DPO Radio

Decree 102/2025/NĐ-CP was issued by the Government of Vietnam on 13 May 2025 and took effect on 1 July 2025. The Ministry of Health is the lead authority. It is an active healthcare-sector overlay governing the access, quality, sharing, and interoperability of health data, an operational layer that sits above shared obligations rather than replacing them.
The decree binds healthcare facilities, health-data platforms, medical examination and treatment providers, health-insurance-related processors, medtech and health-app providers, and other organizations processing health-sector data. Within that scope it asks for a health-data inventory mapped to the relevant healthcare databases, assigned ownership and access controls for national, specialised, and shared healthcare databases, evidenced readiness for electronic health-record and national digital-identity integration where applicable, authorized and audited access and use decisions, and evidenced connection and sharing arrangements with their recipients and safeguards.
Because health data is also personal data, the decree explicitly cross-links rather than duplicates neighbouring frameworks: personal and sensitive health-data processing maps to the Personal Data Protection Law and Decree 356/2025/NĐ-CP, broader data-governance obligations map to the Data Law and Decree 165/2025/NĐ-CP and the Decision 20 core-data list, and technical safeguards map to the Cybersecurity Law. It is an opt-in pack, organizations outside the declared scope can install it in reference mode, which produces no deadlines, score contribution, or automated workflows.
ComplianceOne keeps this overlay connected to those horizontal frameworks without flattening any of their separate legal roles, so healthcare-specific evidence stays distinct from, and linkable to, the underlying data-protection and cybersecurity work it depends on.
Decree 102/2025/NĐ-CP, issued 13 May 2025, effective 1 July 2025, Ministry of Health as lead authority.
Healthcare facilities, health-data platforms, medical exam/treatment providers, health-insurance-related processors, medtech and health-app providers, and organizations processing health-sector data.
Health-data inventory and domain mapping; healthcare database governance; EHR/national-ID integration readiness; access and use authorization; connection and sharing evidence; accuracy and quality controls; PDPL/Data Law/cybersecurity cross-linking.
Data inventories, patient-data mappings, sharing decisions, access records, and control evidence across 8 tracked obligations.
No official form has been verified against the checked Decree 102 Gazette text, appendices, or linked Ministry of Health procedure references; the pack's 9 templates are internal working documents.
ComplianceOne does not record monetary fine amounts for this instrument.
Active, optional healthcare sector overlay, direct mode for in-scope organizations, reference mode for others.

ComplianceOne helps healthcare teams maintain the health-data inventory and the 24-domain mapping as governed records rather than a spreadsheet, with ownership, review, and evidence attached to each entry. Healthcare database governance records, for national, specialised, and shared databases, carry their control description, implementation, and accountable owner.
Where the decree calls for electronic health-record and national digital-identity integration readiness, the platform tracks that evidence alongside access-and-use authorization records, so lawful access, use, and exploitation decisions keep their approval and audit trail. Connection and sharing records document recipients and security safeguards for each interconnection.
Because sensitive health data also falls under the Personal Data Protection Law, the platform links health-data evidence to the relevant PDPL, Data Law, and cybersecurity records without duplicating those parent obligations or changing their legal status. Reviewers can trace a piece of health-data evidence back to the sector overlay and forward to the horizontal framework it also serves.
Maintains the health-data inventory and 24-domain mapping, with data flows, sources, recipients, and cross-framework references.
Explore Data MappingDistinguishes sensitive health and patient data from general operational data for downstream handling decisions.
Explore Data ClassificationRecords authorized access-and-use decisions for healthcare databases with an accountable owner per control.
Explore Access & AccountabilityPreserves contributor, review, approval, sending, and response history.
Explore Audit Trail


Status and scope remain visible throughout the workflow.

Authority-issued and platform-prepared artifacts retain clear source labels.

Contributor, reviewer, approval, and evidence history stays connected.
See how ComplianceOne helps structure evidence, ownership, and review for this framework.

No. The page addresses compliance operations and health-data governance only.
No official forms were verified in the checked decree, appendices, or linked procedure sources; the pack’s templates are internal.
No. It adds healthcare context and cross-links those horizontal frameworks.
It supports health-record and system evidence where relevant to the implemented pack, without claiming clinical functionality.

Test scoped workflows, evidence, and review with your compliance team.

Review applicability, evidence sources, and operating-model requirements.