AZC Legal
    Protection of Personal Data in the Health Sector
    Back to Legal News

    Protection of Personal Data in the Health Sector

    Also available in Spanish:Leer en español

    The General Regime for the Protection of Personal Data, regulated by Law 1581 of 2012, aims to protect the constitutional rights to privacy and information that all persons have to know, update, and rectify the information that has been collected about them, in databases and all types of files that are subject to processing by public and private entities.

    Share article

    The General Regime for the Protection of Personal Data, regulated by Law 1581 of 2012, aims to protect the constitutional rights to privacy and information that all persons have to know, update, and rectify the information that has been collected about them, in databases and all types of files that are subject to processing by public and private entities.

    In this regard, it is pertinent to mention that Personal Data is any information associated or linked to one or more natural persons that allows their identification. Among the data, the law has established some typologies, including:
    • Public data: that which the law or the Constitution determines to be public.
    • Semi-private data: data that does not have the nature of intimacy or reservation and is not public.
    • Private data: data of an intimate nature that is only relevant to the data subject.
    However, Colombian regulations have determined that there is information that is more sensitive, such as data on health status, racial or ethnic origin, sexual life, among other aspects. Therefore, Law 1581 in Article 5 has determined the specific treatment for "sensitive data," given that the improper use thereof could affect the privacy of the data subject.
    Accordingly, entities operating in the health sector are obliged to protect all health-related data, such as medical records, laboratory tests, and all others that involve or compromise the health of data subjects, since these are sensitive data that may affect the privacy of individuals related to such data.
    Otherwise, Law 1581 of 2012 has established a series of sanctions for the violation of constitutional rights and the omission of the provisions contemplated. Thus, as the authority responsible for inspecting, supervising, and controlling the Processing of Personal Data, the Superintendence of Industry and Commerce (SIC) has imposed sanctions exceeding $21,000 million because companies have violated constitutional rights and breached established regulations.
    Among the sanctions imposed by the SIC in the health sector is Resolution 39298 of July 21, 2016. Through this resolution, the plaintiff denounced the health company COLMEDICA S.A. for the improper use of information about the physical and mental health of her sister, arising from the pain and anguish that remembering the situation caused her; a situation that was visible in a public access medium, via the internet.
    Therefore, the SIC concluded that the authorization granted by the data subject did not include as a purpose the publication of sensitive information in mass media, such as the internet. Consequently, Colmédica breached its legal duty and exposed sensitive information of its data subjects and did not implement appropriate measures for the exposed data.
    For that reason, the SIC declared COLMÉDICA as responsible and imposed a total fine of EIGHT HUNDRED TWENTY-SEVEN MILLION THREE HUNDRED FORTY-SIX THOUSAND PESOS CURRENT CURRENCY ($827,346,000), equivalent to one thousand two hundred current legal monthly minimum wages (1200 SMMLV) and an additional fine of TWO HUNDRED SIX MILLION EIGHT HUNDRED THIRTY-SIX THOUSAND FIVE HUNDRED PESOS ($206,836,500).
    In accordance with the aforementioned case, the SIC has imposed sanctions on those who violate constitutional rights and infringe the provisions on the Processing of Personal Data. Therefore, entities engaged in activities in the health sector are obliged to comply with the provisions established in Law 1581 of 2012, given that the use of sensitive data that such entities request, collect, and store on the data subject requires greater care and responsibility on the part of the entities and other parties responsible who have access to them.
    In this vein, it is recommended that entities holding databases of data subjects comply with current regulations through the implementation of Personal Data Processing Manuals and other procedures to ensure the protection of the constitutional rights of data subjects.

    September 22, 2017