DPO Radio

AesirX ComplianceOne | Vietnam Health Data

Overview Image

Why Decree 102 Matters

Decree 102/2025/NĐ-CP was issued by the Government of Vietnam on 13 May 2025 and took effect on 1 July 2025. The Ministry of Health is the lead authority. It is an active healthcare-sector overlay governing the access, quality, sharing, and interoperability of health data, an operational layer that sits above shared obligations rather than replacing them.

The decree binds healthcare facilities, health-data platforms, medical examination and treatment providers, health-insurance-related processors, medtech and health-app providers, and other organizations processing health-sector data. Within that scope it asks for a health-data inventory mapped to the relevant healthcare databases, assigned ownership and access controls for national, specialised, and shared healthcare databases, evidenced readiness for electronic health-record and national digital-identity integration where applicable, authorized and audited access and use decisions, and evidenced connection and sharing arrangements with their recipients and safeguards.

Because health data is also personal data, the decree explicitly cross-links rather than duplicates neighbouring frameworks: personal and sensitive health-data processing maps to the Personal Data Protection Law and Decree 356/2025/NĐ-CP, broader data-governance obligations map to the Data Law and Decree 165/2025/NĐ-CP and the Decision 20 core-data list, and technical safeguards map to the Cybersecurity Law. It is an opt-in pack, organizations outside the declared scope can install it in reference mode, which produces no deadlines, score contribution, or automated workflows.

ComplianceOne keeps this overlay connected to those horizontal frameworks without flattening any of their separate legal roles, so healthcare-specific evidence stays distinct from, and linkable to, the underlying data-protection and cybersecurity work it depends on.

What Decree 102 Covers

Dimension

Coverage

Instrument

Decree 102/2025/NĐ-CP, issued 13 May 2025, effective 1 July 2025, Ministry of Health as lead authority.

Scope

Healthcare facilities, health-data platforms, medical exam/treatment providers, health-insurance-related processors, medtech and health-app providers, and organizations processing health-sector data.

Operational themes

Health-data inventory and domain mapping; healthcare database governance; EHR/national-ID integration readiness; access and use authorization; connection and sharing evidence; accuracy and quality controls; PDPL/Data Law/cybersecurity cross-linking.

Evidence

Data inventories, patient-data mappings, sharing decisions, access records, and control evidence across 8 tracked obligations.

Official forms

No official form has been verified against the checked Decree 102 Gazette text, appendices, or linked Ministry of Health procedure references; the pack's 9 templates are internal working documents.

Fines

ComplianceOne does not record monetary fine amounts for this instrument.

Status

Active, optional healthcare sector overlay, direct mode for in-scope organizations, reference mode for others.

Overview Image

How ComplianceOne Supports Decree 102

ComplianceOne helps healthcare teams maintain the health-data inventory and the 24-domain mapping as governed records rather than a spreadsheet, with ownership, review, and evidence attached to each entry. Healthcare database governance records, for national, specialised, and shared databases, carry their control description, implementation, and accountable owner.

Where the decree calls for electronic health-record and national digital-identity integration readiness, the platform tracks that evidence alongside access-and-use authorization records, so lawful access, use, and exploitation decisions keep their approval and audit trail. Connection and sharing records document recipients and security safeguards for each interconnection.

Because sensitive health data also falls under the Personal Data Protection Law, the platform links health-data evidence to the relevant PDPL, Data Law, and cybersecurity records without duplicating those parent obligations or changing their legal status. Reviewers can trace a piece of health-data evidence back to the sector overlay and forward to the horizontal framework it also serves.

Related Modules

Data MappingData Mapping

Maintains the health-data inventory and 24-domain mapping, with data flows, sources, recipients, and cross-framework references.

Explore Data Mapping

Data ClassificationData Classification

Distinguishes sensitive health and patient data from general operational data for downstream handling decisions.

Explore Data Classification

Access & AccountabilityAccess & Accountability

Records authorized access-and-use decisions for healthcare databases with an accountable owner per control.

Explore Access & Accountability

Audit TrailAudit Trail

Preserves contributor, review, approval, sending, and response history.

Explore Audit Trail

Compare the Difference

Graphic Image

Without Structured Framework Operations

Graphic Image

With ComplianceOne

IconHealth-data inventories are not mapped to the national, specialised, and shared healthcare databases they belong to.
IconMaintain the health-data inventory and domain mapping as governed records with ownership and evidence attached.
IconDatabase ownership, update, and access controls are undocumented across national and shared healthcare systems.
IconAssign ownership, quality, and access controls to national, specialised, and shared healthcare databases.
IconEHR and national digital-identity integration readiness has no evidence trail.
IconTrack EHR and national digital-identity integration readiness as its own evidence type.
IconAccess, use, and sharing decisions for health data are undocumented and hard to reconstruct on request.
IconRecord access, use, and connection/sharing decisions with an accountable owner and audit trail.
IconSensitive health-data processing is tracked separately from the PDPL and Data Law evidence it depends on.
IconCross-link sensitive health-data records to PDPL, Data Law, and cybersecurity evidence without duplicating them.

Built for Identity Law Compliance Operations

Build For Image

Installing the overlay in reference mode lets a team outside declared healthcare scope review Decree 102's requirements without generating deadlines or affecting a compliance score, so browsing carries no operational commitment.

Build For Image

National, specialised, and shared healthcare databases each keep their own control description, implementation, and accountable owner, so oversight doesn't collapse into a single record covering systems with different risk profiles.

Build For Image

Readiness evidence for electronic health-record and national digital-identity integration is tracked as its own record type; the platform organizes that evidence and provides no clinical functionality of its own.

Background Image

See Decree 102 Compliance in Action

See how ComplianceOne helps structure health-data evidence, ownership, and review for this framework.

Demo Image
Ronni K. Gothard Christiansen

Ronni K. Gothard Christiansen - Technical Privacy Engineer & CEO

Technical Compliance Expert, 32+ Years Open Source Advocate, X-BoD Open Source Matters Inc.

Or contact via

ronni@aesirx.io+84 909 500 760

People Also Ask

Healthcare facilities, health-data platforms, medical examination and treatment providers, health-insurance-related processors, medtech and health-app providers, and other organizations processing health-sector data. Organizations outside this scope can still install the pack in reference mode.

Reference mode is the default outside declared healthcare scope. It lets you browse the framework's requirements and evidence templates without generating deadlines, contributing to a compliance score, or triggering automated workflows.

The health-data inventory and 24-domain mapping templates ask for the organizational unit, the scope of the inventory, the data elements and categories covered, data flows with sources, recipients, and storage locations, cross-references to related frameworks, and a responsible person with a review date and status.

No. No official form has been verified against the checked Decree 102 Gazette text, its appendices, or linked Ministry of Health procedure references. The pack's 9 templates are internal ComplianceOne working documents for organizing evidence, not government forms.

Sensitive and personal health-data processing is cross-linked to the relevant Personal Data Protection Law and Decree 356/2025/NĐ-CP evidence rather than governed a second time, so healthcare-specific records stay connected to — but distinct from — the underlying data-protection work.

No. ComplianceOne does not record monetary fine amounts for this instrument. Confirm any penalty figures against the official Decree 102 text.

It tracks readiness and evidence for electronic health-record and national digital-identity integration where the decree calls for it. It does not provide clinical functionality or connect to production EHR systems.

 

Yes. The healthcare database governance and mapping records let each database record its own control description, implementation, and accountable owner, so national, specialised, and shared systems don't share a single undifferentiated control.

 

Next Steps

Icon Image

Start a Compliance Pilot

Test scoped workflows, evidence, and review with your compliance team.

Icon Image

Discuss Your Compliance Needs

Review applicability, evidence sources, and operating-model requirements.