CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
• guaranteeing the ongoing confidentiality, integrity, availability and resilience of processing systems and services; • ability to restore the availability and access to data quickly in case of incidents; and • regular processes for verification, evaluation and assessment of the effectiveness of security meas - ures. In addition, the data controller must report to the Agency any security breach that results in the destruc - tion, leakage, loss or unlawful alteration of data, or unauthorised access to it, especially if there is a risk There are no specific regulations in Chile on the sub - ject of cybersecurity and AI. Therefore, general rules apply, including the Cybersecurity Framework Law and any specific or general instructions that the National Cybersecurity Agency may issue in this regard. However, the SERNAC, the temporary controlling authority for personal data protection in the context of consumer relations, issued an interpretative circular regarding AI systems and consumer safety. It is impor - tant to remember that these circulars are not gener - ally binding but only apply to SERNAC officials in the context of supervisory activities, which could result in a complaint being filed with the courts (SERNAC does not have direct sanctioning powers). to the rights of data subjects. 6.2 Cybersecurity and AI In the Interpretative Circular on consumer protection against the use of AI systems – consumer safety, SER - NAC has interpreted that, in view of the general obli - gation incumbent on suppliers to provide security to consumers, AI systems in the context of a consumer relationship must present adequate standards of pre - cision, reliability and technical effectiveness to obtain well-founded results and to avoid causing harm to consumers of a material or immaterial nature. Specifically, SERNAC interprets this duty as translat - ing into the need to apply appropriate technical and organisational security measures, which guarantee the confidentiality, integrity and availability of the per - sonal data in question, considering especially the risks involved in the processing activities and the nature
of the data stored (including, among other elements, their level of sensitivity). 6.3 Cybersecurity in the Healthcare Sector The healthcare sector in Chile is considered one of the most vulnerable and critical sectors due to the high sensitivity of patient data and the essential nature of its clinical operations. To address these challenges, the Ministry of Health (MINSAL) issued Resolution 853 in April 2025, which approves the updated Cyberse - curity Instruction for the Health Sector. This regulatory framework integrates with the Cybersecurity Frame - work Law No 21.663 to ensure that the entire health ecosystem maintains the confidentiality, integrity, and availability of its systems. Scope and General Obligations Cybersecurity obligations apply to all institutions within the health sector, including the Ministry, its sub secretariats, SEREMI, hospital services, and Primary Health Care centres. The Cybersecurity Framework Law specifically classifies health services provided by hospitals, clinics, and medical centres as essential services. Consequently, many of these entities have been qualified as OIV, which subjects them to the highest level of regulatory scrutiny and more stringent defensive requirements. Health sector entities are required to implement a continuous Information Security Management Sys - tem (ISMS) based on international standards such as ISO/IEC 27001. This system must be supported by a robust governance structure, including the appoint - ment of a Chief Information Security Officer (CISO) and the active involvement of the board of directors. Furthermore, institutions must maintain a document - ed Strategic Security Plan and perform regular risk assessments to identify vulnerabilities in their critical assets. Medical Devices and IoT Requirements Connected medical devices and the IoT are identified as essential components of the technological infra - structure in modern healthcare. These devices, which include infusion pumps, monitors and pacemakers, must comply with specific technical and organisational security controls. The current regulations require enti - ties to maintain a detailed inventory of all IoT assets
71 CHAMBERS.COM
Powered by FlippingBook