A patient's medical record is probably the single most sensitive piece of personal data that exists. It reveals what illnesses someone has, what medication they take, whether they've been in psychiatric treatment, whether they carry a genetic condition. That's why Colombia's healthcare sector isn't governed only by the general Habeas Data Law like any other business — the Superintendencia Nacional de Salud imposes additional, sector-specific requirements on EPS health insurers, IPS providers, clinics, and other operators within Colombia's health system, precisely because the data they handle belongs to a special category of information.
If your organization provides healthcare services, or provides technology to someone who does, here's what you need to understand.
Why Healthcare Gets Different Treatment
Health information is legally classified as sensitive data, alongside sexual orientation, religious beliefs, and political affiliation. Law 1581 already requires a higher level of protection for this category — it demands explicit authorization, generally can't be processed except in narrow exceptions, and its exposure carries more severe legal consequences than a leak of ordinary data like an email address. The Superintendencia de Salud builds on that foundation with sector-specific operational requirements: continuity of service, integrity of electronic medical records, and the ability to respond to incidents that could compromise patient care.
Who It Applies To
Superintendencia de Salud oversight covers EPS health insurance entities, IPS healthcare providers — clinics, hospitals, laboratories — and generally any operator within Colombia's General Social Security Health System. If your business develops electronic health record software, manages technology infrastructure for a hospital, or provides cybersecurity services to any of these players, sooner or later you'll need to show you understand this framework.
What It Means in Practical Terms
While the exact technical detail varies by type of operator, in practice the requirements the Superintendency expects to see cover these areas:
Protecting the electronic medical record. Strict access control — only medical staff authorized and directly involved in a patient's care should be able to view their record. Systems need to be able to audit who accessed what information and when.
Continuity of service. A hospital can't simply "go down" during a ransomware attack without real consequences for patient care. Continuity planning in healthcare carries a different weight than in other sectors — there are literally lives involved.
Reporting incidents that affect patient information. When a breach compromises health data, the operator needs to be able to document it, report it as required, and show it took containment measures.
Managing technology vendors. As in the financial sector, if a healthcare operator outsources its technology infrastructure or medical record software, it needs to be able to demand equivalent security standards from those vendors.
Why Healthcare Is Such an Attractive Ransomware Target
It's no coincidence hospitals consistently rank among the most ransomware-targeted sectors in the region. A hospital faces operational pressure other businesses don't: it can't simply wait days while negotiating with an attacker, because there are patients in surgery, in emergency rooms, depending on systems that have to keep running. That urgency makes healthcare, from an attacker's perspective, a target with a higher likelihood of fast payment — which, perversely, makes it targeted more often, not less.
How to Start Closing the Gap
Frequently asked questions
Does this only apply to large hospitals?
No. It applies to any operator within the General Social Security Health System, which includes small clinics, labs, and practices handling electronic medical records — though the level of technical rigor can be adjusted to their size and complexity.
Does health information have a different protection level than other personal data?
Yes. It's legally classified as sensitive data, which requires explicit authorization and a higher protection standard than ordinary personal data.
What happens if a hospital's technology vendor has a security breach?
The hospital, as the controller of its patients' data, remains accountable to the Superintendency even if the incident occurred on a third party's infrastructure. That's exactly why requiring equivalent standards from vendors matters so much.
How often should an electronic medical record system be audited?
There's no universal number, but given the sensitivity of the information and how frequently healthcare is targeted, an annual review at minimum, with continuous monitoring in between, is the reasonable floor.
Let's talk
Health information doesn't forgive security mistakes the way other data sometimes does. At T.I. RESCUE, we work with healthcare operators on [cybersecurity audits](https://tirescue.com/en/auditoria-de-ciberseguridad/) focused on critical patient-care systems, and on [24/7 incident response](https://tirescue.com/en/respuesta-ante-incidentes-247/) plans designed to minimize operational impact when something goes wrong. Has your clinic or EPS never properly assessed this? [Book a consultation](https://tirescue.com/en/contacto-ti-rescue/).
Contact usYou may also like
SFC Circular 007: Cybersecurity Requirements for Colombia's Financial Sector
Colombia's Cybercrime Law (Law 1273): What It Says and How It Protects You
Colombia's Habeas Data Law (Law 1581): A Complete Guide for Businesses
Comments (0)
Be the first to comment.