DPO Radio

Decree 102/2025/NĐ-CP was issued by the Government of Vietnam on 13 May 2025 and took effect on 1 July 2025. The Ministry of Health is the lead authority. It is an active healthcare-sector overlay governing the access, quality, sharing, and interoperability of health data, an operational layer that sits above shared obligations rather than replacing them.
The decree binds healthcare facilities, health-data platforms, medical examination and treatment providers, health-insurance-related processors, medtech and health-app providers, and other organizations processing health-sector data. Within that scope it asks for a health-data inventory mapped to the relevant healthcare databases, assigned ownership and access controls for national, specialised, and shared healthcare databases, evidenced readiness for electronic health-record and national digital-identity integration where applicable, authorized and audited access and use decisions, and evidenced connection and sharing arrangements with their recipients and safeguards.
Because health data is also personal data, the decree explicitly cross-links rather than duplicates neighbouring frameworks: personal and sensitive health-data processing maps to the Personal Data Protection Law and Decree 356/2025/NĐ-CP, broader data-governance obligations map to the Data Law and Decree 165/2025/NĐ-CP and the Decision 20 core-data list, and technical safeguards map to the Cybersecurity Law. It is an opt-in pack, organizations outside the declared scope can install it in reference mode, which produces no deadlines, score contribution, or automated workflows.
ComplianceOne keeps this overlay connected to those horizontal frameworks without flattening any of their separate legal roles, so healthcare-specific evidence stays distinct from, and linkable to, the underlying data-protection and cybersecurity work it depends on.
Decree 102/2025/NĐ-CP, issued 13 May 2025, effective 1 July 2025, Ministry of Health as lead authority.
Healthcare facilities, health-data platforms, medical exam/treatment providers, health-insurance-related processors, medtech and health-app providers, and organizations processing health-sector data.
Health-data inventory and domain mapping; healthcare database governance; EHR/national-ID integration readiness; access and use authorization; connection and sharing evidence; accuracy and quality controls; PDPL/Data Law/cybersecurity cross-linking.
Data inventories, patient-data mappings, sharing decisions, access records, and control evidence across 8 tracked obligations.
No official form has been verified against the checked Decree 102 Gazette text, appendices, or linked Ministry of Health procedure references; the pack's 9 templates are internal working documents.
ComplianceOne does not record monetary fine amounts for this instrument.
Active, optional healthcare sector overlay, direct mode for in-scope organizations, reference mode for others.

ComplianceOne helps healthcare teams maintain the health-data inventory and the 24-domain mapping as governed records rather than a spreadsheet, with ownership, review, and evidence attached to each entry. Healthcare database governance records, for national, specialised, and shared databases, carry their control description, implementation, and accountable owner.
Where the decree calls for electronic health-record and national digital-identity integration readiness, the platform tracks that evidence alongside access-and-use authorization records, so lawful access, use, and exploitation decisions keep their approval and audit trail. Connection and sharing records document recipients and security safeguards for each interconnection.
Because sensitive health data also falls under the Personal Data Protection Law, the platform links health-data evidence to the relevant PDPL, Data Law, and cybersecurity records without duplicating those parent obligations or changing their legal status. Reviewers can trace a piece of health-data evidence back to the sector overlay and forward to the horizontal framework it also serves.
Maintains the health-data inventory and 24-domain mapping, with data flows, sources, recipients, and cross-framework references.
Explore Data MappingDistinguishes sensitive health and patient data from general operational data for downstream handling decisions.
Explore Data ClassificationRecords authorized access-and-use decisions for healthcare databases with an accountable owner per control.
Explore Access & AccountabilityPreserves contributor, review, approval, sending, and response history.
Explore Audit Trail


Installing the overlay in reference mode lets a team outside declared healthcare scope review Decree 102's requirements without generating deadlines or affecting a compliance score, so browsing carries no operational commitment.

National, specialised, and shared healthcare databases each keep their own control description, implementation, and accountable owner, so oversight doesn't collapse into a single record covering systems with different risk profiles.

Readiness evidence for electronic health-record and national digital-identity integration is tracked as its own record type; the platform organizes that evidence and provides no clinical functionality of its own.
See how ComplianceOne helps structure health-data evidence, ownership, and review for this framework.

Healthcare facilities, health-data platforms, medical examination and treatment providers, health-insurance-related processors, medtech and health-app providers, and other organizations processing health-sector data. Organizations outside this scope can still install the pack in reference mode.
Reference mode is the default outside declared healthcare scope. It lets you browse the framework's requirements and evidence templates without generating deadlines, contributing to a compliance score, or triggering automated workflows.
The health-data inventory and 24-domain mapping templates ask for the organizational unit, the scope of the inventory, the data elements and categories covered, data flows with sources, recipients, and storage locations, cross-references to related frameworks, and a responsible person with a review date and status.
No. No official form has been verified against the checked Decree 102 Gazette text, its appendices, or linked Ministry of Health procedure references. The pack's 9 templates are internal ComplianceOne working documents for organizing evidence, not government forms.
Sensitive and personal health-data processing is cross-linked to the relevant Personal Data Protection Law and Decree 356/2025/NĐ-CP evidence rather than governed a second time, so healthcare-specific records stay connected to — but distinct from — the underlying data-protection work.
No. ComplianceOne does not record monetary fine amounts for this instrument. Confirm any penalty figures against the official Decree 102 text.
It tracks readiness and evidence for electronic health-record and national digital-identity integration where the decree calls for it. It does not provide clinical functionality or connect to production EHR systems.
Yes. The healthcare database governance and mapping records let each database record its own control description, implementation, and accountable owner, so national, specialised, and shared systems don't share a single undifferentiated control.

Test scoped workflows, evidence, and review with your compliance team.

Review applicability, evidence sources, and operating-model requirements.