First, the hospital’s top management should decide the scope of the quality management services. I see hospitals that certified only Imaging Services. I see hospitals that certified Radiology, Physiotherapy and Blood Bank. I see hospitals that certified Orthopedic Services, …
Once the scope is decided one can start to draw the processes. For example for a planned hospitalization can be seen as having as the main processes: Reservation; Admission; Treatment; Discharging.
What I see is hospitals with a legal service monitoring legal requirements and obligations.
The following material will provide you information about implementing an ISO 9001 management system:
The quality manager should comply with the following requirements:
- Understanding the needs of interested parties:
- Establishment and continual improvement of the QMS processes
- Customer focus and product conformity
- Responsibility and authority for the QMS
- Monitoring quality objectives
- Internal and external communication
- Release of products and services
- Internal audit planning & management
- Responsible for Nonconformities and corrective actions
Keep in mind that there are no requirements that say you need to have a quality manager in this ISO 9001:2015.
Regarding the processes - Usually process owners know better than anyone in the organization how the process works, so if you find him/her competent in doing so, they can prepair it with the following approval of the top management or quality manager.
Based on the description you provided, the best way to move forward is to set up in place an Intragroup Data Transfer Agreement based on Controller to Controller Standard Contractual Clauses.
To learn more about international data transfers check out our webinar “How to make personal data transfers to other countries compliant with GDPR” https://advisera.com/webinars/how-to-make-personal-data-transfers-compliant-with-gdpr-free-webinar-on-demand/
Personal Data Protection Policy template
We are a small internet company which mainly develop internet pages for clients (and sometimes do the hosting) with only 2 people (both in the technical and design areas) , So, we don’t have such large list of managers.
Which much worries me is that we don’t have a Data Protection Officer, which is widely referenced in the document, then who will the person in charge of data protection matters?, since as far I know this position is not mandatory for us.
Answer:
The documents are indeed optimized for small and medium size companies and all the job titles are mentioned as examples, you are free to replace the job titles to best suit your organization.
Same goes for the DPO as well, you can have some other employee deal with privacy related matters. The DPO needs to be appointed only if: (a) the processing is carried out by a public authority or body, except for courts acting in their judicial capacity; or (b) the core activities of the legal entity consist of processing operations which, by their nature, their scope and/or their purposes, require regular and systematic monitoring of data subjects on a large scale; or (c) the core activities of the legal entity of processing on a large scale of special categories of data pursuant to Article 9 of the EU GDPR and personal data relating to criminal convictions and offences referred to in Article 10 of the EU GDPR.
We are building an ISMS for an ISO 27001 certification of our entire company. Now the question comes up about the requirements for our data center. Are all these points that are important for certification complete?
- Access protection
- Password policy compliance
- Typical irritant signals: fire loads, dirt or water-bearing cables in data centers or craft materials in server cabinets or unlabeled data carriers lying around.
1. In other words: What are the requirements for our data center provider if we want to certify ourselves as an entire company ISO72001?
Answer: The requirements your datacenter provider must fulfill are practically the same you would have to fulfill if the datacenter belonged to your organization, and without more detailed information abou t your context it is not possible to provide an specific answer. Since your provider is not ISO 27001 certified yet, I'd suggest you to talk to them about performing a risk assessment together to identify which risks the provider must have to treat, so these treatments can be defined as contractual clauses in your service agreement.
2 . Can we also successfully certify ourselves to ISO 27001 with a data center without ISO 27001 certification?
Answer: Provided that your provider can show evidences that it is handling your security requirements as defined in the service agreement, there is no need for the provider to be ISO 27001 certified, although this certification can prove beneficial to it to minimize compliance costs.
Filling the Business Impact Analysis questionnaires
Answer: There is no need to figure out different values of working capital for each time frame. In this part of the questionnaire you only have to identify for how much time you will need the working capital available to resume operations. For example, for a just in time operation which needs US$ 500K of working capital, you my decide to mark that this capital is needed immediately or up to 1h after the disruptive event. For an activity that keeps a significant a stock of products, you may mark that this capital is needed up to 1 week.
2. Under ‘External services’ should the top 10 suppliers be named if the list consists of thousands?
Answer: Under ‘External services’ you have to list the most critical suppliers to ensure the cont inuity under the minimum service levels agreed. These can vary from one to several, depending on the scenario you define.
Included in the toolkit you bought, there is a video tutorial that can help you fill in the Business Impact Analysis, using real data so facilitate the understanding.
Information security standards for medical devices
Answer:
For the protection of personal health information and compliance with medical-related regulations, I suggest you to consider ISO 27001 together with ISO 27299 and ISO 13485.
ISO 27799 has the objective to provide security controls to protect personal health information, presenting guidance for this specific sector.
ISO 13485 has the objective to specify requirements for a Quality Management System where an organization needs to demonstrate its ability to provide medical devices and related services that consistently meet customer and applicable regulatory requirements.
Answer:
If I understand correctly the subject, I, as an assessor, would like to see the performance of the organization (the organization is the client of LRQA) against the management system objectives. What are the trends? What is the evolution of the results? Were the action plans implemented? Were the action plans effective?