Data Governance

Value stream · Data Governance · a component of the Quality, Audit and Certification Center (CAC HCPL)

Data governance in healthcare is a matter of patient safety and continuity of care, not solely a task for the IT department. A healthcare provider must be able to answer five questions: what data it processes, who is accountable for it, who has access and on what legal basis, what its quality is, and how it flows — between hospital systems, between the hospital and the patient’s home, and across borders.

CAC
Place within the Foundation
Data Governance is a component of the Quality, Audit and Certification Center of HCPL. It combines quality audit methodology with data protection and information security audit, so that a hospital does not build three parallel compliance systems (GDPR, NIS2, EHDS) but one coherent management system. Director of the Center: Piotr Welenc.
GDPREHDS — Reg. (EU) 2025/327Polish Data Governance Act (DGA)NIS2 / Polish KSC ActAI Act — Art. 10ISO/IEC 27001ISO 27799HL7 FHIR · IPS

Scope of services

Data and data-flow mapInventory of health data sets, data categories, legal bases for processing, data processing agreements, and a named owner for every data set.
GDPR audit of a healthcare providerData-flow mapping, review of legal bases and processor agreements, assessment of technical and organisational measures, gap analysis and action plan.
EHDS readiness assessmentPrimary use (interoperability, patient summary, patient access to data) and secondary use (anonymisation, pseudonymisation, access protocols). Output: a readiness card with owners and deadlines.
Data governance frameworkRoles and accountability (data owner, DPO, IT, quality, data committee), data quality policy, retention, handling of patient consent and objections.
Information security and NIS2Gap analysis, a diagnostic questionnaire covering 130 hospital risk areas (NIS2/ENISA), mock inspection and remediation plan — in cooperation with the CyberC4HE Coalition.
Data quality for AI and researchAssessment of completeness, representativeness and provenance of data sets used in AI systems (Art. 10 AI Act), research projects and registries.
Training and micro-credentialsHealth data management, GDPR in hospitals, NIS2 for healthcare — for DPOs, medical records managers, IT, quality and management.
Oversight and accountability — board, data owners, DPO, data committeeCompliance — GDPR · NIS2 · EHDS · Data Governance Act · AI ActProcesses — consent, access, quality, retention, incidents, sharingHIS / EHRTelemedicineRemote accessCross-border exchange
Data governance as one system: oversight, compliance and processes cover every channel through which patient data flows.

Focus areas

Telemedicine and remote care

Teleconsultations, video consultations and remote monitoring (including glucose, INR and implantable devices) take data beyond hospital walls — into the patient’s home, onto personal devices and into vendor platforms. We assess patient identification and informed consent in the remote channel, documentation of the service in the electronic medical record, the legal status of platform and device vendors as processors, processing location and transfers outside the EEA, and procedures for loss of data transmission continuity.

The report “10 years of telemedicine development in Poland” (Telemedicine Working Group Foundation, 2026) identifies the lack of effective oversight of remote services as a systemic barrier and calls for a uniform organisational standard. A data governance audit is a practical instrument of that oversight on the provider side.

Remote access and remote management

Servicing of medical equipment, vendor support for systems, remote infrastructure monitoring and off-site administration are the channels through which breaches most often occur. We verify the register of external access, privileged accounts, multi-factor authentication, network segmentation, logging and supervision of service sessions, data clauses in service contracts, and VPN configuration against the recommendations of the Polish e-Health Centre (January 2025).

HIS/EHR systems — procurement, migration, open systems

The choice of a hospital information system determines data governance for years. We support buyers in defining requirements at the procurement and migration stage: interoperability (HL7 FHIR, integration with Poland’s national P1 platform), data portability and vendor exit terms, event logging, backup and recovery, and the division of controller and processor roles. We also assess open-source solutions — including licence compliance and the maintenance model — while remaining vendor-neutral.

Cross-border data exchange

A patient treated in another country needs complete records before arrival and after return. We assess a facility’s preparedness to exchange patient summaries and ePrescriptions through the MyHealth@EU infrastructure, and the flow of records in cross-border care — in connection with the Medical Tourism (MEDiTOUR) value stream.

How we work

  1. Initial audit — meeting with management, document review, preliminary risk assessment.
  2. Gap analysis — mapping the current state against GDPR, NIS2 and EHDS requirements; priorities and effort estimate.
  3. Action plan — schedule, owners, budget and possible funding sources.
  4. Implementation support — policies, procedures, registers, staff training.
  5. Final assessment — mock inspection and a report with observations and corrective actions.

The scope is matched to the size of the organisation: a full programme for university hospitals, legal compliance modules for county hospitals, simplified packages and group training for small facilities.

Regulatory calendar

3 Apr 2026NIS2 (KSC)in force23 Jul 2026Polish DataGovernance Act3 Oct 2026KSC entityregistrationMar–Apr 2027EHDS general applicationKSC: ISMS in place2 Dec 2027AI Act:high-risk systems26 Mar 2029EHDS: patientsummary, ePrescription26 Mar 2031EHDS: images,lab, discharge
Upcoming deadlines shaping the data and information security obligations of healthcare providers.
ActStatus and deadlines
Amendment to the Polish National Cybersecurity System Act (NIS2 transposition)In force since 3 April 2026; registration applications of essential and important entities by 3 October 2026; information security management system in place by 3 April 2027; first audit of essential entities by 3 April 2028.
Polish Data Governance Act (implementing the EU Data Governance Act)In force since 23 July 2026; data intermediation services and data altruism organisations supervised by the President of the Polish Data Protection Office (UODO).
Regulation (EU) 2025/327 on the European Health Data SpaceIn force since 26 March 2025; general application from 26 March 2027; exchange of patient summaries and ePrescriptions and most secondary-use rules from 26 March 2029; medical images, laboratory results and discharge reports from 26 March 2031.
AI Act as amended by the Digital Omnibus on AI (in force since 27 July 2026)Obligations for stand-alone high-risk systems (Annex III) from 2 December 2027; for AI in regulated products (Annex I) from 2 August 2028.

Links within the HCPL ecosystem

Principles of the component

  • Independence. We do not assess solutions that we recommend or supply ourselves; the auditor role is separated from the trainer role for the same organisation.
  • Nature of the assessment. Audit results are advisory assessments. The Foundation is neither a supervisory authority nor a notified body — its assessment does not replace inspections by public authorities or certification within the meaning of the law.
  • Proportionality. Requirements match the size and risk profile of the organisation.
  • Just Culture. A data incident is a source of organisational learning, not a search for someone to blame; accountability remains clearly assigned.
  • Patient at the centre. Data serves treatment and patient safety; every access must have a basis, a purpose and a trace.
Contact
Quality, Audit and Certification Center of HCPL — Piotr Welenc, Director of the Center: p.welenc@healthcarepoland.pl · Healthcare Poland Foundation: global@healthcarepoland.pl