If your clinic keeps patient records — paper charts or an EMR — you are a "personal information controller" under Republic Act No. 10173, the Data Privacy Act of 2012, and you carry specific legal duties: protect the data, collect valid consent, register with the National Privacy Commission (NPC) if you cross its thresholds, and report breaches within 72 hours. For YAKAP clinics, these duties are not optional extras. PhilHealth has tied Data Privacy Act compliance to accreditation paperwork since 2016, and the move to certified EMRs makes your data-handling practices more visible than ever.
What RA 10173 Requires of a Clinic
The core rule: health information is "sensitive personal information" — the most protected category in the law — and processing it is prohibited by default unless a legal exception applies. Under Section 3(l) of RA 10173, data about a person's health sits alongside genetic and sexual-life data in the sensitive category. Section 13 then prohibits processing sensitive personal information except in narrow cases, the most practical of which for a clinic is consent from the patient that is "specific to the purpose."
Three more provisions matter daily:
- Section 16 — patient rights. Patients have the right to be informed, to access their records, to dispute inaccuracies, to block or destroy unlawfully obtained data, and to be indemnified for damages. Your clinic needs a way to answer an access request without printing the entire chart room.
- Section 20 — security measures. Controllers must implement "reasonable and appropriate organizational, physical and technical measures." A locked filing cabinet is a physical measure; encryption and access controls are technical ones; a designated Data Protection Officer (DPO) and staff training are organizational ones.
- Sections 25 and 30 — criminal penalties. Unauthorized processing of sensitive personal information carries 3 to 6 years of imprisonment and a fine of P500,000 to P4,000,000. Concealing a security breach carries 1.5 to 5 years and P500,000 to P1,000,000. These attach to people, not just companies.
Does Your Clinic Need to Register with the NPC?
Many YAKAP clinics do. Under NPC Circular 2022-04, registration of your DPO and your data processing systems is mandatory if any of these apply:
- You employ 250 or more people;
- You process sensitive personal information of 1,000 or more individuals; or
- Your processing is likely to pose a risk to the rights of data subjects.
A YAKAP clinic with an empaneled beneficiary base can cross the 1,000-patient threshold quickly — every registered patient's health record counts. The mechanics:
- Register within 20 days of implementing a new data processing system (your EMR counts) or appointing your first DPO.
- Renew annually, within 30 days before the registration expires.
- Display the registration at your business entrance and on your website.
- If you fall outside mandatory coverage, you must file a sworn declaration — or you may register voluntarily.
Adopting a certified EMR is a natural trigger to sort this out, since the EMR itself is a registrable data processing system. If you are still choosing a provider, our 10-point EMR checklist for YAKAP clinics includes data-privacy questions to ask vendors.
Patient Consent: Not New for PhilHealth Clinics
PhilHealth has required RA 10173-compliant consent from primary-care clinics for a decade. PhilHealth Advisory No. 2016-0040 — the same issuance that first tied accreditation to validated EMR use — requires clinics to have patients review and sign an Informed Consent Form "in compliance with RA 10173," and to keep those forms available for legal or audit purposes.
Under YAKAP the consent trail is now digital and layered. PhilHealth Circular No. 2025-0017 requires a signed Mutual Care Agreement for beneficiary empanelment starting January 1, 2026, renewed annually and submitted as a requirement for first-tranche payments. And under PhilHealth Advisory No. 2026-0029, the Digital YAKAP Empanelment Slip flow has the provider explain the terms, the beneficiary consent, and a second PCU liveness check serve as the patient's digital signature. Consent, in other words, is now an auditable record inside your systems — treat it that way.
Practical consent hygiene for a clinic:
- Consent must be specific to the purpose — treatment, PhilHealth claims submission, and any secondary use are distinct purposes.
- Keep signed forms (paper or digital) retrievable per patient; auditors and lawyers ask for them by name.
- Do not reuse patient data for marketing or research without separate consent.
Breach Duties: The 72-Hour Clock
When sensitive personal information is unlawfully acquired and there is a real risk of serious harm, Section 20(f) of RA 10173 requires you to promptly notify the NPC and the affected patients. NPC Circular 16-03 puts numbers on "promptly": notification within 72 hours of knowledge or reasonable belief of a notifiable breach, and a full report within 5 days unless the NPC grants more time.
What this means operationally:
- Have a breach-response plan before you need one — who declares a breach, who drafts the NPC notice, who calls patients.
- Know where your data lives. You cannot scope a breach in 72 hours if records are scattered across USB drives, personal laptops, and a filing room.
- Never conceal. Section 30's concealment penalty is separate from — and can stack on top of — the breach itself.
How an EMR Helps You Comply
A well-built EMR is the "reasonable and appropriate technical measure" Section 20 demands, implemented once instead of improvised daily. The safeguards that matter:
- Encryption in transit and at rest — patient data and claim files travel encrypted, so an intercepted file is not a readable chart. PhilHealth's own claim pipeline assumes this: claims move as encrypted XML files validated and submitted to PhilHealth's web service.
- Role-based access control — reception staff see scheduling and demographics; only physicians open clinical notes. This enforces the "need-to-know" principle the NPC expects, and creates the access records that prove it.
- Audit trails — who viewed or edited which record, when. Indispensable for both breach scoping and Section 16 access requests.
- Centralized storage — one governed database instead of shadow copies, which is what makes a 72-hour breach assessment achievable.
- Vendor accountability — Advisory 2016-0040 already required a MOA and Service Level Agreement with your EMR provider covering uptime and fault reporting; your EMR vendor is your "personal information processor," and the contract is part of your compliance file.
Note that a data migration is itself a privacy event: moving records from eKonsulta to a certified EMR means transferring sensitive personal information between systems, so do it under your DPO's oversight — our eKonsulta migration guide covers the mechanics, and how PhilHealth certifies an EMR explains what certification does and does not vouch for.
How RecordKo Approaches Data Privacy
RecordKo was designed for the certified-EMR era with RA 10173 assumptions built in: encrypted XML claim generation and storage, role-based access separating reception, doctor, and admin views, clinic-scoped data isolation so one clinic can never see another's patients, PCU liveness-check logging with transaction numbers for your audit trail, and digital eKAS/ePresS/YES document handling that keeps the consent and availment paper trail retrievable per patient. Compliance stops being a filing-room project and becomes how the software works by default.
References
- Republic Act No. 10173 — Data Privacy Act of 2012 (full text)
- NPC Circular 16-03 — Personal Data Breach Management
- NPC Circular 2022-04 registration requirements (DLA Piper summary)
- PhilHealth Advisory No. 2016-0040 — Electronic Medical Record System
- PhilHealth Circular No. 2025-0017 — Selection and Empanelment for PhilHealth's Primary Care Benefit Package
- PhilHealth Advisory No. 2026-0029 — Implementation of the Digital YAKAP Empanelment Slip (YES)