TAIWAN Law and Practice Contributed by: Ken-Ying Tseng, Winona Chen and Roger Kai, Lee and Li Attorneys-at-Law
In addition, on 19 December 2025, the Regulation on Management of National Health Insurance Data (the “NHI Data Regulation”) was formally promulgated, with its effective date to be determined by the Execu - tive Yuan. The Regulation establishes comprehensive standards governing the collection, processing and use of National Health Insurance (NHI) data. From a cybersecurity standpoint, the NHI Data Regulation mandates that applicants seeking access to NHI data implement specific cybersecurity measures and comply with the directives issued by the MOHW and the National Health Insurance Administration (NHIA). Additional requirements are expected to be issued by the MOHW in due course. For hospitals, the MOHW has promulgated the Guide - line for Cybersecurity Protection in Primary Healthcare Facilities. This guideline outlines various recommen - dations for healthcare institutions, specifically primary care clinics and regional hospitals with limited budg - ets and awareness of cybersecurity, with respect to the implementation of certain measures for protect - ing patient data and operations. Key recommenda - tions include immediate incident reporting for threats, requiring a security clause in procurement contracts and proof of vendor cybersecurity certification or training.
For medical devices, the MOHW has published two guidelines concerning security requirements. • The Guideline on Medical Device Inventory Man - agement and Risk Assessment: This guideline is merely advisory, and is aimed at helping informa - tion security staff and medical device managers in hospitals identify and assess the risks of medical devices so that they can take appropriate protec - tive measures and lower security risks at hospitals. • The Guideline on Cybersecurity of Medical Devices Applicable to the Medical Device Manufacturer: This guideline covers cybersecurity issues that manufacturers of medical devices should consider during product design, product development and application for market approval – and after the product is launched on the market. This guideline is also purely advisory, and is published to help manufacturers ensure the cybersecurity of their medical devices. However, it also notes that the MOHW examiner might ask a manufacturer to provide other documents that are not required in the guideline. Both guidelines will be updated from time to time to adapt to technological advances.
405 CHAMBERS.COM
Powered by FlippingBook