Glossary

What Chile's Ley 19.628 requires of your patients' health data

Published

Ley 19.628, published on 28 August 1999 under the title on the protection of private life, defines sensitive data in article 2(g) and includes physical or mental health status among them. That reaches any system reading a medical record and writing to a patient.

What does it permit and what does it forbid today?

Article 10 forbids processing sensitive data, with three exceptions: where the law authorises it, where the data subject consents, or where the data are necessary to determine or grant health benefits owed to those subjects. Article 4 adds that the authorisation must be given in writing and may be revoked, also in writing, without retroactive effect.

The two regimes gate health data at different points. Chile requires a written authorisation before the data are processed; under HIPAA a US covered entity may use protected health information for its own treatment, payment and health care operations without individual authorisation.

Ley 19.628Ley 21.719
Published28 August 199913 December 2024
Health dataSensitive data, article 2(g)Sensitive personal data
AuthorityNo supervisory agencyAgencia de Protección de Datos Personales
In forceIn forceApplies from 1 December 2026

For a patient outreach project there are three practical consequences: consent and its revocation get recorded, the role of whoever processes data on the provider's behalf gets written into a contract, and the institution defines the purposes. Ley 21.719 also creates a specialised authority, which changes who can ask to see that record.

Does your legal team want the processing agreement in detail? Ask for it at pablo@superposition.company.