DPDP Insights › Questions › Imaging machines and lab analysers hold patient data. What d
Question · Healthcare and hospitals
Imaging machines and lab analysers hold patient data. What do we do?
Short answer: Separate network, controlled vendor access, wipe before disposal
Imaging and lab devices store names, ages and results, often on old operating systems. Put them on a separate network, control vendor remote access, change default passwords, and wipe disks before a device is returned or scrapped.
What the law says
Rule 6 safeguards apply to devices that store personal data.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Section 8(7) · Rule 8: Erase personal data when its purpose is over or consent is withdrawn, unless a law requires you to keep it, and have your processors erase it too. Rule 8(3) asks every Data Fiduciary to keep personal data, traffic data and logs for at least one year for purposes listed in the Rules.
Steps
List devices that store patient data.
Segment them.
Control vendor remote access.
Change default passwords.
Wipe before disposal.
Evidence to keep
Device list
Network diagram
Wipe certificates
Common mistakes
Devices on the general network
Vendor modems always on
Disks leaving with old machines
From each seat
CISO / Security head: Segmentation is your priority.
CIO / IT head: Plan upgrades for old device software.
IT department: Keep the device list.
Procurement department: Add wipe clauses to device contracts.
What a good answer from management sounds like
“Devices are segmented, vendor access is controlled and disks are wiped before disposal.” Effort and time: Medium to heavy.