Use secure communication channels, like encrypted email or patient portals, for sharing PHI. Avoid sending PHI through unencrypted email or other insecure methods.
Train all employees who handle PHI on HIPAA compliance, including privacy and security practices and breach notification procedures.
Although GDPR primarily applies to entities operating within the EU or handling the data of EU citizens, Dr. Sangita Pradhan’s website should still consider GDPR principles if it collects or processes data from EU citizens. The following requirements should be implemented:
Establish a lawful basis for collecting and processing personal data, such as obtaining explicit consent from patients before collecting their data or providing services.
Provide clear information about data collection and processing purposes in plain language. Ensure that consent is specific, informed, freely given, and explicit (e.g., via an opt-in checkbox).
Implement mechanisms to enable data subjects (patients) to exercise their rights under GDPR, including the right to access, rectification, erasure (the “right to be forgotten”), and data portability.
Limit data collection to only what is necessary for the intended purposes. Ensure that personal data is used only for the stated purpose and not retained longer than needed.
Implement technical and organizational measures to secure personal data, including encryption, pseudonymization, and regular security audits.
Consider appointing a Data Protection Officer (DPO) if the website processes large amounts of personal data or handles sensitive information regularly.
If you have any questions or concerns about our HIPAA and GDPR compliance, please contact our Data Protection Officer:
We are dedicated to ensuring the security of your personal and health information and respecting your privacy rights.
Thank you for trusting Dr. Sangita Pradhan, MD with your care.