Security

Who owns the patient data: the hospital or the AI vendor?

The hospital owns and controls patient data; an AI vendor is a data processor that may use it only to deliver the contracted service. Under privacy laws such as Indonesia's UU PDP, Singapore's PDPA, and Hong Kong's PDPO, the institution remains accountable for patient data, so the contract must say so explicitly: the institution retains ownership and control, the vendor processes data only on documented instructions, there is no model training or secondary use without written agreement, and data is returned and deleted when the contract ends. A vendor that claims ownership of your patient data, or is vague about it, is disqualifying.

The legal frame is the controller-processor distinction. The hospital (and behind it, the patient) is the data controller: it decides why and how patient data is used, and it answers to the regulator. The AI vendor is a processor acting on the hospital's instructions. That distinction should be written into the agreement as concrete clauses: an ownership and control statement; a use-limitation clause restricting processing to the contracted workflow; an explicit position on model training and product improvement; transparency on subprocessors; audit rights the hospital can actually exercise; and an exit clause guaranteeing return and deletion of data, including backups, within a stated period.

Micromeet's position is simple: the institution's data stays the institution's. Patient data is processed only to run the contracted workflow — whether MCU CoPilot is drafting a medical check-up report or AI Scribe (Voice-to-EMR) is drafting a clinical note — and every clinical output still passes a doctor-review gate before it enters the record. That is governed healthcare AI: AI writes. Doctors decide. Ownership, residency, retention, and deletion terms belong in the contract, not on a marketing page, and a serious vendor will put them there without being pushed.

Related questions

Can an AI vendor train its models on our patient data?+
Only if the institution has explicitly agreed in writing — and the default answer should be no. Ask the vendor to state in the contract whether patient data is used for model training or product improvement, under what de-identification standard, and with what opt-out. Silence on this point is a red flag.
What happens to patient data when the contract ends?+
The contract should guarantee an exit path: the institution's data is returned in a usable format and then deleted from the vendor's systems, including backups, within a stated period, with written confirmation. Agreeing this before signing is far easier than negotiating it during an exit.
Does storing data in the vendor's cloud change who owns it?+
No. Hosting location affects which laws apply and which residency guarantees are needed, but it does not transfer ownership. The institution remains the data controller; the vendor and its cloud provider act as processors under contract.

Micromeet — AI for governed healthcare. MCU CoPilot, AI Scribe (Voice-to-EMR), AI Front Desk, Care Loop, Claim Readiness and AI Care Command Center — every output doctor-reviewed. AI writes. Doctors decide. See the public benchmark →