A Cooperative Research Project Between an Asian Hospital and a European Medical Center

A cooperative research project between an Asian hospital and a medical center passed the data export security assessment, becoming the first successful case in the country. The successful data export security assessment case involving the Asian hospital related to an international multicenter clinical research project jointly initiated by the Asian hospital’s General Surgery Center and the Department of General Surgery of a European medical center as the global lead center. During the project preparation stage, the Asian hospital had already initiated the application for data export approval for the project. As of April 2022, the Asian hospital had enrolled more than one hundred cases in the study.

This successful case of data export security assessment is of significant guiding value for subsequent applications for data export security assessments. Based on currently available public information and regulatory documents, this article provides a brief analysis of the Asian hospital case.

According to Article 4 of the Measures for Data Export Security Assessment, where a data processor provides data overseas under any of the following circumstances, it shall apply to the national cyberspace administration authority for a data export security assessment through the provincial-level cyberspace administration authority where it is located: (1) where the data processor provides important data overseas; (2) where a critical information infrastructure operator or a data processor handling the personal information of more than 1 million individuals provides personal information overseas; (3) where, since January 1 of the previous year, a data processor has cumulatively provided the personal information of 100,000 individuals or the sensitive personal information of 10,000 individuals overseas and provides personal information overseas; or (4) other circumstances requiring application for a data export security assessment as prescribed by the national cyberspace administration authority.

First, the medical and health data processed by hospitals not only constitutes the personal information of individual patients, but may also involve national human genetic resources and biosecurity. However, based on the information currently available to the public, if the Asian hospital’s data export project involved only the medical data of just over one hundred enrolled cases, the likelihood of the relevant data constituting important data would be relatively low.

Second, the Asian hospital holds an important position within the healthcare system, and the number of personal information subjects involved in the personal information it processes may far exceed the threshold of 1 million. Therefore, there is a strong possibility that it may be recognized as a critical information infrastructure operator.

Article 30 of the Notice on Issuing the National Measures for the Administration of Standards, Security, and Services of Health and Medical Big Data (for Trial Implementation) provides that responsible entities shall have data storage, disaster recovery backup, and security management capabilities that meet relevant national requirements, and shall strengthen the storage management of health and medical big data. Health and medical big data shall be stored on secure and reliable servers located within China. Where it is truly necessary for business purposes to provide such data overseas, a security assessment and review shall be conducted in accordance with relevant laws, regulations, and applicable requirements. In practice, even after desensitization, relevant healthcare data will usually still constitute sensitive personal information. Whether a medical data export project reaches the applicable filing threshold under the Measures for Data Export Security Assessment depends on the actual data exported and the cumulative scale of the data export.

In summary, Guozun Law Firm believes that filing an application for data export for data meeting the relevant conditions is a mandatory legal obligation for enterprises. In international cooperation, medical institutions need to determine on a case-by-case basis whether the data involves physical export or remote overseas access. If it constitutes a data export scenario, they should assess whether the filing conditions are met. Where the relevant conditions are satisfied, they should conduct a self-assessment and submit the application in a timely manner.


← Back to List