
Nearly 1.7 million people work in healthcare in the Netherlands. Yet the sector continues to face significant staff shortages. These shortages create new challenges for healthcare executives and HR professionals. In practice, we see that this can, for example, result in healthcare workers being hired who later turn out not to be sufficiently suited for working in healthcare. In this blog series, we discuss various employment law issues that may arise throughout the employment journey, from the recruitment process through to the end of the employment relationship.
Healthcare organisations process large amounts of sensitive personal data relating to patients. Given the sensitive nature of patient information and the risks patients face if such data is not handled carefully, the processing of healthcare workers' data is subject to more extensive information security requirements than in many other sectors. Examples include the mandatory recording of detailed access logs (recording all actions performed involving patient data in, for example, an electronic health record system in accordance with NEN 7513), the proactive and periodic review of these logs, and the obligation to retain such records for at least five years.
The increased focus on information security does not only follow from legislation and regulations, but is also reflected in, for example, enforcement decisions by the privacy regulator.
New legislation is also being introduced in the field of information security, including for healthcare providers: the NIS2 Directive/Cybersecurity Act. Under the NIS2/Cybersecurity Act, certain obligations and responsibilities will apply to healthcare providers and their directors.
For HR departments, this may mean, among other things, that they will need to ensure that healthcare workers are informed about all relevant policies and procedures when they start working, play a role in maintaining employees' and directors' knowledge of cyber hygiene and cybersecurity, and generally contribute to "personnel-related security aspects". This may include involvement in employee screening processes.
The Cybersecurity Act has not yet been finalised or entered into force.
In de praktijk merken we dat op privacy gebied in de zorg niet alleen extra verplichtingen voor medewerkersgegevens gelden, maar ook dat er vaak bepaalde uitdagingen ontstaan waarbij specifiek de privacy van zorgmedewerkers in het geding kan komen. Vraagstukken die wij bijvoorbeeld regelmatig in de zorgsector voorbij zien komen zijn:
In practice, we see that privacy in healthcare does not only involve additional obligations relating to employee data, but also specific challenges where the privacy of healthcare workers themselves may be at stake. Examples of issues regularly arising in the healthcare sector include:
No. Additional obligations mainly apply in the area of information security and the use of employee data. However, there are no additional requirements for matters such as ordinary personnel administration beyond the usual employment law and privacy law frameworks.
The general privacy obligations also apply to healthcare workers. This means, among other things, that employees must know how their personal data is processed, that organisations may not process or retain more employee data than necessary, that processing must have a valid legal basis, and that data may not be used for unrelated purposes without justification.
HR has an important role in, for example, ensuring that employee data is not shared unnecessarily, that data is used carefully, and that HR contributes to essential privacy documentation. This includes documents such as employee privacy statements, data retention policies, agreements with HR service providers (such as IT suppliers, occupational health services, and insurers), and carrying out risk assessments (for example, a Data Protection Impact Assessment (DPIA) for an absence management process or a new HR system).
Privacy in healthcare is a highly regulated area, with information security being a particular focus. In addition, we see that certain privacy issues regularly require attention in practice. It is therefore essential for HR professionals in healthcare to understand the relevant legal frameworks and to know where employees can turn with privacy-related questions and concerns.
Do you have questions about privacy in healthcare? Please contact Michelle Wijnant.
Blog Series: HR in Healthcare
Would you like to receive a monthly overview of updates and blogs in your inbox? Then sign up for our newsletter!