Guide

How is health data protected?

Employee health records are special-category data; access is narrowed, retention is defined and handover is recorded.

Why a separate regime

Health data cannot be processed like an ordinary personnel record. Who may access it, how long it is kept and what happens when the relationship ends are defined in advance. Without those definitions, the data is not in fact protected.

Narrowing access

The fitness conclusion of an examination and the clinical detail are not held at the same access level. What goes to the employer is fitness for work; diagnosis and test detail stay with the physician. If that separation is not built technically, a policy document alone is not enough.

Retention and destruction

A retention period is set for each record type; data past its period is destroyed by a defined procedure. Indefinite retention is a sign of neglect, not of protection.

When the relationship ends

When the service relationship ends, records are delivered to the employer. What happens to the copy in the provider's system afterwards is decided in writing, and its application is recorded.

In Optifora

Health surveillance data is visible under separate permissions; access is logged, retention is defined, and which records were delivered at handover is listed.

  1. Separate data typesClassify health data separately from other records.
  2. Define accessBuild technically who may see what.
  3. Set retentionWrite a period and a destruction procedure for each record type.
  4. Log accessKeep who accessed what and when traceable.
  5. Plan the handoverDecide in writing delivery and the fate of copies when the relationship ends.
  6. Verify practiceCheck periodically that what is defined is actually applied.

Manage this in Optifora

Optifora is not a single program but a compliance platform assembled from modules. The catalogue states which module is ready today and which is on the roadmap.

See what Optifora is