GDPR Case Study # 2
https://saloniq.com/files/2018/01/xgdpr-for-salons-300x221.jpg.pagespeed.ic.6KhKuQLGzL.jpg

GDPR Case Study # 2

Hi Folks, here is the second case study in the sequence that I've planned to publish. Incidentally, the heat is just on and would become hotter when regulatory push starts. It's going to be lots of anxiety on many fronts...! I'm watching...! You can join as well...!

A HIPAA compliant European Healthcare company Oasis Medico has outsourced its patient insurance claim services to a company in India. The Indian IT company Health-O-Big runs the back end services with exclusive team supporing Oasis Medico

When one of the key stakeholders of Oasis Medico was reviewing its GDPR compliance, she asked whether the Indian IT company is compliant to GDPR requirements. The Oasis Medico person responded saying that the Indian IT service provider Health-O-Big only validates Patients claims and do not modify any data

The Oasis Medico person felt that there was minimal to nil risk since the Indian IT service provider works on Citrix system and does not download any data. They only see the claims from the Customer and key it in a software and process the insurance claims. If you are GDPR expert how would you respond?


Note: All the names referred here are fictitious, any resemblance to real world is purely coincidental

Service provider should be compliant to GDPR requirements. Even though they are not downloading the data, they are still viewing the data and keying it in to another software.

To view or add a comment, sign in

More articles by Ramkumar Ramachandran ⇗

  • ISO/IEC 27701:2019 - The New Data Privacy Standard

    With the advent of GDPR that applies to personal data of European 'Residents', there has been a flurry of activity in…

    1 Comment
  • California Consumer Privacy Act Primer

    Lot has been discussed globally about data privacy and the new addition is California Consumer Privacy Act (CCPA). This…

    5 Comments
  • GDPR Myths

    GDPR is hot and along with it comes its own myths. You keep hearing many stories that 'looks true' but you have your…

    3 Comments
  • GDPR - Case Study # 1

    Hi Folks, I've decided to publish sample case studies on GDPR. Looking at the interest from public I will give more…

    5 Comments
  • 5 Mantras for a Great Startup Ecosystem

    Mantra # 1 Have A Unique Idea It is important that idea is great, but is more important that is unique as well. MeToo…

    1 Comment
  • Threat Modelling - Connected Cars

    Well, threat modelling is too much of a sophisticated term that I'm using here, but the message is to tell how…

    17 Comments
  • IT Services Industry - Under Pressure & Enjoying

    The best time to improve operational efficiency is when under stress..

  • Securing Your Software - Be Ready, DON'T Get Ready

    Software security has always been misconstrued as IT Security. Whenever people are asked 'Is your software secure?'…

    3 Comments
  • DevOps - The Myth Buster

    Well, DevOps is the new buzz. You know about DevOps and that's why you are here to read this post, curiously.

    6 Comments
  • Autonomous Cars - Just Get Ready

    Whether you like it or not, believer it or not, would like to drive it or not, it is THERE. You will be driving.

    2 Comments

Explore content categories