Compliance & Regulatory Framework
ScanCare fully adheres to all Philippine healthcare laws, data privacy regulations, and international health standards to ensure legal, ethical, and secure operations.
Philippine Laws & Regulatory Mandates
RA 10173
Data Privacy Act of 2012
Governs collection, processing, and storage of personal data in the Philippines.
- ✓ Explicit patient consent for data processing
- ✓ Encryption of all sensitive health records
- ✓ Right to access, correction, deletion (RACCD)
- ✓ Annual privacy impact assessments
- ✓ Data Protection Officer on staff
RA 11223
Universal Health Care Act
Mandates equitable health service delivery across all population groups.
- ✓ Accessible primary health care to all
- ✓ Integrated referral system to hospitals
- ✓ Essential medicines availability
- ✓ Free preventive care programs
- ✓ Community health worker empowerment
RA 9994
Senior Citizens Welfare Act
Ensures healthcare and social services for citizens aged 60 and above.
- ✓ Automatic age verification (60+)
- ✓ Priority scheduling at health center
- ✓ Discounted/free medicines tracking
- ✓ Enhanced monitoring protocols
- ✓ Family support coordination
Additional Compliance Frameworks
Drug & Medicine Regulations
Philippine Pharmacopeia & FDA Standards: All medicines tracked comply with Bureau of Food and Drugs (BFD) requirements and proper storage protocols.
- ✓ Licensed medicine suppliers only
- ✓ Batch tracking with expiration dates
- ✓ Cold chain compliance for vaccines
- ✓ Adverse event reporting integration
Cybersecurity & IT Standards
NIST Cybersecurity Framework: Infrastructure and data protection aligned with international cybersecurity best practices.
- ✓ SSL/TLS encryption (data in transit)
- ✓ AES-256 encryption (data at rest)
- ✓ Regular penetration testing
- ✓ Intrusion detection & monitoring
Disease Reporting Requirements
DOH Surveillance System Integration: All notifiable diseases reported to Department of Health via integrated systems.
- ✓ Real-time epidemiological reporting
- ✓ Automated case classification
- ✓ Outbreak investigation coordination
- ✓ National surveillance database sync
Healthcare Quality Standards
PhilHealth & Service Standards: Clinical protocols align with Philippine Health Insurance Corporation requirements and Joint Commission standards.
- ✓ Clinical performance monitoring
- ✓ Patient safety incident tracking
- ✓ Service quality audits
- ✓ Accreditation maintenance
Data Protection Policies (Accordion)
Patients provide explicit, informed consent for data processing at registration. This includes consent for:
- Health record digitization and storage
- Data sharing with authorized healthcare providers
- Aggregated statistical reporting (with anonymization)
- Research purposes (approved projects only)
Opt-Out Option: Patients may withdraw consent at any time. Historical data is archived but no new entries are created.
ScanCare maintains a structured data lifecycle:
- Active Records: Kept for 5 years with regular access
- Archive: Moved to secure backup after 5 years
- Deletion: Permanent removal after 10 years (per RA 10173)
- Special Cases: Extended retention for ongoing treatment tracking or legal cases
Patient Request: Right to deletion (RACCD) honored within 30 days, except where data is needed for ongoing care.
Every access to patient data is logged with timestamp, user ID, and action taken:
- Role-based access: users can only view records relevant to their function
- Unusual access patterns are automatically flagged and investigated
- Quarterly audit reports submitted to barangay officials
- Unauthorized access triggers immediate security alert and user suspension
Patient Transparency: Patients can request an audit log of who accessed their records and when.
In the event of a data breach or security incident:
- Immediate containment and forensic investigation (within 24 hours)
- Affected individuals notified within 72 hours (per RA 10173)
- NPC (National Privacy Commission) notified if breach affects >100 individuals
- Corrective actions documented and implemented
- Regular breach drills and incident response tabletop exercises
Goal: Zero breaches through proactive security monitoring and rapid response protocols.
Third-Party Audits & Compliance Verification
Annual External Audits
- 1 Data Privacy Impact Assessment (DPIA) conducted by independent auditors
- 2 Cybersecurity Penetration Testing by certified ethical hackers
- 3 ISO 27001 Compliance certification for information security management
- 4 Healthcare Accreditation Review aligned with PhilHealth standards
Regulatory Agency Oversight
- ✓ NPC (National Privacy Commission): Annual compliance reporting
- ✓ DOH (Department of Health): Surveillance system audits
- ✓ LGU Health Office: Quarterly operational reviews
- ✓ PNP Cybercrime Unit: Security incident coordination