Skip to content
MVPeople Group Logo
MVPeopleGroup
All case studiesHealthcare

Privacy & DPO team strengthened for top-10 hospital

5 weeks
3 specialists

About the organisation

Academic hospital in the Dutch top-10 with 11,000 employees, 800 beds and 450,000 patient contacts per year. Processes medical records, genetic data and research data. Supervised by the Dutch Data Protection Authority and the Health and Youth Care Inspectorate.

The Challenge

Following an enforcement decision by the Dutch Data Protection Authority regarding the sharing of patient data with a research partner, the hospital had to expand its privacy team within 3 months with a Data Protection Officer, a senior privacy officer and a privacy engineer. The existing team of 2 people could no longer handle the workload: 340 processing activities, 85 DPIAs in the pipeline, and a growing number of data breach notifications.

The healthcare sector places unique demands on privacy professionals. They must not only know GDPR, but also Dutch healthcare-specific legislation (Wgbo, Wbp-Z) and the NEN 7510 framework. Candidates with this combination of legal and healthcare-specific knowledge are extremely scarce — there are an estimated fewer than 200 professionals with this profile in the Netherlands.

Our Solution

MVPeople Group combined MVProfessionals (secondment) for the DPO and senior privacy officer — roles requiring immediate deployment — with MVPermanent (recruitment & selection) for the privacy engineer, a role for which the hospital sought a permanent employee. We activated our specific network of healthcare privacy professionals, built through 3 years of recruitment in the healthcare sector.

For the DPO role, we selected a candidate with 8 years of experience in academic hospitals, including experience setting up a privacy-by-design framework for EHR systems (HiX/Epic). The senior privacy officer had demonstrable experience with DPIAs in a clinical research environment. The privacy engineer had a technical background in data masking and pseudonymisation of medical datasets — crucial for the hospital's research collaborations.

Results

  • DPO and 2 privacy professionals placed within 5 weeks
  • DPIA backlog reduced from 85 to 12 in 4 months
  • Processing register fully revised and updated (340 processing activities)
  • DPA enforcement case successfully closed without fine
  • Privacy-by-design framework implemented for 3 new EHR modules

In healthcare, you need privacy specialists who understand both GDPR and healthcare legislation, and who know how an EHR system works. MVPeople found three professionals who met all these criteria. I didn't think that was possible.

Chief Privacy Officer

What the team says

The DPO that MVPeople delivered had previously worked at two other academic hospitals. That experience was invaluable — she knew all the pitfalls and best practices from real-world practice.

Chairman of the Board

READY TO FIND THE RIGHT CYBERSECURITY PROFESSIONAL?