CHINA Law and Practice Contributed by: Kate Yin, Sherman Deng, Yanjun Zhuang and Daniel Wang, Fangda Partners
Services issued by the National Technical Commit - tee 260 on Cybersecurity of SAC operationalise this. The guidelines classify incidents into information content, data security and network attack events. A critical threshold for immediate reporting to authori - ties includes scenarios where third-level (Severe) inci - dents occur cumulatively five times within 24 hours and affect over 10,000 users. Finally, it is crucial to note that these specific AI regulations interact directly with general laws; violations of AI-specific duties will trigger the severe penalty mechanisms prescribed in the CSL, DSL and PIPL, including potential business suspension or criminal liability. 6.3 Cybersecurity in the Healthcare Sector Pursuant to the Administrative Measures for Cyberse - curity of Medical and Health Institutions issued by the National Health Commission, healthcare institutions are mandated to establish a comprehensive cyber - security governance structure where the institution assumes the primary responsibility. This includes, among others, the formation of a cybersecurity lead - ership group and strict adherence to the MLPS. Nota - bly, for any newly constructed networks (including electronic health record systems), the security protec - tion level shall be determined during the planning and declaration phase. Systems classified at third-level or above are subject to MLPS assessment at least once annually, while second-level systems processing personal information of over 100,000 individuals shall undergo assessment at least every three years.
In terms of procurement and supply chain secu - rity, healthcare institutions shall execute written agreements with IT contractors and medical device manufacturers, explicitly defining cybersecurity obli - gations and liability for any breach. A strict “secu - rity-by-design” and lifecycle management approach is required for medical devices, covering tendering, procurement, installation, maintenance and final dis - posal. A unique sector-specific requirement mandates that for all new informatisation projects, the budget allocated specifically for cybersecurity shall not be less than 5% of the total project budget. Regarding data protection and incident reporting, under Articles 20 and 21, institutions shall conduct an annual inventory of data assets and establish a classification system based on the potential harm of a breach. An annual data security risk assessment is also mandatory. Data generated shall primarily be stored within China; cross-border transfers require a security assessment or review in accordance with relevant laws. In the event of a personal information leak or significant cybersecurity incident, the institu - tion is obligated to immediately activate emergency plans, take remedial measures, and notify the affected individuals via telephone, SMS or mail, and report the incident to the supervisory authorities.
88 CHAMBERS.COM
Powered by FlippingBook