The health data are processed in a technological domain very complex, often influenced by the presence of exceptions. These exceptions to the standard management processes add cost, complexity and redundancy in the system, worsening the proper functioning of healthcare organizations.
The regulatory environment also does not provide the appropriate tools to attack the critical issues listed above: the ever changing scenario hinders a comprehensive management and long-term clinical data, prompting healthcare organizations to consider the data protection of consumers almost as an obstacle to the execution of clinical procedures. Consequently, the protection of health data is excluded from the core business and this, unfortunately, makes this area dependent on technology. For this reason, in many situations the responsibility for information security is entrusted only to the Chief Information Officer. This actor is not the suitable individual to fulfill this task: he assures the delivery of services, automation, innovation, efficiency and not the security of the data as a priority. The effective management of the security of health data, in fact, should assume an independent vision, holistic and on a high-level business process, in a standardized and simplified strategic framework aimed at ensuring regulatory compliance, adherence to the framework and standards of safety, risk protection. In addition, as stated by the General Data Protection Regulation 2016/679 (Art. 38, Position of the data protection officer, paragraph 6), the reference point for the protection of data, the Data Protection Officer, should be a figure to above any conflict of interest and should therefore not be dependent on technology.
The activities to be carried out are considerable. For these reasons, it is clear that the most suitable solution to manage this area is the establishment of a dedicated internal structure, composed by a team of certified experts in the legal field and in computer security.
Most likely, most of the initial energy would be expended in removing the opposition to this change, often related to the existence of technical / operational constraints and managerial will to keep alive the current bureaucratic and organizational system.