Value stream · Data Governance · a component of the Quality, Audit and Certification Center (CAC HCPL)
Data governance in healthcare is a matter of patient safety and continuity of care, not solely a task for the IT department. A healthcare provider must be able to answer five questions: what data it processes, who is accountable for it, who has access and on what legal basis, what its quality is, and how it flows — between hospital systems, between the hospital and the patient’s home, and across borders.
Data Governance is a component of the Quality, Audit and Certification Center of HCPL. It combines quality audit methodology with data protection and information security audit, so that a hospital does not build three parallel compliance systems (GDPR, NIS2, EHDS) but one coherent management system. Director of the Center: Piotr Welenc.
Scope of services
Focus areas
Telemedicine and remote care
Teleconsultations, video consultations and remote monitoring (including glucose, INR and implantable devices) take data beyond hospital walls — into the patient’s home, onto personal devices and into vendor platforms. We assess patient identification and informed consent in the remote channel, documentation of the service in the electronic medical record, the legal status of platform and device vendors as processors, processing location and transfers outside the EEA, and procedures for loss of data transmission continuity.
The report “10 years of telemedicine development in Poland” (Telemedicine Working Group Foundation, 2026) identifies the lack of effective oversight of remote services as a systemic barrier and calls for a uniform organisational standard. A data governance audit is a practical instrument of that oversight on the provider side.
Remote access and remote management
Servicing of medical equipment, vendor support for systems, remote infrastructure monitoring and off-site administration are the channels through which breaches most often occur. We verify the register of external access, privileged accounts, multi-factor authentication, network segmentation, logging and supervision of service sessions, data clauses in service contracts, and VPN configuration against the recommendations of the Polish e-Health Centre (January 2025).
HIS/EHR systems — procurement, migration, open systems
The choice of a hospital information system determines data governance for years. We support buyers in defining requirements at the procurement and migration stage: interoperability (HL7 FHIR, integration with Poland’s national P1 platform), data portability and vendor exit terms, event logging, backup and recovery, and the division of controller and processor roles. We also assess open-source solutions — including licence compliance and the maintenance model — while remaining vendor-neutral.
Cross-border data exchange
A patient treated in another country needs complete records before arrival and after return. We assess a facility’s preparedness to exchange patient summaries and ePrescriptions through the MyHealth@EU infrastructure, and the flow of records in cross-border care — in connection with the Medical Tourism (MEDiTOUR) value stream.
How we work
- Initial audit — meeting with management, document review, preliminary risk assessment.
- Gap analysis — mapping the current state against GDPR, NIS2 and EHDS requirements; priorities and effort estimate.
- Action plan — schedule, owners, budget and possible funding sources.
- Implementation support — policies, procedures, registers, staff training.
- Final assessment — mock inspection and a report with observations and corrective actions.
The scope is matched to the size of the organisation: a full programme for university hospitals, legal compliance modules for county hospitals, simplified packages and group training for small facilities.
Regulatory calendar
| Act | Status and deadlines |
|---|---|
| Amendment to the Polish National Cybersecurity System Act (NIS2 transposition) | In force since 3 April 2026; registration applications of essential and important entities by 3 October 2026; information security management system in place by 3 April 2027; first audit of essential entities by 3 April 2028. |
| Polish Data Governance Act (implementing the EU Data Governance Act) | In force since 23 July 2026; data intermediation services and data altruism organisations supervised by the President of the Polish Data Protection Office (UODO). |
| Regulation (EU) 2025/327 on the European Health Data Space | In force since 26 March 2025; general application from 26 March 2027; exchange of patient summaries and ePrescriptions and most secondary-use rules from 26 March 2029; medical images, laboratory results and discharge reports from 26 March 2031. |
| AI Act as amended by the Digital Omnibus on AI (in force since 27 July 2026) | Obligations for stand-alone high-risk systems (Annex III) from 2 December 2027; for AI in regulated products (Annex I) from 2 August 2028. |
Links within the HCPL ecosystem
- Quality, Audit and Certification Center (CAC HCPL) — parent unit: audit methodology, mock inspections, micro-credentials.
- CyberC4HE Coalition — hospital cybersecurity, NIS2 diagnostics, cooperation with solution providers.
- Coordinated Care Center — data flows between levels of care and in home care.
- Medical Tourism (MEDiTOUR) — patient records and data in cross-border care.
- Innovation Center — data in research projects, pilots and regulatory sandboxes.
- The European HeliX project (grant agreement No. 101228287), in which the Foundation is the Polish partner — experience in data management within a European consortium and in EHDS preparation.
Principles of the component
- Independence. We do not assess solutions that we recommend or supply ourselves; the auditor role is separated from the trainer role for the same organisation.
- Nature of the assessment. Audit results are advisory assessments. The Foundation is neither a supervisory authority nor a notified body — its assessment does not replace inspections by public authorities or certification within the meaning of the law.
- Proportionality. Requirements match the size and risk profile of the organisation.
- Just Culture. A data incident is a source of organisational learning, not a search for someone to blame; accountability remains clearly assigned.
- Patient at the centre. Data serves treatment and patient safety; every access must have a basis, a purpose and a trace.
Quality, Audit and Certification Center of HCPL — Piotr Welenc, Director of the Center: p.welenc@healthcarepoland.pl · Healthcare Poland Foundation: global@healthcarepoland.pl