Health Data, Privacy and AI in Viet Nam: What Healthcare Organizations Need to Know Under the Law on Personal Data Protection

POLICY & REGULATORY INSIGHT

9/18/202617 min read

Health Data, Privacy and AI in Viet Nam: What Healthcare Organizations Need to Know Under the Law on Personal Data Protection

Healthcare AI depends on data. An artificial intelligence system used in medical imaging needs images. A clinical decision-support tool may use diagnoses, laboratory results, medications, demographics, or medical history. A remote monitoring platform may continuously collect physiological measurements and behavioral information, while generative AI may process clinical notes, voice recordings, or other information contained in the medical record.

This creates an important governance question for healthcare organizations in Viet Nam. Before asking whether an AI system is accurate, useful, or ready for clinical deployment, organizations also need to understand what patient data it uses, why those data are being processed, who can access them, where they go, whether they are reused for other purposes, and what happens to them when the original purpose has been completed.

These questions became substantially more important when Viet Nam's Law on Personal Data Protection No. 91/2025/QH15 took effect on January 1, 2026. Decree No. 356/2025/ND-CP, also effective from January 1, 2026, provides detailed implementing rules. Together, they establish a significantly more developed legal framework covering health information, artificial intelligence, cloud computing, cross-border transfers, processing-impact assessments, organizational accountability, and other aspects of personal-data governance.

For healthcare organizations, privacy should therefore no longer be treated simply as an information-technology issue or something addressed through a consent form. It increasingly needs to be integrated into clinical governance, AI governance, procurement, vendor management, cybersecurity, research, quality improvement, and patient safety.

Health data are not ordinary data

The Law defines personal data broadly as digital data or information in another form that identifies or helps identify a specific person. Decree No. 356/2025/ND-CP then specifies the categories of basic and sensitive personal data. For healthcare, this is particularly important because health status is expressly classified as sensitive personal data. Biometric data, genetic characteristics, information about private life and personal or family secrets, location determined through location services, and certain forms of behavioral data are also included in the sensitive category.

A healthcare AI system may therefore process far more sensitive information than its product name suggests. A remote monitoring application may process health status together with location and behavioral patterns. An imaging system may process medical images together with patient identifiers, timestamps, hospital information, and clinical findings. A voice-based documentation system may capture diagnoses, medications, family history, and other private information in addition to the clinician's voice.

The relevant privacy question is not simply whether a system uses a medical record. Healthcare organizations also need to understand what information can be combined, derived, predicted, or inferred from everything the system processes.

This matters because Decree 356 specifically addresses information produced through AI inference. If an inference generated by an AI system can identify or help identify a specific person, it must be protected as personal data. Privacy obligations therefore do not necessarily end with the information originally uploaded to the system. They can extend to new information that the system generates from those data.

Encryption is not the same as de-identification

This distinction is especially important when healthcare organizations use patient data for AI development, validation, research, or quality improvement.

Under the Law, personal data that have been genuinely de-identified are no longer personal data. De-identification means altering or removing information so that the resulting data can no longer identify or help identify a specific individual. Encryption is different. The Law expressly states that encrypted personal data remain personal data because they can be restored to an identifiable form through decryption.

Removing a patient's name from a dataset should therefore not automatically be described as de-identification. If the person can still be identified through a medical record number, rare diagnosis, date, medical image, genetic characteristic, combination of variables, or other available information, the dataset may still be personal data.

For an AI project, a hospital should understand whether data supplied to a technology company have actually been de-identified under the legal definition, are merely masked or coded in a way that still permits re-identification, are encrypted, or remain directly identifiable. These are not equivalent from a data-protection perspective.

Viet Nam now has specific rules for health information

Article 26 of the Law addresses health information directly. As a general rule, the collection and processing of personal data relating to health require the consent of the data subject, except where one of the circumstances in Article 19 permits processing without consent. Full compliance with personal-data protection requirements and other applicable laws is still required.

Article 26 also contains a provision that healthcare organizations should examine carefully when sharing information. Organizations and individuals operating in the health sector may not provide personal data to a third party providing healthcare, health-insurance, or life-insurance services unless there is a written request from the data subject or an applicable Article 19 exception. Developers of healthcare and insurance applications must also comply with personal-data protection requirements.

These obligations need to be read together with healthcare-specific law. Under the current consolidated Law on Medical Examination and Treatment, patients have a right to confidentiality of information in their medical records and other private information provided during care, subject to legally defined exceptions. Medical records must also be stored and kept confidential, and access to them is governed by specific rules.

Introducing AI therefore does not create a new exception to patient confidentiality. Sending health information to an algorithm or external technology platform rather than to another clinician does not make the confidentiality obligation disappear.

Consent should match the actual purpose

The new framework makes purpose-specific consent particularly important.

Under Article 9, valid consent must be voluntary and informed. The data subject must know what types of personal data are being processed, the purposes of processing, the relevant controller or controller-processor, and the person's rights and obligations. Consent must be expressed in a clear and specific form that can be printed or copied, including electronically or in another verifiable format. Importantly, consent must be given for each purpose, and silence or failure to respond does not constitute consent.

This has direct implications for healthcare AI. A patient's agreement to receive care should not automatically be treated as permission for every subsequent use of the patient's information. Using information to provide treatment, using the same information to validate an AI system, allowing a vendor to use it to improve a commercial model, and using it for unrelated research can represent different processing purposes.

The legal basis therefore needs to be considered for the actual activity, rather than for the technology in the abstract.

For example, if an AI vendor tells a hospital that patient information is used only to generate a clinical output for that hospital but also retains those data to retrain a general model, benchmark its product, improve services for other customers, or develop new commercial products, the data-processing purpose has materially changed.

Healthcare organizations should therefore be cautious with vague contractual statements such as “data may be used to improve the service.” Before deployment, the organization should understand what improvement means, what data will be retained, who may use them, whether secondary use is optional, how long the information will be retained, and whether it will be incorporated into a model or dataset that cannot later be readily separated.

Consent matters, but it is not the only lawful situation for processing

It would also be inaccurate to say that every use of health information always requires consent.

Article 19 specifies circumstances in which personal data may be processed without consent. These include urgent situations where processing is necessary to protect life, health, dignity, or lawful rights and interests; certain emergency, national-security, crime-prevention, and state functions; performance of an agreement involving the data subject; and other situations provided by law. An organization relying on the urgent-protection ground bears responsibility for demonstrating that the relevant circumstances existed.

These exceptions do not remove accountability. The Law requires organizations processing data without consent to establish procedures and responsibility, implement appropriate safeguards, assess risk and compliance, and maintain mechanisms for receiving and addressing concerns.

For healthcare organizations, the practical lesson is that an emergency exception should remain an emergency exception. It should not become a general justification for routine AI development, commercial model training, analytics, or unrelated secondary use of patient information.

AI has specific personal-data protection requirements

One of the most important features of the current Vietnamese framework is that artificial intelligence is expressly addressed rather than being left implicit.

Article 30 of the Law regulates personal data processed through big data, artificial intelligence, blockchain, virtual environments, and cloud computing. Personal data in these environments must be processed for an appropriate purpose and limited to what is necessary, while the lawful rights and interests of the data subject must be protected. Appropriate security, authentication, identification, and access-control measures are also required.

Decree 356 goes further. It permits the use of personal data in research and development of self-learning algorithms, AI systems, and other automated systems, but only in compliance with personal-data protection requirements. As noted above, AI-generated inferences that can identify a person remain protected personal data.

The Decree also requires controllers and controller-processors to notify data subjects about automated personal-data processing, explain the operating principles of the algorithm and the potential effect on the person's lawful rights and interests, and provide choices enabling the data subject not to participate. Organizations using personal data in AI systems must implement appropriate cybersecurity and data-protection measures, accountability and monitoring mechanisms, early-warning capabilities, and periodic annual personal-data protection compliance assessments.

These requirements become particularly relevant when AI does more than simply process information in the background and begins to profile, classify, predict, recommend, prioritize, or otherwise generate outputs about individual patients.

Privacy should be designed into the AI workflow

For healthcare organizations, privacy review should begin before patient information is uploaded to an AI system, not after deployment.

Consider a hospital evaluating an AI-assisted imaging platform. The clinical team may appropriately focus on sensitivity, specificity, diagnostic performance, and workflow integration. The information-technology team may focus on connectivity and security. But the hospital also needs to understand whether images leave the hospital, which identifiers accompany them, whether the vendor stores copies, whether those copies are used for model improvement, who has access, whether subcontractors are involved, where the data and backups are located, what happens to outputs generated by the AI, and how the information is deleted when no longer required.

The same principle applies to generative AI. Copying a clinical note, laboratory result, discharge summary, or patient conversation into an external AI tool is still personal-data processing. A simple chat interface does not make the underlying data flows simple.

This is why AI procurement should include a data-flow review, not merely a cybersecurity questionnaire and product demonstration.

The hospital and the vendor may have different legal roles

The Law distinguishes among the personal data controller, personal data processor, and personal data controller and processor. The applicable role depends on what each party actually does, including who determines the purpose and means of processing and who processes information under the relevant arrangement.

In a typical healthcare technology arrangement, a hospital may determine why patient information is processed and a vendor may process that information in order to provide the contracted service. But this should not be assumed in every case.

If the vendor begins using patient information for its own model training, benchmarking, product development, commercialization, or other independent purposes, its role and responsibilities may need to be reconsidered. Calling a company a “processor” in a contract does not by itself resolve how the parties should be characterized if the actual processing activities are different.

The Law also requires processors to receive and process personal data pursuant to the relevant agreement or contract with the controller. This makes the data-processing agreement an important part of healthcare AI procurement. The agreement should describe the real data flow and real purposes, rather than rely solely on generic privacy clauses.

A foreign technology company should also not automatically be assumed to sit outside Vietnamese personal-data law. The Law applies not only to Vietnamese entities and foreign entities in Viet Nam, but also to foreign organizations and individuals directly participating in or related to the processing of specified personal data of Vietnamese citizens and certain people of Vietnamese origin residing in Viet Nam.

Cloud AI creates additional obligations and questions

Many healthcare AI systems are now delivered through cloud infrastructure.

Decree 356 contains specific requirements for personal data processed in cloud environments. Cloud providers must comply with Vietnamese personal-data protection requirements, address the obligations of subcontractors, implement technical and organizational safeguards appropriate to the scale and nature of processing, and conduct annual compliance assessments. Personal data stored in cloud environments must be encrypted at rest and in transit, with strict access authorization.

For hospitals, cloud architecture is therefore not merely an IT architecture decision. Vendor due diligence should establish where primary data and backups are stored, which subcontractors or sub-processors may have access, whether support personnel outside Viet Nam can view information, how long backups are retained, what happens after contract termination, whether deleted data remain recoverable, and whether patient information can be reused by the provider.

The hospital also needs to know whether the technical architecture creates a cross-border personal-data transfer.

Using an overseas platform may constitute a cross-border transfer

Viet Nam's legal definition of cross-border personal-data transfer is broader than physically sending a patient file overseas.

Article 20 includes transferring personal data stored in Viet Nam to storage systems located outside Viet Nam, transferring data from Viet Nam to a foreign organization or individual, and using a platform outside Viet Nam to process personal data collected in Viet Nam. Decree 356 similarly covers overseas servers, foreign recipients, foreign cloud services, and offshore platforms used for continued processing.

A hospital using an overseas AI or cloud platform may therefore be carrying out a cross-border transfer even when clinicians never manually email or upload a file to another country.

The Law generally requires an organization carrying out a covered cross-border transfer to prepare a cross-border personal-data transfer impact assessment dossier and submit one original dossier to the specialized personal-data protection authority within 60 days from the first transfer, subject to statutory exemptions.

The assessment is not simply a declaration that data leave Viet Nam. It addresses matters such as the parties involved, purpose and types of data, data-flow architecture, security and retention, onward transfers, the recipient's protection measures, and risks and mitigation measures.

There are specific statutory exemptions. One important example is where an organization stores the personal data of its own employees using a cloud service. That is a narrow exemption relating to employee data and should not be interpreted as a general exemption allowing patient health information to be placed on an overseas cloud platform without considering the cross-border impact-assessment rules.

AI implementation may also require a processing-impact assessment

Cross-border transfer is only one form of impact assessment under the Law.

Article 21 generally requires personal data controllers and controller-processors to prepare and retain a personal-data processing impact assessment dossier and submit one original dossier to the specialized personal-data protection authority within 60 days from the first processing activity, subject to applicable exemptions. Processors have related obligations according to their arrangements with controllers.

The assessment needs to consider the purposes of processing, categories of data, relevant parties and data flows, safeguards, retention and deletion, security, effects on data subjects, and the risks and mitigation measures associated with the processing.

These dossiers should not be treated as documents prepared once and then forgotten. The Law and Decree require updates when relevant circumstances change. Decree 356 provides for six-month updates from the first submission in specified situations, including when new processing or transfer purposes arise or relevant controllers, processors, or third parties are added or changed. Certain organizational changes, changes involving personal-data protection service providers, and changes to registered businesses or services relating to personal-data processing require updates within ten days.

For healthcare AI governance, the implication is practical: introducing a new AI system should not be treated solely as adding another technology asset. If it introduces a new purpose, new vendor, new processor, new recipient, new cloud architecture, or new cross-border data flow, existing privacy documentation may also need to be updated.

Health technology start-ups should not assume that size automatically creates an exemption

Decree 356 provides certain temporary or permanent relief from some impact-assessment and personal-data protection personnel requirements for qualifying small, start-up, household, and micro businesses. However, important exceptions apply.

The relief does not apply in the same way where the business provides personal-data processing services, directly processes sensitive personal data, or processes personal data at or above the statutory scale threshold of 100,000 data subjects. Since health status is sensitive personal data, many health-technology companies handling patient information should not assume that being a start-up or small company automatically removes these obligations.

This is particularly relevant in Viet Nam, where innovative healthcare technologies are frequently introduced through relatively young companies or overseas vendors working with local partners. Organizational size and technological sophistication are different issues from the sensitivity of the information being processed.

Some health technology vendors may be providing regulated personal-data processing services

Decree 356 also identifies categories of personal-data processing services.

These include, among other activities, services that collect and process personal data through healthcare, health-monitoring, and medical-service websites or applications, and automated personal-data processing services based on technologies such as big data and artificial intelligence. Organizations conducting business that falls within these regulated service categories are subject to organizational, personnel, infrastructure, governance, and certification requirements. The Ministry of Public Security has authority over the certificate of eligibility for conducting personal-data processing services.

This does not mean that every software vendor selling a product to a hospital is automatically a regulated personal-data processing service provider. Classification depends on the actual service and business activity.

For healthcare organizations, however, it creates a valuable procurement question: What legal role is the vendor performing, and what regulatory requirements apply to the service it is actually providing?

Vendor due diligence should therefore go beyond asking whether a company has ISO certification, a cybersecurity policy, or experience with hospitals.

Personal-data governance requires accountable people

Article 33 of the Law requires organizations to either designate a qualified personal-data protection function or personnel, or engage a qualified organization or individual providing personal-data protection services. Where an organization designates internal personnel or establishes an internal function, Decree 356 requires the appointment to be made formally in writing and sets competency requirements for the relevant personnel.

Using an external service provider does not remove the substantive responsibilities that the Law assigns to controllers, controller-processors, processors, and other parties involved in personal-data processing. Organizations still need governance mechanisms capable of making and documenting decisions about their own processing activities.

For healthcare organizations, that governance should not sit in isolation. AI and Digital Medicine create issues spanning legal affairs, information technology, cybersecurity, clinical governance, medical ethics, quality management, procurement, research, and patient safety.

An effective structure therefore needs a way for these functions to meet before an AI system enters routine clinical use. Conducting the privacy review after the contract has already been signed is too late to answer many of the most important questions.

A data breach can also become a patient-safety issue

Health data can cause serious harm when exposed, altered, lost, unavailable, or used for an unintended purpose.

Article 23 of the Law requires a controller, controller-processor, or third party that discovers a personal-data protection violation capable of causing specified serious harms, including harm to life, health, dignity, reputation, or property, to notify the specialized personal-data protection authority within 72 hours of discovering the violation. A processor that detects a violation must promptly notify the controller or controller-processor.

Decree 356 contains additional requirements for certain sensitive categories. Where a breach involves personal location data or biometric data, the controller or controller-processor must notify affected data subjects within no more than 72 hours of discovering the breach, report to the competent authority, and maintain relevant breach records.

For healthcare organizations, incident response should therefore connect privacy, cybersecurity, and clinical safety. A compromised AI system can create more than a confidentiality problem. Altered data, corrupted model inputs, unavailable records, or unauthorized access could potentially affect diagnosis, treatment decisions, or continuity of care.

Before an incident occurs, an organization should already know who receives the first report, who evaluates potential clinical consequences, who contacts the technology provider, who preserves logs and evidence, who determines whether external notification is required, and who can suspend the system if patient safety could be affected.

Enforcement is now much more concrete

The enforcement environment changed significantly on August 19, 2026, when Decree No. 330/2026/ND-CP on administrative penalties in cybersecurity and personal-data protection took effect. The Decree creates detailed sanctions for failures involving consent, data-subject rights, processing purposes, safeguards, breach reporting, cross-border transfers, personal-data protection functions, and other obligations.

Importantly for healthcare, Decree 330 contains specific penalties relating to health information and healthcare applications. Examples include collecting sensitive personal data through healthcare or online-health platforms without appropriate access-control and security measures, and improperly providing or sharing patient personal data with another healthcare or insurance organization without the required written request or applicable legal exception.

Cross-border transfers can carry particularly significant exposure. For specified serious violations, Decree 330 provides revenue-based organizational penalties ranging from 1 percent to 5 percent of the previous financial year's revenue in the Vietnamese market, depending on the nature and scale of the violation. The general maximum for other personal-data protection violations is VND 3 billion for organizations, subject to the specific offense and applicable provisions.

For healthcare organizations, the significance goes beyond financial penalties. Personal-data protection is becoming an operational and auditable governance responsibility, not merely a privacy statement placed on a website.

What should healthcare organizations ask before adopting AI?

The most useful starting point is a data-flow discussion, rather than asking the vendor only for its privacy policy.

Before deploying an AI system, a healthcare organization should be able to explain what patient or other personal data enter the system, which of those data are sensitive, where they originate, what the AI does with them, what new information it infers, who receives the output, where information and backups are stored, which vendors and subcontractors can access them, whether data leave Viet Nam, how long they are retained, whether the provider can reuse them for model training or product development, how deletion works, and how the organization will respond if a data subject exercises a legal right or an incident occurs.

It should also be able to explain why each processing activity is legally permitted.

For some activities, consent may provide the relevant basis. In others, a statutory exception or sector-specific legal requirement may apply. The organization should avoid allowing the technical architecture to determine the legal justification after the system has already gone live.

This is especially important when vendors offer a technically attractive default configuration in which data automatically leave the hospital, are retained in a foreign cloud, or are reused for general model improvement. The easiest technical configuration is not necessarily the most appropriate governance configuration.

Privacy and AI governance should be connected

Healthcare organizations sometimes treat AI governance, personal-data protection, cybersecurity, procurement, and clinical governance as separate projects. In practice, they increasingly overlap.

An AI governance team cannot properly assess risk without understanding the data a model uses and generates. A privacy function cannot adequately evaluate an AI system without understanding what the algorithm does, the decisions it influences, and the clinical consequences of error. A cybersecurity team cannot protect a system without understanding its architecture, integrations, users, and data flows. Procurement cannot negotiate meaningful contractual safeguards without input from all of them.

The same AI system may therefore raise questions involving clinical evidence, patient safety, medical-device regulation, AI risk classification, personal-data protection, cybersecurity, cross-border transfers, contractual accountability, and real-world monitoring.

Separate cybersecurity requirements may also apply under Viet Nam's Law on Cybersecurity No. 116/2025/QH15, effective July 1, 2026, and its implementing framework. Personal-data compliance should not therefore be treated as a substitute for cybersecurity compliance.

Responsible implementation requires these different governance systems to work together.

Privacy should enable trustworthy Digital Medicine

Data protection is sometimes presented as a barrier to innovation. That is not the most useful way to approach it.

Healthcare AI needs data if it is to become clinically useful. Hospitals will increasingly need to exchange data across systems. Digital Medicine will rely on cloud infrastructure, connected devices, remote monitoring, artificial intelligence, digital measures, and other forms of software-supported care.

The important question is whether healthcare organizations understand what data they are using, why they are using them, who has access, where the information goes, what new information the technology creates, what risks arise, what rights patients retain, and who remains accountable throughout the data lifecycle.

Viet Nam's new personal-data protection framework makes these questions much more explicit. It creates compliance obligations, but it also provides healthcare organizations with an opportunity to build stronger data governance before AI becomes deeply embedded in clinical care.

A healthcare organization that cannot explain where its patient data go will eventually struggle to explain why its AI should be trusted.

Responsible healthcare AI begins before the algorithm. It begins with responsible data governance.

Key references

National Assembly of Viet Nam. Law on Personal Data Protection No. 91/2025/QH15, dated June 26, 2025, effective January 1, 2026.

Government of Viet Nam. Decree No. 356/2025/ND-CP detailing provisions and measures for implementation of the Law on Personal Data Protection, dated December 31, 2025, effective January 1, 2026.

Government of Viet Nam. Decree No. 330/2026/ND-CP on administrative penalties in cybersecurity and personal-data protection, dated and effective August 19, 2026.

National Assembly of Viet Nam. Law on Data No. 60/2024/QH15, effective July 1, 2025.

National Assembly of Viet Nam. Law on Cybersecurity No. 116/2025/QH15, effective July 1, 2026.

National Assembly of Viet Nam. Law on Medical Examination and Treatment No. 15/2023/QH15, as reflected in Consolidated Document No. 26/VBHN-VPQH dated February 26, 2026.

National Assembly of Viet Nam. Law on Artificial Intelligence No. 134/2025/QH15, effective March 1, 2026.

This article is intended for educational and informational purposes. It does not constitute legal, regulatory, clinical, data-protection, cybersecurity, procurement, or technology advice. The requirements applicable to a particular healthcare organization, AI system, data-processing activity, vendor arrangement, or cross-border transfer should be assessed according to its specific purposes, data categories, organizational roles, technical architecture, contractual arrangements, and applicable laws and regulations.

Updated: September 18, 2026

Digital Medicine Vietnam

Advancing evidence-based Digital Medicine in Viet Nam. A VietnamWellcare Initiative.