DPO Radio

Measure Value, Not Just Traffic Explore new features in AesirX Analytics

AesirX ComplianceOne | Vietnam Health Data

Overview Image

Why Decree 102 Matters

Decree 102/2025/NĐ-CP was issued by the Government of Vietnam on 13 May 2025 and took effect on 1 July 2025. The Ministry of Health is the lead authority. It is an active healthcare-sector overlay governing the access, quality, sharing, and interoperability of health data, an operational layer that sits above shared obligations rather than replacing them.

The decree binds healthcare facilities, health-data platforms, medical examination and treatment providers, health-insurance-related processors, medtech and health-app providers, and other organizations processing health-sector data. Within that scope it asks for a health-data inventory mapped to the relevant healthcare databases, assigned ownership and access controls for national, specialised, and shared healthcare databases, evidenced readiness for electronic health-record and national digital-identity integration where applicable, authorized and audited access and use decisions, and evidenced connection and sharing arrangements with their recipients and safeguards.

Because health data is also personal data, the decree explicitly cross-links rather than duplicates neighbouring frameworks: personal and sensitive health-data processing maps to the Personal Data Protection Law and Decree 356/2025/NĐ-CP, broader data-governance obligations map to the Data Law and Decree 165/2025/NĐ-CP and the Decision 20 core-data list, and technical safeguards map to the Cybersecurity Law. It is an opt-in pack, organizations outside the declared scope can install it in reference mode, which produces no deadlines, score contribution, or automated workflows.

ComplianceOne keeps this overlay connected to those horizontal frameworks without flattening any of their separate legal roles, so healthcare-specific evidence stays distinct from, and linkable to, the underlying data-protection and cybersecurity work it depends on.

What Decree 102 Covers

Dimension

Coverage

Instrument

Decree 102/2025/NĐ-CP, issued 13 May 2025, effective 1 July 2025, Ministry of Health as lead authority.

Scope

Healthcare facilities, health-data platforms, medical exam/treatment providers, health-insurance-related processors, medtech and health-app providers, and organizations processing health-sector data.

Operational themes

Health-data inventory and domain mapping; healthcare database governance; EHR/national-ID integration readiness; access and use authorization; connection and sharing evidence; accuracy and quality controls; PDPL/Data Law/cybersecurity cross-linking.

Evidence

Data inventories, patient-data mappings, sharing decisions, access records, and control evidence across 8 tracked obligations.

Official forms

No official form has been verified against the checked Decree 102 Gazette text, appendices, or linked Ministry of Health procedure references; the pack's 9 templates are internal working documents.

Fines

ComplianceOne does not record monetary fine amounts for this instrument.

Status

Active, optional healthcare sector overlay, direct mode for in-scope organizations, reference mode for others.

Overview Image

How ComplianceOne Supports Decree 102

ComplianceOne helps healthcare teams maintain the health-data inventory and the 24-domain mapping as governed records rather than a spreadsheet, with ownership, review, and evidence attached to each entry. Healthcare database governance records, for national, specialised, and shared databases, carry their control description, implementation, and accountable owner.

Where the decree calls for electronic health-record and national digital-identity integration readiness, the platform tracks that evidence alongside access-and-use authorization records, so lawful access, use, and exploitation decisions keep their approval and audit trail. Connection and sharing records document recipients and security safeguards for each interconnection.

Because sensitive health data also falls under the Personal Data Protection Law, the platform links health-data evidence to the relevant PDPL, Data Law, and cybersecurity records without duplicating those parent obligations or changing their legal status. Reviewers can trace a piece of health-data evidence back to the sector overlay and forward to the horizontal framework it also serves.

Related Modules

Data MappingData Mapping

Maintains the health-data inventory and 24-domain mapping, with data flows, sources, recipients, and cross-framework references.

Explore Data Mapping

Data ClassificationData Classification

Distinguishes sensitive health and patient data from general operational data for downstream handling decisions.

Explore Data Classification

Access & AccountabilityAccess & Accountability

Records authorized access-and-use decisions for healthcare databases with an accountable owner per control.

Explore Access & Accountability

Audit TrailAudit Trail

Preserves contributor, review, approval, sending, and response history.

Explore Audit Trail

Compare the Difference

Graphic Image

Without Structured Framework Operations

Graphic Image

With ComplianceOne

IconHealth-data obligations are mixed with generic data controls.
IconApply healthcare-specific governance to shared controls.
IconPatient and system evidence lacks sector context.
IconConnect patient-data and system records to accountable owners.
IconSharing decisions are difficult to reconstruct.
IconPreserve health-data sharing decisions and review evidence.
IconHealthcare database ownership is inconsistently assigned.
IconAssign ownership across healthcare databases.
IconCross-framework evidence is duplicated across compliance teams.
IconCross-link PDPL, Data Law, and cybersecurity evidence without duplication.

Built for Identity Law Compliance Operations

Build For Image

Status and scope remain visible throughout the workflow.

Build For Image

Authority-issued and platform-prepared artifacts retain clear source labels.

Build For Image

Contributor, reviewer, approval, and evidence history stays connected.

Background Image

See Decree 102 Compliance in Action

See how ComplianceOne helps structure evidence, ownership, and review for this framework.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

No. Direct mode is intended for organizations within the declared healthcare scope; others may use reference mode.

No. The page addresses compliance operations and health-data governance only.

No official forms were verified in the checked decree, appendices, or linked procedure sources; the pack’s templates are internal.

No. It adds healthcare context and cross-links those horizontal frameworks.

It supports health-record and system evidence where relevant to the implemented pack, without claiming clinical functionality.

Next Steps

Icon Image

Start a Compliance Pilot

Test scoped workflows, evidence, and review with your compliance team.

Icon Image

Discuss Your Compliance Needs

Review applicability, evidence sources, and operating-model requirements.