Glossary
What Chile's Ley 19.628 requires of your patients' health data
Ley 19.628, published on 28 August 1999 under the title on the protection of private life, defines sensitive data in article 2(g) and includes physical or mental health status among them. That reaches any system reading a medical record and writing to a patient.
What does it permit and what does it forbid today?
Article 10 forbids processing sensitive data, with three exceptions: where the law authorises it, where the data subject consents, or where the data are necessary to determine or grant health benefits owed to those subjects. Article 4 adds that the authorisation must be given in writing and may be revoked, also in writing, without retroactive effect.
The two regimes gate health data at different points. Chile requires a written authorisation before the data are processed; under HIPAA a US covered entity may use protected health information for its own treatment, payment and health care operations without individual authorisation.
| Ley 19.628 | Ley 21.719 | |
|---|---|---|
| Published | 28 August 1999 | 13 December 2024 |
| Health data | Sensitive data, article 2(g) | Sensitive personal data |
| Authority | No supervisory agency | Agencia de Protección de Datos Personales |
| In force | In force | Applies from 1 December 2026 |
For a patient outreach project there are three practical consequences: consent and its revocation get recorded, the role of whoever processes data on the provider's behalf gets written into a contract, and the institution defines the purposes. Ley 21.719 also creates a specialised authority, which changes who can ask to see that record.