ScanCare Logo ScanCare
Legal & Regulatory Alignment

Compliance & Regulatory Framework

ScanCare fully adheres to all Philippine healthcare laws, data privacy regulations, and international health standards to ensure legal, ethical, and secure operations.

Additional Compliance Frameworks

Drug & Medicine Regulations

FDA / BFD
Licensed medicine suppliers only
Batch tracking with expiration dates
Cold chain compliance for vaccines
Adverse event reporting integration

Cybersecurity & IT Standards

NIST CSF
SSL/TLS encryption
AES-256 encryption at rest
Regular penetration testing
Intrusion detection and monitoring

Disease Reporting Requirements

DOH Integration
Real-time epidemiological reporting
Automated case classification
Outbreak investigation coordination
National surveillance database sync

Healthcare Quality Standards

PhilHealth
Clinical performance monitoring
Patient safety incident tracking
Service quality audits
Accreditation maintenance

Data Protection Policies (Accordion)

Patients provide explicit, informed consent for data processing at registration. This includes consent for:

  • Health record digitization and storage
  • Data sharing with authorized healthcare providers
  • Aggregated statistical reporting (with anonymization)
  • Research purposes (approved projects only)

Opt-Out Option: Patients may withdraw consent at any time. Historical data is archived but no new entries are created.

ScanCare maintains a structured data lifecycle:

  • Active Records: Kept for 5 years with regular access
  • Archive: Moved to secure backup after 5 years
  • Deletion: Permanent removal after 10 years (per RA 10173)
  • Special Cases: Extended retention for ongoing treatment tracking or legal cases

Patient Request: Right to deletion (RACCD) honored within 30 days, except where data is needed for ongoing care.

Every access to patient data is logged with timestamp, user ID, and action taken:

  • Role-based access: users can only view records relevant to their function
  • Unusual access patterns are automatically flagged and investigated
  • Quarterly audit reports submitted to barangay officials
  • Unauthorized access triggers immediate security alert and user suspension

Patient Transparency: Patients can request an audit log of who accessed their records and when.

In the event of a data breach or security incident:

  • Immediate containment and forensic investigation (within 24 hours)
  • Affected individuals notified within 72 hours (per RA 10173)
  • NPC (National Privacy Commission) notified if breach affects >100 individuals
  • Corrective actions documented and implemented
  • Regular breach drills and incident response tabletop exercises

Goal: Zero breaches through proactive security monitoring and rapid response protocols.

Philippine Laws & Regulatory Mandates

RA 10173

Data Privacy Act of 2012

Governs collection, processing, and storage of personal data in the Philippines.

  • Explicit patient consent for data processing
  • Encryption of all sensitive health records
  • Right to access, correction, and deletion
  • Annual privacy impact assessments
RA 11223

Universal Health Care Act

Mandates equitable health service delivery across all population groups.

  • Accessible primary health care to all
  • Integrated referral system to hospitals
  • Essential medicines availability
  • Free preventive care programs
RA 9994

Senior Citizens Welfare Act

Ensures healthcare and social services for citizens aged 60 and above.

  • Automatic age verification for 60+
  • Priority scheduling at health center
  • Discounted and free medicines tracking
  • Group support coordination

Third-Party Audits & Compliance Verification

Annual External Audits

  • 1 Data Privacy Impact Assessment (DPIA) conducted by independent auditors
  • 2 Cybersecurity Penetration Testing by certified ethical hackers
  • 3 ISO 27001 Compliance certification for information security management
  • 4 Healthcare Accreditation Review aligned with PhilHealth standards

Regulatory Agency Oversight

  • ✓ NPC (National Privacy Commission): Annual compliance reporting
  • ✓ DOH (Department of Health): Surveillance system audits
  • ✓ LGU Health Office: Quarterly operational reviews
  • ✓ PNP Cybercrime Unit: Security incident coordination