows (CBC News)",
       "url": "https://www.cbc.ca/news/health/health-data-records-pharmaceutical-private-clinics-1.7529955",
       "date": "2025-05-09",
       "publisherClass": "news"
      },
      {
       "title": "The quiet commercialization of primary care records (Healthy Debate)",
       "url": "https://healthydebate.ca/2026/01/topic/the-quiet-commercialization-of-primary-care-records/",
       "date": "2026-01-20",
       "publisherClass": "news"
      },
      {
       "title": "Résumé de l'enquête conjointe sur l'atteinte chez 23andMe (Joint 23andMe breach investigation summary, OPC)",
       "url": "https://www.priv.gc.ca/fr/nouvelles-du-commissariat/nouvelles-et-annonces/2025/info_23andme_250617/",
       "date": "2025-06-17",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 55,
     "summary": "Clinicians in most provinces can open a provincial viewer with labs, drugs and hospital reports. But 17% of providers said in 2025 that barriers stop them using outside records, and nothing follows a patient across provinces.",
     "sources": [
      {
       "title": "What's an EHR? (eHealth Ontario / Ontario Health)",
       "url": "https://ehealthontario.on.ca/en/patients-and-families/ehrs-explained",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Enquête sur l'utilisation des technologies numériques par les fournisseurs de soins de santé, 2025 (Survey on health providers' use of digital technology, Statistics Canada)",
       "url": "https://www150.statcan.gc.ca/n1/daily-quotidien/260330/dq260330b-fra.htm",
       "date": "2026-03-30",
       "publisherClass": "official"
      },
      {
       "title": "Le point de vue des dispensateurs de soins de santé (The providers' perspective, CIHI)",
       "url": "https://www.cihi.ca/fr/information-numerique-sur-la-sante-au-canada-mesure-de-lacces-et-de-lutilisation/le-point-de-vue-des-dispensateurs-de-soins-de-sante",
       "date": "2026-07-23",
       "publisherClass": "official"
      },
      {
       "title": "Dossier santé numérique: un départ chaotique lundi matin (Digital health record: a chaotic Monday start, La Presse)",
       "url": "https://www.lapresse.ca/actualites/sante/2026-05-11/dossier-sante-numerique/un-depart-chaotique-lundi-matin.php",
       "date": "2026-05-11",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "Identifiable health data can be used for research without consent once an ethics board or Quebec's access centre approves. There is no general opt-out; ethics review, statutory penalties and a Quebec right to refuse research contact lift the cell to 49.",
     "sources": [
      {
       "title": "Personal Health Information Protection Act, 2004 (Ontario e-Laws)",
       "url": "https://www.ontario.ca/laws/statute/04p03",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "EPTC 2 (2022), chapitre 5: Vie privée et confidentialité (TCPS 2 Chapter 5, Panel on Research Ethics)",
       "url": "https://ethics.gc.ca/fra/tcps2-eptc2_2022_chapter5-chapitre5.html",
       "date": "2022",
       "publisherClass": "official"
      },
      {
       "title": "Accès aux renseignements de santé et de services sociaux par les chercheurs (Researcher access to health information, Gouvernement du Québec)",
       "url": "https://www.quebec.ca/sante/professionnels/encadrement-recherche-participants-humains/acces-renseignements-sante-services-sociaux-chercheurs-recherche",
       "date": "2026-01-27",
       "publisherClass": "official"
      },
      {
       "title": "Limiter l'accès aux renseignements de santé et de services sociaux (Limiting access to health information, Gouvernement du Québec)",
       "url": "https://www.quebec.ca/sante/vos-informations-de-sante/loi-renseignements-sante-services-sociaux",
       "date": "2024-07-01",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 56,
     "summary": "Health Canada licenses machine learning medical devices and lets makers pre-authorize planned changes through change control plans. Canada has no AI statute: Bill C-36 has no stand-alone AI rules, and Ontario's 2024 digital trust law has no AI regulation in force.",
     "sources": [
      {
       "title": "Pre-market guidance for machine learning-enabled medical devices (Health Canada)",
       "url": "https://www.canada.ca/en/health-canada/services/drugs-health-products/medical-devices/application-information/guidance-documents/pre-market-guidance-machine-learning-enabled-medical-devices.html",
       "date": "2026-04-01",
       "publisherClass": "official"
      },
      {
       "title": "Bill C-36: A Third Attempt at Federal Private-Sector Privacy Reform (Fasken)",
       "url": "https://www.fasken.com/en/knowledge/2026/06/bill-c-36",
       "date": "2026-06-18",
       "publisherClass": "law_firm"
      },
      {
       "title": "Enhancing Digital Security and Trust Act (Government of Ontario)",
       "url": "http://www.ontario.ca/page/enhancing-digital-security-and-trust-act",
       "date": "2026-05-07",
       "publisherClass": "official"
      },
      {
       "title": "IPC releases new guidance on AI scribes to help protect patient privacy (IPC Ontario)",
       "url": "https://www.ipc.on.ca/en/media-centre/news-releases/ipc-releases-new-guidance-ai-scribes-help-protect-patient-privacy",
       "date": "2026-01-28",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Personal Information Protection and Electronic Documents Act (PIPEDA)",
     "level": "National",
     "year": "2000",
     "what": "Consent-based private-sector privacy law; four provinces have health laws deemed substantially similar.",
     "url": "https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/"
    },
    {
     "name": "Personal Health Information Protection Act (PHIPA), Ontario",
     "level": "State/Provincial",
     "year": "2004",
     "what": "Access within 30 days at cost recovery, marketing needs express consent, EHR access logging, fines up to $1 million.",
     "url": "https://www.ontario.ca/laws/statute/04p03"
    },
    {
     "name": "Loi sur les renseignements de santé et de services sociaux (LRSSS), Quebec",
     "level": "State/Provincial",
     "year": "2023",
     "what": "Right to restrict named providers, know who accessed records, and controlled researcher access.",
     "url": "https://www.legisquebec.gouv.qc.ca/fr/document/lc/R-22.1"
    },
    {
     "name": "Bill S-5, Connected Care for Canadians Act",
     "level": "National",
     "year": "2026",
     "what": "Would mandate interoperability standards and ban vendor data blocking. Passed Senate; not yet law.",
     "url": "https://www.parl.ca/legisinfo/en/bill/45-1/s-5"
    },
    {
     "name": "Bill C-36, Protecting Privacy and Consumer Data Act",
     "level": "National",
     "year": "2026",
     "what": "Would replace PIPEDA's privacy part, define health data as sensitive, add penalties. First reading only.",
     "url": "https://www.parl.ca/documentviewer/fr/45-1/projet-loi/C-36/premiere-lecture"
    },
    {
     "name": "Pre-market guidance for machine learning-enabled medical devices (Health Canada)",
     "level": "National",
     "year": "2026",
     "what": "Licensing expectations for ML devices, including predetermined change control plans and transparency.",
     "url": "https://www.canada.ca/en/health-canada/services/drugs-health-products/medical-devices/application-information/guidance-documents/pre-market-guidance-machine-learning-enabled-medical-devices.html"
    },
    {
     "name": "Enhancing Digital Security and Trust Act, 2024 (Ontario)",
     "level": "State/Provincial",
     "year": "2024",
     "what": "Public sector cyber rules, including hospitals, in force July 2026; AI rules not yet made.",
     "url": "http://www.ontario.ca/page/enhancing-digital-security-and-trust-act"
    }
   ],
   "dti": {
    "grade": 85,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-03-19",
     "headline": "Doctor did not answer a patient's request for their own health record",
     "paraphrase": "A patient in Ontario asked their doctor for access to their health information and got no reply within the legal time limit. The commissioner treated the silence as a refusal and ordered the doctor to respond.",
     "source": "Information and Privacy Commissioner of Ontario (PHIPA Decision 332)",
     "url": "https://www.ipc.on.ca/en/decisions/latest-decisions/phipa-decision-332",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2026-02-06",
     "headline": "Health authority ordered to release withheld lines from a patient's own hospital record",
     "paraphrase": "A patient in British Columbia asked for her own hospital records. The health authority released them but blacked out three sentences. The commissioner found no good reason to withhold them and ordered them disclosed.",
     "source": "Office of the Information and Privacy Commissioner for British Columbia (Order F26-09)",
     "url": "https://www.oipc.bc.ca/documents/orders/3088",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2025-03-31",
     "headline": "Health worker looked into 70 people's records; patients not properly told",
     "paraphrase": "An employee opened the electronic health records of 70 people in Saskatchewan 210 times without a work reason. The commissioner found the health authority did not contain the breach properly or tell those affected enough.",
     "source": "Office of the Saskatchewan Information and Privacy Commissioner (Investigation Report 266-2024, 031-2025)",
     "url": "https://oipc.sk.ca/assets/hipa-investigation_266-2024-031-2025.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-04-29",
     "headline": "Hospital network kept failing to stop staff opening patients' records, watchdog finds",
     "paraphrase": "Ontario's privacy commissioner found several workers at an Ontario hospital network opened patient records without authority between 2023 and 2025. In one breach up to 326 patients were affected, and some were not told for ten months.",
     "source": "CBC News",
     "url": "https://www.cbc.ca/news/canada/toronto/lakeridge-health-failed-to-protect-patients-medical-records-9.7182011",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-05-21",
     "headline": "Unions say every Quebec health worker in one region can open any patient's record",
     "paraphrase": "Health unions in a Quebec region said the new digital health record lets workers of every job type, including those not giving care, open the records of all patients in the region, and asked for the rollout to pause.",
     "source": "Radio-Canada",
     "url": "https://ici.radio-canada.ca/nouvelle/2255476/preoccupations-syndicales-dsn-donnees-personnelles",
     "theme": "other",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "THA",
   "name": "Thailand",
   "region": "Asia",
   "overall": 52,
   "rank": "42=",
   "likelyRank": "39 to 45",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "Thais can choose which hospitals share their records through Health Link, but sign-up is optional and ministry data flows without a choice.",
   "categories": {
    "access": {
     "score": 50,
     "summary": "The PDPA gives a right to a copy within 30 days, and Health Link on the Paotang and Tang Rat apps lets opted-in users see treatment and claims history. Only about 30,129 people had viewed records on Tang Rat by April 2026, and hospitals charge for copies.",
     "sources": [
      {
       "title": "Personal Data Protection Act B.E. 2562 (2019), unofficial translation (Ministry of Digital Economy and Society)",
       "url": "https://www.mdes.go.th/law/detail/3577-Personal-Data-Protection-Act-B-E--2562--2019-",
       "date": "2019-05-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "BDI, NHSO and DGA sign MOU to upgrade Health Link nationwide (Thansettakij)",
       "url": "https://www.thansettakij.com/health-wellness/657666",
       "date": "2026-04-27",
       "publisherClass": "news"
      },
      {
       "title": "BDI says Tang Rat and Health Link only display data and never edit it (Thansettakij)",
       "url": "https://www.thansettakij.com/health-wellness/665340",
       "date": "2026-07-31",
       "publisherClass": "news"
      },
      {
       "title": "Requesting copies of medical records and service fees (Ramathibodi Hospital, Mahidol University)",
       "url": "https://www.rama.mahidol.ac.th/medicalrecord/th/prepare_doc_for_copy",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 50,
     "summary": "Health Link is opt-in: a person chooses which hospitals may share, some hospitals ask for consent each time, and consent can be withdrawn at any time. Ministry of Public Health data flows to its cloud without a verified choice, and no patient-visible access log was verified.",
     "sources": [
      {
       "title": "Health Link: Thailand's health data linking system (Government Public Relations Department)",
       "url": "https://itcenter.prd.go.th/th/content/article/detail/id/8/iid/335512",
       "date": "2024-10-29",
       "publisherClass": "official"
      },
      {
       "title": "Health Link: getting to know the health data link on Paotang (Government Public Relations Department)",
       "url": "https://www.prd.go.th/th/content/category/detail/id/31/iid/505311",
       "date": "2026-05-21",
       "publisherClass": "official"
      },
      {
       "title": "Personal Data Protection Act B.E. 2562 (2019), unofficial translation (Ministry of Digital Economy and Society)",
       "url": "https://www.mdes.go.th/law/detail/3577-Personal-Data-Protection-Act-B-E--2562--2019-",
       "date": "2019-05-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Mor Prom revived: from vaccine app to national health Super App (Thai PBS Policy Watch)",
       "url": "https://policywatch.thaipbs.or.th/article/life-243",
       "date": "2026-01-11",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 55,
     "summary": "The PDPA makes health data sensitive, requires breach notice within 72 hours and allows fines up to 5 million baht. The regulator fined a private hospital 1.21 million baht in 2025 after over 1,000 medical records leaked.",
     "sources": [
      {
       "title": "Personal Data Protection Act B.E. 2562 (2019), unofficial translation (Ministry of Digital Economy and Society)",
       "url": "https://www.mdes.go.th/law/detail/3577-Personal-Data-Protection-Act-B-E--2562--2019-",
       "date": "2019-05-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "PDPC fines a large private hospital 1.2 million baht over leaked medical records (Thai PBS)",
       "url": "https://www.thaipbs.or.th/news/content/354970",
       "date": "2025-08-01",
       "publisherClass": "news"
      },
      {
       "title": "Key takeaways from Thailand's Data Privacy Day 2026 (Tilleke & Gibbins)",
       "url": "https://www.tilleke.com/insights/key-takeaways-from-thailands-data-privacy-day-2026/",
       "date": "2026-01-30",
       "publisherClass": "law_firm"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "journey": {
     "score": 57,
     "summary": "Health Link and the health ministry's Mor Prom and cloud systems together aim to link about 15,000 to 20,000 facilities, including clinics and pharmacies. The two systems are still being joined, and a Digital Health Act is only in drafting.",
     "sources": [
      {
       "title": "Health Link: Thailand's health data linking system (Government Public Relations Department)",
       "url": "https://itcenter.prd.go.th/th/content/article/detail/id/8/iid/335512",
       "date": "2024-10-29",
       "publisherClass": "official"
      },
      {
       "title": "BDI puts Health Link, linking about 20,000 facilities, on the Tang Rat app (MGR Online)",
       "url": "https://mgronline.com/cyberbiz/detail/9690000039578",
       "date": "2026-04-27",
       "publisherClass": "news"
      },
      {
       "title": "Mor Prom revived: from vaccine app to national health Super App (Thai PBS Policy Watch)",
       "url": "https://policywatch.thaipbs.or.th/article/life-243",
       "date": "2026-01-11",
       "publisherClass": "news"
      },
      {
       "title": "NHCO briefs parliament on health data, Section 7 and digital health governance (National Health Commission Office)",
       "url": "https://www.nationalhealth.or.th/public/index.php/NHCO/367",
       "date": "2026-09-24",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 45,
     "summary": "Health data needs explicit consent and cannot be reused beyond its purpose, and people can object to direct marketing. No specific ban on selling de-identified health data was found, and the health ministry plans to draw value from linked data with tech partners.",
     "sources": [
      {
       "title": "Personal Data Protection Act B.E. 2562 (2019), unofficial translation (Ministry of Digital Economy and Society)",
       "url": "https://www.mdes.go.th/law/detail/3577-Personal-Data-Protection-Act-B-E--2562--2019-",
       "date": "2019-05-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Key takeaways from Thailand's Data Privacy Day 2026 (Tilleke & Gibbins)",
       "url": "https://www.tilleke.com/insights/key-takeaways-from-thailands-data-privacy-day-2026/",
       "date": "2026-01-30",
       "publisherClass": "law_firm"
      },
      {
       "title": "Health ministry pushes Mor Prom as national health data hub; 18,052 record complaints (Bangkok Biz News)",
       "url": "https://www.bangkokbiznews.com/health/public-health/1247304",
       "date": "2026-08-14",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 50,
     "summary": "With the patient's consent, doctors at linked facilities can see diagnoses, medicines and lab results from other providers through Health Link, and emergency doctors can search records of unconscious patients. Opt-in sign-up and data errors limit how complete the view is.",
     "sources": [
      {
       "title": "Health Link: Thailand's health data linking system (Government Public Relations Department)",
       "url": "https://itcenter.prd.go.th/th/content/article/detail/id/8/iid/335512",
       "date": "2024-10-29",
       "publisherClass": "official"
      },
      {
       "title": "Health Link: getting to know the health data link on Paotang (Government Public Relations Department)",
       "url": "https://www.prd.go.th/th/content/category/detail/id/31/iid/505311",
       "date": "2026-05-21",
       "publisherClass": "official"
      },
      {
       "title": "BDI, NHSO and DGA sign MOU to upgrade Health Link nationwide (Thansettakij)",
       "url": "https://www.thansettakij.com/health-wellness/657666",
       "date": "2026-04-27",
       "publisherClass": "news"
      },
      {
       "title": "Health ministry pushes Mor Prom as national health data hub; 18,052 record complaints (Bangkok Biz News)",
       "url": "https://www.bangkokbiznews.com/health/public-health/1247304",
       "date": "2026-08-14",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "The PDPA allows health data to be used for research without consent if safeguards set by the regulator apply, and there is no general opt-out. Trials need written consent under the National Health Act, and people may object to research use case by case.",
     "sources": [
      {
       "title": "Personal Data Protection Act B.E. 2562 (2019), unofficial translation (Ministry of Digital Economy and Society)",
       "url": "https://www.mdes.go.th/law/detail/3577-Personal-Data-Protection-Act-B-E--2562--2019-",
       "date": "2019-05-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "National Health Act B.E. 2550 (2007), Thai text (Department of Medical Services)",
       "url": "https://www.dms.go.th/backend/Content/Content_File/Information_Center/Attach/25621124013609AM_17.pdf",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "PDPC Notification on safeguards for research and statistics under sections 24(1) and 26(5)(d), B.E. 2566 (text mirror, SiData)",
       "url": "https://pdpa.sidata.plus/reference-article-26-5",
       "date": "undated",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "PDPA subordinate laws list, including the PDPC research safeguards notification (Chiang Mai University)",
       "url": "https://privacy.cmu.ac.th/%E0%B8%9E%E0%B8%A3%E0%B8%B0%E0%B8%A3%E0%B8%B2%E0%B8%8A%E0%B8%9A%E0%B8%B1%E0%B8%8D%E0%B8%8D%E0%B8%B1%E0%B8%95%E0%B8%B4%E0%B9%81%E0%B8%A5%E0%B8%B0%E0%B8%81%E0%B8%8E%E0%B8%AB%E0%B8%A1%E0%B8%B2%E0%B8%A2/",
       "date": "2025-06-13",
       "publisherClass": "academic"
      }
     ]
    },
    "ai": {
     "score": 55,
     "summary": "Medical AI must be registered as a device, and Thai FDA guidance from 2024 says it must disclose training data and must not replace clinical judgment. Limits on continuous learning are only advice, and a general AI Act is still a draft.",
     "sources": [
      {
       "title": "Guidance manual on regulating software and AI as medical devices (Thai FDA Medical Device Control Division)",
       "url": "https://medical.fda.moph.go.th/media.php?id=616254428592349184&name=Non-IVD_G_SMD_01_Guidance_SaMD.pdf",
       "date": "2024-10",
       "publisherClass": "official"
      },
      {
       "title": "Regulation of software and AI as medical devices (Thai FDA Medical Device Control Division)",
       "url": "https://medical.fda.moph.go.th/samd-head",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "AI push for the economy; business watches new AI law (Thairath)",
       "url": "https://www.thairath.co.th/money/economics/thai_economics/2958310",
       "date": "2026-09-09",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Personal Data Protection Act B.E. 2562",
     "level": "National",
     "year": "2019",
     "what": "Health is sensitive data needing explicit consent; access within 30 days; 72-hour breach notice; research exception.",
     "url": "https://www.mdes.go.th/law/detail/3577-Personal-Data-Protection-Act-B-E--2562--2019-"
    },
    {
     "name": "National Health Act B.E. 2550",
     "level": "National",
     "year": "2007",
     "what": "Health information is confidential (s.7); written consent before research experiments (s.9); jail or fine.",
     "url": "https://www.dms.go.th/backend/Content/Content_File/Information_Center/Attach/25621124013609AM_17.pdf"
    },
    {
     "name": "Declaration of Patients' Rights and Duties",
     "level": "National",
     "year": "2015",
     "what": "Professional councils' declaration: patients may see their own medical record information on request.",
     "url": "https://www.pharmacycouncil.org/index.php?option=content_detail&view=detail&itemid=648&catid=1"
    },
    {
     "name": "PDPC Notification on safeguards for research and statistics",
     "level": "National",
     "year": "2023",
     "what": "Sets security, ethics and pseudonymisation safeguards for research use of data without consent.",
     "url": "https://pdpa.sidata.plus/reference-article-26-5"
    },
    {
     "name": "Medical Device Act B.E. 2551 (amended 2019)",
     "level": "National",
     "year": "2008",
     "what": "Basis for Thai FDA registration of software and AI as medical devices.",
     "url": "https://medical.fda.moph.go.th/media.php?id=616254428592349184&name=Non-IVD_G_SMD_01_Guidance_SaMD.pdf"
    },
    {
     "name": "Digital Health Act (draft, not enacted)",
     "level": "National",
     "year": "2025",
     "what": "Draft central law for exchanging digital health data; framework agreed October 2025, not enacted.",
     "url": "https://techsauce.co/healthtech/thai-digital-health-integration-healthlink"
    },
    {
     "name": "Artificial Intelligence Act (draft, not enacted)",
     "level": "National",
     "year": "2026",
     "what": "Draft risk-based AI law under review after public consultation as of September 2026.",
     "url": "https://www.thairath.co.th/money/economics/thai_economics/2958310"
    }
   ],
   "dti": {
    "grade": 78,
    "tier": "Silver",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-08-02",
     "headline": "Hospital fined after patient record pages sent for destruction leaked as snack bags",
     "paraphrase": "A large private hospital hired a small contractor to destroy patient records but did not oversee the work. Over 1,000 record pages leaked and were reused as snack bags. The regulator fined the hospital and the contractor.",
     "source": "Office of the Personal Data Protection Committee, via Government Public Relations Department",
     "url": "https://www.prd.go.th/th/content/category/detail/id/39/iid/411380",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-08-29",
     "headline": "Health ministry admits staff errors put false entries in citizens' national health app records",
     "paraphrase": "Over 9,000 people flagged more than 24,000 entries in their national health app history as wrong. The ministry told a parliamentary committee about a quarter of checked entries were staff data-entry errors and others reflected performance targets, not care given.",
     "source": "The Standard",
     "url": "https://thestandard.co/moph-morprom-data-error/",
     "theme": "record_wrong",
     "status": "admitted"
    },
    {
     "date": "2026-08-03",
     "headline": "People with wrong entries in national health app say claims were blocked",
     "paraphrase": "Affected people said their national health app history listed treatments they never had, one with 16 false entries. One said an insurance claim could not proceed. They want false entries deleted in writing and those responsible identified.",
     "source": "The Active (Thai PBS)",
     "url": "https://theactive.thaipbs.or.th/news/public-health-20260803-2",
     "theme": "record_wrong",
     "status": "alleged"
    },
    {
     "date": "2025-10-28",
     "headline": "Patients moved after a hospital stopped public scheme care waited days for records",
     "paraphrase": "After a private hospital stopped public scheme outpatients, transferred patients waited up to seven days for their medical history. The national insurer said it could not reach their data because the hospital was not linked to the national records exchange.",
     "source": "Bangkok Post",
     "url": "https://www.bangkokpost.com/thailand/general/3127437/patients-move-over-ct-fee",
     "theme": "lost_between_providers",
     "status": "alleged"
    },
    {
     "date": "2026-07-07",
     "headline": "Cloud failure took patient records offline at public city hospitals, authority says",
     "paraphrase": "The city's medical service department announced that a cloud infrastructure failure stopped the patient database, appointment and dispensing systems at 14 of its hospitals. Hospitals stayed open and switched to paper records, but services were delayed.",
     "source": "Thairath",
     "url": "https://www.thairath.co.th/news/local/bangkok/2944586",
     "theme": "other",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "KEN",
   "name": "Kenya",
   "region": "Africa",
   "overall": 49,
   "rank": "45=",
   "likelyRank": "43 to 49",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Kenya's rules promise patients a national record with alerts, logs and consent, but the live system is young, claims-driven and leaky.",
   "categories": {
    "access": {
     "score": 55,
     "summary": "The 2021 data protection rules make a copy free and due within 7 days, and the Digital Health Agency runs a national portal, Afyangu, showing visits, prescriptions and results. No official figure shows most people use it, so the cell stops at 55.",
     "sources": [
      {
       "title": "Data Protection (General) Regulations 2021, Legal Notice 263 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2021/263/eng@2022-01-14",
       "date": "2022-01-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Health Act No. 15 of 2023 (Digital Health Agency copy)",
       "url": "https://nhts.dha.go.ke/api/file-download/?filename=Digital%20Health%20Act%2015%20of%202023.pdf",
       "date": "2023",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Health (Health Information Management Procedures) Regulations 2025, Legal Notice 76 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/76/eng@2025-04-11",
       "date": "2025-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "National Shared Health Record (Digital Health Agency)",
       "url": "https://p360-preauth-lookup.dha.go.ke/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 44,
     "summary": "Every visit is copied to a national Shared Health Record, but the rules require client authorisation, an alert on each look-up and an access log. A May 2026 fake entry posted with no alert shows these controls are not yet reliable.",
     "sources": [
      {
       "title": "Digital Health (Data Exchange Component) Regulations 2025, Legal Notice 77 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/77/eng@2025-04-11",
       "date": "2025-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Health (Health Information Management Procedures) Regulations 2025, Legal Notice 76 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/76/eng@2025-04-11",
       "date": "2025-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "Afyangu app listing by the Digital Health Agency (Google Play)",
       "url": "https://play.google.com/store/apps/details?id=ke.go.dha.afyangu&hl=en",
       "date": "2026-09-09",
       "publisherClass": "official"
      },
      {
       "title": "SHA patient data safety questioned after Nairobi man's records show treatment in Garissa (Citizen Digital)",
       "url": "https://citizen.digital/article/sha-patient-data-safety-questioned-after-nairobi-mans-records-show-treatment-in-garissa-n382392",
       "date": "2026-05-09",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 55,
     "summary": "Health is sensitive data, the Digital Health Act adds offences up to 15 years in prison, and the Data Commissioner ordered a hospital to pay KES 525,000 in March 2026. An official posting a family's SHA claims in August 2026 shows weak internal controls.",
     "sources": [
      {
       "title": "Data Protection Act No. 24 of 2019 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/2019/24/eng@2022-12-31",
       "date": "2022-12-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "ODPC determination, Merceline v St. Luke Orthopaedic and Trauma Hospital",
       "url": "https://www.odpc.go.ke/wp-content/uploads/2026/04/MERCELINE-VS-ST.-LUKE.pdf",
       "date": "2026-03-16",
       "publisherClass": "official"
      },
      {
       "title": "Govt cleared to proceed with Kenya-US Health Cooperation Framework (Kenyans.co.ke)",
       "url": "https://www.kenyans.co.ke/news/123350-govt-cleared-proceed-ksh322-billion-kenya-us-health-cooperation-framework",
       "date": "2026-05-13",
       "publisherClass": "news"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 45,
     "summary": "Kenya has a live national Shared Health Record built on FHIR and, from mid-2026, requires every SHA-contracted facility to use a certified system linked to it. Volumes are still small: the Agency counts 1.2 million encounters and 4.5 million claims.",
     "sources": [
      {
       "title": "Digital Health (Data Exchange Component) Regulations 2025, Legal Notice 77 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/77/eng@2025-04-11",
       "date": "2025-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "National Shared Health Record (Digital Health Agency)",
       "url": "https://p360-preauth-lookup.dha.go.ke/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "SHA makes accredited HMIS mandatory for all healthcare providers (Kenyans.co.ke)",
       "url": "https://www.kenyans.co.ke/news/124812-sha-makes-accredited-hmis-mandatory-all-healthcare-providers",
       "date": "2026-06-30",
       "publisherClass": "news"
      },
      {
       "title": "SHA rolls out Taifa Care HMIS for Level 4 public hospitals (The Star)",
       "url": "https://www.the-star.co.ke/news/2026-07-01-sha-shifts-level-4-public-hospitals-to-taifa-care-hmis",
       "date": "2026-07-01",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 52,
     "summary": "Commercial use of personal data needs express consent, sensitive data is left out of the direct-marketing permission, and disclosing health data for market research is an offence. Nothing specific covers health apps, data brokers or sale of de-identified data.",
     "sources": [
      {
       "title": "Data Protection Act No. 24 of 2019 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/2019/24/eng@2022-12-31",
       "date": "2022-12-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Data Protection (General) Regulations 2021, Legal Notice 263 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2021/263/eng@2022-01-14",
       "date": "2022-01-14",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Health (Health Information Management Procedures) Regulations 2025, Legal Notice 76 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/76/eng@2025-04-11",
       "date": "2025-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "ODPC Guidance Note on the Processing of Health Data",
       "url": "https://www.odpc.go.ke/wp-content/uploads/2024/02/ODPC-Guidance-Note-on-Processing-of-Health-Data.pdf",
       "date": "2023-12",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 42,
     "summary": "The rules make certified systems query and update the Shared Health Record at every encounter and allow logged emergency access, so a clinician can in principle see care from other facilities. Coverage is still small and largely claims-driven.",
     "sources": [
      {
       "title": "Digital Health (Data Exchange Component) Regulations 2025, Legal Notice 77 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/77/eng@2025-04-11",
       "date": "2025-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Health (Health Information Management Procedures) Regulations 2025, Legal Notice 76 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/76/eng@2025-04-11",
       "date": "2025-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Health Act No. 15 of 2023 (Digital Health Agency copy)",
       "url": "https://nhts.dha.go.ke/api/file-download/?filename=Digital%20Health%20Act%2015%20of%202023.pdf",
       "date": "2023",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digitising Care: How Kenya's Afya Yangu platform is shaping the road to UHC (Talk Africa)",
       "url": "https://www.talkafrica.co.ke/digitising-care-how-kenyas-afya-yangu-platform-is-shaping-the-road-to-universal-health-coverage/",
       "date": "2025-12-04",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "There is no general research opt-out, but identifiable data from the national system needs the person's written consent plus ethics board, NACOSTI licence and ministerial approval. Four safeguard classes put the cell at the 50 cap.",
     "sources": [
      {
       "title": "Data Protection Act No. 24 of 2019 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/2019/24/eng@2022-12-31",
       "date": "2022-12-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Digital Health (Health Information Management Procedures) Regulations 2025, Legal Notice 76 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/76/eng@2025-04-11",
       "date": "2025-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "ODPC Guidance Notes: Processing for Research Purposes",
       "url": "https://www.odpc.go.ke/wp-content/uploads/2025/11/ODPC-%E2%80%93-GUIDANCE-NOTES-Processing-for-Research-Purpose.pdf",
       "date": "2025",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 48,
     "summary": "The Pharmacy and Poisons Board's February 2026 medical device software guideline sets rules for AI devices, including control of continuous learning and rollback. It is guidance, not statute, and one report calls it a draft, so it scores at the top of the guidance band.",
     "sources": [
      {
       "title": "Guideline on Regulation of Medical Device Software in Kenya (Pharmacy and Poisons Board, Revision 0)",
       "url": "https://web.pharmacyboardkenya.org/download/guideline-on-regulation-of-medical-device-software-in-kenya-mdsw/",
       "date": "2026-02",
       "publisherClass": "official"
      },
      {
       "title": "Kenya tightens oversight of medical device software (Health Business)",
       "url": "https://healthbusiness.co.ke/10137/kenya-tightens-oversight-of-medical-device-software/",
       "date": "2026-04-16",
       "publisherClass": "news"
      },
      {
       "title": "The Artificial Intelligence Bill, Senate Bill No. 4 of 2026 (Mzalendo Bill Tracker)",
       "url": "https://mzalendo.com/legislative-trends/bills/senate/560/",
       "date": "2026-08-10",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "Data Protection Act No. 24 of 2019 (Kenya Law)",
       "url": "https://new.kenyalaw.org/akn/ke/act/2019/24/eng@2022-12-31",
       "date": "2022-12-31",
       "publisherClass": "legal_text"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Data Protection Act No. 24 of 2019",
     "level": "National",
     "year": "2019",
     "what": "Health is sensitive data; access and portability rights; 72-hour breach notice; express consent for commercial use.",
     "url": "https://new.kenyalaw.org/akn/ke/act/2019/24/eng@2022-12-31"
    },
    {
     "name": "Data Protection (General) Regulations 2021",
     "level": "National",
     "year": "2021",
     "what": "Free access within 7 days; no direct marketing with sensitive data; health care processing kept in Kenya.",
     "url": "https://new.kenyalaw.org/akn/ke/act/ln/2021/263/eng@2022-01-14"
    },
    {
     "name": "Digital Health Act No. 15 of 2023",
     "level": "National",
     "year": "2023",
     "what": "Creates Digital Health Agency and integrated system; right to a copy; consent withdrawal; offences up to 15 years.",
     "url": "https://nhts.dha.go.ke/api/file-download/?filename=Digital%20Health%20Act%2015%20of%202023.pdf"
    },
    {
     "name": "Digital Health (Health Information Management Procedures) Regulations 2025",
     "level": "National",
     "year": "2025",
     "what": "48-hour breach notice; patient portal access; written consent for identifiable data; research approvals and fees.",
     "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/76/eng@2025-04-11"
    },
    {
     "name": "Digital Health (Data Exchange Component) Regulations 2025",
     "level": "National",
     "year": "2025",
     "what": "Client registry and Shared Health Record; 24-hour upload; access alerts and logs; insurer claims links.",
     "url": "https://new.kenyalaw.org/akn/ke/act/ln/2025/77/eng@2025-04-11"
    },
    {
     "name": "Guideline on Regulation of Medical Device Software in Kenya (PPB)",
     "level": "National",
     "year": "2026",
     "what": "Regulator guidance for software and AI devices, including continuous-learning controls and rollback.",
     "url": "https://web.pharmacyboardkenya.org/download/guideline-on-regulation-of-medical-device-software-in-kenya-mdsw/"
    }
   ],
   "dti": {
    "grade": 86,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-03-16",
     "headline": "Hospital twice gave a patient another person's test results",
     "paraphrase": "A patient was twice handed test results belonging to someone with a similar name. The hospital admitted an administrative error; the regulator also found it shared her data with an outside lab without consent and ordered KES 525,000.",
     "source": "Office of the Data Protection Commissioner (Kenya)",
     "url": "https://www.odpc.go.ke/wp-content/uploads/2026/04/MERCELINE-VS-ST.-LUKE.pdf",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-12-16",
     "headline": "Regulator finds hospital had no way for patients to see or correct records",
     "paraphrase": "An investigation the regulator opened itself found the hospital had no process for patients' access or correction requests, shared data with third parties without agreements, and was unregistered. An enforcement notice was issued.",
     "source": "Office of the Data Protection Commissioner (Kenya)",
     "url": "https://www.odpc.go.ke/wp-content/uploads/2026/01/ELDORET-HOSPITAL-2.pdf",
     "theme": "other",
     "status": "finding"
    },
    {
     "date": "2024-12",
     "headline": "Regulator finds weak access controls at a nursing home led to data breaches",
     "paraphrase": "The regulator investigated on its own initiative and found no role-based checks on who received sensitive data, which led to several breaches, plus no process for access or correction requests. An enforcement notice followed.",
     "source": "Office of the Data Protection Commissioner (Kenya)",
     "url": "https://www.odpc.go.ke/wp-content/uploads/2025/01/20241218-SUO-MOTU-NALA-MATERNITY-NURSING-HOME-LIMITED.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-01-18",
     "headline": "Hospital ordered to pay patient after using secretly filmed footage in its adverts",
     "paraphrase": "The regulator found a staff member recorded a patient during treatment and the hospital showed the footage on its screens as promotion. It could not prove consent, so it must pay Sh500,000 and delete the adverts.",
     "source": "Business Daily (reporting a Data Protection Commissioner decision)",
     "url": "https://www.businessdailyafrica.com/bd/corporate/companies/nairobi-hospital-to-pay-patient-sh500000-illegal-use-of-images-5329802",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2026-03-02",
     "headline": "National health insurer apologises as system failure halts approvals at hospitals",
     "paraphrase": "The insurer issued a notice that a critical failure at its digital platform since 1 March had stopped pre-authorisation and eligibility checks at contracted facilities nationwide. It apologised for the disruption to patient care.",
     "source": "The Star (Kenya)",
     "url": "https://www.the-star.co.ke/news/2026-03-02-health-services-hit-as-sha-platform-faces-outage",
     "theme": "access_delay_or_cost",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "UKR",
   "name": "Ukraine",
   "region": "Europe",
   "overall": 49,
   "rank": "45=",
   "likelyRank": "43 to 51",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Ukraine's national e-health system holds records on 34.6 million people, but patients still cannot see their own medical data in the state portal.",
   "categories": {
    "access": {
     "score": 46,
     "summary": "The law gives patients a right to see their medical documents and to get their personal data within 30 days, but the national patient cabinet shows only personal data and doctor declarations. Some private apps show part of the record.",
     "sources": [
      {
       "title": "Osnovy zakonodavstva Ukrainy pro okhoronu zdorovia (Fundamentals of Health Legislation), Art. 39",
       "url": "https://zakon.rada.gov.ua/laws/show/2801-12",
       "date": "2026-02-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "De ya mozhu perehlianuty svoi medychni dani v ESOZ? (Patient cabinet FAQ, NSZU)",
       "url": "https://pis.esoz.gov.ua/faq/de-ya-mozhu-perehlyanuty-svoyi-medychni-dani-e-napravlennya-e-retsepty-toshcho-yaki-zberihayutsya-v-esoz/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Kabinet patsiienta: podannia deklaratsii likariu onlain (eHealth)",
       "url": "https://ehealth.gov.ua/2026/02/11/kabinet-patsiyenta-dlya-ukrayintsiv-teper-dostupna-mozhlyvist-podannya-deklaratsiyi-likaryu-onlajn/",
       "date": "2026-02-11",
       "publisherClass": "official"
      },
      {
       "title": "Zakon Ukrainy pro zakhyst personalnykh danykh (Personal Data Protection Law), Art. 8",
       "url": "https://zakon.rada.gov.ua/laws/show/2297-17",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "control": {
     "score": 50,
     "summary": "The law says access to a patient's e-health data needs consent, and patients approve other doctors by SMS code. But signing a family doctor declaration counts as blanket consent, and no patient-visible access log was found.",
     "sources": [
      {
       "title": "Fundamentals of Health Legislation, Art. 24-2 (electronic health system)",
       "url": "https://zakon.rada.gov.ua/laws/show/2801-12",
       "date": "2026-02-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "Khto maie dostup do danykh patsiienta v ESOZ? (eHealth)",
       "url": "https://ehealth.gov.ua/2024/02/29/hto-maye-dostup-do-danyh-patsiyenta-v-esoz/",
       "date": "2024-02-29",
       "publisherClass": "official"
      },
      {
       "title": "Medychni dani ukraintsiv: khto mozhe dyvytysia vashu istoriiu khvorob (RBC-Ukraine)",
       "url": "https://www.rbc.ua/rus/news/medichni-dani-ukrayintsiv-hto-mozhe-divitisya-1764940793.html",
       "date": "2025-12-09",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 42,
     "summary": "Health data is a special category under a 2010 law enforced by the parliamentary human rights commissioner, not a standalone regulator. A GDPR-style replacement (bill 8153) passed first reading in November 2024 and was still not adopted at research date.",
     "sources": [
      {
       "title": "Zakon Ukrainy pro zakhyst personalnykh danykh, Arts. 7, 22, 23",
       "url": "https://zakon.rada.gov.ua/laws/show/2297-17",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Bill 8153 card: Pro zakhyst personalnykh danykh (Verkhovna Rada)",
       "url": "https://itd.rada.gov.ua/billinfo/Bills/Card/40707",
       "date": "2022-10-25",
       "publisherClass": "official"
      },
      {
       "title": "Oprylyudnyly perelik medychnykh onlain-system, yaki vidkliuchat vid ESOZ (LB.ua)",
       "url": "https://lb.ua/health/2026/04/23/734385_oprilyudnili_perelik_medichnih.html",
       "date": "2026-04-23",
       "publisherClass": "news"
      },
      {
       "title": "Medychni dani ukraintsiv: khto mozhe dyvytysia vashu istoriiu khvorob (RBC-Ukraine)",
       "url": "https://www.rbc.ua/rus/news/medichni-dani-ukrayintsiv-hto-mozhe-divitisya-1764940793.html",
       "date": "2025-12-09",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 62,
     "summary": "One national e-health system links family doctors, e-referrals, e-prescriptions, sick notes and NSZU payments for 34.6 million registered patients. Over 111.8 million e-prescriptions have been created, but self-paid prescriptions and hospital data are less complete.",
     "sources": [
      {
       "title": "Reiestr patsiientiv ESOZ nalichuie ponad 34,5 miljony aktyvnykh zapysiv (eHealth)",
       "url": "https://ehealth.gov.ua/2026/03/13/reyestr-patsiyentiv-esoz-nalichuye-ponad-34-5-miljony-aktyvnyh-zapysiv-yaki-mozhlyvosti-dostupni-dlya-patsiyenta/",
       "date": "2026-03-13",
       "publisherClass": "official"
      },
      {
       "title": "V ESOZ stvoreno ponad 111 miljoniv e-Retseptiv (eHealth)",
       "url": "https://ehealth.gov.ua/2026/05/14/v-esoz-stvoreno-ponad-111-miljoniv-e-retseptiv/",
       "date": "2026-05-14",
       "publisherClass": "official"
      },
      {
       "title": "Khto maie dostup do danykh patsiienta v ESOZ? (eHealth)",
       "url": "https://ehealth.gov.ua/2024/02/29/hto-maye-dostup-do-danyh-patsiyenta-v-esoz/",
       "date": "2024-02-29",
       "publisherClass": "official"
      },
      {
       "title": "Oprylyudnyly perelik medychnykh onlain-system, yaki vidkliuchat vid ESOZ (LB.ua)",
       "url": "https://lb.ua/health/2026/04/23/734385_oprilyudnili_perelik_medichnih.html",
       "date": "2026-04-23",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 40,
     "summary": "Commercial use of health data needs the person's unambiguous consent, but no specific ban on selling health data was found. Private firms run the patient apps; Helsi, with about 29 million users, planned an 80 hryvnia AI subscription by end-2025.",
     "sources": [
      {
       "title": "Zakon Ukrainy pro zakhyst personalnykh danykh, Art. 7",
       "url": "https://zakon.rada.gov.ua/laws/show/2297-17",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Platni funktsii Helsi: navishcho servis vvodyt pidpysku (Forbes Ukraine)",
       "url": "https://forbes.ua/innovations/peretvoriti-patsientiv-na-pidpisnikiv-medichniy-servis-helsi-robit-platnoyu-shi-rozshifrovku-analiziv-u-rozrobku-yakoi-vklala-400-000-yak-kompaniya-monetizue-29-mln-koristuvachiv-04072025-31016",
       "date": "2025-07-04",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 58,
     "summary": "A patient's family doctor sees all records except HIV and psychiatric data, and the law allows access without consent when life is at risk. Other doctors see only what the patient approves by SMS code or what is attached to a referral.",
     "sources": [
      {
       "title": "Khto maie dostup do danykh patsiienta v ESOZ? (eHealth)",
       "url": "https://ehealth.gov.ua/2024/02/29/hto-maye-dostup-do-danyh-patsiyenta-v-esoz/",
       "date": "2024-02-29",
       "publisherClass": "official"
      },
      {
       "title": "Fundamentals of Health Legislation, Art. 24-2",
       "url": "https://zakon.rada.gov.ua/laws/show/2801-12",
       "date": "2026-02-11",
       "publisherClass": "legal_text"
      }
     ]
    },
    "research": {
     "score": 44,
     "summary": "Law requires anonymity when medical secrets are used in research and free, informed consent for experiments on people, but no opt-out from secondary use was found. As a non-EU country, Ukraine is not covered by the EHDS opt-out.",
     "sources": [
      {
       "title": "Fundamentals of Health Legislation, Arts. 40 and 45",
       "url": "https://zakon.rada.gov.ua/laws/show/2801-12",
       "date": "2026-02-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "Khto maie dostup do danykh patsiienta v ESOZ? (eHealth)",
       "url": "https://ehealth.gov.ua/2024/02/29/hto-maye-dostup-do-danyh-patsiyenta-v-esoz/",
       "date": "2024-02-29",
       "publisherClass": "official"
      },
      {
       "title": "European Health Data Space Regulation (European Commission)",
       "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "ai": {
     "score": 40,
     "summary": "Medical devices, including software, still fall under 2013 rules based on older EU directives. New device rules were adopted in June 2026 (their EU MDR basis is not verified in the text) but take effect only from 31 December 2030, and no clinical AI law was found.",
     "sources": [
      {
       "title": "Postanova KMU No. 759 vid 10.06.2026 pro zatverdzhennia Tekhnichnoho rehlamentu shchodo medychnykh vyrobiv",
       "url": "https://zakon.rada.gov.ua/laws/show/759-2026-%D0%BF",
       "date": "2026-06-10",
       "publisherClass": "legal_text"
      },
      {
       "title": "Zatverdzhennia novykh Tekhnichnykh rehlamentiv shchodo medychnykh vyrobiv (State Service on Medicines and Drugs Control)",
       "url": "https://www.dls.gov.ua/for_subject/%D0%B7%D0%B0%D1%82%D0%B2%D0%B5%D1%80%D0%B4%D0%B6%D0%B5%D0%BD%D0%BD%D1%8F-%D0%BD%D0%BE%D0%B2%D0%B8%D1%85-%D1%82%D0%B5%D1%85%D0%BD%D1%96%D1%87%D0%BD%D0%B8%D1%85-%D1%80%D0%B5%D0%B3%D0%BB%D0%B0%D0%BC/",
       "date": "2026-06-16",
       "publisherClass": "official"
      },
      {
       "title": "MOZ: 80,5% opytanykh medykiv uzhe vykorystovuiut ShI u roboti (7eminar)",
       "url": "https://7eminar.ua/news/23759-moz-805-opitanix-medikiv-uze-vikoristovuyut-si-u-roboti",
       "date": "2026-08-28",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Fundamentals of Ukrainian Health Legislation (No. 2801-XII)",
     "level": "National",
     "year": "1992",
     "what": "Right to review medical documents, medical secrecy, consent rules for e-health access (Art. 24-2).",
     "url": "https://zakon.rada.gov.ua/laws/show/2801-12"
    },
    {
     "name": "Law on Personal Data Protection (No. 2297-VI)",
     "level": "National",
     "year": "2010",
     "what": "Health data is special category; access within 30 days; human rights commissioner oversees.",
     "url": "https://zakon.rada.gov.ua/laws/show/2297-17"
    },
    {
     "name": "Law No. 4497-IX (State Register of Servicemen; amends Art. 24-2 of the Fundamentals)",
     "level": "National",
     "year": "2025",
     "what": "Lets the defence ministry receive military medical exam results from the e-health system.",
     "url": "https://zakon.rada.gov.ua/laws/show/4497-20"
    },
    {
     "name": "Cabinet Resolution No. 759, Technical Regulation on Medical Devices",
     "level": "National",
     "year": "2026",
     "what": "New medical device technical regulation; applies from 31 December 2030. EU MDR basis not verified.",
     "url": "https://zakon.rada.gov.ua/laws/show/759-2026-%D0%BF"
    }
   ],
   "dti": {
    "grade": 89,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-08-17",
     "headline": "Court voids military fitness ruling after commission could not produce examination records",
     "paraphrase": "A man said he was never examined, yet a military medical commission certified him fit for service. Asked by the court for the examination file and doctors' findings, the commission produced only the certificate, so the court annulled it.",
     "source": "Sudovo-yurydychna hazeta (sud.ua)",
     "url": "https://sud.ua/uk/news/sudova-praktyka/369460-vlk-na-paperi-cholovika-vyznaly-prydatnym-ale-ttsk-ne-nadav-sudu-dokumentiv-pro-medohliad",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2026-02-02",
     "headline": "National health service ends contracts with clinics that falsified patients' electronic records",
     "paraphrase": "The national health service said some clinics put inflated or invented entries into patients' electronic records to raise payments, and it ended contracts with several. Patients have reported finding visits in their records that never happened.",
     "source": "RBC-Ukraine",
     "url": "https://www.rbc.ua/rus/news/okremimi-likarnyami-nszu-rozirvala-dogovori-1770013744.html",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2026-03-26",
     "headline": "Family doctor held over 1,731 patient sign-ups allegedly made without people's knowledge",
     "paraphrase": "Investigators say a family doctor registered 1,731 patient declarations in the national e-health system without people's knowledge, using altered names, birth dates and addresses, to claim state payments for care never given.",
     "source": "StopCor",
     "url": "https://www.stopcor.org/ukr/section-uanews/news-medposlugi-lishe-na-paperi-likarka-otrimala-miljoni-za-fejkovi-deklaratsii-26-03-2026.html",
     "theme": "record_wrong",
     "status": "alleged"
    },
    {
     "date": "2024-12-16",
     "headline": "Women found clinic visits they never made written into their electronic records",
     "paraphrase": "Prosecutors named a doctor as a suspect for entering at least 22 false appointment records over two years for women who had never met him. The women discovered the entries themselves and went to police.",
     "source": "KP.UA",
     "url": "https://kp.ua/ua/life/a702092-pju-vdoma-kavu-a-likar-pishe-shcho-ja-u-noho-na-prijomi-chim-zahrozhujut-fejkovi-zapisi-v-helsi",
     "theme": "record_wrong",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "ARG",
   "name": "Argentina",
   "region": "Americas",
   "overall": 48,
   "rank": "47=",
   "likelyRank": "45 to 52",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "Argentine law makes patients owners of their record, and a national app lets people refuse network sharing, but the network is still young.",
   "categories": {
    "access": {
     "score": 60,
     "summary": "Ley 26.529 makes the patient the owner of the clinical record, with an authenticated copy due within 48 hours. The Mi Argentina app shows vaccines, 60 days of e-prescriptions and records from connected facilities, not the full chart; usage figures were not verified.",
     "sources": [
      {
       "title": "Ley 26.529, derechos del paciente, texto actualizado (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/160000-164999/160432/texact.htm",
       "date": "2009-10-21",
       "publisherClass": "legal_text"
      },
      {
       "title": "Decreto 1089/2012, reglamentacion de la Ley 26.529 (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/195000-199999/199296/norma.htm",
       "date": "2012-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Preguntas frecuentes: Mi Salud en Mi Argentina (Ministerio de Salud)",
       "url": "https://www.argentina.gob.ar/salud/frecuentes",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "La Receta Electronica se incorpora a la app Mi Argentina (Ministerio de Salud)",
       "url": "https://www.argentina.gob.ar/noticias/la-receta-electronica-se-incorpora-la-app-mi-argentina",
       "date": "2026-05-14",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 48,
     "summary": "Official pages say facilities on the national network can see a record unless the person explicitly refuses, using privacy settings in Mi Argentina. A patient-visible access log is described only as design intent; use of the opt-out was not verified.",
     "sources": [
      {
       "title": "Red Nacional de Salud Digital: configuracion de privacidad (Mi Argentina)",
       "url": "https://www.argentina.gob.ar/miargentina/configuracion-de-privacidad",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Preguntas frecuentes: Mi Salud en Mi Argentina (Ministerio de Salud)",
       "url": "https://www.argentina.gob.ar/salud/frecuentes",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Red Nacional de Salud Digital (Ministerio de Salud)",
       "url": "https://www.argentina.gob.ar/salud/digital/red",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ley 25.326, proteccion de los datos personales, texto actualizado (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/60000-64999/64790/texact.htm",
       "date": "2000-10-04",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 42,
     "summary": "Health data is sensitive under Ley 25.326 (2000), but fines still top out at 100,000 pesos and the law itself has no breach notification article. The EU still rates the law adequate; a 2026 reform bill with 72-hour breach notice is pending.",
     "sources": [
      {
       "title": "Ley 25.326, proteccion de los datos personales, texto actualizado (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/60000-64999/64790/texact.htm",
       "date": "2000-10-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "Resolucion AAIP 126/2024, infracciones y sanciones (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/395000-399999/399750/norma.htm",
       "date": "2024-05-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "La AAIP inicio una investigacion de oficio ante presunta filtracion masiva de datos personales",
       "url": "https://www.argentina.gob.ar/noticias/la-aaip-inicio-una-investigacion-de-oficio-ante-presunta-filtracion-masiva-de-datos",
       "date": "2025-12-23",
       "publisherClass": "official"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 45,
     "summary": "E-prescription has been mandatory nationwide since January 2025, and the ministry reports more than 70 million prescriptions registered. Clinical records move through a federated network that provinces were still testing in June 2026; national coverage was not verified.",
     "sources": [
      {
       "title": "Salud impulsa la interoperabilidad para consolidar un sistema de salud digital integrado (Ministerio de Salud)",
       "url": "https://www.argentina.gob.ar/noticias/salud-impulsa-la-interoperabilidad-para-consolidar-un-sistema-de-salud-digital-integrado",
       "date": "2026-06-04",
       "publisherClass": "official"
      },
      {
       "title": "El Ministerio de Salud completa la implementacion de la receta electronica (Resolucion 2214/2025)",
       "url": "https://www.argentina.gob.ar/noticias/el-ministerio-de-salud-completa-la-implementacion-de-la-receta-electronica-ahora-tambien",
       "date": "2025-07-21",
       "publisherClass": "official"
      },
      {
       "title": "Integracion sanitaria digital en Tucuman impulsa la atencion federal de pacientes (Ministerio de Salud Publica de Tucuman)",
       "url": "https://msptucuman.gov.ar/integracion-sanitaria-digital-en-tucuman-impulsa-la-atencion-federal-de-pacientes/",
       "date": "2026-05-19",
       "publisherClass": "official"
      },
      {
       "title": "La plataforma Historia de Salud Integrada ya alcanza a ocho provincias y mas de 1.600 establecimientos (Convergencia)",
       "url": "https://www.convergencia.com/a-diario-convergencia/la-plataforma-historia-de-salud-integrada-ya-alcanza-a-ocho-provincias-y-mas-de-1-600-establecimientos-5786/",
       "date": "2026-05-29",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 45,
     "summary": "Ley 25.326 requires prior, revocable consent to pass personal data to others and bans databases that reveal sensitive data, with anonymised research as the exception. No health-specific rule on data brokers, health apps or ad targeting was found, and fines are small.",
     "sources": [
      {
       "title": "Ley 25.326, proteccion de los datos personales, texto actualizado (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/60000-64999/64790/texact.htm",
       "date": "2000-10-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "Condiciones de uso, intercambio y confidencialidad de salud digital (Ministerio de Salud)",
       "url": "https://www.argentina.gob.ar/salud/digital/condiciones-de-uso",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Resolucion AAIP 126/2024, infracciones y sanciones (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/395000-399999/399750/norma.htm",
       "date": "2024-05-24",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 42,
     "summary": "A clinician using a standards-based record can query a patient's history at other facilities through the national network, unless the patient has refused. Cross-province sharing was only being validated in 2026, and the share of facilities connected was not verified.",
     "sources": [
      {
       "title": "Red Nacional de Salud Digital (Ministerio de Salud)",
       "url": "https://www.argentina.gob.ar/salud/digital/red",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Preguntas frecuentes: Mi Salud en Mi Argentina (Ministerio de Salud)",
       "url": "https://www.argentina.gob.ar/salud/frecuentes",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Ley 27.706, Programa Federal Unico de Informatizacion y Digitalizacion de Historias Clinicas (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/380000-384999/380710/norma.htm",
       "date": "2023-03",
       "publisherClass": "legal_text"
      },
      {
       "title": "Integracion sanitaria digital en Tucuman impulsa la atencion federal de pacientes (Ministerio de Salud Publica de Tucuman)",
       "url": "https://msptucuman.gov.ar/integracion-sanitaria-digital-en-tucuman-impulsa-la-atencion-federal-de-pacientes/",
       "date": "2026-05-19",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "Studies using identifiable data need informed consent and ethics review under Resolution 1480/2011, but committees can waive consent for record or registry research, and there is no general opt-out. Score: base 40, +3 each for ethics review, a consent route and a public research registry.",
     "sources": [
      {
       "title": "Resolucion 1480/2011, Guia para Investigaciones en Salud Humana, texto actualizado (Argentina.gob.ar)",
       "url": "https://www.argentina.gob.ar/normativa/nacional/norma-187206/actualizacion",
       "date": "2011-09-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 25.326, proteccion de los datos personales, texto actualizado (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/60000-64999/64790/texact.htm",
       "date": "2000-10-04",
       "publisherClass": "legal_text"
      },
      {
       "title": "Nueva normativa sobre Buenas Practicas Clinicas para estudios de farmacologia clinica (ANMAT)",
       "url": "https://www.argentina.gob.ar/noticias/nueva-normativa-sobre-buenas-practicas-clinicas-para-estudios-de-farmacologia-clinica",
       "date": "2025-10-09",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 40,
     "summary": "ANMAT treats software that diagnoses, prevents or treats disease as a medical device needing registration under Disposition 64/2025, with post-market vigilance. No AI-specific change control or human oversight rule exists, so the score sits low in the guidance band, near Mexico (38).",
     "sources": [
      {
       "title": "ANMAT actualiza los criterios regulatorios para software como dispositivo medico (SaMD)",
       "url": "https://www.argentina.gob.ar/noticias/anmat-actualiza-los-criterios-regulatorios-para-software-como-dispositivo-medico-samd",
       "date": "2026-09-10",
       "publisherClass": "official"
      },
      {
       "title": "Disposicion ANMAT 64/2025, Reglamento Tecnico Mercosur de Registro de Productos Medicos (Infoleg)",
       "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/405000-409999/408309/norma.htm",
       "date": "2025-01-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Inteligencia artificial y software medico en Argentina: desafios regulatorios (Abogados.com.ar, Allende & Brea)",
       "url": "https://abogados.com.ar/inteligencia-artificial-y-software-medico-en-argentina-desafios-regulatorios-para-el-regimen-de-productos-medicos/40131",
       "date": "2026-09-24",
       "publisherClass": "law_firm"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Ley 26.529 (derechos del paciente, historia clinica y consentimiento informado)",
     "level": "National",
     "year": "2009",
     "what": "Patient owns the record; authenticated copy within 48 hours; confidentiality; habeas data if refused.",
     "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/160000-164999/160432/texact.htm"
    },
    {
     "name": "Ley 25.326 (proteccion de los datos personales)",
     "level": "National",
     "year": "2000",
     "what": "Health is sensitive data; consent to pass data on; ten-day access right; AAIP enforces.",
     "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/60000-64999/64790/texact.htm"
    },
    {
     "name": "Ley 27.706 (historias clinicas electronicas)",
     "level": "National",
     "year": "2023",
     "what": "Federal program for a single interoperable electronic record system; patient owns data with free access.",
     "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/380000-384999/380710/norma.htm"
    },
    {
     "name": "Ley 27.553 (recetas electronicas o digitales)",
     "level": "National",
     "year": "2020",
     "what": "Allows electronic prescriptions and telehealth platforms nationwide under data protection and patient rights laws.",
     "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/340000-344999/340919/norma.htm"
    },
    {
     "name": "Resolucion 1480/2011 (Guia para Investigaciones en Salud Humana)",
     "level": "National",
     "year": "2011",
     "what": "Consent and ethics review for research on people or their data; creates national research registry.",
     "url": "https://www.argentina.gob.ar/normativa/nacional/norma-187206/actualizacion"
    },
    {
     "name": "Disposicion ANMAT 64/2025",
     "level": "National",
     "year": "2025",
     "what": "Adopts the Mercosur medical device registration rule, defining software as a medical device.",
     "url": "https://servicios.infoleg.gob.ar/infolegInternet/anexos/405000-409999/408309/norma.htm"
    },
    {
     "name": "Ley 15.201 (Provincia de Buenos Aires, gestion digital de estudios)",
     "level": "State/Provincial",
     "year": "2020",
     "what": "Labs and imaging centres must send results digitally, free, in a non-proprietary format if patients opt in.",
     "url": "https://normas.gba.gob.ar/documentos/xAm1DYco.html"
    }
   ],
   "dti": {
    "grade": 90,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2024-12-03",
     "headline": "Cyberattack locked databases at three medical testing centres, delaying patients' results",
     "paraphrase": "A ransomware attack encrypted the shared databases of three large testing and laboratory centres, affecting thousands of patients for ten days. The group said no patient data was taken, but labs closed and reports were handed out manually.",
     "source": "La Nación",
     "url": "https://www.lanacion.com.ar/sociedad/estamos-haciendo-el-maximo-esfuerzo-para-resolverlo-hackearon-el-servidor-de-tres-importantes-nid02122024/",
     "theme": "access_delay_or_cost",
     "status": "admitted"
    },
    {
     "date": "2025-04-05",
     "headline": "Hackers offer 665,128 patients' test results for sale after attack on software supplier",
     "paraphrase": "Criminals put up for sale 665,128 medical test results with patients' personal details, taken from a company that stores imaging for about 30 clinics and hospitals in several provinces. After extortion failed, the data went on sale.",
     "source": "Tiempo Argentino",
     "url": "https://www.tiempoar.com.ar/ta_article/hackean-665-128-estudios-medicos-la-filtracion-de-datos-de-salud-mas-grande-del-pais/",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-05-15",
     "headline": "Lawmaker seeks answers over claimed sale of millions of Argentines' health records",
     "paraphrase": "Attackers claimed to be selling 700 GB from a national government health database, including clinical records and personal details of up to 52 million people. A national deputy filed requests for information. The leak was unconfirmed.",
     "source": "Código Baires",
     "url": "https://www.codigobaires.com.ar/2026-05-15/denuncian-filtracion-y-la-venta-de-historias-clinicas-y-datos-sensibles-de-52-millones-de-argentinos-248315",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-05-23",
     "headline": "Retirees' insurer posted members' clinical records on its public purchasing site",
     "paraphrase": "A fact-checking investigation found at least 40 purchase files on the insurer's public procurement search showing members' clinical histories, test results and ID copies. The insurer called it a serious anomaly, removed the files and opened internal inquiries.",
     "source": "Jujuygráfico",
     "url": "https://jujuygrafico.com.ar/pami-historias-clinicas-jubilados-jujuy-gob",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "NZL",
   "name": "New Zealand",
   "region": "Oceania",
   "overall": 48,
   "rank": "47=",
   "likelyRank": "45 to 52",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "high",
   "headline": "New Zealanders get records free from public agencies, but the national shared record is not live and a 2025 portal hack exposed nearly 100,000 patients.",
   "categories": {
    "access": {
     "score": 55,
     "summary": "The health privacy code gives a right to your records within 20 working days, free from public agencies. The national My Health Record shows only immunisations, COVID-19 results and some identity details; fuller views sit in private GP portals.",
     "sources": [
      {
       "title": "Ask for your information (Office of the Privacy Commissioner)",
       "url": "https://www.privacy.org.nz/your-rights/ask-for-your-information/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Charging for access to personal information (Office of the Privacy Commissioner)",
       "url": "https://www.privacy.org.nz/responsibilities/charging-for-access-to-personal-information/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "About My Health Account (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/websites-and-apps/my-health-account/about-my-health-account",
       "date": "2026-07-22",
       "publisherClass": "official"
      },
      {
       "title": "Manage My Health data breach: a timeline of what happened (RNZ)",
       "url": "https://www.rnz.co.nz/news/crime-and-justice/584053/manage-my-health-data-breach-a-timeline-of-what-happened-and-everything-we-know-so-far",
       "date": "2026-01-14",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 47,
     "summary": "Today choices are narrow: people can restrict their national immunisation record, and some regional shared records allow opt-out. The national Shared Digital Health Record, with opt-out, item blocking and access summaries, has not started sharing.",
     "sources": [
      {
       "title": "Privacy: Shared Digital Health Record (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/privacy/wider-sharing-of-your-health-information/privacy-shared-digital-health-record",
       "date": "2026-08-07",
       "publisherClass": "official"
      },
      {
       "title": "Restricted access to records in the AIR (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/health-professionals/guidance-standards/topic/immunisation/aotearoa-immunisation-register-air/restricted-access-to-records-air",
       "date": "2026-05-21",
       "publisherClass": "official"
      },
      {
       "title": "Shared Electronic Health Record: frequently asked questions (sehr.org.nz, operator not stated)",
       "url": "https://sehr.org.nz/frequently-asked-questions/",
       "date": "undated",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "Supporting your care with shared health information (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/privacy/wider-sharing-of-your-health-information",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 50,
     "summary": "A health-specific code and an active commissioner exist, but the December 2025 Manage My Health hack exposed nearly 100,000 people and the regulator's strongest tool was a compliance notice. Fines reach only NZ$10,000, for failing to report a breach.",
     "sources": [
      {
       "title": "Privacy Commissioner releases Phase 1 Inquiry into Manage My Health cyber incident (Office of the Privacy Commissioner)",
       "url": "https://www.privacy.org.nz/tuhono-connect/statements-media-releases/privacy-commissioner-finds-manage-my-health-and-health-nz-breached-privacy-act/",
       "date": "2026-05-27",
       "publisherClass": "official"
      },
      {
       "title": "Privacy Commissioner issues Compliance Notices to Manage My Health and Health NZ (Office of the Privacy Commissioner)",
       "url": "https://www.privacy.org.nz/tuhono-connect/statements-media-releases/privacy-commissioner-issues-compliance-notices-to-manage-my-health-and-health-nz/",
       "date": "2026-09-23",
       "publisherClass": "official"
      },
      {
       "title": "NotifyUs: evaluate a privacy breach (Office of the Privacy Commissioner)",
       "url": "https://www.privacy.org.nz/responsibilities/privacy-breaches/notify-us/evaluate",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Calls to strengthen New Zealand's Privacy Act grow amid an increasing number of major breaches (IAPP)",
       "url": "https://iapp.org/news/a/calls-to-strengthen-new-zealand-s-privacy-act-grow-amid-an-increasing-number-of-major-breaches",
       "date": "2026-03-05",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 40,
     "summary": "National building blocks exist: an immunisation register, the ePrescription Service and a dispensing claims collection. But Health NZ says record sharing happens only in some regions, and its national connector will not share GP data until mid-2027.",
     "sources": [
      {
       "title": "Shared Digital Health Record update: July 2026 (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/news-and-updates/shared-digital-health-record-update-july-2026",
       "date": "2026-07-09",
       "publisherClass": "official"
      },
      {
       "title": "Privacy: Shared Digital Health Record (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/privacy/wider-sharing-of-your-health-information/privacy-shared-digital-health-record",
       "date": "2026-08-07",
       "publisherClass": "official"
      },
      {
       "title": "e-Medicines programme (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/about-us/what-we-do/programmes-and-initiatives/e-medicines-programme",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Pharmaceutical collection (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/about-us/health-data/data-sets-and-collections/national-collections/pharmaceutical-collection",
       "date": "2026-07-22",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 52,
     "summary": "The health code covers insurers, sellers of medicines and devices, and firms that handle health information for others, and limits disclosure beyond the original purpose. But breaches carry no civil fines, and vendors acting for others escape direct liability.",
     "sources": [
      {
       "title": "Health Information Privacy Code 2020 (Privacy Commissioner, consolidated website version)",
       "url": "https://www.privacy.org.nz/assets/Codes-of-Practice-2020/Health-Information-Privacy-Code-2020-website-version.pdf",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Privacy Commissioner releases Phase 1 Inquiry into Manage My Health cyber incident (Office of the Privacy Commissioner)",
       "url": "https://www.privacy.org.nz/tuhono-connect/statements-media-releases/privacy-commissioner-finds-manage-my-health-and-health-nz-breached-privacy-act/",
       "date": "2026-05-27",
       "publisherClass": "official"
      },
      {
       "title": "Calls to strengthen New Zealand's Privacy Act grow amid an increasing number of major breaches (IAPP)",
       "url": "https://iapp.org/news/a/calls-to-strengthen-new-zealand-s-privacy-act-grow-amid-an-increasing-number-of-major-breaches",
       "date": "2026-03-05",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 40,
     "summary": "In regions with a shared electronic record, GPs, pharmacists, paramedics and emergency departments can view a summary. Elsewhere clinicians rely on local systems, as Health NZ's national connector has not yet begun sharing.",
     "sources": [
      {
       "title": "Supporting your care with shared health information (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/privacy/wider-sharing-of-your-health-information",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Privacy: Shared Digital Health Record (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/privacy/wider-sharing-of-your-health-information/privacy-shared-digital-health-record",
       "date": "2026-08-07",
       "publisherClass": "official"
      },
      {
       "title": "Shared Electronic Health Record: frequently asked questions (sehr.org.nz, operator not stated)",
       "url": "https://sehr.org.nz/frequently-asked-questions/",
       "date": "undated",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "Health Information Privacy Code 2020 (Privacy Commissioner, consolidated website version)",
       "url": "https://www.privacy.org.nz/assets/Codes-of-Practice-2020/Health-Information-Privacy-Code-2020-website-version.pdf",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Identifiable health data can be used for research without consent if an ethics committee approves a waiver, with no general opt-out. Stats NZ's Integrated Data Infrastructure applies de-identification, a closed data lab and prosecution for misuse.",
     "sources": [
      {
       "title": "Health Information Privacy Code 2020 (Privacy Commissioner, consolidated website version)",
       "url": "https://www.privacy.org.nz/assets/Codes-of-Practice-2020/Health-Information-Privacy-Code-2020-website-version.pdf",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "National Ethical Standards, 7. Informed consent (National Ethics Advisory Committee)",
       "url": "https://neac.health.govt.nz/national-ethical-standards/part-two/7-informed-consent/",
       "date": "2026-03-30",
       "publisherClass": "official"
      },
      {
       "title": "How we keep integrated data safe (Stats NZ)",
       "url": "https://www.stats.govt.nz/integrated-data/how-we-keep-integrated-data-safe/",
       "date": "2022-08-23",
       "publisherClass": "official"
      },
      {
       "title": "Restricted access to records in the AIR (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/health-professionals/guidance-standards/topic/immunisation/aotearoa-immunisation-register-air/restricted-access-to-records-air",
       "date": "2026-05-21",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 40,
     "summary": "New Zealand has no approval system for medical devices, so clinical AI is not assessed before use. Health NZ's own rules bar clinical decisions by generative AI and require registration of AI projects, while a new Medical Products Bill is still being drafted.",
     "sources": [
      {
       "title": "Explanation of the WAND database (Medsafe)",
       "url": "https://www.medsafe.govt.nz/regulatory/devicesnew/3-2Explanation.asp",
       "date": "2011-05-10",
       "publisherClass": "official"
      },
      {
       "title": "Using generative AI and large language models (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/health-professionals/guidance-standards/topic/digital-technologies/using-generative-ai-and-large-language-models",
       "date": "2026-05-21",
       "publisherClass": "official"
      },
      {
       "title": "Artificial Intelligence and Algorithm Expert Advisory Group (Health New Zealand)",
       "url": "https://www.healthnz.govt.nz/about-us/who-we-are/expert-groups-and-networks/expert-groups/artificial-intelligence-and-algorithm-expert-advisory-group",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Medical Products Bill to introduce risk-based framework for software and AI regulation (eHealthNews.nz, HiNZ)",
       "url": "https://www.hinz.org.nz/news/727150/Medical-Products-Bill-to-introduce-risk-based-framework-for-software-and-AI-regulation-.htm",
       "date": "2026-05-12",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Privacy Act 2020",
     "level": "National",
     "year": "2020",
     "what": "General privacy law; breach notification, compliance notices, fines up to $10,000 for failing to notify.",
     "url": "https://www.privacy.org.nz/responsibilities/privacy-breaches/notify-us/evaluate"
    },
    {
     "name": "Health Information Privacy Code 2020",
     "level": "National",
     "year": "2020",
     "what": "Health-specific rules on collection, security, access, charges and disclosure for health agencies and insurers.",
     "url": "https://www.privacy.org.nz/assets/Codes-of-Practice-2020/Health-Information-Privacy-Code-2020-website-version.pdf"
    },
    {
     "name": "Health Information Privacy Code 2020 Amendment No 2",
     "level": "National",
     "year": "2026",
     "what": "Adds rule 3A: tell people when health data is collected from someone else. In force 1 May 2026.",
     "url": "https://www.privacy.org.nz/assets/Codes-of-Practice-2020/Amendment-No-2-to-Health-Information-Privacy-Code-2020.pdf"
    },
    {
     "name": "Medicines Act 1981 and Medicines (Database of Medical Devices) Regulations 2003",
     "level": "National",
     "year": "1981",
     "what": "Devices, including software, need only WAND notification; no pre-market approval.",
     "url": "https://www.medsafe.govt.nz/regulatory/devicesnew/3-2Explanation.asp"
    },
    {
     "name": "Data and Statistics Act 2022",
     "level": "National",
     "year": "2022",
     "what": "Confidentiality duties and penalties for researchers using integrated government data, including health records.",
     "url": "https://www.stats.govt.nz/integrated-data/how-we-keep-integrated-data-safe/"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-06-16",
     "headline": "Agency mailed a person's health information to the wrong house",
     "paraphrase": "A government agency sent a person's health information to the wrong address because a staff member recorded the house number incorrectly. The agency at first denied a mistake; after the regulator stepped in, it apologised and agreed to pay compensation.",
     "source": "Office of the Privacy Commissioner (New Zealand), Case Note 329225 [2025] NZ Priv Cmr 1",
     "url": "https://www.privacy.org.nz/resources-and-learning/case-notes-and-court-decisions/case-note-329225-2025-nz-priv-cmr-1-individual-complains-that-government-agency-sent-their-health-information-to-an-incorrect-address/",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-09-23",
     "headline": "Portal and Health NZ ordered to fix security after 99,416 patients' data exposed",
     "paraphrase": "After a cyberattack exposed health documents belonging to 99,416 people, a review found gaps in protection, weak oversight of tech suppliers and late notice to those affected. The portal operator and Health NZ were ordered to strengthen safeguards.",
     "source": "Stuff",
     "url": "https://www.stuff.co.nz/nz-news/361037084/nearly-100000-patients-had-health-data-exposed-now-two-agencies-have-been-ordered-fix-security",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-01-09",
     "headline": "Patients told their health records were stolen could not get answers",
     "paraphrase": "After a ransomware attack on a patient portal, a woman told her records were affected could not log in, and the helpline cut her off. Another was told both that her data was and was not affected.",
     "source": "RNZ",
     "url": "https://www.rnz.co.nz/news/business/583637/manage-my-health-patients-draw-blanks-in-quest-for-information-on-cybersecurity-breach",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2026-03-29",
     "headline": "Health NZ says two people can be wrongly linked to one patient number",
     "paraphrase": "Health NZ acknowledged that two people with near-identical details can be linked to one National Health Index number, and that some may have received the wrong care as a result. It said it keeps no central record of such cases.",
     "source": "RNZ",
     "url": "https://www.rnz.co.nz/news/health/590930/concerns-patients-receiving-incorrect-treatment-due-to-mistaken-identity",
     "theme": "record_wrong",
     "status": "admitted"
    },
    {
     "date": "2026-02-25",
     "headline": "Health worker used a colleague's login to open her ex-partner's records",
     "paraphrase": "An audit a man and his new partner requested showed his former partner, a health worker, had opened both their medical records using a colleague's login. She lost her job, and a court found her guilty.",
     "source": "RNZ",
     "url": "https://www.rnz.co.nz/news/regions_wellington/587931/health-worker-guilty-of-illegally-accessing-ex-partner-s-medical-records",
     "theme": "breach",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "USA",
   "name": "United States",
   "region": "Americas",
   "overall": 48,
   "rank": "47=",
   "likelyRank": "44 to 52",
   "band": "Mixed",
   "keysModel": "Institutional",
   "confidence": "high",
   "headline": "Americans have an enforced legal right to copies of their records, but providers and insurers decide most sharing, and health apps sit outside HIPAA.",
   "categories": {
    "access": {
     "score": 50,
     "summary": "HIPAA gives a right to the whole designated record set within 30 days at a cost-based fee, and OCR has brought 55 right of access enforcement actions. There is no national record: 65% used a portal in 2024, and 59% had more than one.",
     "sources": [
      {
       "title": "45 CFR 164.524 Access of individuals to protected health information (eCFR)",
       "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.524",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "HHS OCR settles HIPAA Right of Access investigation with Azul Vision (HHS)",
       "url": "https://www.hhs.gov/press-room/hhs-ocr-settles-hipaa-investigation-with-azul-vision.html",
       "date": "2026-08-27",
       "publisherClass": "official"
      },
      {
       "title": "Individuals' Access and Use of Patient Portals and Smartphone Health Apps, 2024, Data Brief 77 (ASTP/ONC)",
       "url": "https://healthit.gov/data/data-briefs/individuals-access-and-use-patient-portals-and-smartphone-health-apps-2024/",
       "date": "2025-07",
       "publisherClass": "official"
      },
      {
       "title": "OCR Director Says Carry On: July sees news of Security delay, surprise access reg (HCCA via JD Supra)",
       "url": "https://www.jdsupra.com/legalnews/ocr-director-says-carry-on-usually-6479185/",
       "date": "2026-08-06",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 35,
     "summary": "HIPAA lets providers and plans share records for treatment, payment and operations without consent, and they may refuse restriction requests. A block on items paid in full and a six-year disclosure log that omits routine sharing put the cell at the top of its band.",
     "sources": [
      {
       "title": "45 CFR 164.506 Uses and disclosures to carry out treatment, payment, or health care operations (eCFR)",
       "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.506",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "45 CFR 164.522 Rights to request privacy protection (eCFR)",
       "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.522",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "45 CFR 164.528 Accounting of disclosures (eCFR)",
       "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.528",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Confidentiality of Substance Use Disorder Patient Records, final rule (Federal Register)",
       "url": "https://www.federalregister.gov/documents/2024/02/16/2024-02544/confidentiality-of-substance-use-disorder-ud-patient-records",
       "date": "2024-02-16",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 50,
     "summary": "HIPAA is enforced, with breach reporting and fines, but breaches are vast: 397 large breaches exposed 33.77 million people in the first half of 2026. The Security Rule overhaul proposed in January 2025 now has a July 2027 target.",
     "sources": [
      {
       "title": "H1 2026 Healthcare Data Breach Report (HIPAA Journal)",
       "url": "https://www.hipaajournal.com/h1-2026-healthcare-data-breach-report/",
       "date": "2026-09-30",
       "publisherClass": "news"
      },
      {
       "title": "Unified Agenda: HIPAA Security Rule, RIN 0945-AA22 (OIRA, reginfo.gov)",
       "url": "https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202510&RIN=0945-AA22",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "HIPAA and Reproductive Health (HHS OCR)",
       "url": "https://www.hhs.gov/hipaa/for-professionals/special-topics/reproductive-health/index.html",
       "date": "2025-06-27",
       "publisherClass": "official"
      },
      {
       "title": "Texas SB 1188, enrolled text (Texas Legislature)",
       "url": "https://capitol.texas.gov/tlodocs/89R/billtext/html/SB01188F.htm",
       "date": "2025",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 60,
     "summary": "Exchange is growing: 76% of hospitals did all four exchange tasks in 2025, and TEFCA went from 10 million to over 1 billion records in under a year. There is still no national record, and payer APIs are due in 2027.",
     "sources": [
      {
       "title": "HHS expands secure access to health records through TEFCA, one billion records exchanged (HHS)",
       "url": "https://www.hhs.gov/press-room/onc-strengthens-tefca-one-billion-health-records-exchanged.html",
       "date": "2026-06-26",
       "publisherClass": "official"
      },
      {
       "title": "Electronic Health Information Exchange by Hospitals, Quick Stat (ASTP/ONC)",
       "url": "https://healthit.gov/data/quickstats/electronic-health-information-exchange-hospitals/",
       "date": "2026-02",
       "publisherClass": "official"
      },
      {
       "title": "Electronic Public Health Reporting Among Non-Federal Acute Care Hospitals, 2024, Data Brief 78 (ASTP/ONC)",
       "url": "https://healthit.gov/data/data-briefs/electronic-public-health-reporting-among-non-federal-acute-care-hospitals-2024/",
       "date": "2025-07",
       "publisherClass": "official"
      },
      {
       "title": "CMS Interoperability and Prior Authorization Final Rule CMS-0057-F (CMS)",
       "url": "https://www.cms.gov/newsroom/fact-sheets/cms-interoperability-prior-authorization-final-rule-cms-0057-f",
       "date": "2024-01-17",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 38,
     "summary": "Inside HIPAA, marketing and any sale of patient data need written authorization. But de-identified data falls outside the law, and health apps answer mainly to an FTC breach-notice rule and a few state laws such as Washington's.",
     "sources": [
      {
       "title": "45 CFR 164.508 Uses and disclosures for which an authorization is required (eCFR)",
       "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.508",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "45 CFR 164.514 De-identification of protected health information (eCFR)",
       "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "FTC Finalizes Changes to the Health Breach Notification Rule (FTC)",
       "url": "https://www.ftc.gov/news-events/news/press-releases/2024/04/ftc-finalizes-changes-health-breach-notification-rule",
       "date": "2024-04-26",
       "publisherClass": "official"
      },
      {
       "title": "RCW 19.373.070 Valid authorization to sell consumer health data (Washington Legislature)",
       "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.070",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 55,
     "summary": "HIPAA allows sharing for treatment without consent, so the limits are technical. In 2023, 71% of hospitals had routine access to outside records at the point of care, but only 42% said clinicians routinely used them.",
     "sources": [
      {
       "title": "Interoperable Exchange of Patient Health Information Among U.S. Hospitals: 2023, Data Brief 71 (ASTP/ONC)",
       "url": "https://healthit.gov/data/data-briefs/interoperable-exchange-patient-health-information-among-us-hospitals-2023/",
       "date": "2024-05",
       "publisherClass": "official"
      },
      {
       "title": "A Decade of Data Examined: The Evolution of Electronic Prescribing (ASTP/ONC)",
       "url": "https://healthit.gov/blog/health-data/a-decade-of-data-examined-the-evolution-of-electronic-prescribing/",
       "date": "2024-07-15",
       "publisherClass": "official"
      },
      {
       "title": "HHS Announces Crackdown on Health Data Blocking (HHS)",
       "url": "https://www.hhs.gov/press-room/hhs-crackdown-health-data-blocking.html",
       "date": "2025-09-03",
       "publisherClass": "official"
      },
      {
       "title": "The Wait Is Over: Information Blocking Enforcement Is Officially Here (Holland & Knight)",
       "url": "https://www.hklaw.com/en/insights/publications/2026/02/the-wait-is-over-information-blocking-enforcement-is-officially-here",
       "date": "2026-02",
       "publisherClass": "law_firm"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "An IRB or privacy board can waive the patient's authorization when risk is minimal, and de-identified data needs no consent, so there is no general opt-out. Three safeguards lift the cell: board review, Certificates of Confidentiality and a broad-consent route.",
     "sources": [
      {
       "title": "45 CFR 164.512 Uses and disclosures for which authorization is not required (eCFR)",
       "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.512",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "45 CFR 164.514 De-identification of protected health information (eCFR)",
       "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "45 CFR 46.116 General requirements for informed consent (eCFR)",
       "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-A/part-46/subpart-A/section-46.116",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Certificates of Confidentiality (NIH)",
       "url": "https://grants.nih.gov/policy-and-compliance/policy-topics/human-subjects/coc",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 56,
     "summary": "FDA regulates AI devices, listing about 1,600, and has final guidance on change control plans. But HHS proposed removing the only federal AI transparency rule for certified EHRs, and January 2026 guidance took more decision support software out of oversight.",
     "sources": [
      {
       "title": "Artificial Intelligence-Enabled Medical Devices (FDA)",
       "url": "https://www.fda.gov/medical-devices/software-medical-device-samd/artificial-intelligence-enabled-medical-devices",
       "date": "2026-09-04",
       "publisherClass": "official"
      },
      {
       "title": "Marketing Submission Recommendations for a Predetermined Change Control Plan for AI-Enabled Device Software Functions (FDA)",
       "url": "https://www.fda.gov/regulatory-information/search-fda-guidance-documents/marketing-submission-recommendations-predetermined-change-control-plan-artificial-intelligence",
       "date": "2025-08",
       "publisherClass": "official"
      },
      {
       "title": "HTI-5 proposed rule: ASTP/ONC deregulatory actions (Federal Register)",
       "url": "https://www.federalregister.gov/documents/2025/12/29/2025-23896/health-data-technology-and-interoperability-astponc-deregulatory-actions-to-unleash-prosperity",
       "date": "2025-12-29",
       "publisherClass": "legal_text"
      },
      {
       "title": "California AB 3030, health care services: artificial intelligence (California Legislature)",
       "url": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB3030",
       "date": "2024",
       "publisherClass": "legal_text"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "HIPAA Privacy Rule, right of access (45 CFR 164.524)",
     "level": "National",
     "year": "2000",
     "what": "Right to the designated record set within 30 days, cost-based fee, electronic format if readily producible.",
     "url": "https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.524"
    },
    {
     "name": "42 CFR Part 2, substance use disorder records final rule",
     "level": "National",
     "year": "2024",
     "what": "Single revocable consent for future treatment, payment and operations uses; compliance from February 16, 2026.",
     "url": "https://www.federalregister.gov/documents/2024/02/16/2024-02544/confidentiality-of-substance-use-disorder-ud-patient-records"
    },
    {
     "name": "FTC Health Breach Notification Rule (2024 update)",
     "level": "National",
     "year": "2024",
     "what": "Breach notice duties for health apps and similar technologies not covered by HIPAA.",
     "url": "https://www.ftc.gov/news-events/news/press-releases/2024/04/ftc-finalizes-changes-health-breach-notification-rule"
    },
    {
     "name": "CMS Interoperability and Prior Authorization Final Rule (CMS-0057-F)",
     "level": "National",
     "year": "2024",
     "what": "Payer FHIR APIs for patients, providers and payer-to-payer exchange, mostly by January 1, 2027.",
     "url": "https://www.cms.gov/newsroom/fact-sheets/cms-interoperability-prior-authorization-final-rule-cms-0057-f"
    },
    {
     "name": "Washington My Health My Data Act (RCW 19.373)",
     "level": "State/Provincial",
     "year": "2023",
     "what": "Consent to collect or share consumer health data outside HIPAA; signed authorization to sell it.",
     "url": "https://app.leg.wa.gov/RCW/default.aspx?cite=19.373.070"
    },
    {
     "name": "Texas SB 1188",
     "level": "State/Provincial",
     "year": "2025",
     "what": "Health records stored in the US from 2026; practitioners review AI records and disclose diagnostic AI use.",
     "url": "https://capitol.texas.gov/tlodocs/89R/billtext/html/SB01188F.htm"
    },
    {
     "name": "California AB 3030",
     "level": "State/Provincial",
     "year": "2024",
     "what": "Disclaimer and human contact route on generative AI patient messages not reviewed by a clinician.",
     "url": "https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB3030"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-08-27",
     "headline": "Patient waited almost two years for the records she had asked for",
     "paraphrase": "A complaint to the federal regulator said a provider did not give a patient timely access to her records. She received them almost two years after asking. The provider paid $50,000 and agreed to two years of monitoring.",
     "source": "U.S. Department of Health and Human Services, Office for Civil Rights",
     "url": "https://www.hhs.gov/press-room/hhs-ocr-settles-hipaa-investigation-with-azul-vision.html",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2025-12-16",
     "headline": "Six requests and more than a year before a patient got his records",
     "paraphrase": "A patient made six requests for his health information and waited more than a year to receive it. The regulator proposed a penalty; the provider settled before a hearing and paid $112,500.",
     "source": "U.S. Department of Health and Human Services, Office for Civil Rights",
     "url": "https://www.hhs.gov/press-room/ocr-settles-with-concentra.html",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2025-09-30",
     "headline": "Care provider posted patient stories online without written permission",
     "paraphrase": "A complaint said a group of care facilities put a patient's name, photo and care details on its website as a success story. The regulator found the same had happened to 150 patients without valid written authorization.",
     "source": "U.S. Department of Health and Human Services, Office for Civil Rights",
     "url": "https://www.hhs.gov/press-room/ocr-settles-hipaa-with-cadia-healthcare-facilities.html",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-01-15",
     "headline": "Patient asked by mail, phone and portal, then waited about nine months",
     "paraphrase": "A patient asked a health system for his medical records by mail, telephone and its patient portal. He received them about nine months later, only after the regulator opened an investigation. The system paid $60,000.",
     "source": "U.S. Department of Health and Human Services, Office for Civil Rights",
     "url": "https://www.hhs.gov/about/news/2025/01/15/hhs-office-civil-rights-settles-hipaa-case-against-memorial-healthcare-system-over-patient-access-records.html",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2025-01-24",
     "headline": "Insurer confirms health data of about 190 million Americans hit in one attack",
     "paraphrase": "A ransomware attack on a claims-processing company exposed names, ID numbers, insurance details and medical information such as test results and medications. Its parent company raised the count to about 190 million people. Attackers used a stolen credential.",
     "source": "TechCrunch",
     "url": "https://techcrunch.com/2025/01/24/unitedhealth-confirms-190-million-americans-affected-by-change-healthcare-data-breach/",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "IDN",
   "name": "Indonesia",
   "region": "Asia",
   "overall": 47,
   "rank": "50=",
   "likelyRank": "45 to 53",
   "band": "Mixed",
   "keysModel": "State",
   "confidence": "medium",
   "headline": "Indonesia's laws give patients rights to their records, but the ministry holds the data by default and the privacy regulator still does not exist.",
   "categories": {
    "access": {
     "score": 55,
     "summary": "The Health Law and the PDP Law give patients a right to their record data, with access due within 3 x 24 hours. SATUSEHAT Mobile shows a medical summary, not the full chart, and how widely it works was not verified.",
     "sources": [
      {
       "title": "Undang-Undang 17 Tahun 2023 tentang Kesehatan, annotated text (Mahkamah Konstitusi, Anotasi 2025)",
       "url": "https://s.mkri.id/public/content/infoumum/undang/pdf/Anotasi_180_ANOTASI%20UU%2017%20TAHUN%202023.pdf",
       "date": "2025",
       "publisherClass": "legal_text"
      },
      {
       "title": "Undang-Undang 27 Tahun 2022 tentang Pelindungan Data Pribadi (BPK JDIH)",
       "url": "https://peraturan.bpk.go.id/Download/224884/UU%20Nomor%2027%20Tahun%202022.pdf",
       "date": "2022-10-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kemenkes Luncurkan SATUSEHAT RME, Rekam Medis Pasien Terintegrasi Secara Nasional",
       "url": "https://www.kemkes.go.id/id/kemenkes-luncurkan-satusehat-rme-rekam-medis-pasien-terintegrasi-secara-nasional",
       "date": "2026-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Kemenkes Pastikan SatuSehat RME Bisa Diakses dalam Kondisi Darurat (Beritasatu)",
       "url": "https://www.beritasatu.com/lifestyle/3023896/kemenkes-pastikan-satusehat-rme-bisa-diakses-dalam-kondisi-darurat",
       "date": "2026-09-02",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 42,
     "summary": "Every facility must open its electronic records to the health ministry, with no patient choice. A 6-digit consent code and a patient-visible access history arrived with SATUSEHAT RME, which is starting in stages at a few named facilities.",
     "sources": [
      {
       "title": "Peraturan Menteri Kesehatan 24 Tahun 2022 tentang Rekam Medis",
       "url": "https://keslan.kemkes.go.id/unduhan/fileunduhan_1662611251_882318.pdf",
       "date": "2022",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kemenkes Luncurkan SATUSEHAT RME, Rekam Medis Pasien Terintegrasi Secara Nasional",
       "url": "https://www.kemkes.go.id/id/kemenkes-luncurkan-satusehat-rme-rekam-medis-pasien-terintegrasi-secara-nasional",
       "date": "2026-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Undang-Undang 27 Tahun 2022 tentang Pelindungan Data Pribadi (BPK JDIH)",
       "url": "https://peraturan.bpk.go.id/Download/224884/UU%20Nomor%2027%20Tahun%202022.pdf",
       "date": "2022-10-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Peraturan Pemerintah 28 Tahun 2024, pelaksanaan UU Kesehatan (JDIH Kemenkes)",
       "url": "https://jdih.kemkes.go.id/storage/documents/pdfs/2024pp028.pdf",
       "date": "2024-07-26",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 38,
     "summary": "Health data is specific personal data with 3 x 24 hour breach notice and fines up to 2% of revenue. But the data protection agency still does not exist nearly four years after the law, and the implementing regulation starts only in January 2027.",
     "sources": [
      {
       "title": "Undang-Undang 27 Tahun 2022 tentang Pelindungan Data Pribadi (BPK JDIH)",
       "url": "https://peraturan.bpk.go.id/Download/224884/UU%20Nomor%2027%20Tahun%202022.pdf",
       "date": "2022-10-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Dua Tahun UU PDP Tanpa Lembaga Pengawas, Pemerintah Bantah Ada Kekosongan Hukum (Hukumonline)",
       "url": "https://www.hukumonline.com/berita/a/dua-tahun-uu-pdp-tanpa-lembaga-pengawas--pemerintah-bantah-ada-kekosongan-hukum-lt6a69d92f6fce4/",
       "date": "2026-07-29",
       "publisherClass": "news"
      },
      {
       "title": "Ministry to issue decision on BPJS data leak soon (ANTARA)",
       "url": "https://en.antaranews.com/news/195925/ministry-to-issue-decision-on-bpjs-data-leak-soon",
       "date": "2021",
       "publisherClass": "news"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 57,
     "summary": "By 31 July 2026, 42,337 health facilities were integrated with SATUSEHAT, the national interoperability platform. Many hospitals still send incomplete data, and the person-based record and the claims link are only starting.",
     "sources": [
      {
       "title": "Kemenkes RI Raih Penghargaan Nasional dan Global Sekaligus untuk SATUSEHAT",
       "url": "https://kemkes.go.id/id/kemenkes-ri-raih-penghargaan-nasional-dan-global-sekaligus-untuk-satusehat",
       "date": "2026-09-24",
       "publisherClass": "official"
      },
      {
       "title": "Wajib Integrasi Satu Sehat, Kemenkes Desak Percepatan RME di Fasyankes (BKPK Kemenkes)",
       "url": "https://www.badankebijakan.kemkes.go.id/wajib-integrasi-satu-sehat-kemenkes-desak-percepatan-rme-di-fasyankes/",
       "date": "2025-10-28",
       "publisherClass": "official"
      },
      {
       "title": "Dukcapil Perkuat Validasi Identitas, Dukung Integrasi Rekam Medis Elektronik dengan SATUSEHAT",
       "url": "https://dukcapil.kemendagri.go.id/blog/read/dukcapil-perkuat-validasi-identitas-dukung-integrasi-rekam-medis-elektronik-dengan-satusehat",
       "date": "2026-08-01",
       "publisherClass": "official"
      },
      {
       "title": "Peraturan Pemerintah 28 Tahun 2024, pelaksanaan UU Kesehatan (JDIH Kemenkes)",
       "url": "https://jdih.kemkes.go.id/storage/documents/pdfs/2024pp028.pdf",
       "date": "2024-07-26",
       "publisherClass": "legal_text"
      }
     ]
    },
    "commercial": {
     "score": 42,
     "summary": "Health data needs explicit consent or another legal basis, and the Health Law limits national health system data to care, public health, development and policy. No specific ban on selling health data was found, and no regulator enforces the PDP Law yet.",
     "sources": [
      {
       "title": "Undang-Undang 17 Tahun 2023 tentang Kesehatan, annotated text (Mahkamah Konstitusi, Anotasi 2025)",
       "url": "https://s.mkri.id/public/content/infoumum/undang/pdf/Anotasi_180_ANOTASI%20UU%2017%20TAHUN%202023.pdf",
       "date": "2025",
       "publisherClass": "legal_text"
      },
      {
       "title": "Undang-Undang 27 Tahun 2022 tentang Pelindungan Data Pribadi (BPK JDIH)",
       "url": "https://peraturan.bpk.go.id/Download/224884/UU%20Nomor%2027%20Tahun%202022.pdf",
       "date": "2022-10-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Dua Tahun UU PDP Tanpa Lembaga Pengawas, Pemerintah Bantah Ada Kekosongan Hukum (Hukumonline)",
       "url": "https://www.hukumonline.com/berita/a/dua-tahun-uu-pdp-tanpa-lembaga-pengawas--pemerintah-bantah-ada-kekosongan-hukum-lt6a69d92f6fce4/",
       "date": "2026-07-29",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 40,
     "summary": "Under SATUSEHAT RME, launched 1 September 2026, a clinician can open a patient's cross-facility record with the patient's code, but rollout is staged and only two hospitals were named. Elsewhere data moves between facilities through referral transfers on the national platform.",
     "sources": [
      {
       "title": "Kemenkes Luncurkan SATUSEHAT RME, Rekam Medis Pasien Terintegrasi Secara Nasional",
       "url": "https://www.kemkes.go.id/id/kemenkes-luncurkan-satusehat-rme-rekam-medis-pasien-terintegrasi-secara-nasional",
       "date": "2026-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Kemenkes Pastikan SatuSehat RME Bisa Diakses dalam Kondisi Darurat (Beritasatu)",
       "url": "https://www.beritasatu.com/lifestyle/3023896/kemenkes-pastikan-satusehat-rme-bisa-diakses-dalam-kondisi-darurat",
       "date": "2026-09-02",
       "publisherClass": "news"
      },
      {
       "title": "Peraturan Menteri Kesehatan 24 Tahun 2022 tentang Rekam Medis",
       "url": "https://keslan.kemkes.go.id/unduhan/fileunduhan_1662611251_882318.pdf",
       "date": "2022",
       "publisherClass": "legal_text"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "Records can be opened for research without consent if identity is withheld and the Minister approves, and there is no general opt-out. Ethics committee approval is required, and biomedical specimens and linked data need donor consent.",
     "sources": [
      {
       "title": "Peraturan Menteri Kesehatan 24 Tahun 2022 tentang Rekam Medis",
       "url": "https://keslan.kemkes.go.id/unduhan/fileunduhan_1662611251_882318.pdf",
       "date": "2022",
       "publisherClass": "legal_text"
      },
      {
       "title": "Undang-Undang 17 Tahun 2023 tentang Kesehatan, annotated text (Mahkamah Konstitusi, Anotasi 2025)",
       "url": "https://s.mkri.id/public/content/infoumum/undang/pdf/Anotasi_180_ANOTASI%20UU%2017%20TAHUN%202023.pdf",
       "date": "2025",
       "publisherClass": "legal_text"
      },
      {
       "title": "Komite Etik Penelitian dan Pengembangan Kesehatan Nasional (KEPPKN, Kemenkes)",
       "url": "https://kepkn.kemkes.go.id/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 56,
     "summary": "A health ministry decree in force since 7 September 2026 covers AI medical devices, requiring change control for self-learning models, rollback, hallucination controls for generative models and local validation. It is new, and human oversight is a documentation item, not a mandate.",
     "sources": [
      {
       "title": "Keputusan Menteri Kesehatan HK.01.07/MENKES/951/2026, Pedoman Izin Edar Alat Kesehatan Berbasis Perangkat Lunak",
       "url": "https://jdih.kemkes.go.id/storage/documents/pdfs/2026kepmenkes951.pdf",
       "date": "2026-09-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kemenkes Dorong Pengembangan Ekosistem AI Kesehatan yang Aman, Adil, dan Bertanggung Jawab",
       "url": "https://keslan.kemkes.go.id/read/3798/kemenkes-dorong-pengembangan-ekosistem-ai-kesehatan-yang-aman-adil-dan-bertanggung-jawab",
       "date": "2026-06",
       "publisherClass": "official"
      },
      {
       "title": "AFTECH Akui Masih Tunggu Dua Perpres AI untuk Perkuat Tata Kelola Digital (Investortrust)",
       "url": "https://investortrust.id/national/109712/aftech-akui-masih-tunggu-dua-perpres-ai-untuk-perkuat-tata-kelola-digital",
       "date": "2026-07-16",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Law 17/2023 on Health",
     "level": "National",
     "year": "2023",
     "what": "Patient access to record information; consent for health data processing; data portability; local processing of health data.",
     "url": "https://s.mkri.id/public/content/infoumum/undang/pdf/Anotasi_180_ANOTASI%20UU%2017%20TAHUN%202023.pdf"
    },
    {
     "name": "Law 27/2022 on Personal Data Protection",
     "level": "National",
     "year": "2022",
     "what": "Health is specific data; access within 3 x 24 hours; breach notice; fines up to 2% of revenue.",
     "url": "https://peraturan.bpk.go.id/Download/224884/UU%20Nomor%2027%20Tahun%202022.pdf"
    },
    {
     "name": "Government Regulation 28/2024 (Health Law implementing rules)",
     "level": "National",
     "year": "2024",
     "what": "Electronic records mandatory and integrated nationally; rules for opening records with and without consent.",
     "url": "https://jdih.kemkes.go.id/storage/documents/pdfs/2024pp028.pdf"
    },
    {
     "name": "Government Regulation 33/2026 (PDP Law implementing rules)",
     "level": "National",
     "year": "2026",
     "what": "Detailed consent, correction and research exemption rules; enacted 16 July 2026, in force January 2027.",
     "url": "https://static.banyumaskab.go.id/website/file/peraturan_pemerintah_no._33_tahun_2026_100926115902.pdf"
    },
    {
     "name": "Minister of Health Regulation 24/2022 on Medical Records",
     "level": "National",
     "year": "2022",
     "what": "Record content belongs to patient; facilities must open records to ministry; referral transfers via national platform.",
     "url": "https://keslan.kemkes.go.id/unduhan/fileunduhan_1662611251_882318.pdf"
    },
    {
     "name": "Minister of Health Decree HK.01.07/MENKES/951/2026",
     "level": "National",
     "year": "2026",
     "what": "Marketing authorization for software and AI medical devices, including change control and local validation.",
     "url": "https://jdih.kemkes.go.id/storage/documents/pdfs/2026kepmenkes951.pdf"
    }
   ],
   "dti": {
    "grade": 84,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-09-24",
     "headline": "Patient's lawyer says a public hospital gave only partial copies of her records",
     "paraphrase": "A woman asked a regional public hospital in Banten for copies of her medical records through her lawyer. The lawyer says only incomplete copies came, a legal notice went unanswered, and a Health Ministry complaint would follow.",
     "source": "MediaBanten.com",
     "url": "https://mediabanten.com/salinan-rekam-medis-tak-diberikan-rs-drajat-akan-dilaporkan-ke-kemenkes/",
     "theme": "access_refused",
     "status": "alleged"
    },
    {
     "date": "2026-09-26",
     "headline": "Patient says referral records sent to a hospital abroad were incomplete",
     "paraphrase": "A patient in East Kalimantan alleges that the procedure video a public hospital sent with his referral abroad had cuts at crucial moments, and that the referral letter described his condition as good when it was not.",
     "source": "Swarakaltim.com",
     "url": "https://swarakaltim.com/2026/09/26/diduga-alami-malapraktik-kawat-tertinggal-di-jantung-pasien-rsud-aws-layangkan-somasi-dan-tuntut-kompensasi-rp5-miliar/",
     "theme": "lost_between_providers",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "IRL",
   "name": "Ireland",
   "region": "Europe",
   "overall": 47,
   "rank": "50=",
   "likelyRank": "45 to 54",
   "band": "Mixed",
   "keysModel": "State",
   "confidence": "high",
   "headline": "Irish records are still largely paper, but a national Shared Care Record went live for clinicians in 2026; patient controls are legislated, not in force.",
   "categories": {
    "access": {
     "score": 55,
     "summary": "Patients have a free GDPR and FOI right to their whole record, but get it by writing to each hospital or service. The HSE Health App shows only part of the record (appointments, waiting lists, vaccines) and had about 125,000 registered users in January 2026.",
     "sources": [
      {
       "title": "Access to medical records in the public healthcare system (Citizens Information)",
       "url": "https://www.citizensinformation.ie/en/health/legal-matters-and-health/access-to-medical-records/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Minister for Health welcomes increase in HSE Health app usage as registrations pass 125,000 (Department of Health)",
       "url": "https://www.gov.ie/en/department-of-health/press-releases/minister-for-health-welcomes-increase-in-hse-health-app-usage-as-registrations-pass-125000/",
       "date": "2026-01-05",
       "publisherClass": "official"
      },
      {
       "title": "Ireland confirmed as one of the EU's strongest digital performers (Department of Enterprise, Tourism and Employment)",
       "url": "https://enterprise.gov.ie/en/news-and-events/department-news/2026/august/ireland-confirmed-as-one-of-the-eus-strongest-digital-performers.html",
       "date": "2026-08-06",
       "publisherClass": "official"
      },
      {
       "title": "2026 Digital Decade eHealth Indicator Study, executive summary (European Commission)",
       "url": "https://data.europa.eu/doi/10.2759/8560168",
       "date": "2026-06",
       "publisherClass": "intergov"
      }
     ]
    },
    "control": {
     "score": 30,
     "summary": "The new Shared Care Record shares data by default on a public interest basis, with no opt-out found and no patient-readable access log. Rights to restrict access and to be told who looked are in the Health Information Act 2026 but not commenced.",
     "sources": [
      {
       "title": "Data Protection Impact Assessment summary: Shared Care Record (HSE)",
       "url": "https://about.hse.ie/publications/national-shared-care-record-dpia/",
       "date": "2026-03",
       "publisherClass": "official"
      },
      {
       "title": "HSE Privacy Notice for patients and service users (HSE)",
       "url": "https://about.hse.ie/publications/hse-privacy-notice-service-users/",
       "date": "2024-12",
       "publisherClass": "official"
      },
      {
       "title": "Health Information Act 2026, No. 10 of 2026 (Irish Statute Book)",
       "url": "https://www.irishstatutebook.ie/eli/2026/act/10/enacted/en/index.html",
       "date": "2026-04-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Health Information Act 2026: commencement table (Irish Statute Book)",
       "url": "https://www.irishstatutebook.ie/eli/isbc/2026_10.html",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 56,
     "summary": "The Data Protection Commission fined the HSE twice in 2026 (300,000 and 645,000 euros) for health record failures and reprimanded Children's Health Ireland. Fines on public bodies are capped at 1 million euros, and one case took over seven years.",
     "sources": [
      {
       "title": "DPC announces final decision following inquiry into the HSE (paper records storage)",
       "url": "https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-announces-final-decision-following-inquiry-health-service-executive-hse",
       "date": "2026-09-02",
       "publisherClass": "official"
      },
      {
       "title": "Inquiry into Midlands Regional Hospital Tullamore (Data Protection Commission decision)",
       "url": "https://www.dataprotection.ie/en/dpc-guidance/decisions/inquiry-midlands-regional-hospital-tullamore",
       "date": "2026-06-10",
       "publisherClass": "official"
      },
      {
       "title": "DPC publishes final decision following inquiry into Children's Health Ireland",
       "url": "https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-publishes-final-decision-following-inquiry-childrens-health-ireland-chi",
       "date": "2026-10-01",
       "publisherClass": "official"
      },
      {
       "title": "Data Protection Act 2018, section 141 (Irish Statute Book)",
       "url": "https://www.irishstatutebook.ie/eli/2018/act/7/section/141/enacted/en/html",
       "date": "2018",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 38,
     "summary": "A national Shared Care Record released nationally in early 2026 now pulls medicines, GP labs and radiology, discharge summaries and vaccines into one read-only view. But the Department of Health says records remain 'fragmented and largely paper-based', and a national EHR is only in procurement.",
     "sources": [
      {
       "title": "HSE Shared Care Record (HSE)",
       "url": "https://about.hse.ie/our-work/technology/shared-care-record/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Shared Care Record continues to grow with expanded datasets and nationwide rollout (HSE)",
       "url": "https://about.hse.ie/news/national-shared-care-record-nscr-continues-to-grow-with-expanded-datasets-and-nationwide-rollout/",
       "date": "2026-06-19",
       "publisherClass": "official"
      },
      {
       "title": "Minister announces Government approval to commence procurement for a National Electronic Health Record (Department of Health)",
       "url": "https://www.gov.ie/en/department-of-health/press-releases/minister-announces-government-approval-to-commence-procurement-for-a-national-electronic-health-record/",
       "date": "2026-02-05",
       "publisherClass": "official"
      },
      {
       "title": "HSE Laboratory Information System (MedLIS) (HSE)",
       "url": "https://about.hse.ie/our-work/technology/national-laboratory-information-system-medlis/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 58,
     "summary": "Research use of personal health data, including commercial research, needs explicit consent unless a national committee grants a declaration. We found no Irish ban on selling health data or on its use for advertising.",
     "sources": [
      {
       "title": "Data Protection Act 2018 (Section 36(2)) (Health Research) Regulations 2018, S.I. No. 314 of 2018 (Irish Statute Book)",
       "url": "https://www.irishstatutebook.ie/eli/2018/si/314/made/en/print",
       "date": "2018",
       "publisherClass": "legal_text"
      },
      {
       "title": "Who we are (Health Research Consent Declaration Committee)",
       "url": "https://hrcdc.ie/who-we-are/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Health Information Act 2026, No. 10 of 2026 (Irish Statute Book)",
       "url": "https://www.irishstatutebook.ie/eli/2026/act/10/enacted/en/index.html",
       "date": "2026-04-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Health Information Act 2026: commencement table (Irish Statute Book)",
       "url": "https://www.irishstatutebook.ie/eli/isbc/2026_10.html",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 36,
     "summary": "Over 2,500 HSE staff use the Shared Care Record to see a patient's medicines, results and discharge summaries from other services. It is read-only, not a complete record, and open only to HSE staff on the HSE network.",
     "sources": [
      {
       "title": "HSE Shared Care Record (HSE)",
       "url": "https://about.hse.ie/our-work/technology/shared-care-record/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Data Protection Impact Assessment summary: Shared Care Record (HSE)",
       "url": "https://about.hse.ie/publications/national-shared-care-record-dpia/",
       "date": "2026-03",
       "publisherClass": "official"
      },
      {
       "title": "Almost 100k patient record requests amid lack of online system (RTÉ)",
       "url": "https://www.rte.ie/news/2026/0513/1573052-hse-medical-records/",
       "date": "2026-05-13",
       "publisherClass": "news"
      },
      {
       "title": "Health Information Act 2026: commencement table (Irish Statute Book)",
       "url": "https://www.irishstatutebook.ie/eli/isbc/2026_10.html",
       "date": "undated",
       "publisherClass": "legal_text"
      }
     ]
    },
    "research": {
     "score": 70,
     "summary": "Explicit consent is the default for using personal data in health research, and a national committee can waive it only where the public interest significantly outweighs consent. The committee publishes an application log and meeting minutes.",
     "sources": [
      {
       "title": "Data Protection Act 2018 (Section 36(2)) (Health Research) Regulations 2018, S.I. No. 314 of 2018 (Irish Statute Book)",
       "url": "https://www.irishstatutebook.ie/eli/2018/si/314/made/en/print",
       "date": "2018",
       "publisherClass": "legal_text"
      },
      {
       "title": "Who we are (Health Research Consent Declaration Committee)",
       "url": "https://hrcdc.ie/who-we-are/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Decisions: public application log and meeting minutes (HRCDC)",
       "url": "https://hrcdc.ie/decisions/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "HealthData@IE: national project implementing EHDS (Department of Health)",
       "url": "https://www.gov.ie/en/department-of-health/collections/healthdataie-national-project-implementing-ehds/",
       "date": "2026-09-09",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "Clinical AI falls under EU device law and the EU AI Act. Ireland's Regulation of Artificial Intelligence Act 2026 sets up an AI Office but, by the government's own account, adds no obligations, and HIQA's July 2026 AI guidance is good-practice guidance.",
     "sources": [
      {
       "title": "AI Office of Ireland established under the Regulation of Artificial Intelligence Act 2026 (DETE)",
       "url": "https://www.gov.ie/en/department-of-enterprise-tourism-and-employment/press-releases/ai-office-of-ireland-established-under-the-ai-regulation-bill-2026-paul-byrne-appointed-as-ceo/",
       "date": "2026-07-30",
       "publisherClass": "official"
      },
      {
       "title": "HIQA publishes first National Guidance on Responsible and Safe Use of AI in Health and Social Care (HIQA)",
       "url": "https://www.hiqa.ie/hiqa-news-updates/hiqa-publishes-first-national-guidance-responsible-and-safe-use-ai-health-and",
       "date": "2026-07-29",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Health Information Act 2026 (No. 10 of 2026)",
     "level": "National",
     "year": "2026",
     "what": "National EHR for every patient, duty to share, restriction and access-notice rights; key sections not commenced.",
     "url": "https://www.irishstatutebook.ie/eli/2026/act/10/enacted/en/index.html"
    },
    {
     "name": "Data Protection Act 2018 (Section 36(2)) (Health Research) Regulations 2018 (S.I. 314/2018)",
     "level": "National",
     "year": "2018",
     "what": "Explicit consent is a required safeguard for health research, unless the HRCDC grants a declaration.",
     "url": "https://www.irishstatutebook.ie/eli/2018/si/314/made/en/print"
    },
    {
     "name": "Data Protection Act 2018",
     "level": "National",
     "year": "2018",
     "what": "Irish GDPR law; fines on public bodies capped at 1 million euros (s. 141).",
     "url": "https://www.irishstatutebook.ie/eli/2018/act/7/section/141/enacted/en/html"
    },
    {
     "name": "Freedom of Information Act 2014",
     "level": "National",
     "year": "2014",
     "what": "Right of access to personal records held by the HSE, voluntary hospitals and GP records of medical card holders.",
     "url": "https://www.citizensinformation.ie/en/health/legal-matters-and-health/access-to-medical-records/"
    },
    {
     "name": "General Data Protection Regulation (EU) 2016/679",
     "level": "Supranational",
     "year": "2016",
     "what": "Health data is a special category; access within one month, first copy free.",
     "url": "https://www.edpb.europa.eu/sme/be-compliant/respect-individuals-rights_en"
    },
    {
     "name": "European Health Data Space Regulation (EU) 2025/327",
     "level": "Supranational",
     "year": "2025",
     "what": "Patient access, restriction and access logs, cross-border exchange and secondary-use permits, phased 2029 to 2031.",
     "url": "https://health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en"
    },
    {
     "name": "Regulation of Artificial Intelligence Act 2026",
     "level": "National",
     "year": "2026",
     "what": "Creates the AI Office of Ireland to coordinate EU AI Act enforcement; adds no new obligations.",
     "url": "https://www.gov.ie/en/department-of-enterprise-tourism-and-employment/press-releases/ai-office-of-ireland-established-under-the-ai-regulation-bill-2026-paul-byrne-appointed-as-ceo/"
    }
   ],
   "dti": {
    "grade": 89,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-09-02",
     "headline": "Health service fined €645,000 over neglected and insecure paper record stores",
     "paraphrase": "Intruders reached medical records kept in disused buildings. Inspections at 12 sites found records damaged by mould, water and rubble, kept longer than needed and not filed in any accessible way. The regulator fined the HSE €645,000.",
     "source": "Data Protection Commission",
     "url": "https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-announces-final-decision-following-inquiry-health-service-executive-hse",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-06-30",
     "headline": "Patient's request to correct GP record went unanswered until the regulator asked",
     "paraphrase": "A patient asked a former GP surgery to correct entries they believed were wrong and heard nothing. After the regulator stepped in, the surgery apologised, kept the entries as clinical opinion, and offered to add the patient's disagreement.",
     "source": "Data Protection Commission (Annual Report 2025 case studies)",
     "url": "https://www.dataprotection.ie/sites/default/files/uploads/2026-06/DPC-Case-Studies-Booklet-2025-Final.pdf",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2026-06-30",
     "headline": "GP surgery emailed a patient's details unencrypted to the wrong person",
     "paraphrase": "A small GP surgery recorded a mistyped email address without checking it, then sent the patient's personal data, unencrypted, from a free email account to a stranger. After the regulator engaged, it moved to secure email and a patient portal.",
     "source": "Data Protection Commission (Annual Report 2025 case studies)",
     "url": "https://www.dataprotection.ie/sites/default/files/uploads/2026-06/DPC-Case-Studies-Booklet-2025-Final.pdf",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-06",
     "headline": "Hospital released a patient's records only after the regulator stepped in",
     "paraphrase": "A patient asked a public hospital for all the personal data it held. More than a month later there was still no answer, though the matter was urgent. The records were provided only after the regulator contacted the hospital group.",
     "source": "Data Protection Commission (Annual Report 2024 case studies)",
     "url": "https://www.dataprotection.ie/sites/default/files/uploads/2025-08/DPC_Cases_Studies_EN_Low_Res.pdf",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2025-06",
     "headline": "Medical facility sent a worker's full consultation notes to their employer",
     "paraphrase": "A worker was sent by their employer to a medical facility. The facility gave the employer, including the HR department, full consultation notes with past medical history, assuming consent. The regulator found the disclosure unlawful.",
     "source": "Data Protection Commission (Annual Report 2024 case studies)",
     "url": "https://www.dataprotection.ie/sites/default/files/uploads/2025-08/DPC_Cases_Studies_EN_Low_Res.pdf",
     "theme": "sold_or_shared",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "VNM",
   "name": "Vietnam",
   "region": "Asia",
   "overall": 47,
   "rank": "50=",
   "likelyRank": "45 to 53",
   "band": "Mixed",
   "keysModel": "State",
   "confidence": "high",
   "headline": "Vietnamese patients can download visit records in their ID app, but every facility must feed a national database with no opt-out.",
   "categories": {
    "access": {
     "score": 60,
     "summary": "Law 15/2023 lets patients read and copy their record on written request, and Decree 356 sets a 10-day deadline. VNeID shows visit summaries, labs and drugs as downloadable PDFs, but only 34 million people had one in September 2026, short of most residents.",
     "sources": [
      {
       "title": "Luật Khám bệnh, chữa bệnh số 15/2023/QH15, toàn văn (Xây dựng chính sách, Cổng TTĐT Chính phủ)",
       "url": "https://xaydungchinhsach.chinhphu.vn/toan-van-luat-15-2023-qh15-kham-benh-chua-benh-119231127164453959.htm",
       "date": "2023-11-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Nghị định 356/2025/NĐ-CP quy định chi tiết Luật Bảo vệ dữ liệu cá nhân (LuatVietnam)",
       "url": "https://luatvietnam.vn/dan-su/nghi-dinh-356-2025-nd-cp-quy-dinh-chi-tiet-luat-bao-ve-du-lieu-ca-nhan-422896-d1.html",
       "date": "2025-12-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Sổ sức khỏe điện tử trên VNeID có thể thay sổ giấy (Báo Điện tử Chính phủ)",
       "url": "https://baochinhphu.vn/so-suc-khoe-dien-tu-tren-vneid-co-the-thay-so-giay-102260108162952758.htm",
       "date": "2026-01-08",
       "publisherClass": "official"
      },
      {
       "title": "Hơn 34 triệu người đã có Sổ sức khỏe điện tử trên VNeID (VOV)",
       "url": "https://vov.gov.vn/hon-34-trieu-nguoi-da-co-so-suc-khoe-dien-tu-tren-vneid-mobiledtnew-1165910",
       "date": "2026-09-21",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 30,
     "summary": "Decree 102/2025 makes every facility push records to the national health database and VNeID, with no article letting a patient opt out. Agency heads may release health data without consent for public interest, and no patient-visible access log was found.",
     "sources": [
      {
       "title": "Decree 102/2025/ND-CP on health data management, English text (LuatVietnam)",
       "url": "https://english.luatvietnam.vn/y-te/decree-102-2025-nd-cp-health-data-management-400071-d1.html",
       "date": "2025-05-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Luật Bảo vệ dữ liệu cá nhân 2025, số 91/2025/QH15 (LuatVietnam)",
       "url": "https://luatvietnam.vn/dan-su/luat-bao-ve-du-lieu-ca-nhan-2025-so-91-2025-qh15-405135-d1.html",
       "date": "2025-06-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Nghị định 356/2025/NĐ-CP quy định chi tiết Luật Bảo vệ dữ liệu cá nhân (LuatVietnam)",
       "url": "https://luatvietnam.vn/dan-su/nghi-dinh-356-2025-nd-cp-quy-dinh-chi-tiet-luat-bao-ve-du-lieu-ca-nhan-422896-d1.html",
       "date": "2025-12-31",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 42,
     "summary": "Health is sensitive data under the 2025 PDP Law, with 72-hour breach notice, fines up to VND 3 billion (5% of revenue for cross-border breaches) and an August 2026 sanctions decree. But the regulator is the police ministry, state uses are exempt from consent, and hospital hacks continue.",
     "sources": [
      {
       "title": "Luật Bảo vệ dữ liệu cá nhân 2025, số 91/2025/QH15 (LuatVietnam)",
       "url": "https://luatvietnam.vn/dan-su/luat-bao-ve-du-lieu-ca-nhan-2025-so-91-2025-qh15-405135-d1.html",
       "date": "2025-06-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Nghị định 356/2025/NĐ-CP quy định chi tiết Luật Bảo vệ dữ liệu cá nhân (LuatVietnam)",
       "url": "https://luatvietnam.vn/dan-su/nghi-dinh-356-2025-nd-cp-quy-dinh-chi-tiet-luat-bao-ve-du-lieu-ca-nhan-422896-d1.html",
       "date": "2025-12-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Mức xử phạt vi phạm hành chính đối với hành vi vi phạm về bảo vệ dữ liệu cá nhân (Báo Điện tử Chính phủ)",
       "url": "https://baochinhphu.vn/muc-xu-phat-vi-pham-hanh-chinh-doi-voi-hanh-vi-vi-pham-ve-bao-ve-du-lieu-ca-nhan-102260822154959691.htm",
       "date": "2026-08-22",
       "publisherClass": "official"
      },
      {
       "title": "Cảnh báo rò rỉ dữ liệu y tế do hacker (Thanh Niên)",
       "url": "https://thanhnien.vn/canh-bao-ro-ri-du-lieu-y-te-do-hacker-185260524204547959.htm",
       "date": "2026-05-25",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 55,
     "summary": "By 19 September 2026, 1,268 of 1,650 hospitals had electronic records and 99.5% of facilities linked to the social insurance claims system. The ministry admits many hospitals still run paper in parallel, and lab and pharmacy links are still being built.",
     "sources": [
      {
       "title": "Số cơ sở y tế tham gia bệnh án điện tử tiếp tục tăng (Sức khỏe & Đời sống, Bộ Y tế)",
       "url": "https://suckhoedoisong.vn/so-co-so-y-te-tham-gia-benh-an-dien-tu-tiep-tuc-tang-169260919154315649.htm",
       "date": "2026-09-19",
       "publisherClass": "official"
      },
      {
       "title": "Cổng thông tin Bệnh án điện tử, danh sách cơ sở tham gia (Bộ Y tế)",
       "url": "https://benhandientu.moh.gov.vn/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Hơn 75% bệnh viện triển khai bệnh án điện tử, tiến tới bỏ bệnh án giấy từ năm 2027 (Báo Đầu tư)",
       "url": "https://baodautu.vn/hon-75-benh-vien-trien-khai-benh-an-dien-tu-tien-toi-bo-benh-an-giay-tu-nam-2027-d701953.html",
       "date": "2026-09-14",
       "publisherClass": "news"
      },
      {
       "title": "Cơ sở bán buôn, bán lẻ thuốc phải liên thông dữ liệu từ 01/01/2026 lên Hệ thống Cơ sở dữ liệu về dược (LuatVietnam)",
       "url": "https://luatvietnam.vn/tin-van-ban-moi/co-so-ban-buon-ban-le-thuoc-phai-lien-thong-du-lieu-tu-01-01-2026-len-he-thong-co-so-du-lieu-ve-duoc-186-111475-article.html",
       "date": "2026-08-14",
       "publisherClass": "law_firm"
      }
     ]
    },
    "commercial": {
     "score": 55,
     "summary": "The PDP Law bans buying and selling personal data, with fines up to 10 times the revenue gained, and bars health bodies from giving data to insurers without the person's written request. De-identified data falls outside the law.",
     "sources": [
      {
       "title": "Luật Bảo vệ dữ liệu cá nhân 2025, số 91/2025/QH15 (LuatVietnam)",
       "url": "https://luatvietnam.vn/dan-su/luat-bao-ve-du-lieu-ca-nhan-2025-so-91-2025-qh15-405135-d1.html",
       "date": "2025-06-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Những quy định đáng chú ý trong Luật Bảo vệ dữ liệu cá nhân 2025 (Xây dựng chính sách, Cổng TTĐT Chính phủ)",
       "url": "https://xaydungchinhsach.chinhphu.vn/nhung-quy-dinh-dang-chu-y-trong-luat-bao-ve-du-lieu-ca-nhan-2025-119251225084154179.htm",
       "date": "2025-12-25",
       "publisherClass": "official"
      },
      {
       "title": "Công an TP Hà Nội khởi tố 3 người điều hành sàn mua bán dữ liệu cá nhân (VietNamNet)",
       "url": "https://vietnamnet.vn/cong-an-tp-ha-noi-khoi-to-3-nguoi-dieu-hanh-san-mua-ban-du-lieu-ca-nhan-2534474.html",
       "date": "2026-07-10",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 44,
     "summary": "Treating doctors may open a patient's VNeID health book, which carries visit summaries, test values and drugs from other facilities. The full chart from another hospital needs that hospital's consent, and cross-facility reuse of test results is still a draft.",
     "sources": [
      {
       "title": "Luật Khám bệnh, chữa bệnh số 15/2023/QH15, toàn văn (Xây dựng chính sách, Cổng TTĐT Chính phủ)",
       "url": "https://xaydungchinhsach.chinhphu.vn/toan-van-luat-15-2023-qh15-kham-benh-chua-benh-119231127164453959.htm",
       "date": "2023-11-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Giảm xét nghiệm trùng lặp, đưa dịch vụ đến gần người dân (Báo Đầu tư)",
       "url": "https://baodautu.vn/giam-xet-nghiem-trung-lap-dua-dich-vu-den-gan-nguoi-dan-d710899.html",
       "date": "2026-10-01",
       "publisherClass": "news"
      },
      {
       "title": "Bộ Y tế đề xuất hơn 400 xét nghiệm, điện quang có thể dùng lại khi chuyển viện khám, chữa bệnh BHYT (Bảo hiểm xã hội Việt Nam)",
       "url": "https://baohiemxahoi.gov.vn/tintuc/Pages/cai-cach-thu-tuc-hanh-chinh.aspx?CateID=0&ItemID=27035",
       "date": "2026-08-25",
       "publisherClass": "official"
      },
      {
       "title": "Sổ sức khỏe điện tử trên VNeID có thể thay sổ giấy (Báo Điện tử Chính phủ)",
       "url": "https://baochinhphu.vn/so-suc-khoe-dien-tu-tren-vneid-co-the-thay-so-giay-102260108162952758.htm",
       "date": "2026-01-08",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Patients may refuse biomedical research and trials need written consent and ethics approval. Archived records can be lent to researchers with only the hospital's approval, with no opt-out, so the score is capped at 50.",
     "sources": [
      {
       "title": "Luật Khám bệnh, chữa bệnh số 15/2023/QH15, toàn văn (Xây dựng chính sách, Cổng TTĐT Chính phủ)",
       "url": "https://xaydungchinhsach.chinhphu.vn/toan-van-luat-15-2023-qh15-kham-benh-chua-benh-119231127164453959.htm",
       "date": "2023-11-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Thông tư 50/2025/TT-BYT quy định về thử thuốc trên lâm sàng (LuatVietnam)",
       "url": "https://luatvietnam.vn/y-te/thong-tu-50-2025-tt-byt-quy-dinh-thu-thuoc-tren-lam-sang-hieu-luc-tu-27-02-2026-422988-d1.html",
       "date": "2025-12-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Decree 102/2025/ND-CP on health data management, English text (LuatVietnam)",
       "url": "https://english.luatvietnam.vn/y-te/decree-102-2025-nd-cp-health-data-management-400071-d1.html",
       "date": "2025-05-13",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 50,
     "summary": "The AI Law in force since 1 March 2026 requires human oversight and risk review on significant changes for high-risk systems. But health AI already in use has until 1 September 2027, and a summary of the high-risk list shows only robotic surgery for health.",
     "sources": [
      {
       "title": "Luật Trí tuệ nhân tạo 2025, số 134/2025/QH15 (LuatVietnam)",
       "url": "https://luatvietnam.vn/khoa-hoc/luat-tri-tue-nhan-tao-2025-so-134-2025-qh15-422299-d1.html",
       "date": "2025-12-10",
       "publisherClass": "legal_text"
      },
      {
       "title": "Các điểm mới quan trọng của nghị định hướng dẫn Luật Trí tuệ nhân tạo (Atsumi & Sakai)",
       "url": "https://www.aplawjapan.com/en/newsletter/20260528-2",
       "date": "2026-05-28",
       "publisherClass": "law_firm"
      },
      {
       "title": "Danh mục hệ thống trí tuệ nhân tạo có rủi ro cao từ 15/8/2026 (LuatVietnam)",
       "url": "https://luatvietnam.vn/tin-van-ban-moi/danh-muc-he-thong-tri-tue-nhan-tao-co-rui-ro-cao-tu-15-8-2026-186-110045-article.html",
       "date": "2026-07-02",
       "publisherClass": "law_firm"
      },
      {
       "title": "Bộ Y tế chuẩn bị ban hành quy định về AI trong y tế (Người Lao Động)",
       "url": "https://tuoitre.vn/nld/bo-y-te-chuan-bi-ban-hanh-quy-dinh-ve-ai-trong-y-te-196251211145240185.htm",
       "date": "2025-12-11",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Law on Medical Examination and Treatment (15/2023/QH15)",
     "level": "National",
     "year": "2023",
     "what": "Right to read and copy archived records; right to refuse research; confidentiality of records.",
     "url": "https://xaydungchinhsach.chinhphu.vn/toan-van-luat-15-2023-qh15-kham-benh-chua-benh-119231127164453959.htm"
    },
    {
     "name": "Law on Personal Data Protection (91/2025/QH15)",
     "level": "National",
     "year": "2025",
     "what": "Health data needs consent; data trading banned; 72-hour breach notice; in force 1 January 2026.",
     "url": "https://luatvietnam.vn/dan-su/luat-bao-ve-du-lieu-ca-nhan-2025-so-91-2025-qh15-405135-d1.html"
    },
    {
     "name": "Decree 356/2025/ND-CP",
     "level": "National",
     "year": "2025",
     "what": "Lists health as sensitive data; sets 10-day deadline to provide personal data.",
     "url": "https://luatvietnam.vn/dan-su/nghi-dinh-356-2025-nd-cp-quy-dinh-chi-tiet-luat-bao-ve-du-lieu-ca-nhan-422896-d1.html"
    },
    {
     "name": "Decree 102/2025/ND-CP on health data management",
     "level": "National",
     "year": "2025",
     "what": "Creates National Health Database; facilities must link data to VNeID; state may override consent.",
     "url": "https://english.luatvietnam.vn/y-te/decree-102-2025-nd-cp-health-data-management-400071-d1.html"
    },
    {
     "name": "Decree 330/2026/ND-CP",
     "level": "National",
     "year": "2026",
     "what": "Administrative penalties for cybersecurity and personal data protection violations.",
     "url": "https://vanban.chinhphu.vn/?pageid=27160&docid=219266&classid=1&typegroupid=4"
    },
    {
     "name": "Law on Artificial Intelligence (134/2025/QH15)",
     "level": "National",
     "year": "2025",
     "what": "Risk-based AI rules with human oversight; health AI already operating has until 1 September 2027.",
     "url": "https://luatvietnam.vn/khoa-hoc/luat-tri-tue-nhan-tao-2025-so-134-2025-qh15-422299-d1.html"
    },
    {
     "name": "Circular 50/2025/TT-BYT on clinical drug trials",
     "level": "National",
     "year": "2025",
     "what": "Written voluntary consent and ethics council approval for drug trials; in force 27 February 2026.",
     "url": "https://luatvietnam.vn/y-te/thong-tu-50-2025-tt-byt-quy-dinh-thu-thuoc-tren-lam-sang-hieu-luc-tu-27-02-2026-422988-d1.html"
    }
   ],
   "dti": {
    "grade": 83,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-10-05",
     "headline": "Hospital systems hit by attackers; patient data offered for sale on hacker forums",
     "paraphrase": "The report lists several attacks on major hospitals, including encrypted servers, ransom demands and patient and staff records advertised for sale on cybercrime forums. It reports no statement from the hospitals and no penalty.",
     "source": "VietNamNet",
     "url": "https://vietnamnet.vn/en/major-hospitals-hit-by-cyberattacks-patient-data-sold-on-hacker-forums-2449058.html",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-05-23",
     "headline": "Police cybersecurity unit warns of two attacks on hospital data in one month",
     "paraphrase": "A police cybersecurity official said attackers hit hospital or health ministry data twice in one month, threatening to expose details of thousands of doctors and patients, including diagnostic imaging, and warned that health sector security is weak.",
     "source": "Tuoi Tre",
     "url": "https://tuoitre.vn/canh-bao-tinh-trang-tin-tac-tan-cong-du-lieu-so-cua-benh-vien-lo-thong-tin-bac-si-va-nguoi-benh-2026052321424194.htm",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2025-08-20",
     "headline": "Patients get sales calls after hospital visits as their data is sold online",
     "paraphrase": "Patients described being phoned with sales offers soon after hospital discharge. A security expert found patient names, phone numbers and medical history sold cheaply on a messaging app. Some hospitals stayed silent about attacks, the report says.",
     "source": "VietTimes",
     "url": "https://viettimes.vn/lo-hong-so-hoa-benh-vien-khi-du-lieu-benh-nhan-bi-bien-thanh-mon-hang-post188681.html",
     "theme": "sold_or_shared",
     "status": "alleged"
    },
    {
     "date": "2025-06-10",
     "headline": "Patients say doctors posted their consultations and procedures online without clear consent",
     "paraphrase": "Two adult patients said clinics posted images or livestreamed their consultations for promotion without clear consent; one learned colleagues had seen the video. A city health department head condemned the practice, citing confidentiality rules.",
     "source": "Sai Gon Giai Phong",
     "url": "https://www.sggp.org.vn/dang-tai-hinh-anh-nguoi-benh-len-mang-xa-hoi-vi-pham-quyen-ca-nhan-va-bi-mat-doi-tu-post798808.html",
     "theme": "sold_or_shared",
     "status": "alleged"
    },
    {
     "date": "2026-10-01",
     "headline": "Provincial health department finds recurring errors and gaps in hospital medical records",
     "paraphrase": "A provincial health department official reported common record faults found across facilities: diagnoses not updated, test results not assessed, sections that contradict each other and orders with no clear link to the patient's condition. No facility was named.",
     "source": "Bao Dong Nai",
     "url": "https://baodongnai.com.vn/xa-hoi/202610/chan-chinh-chi-dinh-can-lam-sang-ke-don-thuoc-va-chat-luong-ho-so-benh-an-7fb1fc2/",
     "theme": "record_wrong",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "IND",
   "name": "India",
   "region": "Asia",
   "overall": 45,
   "rank": "53=",
   "likelyRank": "48 to 57",
   "band": "Mixed",
   "keysModel": "Shared",
   "confidence": "medium",
   "headline": "India built an opt-in consent exchange linking 110 crore records, but the records are thin and its privacy law and regulator are not yet working.",
   "categories": {
    "access": {
     "score": 55,
     "summary": "A binding medical ethics regulation makes doctors issue records within 72 hours, and 96.43 crore ABHA accounts can view 110 crore linked records (August 2026). Linked records average about one per account, and the DPDP access right only gives a summary and starts in May 2027.",
     "sources": [
      {
       "title": "Code of Medical Ethics Regulations, 2002 (NMC)",
       "url": "https://nmc.org.in/page/rules-regulations-rules-regulations-of-erstwhile-mci-code-of-medical-ethics-regulations-2002",
       "date": "2002",
       "publisherClass": "legal_text"
      },
      {
       "title": "The Digital Personal Data Protection Act, 2023 (Gazette text, MeitY)",
       "url": "https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf",
       "date": "2023-08-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "G.S.R. 843(E): commencement dates of the DPDP Act (MeitY)",
       "url": "https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf",
       "date": "2025-11-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Affordable and Accessible Healthcare for All (PIB fact sheet)",
       "url": "https://www.pib.gov.in/FactsheetDetails.aspx?id=150834&ModuleId=16&reg=%203&lang=1",
       "date": "2026-08-12",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 50,
     "summary": "ABDM shares records between providers only on the patient's revocable, time-bound consent, an opt-in choice that is live nationwide. Policy lets patients see their consents, but a log of each access was not verified, so the cell sits mid-band (40 to 55), level with Thailand.",
     "sources": [
      {
       "title": "Ayushman Bharat Digital Mission: India's Digital Health Backbone (PIB)",
       "url": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2026/jul/doc202676912801.pdf",
       "date": "2026-07-06",
       "publisherClass": "official"
      },
      {
       "title": "National Digital Health Mission: Health Data Management Policy (archived copy of abdm.gov.in PDF)",
       "url": "https://web.archive.org/web/2025id_/https://abdm.gov.in/strapicms/uploads/health_management_policy_bac9429a79.pdf",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "ABHA ID now mandatory for OPD, emergency registration (Times of India)",
       "url": "https://timesofindia.indiatimes.com/city/jaipur/abha-id-now-mandatory-for-opd-emergency-registration/articleshow/127727998.cms",
       "date": "2026-01-29",
       "publisherClass": "news"
      },
      {
       "title": "G.S.R. 843(E): commencement dates of the DPDP Act (MeitY)",
       "url": "https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf",
       "date": "2025-11-13",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 35,
     "summary": "India's new data law does not make health data a special category, and its duties and penalties of up to Rs 250 crore start only in May 2027. The Data Protection Board had no chair or members in September 2026, while hospital leaks continued.",
     "sources": [
      {
       "title": "IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011",
       "url": "https://prsindia.org/files/bills_acts/bills_parliament/2011/IT_Rules_2011.pdf",
       "date": "2011-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "The Digital Personal Data Protection Act, 2023 (Gazette text, MeitY)",
       "url": "https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf",
       "date": "2023-08-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "Hackers target Ernakulam hospital, steal 800GB data (New Indian Express)",
       "url": "https://www.newindianexpress.com/states/kerala/2026/Jun/10/hackers-target-ernakulam-hospital-steal-800gb-data",
       "date": "2026-06-10",
       "publisherClass": "news"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 45,
     "summary": "ABDM gives India national registries, a consent exchange and a claims exchange, with 5.47 lakh facilities registered and 110 crore records linked by August 2026. Hospitals lead, while labs and pharmacies trail far behind, and records are linked rather than merged.",
     "sources": [
      {
       "title": "100 crore health records linked with ABHA under ABDM (PIB)",
       "url": "https://www.pib.gov.in/PressReleasePage.aspx?PRID=2264241&reg=3&lang=1",
       "date": "2026-05-22",
       "publisherClass": "official"
      },
      {
       "title": "Ayushman Bharat Digital Mission: India's Digital Health Backbone (PIB)",
       "url": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2026/jul/doc202676912801.pdf",
       "date": "2026-07-06",
       "publisherClass": "official"
      },
      {
       "title": "Affordable and Accessible Healthcare for All (PIB fact sheet)",
       "url": "https://www.pib.gov.in/FactsheetDetails.aspx?id=150834&ModuleId=16&reg=%203&lang=1",
       "date": "2026-08-12",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 35,
     "summary": "No Indian law bans selling health data or using it for advertising. Private bodies need prior permission to disclose medical records under 2011 rules, and the DPDP ban on targeted ads at children starts only in May 2027.",
     "sources": [
      {
       "title": "IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011",
       "url": "https://prsindia.org/files/bills_acts/bills_parliament/2011/IT_Rules_2011.pdf",
       "date": "2011-04-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "The Digital Personal Data Protection Act, 2023 (Gazette text, MeitY)",
       "url": "https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf",
       "date": "2023-08-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "National Digital Health Mission: Health Data Management Policy (archived copy of abdm.gov.in PDF)",
       "url": "https://web.archive.org/web/2025id_/https://abdm.gov.in/strapicms/uploads/health_management_policy_bac9429a79.pdf",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "STAR Hospitals alleges patient data was leaked, FIR registered (The South First)",
       "url": "https://thesouthfirst.com/health/hyderabads-star-hospitals-alleges-confidential-patient-data-was-leaked-published-online-fir-registered/",
       "date": "2026-08-03",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 35,
     "summary": "A treating doctor can pull earlier ABHA-linked records only after the patient consents to each request. With about one linked record per account and no verified break-glass access, most clinicians still rely on what the patient brings.",
     "sources": [
      {
       "title": "Ayushman Bharat Digital Mission: India's Digital Health Backbone (PIB)",
       "url": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2026/jul/doc202676912801.pdf",
       "date": "2026-07-06",
       "publisherClass": "official"
      },
      {
       "title": "National Digital Health Mission: Health Data Management Policy (archived copy of abdm.gov.in PDF)",
       "url": "https://web.archive.org/web/2025id_/https://abdm.gov.in/strapicms/uploads/health_management_policy_bac9429a79.pdf",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Affordable and Accessible Healthcare for All (PIB fact sheet)",
       "url": "https://www.pib.gov.in/FactsheetDetails.aspx?id=150834&ModuleId=16&reg=%203&lang=1",
       "date": "2026-08-12",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 46,
     "summary": "Research on anonymised or registry data can proceed without individual consent and there is no general opt-out, but an ethics committee must approve any consent waiver. Clinical trials need written informed consent, with video recording for vulnerable participants.",
     "sources": [
      {
       "title": "The Digital Personal Data Protection Act, 2023 (Gazette text, MeitY)",
       "url": "https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf",
       "date": "2023-08-11",
       "publisherClass": "legal_text"
      },
      {
       "title": "ICMR National Ethical Guidelines for Biomedical and Health Research Involving Human Participants, 2017",
       "url": "https://ethics.ncdirindia.org/asset/pdf/ICMR_National_Ethical_Guidelines.pdf",
       "date": "2017",
       "publisherClass": "official"
      },
      {
       "title": "New Drugs and Clinical Trials Rules, 2019 (CDSCO)",
       "url": "https://cdsco.gov.in/opencms/resources/UploadCDSCOWeb/2022/new_DC_rules/NEW%20DRUGS%20ANDctrS%20RULE,%202019.pdf",
       "date": "2019-03-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ayushman Bharat Digital Mission: India's Digital Health Backbone (PIB)",
       "url": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2026/jul/doc202676912801.pdf",
       "date": "2026-07-06",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 55,
     "summary": "AI medical software is a device under the binding Medical Devices Rules, 2017, and CDSCO's final July 2026 guidance adds change approval and drift monitoring. A binding human oversight rule was not verified, so the cell sits at the band floor.",
     "sources": [
      {
       "title": "Guidance Document on Medical Device Software, CDSCO/MD/GD/MDSW/01/2026",
       "url": "https://cdsco.gov.in/opencms/export/sites/CDSCO_WEB/Pdf-documents/Guidance-document-on-Medical-Device-Software-under-MDR-2017.pdf",
       "date": "2026-07",
       "publisherClass": "official"
      },
      {
       "title": "CDSCO releases final guidance document on Medical Device Software (Pharmabiz)",
       "url": "https://www.pharmabiz.com/NewsDetails.aspx?aid=187330&sid=1",
       "date": "2026-07-23",
       "publisherClass": "news"
      },
      {
       "title": "Ayushman Bharat Digital Mission: India's Digital Health Backbone (PIB)",
       "url": "https://static.pib.gov.in/WriteReadData/specificdocs/documents/2026/jul/doc202676912801.pdf",
       "date": "2026-07-06",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Digital Personal Data Protection Act, 2023",
     "level": "National",
     "year": "2023",
     "what": "General data law: consent, summary access, breach notice, Rs 250 crore penalties; main duties start May 2027.",
     "url": "https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf"
    },
    {
     "name": "Digital Personal Data Protection Rules, 2025",
     "level": "National",
     "year": "2025",
     "what": "Notified 13 Nov 2025; consent managers from Nov 2026, most duties from May 2027; research exemption standards.",
     "url": "https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf"
    },
    {
     "name": "IT (Reasonable Security Practices and Sensitive Personal Data) Rules, 2011",
     "level": "National",
     "year": "2011",
     "what": "Medical records are sensitive data; prior permission for disclosure; binds companies until May 2027.",
     "url": "https://prsindia.org/files/bills_acts/bills_parliament/2011/IT_Rules_2011.pdf"
    },
    {
     "name": "Code of Medical Ethics Regulations, 2002",
     "level": "National",
     "year": "2002",
     "what": "Doctors must issue medical records within 72 hours of a patient request.",
     "url": "https://nmc.org.in/page/rules-regulations-rules-regulations-of-erstwhile-mci-code-of-medical-ethics-regulations-2002"
    },
    {
     "name": "New Drugs and Clinical Trials Rules, 2019",
     "level": "National",
     "year": "2019",
     "what": "Written informed consent for all trials; audio-video consent recording for vulnerable subjects.",
     "url": "https://cdsco.gov.in/opencms/resources/UploadCDSCOWeb/2022/new_DC_rules/NEW%20DRUGS%20ANDctrS%20RULE,%202019.pdf"
    },
    {
     "name": "Medical Devices Rules, 2017 (CDSCO software guidance, 2026)",
     "level": "National",
     "year": "2017",
     "what": "Software and AI/ML medical devices licensed by risk class; change approval and drift monitoring.",
     "url": "https://cdsco.gov.in/opencms/export/sites/CDSCO_WEB/Pdf-documents/Guidance-document-on-Medical-Device-Software-under-MDR-2017.pdf"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2024-10-11",
     "headline": "Health insurer confirms illegal access to customer records offered through chatbots",
     "paraphrase": "Records of more than 30 million customers, including ID images and claim documents, were offered through chatbots and later a website. The insurer acknowledged unauthorized and illegal access to certain data and obtained a court injunction.",
     "source": "The Register",
     "url": "https://www.theregister.com/2024/10/11/star_health_breach/",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2025-12-20",
     "headline": "Consumer commission orders hospital to hand over a senior citizen's discharge papers",
     "paraphrase": "A private hospital did not give a retired patient the discharge summary, case papers and receipts, so the insurance claim could not be filed. A district consumer commission ordered compensation and the papers supplied within one month.",
     "source": "Medical Dialogues",
     "url": "https://medicaldialogues.in/news/health/medico-legal/consumer-court-slaps-rs-60k-compensation-on-hospital-for-withholding-discharge-summary-from-covid-patient-161066",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2026-08-03",
     "headline": "Hospital group tells police patient records were posted online without authorization",
     "paraphrase": "A hospital group's chief executive told police that patients' personal details and medical records, with staff data and internal documents, were posted on an outside website. The state cyber bureau registered a case and is investigating.",
     "source": "NewsMeter",
     "url": "https://newsmeter.in/hyderabad/healthcare-data-breach-tgcsb-registers-case-after-star-hospitals-patients-records-leaked-online-772895",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2025-04-07",
     "headline": "Researchers say a hospital chain left patient records and ID documents exposed online",
     "paraphrase": "Security researchers reported finding a file on a subsidiary website holding patient records, vaccination reports and identity documents. They told national cyber agencies; more than 60 days later the report saw no meaningful response and the chain had not replied.",
     "source": "Decode (BOOM)",
     "url": "https://www.decodeinternet.in/decode/hackers-may-have-stolen-patient-data-from-indias-largest-hospital-chain-28228",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-04-10",
     "headline": "Consumer commission orders hospitals to release a patient's complete records within 45 days",
     "paraphrase": "Two linked hospitals did not give a patient's family the complete medical records despite repeated requests. A district consumer commission ordered the full records, including consent forms and procedure details, within 45 days, with interest if late.",
     "source": "DT Next",
     "url": "https://www.dtnext.in/amp/story/news/chennai/consumer-panel-holds-hospital-group-liable-for-negligence-awards-rs-7-lakh-compensation",
     "theme": "access_refused",
     "status": "finding"
    }
   ]
  },
  {
   "iso3": "RUS",
   "name": "Russia",
   "region": "Europe",
   "overall": 45,
   "rank": "53=",
   "likelyRank": "49 to 58",
   "band": "Mixed",
   "keysModel": "State",
   "confidence": "medium",
   "headline": "Russians can see 32 types of medical documents on the state portal, but the state system decides how records flow and police access is broad.",
   "categories": {
    "access": {
     "score": 60,
     "summary": "Federal Law 323-FZ gives patients the right to see their records and get copies, including electronically. The Gosuslugi portal shows 32 types of electronic documents, but how many people use it and how complete it is were not verified.",
     "sources": [
      {
       "title": "Article 22. Information about state of health, Federal Law 323-FZ (ConsultantPlus)",
       "url": "https://www.consultant.ru/document/cons_doc_LAW_121895/d2872d82b3b26ca307971f590ce02dd37f71cafc/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "32 types of electronic medical documents now shown on Gosuslugi (Kholmsk Central District Hospital)",
       "url": "https://kholmskcrb.gosuslugi.ru/novosti/vyvedeny-32-vida-elektronnyh-meditsinskih-dokumentov.html",
       "date": "2025-12-25",
       "publisherClass": "official"
      },
      {
       "title": "New procedure and deadlines for providing medical documents approved (ConsultantPlus)",
       "url": "https://www.consultant.ru/law/hotdocs/64775.html",
       "date": "2020-09-25",
       "publisherClass": "legal_text"
      },
      {
       "title": "Health Ministry prepares new procedure for keeping medical documentation (Medvestnik)",
       "url": "https://medvestnik.ru/content/news/minzdrav-rf-podgotovil-proekt-novogo-poryadka-vedeniya-medicinskoi-dokumentacii.html",
       "date": "2026-02-19",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 30,
     "summary": "Law 323-FZ lets clinics exchange records through state information systems for care without the patient's consent. The health regulator has said a patient's written refusal to send health data to the state system should be honoured, but no patient-visible access log was found.",
     "sources": [
      {
       "title": "Article 13. Medical secrecy, Federal Law 323-FZ (SudAct)",
       "url": "https://sudact.ru/law/federalnyi-zakon-ot-21112011-n-323-fz-ob/glava-2/statia-13/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Is it legal to take a patient's refusal to send data to EGISZ? Roszdravnadzor's answer (Medrate)",
       "url": "https://medrate.ru/posts/zakonno-li-brat-s-pacienta-otkaz-ot-peredachi-dannyh-v-egisz-otvet-roszdravnadzora.html",
       "date": "2025-06-03",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "How to limit transfer of paid doctor visit data to EGISZ (Klerk)",
       "url": "https://www.klerk.ru/buh/news/696717/",
       "date": "2026-06-23",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 34,
     "summary": "Health data is a special category, and since May 2025 leaking it can cost a firm 10 to 15 million rubles. The regulator is a government service, investigators can demand records without consent, and over a million medical records leaked in several 2026 months.",
     "sources": [
      {
       "title": "Article 10. Special categories of personal data, Federal Law 152-FZ (Klerk legal database)",
       "url": "https://www.klerk.ru/cdoc/view/3b8e926083fc0bd01959f782189eeea9/stata-10-specialnye-kategorii-personalnyh-dannyh/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Personal data: new fines from 30 May 2025 (ConsultantPlus)",
       "url": "https://www.consultant.ru/legalnews/28492/",
       "date": "2025-05-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Article 13. Medical secrecy, Federal Law 323-FZ (SudAct)",
       "url": "https://sudact.ru/law/federalnyi-zakon-ot-21112011-n-323-fz-ob/glava-2/statia-13/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Fraudsters keep publishing leaked medical data (CNews)",
       "url": "https://safe.cnews.ru/news/line/2026-07-03_perspektivnyj_monitoring",
       "date": "2026-07-03",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 55,
     "summary": "A single state system, EGISZ, has 18 subsystems including a federal electronic medical card and a register of electronic documents, and it exchanges data with compulsory insurance. Private clinics barely take part and e-prescriptions still stop at regional borders.",
     "sources": [
      {
       "title": "Government Decree No. 140 of 9 February 2022 on EGISZ (Rossiyskaya Gazeta)",
       "url": "https://rg.ru/documents/2022/02/15/pravitelstvo-post140-site-dok.html",
       "date": "2022-02-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Health Ministry prepares new procedure for keeping medical documentation (Medvestnik)",
       "url": "https://medvestnik.ru/content/news/minzdrav-rf-podgotovil-proekt-novogo-poryadka-vedeniya-medicinskoi-dokumentacii.html",
       "date": "2026-02-19",
       "publisherClass": "news"
      },
      {
       "title": "Health Ministry proposes experiment on central accounting of e-prescriptions (Vademecum)",
       "url": "https://www.vademec.ru/news/2026/07/27/minzdrav-predlozhil-eksperiment-po-tsentralizovannomu-uchetu-elektronnykh-retseptov/",
       "date": "2026-07-27",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 40,
     "summary": "Commercial use of health data needs consent under the Personal Data Law, and the 2025 de-identified data rule excludes information restricted by law. Leaked clinic databases are sold, and drug makers sought access to state records in September 2026.",
     "sources": [
      {
       "title": "Article 10. Special categories of personal data, Federal Law 152-FZ (Klerk legal database)",
       "url": "https://www.klerk.ru/cdoc/view/3b8e926083fc0bd01959f782189eeea9/stata-10-specialnye-kategorii-personalnyh-dannyh/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Law 233-FZ and new de-identification rules from 1 September 2025 (Anti-Malware)",
       "url": "https://www.anti-malware.ru/analytics/Technology_Analysis/Depersonalization-of-personal-data-in-Russia-2025",
       "date": "2025-06-02",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "Pharma business proposes using Russians' de-identified medical data for new drugs (GxP News)",
       "url": "https://gxpnews.net/2026/09/farmbiznes-predlozhil-ispolzovat-obezlichennye-meddannye-rossiyan-radi-novyh-lekarstv/",
       "date": "2026-09-09",
       "publisherClass": "news"
      },
      {
       "title": "Fraudsters keep publishing leaked medical data (CNews)",
       "url": "https://safe.cnews.ru/news/line/2026-07-03_perspektivnyj_monitoring",
       "date": "2026-07-03",
       "publisherClass": "news"
      }
     ]
    },
    "clinical": {
     "score": 45,
     "summary": "The law lets clinics share records through information systems for care without consent, and a federal electronic medical card exists. Whether a treating doctor in practice sees records from other providers, especially private ones, was not verified.",
     "sources": [
      {
       "title": "Article 13. Medical secrecy, Federal Law 323-FZ (SudAct)",
       "url": "https://sudact.ru/law/federalnyi-zakon-ot-21112011-n-323-fz-ob/glava-2/statia-13/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Government Decree No. 140 of 9 February 2022 on EGISZ (Rossiyskaya Gazeta)",
       "url": "https://rg.ru/documents/2022/02/15/pravitelstvo-post140-site-dok.html",
       "date": "2022-02-15",
       "publisherClass": "legal_text"
      }
     ]
    },
    "research": {
     "score": 42,
     "summary": "Drug trial participants must sign written consent and can leave at any stage under Law 61-FZ. De-identified datasets from the federal electronic medical card have been offered to accredited AI developers since 2022 with no individual consent or opt-out found.",
     "sources": [
      {
       "title": "Article 43. Rights of patients in clinical trials, Federal Law 61-FZ (ConsultantPlus)",
       "url": "https://www.consultant.ru/document/cons_doc_LAW_99350/9570de6d7195a78722b0b5efdcf4fa9a90c54557/",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Health Ministry opens AI developers' access to datasets from electronic medical records (Medvestnik)",
       "url": "https://medvestnik.ru/content/news/Minzdrav-otkryl-razrabotchikam-iskusstvennogo-intellekta-dostup-k-datasetam-iz-elektronnyh-medkart.html",
       "date": "2022-11-25",
       "publisherClass": "news"
      }
     ]
    },
    "ai": {
     "score": 55,
     "summary": "AI software in care is registered as a medical device in the highest risk class, and registered AI products must automatically report usage data to the regulator. Roszdravnadzor counted 59 domestic AI devices in August 2026; formal change control was not verified.",
     "sources": [
      {
       "title": "AI law 243-FZ signed (ConsultantPlus)",
       "url": "https://www.consultant.ru/law/hotdocs/95007.html",
       "date": "2026-07-27",
       "publisherClass": "legal_text"
      },
      {
       "title": "Developer of AI medical devices asks not to class them automatically as risk class 3 (ComNews)",
       "url": "https://www.comnews.ru/content/247569/2026-09-28/2026-w40/1007/razrabotchik-medizdeliy-iskusstvennym-intellektom-poprosil-ne-prichislyat-ikh-avtomaticheski-k-tretemu-klassu-riska",
       "date": "2026-09-28",
       "publisherClass": "news"
      },
      {
       "title": "Procedure approved for automatic transfer of AI medical device data to Roszdravnadzor (Meditex)",
       "url": "https://meditex.ru/news_all/UtverzhdenporyadokavtomaticheskoyperedachidannykhomedizdeliyakhsIIvinformatsionnuyusistemuRoszdravna/",
       "date": "2025-10-23",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "Russia has registered 59 AI medical devices (Vedomosti)",
       "url": "https://www.vedomosti.ru/technology/news/2026/08/18/1221917-rossii-zaregistrirovali",
       "date": "2026-08-18",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Federal Law 323-FZ on the Basics of Protecting Citizens' Health",
     "level": "National",
     "year": "2011",
     "what": "Right to read records and get copies; medical secrecy with 11 listed exceptions, including police requests.",
     "url": "https://www.consultant.ru/document/cons_doc_LAW_121895/d2872d82b3b26ca307971f590ce02dd37f71cafc/"
    },
    {
     "name": "Federal Law 152-FZ on Personal Data",
     "level": "National",
     "year": "2006",
     "what": "Health data is a special category; processing banned except listed cases such as medical care.",
     "url": "https://www.klerk.ru/cdoc/view/3b8e926083fc0bd01959f782189eeea9/stata-10-specialnye-kategorii-personalnyh-dannyh/"
    },
    {
     "name": "Government Decree 140 on the Unified State Health Information System (EGISZ)",
     "level": "National",
     "year": "2022",
     "what": "Sets up EGISZ with 18 subsystems, including the federal electronic medical card and document register.",
     "url": "https://rg.ru/documents/2022/02/15/pravitelstvo-post140-site-dok.html"
    },
    {
     "name": "Federal Law 61-FZ on Circulation of Medicines (Article 43)",
     "level": "National",
     "year": "2010",
     "what": "Voluntary, signed consent for drug trials and the right to withdraw at any stage.",
     "url": "https://www.consultant.ru/document/cons_doc_LAW_99350/9570de6d7195a78722b0b5efdcf4fa9a90c54557/"
    },
    {
     "name": "Administrative Code amendments on personal data fines (Law 420-FZ)",
     "level": "National",
     "year": "2024",
     "what": "From 30 May 2025, fines up to 15 million rubles for health data leaks, turnover fines for repeats.",
     "url": "https://www.consultant.ru/legalnews/28492/"
    },
    {
     "name": "Federal Law 243-FZ on Support for AI Technologies",
     "level": "National",
     "year": "2026",
     "what": "Defines sovereign and national AI models, state powers over AI and labelling of AI content, mostly from 1 September 2026.",
     "url": "https://www.consultant.ru/law/hotdocs/95007.html"
    }
   ],
   "dti": {
    "grade": 83,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-07-17",
     "headline": "Hospital worker opened a patient's electronic record without cause, health ministry confirmed",
     "paraphrase": "A patient in the Bashkortostan region learned her former employer knew details from her medical file. The regional health ministry confirmed a worker at another hospital had accessed it unlawfully and dismissed him, but refused her the inspection file.",
     "source": "Пруфы",
     "url": "https://prufy.ru/news/society/188845-skandal_s_utechkoy_dannykh_v_pravitelstvennoy_bolnitse_ufy_doshel_do_sledstviya/",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-04-22",
     "headline": "Inspection finds ambulance service head passed patients' data to outside parties",
     "paraphrase": "An unplanned inspection by the Vologda regional health ministry found that the head of an ambulance service had passed data on patients it carried to third parties. He was dismissed and the material was sent to oversight bodies.",
     "source": "Медвестник",
     "url": "https://medvestnik.ru/content/news/glavvracha-skoroi-pomoshi-vologdy-uvolili-za-utechku-dannyh-pacientov.html",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-08-21",
     "headline": "Court rules a patient cannot claim damages for false entries in his record",
     "paraphrase": "A man in the Astrakhan region found his record held a relative's history, entered when the relative was treated under his documents. Another hospital refused him care. The cassation court overturned his damages award, finding the error his own.",
     "source": "РАПСИ",
     "url": "https://rapsinews.ru/judicial_news/20250821/311095872.html",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-05-14",
     "headline": "Court upholds damages after a clinic lost a patient's record during a merger",
     "paraphrase": "In a review of court practice, a clinic could not produce a patient's record for expert review because it was not transferred when two clinics merged. Courts held the successor clinic responsible for keeping it and ordered compensation.",
     "source": "КонсультантПлюс",
     "url": "https://www.consultant.ru/legalnews/28446/",
     "theme": "lost_between_providers",
     "status": "finding"
    },
    {
     "date": "2025-07-30",
     "headline": "Clinic network confirms hacker attack disrupted services; says no leak confirmed",
     "paraphrase": "Hackers broke into a private clinic network owned by an insurer, the company confirmed, alongside attacks on two pharmacy chains. Services were disrupted; the clinic said patient data leakage had not been confirmed.",
     "source": "Коммерсантъ",
     "url": "https://www.kommersant.ru/doc/7925020",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "RWA",
   "name": "Rwanda",
   "region": "Africa",
   "overall": 44,
   "rank": "55",
   "likelyRank": "50 to 58",
   "band": "Weak",
   "keysModel": "State",
   "confidence": "medium",
   "headline": "Rwanda's 2025 health law gives patients their file within five working days, but the state record is still rolling out with no sharing controls.",
   "categories": {
    "access": {
     "score": 50,
     "summary": "Law 026/2025 gives patients the right to consult their file and get a copy within five working days of a written request. A national patient app is planned, and whether patients can see their own records online today is not verified.",
     "sources": [
      {
       "title": "Law n° 026/2025 of 17/09/2025 regulating healthcare services (Official Gazette n° Special of 18/09/2025, Ministry of Justice)",
       "url": "https://www.minijust.gov.rw/index.php?eID=dumpFile&f=144155&t=f&token=75e63fc504481c93e1ed017130c13b4c35f3935e",
       "date": "2025-09-18",
       "publisherClass": "legal_text"
      },
      {
       "title": "Law n° 058/2021 relating to the protection of personal data and privacy (RwandaLII)",
       "url": "https://rwandalii.org/akn/rw/act/law/2021/58/eng@2021-10-15",
       "date": "2021-10-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Health Sector Strategic Plan V, July 2024 to June 2029 (Ministry of Health)",
       "url": "https://www.moh.gov.rw/index.php?eID=dumpFile&t=f&f=117507&token=f2a527e089201f73bec29f8ce6d6c4dc55ed241e",
       "date": "2024",
       "publisherClass": "official"
      },
      {
       "title": "Five Years On, Rwanda Is Leading the Edge of Digital Health in Africa (KT Press)",
       "url": "https://www.ktpress.rw/2026/09/five-years-on-rwanda-is-leading-the-edge-of-digital-health-in-africa/",
       "date": "2026-09-30",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 30,
     "summary": "The law requires consent or another legal ground, but health processing for care and public health needs no separate consent, and records are linked to the national ID. We found no opt-out and no access log patients can see.",
     "sources": [
      {
       "title": "Law n° 058/2021 relating to the protection of personal data and privacy (RwandaLII)",
       "url": "https://rwandalii.org/akn/rw/act/law/2021/58/eng@2021-10-15",
       "date": "2021-10-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Law n° 026/2025 of 17/09/2025 regulating healthcare services (Official Gazette n° Special of 18/09/2025, Ministry of Justice)",
       "url": "https://www.minijust.gov.rw/index.php?eID=dumpFile&f=144155&t=f&token=75e63fc504481c93e1ed017130c13b4c35f3935e",
       "date": "2025-09-18",
       "publisherClass": "legal_text"
      },
      {
       "title": "Rwanda Health Information Exchange (RHIE): achievements over the last three years, full report (CIIC-HIN, implementing partner)",
       "url": "https://ciichin.org/wp-content/uploads/2025/01/Rwanda-Health-Information-System-Ecosystem-RHIE-Achievement-over-last-Three-years-Full-Report.pdf",
       "date": "2025-01",
       "publisherClass": "blog_vendor"
      }
     ]
    },
    "privacy": {
     "score": 52,
     "summary": "Health status and medical records are sensitive data, breaches go to the regulator within 48 hours, and the 2025 health law requires encryption of patient data. The regulator sits inside the national cyber security authority, and we found no published health-sector fine.",
     "sources": [
      {
       "title": "Law n° 058/2021 relating to the protection of personal data and privacy (RwandaLII)",
       "url": "https://rwandalii.org/akn/rw/act/law/2021/58/eng@2021-10-15",
       "date": "2021-10-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Law n° 026/2025 of 17/09/2025 regulating healthcare services (Official Gazette n° Special of 18/09/2025, Ministry of Justice)",
       "url": "https://www.minijust.gov.rw/index.php?eID=dumpFile&f=144155&t=f&token=75e63fc504481c93e1ed017130c13b4c35f3935e",
       "date": "2025-09-18",
       "publisherClass": "legal_text"
      },
      {
       "title": "What to do after you register with NCSA (Data Protection and Privacy Office)",
       "url": "https://dpo.gov.rw/news-and-updates/news/article/what-to-do-after-you-register-with-ncsa",
       "date": "2026-01-26",
       "publisherClass": "official"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 46,
     "summary": "Insurance claims and public health data are digital and national, but the Ministry's own plan put facilities with a fully working electronic record at 12% at baseline. The goal of a paper-free public system by end-2025 is not verified as met.",
     "sources": [
      {
       "title": "Health Sector Strategic Plan V, July 2024 to June 2029 (Ministry of Health)",
       "url": "https://www.moh.gov.rw/index.php?eID=dumpFile&t=f&f=117507&token=f2a527e089201f73bec29f8ce6d6c4dc55ed241e",
       "date": "2024",
       "publisherClass": "official"
      },
      {
       "title": "Ikoranabuhanga rya E-Ubuzima riratangira gukoreshwa hose bitarenze 2025 (Voice of Africa)",
       "url": "https://voiceofafrica.rw/2025/05/08/ikoranabuhanga-rya-e-ubuzima-riratangira-gukoreshwa-hose-bitarenze-2025/",
       "date": "2025-05-08",
       "publisherClass": "news"
      },
      {
       "title": "CBHI / Mutuelle de Santé scheme page (Rwanda Social Security Board)",
       "url": "https://rssb.rw/schemes/cbhi-scheme",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "New Health Intelligence Center to drive real-time, evidence-based decisions (Ministry of Health)",
       "url": "https://www.moh.gov.rw/news-detail/new-health-intelligence-center-to-drive-real-time-evidence-based-decisions",
       "date": "2025-04-03",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 50,
     "summary": "Selling personal data against the law carries five to seven years in prison, re-identifying de-identified data is a crime, and the 2025 health law bans advertising of health services. We found no rules for health apps, data brokers or de-identified data sales.",
     "sources": [
      {
       "title": "Law n° 058/2021 relating to the protection of personal data and privacy (RwandaLII)",
       "url": "https://rwandalii.org/akn/rw/act/law/2021/58/eng@2021-10-15",
       "date": "2021-10-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Law n° 026/2025 of 17/09/2025 regulating healthcare services (Official Gazette n° Special of 18/09/2025, Ministry of Justice)",
       "url": "https://www.minijust.gov.rw/index.php?eID=dumpFile&f=144155&t=f&token=75e63fc504481c93e1ed017130c13b4c35f3935e",
       "date": "2025-09-18",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 34,
     "summary": "A shared health record and national patient ID exist, but an implementing partner reported that clinicians were not yet trained to view data from other facilities. We found no source showing cross-facility viewing in use, so the cell sits below Tanzania's working referral view.",
     "sources": [
      {
       "title": "Rwanda Health Information Exchange (RHIE): achievements over the last three years, full report (CIIC-HIN, implementing partner)",
       "url": "https://ciichin.org/wp-content/uploads/2025/01/Rwanda-Health-Information-System-Ecosystem-RHIE-Achievement-over-last-Three-years-Full-Report.pdf",
       "date": "2025-01",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "Rwanda: Bill Gates in Rwanda to Explore Health, AI Progress (The New Times via allAfrica)",
       "url": "https://allafrica.com/stories/202607210078.html",
       "date": "2026-07-20",
       "publisherClass": "news"
      },
      {
       "title": "Health Sector Strategic Plan V, July 2024 to June 2029 (Ministry of Health)",
       "url": "https://www.moh.gov.rw/index.php?eID=dumpFile&t=f&f=117507&token=f2a527e089201f73bec29f8ce6d6c4dc55ed241e",
       "date": "2024",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Research on people needs ethics approval and written consent, reuse of research data needs the participant's permission again, and re-identification is a crime. Routine data still flows to a national analytics centre with no individual opt-out we could find.",
     "sources": [
      {
       "title": "Law n° 015/2022 relating to research on a human being (RwandaLII)",
       "url": "https://rwandalii.org/akn/rw/act/law/2022/15/eng@2022-08-12",
       "date": "2022-08-12",
       "publisherClass": "legal_text"
      },
      {
       "title": "Law n° 026/2025 of 17/09/2025 regulating healthcare services (Official Gazette n° Special of 18/09/2025, Ministry of Justice)",
       "url": "https://www.minijust.gov.rw/index.php?eID=dumpFile&f=144155&t=f&token=75e63fc504481c93e1ed017130c13b4c35f3935e",
       "date": "2025-09-18",
       "publisherClass": "legal_text"
      },
      {
       "title": "Law n° 058/2021 relating to the protection of personal data and privacy (RwandaLII)",
       "url": "https://rwandalii.org/akn/rw/act/law/2021/58/eng@2021-10-15",
       "date": "2021-10-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "New Health Intelligence Center to drive real-time, evidence-based decisions (Ministry of Health)",
       "url": "https://www.moh.gov.rw/news-detail/new-health-intelligence-center-to-drive-real-time-evidence-based-decisions",
       "date": "2025-04-03",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 55,
     "summary": "Rwanda FDA guidelines in effect since December 2025 cover AI software as a medical device, including adaptive models, data provenance, algorithm changes and post-market drift. Human oversight appears only in the foreword, not as a binding requirement, so the cell sits at the bottom of the band.",
     "sources": [
      {
       "title": "Guidelines for Review and Approval of Software as Medical Devices (SaMD), Version 1 (Rwanda FDA; Internet Archive copy of 7 Jan 2026, live link returned 404 on 2 Oct 2026)",
       "url": "https://web.archive.org/web/20260107064605/https://rwandafda.gov.rw/monitoring-tool/documents-management/uploads/1/Guidelines/1767694227_Guidelines%20for%20Review%20and%20Approval%20of%20Software%20as%20Medical%20Devices%20(SaMD)_December%202025.pdf",
       "date": "2025-06-11",
       "publisherClass": "official"
      },
      {
       "title": "Stakeholders documents: Guidelines for review and approval of software as medical devices (SaMD), listed 17/12/2025 (Rwanda FDA)",
       "url": "https://monitoring.rwandafda.gov.rw/stakeholders/",
       "date": "2025-12-17",
       "publisherClass": "official"
      },
      {
       "title": "The National AI Policy (Ministry of ICT and Innovation)",
       "url": "https://www.minict.gov.rw/fileadmin/user_upload/minict_user_upload/Documents/Policies/Artificial_Intelligence_Policy.pdf",
       "date": "2022",
       "publisherClass": "official"
      },
      {
       "title": "Rwanda: Bill Gates in Rwanda to Explore Health, AI Progress (The New Times via allAfrica)",
       "url": "https://allafrica.com/stories/202607210078.html",
       "date": "2026-07-20",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Law n° 058/2021 relating to the protection of personal data and privacy",
     "level": "National",
     "year": "2021",
     "what": "Health is sensitive data; copy right; 48-hour breach notice; storage in Rwanda; prison for selling data.",
     "url": "https://rwandalii.org/akn/rw/act/law/2021/58/eng@2021-10-15"
    },
    {
     "name": "Law n° 026/2025 regulating healthcare services",
     "level": "National",
     "year": "2025",
     "what": "Patient file copy in five working days; confidentiality; encryption of patient data; ten-year retention.",
     "url": "https://www.minijust.gov.rw/index.php?eID=dumpFile&f=144155&t=f&token=75e63fc504481c93e1ed017130c13b4c35f3935e"
    },
    {
     "name": "Law n° 015/2022 relating to research on a human being",
     "level": "National",
     "year": "2022",
     "what": "Ethics committee approval; written, revocable consent; reuse of research data needs fresh permission.",
     "url": "https://rwandalii.org/akn/rw/act/law/2022/15/eng@2022-08-12"
    },
    {
     "name": "Rwanda FDA Guidelines for Review and Approval of Software as Medical Devices (SaMD)",
     "level": "National",
     "year": "2025",
     "what": "Registration rules for AI software, covering adaptive models, provenance, changes and post-market drift.",
     "url": "https://monitoring.rwandafda.gov.rw/stakeholders/"
    },
    {
     "name": "National Artificial Intelligence Policy",
     "level": "National",
     "year": "2022",
     "what": "Names healthcare a priority AI sector; RURA to promote national ethical AI guidelines.",
     "url": "https://www.minict.gov.rw/fileadmin/user_upload/minict_user_upload/Documents/Policies/Artificial_Intelligence_Policy.pdf"
    }
   ],
   "dti": {
    "grade": 83,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": []
  },
  {
   "iso3": "CHN",
   "name": "China",
   "region": "Asia",
   "overall": 43,
   "rank": "56=",
   "likelyRank": "52 to 60",
   "band": "Weak",
   "keysModel": "State",
   "confidence": "high",
   "headline": "Over 9,000 public hospitals feed provincial data platforms, but patients can copy only listed parts of their chart and cannot see who looked.",
   "categories": {
    "access": {
     "score": 35,
     "summary": "The Civil Code lets patients read and copy listed record types, and the 2013 rules list what hospitals may copy, leaving out progress notes, with a fee and no fixed deadline. Public health files are opening to residents county by county, a target for 2026.",
     "sources": [
      {
       "title": "Civil Code of the People's Republic of China (Xinhua text on Ministry of National Defense site)",
       "url": "http://www.mod.gov.cn/gfbw/qwfb/yw_214049/4866121.html",
       "date": "2020-06-02",
       "publisherClass": "legal_text"
      },
      {
       "title": "Medical Record Management Rules for Medical Institutions (2013), full text (Tongji University School of Medicine)",
       "url": "https://med.tongji.edu.cn/info/1607/11324.htm",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "Notice on 2026 basic public health services (NHC and three agencies, Shenzhen Health Commission copy)",
       "url": "https://wjw.sz.gov.cn/xxgk/zcfggfxwj/mybh_5/content/post_12991931.html",
       "date": "2026-07-28",
       "publisherClass": "official"
      },
      {
       "title": "Personal Information Protection Law of the People's Republic of China (Cyberspace Administration of China)",
       "url": "https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm",
       "date": "2021-08-20",
       "publisherClass": "legal_text"
      }
     ]
    },
    "control": {
     "score": 30,
     "summary": "PIPL needs separate consent for health data and lets people withdraw it, but statutory duties and public health emergencies need no consent. Hospitals feed provincial platforms by default, with no national opt-out and no patient-visible access log found.",
     "sources": [
      {
       "title": "Personal Information Protection Law of the People's Republic of China (Cyberspace Administration of China)",
       "url": "https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm",
       "date": "2021-08-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Shenzhen Health Data Management Measures (Shenzhen Health Commission)",
       "url": "https://wjw.sz.gov.cn/xxgk/zcfggfxwj/mybh_5/content/post_11009298.html",
       "date": "2023-11-16",
       "publisherClass": "official"
      },
      {
       "title": "China's health services: digital intelligence (Health News, reposted by WFCMS)",
       "url": "https://www.wfcms.org/show/22/8567.html",
       "date": "2026-05-21",
       "publisherClass": "news"
      },
      {
       "title": "Measures on Data Security and Personal Information Protection in Medical and Health Institutions (Trial), full text (Digital Elite reprint)",
       "url": "https://www.digitalelite.cn/h-nd-10024.html",
       "date": "2026-04-21",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 45,
     "summary": "A February 2026 measure by the NHC, police and cyberspace agencies (Yicai) sets health-sector data rules, and an April 2026 campaign targets hospitals that let strangers look up records. Oversight sits with government departments, not an independent authority, and state access is broad.",
     "sources": [
      {
       "title": "Measures on Data Security and Personal Information Protection in Medical and Health Institutions (Trial), full text (Digital Elite reprint)",
       "url": "https://www.digitalelite.cn/h-nd-10024.html",
       "date": "2026-04-21",
       "publisherClass": "legal_text"
      },
      {
       "title": "CAC, MIIT and MPS announcement on the 2026 personal information protection campaigns",
       "url": "https://www.cac.gov.cn/2026-04/02/c_1776867645836849.htm",
       "date": "2026-04-02",
       "publisherClass": "official"
      },
      {
       "title": "Supreme People's Court typical cases on crimes infringing citizens' personal information (Xinhua)",
       "url": "https://www.news.cn/legal/20260508/6d75070dddf44834adfbe5734b20af3e/c.html",
       "date": "2026-05-08",
       "publisherClass": "news"
      },
      {
       "title": "Medical data security enters a year of special governance (Yicai)",
       "url": "https://www.yicai.com/news/103232118.html",
       "date": "2026-06-16",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 60,
     "summary": "Health News reported 9,125 public hospitals linked to regional platforms and 8,069 sharing test results across institutions in 2026. One national insurance platform covers 1.36 billion people, but the record is joined by province, not as one national chart.",
     "sources": [
      {
       "title": "Hubei Medical Insurance Bureau notice on regulating externally dispensed insurance prescriptions (Wuhan Medical Insurance Bureau copy)",
       "url": "https://ybj.wuhan.gov.cn/zwgk_52/zcfgyjd/qtzdgkwj/202502/t20250225_2539139.shtml",
       "date": "2024-12-03",
       "publisherClass": "official"
      },
      {
       "title": "China's health services: digital intelligence (Health News, reposted by WFCMS)",
       "url": "https://www.wfcms.org/show/22/8567.html",
       "date": "2026-05-21",
       "publisherClass": "news"
      },
      {
       "title": "National unified medical insurance information platform fully built, covering 1.36 billion insured (Xinhua)",
       "url": "http://www.news.cn/2022-05/16/c_1128655718.htm",
       "date": "2022-05-16",
       "publisherClass": "news"
      },
      {
       "title": "NHC director: 98% of prefecture cities recognise over 300 test results (Beijing News via Tencent)",
       "url": "https://news.qq.com/rain/a/20260914A08U5D00",
       "date": "2026-09-14",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 38,
     "summary": "PIPL needs separate consent before data goes to another company, and selling personal data is a crime. Yet Shanghai now opens anonymised hospital data to insurers for product design without individual consent, and national policy pushes clinical data authorised operation.",
     "sources": [
      {
       "title": "Personal Information Protection Law of the People's Republic of China (Cyberspace Administration of China)",
       "url": "https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm",
       "date": "2021-08-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Shanghai opens hospital data for 'pre-existing condition' insurance products (Yicai via Tencent News)",
       "url": "https://news.qq.com/rain/a/20260920A0C4MZ00",
       "date": "2026-09-20",
       "publisherClass": "news"
      },
      {
       "title": "Medical data security enters a year of special governance (Yicai)",
       "url": "https://www.yicai.com/news/103232118.html",
       "date": "2026-06-16",
       "publisherClass": "news"
      },
      {
       "title": "Implementation opinion on promoting and regulating AI plus healthcare, Guo Wei Ban Gui Hua Fa [2025] No. 30 (MOFCOM law database)",
       "url": "https://policy.mofcom.gov.cn/claw/clawContent.shtml?id=104035",
       "date": "2025-10-20",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 50,
     "summary": "Doctors in 8,069 public hospitals can retrieve test results from other institutions, and the national goal is cross-region result sharing. Full cross-provider charts are visible to clinicians only in some regions, such as Chongqing.",
     "sources": [
      {
       "title": "Implementation opinion on promoting and regulating AI plus healthcare, Guo Wei Ban Gui Hua Fa [2025] No. 30 (MOFCOM law database)",
       "url": "https://policy.mofcom.gov.cn/claw/clawContent.shtml?id=104035",
       "date": "2025-10-20",
       "publisherClass": "official"
      },
      {
       "title": "Shenzhen Health Data Management Measures (Shenzhen Health Commission)",
       "url": "https://wjw.sz.gov.cn/xxgk/zcfggfxwj/mybh_5/content/post_11009298.html",
       "date": "2023-11-16",
       "publisherClass": "official"
      },
      {
       "title": "China's health services: digital intelligence (Health News, reposted by WFCMS)",
       "url": "https://www.wfcms.org/show/22/8567.html",
       "date": "2026-05-21",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "Research on identifiable people needs informed consent and ethics review, but anonymised data is exempt from review and Shanghai waived individual consent for insurer use. Credit goes to ethics committees, a secure processing zone and criminal penalties.",
     "sources": [
      {
       "title": "Measures for Ethical Review of Life Science and Medical Research Involving Humans, Guo Wei Ke Jiao Fa [2023] No. 4 (Peking University Health Science Center copy)",
       "url": "https://research.bjmu.edu.cn/llwyh/llwyh_fgwj/98685712020c4ae1a670bfe0adbfa905.htm",
       "date": "2023-02-18",
       "publisherClass": "legal_text"
      },
      {
       "title": "Shanghai opens hospital data for 'pre-existing condition' insurance products (Yicai via Tencent News)",
       "url": "https://news.qq.com/rain/a/20260920A0C4MZ00",
       "date": "2026-09-20",
       "publisherClass": "news"
      },
      {
       "title": "Medical data security enters a year of special governance (Yicai)",
       "url": "https://www.yicai.com/news/103232118.html",
       "date": "2026-06-16",
       "publisherClass": "news"
      },
      {
       "title": "Supreme People's Court typical cases on crimes infringing citizens' personal information (Xinhua)",
       "url": "https://www.news.cn/legal/20260508/6d75070dddf44834adfbe5734b20af3e/c.html",
       "date": "2026-05-08",
       "publisherClass": "news"
      }
     ]
    },
    "ai": {
     "score": 62,
     "summary": "AI medical devices are registered under the NMPA's AI device guideline that locks algorithms and needs re-registration for updates that affect safety or effectiveness. Internet hospitals may not let AI write prescriptions or stand in for the doctor.",
     "sources": [
      {
       "title": "Consultation on the AI Medical Device Registration Review Guideline (2026 revision draft) (CMDE Yangtze River Delta branch)",
       "url": "https://www.ydcmdei.org.cn/article/975",
       "date": "2026-09-14",
       "publisherClass": "official"
      },
      {
       "title": "Internet diagnosis and treatment supervision rules issued (Health News, Ankang Health Commission)",
       "url": "https://wjw.ankang.gov.cn/Content-2416375.html",
       "date": "2022-06-17",
       "publisherClass": "official"
      },
      {
       "title": "Implementation opinion on promoting and regulating AI plus healthcare, Guo Wei Ban Gui Hua Fa [2025] No. 30 (MOFCOM law database)",
       "url": "https://policy.mofcom.gov.cn/claw/clawContent.shtml?id=104035",
       "date": "2025-10-20",
       "publisherClass": "official"
      },
      {
       "title": "Sandbox regulation for autonomous surgical robots: China vs abroad (China Pharmaceutical News)",
       "url": "https://bk.cnpharm.com/zgyyb/2026/04/30/app_324606.html",
       "date": "2026-04-30",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Personal Information Protection Law",
     "level": "National",
     "year": "2021",
     "what": "Health data is sensitive and needs separate consent; no consent needed for statutory duties.",
     "url": "https://www.cac.gov.cn/2021-08/20/c_1631050028355286.htm"
    },
    {
     "name": "Civil Code (Articles 1034, 1225, 1226)",
     "level": "National",
     "year": "2020",
     "what": "Patients may read and copy listed records; hospitals must keep patient information confidential.",
     "url": "http://www.mod.gov.cn/gfbw/qwfb/yw_214049/4866121.html"
    },
    {
     "name": "Medical Record Management Rules for Medical Institutions",
     "level": "National",
     "year": "2013",
     "what": "Lists copyable record parts, allows a cost fee, sets 15 and 30 year retention.",
     "url": "https://med.tongji.edu.cn/info/1607/11324.htm"
    },
    {
     "name": "Measures on Data Security and Personal Information Protection in Medical and Health Institutions (Trial)",
     "level": "National",
     "year": "2026",
     "what": "Health-sector rules on data grading, record lookup authorisation, local storage and penalties.",
     "url": "https://www.digitalelite.cn/h-nd-10024.html"
    },
    {
     "name": "Measures for Ethical Review of Life Science and Medical Research Involving Humans",
     "level": "National",
     "year": "2023",
     "what": "Informed consent and ethics review; anonymised data research exempt from review.",
     "url": "https://research.bjmu.edu.cn/llwyh/llwyh_fgwj/98685712020c4ae1a670bfe0adbfa905.htm"
    },
    {
     "name": "Internet Diagnosis and Treatment Supervision Rules (Trial)",
     "level": "National",
     "year": "2022",
     "what": "Bans AI-generated prescriptions and AI replacing the doctor in online care.",
     "url": "https://wjw.ankang.gov.cn/Content-2416375.html"
    },
    {
     "name": "Shenzhen Health Data Management Measures",
     "level": "Regional",
     "year": "2023",
     "what": "Other institutions may view a person's record only with separate, revocable consent.",
     "url": "https://wjw.sz.gov.cn/xxgk/zcfggfxwj/mybh_5/content/post_11009298.html"
    }
   ],
   "dti": {
    "grade": 81,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-05-08",
     "headline": "Hospital booking contractor secretly copied millions of patients' details, court rules",
     "paraphrase": "A software firm that ran a hospital's online appointment system copied registration details of about 2.88 million patients into its own database over several years. A court convicted the firm and its managers, with fines and prison terms.",
     "source": "Supreme People's Court of China (typical cases)",
     "url": "https://www.court.gov.cn/zixun/xiangqing/499271.html",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2024-11-18",
     "headline": "Court finds hospital rewrote a patient's electronic record after discharge; hospital pays in full",
     "paraphrase": "A court found that key parts of a patient's electronic record had been modified several times and created after discharge. Because the altered record blocked a fair assessment, the court presumed the hospital at fault and ordered full compensation.",
     "source": "Health China (健康界)",
     "url": "https://www.cn-healthcare.com/articlewm/20241118/wap-content-1642040.html",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2026-02-16",
     "headline": "Appeal court orders hospital to correct what a patient's record said they reported",
     "paraphrase": "A patient said their discharge record overstated how long they had noticed a symptom, harming an insurance claim, and the hospital refused to change it. The appeal court found the hospital could not prove the entry and ordered it corrected.",
     "source": "Health China (健康界)",
     "url": "https://www.cn-healthcare.com/articlewm/20260215/content-1666830.html",
     "theme": "record_wrong",
     "status": "finding"
    },
    {
     "date": "2025-04-28",
     "headline": "Shanghai regulator penalises online medical firms after patient data was stolen and left unencrypted",
     "paraphrase": "Shanghai's cyberspace regulator penalised several online medical service firms. One had unpatched flaws and suspicious foreign access that led to data theft; another stored over 6.5 million patient records, including conditions and prescriptions, without encryption.",
     "source": "The Paper (澎湃新闻)",
     "url": "https://www.thepaper.cn/newsDetail_forward_30736580",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2026-06-03",
     "headline": "National notice lists health apps that shared users' data with third parties without consent",
     "paraphrase": "A national cybersecurity notice listed 71 apps breaking personal data rules, including several medical and health apps. Violations included giving personal data to third parties without separate consent, no way to withdraw consent, and missing encryption.",
     "source": "21st Century Business Herald (21经济网)",
     "url": "https://www.21jingji.com/article/20260603/herald/fba2d42a4d84eabb6a46c30e8f5d3855.html",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-10-28",
     "headline": "Hospital apps let an ex-spouse download a patient's records with just name and ID",
     "paraphrase": "Several large hospitals' online services released test reports and records to anyone with a patient's name and ID number. A woman's former husband used this for two years to obtain and circulate her records. Some hospitals then added identity checks.",
     "source": "China Women's News (via Tencent News)",
     "url": "https://news.qq.com/rain/a/20251028A03EDO00",
     "theme": "breach",
     "status": "admitted"
    },
    {
     "date": "2025-05-06",
     "headline": "Investigation finds hospital staff selling patients' contact details for about 50 yuan each",
     "paraphrase": "Reporters found some hospital staff and outside contractors selling patients' names, addresses and phone numbers to private companies, about 50 yuan per record. A patient described being contacted by a company that already knew her private details.",
     "source": "Legal Daily (via Hunan Daily / voc.com.cn)",
     "url": "https://m.voc.com.cn/xhn/news/202505/29345447.html",
     "theme": "sold_or_shared",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "COL",
   "name": "Colombia",
   "region": "Americas",
   "overall": 43,
   "rank": "56=",
   "likelyRank": "52 to 59",
   "band": "Weak",
   "keysModel": "State",
   "confidence": "medium",
   "headline": "Colombia's law says patients own their electronic record and must consent to sharing, but the new national exchange is built for providers, not patients.",
   "categories": {
    "access": {
     "score": 45,
     "summary": "Ley 1751 and Ley 2015 give patients a free, complete electronic copy of their record. No national patient portal was found; the new national summaries are viewed by providers, so access still runs provider by provider.",
     "sources": [
      {
       "title": "Ley Estatutaria 1751 de 2015, articulo 10 (Secretaria del Senado)",
       "url": "http://www.secretariasenado.gov.co/senado/basedoc/ley_1751_2015.html",
       "date": "2015",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 2015 de 2020, historia clinica electronica interoperable (Funcion Publica)",
       "url": "https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=105472",
       "date": "2020-01-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Resolucion 1995 de 1999, manejo de la historia clinica (Minsalud)",
       "url": "https://www.minsalud.gov.co/Normatividad_Nuevo/RESOLUCI%C3%93N%201995%20DE%201999.pdf",
       "date": "1999",
       "publisherClass": "legal_text"
      },
      {
       "title": "Resumen Digitales de Atencion (RDA), micrositio IHCE (Minsalud)",
       "url": "https://www.minsalud.gov.co/ihce/Paginas/resumen-digitales-de-atencion.aspx",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 27,
     "summary": "Ley 2015 says providers may access the electronic record only with the person's prior, express consent. The rollout rules describe automatic sharing with any authorised professional and no patient-facing consent switch or access log.",
     "sources": [
      {
       "title": "Ley 2015 de 2020, historia clinica electronica interoperable (Funcion Publica)",
       "url": "https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=105472",
       "date": "2020-01-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Resolucion 1888 de 2025, Resumen Digital de Atencion en Salud (Minsalud)",
       "url": "https://www.minsalud.gov.co/Normatividad_Nuevo/Resolucion%20No%201888%20de%202025.pdf",
       "date": "2025-09-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Informe especial: implementacion de la interoperabilidad de la historia clinica electronica (Minsalud)",
       "url": "https://www.minsalud.gov.co/sites/rid/Lists/BibliotecaDigital/RIDE/DE/OT/informe-especial-ihce.pdf",
       "date": "2026-08",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 50,
     "summary": "Ley 1581 treats health data as sensitive and the SIC has sanctioned health insurers, including EPS SOS for sharing an HIV patient's record. Fines reach 2,000 monthly minimum wages but apply only to private entities, and the health superintendency itself was breached in March 2026.",
     "sources": [
      {
       "title": "Ley 1581 de 2012, proteccion de datos personales (Secretaria del Senado)",
       "url": "http://www.secretariasenado.gov.co/senado/basedoc/ley_1581_2012.html",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "Sanciones proteccion de datos personales 2025 (SIC)",
       "url": "https://www.sic.gov.co/sanciones-proteccion-datos-personales-2025",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "SIC sanciona a EPS SOS por divulgar historia clinica de paciente con VIH",
       "url": "https://consultorsalud.com/sic-sanciona-eps-sos-historia-clinica-vih/",
       "date": "2025-08-25",
       "publisherClass": "news"
      },
      {
       "title": "Supersalud confirma filtracion masiva de datos sensibles de su archivo documental",
       "url": "https://www.eltiempo.com/datos/supersalud-confirma-filtracion-masiva-de-datos-sensibles-de-su-archivo-documental-en-ciberataque-3544641",
       "date": "2026-04-01",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 50,
     "summary": "A national exchange run by the Ministry of Health went live on 15 April 2026. By 4 August 2026 it held 21.5 million care summaries for 6.9 million patients from 1,430 providers, but labs, imaging and claims are not yet included.",
     "sources": [
      {
       "title": "Informe especial: implementacion de la interoperabilidad de la historia clinica electronica (Minsalud)",
       "url": "https://www.minsalud.gov.co/sites/rid/Lists/BibliotecaDigital/RIDE/DE/OT/informe-especial-ihce.pdf",
       "date": "2026-08",
       "publisherClass": "official"
      },
      {
       "title": "Resolucion 1888 de 2025, Resumen Digital de Atencion en Salud (Minsalud)",
       "url": "https://www.minsalud.gov.co/Normatividad_Nuevo/Resolucion%20No%201888%20de%202025.pdf",
       "date": "2025-09-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Resolucion 1799 de 2026, RDA de dispensacion de medicamentos (Minsalud)",
       "url": "https://www.minsalud.gov.co/sites/rid/Lists/BibliotecaDigital/RIDE/DE/DIJ/resolucion-1799-de-2026.pdf",
       "date": "2026-08-05",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 2015 de 2020, historia clinica electronica interoperable (Funcion Publica)",
       "url": "https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=105472",
       "date": "2020-01-31",
       "publisherClass": "legal_text"
      }
     ]
    },
    "commercial": {
     "score": 50,
     "summary": "Health data cannot be processed without explicit authorisation under Ley 1581, and Ley 2015 bars insurers and providers from disclosing record data without express consent. No specific rule on health-data brokers, ad targeting or de-identified data sales was found.",
     "sources": [
      {
       "title": "Ley 1581 de 2012, proteccion de datos personales (Secretaria del Senado)",
       "url": "http://www.secretariasenado.gov.co/senado/basedoc/ley_1581_2012.html",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 2015 de 2020, historia clinica electronica interoperable (Funcion Publica)",
       "url": "https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=105472",
       "date": "2020-01-31",
       "publisherClass": "legal_text"
      },
      {
       "title": "Sanciones proteccion de datos personales 2025 (SIC)",
       "url": "https://www.sic.gov.co/sanciones-proteccion-datos-personales-2025",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 50,
     "summary": "Any authenticated professional at a connected provider can search a patient's national care summaries in real time from their own system. Coverage is limited to care since each provider joined in 2026, about 13 percent of residents by August.",
     "sources": [
      {
       "title": "Resolucion 1888 de 2025, Resumen Digital de Atencion en Salud (Minsalud)",
       "url": "https://www.minsalud.gov.co/Normatividad_Nuevo/Resolucion%20No%201888%20de%202025.pdf",
       "date": "2025-09-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Informe especial: implementacion de la interoperabilidad de la historia clinica electronica (Minsalud)",
       "url": "https://www.minsalud.gov.co/sites/rid/Lists/BibliotecaDigital/RIDE/DE/OT/informe-especial-ihce.pdf",
       "date": "2026-08",
       "publisherClass": "official"
      }
     ]
    },
    "research": {
     "score": 45,
     "summary": "Research on people needs written informed consent reviewed by an ethics committee under Resolution 8430, but the committee may waive consent for no-risk studies such as record review. No general opt-out or public register of data uses was found.",
     "sources": [
      {
       "title": "Resolucion 8430 de 1993, normas para la investigacion en salud (Minsalud)",
       "url": "https://www.minsalud.gov.co/sites/rid/Lists/BibliotecaDigital/RIDE/DE/DIJ/RESOLUCION-8430-DE-1993.PDF",
       "date": "1993",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 1581 de 2012, proteccion de datos personales (Secretaria del Senado)",
       "url": "http://www.secretariasenado.gov.co/senado/basedoc/ley_1581_2012.html",
       "date": "2012",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 35,
     "summary": "Decreto 4725 of 2005 treats medical software as a device needing INVIMA registration, but no AI-specific change control or oversight rule was found. A health AI strategy is still being drafted and the AI bill filed in July 2026 is pending.",
     "sources": [
      {
       "title": "Decreto 4725 de 2005, dispositivos medicos (normograma INVIMA)",
       "url": "https://normograma.invima.gov.co/compilacion/docs/decreto_4725_2005.htm",
       "date": "2005",
       "publisherClass": "legal_text"
      },
      {
       "title": "CONPES 4144: hoja de ruta de Colombia en inteligencia artificial (DNP)",
       "url": "https://www.dnp.gov.co/publicaciones/Planeacion/Paginas/conpes-4144-hoja-de-ruta-colombia-inteligencia-artificial-retos-actuales-transformacion-futura.aspx",
       "date": "2025-05-16",
       "publisherClass": "official"
      },
      {
       "title": "Informe especial: implementacion de la interoperabilidad de la historia clinica electronica (Minsalud)",
       "url": "https://www.minsalud.gov.co/sites/rid/Lists/BibliotecaDigital/RIDE/DE/OT/informe-especial-ihce.pdf",
       "date": "2026-08",
       "publisherClass": "official"
      },
      {
       "title": "Proyecto de Ley 025 de 2026 Camara, regula la inteligencia artificial",
       "url": "https://www.camara.gov.co/wp-content/uploads/2026/07/proyectos-ley/documentos/proyecto-36127/P.L.025-2026SC-INTELIGENCIA-ARTIFICIAL.pdf",
       "date": "2026-07-21",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Ley Estatutaria 1751 de 2015 (derecho fundamental a la salud)",
     "level": "National",
     "year": "2015",
     "what": "Right to consult the whole clinical record free, get a copy, and confidentiality.",
     "url": "http://www.secretariasenado.gov.co/senado/basedoc/ley_1751_2015.html"
    },
    {
     "name": "Ley 2015 de 2020 (historia clinica electronica interoperable)",
     "level": "National",
     "year": "2020",
     "what": "Patient owns the electronic record; consent for access; free electronic copy; national interoperability.",
     "url": "https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=105472"
    },
    {
     "name": "Ley 1581 de 2012 (proteccion de datos personales)",
     "level": "National",
     "year": "2012",
     "what": "Health data sensitive; explicit authorisation; breach reporting; SIC fines up to 2,000 minimum wages.",
     "url": "http://www.secretariasenado.gov.co/senado/basedoc/ley_1581_2012.html"
    },
    {
     "name": "Resolucion 1888 de 2025 (Resumen Digital de Atencion en Salud)",
     "level": "National",
     "year": "2025",
     "what": "Adopts national care summaries, FHIR exchange, access logging; providers to connect by April 2026.",
     "url": "https://www.minsalud.gov.co/Normatividad_Nuevo/Resolucion%20No%201888%20de%202025.pdf"
    },
    {
     "name": "Resolucion 1799 de 2026 (RDA de dispensacion de medicamentos)",
     "level": "National",
     "year": "2026",
     "what": "Adds medicine dispensing to the national summaries; six months from 1 September 2026.",
     "url": "https://www.minsalud.gov.co/sites/rid/Lists/BibliotecaDigital/RIDE/DE/DIJ/resolucion-1799-de-2026.pdf"
    },
    {
     "name": "Resolucion 8430 de 1993 (investigacion en salud)",
     "level": "National",
     "year": "1993",
     "what": "Written informed consent and ethics committee review; waiver possible for no-risk research.",
     "url": "https://www.minsalud.gov.co/sites/rid/Lists/BibliotecaDigital/RIDE/DE/DIJ/RESOLUCION-8430-DE-1993.PDF"
    },
    {
     "name": "Decreto 4725 de 2005 (dispositivos medicos)",
     "level": "National",
     "year": "2005",
     "what": "Medical device rules covering software; INVIMA registration by risk class.",
     "url": "https://normograma.invima.gov.co/compilacion/docs/decreto_4725_2005.htm"
    }
   ],
   "dti": {
    "grade": 90,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-01",
   "stories": [
    {
     "date": "2026-04-13",
     "headline": "Regulator orders hospital and insurer to fix data handling after a patient's record leaked",
     "paraphrase": "Sensitive details from a woman's health record reached community leaders without her consent. The data protection regulator found the hospital and her health insurer at fault and ordered five corrective measures, including staff training and stronger confidentiality.",
     "source": "La FM",
     "url": "https://www.lafm.com.co/economia/sin-sanciona-a-eps-por-revelar-datos-personales-de-paciente-que-interrumpe-su-embarazo-396092",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2025-08-23",
     "headline": "Insurer sanctioned for sending a patient's full record to the patient's employer",
     "paraphrase": "During a workplace illness review, a health insurer sent a patient's complete record, including sensitive test results, to four managers at the patient's employer. The data protection regulator sanctioned the insurer, saying the disclosure had no necessity or relevance.",
     "source": "El Tiempo",
     "url": "https://www.eltiempo.com/salud/sic-sanciona-a-sos-eps-por-divulgar-sin-autorizacion-la-historia-clinica-de-paciente-con-vih-3484039",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2024-10-17",
     "headline": "Court orders clinic to apologise after staff passed patient data to an outside group",
     "paraphrase": "Clinic staff shared a woman's personal and medical details with an outside organisation, which then called and messaged her. The Constitutional Court ruled her privacy was violated and ordered the clinic to apologise publicly and investigate its staff.",
     "source": "El Colombiano",
     "url": "https://www.elcolombiano.com/colombia/salud/aborto-clinica-que-filtro-datos-de-mujer-que-pidio-ive-a-fundacion-tendra-que-investigar-a-su-personal-FC25637332",
     "theme": "sold_or_shared",
     "status": "finding"
    },
    {
     "date": "2026-04-02",
     "headline": "Cyberattack on the national health regulator exposed patient records and complaints",
     "paraphrase": "The national health regulator confirmed unauthorised access to its document system. Reports say files downloaded included medical histories and patients' petitions and complaints, about 1.6 percent of its document store.",
     "source": "Pulzo",
     "url": "https://www.pulzo.com/nacion/crece-alerta-por-ataque-supersalud-por-que-filtraron-datos-pacientes-PP5122633",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "ZAF",
   "name": "South Africa",
   "region": "Africa",
   "overall": 43,
   "rank": "56=",
   "likelyRank": "51 to 59",
   "band": "Weak",
   "keysModel": "Institutional",
   "confidence": "high",
   "headline": "South African patients have strong paper rights under POPIA and the National Health Act, but records stay in each provider's or province's own system.",
   "categories": {
    "access": {
     "score": 40,
     "summary": "POPIA section 23 and PAIA give a right to your record within 30 days, but providers may charge a prescribed fee and no national patient portal was found. Scored as statutory right (45) minus 5 for the fee.",
     "sources": [
      {
       "title": "Protection of Personal Information Act 4 of 2013 (Government Gazette 37067)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf",
       "date": "2013-11-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Promotion of Access to Information Act 2 of 2000 (Department of Justice consolidated copy)",
       "url": "https://www.justice.gov.za/legislation/acts/2000-002.pdf",
       "date": "undated",
       "publisherClass": "legal_text"
      },
      {
       "title": "HPCSA Guidelines on the Keeping of Patient Records, Booklet 9 (mirror copy)",
       "url": "https://www.hpcsa-blogs.co.za/wp-content/uploads/2022/08/Booklet-9-Guidelines-on-Patient-Records.pdf",
       "date": "2016-09",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "NHI Chief Directorate: Health Systems Digital Information (National Department of Health)",
       "url": "https://www.health.gov.za/nhi-cd-hs/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 42,
     "summary": "The National Health Act needs written consent to disclose records outside care, and POPIA lets you ask which third parties saw your data. But providers share for care without asking, and no system shows patients who opened their record.",
     "sources": [
      {
       "title": "National Health Act 61 of 2003 (Government Gazette 26595)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/201409/a61-03.pdf",
       "date": "2004-07-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Protection of Personal Information Act 4 of 2013 (Government Gazette 37067)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf",
       "date": "2013-11-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Discovery Health: Permission to make certain information available to a third party (HealthID consent form)",
       "url": "https://discoveryhealthmedicalscheme.co.za/wcm/discoverycoza/assets/medical-aid/application-forms/2024/permission-to-make-certain-information-available-to-a-third-party.pdf",
       "date": "2024-10-01",
       "publisherClass": "blog_vendor"
      }
     ]
    },
    "privacy": {
     "score": 60,
     "summary": "POPIA makes health special personal information, with fines up to R10 million and new 2026 health rules for insurers, schemes and employers. Breach notice has no fixed deadline, and no health-sector fine was found.",
     "sources": [
      {
       "title": "Protection of Personal Information Act 4 of 2013 (Government Gazette 37067)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf",
       "date": "2013-11-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties, 2026 (Gazette 54268, Notice 7198)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/202603/54268gon7198.pdf",
       "date": "2026-03-06",
       "publisherClass": "legal_text"
      },
      {
       "title": "Information Regulator: Enforcement notice issued to Dis-Chem due to contravention of POPIA",
       "url": "https://inforegulator.org.za/wp-content/uploads/2020/07/FINAL-MEDIA-STATEMENT-ENFORCEMENT-NOTICE-ISSUED-TO-DISCHEM-PHARMACIES-LTD.pdf",
       "date": "2023-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Information Regulator refers National Department of Health to the Enforcement Committee over COVID-19 data",
       "url": "https://inforegulator.org.za/wp-content/uploads/2020/07/Media-Statement_Information-Regulator-Refers-NDOH-to-the-Enforcement-Committee.pdf",
       "date": "2023-02-20",
       "publisherClass": "official"
      }
     ]
    },
    "journey": {
     "score": 33,
     "summary": "Public clinics share a patient registration number (HPRS, in 3,265 facilities), but hospital records sit in separate provincial systems and four provinces have none. A national clinic EMR is only starting a 3,200-facility rollout.",
     "sources": [
      {
       "title": "National Department of Health Annual Report 2024/25",
       "url": "https://www.health.gov.za/wp-content/uploads/2025/11/NDoH-2024-25-Annual-Report-_-19-September-2025.pdf",
       "date": "2025-09-19",
       "publisherClass": "official"
      },
      {
       "title": "Minister of Health reply to question NW2014 on hospital and PHC electronic records (PMG)",
       "url": "https://pmg.org.za/committee-question/37900/",
       "date": "2026-05-28",
       "publisherClass": "official"
      },
      {
       "title": "Minister of Health reply to question NW4495 on EHR use in public hospitals and clinics (PMG)",
       "url": "https://pmg.org.za/committee-question/31734/",
       "date": "2025-08-01",
       "publisherClass": "official"
      },
      {
       "title": "The 2024 CMS Industry Report is now available (Council for Medical Schemes)",
       "url": "https://www.medicalschemes.co.za/the-2024-cms-industry-report-is-now-available/",
       "date": "2025-12-04",
       "publisherClass": "official"
      }
     ]
    },
    "commercial": {
     "score": 50,
     "summary": "POPIA requires opt-in consent for electronic direct marketing and treats health as special information, and the National Health Act bars disclosure without written consent. Insurers may still use health data for risk unless you object, and consumer health apps fall into gaps.",
     "sources": [
      {
       "title": "Protection of Personal Information Act 4 of 2013 (Government Gazette 37067)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf",
       "date": "2013-11-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "National Health Act 61 of 2003 (Government Gazette 26595)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/201409/a61-03.pdf",
       "date": "2004-07-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Regulatory challenges of digital health: mental health applications and personal data in South Africa (Frontiers in Pharmacology)",
       "url": "https://www.frontiersin.org/journals/pharmacology/articles/10.3389/fphar.2025.1498600/full",
       "date": "2025-04-30",
       "publisherClass": "academic"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "clinical": {
     "score": 32,
     "summary": "Clinicians can see public lab results across facilities through the NHLS, which serves over 80 percent of South Africans, but no shared record exists across hospitals or between public and private care.",
     "sources": [
      {
       "title": "National Health Act 61 of 2003 (Government Gazette 26595)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/201409/a61-03.pdf",
       "date": "2004-07-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "About the National Health Laboratory Service",
       "url": "https://www.nhls.ac.za/about-us/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "NHLS TrakCare Lab WebView results viewer",
       "url": "https://trakcarelabwebview.nhls.ac.za/trakcarelab/RDdefault.htm",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Discovery Health: Permission to make certain information available to a third party (HealthID consent form)",
       "url": "https://discoveryhealthmedicalscheme.co.za/wcm/discoverycoza/assets/medical-aid/application-forms/2024/permission-to-make-certain-information-available-to-a-third-party.pdf",
       "date": "2024-10-01",
       "publisherClass": "blog_vendor"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Identifiable records need the patient's, facility head's and an ethics committee's authorisation, but de-identified use needs none and POPIA allows research without consent where asking is disproportionate. There is no opt-out and no public register of uses.",
     "sources": [
      {
       "title": "National Health Act 61 of 2003 (Government Gazette 26595)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/201409/a61-03.pdf",
       "date": "2004-07-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Protection of Personal Information Act 4 of 2013 (Government Gazette 37067)",
       "url": "https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf",
       "date": "2013-11-26",
       "publisherClass": "legal_text"
      },
      {
       "title": "South African Ethics in Health Research Guidelines, 3rd edition v3.2 (NHREC, National Department of Health)",
       "url": "https://knowledgehub.health.gov.za/system/files/elibdownloads/2026-08/NDoH-2024-v3.2-master-signed.pdf",
       "date": "2024",
       "publisherClass": "official"
      },
      {
       "title": "ASSAf POPIA Compliance Framework for Researchers and Research Institutions",
       "url": "https://www.univen.ac.za/wp-content/uploads/2026/09/2025_ASSAf_POPIACompliance-Framework.pdf",
       "date": "2025-05-01",
       "publisherClass": "academic"
      }
     ]
    },
    "ai": {
     "score": 48,
     "summary": "SAHPRA's September 2025 communication MD08 sets AI device expectations, including local validation, human oversight and change control plans. SAHPRA has not started product registration of medical devices, so this is guidance, scored near the top of the 35 to 50 band.",
     "sources": [
      {
       "title": "SAHPRA Communication to Stakeholders MD08-2025/2026: Regulatory requirements of AI/ML-enabled medical devices",
       "url": "https://www.sahpra.org.za/wp-content/uploads/2025/09/MD08-20252026_-SAHPRA-Communication-to-Industry-AI-Medical-devices_Acknowledgements.pdf",
       "date": "2025-09-26",
       "publisherClass": "official"
      },
      {
       "title": "Cabinet approves withdrawal of AI policy (SAnews)",
       "url": "https://www.sanews.gov.za/south-africa/cabinet-approves-withdrawal-ai-policy",
       "date": "2026-06-05",
       "publisherClass": "official"
      },
      {
       "title": "Minister of Health reply to question NW3043 on AI and digital health (PMG)",
       "url": "https://pmg.org.za/committee-question/39322/",
       "date": "2026-07-09",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Protection of Personal Information Act 4 of 2013 (POPIA)",
     "level": "National",
     "year": "2013",
     "what": "Health is special personal information; access right; opt-in electronic marketing; breach notice; fines up to R10 million.",
     "url": "https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013protectionofpersonalinforcorrect.pdf"
    },
    {
     "name": "Promotion of Access to Information Act 2 of 2000 (PAIA)",
     "level": "National",
     "year": "2000",
     "what": "Access to records held by public and private bodies, 30-day deadline, special rules for health records.",
     "url": "https://www.justice.gov.za/legislation/acts/2000-002.pdf"
    },
    {
     "name": "National Health Act 61 of 2003",
     "level": "National",
     "year": "2003",
     "what": "Record keeping, confidentiality, written consent for disclosure, research authorisation, offences for record misuse.",
     "url": "https://www.gov.za/sites/default/files/gcis_document/201409/a61-03.pdf"
    },
    {
     "name": "National Health Insurance Act 20 of 2023",
     "level": "National",
     "year": "2023",
     "what": "National fund with user registration; written approval for disclosure. Proclamation of sections delayed pending court judgment.",
     "url": "https://www.gov.za/sites/default/files/gcis_document/202405/50664nathealthinsuranceact202023.pdf"
    },
    {
     "name": "Regulations relating to the Processing of Data Subjects' Health Information by Certain Responsible Parties, 2026",
     "level": "National",
     "year": "2026",
     "what": "Safeguards and transfer limits for insurers, schemes, administrators, pension funds and employers handling health data.",
     "url": "https://www.gov.za/sites/default/files/gcis_document/202603/54268gon7198.pdf"
    },
    {
     "name": "National 2021 Normative Standards Framework for Interoperability in Digital Health (Notice 2667)",
     "level": "National",
     "year": "2022",
     "what": "National interoperability standards for digital health systems, issued under the National Health Act.",
     "url": "https://www.gov.za/documents/notices/national-health-act-national-2021-normative-standards-framework-interoperability"
    }
   ],
   "dti": {
    "grade": 92,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-11-26",
     "headline": "Pathology lab fined after failing to tell patients their data was exposed",
     "paraphrase": "The regulator found the lab had suffered breaches and not notified affected people within a reasonable time. It ordered better security and notification processes, then fined the lab R100,000 for not complying. The lab paid.",
     "source": "Juta MedicalBrief (reporting an Information Regulator decision)",
     "url": "https://www.medicalbrief.co.za/lancet-labs-fined-for-data-breach/",
     "theme": "breach",
     "status": "finding"
    },
    {
     "date": "2025-07-22",
     "headline": "Provincial health department says lost and misplaced files have harmed patients' care",
     "paraphrase": "Launching a records digitisation drive, the provincial health MEC said patients' care had been interrupted by misplaced records, delayed care and lost files, compromising patient safety and exposing the department to legal claims.",
     "source": "SABC News",
     "url": "https://www.sabcnews.com/sabcnews/gauteng-based-public-hospitals-patients-records-going-digital/",
     "theme": "other",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "MEX",
   "name": "Mexico",
   "region": "Americas",
   "overall": 42,
   "rank": "59",
   "likelyRank": "54 to 60",
   "band": "Weak",
   "keysModel": "Institutional",
   "confidence": "high",
   "headline": "Mexican law gives patients a free copy of their data, but records stay inside each institution until cross-institution sharing, decreed in April 2026, begins.",
   "categories": {
    "access": {
     "score": 55,
     "summary": "Both data laws make access free with a 20-day answer deadline, and the IMSS app shows 36 months of visits, prescriptions and labs. Score: base 45, +5 free with a deadline, +5 official portal; only 493,144 of 54 million eligible had enrolled by October 2025.",
     "sources": [
      {
       "title": "Ley General de Proteccion de Datos Personales en Posesion de Sujetos Obligados (Camara de Diputados, texto vigente)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LGPDPPSO.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (Camara de Diputados, texto vigente)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "NOM-004-SSA3-2012, Del expediente clinico (DOF)",
       "url": "https://dof.gob.mx/nota_detalle.php?codigo=5272787&fecha=15/10/2012",
       "date": "2012-10-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "IMSS Boletin 542/2025: Cedula Digital de Salud",
       "url": "https://www.imss.gob.mx/sites/all/statics/i2f_news/IMSS.%20Boletin.%20542.pdf",
       "date": "2025-10-24",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 35,
     "summary": "Mexico's public-sector law lets providers use health data for care without consent, and the private-sector law lets them share it for treatment without consent. No opt-out or patient-visible log exists; scored at the band top because no cross-institution sharing is live.",
     "sources": [
      {
       "title": "Decreto por el que se crea el Servicio Universal de Salud (DOF, 17 abril 2026)",
       "url": "https://sidof.segob.gob.mx/notas/5785257",
       "date": "2026-04-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley General de Proteccion de Datos Personales en Posesion de Sujetos Obligados (Camara de Diputados, texto vigente)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LGPDPPSO.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (Camara de Diputados, texto vigente)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "NOM-024-SSA3-2012, Sistemas de informacion de registro electronico para la salud (DOF)",
       "url": "https://dof.gob.mx/nota_detalle.php?codigo=5280847&fecha=30/11/2012",
       "date": "2012-11-30",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 40,
     "summary": "Health data are sensitive under both 2025 laws, with breach notice and fines, but the independent INAI was abolished and oversight moved to a ministry. A leak of 20 million IMSS pensioner records with medical conditions surfaced in September 2025, Infobae reported.",
     "sources": [
      {
       "title": "Ley General de Proteccion de Datos Personales en Posesion de Sujetos Obligados (Camara de Diputados, texto vigente)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LGPDPPSO.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (Camara de Diputados, texto vigente)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Filtracion de 20 millones de datos de pensionados del IMSS (Infobae)",
       "url": "https://www.infobae.com/mexico/2025/10/08/filtracion-de-20-millones-de-datos-de-pensionados-del-imss-primer-gran-reto-de-la-nueva-unidad-de-proteccion-de-datos/",
       "date": "2025-10-08",
       "publisherClass": "news"
      },
      {
       "title": "Ciberataque a SAT, IMSS y Morena expone datos de 36 millones (El Universal via Yahoo)",
       "url": "https://es-us.finanzas.yahoo.com/noticias/ciberataque-sat-imss-morena-expone-201520425.html",
       "date": "2026-02-10",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 38,
     "summary": "IMSS keeps an electronic record for 54 million people, but each public institution runs its own system and no national exchange is live. The April 2026 decree orders a shared record; service sharing starts in January 2027, with labs and imaging from July 2027.",
     "sources": [
      {
       "title": "Decreto por el que se crea el Servicio Universal de Salud (DOF, 17 abril 2026)",
       "url": "https://sidof.segob.gob.mx/notas/5785257",
       "date": "2026-04-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley General de Salud, texto vigente con reforma de salud digital del 15 enero 2026 (Camara de Diputados)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LGS.pdf",
       "date": "2026-01-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "NOM-024-SSA3-2012, Sistemas de informacion de registro electronico para la salud (DOF)",
       "url": "https://dof.gob.mx/nota_detalle.php?codigo=5280847&fecha=30/11/2012",
       "date": "2012-11-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Salud e IMSS firman convenio para la interoperabilidad del expediente clinico electronico (ConsultorSalud)",
       "url": "https://consultorsalud.com.mx/expediente-clinico-electronico-salud-imss/",
       "date": "2026-08-10",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 45,
     "summary": "Private use of health data needs express written consent, and misuse of sensitive data for profit carries doubled prison terms. No health-specific ban on selling data or ad targeting was found.",
     "sources": [
      {
       "title": "Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (Camara de Diputados, texto vigente)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Primeros criterios publicos de la SABG tras el caso FAN ID (Ritch Mueller)",
       "url": "https://www.ritch.com.mx/prensa/alerta-para-clientes-primeros-criterios-publicos-de-la-sabg-en-materia-de-proteccion-de-datos-personales-tras-la-resolucion-del-caso-fan-id",
       "date": "2026-07-29",
       "publisherClass": "law_firm"
      }
     ]
    },
    "clinical": {
     "score": 35,
     "summary": "Today a doctor at one public institution cannot open a patient's record from another. The April 2026 decree already authorises staff of all public institutions to view history, diagnoses, labs, imaging and vaccines, but the exchange is not built; phases start in 2027.",
     "sources": [
      {
       "title": "Decreto por el que se crea el Servicio Universal de Salud (DOF, 17 abril 2026)",
       "url": "https://sidof.segob.gob.mx/notas/5785257",
       "date": "2026-04-17",
       "publisherClass": "legal_text"
      },
      {
       "title": "Salud e IMSS firman convenio para la interoperabilidad del expediente clinico electronico (ConsultorSalud)",
       "url": "https://consultorsalud.com.mx/expediente-clinico-electronico-salud-imss/",
       "date": "2026-08-10",
       "publisherClass": "news"
      },
      {
       "title": "El IMSS planea IA en su expediente clinico e interoperabilidad con ISSSTE e IMSS-Bienestar para 2027 (El Imparcial)",
       "url": "https://www.elimparcial.com/mexico/2026/06/04/el-imss-planea-aplicar-inteligencia-artificial-en-su-expediente-clinico-electronico-mientras-desarrolla-la-interoperabilidad-total-de-datos-de-salud-con-el-issste-e-imss-bienestar-para-inicios-de-2027/",
       "date": "2026-06-04",
       "publisherClass": "news"
      },
      {
       "title": "Ley General de Proteccion de Datos Personales en Posesion de Sujetos Obligados (Camara de Diputados, texto vigente)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LGPDPPSO.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Research on people needs written informed consent and ethics committee approval, and record review is classed as no-risk research, not consent-free. De-identified data can be used without consent, with no opt-out or public register.",
     "sources": [
      {
       "title": "Ley General de Salud, texto vigente con reforma de salud digital del 15 enero 2026 (Camara de Diputados)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LGS.pdf",
       "date": "2026-01-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Reglamento de la Ley General de Salud en Materia de Investigacion para la Salud (Camara de Diputados)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/regley/Reg_LGS_MIS.pdf",
       "date": "2014-04-02",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley General de Proteccion de Datos Personales en Posesion de Sujetos Obligados (Camara de Diputados, texto vigente)",
       "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LGPDPPSO.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "NOM-004-SSA3-2012, Del expediente clinico (DOF)",
       "url": "https://dof.gob.mx/nota_detalle.php?codigo=5272787&fecha=15/10/2012",
       "date": "2012-10-15",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 38,
     "summary": "COFEPRIS registers software as a medical device with lifecycle, clinical evidence and cybersecurity files, but its own guide says the General Health Law does not yet recognise such software. No AI-specific change control rule or AI law exists.",
     "sources": [
      {
       "title": "COFEPRIS: Guia para la obtencion del Registro Sanitario de Dispositivos Medicos",
       "url": "https://www.gob.mx/cofepris/documentos/guia-para-la-obtencion-del-registro-sanitario-de-dispositivos-medicos",
       "date": "2023-12-12",
       "publisherClass": "official"
      },
      {
       "title": "Mexico regula la inteligencia artificial por sectores mientras aplaza la ley general (El Economista)",
       "url": "https://www.eleconomista.com.mx/tecnologia/mexico-regula-inteligencia-artificial-sectores-aplaza-ley-general-20260723-824716.html",
       "date": "2026-07-23",
       "publisherClass": "news"
      },
      {
       "title": "El IMSS planea IA en su expediente clinico e interoperabilidad con ISSSTE e IMSS-Bienestar para 2027 (El Imparcial)",
       "url": "https://www.elimparcial.com/mexico/2026/06/04/el-imss-planea-aplicar-inteligencia-artificial-en-su-expediente-clinico-electronico-mientras-desarrolla-la-interoperabilidad-total-de-datos-de-salud-con-el-issste-e-imss-bienestar-para-inicios-de-2027/",
       "date": "2026-06-04",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Ley General de Proteccion de Datos Personales en Posesion de Sujetos Obligados",
     "level": "National",
     "year": "2025",
     "what": "Public bodies: health data sensitive, free access in 20 days, care exempt from consent; INAI replaced by a ministry.",
     "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LGPDPPSO.pdf"
    },
    {
     "name": "Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares",
     "level": "National",
     "year": "2025",
     "what": "Private sector: express written consent for health data, fines can double and prison for sensitive data misuse.",
     "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf"
    },
    {
     "name": "Ley General de Salud (reforma de salud digital)",
     "level": "National",
     "year": "2026",
     "what": "Adds digital health and telehealth chapter; research needs written informed consent; record interoperability rules.",
     "url": "https://www.diputados.gob.mx/LeyesBiblio/pdf/LGS.pdf"
    },
    {
     "name": "Decreto por el que se crea el Servicio Universal de Salud",
     "level": "National",
     "year": "2026",
     "what": "CURP-linked health credential and shared electronic record across public institutions, phased from January 2027.",
     "url": "https://sidof.segob.gob.mx/notas/5785257"
    },
    {
     "name": "NOM-004-SSA3-2012, Del expediente clinico",
     "level": "National",
     "year": "2012",
     "what": "Record content and five-year retention; institution owns the record, patient holds rights over the information.",
     "url": "https://dof.gob.mx/nota_detalle.php?codigo=5272787&fecha=15/10/2012"
    },
    {
     "name": "NOM-024-SSA3-2012, Sistemas de informacion de registro electronico para la salud",
     "level": "National",
     "year": "2012",
     "what": "Standards, audit records, export and consent controls for certified electronic health record systems.",
     "url": "https://dof.gob.mx/nota_detalle.php?codigo=5280847&fecha=30/11/2012"
    },
    {
     "name": "Ley de Proteccion de Datos Personales en Posesion de Sujetos Obligados de la Ciudad de Mexico",
     "level": "State/Provincial",
     "year": "2026",
     "what": "Mexico City public-body data law; health data sensitive; oversight under the city comptroller's office.",
     "url": "https://iecm.mx/www/marconormativo/docs/Ley_proteccion_DDPP_2026.pdf"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-01-27",
     "headline": "Public insurer answered late and incompletely when a patient asked for scans",
     "paraphrase": "A person asked a public health insurer for copies of their imaging studies and the reports on them. The insurer missed the legal deadline and only found the files after a complaint. The regulator ordered delivery free of charge.",
     "source": "Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI/013/2025)",
     "url": "https://home.inai.org.mx/wp-content/documentos/SalaDePrensa/Comunicados/Nota%20INAI-013-25.pdf",
     "theme": "access_delay_or_cost",
     "status": "finding"
    },
    {
     "date": "2024-10-03",
     "headline": "Asked for a late father's record, a person was given someone else's",
     "paraphrase": "A person paid a public insurer for certified copies of their deceased father's record but was handed a relative's record instead. After a complaint, the insurer found the father's file. The regulator ordered free certified copies.",
     "source": "Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI/142/2024)",
     "url": "https://home.inai.org.mx/wp-content/documentos/SalaDePrensa/Comunicados/Nota%20INAI-142-24.pdf",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2026-08-26",
     "headline": "Court says judges can act at once when a clinic withholds a patient's record",
     "paraphrase": "A federal appeals court ruled that when a person says a health institution is denying access to their clinical record, judges may grant immediate protection, treating record access as part of the right to health.",
     "source": "La Silla Rota",
     "url": "https://lasillarota.com/nacion/2026/8/26/el-hospital-o-doctor-te-niegan-acceso-a-tu-expediente-clinico-esto-dice-la-justicia-526020.html",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2025-07-03",
     "headline": "Records of a private hospital group's patients offered for sale online",
     "paraphrase": "A seller claimed to offer 400,000 lines of data from a private hospital group: patients' names, national ID and tax numbers, phones, emails, insurance policies, diagnoses and medical notes. The report carried no response from the hospital.",
     "source": "Publimetro México",
     "url": "https://www.publimetro.com.mx/noticias/2025/07/03/hacker-vende-400-mil-datos-sensibles-de-pacientes-del-hospital-espanol-de-mexico/",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2026-02-09",
     "headline": "Patient details from a public hospital in Jalisco reportedly sold after cyberattack",
     "paraphrase": "A report says a cyberattack exposed patients' names, addresses, phones, emails and diagnoses, later offered for sale. The hospital filed a criminal complaint; earlier it said only part of a website was hit and patient records were safe.",
     "source": "N+ (Nmas)",
     "url": "https://www.nmas.com.mx/seguridad/hackeo-hospital-civil-guadalajara-datos-medicos-expuestos-se-vendian-foros-clandestinos/",
     "theme": "breach",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "ALB",
   "name": "Albania",
   "region": "Europe",
   "overall": 41,
   "rank": "60",
   "likelyRank": "56 to 61",
   "band": "Weak",
   "keysModel": "Institutional",
   "confidence": "medium",
   "headline": "Albania has a new EU-aligned data protection law, but patients have no national record to view and hospitals were still going digital in 2026.",
   "categories": {
    "access": {
     "score": 50,
     "summary": "The 2024 data protection law gives a free right of access within 30 days, but no national portal shows the medical record. Only pieces are online, such as a child vaccination card on e-Albania, so the score sits at 50.",
     "sources": [
      {
       "title": "Ligji nr. 124/2024 Për mbrojtjen e të dhënave personale (IDP copy)",
       "url": "https://idp.al/wp-content/uploads/2025/07/ligj-2024-12-19-124.pdf",
       "date": "2024-12-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ligji nr. 10 107, datë 30.3.2009 Për kujdesin shëndetësor në Republikën e Shqipërisë (ISHP copy)",
       "url": "https://www.ishp.gov.al/wp-content/uploads/2015/ligjet/Per-kujdesin-shendetesor-ne-Republiken-e-Shqiperise.pdf",
       "date": "2009-03-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Kartela dhe rezervimi për bërjen e vaksinave për fëmijët 0-7 vjeç, online tek e-Albania (RTSH)",
       "url": "https://rtsh.al/kartela-dhe-rezervimi-per-berjen-e-vaksinave-per-femijet-0-7-vjec-online-tek-e-albania/",
       "date": "2024-06-11",
       "publisherClass": "news"
      },
      {
       "title": "Gjendja e sistemit spitalor, PD kërkon interpelancë urgjente me Ministren Sala (RTSH)",
       "url": "https://rtsh.al/gjendja-e-sistemit-spitalor-pd-kerkon-interpelance-urgjente-me-ministren-sala/",
       "date": "2026-06-15",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 30,
     "summary": "Health data is a special category, but the law lets providers process it for care without consent, and no opt-out or patient-visible access log was found. Records sit with institutions, and the ministry has a legal right of access.",
     "sources": [
      {
       "title": "Ligji nr. 124/2024 Për mbrojtjen e të dhënave personale (IDP copy)",
       "url": "https://idp.al/wp-content/uploads/2025/07/ligj-2024-12-19-124.pdf",
       "date": "2024-12-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ligji nr. 10 107, datë 30.3.2009 Për kujdesin shëndetësor në Republikën e Shqipërisë (ISHP copy)",
       "url": "https://www.ishp.gov.al/wp-content/uploads/2015/ligjet/Per-kujdesin-shendetesor-ne-Republiken-e-Shqiperise.pdf",
       "date": "2009-03-30",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 55,
     "summary": "No health-sector enforcement evidence was found, so this is scored on the general law. Law 124/2024 is fully aligned with EU rules per the European Commission, with 72-hour breach notice and fines up to ALL 2 billion or 4% of turnover.",
     "sources": [
      {
       "title": "Ligji nr. 124/2024 Për mbrojtjen e të dhënave personale (IDP copy)",
       "url": "https://idp.al/wp-content/uploads/2025/07/ligj-2024-12-19-124.pdf",
       "date": "2024-12-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Albania 2025 Report, SWD(2025) (European Commission)",
       "url": "https://enlargement.ec.europa.eu/document/download/fe9138b7-90fe-4277-a12c-3a03f6d1957f_en?filename=albania-report-2025.pdf",
       "date": "2025-11-04",
       "publisherClass": "intergov"
      },
      {
       "title": "900 ankesa për cenim të të dhënave personale, ligji i ri ka shtrënguar masat (RTSH)",
       "url": "https://rtsh.al/900-ankesa-per-cenim-te-te-dhenave-personale-ligji-i-ri-ka-shtrenguar-masat/",
       "date": "2026-06-28",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 34,
     "summary": "National systems exist for parts of the journey, including a health information system, a citizen register and e-prescriptions. The European Commission reports a system for collecting and reporting health data, but the government's plan for electronic public hospitals from August 2026 was not verified as done.",
     "sources": [
      {
       "title": "Albania 2025 Report, SWD(2025) (European Commission)",
       "url": "https://enlargement.ec.europa.eu/document/download/fe9138b7-90fe-4277-a12c-3a03f6d1957f_en?filename=albania-report-2025.pdf",
       "date": "2025-11-04",
       "publisherClass": "intergov"
      },
      {
       "title": "Nënshkrimi elektronik, një tjetër element dhe standard i rëndësishëm i Shëndetësisë Elektronike (FSDKSH)",
       "url": "https://fsdksh.gov.al/nenshkrimi-elektronik-nje-tjeter-element-dhe-standard-i-rendesishem-i-shendetesise-elektronike/",
       "date": "2019-01-08",
       "publisherClass": "official"
      },
      {
       "title": "Sala: Nis konsultimi publik për krijimin e Institutit Onkologjik Kombëtar. Nga 1 gushti, spitalet publike funksionojnë elektronikisht (RTSH)",
       "url": "https://rtsh.al/sala-nis-konsultimi-publik-per-krijimin-e-institutit-onkologjik-kombetar-nga-1-gushti-spitalet-publike-funksionojne-elektronikisht/",
       "date": "2026-06-15",
       "publisherClass": "news"
      },
      {
       "title": "Gjendja e sistemit spitalor, PD kërkon interpelancë urgjente me Ministren Sala (RTSH)",
       "url": "https://rtsh.al/gjendja-e-sistemit-spitalor-pd-kerkon-interpelance-urgjente-me-ministren-sala/",
       "date": "2026-06-15",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 50,
     "summary": "Using health data for direct marketing needs the person's explicit consent under Law 124/2024, and people can object at any time. No specific ban on selling health data or rule on health apps was found.",
     "sources": [
      {
       "title": "Ligji nr. 124/2024 Për mbrojtjen e të dhënave personale (IDP copy)",
       "url": "https://idp.al/wp-content/uploads/2025/07/ligj-2024-12-19-124.pdf",
       "date": "2024-12-19",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 30,
     "summary": "No shared record that lets a treating clinician see care from other providers was found. The health law leaves documentation with each institution or the patient, and opposition MPs said in June 2026 that hospitals still lack electronic records.",
     "sources": [
      {
       "title": "Ligji nr. 10 107, datë 30.3.2009 Për kujdesin shëndetësor në Republikën e Shqipërisë (ISHP copy)",
       "url": "https://www.ishp.gov.al/wp-content/uploads/2015/ligjet/Per-kujdesin-shendetesor-ne-Republiken-e-Shqiperise.pdf",
       "date": "2009-03-30",
       "publisherClass": "legal_text"
      },
      {
       "title": "Gjendja e sistemit spitalor, PD kërkon interpelancë urgjente me Ministren Sala (RTSH)",
       "url": "https://rtsh.al/gjendja-e-sistemit-spitalor-pd-kerkon-interpelance-urgjente-me-ministren-sala/",
       "date": "2026-06-15",
       "publisherClass": "news"
      },
      {
       "title": "Sala: Nis konsultimi publik për krijimin e Institutit Onkologjik Kombëtar. Nga 1 gushti, spitalet publike funksionojnë elektronikisht (RTSH)",
       "url": "https://rtsh.al/sala-nis-konsultimi-publik-per-krijimin-e-institutit-onkologjik-kombetar-nga-1-gushti-spitalet-publike-funksionojne-elektronikisht/",
       "date": "2026-06-15",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 43,
     "summary": "Law 124/2024 treats research use of health data as a legitimate interest without consent, with no general opt-out. One safeguard class counts: fines up to 4% of turnover for misuse, including using research data for decisions about the person.",
     "sources": [
      {
       "title": "Ligji nr. 124/2024 Për mbrojtjen e të dhënave personale (IDP copy)",
       "url": "https://idp.al/wp-content/uploads/2025/07/ligj-2024-12-19-124.pdf",
       "date": "2024-12-19",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 30,
     "summary": "No clinical AI rules or guidance were found, only a medical device law the European Commission calls partly aligned with EU rules. The Commission says Albania should fully align with the AI Act.",
     "sources": [
      {
       "title": "Albania 2025 Report, SWD(2025) (European Commission)",
       "url": "https://enlargement.ec.europa.eu/document/download/fe9138b7-90fe-4277-a12c-3a03f6d1957f_en?filename=albania-report-2025.pdf",
       "date": "2025-11-04",
       "publisherClass": "intergov"
      },
      {
       "title": "Projektligji i ri përcakton rregulla të rrepta për pajisjet mjekësore diagnostikuese in vitro (RTSH)",
       "url": "https://rtsh.al/projektligji-i-ri-percakton-rregulla-te-rrepta-per-pajisjet-mjekesore-diagnostikuese-in-vitro/",
       "date": "2026-07-20",
       "publisherClass": "news"
      },
      {
       "title": "Rama: 1 mld euro për Shëndetësinë... 2026, viti i AI në mjekësi (RTSH)",
       "url": "https://rtsh.al/rama-1-mld-euro-per-shendetesine-15-mln-euro-ekstra-per-pacientet-e-onkologjikut-2026-viti-i-ai-ne-mjekesi/",
       "date": "2025-11-08",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Law No. 124/2024 On personal data protection",
     "level": "National",
     "year": "2024",
     "what": "EU-aligned data protection law: health as sensitive data, access in 30 days, 72-hour breach notice, high fines.",
     "url": "https://idp.al/wp-content/uploads/2025/07/ligj-2024-12-19-124.pdf"
    },
    {
     "name": "Law No. 10107/2009 On health care in the Republic of Albania",
     "level": "National",
     "year": "2009",
     "what": "Organises health care; creates a single health information system; institutions keep records confidential.",
     "url": "https://www.ishp.gov.al/wp-content/uploads/2015/ligjet/Per-kujdesin-shendetesor-ne-Republiken-e-Shqiperise.pdf"
    },
    {
     "name": "Law No. 9288/2004 ratifying Council of Europe Convention 108",
     "level": "National",
     "year": "2004",
     "what": "Ratifies the Council of Europe convention on automatic processing of personal data.",
     "url": "https://idp.al/wp-content/uploads/2024/01/ligji_9288_koventa-1.pdf"
    },
    {
     "name": "Law No. 49/2022 ratifying the Protocol amending Convention 108",
     "level": "National",
     "year": "2022",
     "what": "Ratifies the protocol that modernises Convention 108.",
     "url": "https://idp.al/wp-content/uploads/2024/01/ligji-49-2022.pdf"
    }
   ],
   "dti": {
    "grade": 87,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-08-24",
     "headline": "Regulator steps in after clinic ignores a patient's request for their file",
     "paraphrase": "A patient asked a private clinic for all the records it held on them and got no reply. After a complaint, inspectors visited, the clinic produced the file and undertook to supply it, and the regulator ordered fixes.",
     "source": "Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale (IDP)",
     "url": "https://idp.al/wp-content/uploads/2026/09/Rekomandim-Nr.-55-Viti-2026-DPM.pdf",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2026-02-26",
     "headline": "Medical laboratory fined for weak safeguards on patient data",
     "paraphrase": "Months after a regulator recommendation, a medical laboratory still had no data protection terms with firms handling patient data for it and an incomplete security system. The regulator fined it ALL 2.8 million.",
     "source": "Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale (IDP)",
     "url": "https://idp.al/wp-content/uploads/2026/03/Vendim-Nr.-8-Viti-2026-DPM.pdf",
     "theme": "other",
     "status": "finding"
    },
    {
     "date": "2024-11-21",
     "headline": "Ransomware locks a public hospital's data and halts scans and lab tests",
     "paraphrase": "Ransomware encrypted all of a regional public hospital's data, stopping imaging and blood testing until services returned within 72 hours. The report says some patient data was deleted. The hospital confirmed the attack.",
     "source": "Faktoje.al",
     "url": "https://faktoje.al/terrorizmi-kibernetik-i-korese-se-veriut-ndaj-spitalit-memorial-te-fierit-dhe-rreziku-i-ekspozimit-te-spitaleve-publike-ndaj-ketyre-sulmeve/",
     "theme": "breach",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "CHL",
   "name": "Chile",
   "region": "Americas",
   "overall": 39,
   "rank": "61=",
   "likelyRank": "59 to 63",
   "band": "Weak",
   "keysModel": "Institutional",
   "confidence": "medium",
   "headline": "Chilean law gives patients a free, portable copy of their record, but records stay provider by provider and the new data law may slip.",
   "categories": {
    "access": {
     "score": 45,
     "summary": "Ley 20.584 Article 13 gives patients a free, complete copy of their record in a structured, portable format, but only on request to each provider. The national Portal Paciente shows vaccines, GES guarantees and waiting lists, not the clinical record.",
     "sources": [
      {
       "title": "Ley 20.584, derechos y deberes de los pacientes, texto vigente (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1039348",
       "date": "2012-04-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Decreto 41 de 2012, reglamento sobre fichas clinicas (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1046753",
       "date": "2012-12-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Portal Paciente, Ministerio de Salud",
       "url": "https://portalpaciente.minsal.cl/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Avances y desafios de la Receta Electronica del Minsal (Ehealth Reporter)",
       "url": "https://ehealthreporter.com/avances-y-desafios-de-la-receta-electronica-del-minsal/",
       "date": "2025-12-10",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 35,
     "summary": "The law bars staff not involved in care from the record and makes providers log who opens it, but patients have no opt-out, consent switch or visible log. Scored at the top of the lowest band because no national sharing system is live.",
     "sources": [
      {
       "title": "Ley 20.584, derechos y deberes de los pacientes, texto vigente (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1039348",
       "date": "2012-04-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 21.668, interoperabilidad de las fichas clinicas (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1203827",
       "date": "2024-05-28",
       "publisherClass": "legal_text"
      },
      {
       "title": "Decreto 41 de 2012, reglamento sobre fichas clinicas (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1046753",
       "date": "2012-12-15",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 19.628, proteccion de la vida privada, texto vigente (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=141599",
       "date": "1999-08-28",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 40,
     "summary": "Health data are sensitive in law, but Chile still runs on its 1999 data law with no regulator, and a September 2026 bill would delay the new law to December 2027. Two major hospital breaches hit in the past year.",
     "sources": [
      {
       "title": "Ley 19.628, proteccion de la vida privada, texto vigente (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=141599",
       "date": "1999-08-28",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 19.628, version que rige desde el 1 de diciembre de 2026 (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=141599&idVersion=2026-12-01",
       "date": "2024-12-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "Prorroga de la Ley de Datos abre un ano clave para que empresas preparen su cumplimiento (Publimetro)",
       "url": "https://www.publimetro.cl/tecnologia/2026/09/15/prorroga-de-la-ley-de-datos-abre-un-ano-clave-para-que-empresas-preparen-su-cumplimiento/",
       "date": "2026-09-15",
       "publisherClass": "news"
      },
      {
       "title": "SERNAC oficia a Clinica Davila tras incidente de ciberseguridad",
       "url": "https://www.sernac.cl/portal/604/w3-article-87923.html",
       "date": "2025-12-24",
       "publisherClass": "official"
      }
     ]
    },
    "journey": {
     "score": 38,
     "summary": "Ley 21.668 requires providers to make records interoperable, but the implementing regulation is not in force: Decreto 41 on BCN is unchanged since 2012. MINSAL calls a shared national record a goal for 2030; e-prescriptions reached about 2 million patients by September 2025.",
     "sources": [
      {
       "title": "Ley 21.668, interoperabilidad de las fichas clinicas (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1203827",
       "date": "2024-05-28",
       "publisherClass": "legal_text"
      },
      {
       "title": "Un portal ciudadano e historia clinica compartida: los siete proyectos de la ministra Chomali (The Clinic)",
       "url": "https://www.theclinic.cl/2026/09/02/un-portal-ciudadano-e-historia-clinica-compartida-los-siete-proyectos-con-los-que-la-ministra-chomali-busca-modernizar-el-sistema-de-salud-publico/",
       "date": "2026-09-02",
       "publisherClass": "news"
      },
      {
       "title": "Avances y desafios de la Receta Electronica del Minsal (Ehealth Reporter)",
       "url": "https://ehealthreporter.com/avances-y-desafios-de-la-receta-electronica-del-minsal/",
       "date": "2025-12-10",
       "publisherClass": "news"
      },
      {
       "title": "Los cambios digitales que prepara el Minsal para la atencion primaria (Meganoticias)",
       "url": "https://www.meganoticias.cl/nacional/532436-filas-consultorio-5-de-la-manana-cambios-digitales-minsal-atencion-primaria.html",
       "date": "2026-09-24",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 42,
     "summary": "Current law allows sensitive data to be processed only with consent, a legal basis or for health benefits, and blocks commercial use on request. The stronger ban on health data gathered by insurers, employers and others waits for Ley 21.719.",
     "sources": [
      {
       "title": "Ley 19.628, proteccion de la vida privada, texto vigente (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=141599",
       "date": "1999-08-28",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 20.584, derechos y deberes de los pacientes, texto vigente (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1039348",
       "date": "2012-04-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 21.719, proteccion y tratamiento de datos personales (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1209272",
       "date": "2024-12-13",
       "publisherClass": "legal_text"
      },
      {
       "title": "SERNAC oficia a Clinica Davila tras incidente de ciberseguridad",
       "url": "https://www.sernac.cl/portal/604/w3-article-87923.html",
       "date": "2025-12-24",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 35,
     "summary": "Ley 21.668 gives treating professionals a legal right to the data essential for continuity of care, but no national exchange delivers it yet. Clinicians mostly see only their own provider's record.",
     "sources": [
      {
       "title": "Ley 20.584, derechos y deberes de los pacientes, texto vigente (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1039348",
       "date": "2012-04-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 21.668, interoperabilidad de las fichas clinicas (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1203827",
       "date": "2024-05-28",
       "publisherClass": "legal_text"
      },
      {
       "title": "Minsal fija hoja de ruta 2026-2030 con foco en acceso y digitalizacion (El Periodista)",
       "url": "https://www.elperiodista.cl/2026/07/minsal-fija-hoja-de-ruta-2026-2030-con-foco-en-acceso-digitalizacion-y-fortalecimiento-de-red-publica/",
       "date": "2026-07-29",
       "publisherClass": "news"
      },
      {
       "title": "Los cambios digitales que prepara el Minsal para la atencion primaria (Meganoticias)",
       "url": "https://www.meganoticias.cl/nacional/532436-filas-consultorio-5-de-la-manana-cambios-digitales-minsal-atencion-primaria.html",
       "date": "2026-09-24",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Research on people needs prior, written, informed consent and approval by an accredited ethics committee under Ley 20.120. Ley 21.719 will allow public-interest research on health data without consent, and record-based research rules today were not verified.",
     "sources": [
      {
       "title": "Ley 20.120, investigacion cientifica en el ser humano (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=253478",
       "date": "2006-09-22",
       "publisherClass": "legal_text"
      },
      {
       "title": "Decreto 114 de 2011, reglamento de la Ley 20.120 (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1032919",
       "date": "2011-11-19",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 20.584, derechos y deberes de los pacientes, texto vigente (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1039348",
       "date": "2012-04-24",
       "publisherClass": "legal_text"
      },
      {
       "title": "Ley 21.719, proteccion y tratamiento de datos personales (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1209272",
       "date": "2024-12-13",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 30,
     "summary": "Chile has no rules specific to clinical AI. A March 2026 decree brings oncology imaging software under device registration, with re-registration for major changes and a phase-in of up to 36 months, while the AI bill is still in the Senate.",
     "sources": [
      {
       "title": "ISP informa sobre nueva normativa que regula 39 dispositivos medicos (Instituto de Salud Publica)",
       "url": "https://www.ispch.gob.cl/noticia/isp-informa-sobre-nueva-normativa-que-regula-39-dispositivos-medicos-incluidos-dispositivos-medicos-de-diagnostico-in-vitro/",
       "date": "2026-03-20",
       "publisherClass": "official"
      },
      {
       "title": "MINSAL incorpora nuevos dispositivos medicos al regimen de control sanitario (Carey)",
       "url": "https://www.carey.cl/minsal-incorpora-nuevos-dispositivos-medicos-al-regimen-de-control-sanitario",
       "date": "2026-03-20",
       "publisherClass": "law_firm"
      },
      {
       "title": "Inteligencia Artificial: especialistas debaten sobre nueva legislacion (Senado de Chile)",
       "url": "https://www.senado.cl/comunicaciones/noticias/inteligencia-artificial-especialistas-de-la-industria-la-academia-y-sector",
       "date": "2026-04-24",
       "publisherClass": "official"
      },
      {
       "title": "Ley 21.719, proteccion y tratamiento de datos personales (BCN Ley Chile)",
       "url": "https://www.bcn.cl/leychile/navegar?idNorma=1209272",
       "date": "2024-12-13",
       "publisherClass": "legal_text"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Ley 20.584 (derechos y deberes de los pacientes)",
     "level": "National",
     "year": "2012",
     "what": "Confidential record kept 15 years; free, structured, portable copy for the patient on request.",
     "url": "https://www.bcn.cl/leychile/navegar?idNorma=1039348"
    },
    {
     "name": "Ley 21.668 (interoperabilidad de las fichas clinicas)",
     "level": "National",
     "year": "2024",
     "what": "Makes providers responsible for record interoperability; treating professionals get essential data for continuity.",
     "url": "https://www.bcn.cl/leychile/navegar?idNorma=1203827"
    },
    {
     "name": "Ley 19.628 (proteccion de la vida privada)",
     "level": "National",
     "year": "1999",
     "what": "Current data law; sensitive data need consent or a legal basis; enforced through the courts.",
     "url": "https://www.bcn.cl/leychile/navegar?idNorma=141599"
    },
    {
     "name": "Ley 21.719 (proteccion de datos personales)",
     "level": "National",
     "year": "2024",
     "what": "New data law, agency, breach reporting, fines to 20,000 UTM; due 1 December 2026, delay proposed.",
     "url": "https://www.bcn.cl/leychile/navegar?idNorma=1209272"
    },
    {
     "name": "Decreto 41 de 2012 (reglamento sobre fichas clinicas)",
     "level": "National",
     "year": "2012",
     "what": "Record content and storage rules; providers must log who accessed each record.",
     "url": "https://www.bcn.cl/leychile/navegar?idNorma=1046753"
    },
    {
     "name": "Ley 20.120 (investigacion cientifica en el ser humano)",
     "level": "National",
     "year": "2006",
     "what": "Written informed consent and ethics committee approval for research on people.",
     "url": "https://www.bcn.cl/leychile/navegar?idNorma=253478"
    }
   ],
   "dti": {
    "grade": 90,
    "tier": "Platinum",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-04-23",
     "headline": "Court orders clinic to give a deceased patient's record to his children",
     "paraphrase": "A clinic refused to give a deceased patient's record to some of his children, saying all heirs had to ask together. The appeals court called the refusal illegal and arbitrary and ordered a full copy delivered within three working days.",
     "source": "Poder Judicial de Chile, Corte de Apelaciones de Santiago (rol 24.909-2025)",
     "url": "https://www.pjud.cl/prensa-y-comunicaciones/noticias-del-poder-judicial/144388",
     "theme": "access_refused",
     "status": "finding"
    },
    {
     "date": "2026-05-07",
     "headline": "Lookup website showed patients' diagnoses to anyone who typed in their ID number",
     "paraphrase": "For about 48 hours, a people-search website let anyone enter a Chilean ID number and see that person's diagnoses under the national guaranteed-care scheme, alongside address and contact details. Police and the cybersecurity agency are investigating.",
     "source": "BioBioChile (BBCL Investiga)",
     "url": "https://www.biobiochile.cl/especial/bbcl-investiga/noticias/articulos/2026/05/07/desentranando-rutify-la-plataforma-hacker-que-expuso-datos-medicos-y-hoy-es-investigada-por-la-pdi.shtml",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2025-12-24",
     "headline": "Consumer agency demands answers after 250 GB of patient records stolen from private clinic",
     "paraphrase": "A ransomware group reportedly took about 250 GB from a private clinic, including clinical records, test results and identity card copies. Chile's consumer agency ordered the clinic to report how many patients were affected and how they were told.",
     "source": "BioBioChile",
     "url": "https://www.biobiochile.cl/noticias/economia/negocios-y-empresas/2025/12/24/fichas-clinicas-y-hasta-resultados-de-vih-sernac-oficia-a-clinica-davila-tras-robo-con-ciberataque.shtml",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2025-08-19",
     "headline": "Cyberattack on national public health lab doubled waits for patients' confirmatory test results",
     "paraphrase": "After a cyberattack slowed the national public health institute's systems, confirmatory results for patients in at least seven hospitals took about 30 days instead of 12 to 15. The institute blamed a switch to a manual system.",
     "source": "CIPER Chile",
     "url": "https://www.ciperchile.cl/2025/08/19/hospitales-fueron-afectados-por-retrasos-en-entrega-de-resultados-vih-y-hepatitis-tras-el-ciberataque-al-instituto-de-salud-publica/",
     "theme": "access_delay_or_cost",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "PHL",
   "name": "Philippines",
   "region": "Asia",
   "overall": 39,
   "rank": "61=",
   "likelyRank": "59 to 63",
   "band": "Weak",
   "keysModel": "Institutional",
   "confidence": "medium",
   "headline": "Filipino patients have strong privacy rights on paper, but records stay hospital by hospital and a shared exchange is still a pilot.",
   "categories": {
    "access": {
     "score": 40,
     "summary": "The Data Privacy Act gives a right of access and a structured electronic copy, but no fixed deadline is in force and one city hospital's rules release only parts of the record. Base 45, +5 structured copy, -5 no fixed deadline, -5 limited scope = 40.",
     "sources": [
      {
       "title": "Republic Act No. 10173, Data Privacy Act of 2012 (Lawphil)",
       "url": "https://lawphil.net/statutes/repacts/ra2012/ra_10173_2012.html",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "NPC Draft Circular on Data Subject Rights (for public consultation)",
       "url": "https://privacy.gov.ph/wp-content/uploads/2026/09/For-Publication-DPCJ-18Sep2026-Draft-Circular-Data-Subjects-Rights.pdf",
       "date": "2026-09-18",
       "publisherClass": "official"
      },
      {
       "title": "Patients Rights and Safety: The right to the medical record (J.R. Borja General Hospital, Cagayan de Oro)",
       "url": "https://jrbgh.cagayandeoro.gov.ph/index.php/patients-visitors/patients-safety",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Patient's Rights (Adela Serra Ty Memorial Medical Center, DOH)",
       "url": "https://astmmc.doh.gov.ph/patients-rights/",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 40,
     "summary": "By law a patient can ask any provider who received their data and when it was last accessed (RA 10173 Section 16(c)), but only on request; practice was not verified. UHC Act Section 31 makes every provider send health data to PhilHealth, with no consent step.",
     "sources": [
      {
       "title": "Republic Act No. 10173, Data Privacy Act of 2012 (Lawphil)",
       "url": "https://lawphil.net/statutes/repacts/ra2012/ra_10173_2012.html",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "DOH Administrative Order No. 2020-0030: Data Privacy Guidelines on the Processing of Health Information (UP Law copy)",
       "url": "https://law.upd.edu.ph/wp-content/uploads/2020/07/DOH-AO-No-2020-0030.pdf",
       "date": "2020-07-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Republic Act No. 11223, Universal Health Care Act (Lawphil)",
       "url": "https://lawphil.net/statutes/repacts/ra2019/ra_11223_2019.html",
       "date": "2019",
       "publisherClass": "legal_text"
      }
     ]
    },
    "privacy": {
     "score": 45,
     "summary": "The law is strict, with an independent regulator, 72-hour breach notice and up to 6 years in prison for misusing health data. But the 2023 PhilHealth breach exposed records of 42 million people, and in September 2026 a GenSan hospital reportedly admitted a ransomware breach (not verified).",
     "sources": [
      {
       "title": "Republic Act No. 10173, Data Privacy Act of 2012 (Lawphil)",
       "url": "https://lawphil.net/statutes/repacts/ra2012/ra_10173_2012.html",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "Breach Reporting (National Privacy Commission)",
       "url": "https://privacy.gov.ph/pips-and-pics/breach-reporting/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "2023 PhilHealth data breach affected 42M individuals, NPC (GMA News)",
       "url": "https://www.gmanetwork.com/news/topstories/nation/912661/2023-philhealth-data-breach-affected-42m-individuals-official/story/",
       "date": "2024-07-08",
       "publisherClass": "news"
      },
      {
       "title": "GenSan hospital admits 'data breach' after ransomware group's claims (MindaNews)",
       "url": "https://mindanews.com/top-stories/2026/09/gensan-hospital-admits-data-breach-after-ransomware-groups-claims/",
       "date": "2026-09-25",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 32,
     "summary": "Claims and primary care data flow to PhilHealth: eClaims 3.0 became mandatory on 1 July 2026 and YAKAP clinics must use certified EMRs. A provider-to-provider exchange exists only as a pilot, with a first eReferral prototype due in January 2027.",
     "sources": [
      {
       "title": "Republic Act No. 11223, Universal Health Care Act (Lawphil)",
       "url": "https://lawphil.net/statutes/repacts/ra2019/ra_11223_2019.html",
       "date": "2019",
       "publisherClass": "legal_text"
      },
      {
       "title": "PhilHealth Advisory No. 2026-0040: Final deadline to migrate to eClaims 3.0",
       "url": "https://www.philhealth.gov.ph/advisories/2026/PA2026-0040.pdf",
       "date": "2026-07-01",
       "publisherClass": "official"
      },
      {
       "title": "PhilHealth Advisory No. 2026-0038: YAKAP digitalization requirements",
       "url": "https://www.philhealth.gov.ph/advisories/2026/PA2026-0038.pdf",
       "date": "2026-06-30",
       "publisherClass": "official"
      },
      {
       "title": "Philippine EMR systems achieve live health data exchange at June 2026 FHIR Connectathon in Aklan (UP Manila)",
       "url": "https://www.upm.edu.ph/cpt_news/philippine-emr-systems-achieve-live-health-data-exchange-at-june-2026-fhir-connectathon-in-aklan/",
       "date": "2026-07-03",
       "publisherClass": "academic"
      }
     ]
    },
    "commercial": {
     "score": 45,
     "summary": "Health data cannot be processed on legitimate interest, so marketing with it needs specific consent, and disclosing it without consent carries 3 to 5 years in prison. There is no rule on de-identified data sales or data brokers.",
     "sources": [
      {
       "title": "Republic Act No. 10173, Data Privacy Act of 2012 (Lawphil)",
       "url": "https://lawphil.net/statutes/repacts/ra2012/ra_10173_2012.html",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "NPC Circular No. 2023-04: Guidelines on Consent",
       "url": "https://privacy.gov.ph/wp-content/uploads/2023/11/NPC-Circular-No.-2023-04_Guidelines-on-Consent_07Nov2023.pdf",
       "date": "2023-11-07",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 27,
     "summary": "A treating doctor can use records without separate consent, but only those held in their own facility. No cross-provider clinical view was verified, and the first eReferral prototype starts in one Aklan town in January 2027.",
     "sources": [
      {
       "title": "Republic Act No. 10173, Data Privacy Act of 2012 (Lawphil)",
       "url": "https://lawphil.net/statutes/repacts/ra2012/ra_10173_2012.html",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "DOH Administrative Order No. 2020-0030: Data Privacy Guidelines on the Processing of Health Information (UP Law copy)",
       "url": "https://law.upd.edu.ph/wp-content/uploads/2020/07/DOH-AO-No-2020-0030.pdf",
       "date": "2020-07-09",
       "publisherClass": "legal_text"
      },
      {
       "title": "Philippine EMR systems achieve live health data exchange at June 2026 FHIR Connectathon in Aklan (UP Manila)",
       "url": "https://www.upm.edu.ph/cpt_news/philippine-emr-systems-achieve-live-health-data-exchange-at-june-2026-fhir-connectathon-in-aklan/",
       "date": "2026-07-03",
       "publisherClass": "academic"
      }
     ]
    },
    "research": {
     "score": 46,
     "summary": "Research data falls largely outside the Data Privacy Act with no opt-out, though it must be held under strict confidentiality and a statutory ethics board oversees 114 accredited ethics committees. Base 40, +3 ethics body, +3 statutory confidentiality = 46.",
     "sources": [
      {
       "title": "Republic Act No. 10173, Data Privacy Act of 2012 (Lawphil)",
       "url": "https://lawphil.net/statutes/repacts/ra2012/ra_10173_2012.html",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "Republic Act No. 10532, Philippine National Health Research System Act of 2013 (Supreme Court E-Library)",
       "url": "https://elibrary.judiciary.gov.ph/thebookshelf/showdocs/2/55630",
       "date": "2013-05-07",
       "publisherClass": "legal_text"
      },
      {
       "title": "PHREB Accredited RECs (Philippine Health Research Ethics Board)",
       "url": "https://ethics-accreditation.healthresearch.ph/accredited-rec/0/0",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Republic Act No. 11223, Universal Health Care Act (Lawphil)",
       "url": "https://lawphil.net/statutes/repacts/ra2019/ra_11223_2019.html",
       "date": "2019",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 42,
     "summary": "Medical software falls under the FDA's 2018 device rules, but the rules written for AI software are still a draft, revised for consultation in August 2026. The privacy regulator's 2024 AI advisory requires human intervention in automated decisions.",
     "sources": [
      {
       "title": "Draft for Comments: Guidelines on the Regulation of Medical Device Software (FDA Philippines)",
       "url": "https://www.fda.gov.ph/draft-for-comments-guidelines-on-the-regulation-of-medical-device-software-mdsw-by-the-food-and-drug-administration-fda/",
       "date": "2025-05-21",
       "publisherClass": "official"
      },
      {
       "title": "Philippines new medical device software regulation draft (Asia Actual, updated after the August 2026 consultation)",
       "url": "https://asiaactual.com/blog/philippines-medical-device-software-regulation/",
       "date": "2025-05-23",
       "publisherClass": "blog_vendor"
      },
      {
       "title": "NPC Advisory No. 2024-04: Guidelines on the application of the DPA to artificial intelligence systems processing personal data",
       "url": "https://privacy.gov.ph/wp-content/uploads/2025/02/Advisory-2024.12.19-Guidelines-on-Artificial-Intelligence-w-SGD.pdf",
       "date": "2024-12-19",
       "publisherClass": "official"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Data Privacy Act of 2012 (RA 10173)",
     "level": "National",
     "year": "2012",
     "what": "Health is sensitive data; access and portability rights; independent NPC; prison terms for misuse.",
     "url": "https://lawphil.net/statutes/repacts/ra2012/ra_10173_2012.html"
    },
    {
     "name": "Universal Health Care Act (RA 11223)",
     "level": "National",
     "year": "2019",
     "what": "Mandates EHRs and e-prescription logs; all health entities must submit data to PhilHealth.",
     "url": "https://lawphil.net/statutes/repacts/ra2019/ra_11223_2019.html"
    },
    {
     "name": "E-Governance Act (RA 12254)",
     "level": "National",
     "year": "2025",
     "what": "Orders a national, interoperable Philippine Digital Health System as part of government digitization.",
     "url": "https://lawphil.net/statutes/repacts/ra2025/ra_12254_2025.html"
    },
    {
     "name": "Philippine National Health Research System Act (RA 10532)",
     "level": "National",
     "year": "2013",
     "what": "Gives the health research ethics board power over ethics guidelines and committees.",
     "url": "https://elibrary.judiciary.gov.ph/thebookshelf/showdocs/2/55630"
    },
    {
     "name": "DOH Administrative Order 2020-0030",
     "level": "National",
     "year": "2020",
     "what": "Health data privacy rules: admission consent form, provider-only access, outbreak access for DOH.",
     "url": "https://law.upd.edu.ph/wp-content/uploads/2020/07/DOH-AO-No-2020-0030.pdf"
    },
    {
     "name": "NPC Circular 2023-04 on Consent",
     "level": "National",
     "year": "2023",
     "what": "Unbundled, withdrawable consent; consent needed for high-impact direct marketing.",
     "url": "https://privacy.gov.ph/wp-content/uploads/2023/11/NPC-Circular-No.-2023-04_Guidelines-on-Consent_07Nov2023.pdf"
    }
   ],
   "dti": {
    "grade": 85,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-09-12",
     "headline": "Ransomware group claims it stole millions of files from a private hospital",
     "paraphrase": "A ransomware group said it took about 2.44 terabytes of hospital data, including patient records and scans, and demanded payment. The hospital in Mindanao said its first checks found no sign of a breach and it was still investigating.",
     "source": "The Mindanao Sentinel",
     "url": "https://themindanaosentinel.com/2026/09/rhysida-claims-2-44-tb-data-theft-from-general-santos-doctors-hospital-gsdh-says-no-breach-confirmed/",
     "theme": "breach",
     "status": "alleged"
    },
    {
     "date": "2025-12-09",
     "headline": "Insurer finds about 1,000 paid claims for patients who were never treated",
     "paraphrase": "The national health insurer said it was investigating about 1,000 suspected ghost patient claims in the Cordillera region, where members were recorded as treated when they were not. Members spotted them after receiving text alerts.",
     "source": "Philstar.com",
     "url": "https://www.philstar.com/nation/2025/12/09/2492899/philhealth-probes-ghost-patients-car",
     "theme": "record_wrong",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "GHA",
   "name": "Ghana",
   "region": "Africa",
   "overall": 38,
   "rank": "63",
   "likelyRank": "60 to 63",
   "band": "Weak",
   "keysModel": "State",
   "confidence": "high",
   "headline": "Ghana's data law gives patients a 40-day right of access, but records sit in a state-owned hospital system rebuilt after a 2025 vendor shutdown.",
   "categories": {
    "access": {
     "score": 40,
     "summary": "Act 843 lets you ask any provider for your data, with a reply due within 40 days, but the request can carry a prescribed fee. There is no national patient portal: the official MyNHIS app covers insurance membership, not records.",
     "sources": [
      {
       "title": "Data Protection Act, 2012 (Act 843), full text (WHO Compendium of Public Health Legislation copy)",
       "url": "https://extranet.who.int/cpcd/sites/default/files/public_file_repository/GHA_Ghana_Data-Protection-Act_2012.pdf",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "MyNHIS app listing, National Health Insurance Authority (Google Play)",
       "url": "https://play.google.com/store/apps/details?id=gh.gov.nhis.android.nma&hl=en",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Patients' access to medical records: is it a privilege or a right? (Advances in Applied Sociology)",
       "url": "https://file.scirp.org/Html/1-2290290_61714.htm",
       "date": "2015-12",
       "publisherClass": "academic"
      }
     ]
    },
    "control": {
     "score": 30,
     "summary": "On paper the Act lets you object to processing and learn who has had access, but health processing by clinicians is presumed necessary and no opt-out or patient access log works in practice (not verified). Hospital records now sit in a state-owned system by design.",
     "sources": [
      {
       "title": "Data Protection Act, 2012 (Act 843), full text (WHO Compendium of Public Health Legislation copy)",
       "url": "https://extranet.who.int/cpcd/sites/default/files/public_file_repository/GHA_Ghana_Data-Protection-Act_2012.pdf",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "The GHS Patients Charter (Ghana Health Service, posted by Nandom Municipal Health Directorate)",
       "url": "https://www.nandomdistrict.gov.gh/wp-content/uploads/2026/07/Ghana-Health-Service-Patients-Charter_Nandom-MHD.pdf",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "GHIMS gives state ownership of Ghanaian medical records, Health Minister (Information Services Department)",
       "url": "https://www.isd.gov.gh/ghims-gives-state-ownership-of-ghanaian-medical-records-health-minister/",
       "date": "2025-10-29",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 45,
     "summary": "Health is special personal data under Act 843, breaches must be reported, and selling personal data carries up to five years in prison. But the Commission runs from one office, declared 2026 a year of enforcement, and reports complaints about improper disclosure of health records.",
     "sources": [
      {
       "title": "Data Protection Act, 2012 (Act 843), full text (WHO Compendium of Public Health Legislation copy)",
       "url": "https://extranet.who.int/cpcd/sites/default/files/public_file_repository/GHA_Ghana_Data-Protection-Act_2012.pdf",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "2026 will be a year of enforcement, Data Protection Commission warns (Ghana News Agency)",
       "url": "https://gna.org.gh/2026/01/2026-will-be-a-year-of-enforcement-data-protection-commission-warns/",
       "date": "2026-01-31",
       "publisherClass": "news"
      },
      {
       "title": "Data Protection Commission steps up enforcement with new vehicles (Graphic Online)",
       "url": "https://www.graphic.com.gh/news/general-news/data-protection-commission-steps-up-enforcement-with-new-vehicles.html",
       "date": "2026-08-22",
       "publisherClass": "news"
      },
      {
       "title": "Adequacy decisions (European Commission)",
       "url": "https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en",
       "date": "undated",
       "publisherClass": "intergov"
      }
     ]
    },
    "journey": {
     "score": 35,
     "summary": "Insurance claims are almost fully electronic (99.96 percent by end of 2024), but hospital records were split when the LHIMS system went down in 2025. Its state-owned replacement, GHIMS, began at teaching hospitals in November 2025; its current reach is not verified.",
     "sources": [
      {
       "title": "GHIMS gives state ownership of Ghanaian medical records, Health Minister (Information Services Department)",
       "url": "https://www.isd.gov.gh/ghims-gives-state-ownership-of-ghanaian-medical-records-health-minister/",
       "date": "2025-10-29",
       "publisherClass": "official"
      },
      {
       "title": "GHIMS rollout begins at Tamale Teaching Hospital (Tamale Teaching Hospital)",
       "url": "https://www.tth.gov.gh/blog/ghims-rollout-begins-at-tamale-teaching-hospital",
       "date": "2025-11-08",
       "publisherClass": "official"
      },
      {
       "title": "NHIA's electronic claims system enhances efficiency in healthcare reimbursement (National Health Insurance Authority)",
       "url": "https://www.nhis.gov.gh/News/nhia%E2%80%99s-electronic-claims-system-enhances-efficiency-in-healthcare-reimbursement-5656",
       "date": "2025-02-28",
       "publisherClass": "official"
      },
      {
       "title": "Beyond a single system: lessons from Ghana's discontinued national EHR (Ghana Medical Journal, PMC)",
       "url": "https://pmc.ncbi.nlm.nih.gov/articles/PMC12877703/",
       "date": "2025-12",
       "publisherClass": "academic"
      }
     ]
    },
    "commercial": {
     "score": 48,
     "summary": "Act 843 requires prior written consent for direct marketing and makes buying or selling personal data a crime, which the regulator restated in 2026. We found no health-specific rules for apps, brokers or de-identified data, and no published health enforcement case.",
     "sources": [
      {
       "title": "Data Protection Act, 2012 (Act 843), full text (WHO Compendium of Public Health Legislation copy)",
       "url": "https://extranet.who.int/cpcd/sites/default/files/public_file_repository/GHA_Ghana_Data-Protection-Act_2012.pdf",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "2026 will be a year of enforcement, Data Protection Commission warns (Ghana News Agency)",
       "url": "https://gna.org.gh/2026/01/2026-will-be-a-year-of-enforcement-data-protection-commission-warns/",
       "date": "2026-01-31",
       "publisherClass": "news"
      },
      {
       "title": "Electronic Pharmacy Policy (Pharmacy Council, Ghana)",
       "url": "https://pcghana.org/newwebsite/wp-content/uploads/2024/08/EPHARMACY-POLICY.pdf",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "clinical": {
     "score": 28,
     "summary": "A clinician sees what is in their own facility system, and since 2025 that system may be the new state-owned GHIMS. Cross-facility viewing through the national exchange is planned but its use at the bedside is not verified.",
     "sources": [
      {
       "title": "GHIMS gives state ownership of Ghanaian medical records, Health Minister (Information Services Department)",
       "url": "https://www.isd.gov.gh/ghims-gives-state-ownership-of-ghanaian-medical-records-health-minister/",
       "date": "2025-10-29",
       "publisherClass": "official"
      },
      {
       "title": "Ghana Health Service and JICA launch National Teleconsultation Center project (Ghana Health Service)",
       "url": "https://ghs.gov.gh/news-and-events/ghana-health-service-and-jica-launch-national-teleconsultation-center-project-to-drive-universal-health-coverage",
       "date": "2026-07-24",
       "publisherClass": "official"
      },
      {
       "title": "We don't own patient data; it belongs to the MOH, LHIMS Project Manager (MyJoyOnline)",
       "url": "https://www.myjoyonline.com/we-dont-own-patient-data-it-belongs-to-the-moh-lhims-project-manager/",
       "date": "2025-10-27",
       "publisherClass": "news"
      },
      {
       "title": "Beyond a single system: lessons from Ghana's discontinued national EHR (Ghana Medical Journal, PMC)",
       "url": "https://pmc.ncbi.nlm.nih.gov/articles/PMC12877703/",
       "date": "2025-12",
       "publisherClass": "academic"
      }
     ]
    },
    "research": {
     "score": 49,
     "summary": "Trials need FDA approval, ethics clearance, PACTR registration and written informed consent under the Public Health Act. Record reuse for research falls under a broad Act 843 exemption with no consent or opt-out; three safeguard classes (ethics body, public trial register, Act 843 misuse offences) give 49.",
     "sources": [
      {
       "title": "Public Health Act, 2012 (Act 851), full text (Ministry of Health)",
       "url": "https://www.moh.gov.gh/wp-content/uploads/2016/02/Public-Health-Act-851.pdf",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "Guideline for Authorization of Clinical Trials of Medicines, Food Supplements, Vaccines and Medical Devices in Ghana (Food and Drugs Authority)",
       "url": "https://fdaghana.gov.gh/guideline-for-authorization-of-clinical-trials-of-medicines-food-supplements-vaccines-and-medical-devices-in-ghana/",
       "date": "2024-01-15",
       "publisherClass": "official"
      },
      {
       "title": "Data Protection Act, 2012 (Act 843), full text (WHO Compendium of Public Health Legislation copy)",
       "url": "https://extranet.who.int/cpcd/sites/default/files/public_file_repository/GHA_Ghana_Data-Protection-Act_2012.pdf",
       "date": "2012",
       "publisherClass": "legal_text"
      },
      {
       "title": "The GHS Patients Charter (Ghana Health Service, posted by Nandom Municipal Health Directorate)",
       "url": "https://www.nandomdistrict.gov.gh/wp-content/uploads/2026/07/Ghana-Health-Service-Patients-Charter_Nandom-MHD.pdf",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 40,
     "summary": "The FDA's 2017 software-as-a-medical-device guideline requires registration and approval for significant changes, including algorithm changes, but has nothing specific on AI or human oversight. A national AI-in-health policy was still being drafted in August 2026.",
     "sources": [
      {
       "title": "Guideline for Registration of Software as a Medical Device, FDA/MCH/MDD/GL-RSAMD/2017/03 (Food and Drugs Authority)",
       "url": "https://fdaghana.gov.gh/guideline-for-registration-of-software-as-medical-device-3/",
       "date": "2017-12-01",
       "publisherClass": "official"
      },
      {
       "title": "Ghana launches AI-driven health programme to strengthen systems and safeguard communities (WHO Regional Office for Africa)",
       "url": "https://www.afro.who.int/countries/ghana/news/ghana-launches-artificial-intelligence-driven-health-programme-strengthen-systems-and-safeguard",
       "date": "2026-05-17",
       "publisherClass": "intergov"
      },
      {
       "title": "Health Ministry develops AI policy to guide safe use of artificial intelligence in Ghana's healthcare system (MyJoyOnline)",
       "url": "https://www.myjoyonline.com/health-ministry-develops-ai-policy-to-guide-safe-use-of-artificial-intelligence-in-ghanas-healthcare-system/",
       "date": "2026-08-06",
       "publisherClass": "news"
      },
      {
       "title": "Govt to introduce new Data Protection Bill to regulate AI, cross-border data flows (Ghana News Agency)",
       "url": "https://gna.org.gh/2026/03/govt-to-introduce-new-data-protection-bill-to-regulate-ai-cross-border-data-flows/",
       "date": "2026-03-02",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Data Protection Act, 2012 (Act 843)",
     "level": "National",
     "year": "2012",
     "what": "Health is special data; 40-day access; breach notice; written consent for marketing; selling data is a crime.",
     "url": "https://extranet.who.int/cpcd/sites/default/files/public_file_repository/GHA_Ghana_Data-Protection-Act_2012.pdf"
    },
    {
     "name": "Public Health Act, 2012 (Act 851)",
     "level": "National",
     "year": "2012",
     "what": "FDA powers over medical devices; clinical trials need authorisation and written informed consent (section 158).",
     "url": "https://www.moh.gov.gh/wp-content/uploads/2016/02/Public-Health-Act-851.pdf"
    },
    {
     "name": "FDA Guideline for Registration of Software as a Medical Device",
     "level": "National",
     "year": "2017",
     "what": "Registration, post-market surveillance and change approval for medical software; no AI-specific rules.",
     "url": "https://fdaghana.gov.gh/guideline-for-registration-of-software-as-medical-device-3/"
    },
    {
     "name": "FDA Guideline for Authorization of Clinical Trials",
     "level": "National",
     "year": "2024",
     "what": "Ethics approval, informed consent forms and PACTR registration required before trials.",
     "url": "https://fdaghana.gov.gh/guideline-for-authorization-of-clinical-trials-of-medicines-food-supplements-vaccines-and-medical-devices-in-ghana/"
    },
    {
     "name": "Ghana Health Service Patients Charter",
     "level": "National",
     "year": "not verified",
     "what": "Confidentiality without consent except by law or public interest; right to refuse research.",
     "url": "https://www.nandomdistrict.gov.gh/wp-content/uploads/2026/07/Ghana-Health-Service-Patients-Charter_Nandom-MHD.pdf"
    },
    {
     "name": "Pharmacy Council Electronic Pharmacy Policy",
     "level": "National",
     "year": "not verified",
     "what": "All e-pharmacy orders through the national platform; registration with the Data Protection Commission.",
     "url": "https://pcghana.org/newwebsite/wp-content/uploads/2024/08/EPHARMACY-POLICY.pdf"
    }
   ],
   "dti": {
    "grade": 85,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-10-24",
     "headline": "Hospitals return to paper folders after the electronic record system breaks down",
     "paraphrase": "Reporters found public hospitals in the Ashanti region writing patient histories in folders and exercise books for almost a week, with long queues. Some facilities said they had lost patient records dating back to 2023.",
     "source": "Adom Online (Multimedia Group)",
     "url": "https://www.adomonline.com/public-health-facilities-return-to-paper-based-system-as-lhims-shuts-down/",
     "theme": "access_delay_or_cost",
     "status": "alleged"
    },
    {
     "date": "2025-10-27",
     "headline": "Record system vendor blames unrenewed contract for hospital disruptions",
     "paraphrase": "The system's project manager said the contract expired in 2024 and an extension never came, leaving the project uncertain. Hospitals reverted to manual records and patients reported longer waits; the insurer told facilities to use a phone-based workaround.",
     "source": "Adom Online (Multimedia Group)",
     "url": "https://www.adomonline.com/hospitals-return-to-manual-records-as-lhims-contract-stalls/",
     "theme": "other",
     "status": "alleged"
    },
    {
     "date": "2025-10-29",
     "headline": "Data Protection Commission opens investigation into handling of national patient records",
     "paraphrase": "After a dispute over a shutdown of the national electronic records system, the regulator said it would assess how patient data is stored, retained and secured, and whether patients' rights are protected. No findings were reported.",
     "source": "Citi Newsroom",
     "url": "https://citinewsroom.com/2025/10/data-protection-commission-probes-handling-of-patient-data-managed-by-lightwave/",
     "theme": "other",
     "status": "alleged"
    },
    {
     "date": "2025-10-30",
     "headline": "Health minister says the state lacked control over citizens' electronic medical records",
     "paraphrase": "The minister said a private vendor held exclusive access to patients' electronic records, refused state administrative control, and switched the system off, leaving it down for two weeks. The vendor publicly disputes his account.",
     "source": "Graphic Online",
     "url": "https://www.graphic.com.gh/news/general-news/ghana-news-health-minister-uncovers-100m-e-health-scandal-rolls-out-4-week-fix.html",
     "theme": "other",
     "status": "alleged"
    },
    {
     "date": "2025-11-08",
     "headline": "Doctors say years of patient records became unreachable when the system shut down",
     "paraphrase": "A specialist told reporters that records back to 2020 were inaccessible after the national system shut down for weeks. Patients were asked to recall their own medicines, and staff logged new data in exercise books.",
     "source": "MyJoyOnline (JoyNews)",
     "url": "https://www.myjoyonline.com/e-health-records-disaster-clinicians-risk-misdiagnosing-patients-after-losing-5-years-of-medical-data/",
     "theme": "other",
     "status": "alleged"
    }
   ]
  },
  {
   "iso3": "NGA",
   "name": "Nigeria",
   "region": "Africa",
   "overall": 35,
   "rank": "64",
   "likelyRank": "63 to 65",
   "band": "Weak",
   "keysModel": "Institutional",
   "confidence": "high",
   "headline": "A modern data law on paper, but records stay inside each hospital and patients have no tool to see or steer who uses them.",
   "categories": {
    "access": {
     "score": 40,
     "summary": "Section 34 of the Data Protection Act 2023 gives a right to a copy in a common electronic format, but sets no day limit and lets providers pass on unreasonable costs. There is no national patient portal, so each hospital must be asked separately.",
     "sources": [
      {
       "title": "Nigeria Data Protection Act, 2023 (Official Gazette copy, NDPC)",
       "url": "https://ndpc.gov.ng/wp-content/uploads/2024/03/Nigeria_Data_Protection_Act_2023.pdf",
       "date": "2023-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "NDP Act General Application and Implementation Directive (GAID) 2025 (NDPC)",
       "url": "https://ndpc.gov.ng/wp-content/uploads/2025/07/NDP-ACT-GAID-2025-MARCH-20TH.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "National Health Act, 2014 (Official Gazette, FAOLEX copy)",
       "url": "https://faolex.fao.org/docs/pdf/nig162642.pdf",
       "date": "2014",
       "publisherClass": "legal_text"
      },
      {
       "title": "Patients' Bill of Rights (Consumer Protection Council and Federal Ministry of Health; copy hosted by Infusion Lawyers)",
       "url": "https://infusionlawyers.com/wp-content/uploads/2018/08/Patients-Bill-of-Rights-PBoR-Long-version.pdf",
       "date": "2018",
       "publisherClass": "official"
      }
     ]
    },
    "control": {
     "score": 28,
     "summary": "The National Health Act requires written consent to disclose health information, but section 27 lets providers pass records to other providers without asking again. Patients may ask which recipients got their data, but no working opt-out or patient-visible log exists, so control sits with each facility.",
     "sources": [
      {
       "title": "National Health Act, 2014 (Official Gazette, FAOLEX copy)",
       "url": "https://faolex.fao.org/docs/pdf/nig162642.pdf",
       "date": "2014",
       "publisherClass": "legal_text"
      },
      {
       "title": "Nigeria Data Protection Act, 2023 (Official Gazette copy, NDPC)",
       "url": "https://ndpc.gov.ng/wp-content/uploads/2024/03/Nigeria_Data_Protection_Act_2023.pdf",
       "date": "2023-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "NDP Act General Application and Implementation Directive (GAID) 2025 (NDPC)",
       "url": "https://ndpc.gov.ng/wp-content/uploads/2025/07/NDP-ACT-GAID-2025-MARCH-20TH.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Nigerian govt sued over deal to share citizens' health data with US (Daily Trust, from Premium Times)",
       "url": "https://dailytrust.com/nigerian-govt-sued-over-deal-to-share-citizens-health-data-with-us/",
       "date": "2026-03-20",
       "publisherClass": "news"
      }
     ]
    },
    "privacy": {
     "score": 45,
     "summary": "Health status is sensitive data under the 2023 Act, with 72-hour breach notice and fines of the greater of N10 million or 2% of revenue. But we found no health-sector enforcement, and a state teaching hospital was found unregistered in 2026.",
     "sources": [
      {
       "title": "Nigeria Data Protection Act, 2023 (Official Gazette copy, NDPC)",
       "url": "https://ndpc.gov.ng/wp-content/uploads/2024/03/Nigeria_Data_Protection_Act_2023.pdf",
       "date": "2023-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "National Health Act, 2014 (Official Gazette, FAOLEX copy)",
       "url": "https://faolex.fao.org/docs/pdf/nig162642.pdf",
       "date": "2014",
       "publisherClass": "legal_text"
      },
      {
       "title": "Inside Nigeria's deal to write off $32.8 million fine against Meta (Premium Times)",
       "url": "https://www.premiumtimesng.com/news/headlines/873350-exclusive-inside-nigerias-deal-to-write-off-32-8-million-fine-against-meta.html",
       "date": "2026-04-26",
       "publisherClass": "news"
      },
      {
       "title": "Airlines, hospitals... major data controllers not registered under NDPC (FIJ)",
       "url": "https://fij.ng/article/alert-airlines-hospitals-major-data-controllers-not-registered-under-ndpc/",
       "date": "2026-05-30",
       "publisherClass": "news"
      }
     ]
    },
    "journey": {
     "score": 28,
     "summary": "An assessment of 79 federal tertiary hospitals found average EMR adoption of 74.5%, but the Minister of State says donor-built systems still cannot share patient information across facilities. A national architecture was endorsed in June 2025, yet no working exchange links hospitals, labs and pharmacies.",
     "sources": [
      {
       "title": "Nigeria needs N500 billion to scale digital health infrastructure over five years (Premium Times)",
       "url": "https://www.premiumtimesng.com/health/health-news/890930-nigeria-needs-%E2%82%A6500-billion-to-scale-digital-health-infrastructure-over-five-years-official.html",
       "date": "2026-06-26",
       "publisherClass": "news"
      },
      {
       "title": "Nigeria Digital in Health Initiative (Federal Ministry of Health and Social Welfare)",
       "url": "https://www.digitalhealth.gov.ng/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "FG records major gains in health sector renewal, approves N32.8 billion BHCPF disbursement (Federal Ministry of Information)",
       "url": "https://fmino.gov.ng/fg-records-major-gains-in-health-sector-renewal-approves-n32-8-billion-bhcpf-disbursement-to-states/",
       "date": "2026-06-27",
       "publisherClass": "official"
      },
      {
       "title": "Federal Govt expands electronic medical records deployment across health facilities (Leadership)",
       "url": "https://leadership.ng/federal-govt-expands-electronic-medical-records-deployment-across-health-facilities/",
       "date": "2026-06-17",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 42,
     "summary": "GAID 2025 requires consent for any direct marketing and for processing sensitive data such as health data. There are no rules we found on health apps, data brokers or sale of de-identified data, and the Meta settlement softened earlier consent orders on behavioural advertising.",
     "sources": [
      {
       "title": "NDP Act General Application and Implementation Directive (GAID) 2025 (NDPC)",
       "url": "https://ndpc.gov.ng/wp-content/uploads/2025/07/NDP-ACT-GAID-2025-MARCH-20TH.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Nigeria Data Protection Act, 2023 (Official Gazette copy, NDPC)",
       "url": "https://ndpc.gov.ng/wp-content/uploads/2024/03/Nigeria_Data_Protection_Act_2023.pdf",
       "date": "2023-07-01",
       "publisherClass": "legal_text"
      },
      {
       "title": "Inside Nigeria's deal to write off $32.8 million fine against Meta (Premium Times)",
       "url": "https://www.premiumtimesng.com/news/headlines/873350-exclusive-inside-nigerias-deal-to-write-off-32-8-million-fine-against-meta.html",
       "date": "2026-04-26",
       "publisherClass": "news"
      },
      {
       "title": "Review of Nigeria's Digital Health Services Bill, 2025 (Tech Hive Advisory)",
       "url": "https://www.techhiveadvisory.africa/insights/review-of-nigerias-digital-health-services-bill-2025",
       "date": "2025-11-10",
       "publisherClass": "law_firm"
      }
     ]
    },
    "clinical": {
     "score": 22,
     "summary": "A clinician usually sees only their own facility's record. Section 27 of the Health Act lets providers share for treatment, but there is no national record or exchange to pull a patient's history from elsewhere.",
     "sources": [
      {
       "title": "National Health Act, 2014 (Official Gazette, FAOLEX copy)",
       "url": "https://faolex.fao.org/docs/pdf/nig162642.pdf",
       "date": "2014",
       "publisherClass": "legal_text"
      },
      {
       "title": "Senate advances bill to integrate e-health services in Nigeria (Vanguard)",
       "url": "https://www.vanguardngr.com/2026/07/senate-advances-bill-to-integrate-e-health-services-in-nigeria/",
       "date": "2026-07-08",
       "publisherClass": "news"
      },
      {
       "title": "Nigerian govt unveils blueprint for secure, interoperable digital health system (Premium Times)",
       "url": "https://www.premiumtimesng.com/news/top-news/898831-nigerian-govt-unveils-blueprint-for-secure-interoperable-digital-health-system.html",
       "date": "2026-07-28",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "Research use of identifiable records needs the patient's authorisation, the facility head's approval and ethics clearance under section 28 of the Health Act, the same regime as South Africa. De-identified data is exempt, and there is no public register of uses.",
     "sources": [
      {
       "title": "National Health Act, 2014 (Official Gazette, FAOLEX copy)",
       "url": "https://faolex.fao.org/docs/pdf/nig162642.pdf",
       "date": "2014",
       "publisherClass": "legal_text"
      },
      {
       "title": "National Code of Health Research Ethics (NHREC, Federal Ministry of Health)",
       "url": "https://healthresearchwebafrica.org.za/files/NCHRECurrentVersion.pdf",
       "date": "2007-08-13",
       "publisherClass": "official"
      },
      {
       "title": "Nigeria Data Protection Act, 2023 (Official Gazette copy, NDPC)",
       "url": "https://ndpc.gov.ng/wp-content/uploads/2024/03/Nigeria_Data_Protection_Act_2023.pdf",
       "date": "2023-07-01",
       "publisherClass": "legal_text"
      }
     ]
    },
    "ai": {
     "score": 38,
     "summary": "NAFDAC registers software as a medical device under a 2024 guideline with risk classes and clinical validation, but it has no AI-specific rules. The Health Minister asked in July 2026 whether frameworks for health AI exist.",
     "sources": [
      {
       "title": "Guidelines for Registration of Software as a Medical Device (SaMD) in Nigeria, DR&R-GDL-036-00 (NAFDAC)",
       "url": "https://nafdac.gov.ng/wp-content/uploads/Files/Resources/Guidelines/DR_And_R_Guidelines/Guidelines-for-Registration-of-Software-as-a-Medical-Device-SaMD-in-Nigeria.pdf",
       "date": "2024-07-01",
       "publisherClass": "official"
      },
      {
       "title": "NDP Act General Application and Implementation Directive (GAID) 2025 (NDPC)",
       "url": "https://ndpc.gov.ng/wp-content/uploads/2025/07/NDP-ACT-GAID-2025-MARCH-20TH.pdf",
       "date": "2025-03-20",
       "publisherClass": "legal_text"
      },
      {
       "title": "Senate begins consideration of bill to regulate AI diagnostics, IVF and emerging health technologies (National Assembly Library Trust Fund)",
       "url": "https://naltf.gov.ng/senate-begins-consideration-of-landmark-bill-to-regulate-ai-diagnostics-ivf-and-emerging-health-technologies/",
       "date": "2026-07-24",
       "publisherClass": "official"
      },
      {
       "title": "Nigerian govt unveils blueprint for secure, interoperable digital health system (Premium Times)",
       "url": "https://www.premiumtimesng.com/news/top-news/898831-nigerian-govt-unveils-blueprint-for-secure-interoperable-digital-health-system.html",
       "date": "2026-07-28",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Nigeria Data Protection Act, 2023",
     "level": "National",
     "year": "2023",
     "what": "Health status is sensitive data; access, objection, 72-hour breach notice, fines of greater of N10 million or 2% revenue.",
     "url": "https://ndpc.gov.ng/wp-content/uploads/2024/03/Nigeria_Data_Protection_Act_2023.pdf"
    },
    {
     "name": "NDP Act General Application and Implementation Directive (GAID) 2025",
     "level": "National",
     "year": "2025",
     "what": "Consent for marketing and sensitive data; portability; AI deployment duties under Article 43.",
     "url": "https://ndpc.gov.ng/wp-content/uploads/2025/07/NDP-ACT-GAID-2025-MARCH-20TH.pdf"
    },
    {
     "name": "National Health Act, 2014",
     "level": "National",
     "year": "2014",
     "what": "Record keeping, confidentiality, provider sharing, research authorisation, offences for unauthorised record access.",
     "url": "https://faolex.fao.org/docs/pdf/nig162642.pdf"
    },
    {
     "name": "National Health Insurance Authority Act, 2022",
     "level": "National",
     "year": "2022",
     "what": "Makes health insurance mandatory and requires state schemes to feed data into NHIA's ICT system.",
     "url": "https://p4h.world/app/uploads/2024/06/Nigeria-National-Health-Insurance-Act.x23411.pdf"
    },
    {
     "name": "NAFDAC Guidelines for Registration of Software as a Medical Device",
     "level": "National",
     "year": "2024",
     "what": "Risk classes and clinical validation for medical software; no AI-specific provisions.",
     "url": "https://nafdac.gov.ng/wp-content/uploads/Files/Resources/Guidelines/DR_And_R_Guidelines/Guidelines-for-Registration-of-Software-as-a-Medical-Device-SaMD-in-Nigeria.pdf"
    },
    {
     "name": "National E-Health Bill, 2026 (SB. 758)",
     "level": "National",
     "year": "2026",
     "what": "Pending: passed Senate second reading July 2026; would regulate and integrate electronic health services.",
     "url": "https://www.vanguardngr.com/2026/07/senate-advances-bill-to-integrate-e-health-services-in-nigeria/"
    }
   ],
   "dti": {
    "grade": 88,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2025-01-18",
     "headline": "Patient paid repeatedly for the same tests because records did not follow her",
     "paraphrase": "A patient told reporters that each new hospital, private then public, made her repeat and pay for routine tests she had already done, because results were not transferable. A records officer said each hospital keeps its own unlinked system.",
     "source": "Sahara Reporters (republishing a Daily Trust report)",
     "url": "https://saharareporters.com/2025/01/18/non-harmonisation-health-records-nigerian-hospitals-slows-down-patients-during-medical",
     "theme": "lost_between_providers",
     "status": "self_reported"
    },
    {
     "date": "2026-07-23",
     "headline": "Teaching hospital says patient case files are still carried by hand during digitisation",
     "paraphrase": "Responding to reports of consultation delays and piles of paper folders, the hospital's chief medical director said electronic records cover only two departments so far and the rest will follow in phases.",
     "source": "Punch",
     "url": "https://punchng.com/lasuth-defends-digitalisation-over-patient-record-concerns/",
     "theme": "access_delay_or_cost",
     "status": "admitted"
    }
   ]
  },
  {
   "iso3": "EGY",
   "name": "Egypt",
   "region": "Middle East",
   "overall": 33,
   "rank": "65",
   "likelyRank": "64 to 65",
   "band": "Weak",
   "keysModel": "State",
   "confidence": "high",
   "headline": "Egypt links records for about 6.8 million people in seven governorates, but patients get no say over sharing, and data protection enforcement starts November 2026.",
   "categories": {
    "access": {
     "score": 30,
     "summary": "Law 151 of 2020 gives a right to access only electronically processed data, with fees up to EGP 20,000, no response deadline, and enforcement from November 2026. Each gap costs 5 points from the base of 45, clamped at 30; what the patient e-portal shows is not verified.",
     "sources": [
      {
       "title": "Law No. 151 of 2020, Personal Data Protection Law (English translation, Andersen Egypt)",
       "url": "https://eg.andersen.com/wp-content/uploads/2025/06/Law-No.-151-OF-2020.pdf",
       "date": "undated",
       "publisherClass": "law_firm"
      },
      {
       "title": "Executive Regulations of the Personal Data Protection Law: a legal commentary (Masaar and EIPR, Arabic)",
       "url": "https://eipr.org/sites/default/files/reports/pdf/_-_hmy_lbynt-2.pdf",
       "date": "2026-02",
       "publisherClass": "academic"
      },
      {
       "title": "Hospital policy on patient rights (newborns and families), Egyptian Health Council training portal (Arabic)",
       "url": "https://lms.ehc.gov.eg/lms/mod/book/view.php?id=457&chapterid=2491&lang=ar",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Prime Minister reviews Egypt Healthcare Authority results for H1 2025/2026 (Youm7, Arabic)",
       "url": "https://www.youm7.com/story/2026/9/5/%D9%85%D8%AF%D8%A8%D9%88%D9%84%D9%89-%D9%8A%D8%B3%D8%AA%D8%B9%D8%B1%D8%B6-%D8%AA%D9%82%D8%B1%D9%8A%D8%B1%D9%8B%D8%A7-%D8%AD%D9%88%D9%84-%D8%A5%D9%86%D8%AC%D8%A7%D8%B2%D8%A7%D8%AA-%D8%A7%D9%84%D8%B1%D8%B9%D8%A7%D9%8A%D8%A9-%D8%A7%D9%84%D8%B5%D8%AD%D9%8A%D8%A9-%D8%A8%D8%A7%D9%84%D9%86%D8%B5%D9%81-%D8%A7%D9%84%D8%A3%D9%88%D9%84-%D9%85%D9%86/7536515",
       "date": "2026-09-05",
       "publisherClass": "news"
      }
     ]
    },
    "control": {
     "score": 25,
     "summary": "Records are created and shared by default inside the universal insurance system, which is compulsory for citizens living in Egypt, with no opt-out and no patient-visible access log found. Written consent for health data applies only where no law authorises the processing.",
     "sources": [
      {
       "title": "Universal Health Insurance Law No. 2 of 2018, full text (Manshurat legal archive, Arabic)",
       "url": "https://manshurat.org/node/63712",
       "date": "2018",
       "publisherClass": "legal_text"
      },
      {
       "title": "Universal Health Insurance Authority home page: registration steps (Arabic)",
       "url": "https://uhia.gov.eg/",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Law No. 151 of 2020, Personal Data Protection Law (English translation, Andersen Egypt)",
       "url": "https://eg.andersen.com/wp-content/uploads/2025/06/Law-No.-151-OF-2020.pdf",
       "date": "undated",
       "publisherClass": "law_firm"
      },
      {
       "title": "Hospital policy on patient rights (newborns and families), Egyptian Health Council training portal (Arabic)",
       "url": "https://lms.ehc.gov.eg/lms/mod/book/view.php?id=457&chapterid=2491&lang=ar",
       "date": "undated",
       "publisherClass": "official"
      }
     ]
    },
    "privacy": {
     "score": 36,
     "summary": "Law 151 makes health data sensitive, with prison and fines up to EGP 5 million, and the 2025 Medical Liability Law bars disclosing patient secrets. But the ICT minister chairs the regulator, whose board seats defence, interior and intelligence, and enforcement starts only after November 2026.",
     "sources": [
      {
       "title": "Law No. 151 of 2020, Personal Data Protection Law (English translation, Andersen Egypt)",
       "url": "https://eg.andersen.com/wp-content/uploads/2025/06/Law-No.-151-OF-2020.pdf",
       "date": "undated",
       "publisherClass": "law_firm"
      },
      {
       "title": "President ratifies the Personal Data Protection Law (State Information Service, Arabic)",
       "url": "https://sis.gov.eg/ar/%D8%A7%D9%84%D8%B1%D8%A6%D8%A7%D8%B3%D8%A9/%D8%B4%D8%A6%D9%88%D9%86-%D8%AF%D8%A7%D8%AE%D9%84%D9%8A%D8%A9/%D8%A7%D9%84%D9%82%D8%B1%D8%A7%D8%B1%D8%A7%D8%AA-%D8%A7%D9%84%D8%B1%D8%A6%D8%A7%D8%B3%D9%8A%D8%A9/%D8%A7%D9%84%D8%B1%D8%A6%D9%8A%D8%B3-%D8%A7%D9%84%D8%B3%D9%8A%D8%B3%D9%89%D9%8A-%D9%8A-%D8%B5%D8%AF-%D9%82-%D8%B9%D9%84%D9%89-%D9%82%D8%A7%D9%86%D9%88%D9%86-%D8%AD%D9%85%D8%A7%D9%8A%D8%A9-%D8%A7%D9%84%D8%A8%D9%8A%D8%A7%D9%86%D8%A7%D8%AA-%D8%A7%D9%84%D8%B4%D8%AE%D8%B5%D9%8A%D8%A9/",
       "date": "2020-07-15",
       "publisherClass": "official"
      },
      {
       "title": "Executive Regulations of the Personal Data Protection Law: a legal commentary (Masaar and EIPR, Arabic)",
       "url": "https://eipr.org/sites/default/files/reports/pdf/_-_hmy_lbynt-2.pdf",
       "date": "2026-02",
       "publisherClass": "academic"
      },
      {
       "title": "Law No. 13 of 2025 on Medical Liability and Patient Safety, Official Gazette No. 17 bis (Ministry of Justice, Arabic)",
       "url": "https://moj.gov.eg:73/Doc/001/70640132025.pdf",
       "date": "2025-04-28",
       "publisherClass": "legal_text"
      }
     ]
    },
    "journey": {
     "score": 35,
     "summary": "Inside the universal insurance governorates, primary care runs fully digital and labs, imaging and prescriptions feed a unified record for about 6.8 million beneficiaries. Elsewhere care is not linked; a national platform was only proposed in September 2026.",
     "sources": [
      {
       "title": "Health ministry: universal insurance delivered 117 million services to 6 million people (Youm7, Arabic)",
       "url": "https://www.youm7.com/story/2026/7/6/%D9%88%D8%B2%D8%A7%D8%B1%D8%A9-%D8%A7%D9%84%D8%B5%D8%AD%D8%A9-%D8%A7%D9%84%D8%AA%D8%A3%D9%85%D9%8A%D9%86-%D8%A7%D9%84%D8%B5%D8%AD%D9%89-%D8%A7%D9%84%D8%B4%D8%A7%D9%85%D9%84-%D9%82%D8%AF%D9%85-%D8%A3%D9%83%D8%AB%D8%B1-%D9%85%D9%86-117-%D9%85%D9%84%D9%8A%D9%88%D9%86/7471635",
       "date": "2026-07-06",
       "publisherClass": "news"
      },
      {
       "title": "Prime Minister reviews Egypt Healthcare Authority results for H1 2025/2026 (Youm7, Arabic)",
       "url": "https://www.youm7.com/story/2026/9/5/%D9%85%D8%AF%D8%A8%D9%88%D9%84%D9%89-%D9%8A%D8%B3%D8%AA%D8%B9%D8%B1%D8%B6-%D8%AA%D9%82%D8%B1%D9%8A%D8%B1%D9%8B%D8%A7-%D8%AD%D9%88%D9%84-%D8%A5%D9%86%D8%AC%D8%A7%D8%B2%D8%A7%D8%AA-%D8%A7%D9%84%D8%B1%D8%B9%D8%A7%D9%8A%D8%A9-%D8%A7%D9%84%D8%B5%D8%AD%D9%8A%D8%A9-%D8%A8%D8%A7%D9%84%D9%86%D8%B5%D9%81-%D8%A7%D9%84%D8%A3%D9%88%D9%84-%D9%85%D9%86/7536515",
       "date": "2026-09-05",
       "publisherClass": "news"
      },
      {
       "title": "National Digital Health Strategy 2025-2029 (State Information Service, Arabic)",
       "url": "https://sis.gov.eg/ar/%D8%A7%D9%84%D9%85%D8%B1%D9%83%D8%B2-%D8%A7%D9%84%D8%A5%D8%B9%D9%84%D8%A7%D9%85%D9%8A/%D8%A7%D8%B3%D8%AA%D8%B1%D8%A7%D8%AA%D9%8A%D8%AC%D9%8A%D8%A7%D8%AA/%D8%A7%D9%84%D8%A7%D8%B3%D8%AA%D8%B1%D8%A7%D8%AA%D9%8A%D8%AC%D9%8A%D8%A9-%D8%A7%D9%84%D9%88%D8%B7%D9%86%D9%8A%D8%A9-%D9%84%D9%84%D8%B5%D8%AD%D8%A9-%D8%A7%D9%84%D8%B1%D9%82%D9%85%D9%8A%D8%A9-2025-2029/",
       "date": "2025-11-15",
       "publisherClass": "official"
      },
      {
       "title": "Egypt plans unified digital platform to link patient records across health facilities (Daily News Egypt)",
       "url": "https://www.dailynewsegypt.com/2026/09/14/egypt-plans-unified-digital-platform-to-link-patient-records-across-health-facilities/",
       "date": "2026-09-14",
       "publisherClass": "news"
      }
     ]
    },
    "commercial": {
     "score": 40,
     "summary": "Law 151 requires prior consent and a licence for electronic direct marketing and a licence plus written consent for any health data processing. Trading in research samples is banned, but no rule on de-identified data sales or health data brokers was found, and enforcement starts November 2026.",
     "sources": [
      {
       "title": "Law No. 151 of 2020, Personal Data Protection Law (English translation, Andersen Egypt)",
       "url": "https://eg.andersen.com/wp-content/uploads/2025/06/Law-No.-151-OF-2020.pdf",
       "date": "undated",
       "publisherClass": "law_firm"
      },
      {
       "title": "Executive Regulations of the Data Protection Law and the Data Protection Centre (Soliman, Hashish & Partners)",
       "url": "https://www.shandpartners.com/insights/briefings/telecoms-media-technology/the-issuance-of-the-executive-regulations-of-the-data-protection-law-and-the-establishment-of-the-data-protection-centre/",
       "date": "2026-01-11",
       "publisherClass": "law_firm"
      },
      {
       "title": "Law No. 214 of 2020 on Clinical Medical Research, Official Gazette No. 51 bis (f) (Arabic)",
       "url": "https://nrc-mrec.online/?jet_download=c70bfcea951063cca1a77b849268a5dca8fe1356",
       "date": "2020-12-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Law No. 13 of 2025 on Medical Liability and Patient Safety, Official Gazette No. 17 bis (Ministry of Justice, Arabic)",
       "url": "https://moj.gov.eg:73/Doc/001/70640132025.pdf",
       "date": "2025-04-28",
       "publisherClass": "legal_text"
      }
     ]
    },
    "clinical": {
     "score": 30,
     "summary": "Treating teams in universal insurance facilities can reach a patient's unified electronic record, which the Healthcare Authority says gives fast access to patient data. Most Egyptians are outside that system, and the law only requires doctors to share information when consulted.",
     "sources": [
      {
       "title": "Prime Minister reviews Egypt Healthcare Authority results for H1 2025/2026 (Youm7, Arabic)",
       "url": "https://www.youm7.com/story/2026/9/5/%D9%85%D8%AF%D8%A8%D9%88%D9%84%D9%89-%D9%8A%D8%B3%D8%AA%D8%B9%D8%B1%D8%B6-%D8%AA%D9%82%D8%B1%D9%8A%D8%B1%D9%8B%D8%A7-%D8%AD%D9%88%D9%84-%D8%A5%D9%86%D8%AC%D8%A7%D8%B2%D8%A7%D8%AA-%D8%A7%D9%84%D8%B1%D8%B9%D8%A7%D9%8A%D8%A9-%D8%A7%D9%84%D8%B5%D8%AD%D9%8A%D8%A9-%D8%A8%D8%A7%D9%84%D9%86%D8%B5%D9%81-%D8%A7%D9%84%D8%A3%D9%88%D9%84-%D9%85%D9%86/7536515",
       "date": "2026-09-05",
       "publisherClass": "news"
      },
      {
       "title": "Hospital policy on patient rights (newborns and families), Egyptian Health Council training portal (Arabic)",
       "url": "https://lms.ehc.gov.eg/lms/mod/book/view.php?id=457&chapterid=2491&lang=ar",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Law No. 13 of 2025 on Medical Liability and Patient Safety, Official Gazette No. 17 bis (Ministry of Justice, Arabic)",
       "url": "https://moj.gov.eg:73/Doc/001/70640132025.pdf",
       "date": "2025-04-28",
       "publisherClass": "legal_text"
      },
      {
       "title": "Egypt plans unified digital platform to link patient records across health facilities (Daily News Egypt)",
       "url": "https://www.dailynewsegypt.com/2026/09/14/egypt-plans-unified-digital-platform-to-link-patient-records-across-health-facilities/",
       "date": "2026-09-14",
       "publisherClass": "news"
      }
     ]
    },
    "research": {
     "score": 50,
     "summary": "The 2020 Clinical Research Law covers retrospective record studies and requires written informed consent, Supreme Council ethics review, identity secrecy and prison for research without consent. Those four safeguards reach the 50 cap, though data must be open to the General Intelligence Service and no opt-out exists.",
     "sources": [
      {
       "title": "Law No. 214 of 2020 on Clinical Medical Research, Official Gazette No. 51 bis (f) (Arabic)",
       "url": "https://nrc-mrec.online/?jet_download=c70bfcea951063cca1a77b849268a5dca8fe1356",
       "date": "2020-12-23",
       "publisherClass": "legal_text"
      },
      {
       "title": "Hospital policy on patient rights (newborns and families), Egyptian Health Council training portal (Arabic)",
       "url": "https://lms.ehc.gov.eg/lms/mod/book/view.php?id=457&chapterid=2491&lang=ar",
       "date": "undated",
       "publisherClass": "official"
      },
      {
       "title": "Egypt plans to establish first national center for health data science (State Information Service)",
       "url": "https://sis.gov.eg/en/media-center/news/egypt-plans-to-establish-first-national-center-for-health-data-science/",
       "date": "2026-05-16",
       "publisherClass": "official"
      }
     ]
    },
    "ai": {
     "score": 40,
     "summary": "Egypt governs AI through guidance: a 2023 Responsible AI Charter requiring final human determination and 2026 national guidelines. Medical device rules cover software and changes generally, but no AI-specific medical rule was found, and the AI law is still pending.",
     "sources": [
      {
       "title": "Egyptian Charter for Responsible AI (National Council for AI)",
       "url": "https://ai.gov.eg/SynchedFiles/en/Resources/Egyptian%20Charter%20for%20Responsible%20AI.pdf",
       "date": "2023",
       "publisherClass": "official"
      },
      {
       "title": "Egypt National Artificial Intelligence Strategy 2025-2030 (OECD.AI Policy Navigator)",
       "url": "https://oecd.ai/en/dashboards/policy-initiatives/egypt-national-artificial-intelligence-strategy",
       "date": "2026-02-10",
       "publisherClass": "intergov"
      },
      {
       "title": "Regulatory guideline on changes to a registered medical device, version 3 (Egyptian Drug Authority)",
       "url": "https://www.edaegypt.gov.eg/media/jf2cxmo4/3-regulatory-guideline-of-the-procedures-and-rules-organizing-the-changes-done-to-a-registration-license-data-of-a-medical-device_gd.pdf",
       "date": "2025-09-01",
       "publisherClass": "official"
      },
      {
       "title": "Four ICT bills before parliament, from AI to child protection (El Watan, Arabic)",
       "url": "https://www.elwatannews.com/news/details/8341286",
       "date": "2026-08-17",
       "publisherClass": "news"
      }
     ]
    }
   },
   "laws": [
    {
     "name": "Personal Data Protection Law No. 151 of 2020",
     "level": "National",
     "year": "2020",
     "what": "Health data is sensitive; licence and written consent required; fines up to EGP 5 million.",
     "url": "https://eg.andersen.com/wp-content/uploads/2025/06/Law-No.-151-OF-2020.pdf"
    },
    {
     "name": "PDPL Executive Regulations, Ministerial Decree 816 of 2025",
     "level": "National",
     "year": "2025",
     "what": "Licensing, DPOs, breach steps; one-year compliance period ending 1 November 2026.",
     "url": "https://eipr.org/sites/default/files/reports/pdf/_-_hmy_lbynt-2.pdf"
    },
    {
     "name": "Medical Liability and Patient Safety Law No. 13 of 2025",
     "level": "National",
     "year": "2025",
     "what": "Duty to record procedures, obtain consent and keep patient secrets; effective late October 2025.",
     "url": "https://moj.gov.eg:73/Doc/001/70640132025.pdf"
    },
    {
     "name": "Universal Health Insurance Law No. 2 of 2018",
     "level": "National",
     "year": "2018",
     "what": "Compulsory family-based insurance; insurer builds a beneficiary database linked to other state databases.",
     "url": "https://manshurat.org/node/63712"
    },
    {
     "name": "Clinical Medical Research Law No. 214 of 2020",
     "level": "National",
     "year": "2020",
     "what": "Written informed consent, withdrawal right, sample rules; data open to intelligence service for audit.",
     "url": "https://nrc-mrec.online/?jet_download=c70bfcea951063cca1a77b849268a5dca8fe1356"
    },
    {
     "name": "Medical Ethics Regulations, Ministerial Resolution 238 of 2003 (text hosted by the Egyptian Health Council)",
     "level": "National",
     "year": "2003",
     "what": "Doctors may not disclose patient secrets except by court order, serious risk or law.",
     "url": "https://www.ehc.gov.eg/documents/20126/0/medicine.pdf/7dee94e8-e6ac-1495-ffdf-2f0c95d582c7?t=1693421634760&download=true"
    }
   ],
   "dti": {
    "grade": 83,
    "tier": "Gold",
    "tierCapped": false
   },
   "asOf": "2026-10-02",
   "stories": [
    {
     "date": "2026-08-27",
     "headline": "Lawmaker asks why some hospital patients cannot get their full medical files",
     "paraphrase": "A member of parliament told the health minister that patients at some public hospitals leave with only a final summary, not detailed reports and test results, and some are stopped from photographing their own records.",
     "source": "Cairo 24",
     "url": "https://www.cairo24.com/2484087",
     "theme": "access_refused",
     "status": "alleged"
    },
    {
     "date": "2025-01-19",
     "headline": "Lawmaker raises claims that some medical labs misused patients' data",
     "paraphrase": "In a formal request to the health minister, a member of parliament cited press reports that some laboratories had used patients' data unlawfully, and asked for regular oversight to stop misuse of patient data. No finding was reported.",
     "source": "Darb",
     "url": "https://daaarb.com/%D8%AA%D8%AD%D8%B1%D9%83-%D8%A8%D8%B1%D9%84%D9%85%D8%A7%D9%86%D9%8A-%D8%B9%D9%86-%D8%A7%D8%AD%D8%AA%D9%83%D8%A7%D8%B1-%D8%AB%D9%84%D8%A7%D8%AB-%D9%85%D8%B9%D8%A7%D9%85%D9%84-%D8%AA%D8%AD%D8%A7%D9%84/",
     "theme": "other",
     "status": "alleged"
    },
    {
     "date": "2025-04-27",
     "headline": "Disciplinary court suspends public hospital doctor who disclosed patients' confidential medical data",
     "paraphrase": "A disciplinary court suspended a public hospital doctor for six months. Prosecutors found she disclosed confidential medical information about patients online without their or the hospital's permission, and used patient information to promote clinics.",
     "source": "Youm7",
     "url": "https://www.youm7.com/story/2025/4/27/11-%D9%85%D8%AE%D8%A7%D9%84%D9%81%D8%A9-%D9%82%D8%A7%D8%AF%D8%AA-%D8%B7%D8%A8%D9%8A%D8%A8%D8%A9-%D9%83%D9%81%D8%B1-%D8%A7%D9%84%D8%AF%D9%88%D8%A7%D8%B1-%D9%85%D9%86-%D8%A7%D9%84%D8%B4%D9%87%D8%B1%D8%A9-%D9%84%D9%84%D9%88%D9%82%D9%81-%D8%B9%D9%86/6967597",
     "theme": "breach",
     "status": "finding"
    }
   ]
  }
 ]
}