CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
Procurement Requirements Procurement processes for information technology services must also incorporate specific cybersecurity requirements. Contracts with third-party providers must include explicit clauses requiring the provider to comply with MINSAL security guidelines and the Framework Law. When using cloud services, health institutions must perform enhanced due diligence to ensure that the provider maintains security levels at least equivalent to national regulations, particularly regarding data encryption and sovereign data han - dling.
and to implement network segmentation (VLANs) to isolate these devices from other critical systems. Access controls for medical devices must be strictly managed, involving the removal of default factory credentials and the implementation of multi-factor authentication where feasible. Manufacturers and pro - viders are obligated to deliver regular security patches and firmware updates, accompanied by documenta - tion of any security tests performed. Before any IoT device is put into operation, the institution must con - duct penetration testing and evaluate the potential impact on clinical interoperability.
72 CHAMBERS.COM
Powered by FlippingBook