Protection for patient information, in the systems that hold it.
F Creative Studio 360 helps healthcare organisations in any country see where patient information sits, who can reach it, and what happens if it leaves. The privacy rule is the one that organisation is actually subject to.
The record is the asset.
Clinics, hospitals, payers and life-sciences teams hold information that can harm a person if it is exposed. The duty might be the HIPAA Security Rule, the GDPR, or, for an organisation subject to Australian law, the Privacy Act and the Notifiable Data Breaches scheme.
F Creative Studio 360 reviews the controls. We do not notify a regulator, and we do not decide whether a breach is notifiable. That judgment belongs to the organisation and its counsel.
- Systems, not a slogan
- Electronic records, billing, prescribing, telehealth and the suppliers that host them are in scope only when you name them.
- Access is the common gap
- Shared accounts, former staff and vendors who can still open a record are reviewed before exotic threats.
- Suppliers are in the picture
- A clinic is still accountable for a processor that stores the backup or runs the record system.
- Clinical safety stays with clinicians
- We do not change a clinical system in a way that could affect care unless that change is written into scope and agreed with the operator.
What the review covers
The same method works for a single clinic or a group that spans countries. The legal notice path changes with the law that applies.
- Where the data sits
- Records, images, backups, email and cloud stores, including copies a supplier holds.
- Who can open it
- Identities, shared logins, and access that outlives the job.
- How it would be noticed
- Logging, alerting and the path from an alert to a person who can act.
- What counsel would need
- A factual record. The decision to notify a person or a regulator is not ours.
How an engagement runs
On site or remotely. Patient systems can sit in more than one country.
- 1
Name the services
Which organisations, which record systems, and which countries’ privacy laws apply.
- 2
Map the copies
Including backups and suppliers.
- 3
Review access and detection
Authorised testing of a system is separate, and only when it is written in.
- 4
Hand back the order
What to close first, without a claim that you comply.
What you receive
- A map of patient-information stores in scope.
- An access and supplier review.
- A note of detection gaps.
- A prioritised list. No notification is filed by F Creative Studio 360.
A neighbouring page
Connected medical devices are a different problem. They have their own page, because a pump is not an electronic record system.
Common questions
Do you only cover the Australian Privacy Act?+
No. The work is for healthcare organisations in any country. The Privacy Act and the NDB scheme are used when that organisation is subject to them. HIPAA or the GDPR is used when those apply instead.
Will you tell the regulator if we are breached?+
No. We can help establish what happened. Counsel and the organisation decide whether a notice is required, and they send it.
Where do you deliver this?+
For organisations in any country. A local rule is used only when that organisation is actually subject to it. F Creative Studio 360 does not limit the work to one jurisdiction.
How much does it cost, and how long does it take?+
It depends on the systems in scope and whether you want an assessment only or help afterwards. A scoping conversation with F Creative Studio 360 is the way to get a quote. There is no obligation to proceed.
Start with where the records actually are.
F Creative Studio 360 will look at the systems and the laws that apply, then say what a sensible review includes.
