Data Privacy Notice
De Los Santos Medical Center Privacy Notice
De Los Santos Medical Center (“DLSMC”) is committed to uphold the safety and confidentiality of the Personal Information of all our data subjects. This Privacy Notice (“Notice”) therefore seeks to inform you of our policies regarding the collection, use, disclosure, retention, sharing and destruction of Personal Information of our customers and clients, as well as from our own personnel.
DLSMC has developed this Notice to ensure that all appropriate standards for Personal Information protection are in place in compliance with Republic Act No. 10173 or the Data Privacy Act of 2012 (“DPA”), its Implementing Rules and Regulations, and other applicable and related laws and regulations, including issuances and advisories of the National Privacy Commission.
What is Personal Information?
Under the DPA, Personal Information are information whether recorded in a material form or not, from which your identity is apparent or can be reasonably and directly ascertained by the entity holding the information, or when put together with other information, would directly identify you as an individual.
Personal Information also includes Sensitive Personal Information. You may refer to the link for the list of Sensitive Personal Information as enumerated under the Data Privacy Act of 2012 https://www.privacy.gov.ph/data-privacy-act/#13.
Why We Collect It
We collect your Personal Information, primarily, to provide medical services to patients or to process applicant/ employee data for employment purpose. With your consent we also disclose, share or provide such data to our clients, affiliates, partners and service providers who aid us in providing you with timely and efficient services.
We may also use your Personal Information, secondarily, in cases enumerated in the consent form you will sign upon availing DLSMC services or in case of applicants during the application process.
As a data subject you have the right to withdraw your consent (subject to the applicable laws) to the processing of your Personal Information at any time by contacting us in writing.
How and When We Collect Your Personal Information
Your Personal Information may be obtained in various ways including through interviews, from application forms or correspondences, by telephone or e-mail, via our website at http://delossantosmed.ph, and from third party providers. Nevertheless, the Personal Information we have are those that you have given us yourself or that of your authorized representative.
Your Personal Information is collected when:
a. you avail of, or apply for, our services by filling out application forms or other information forms through any of our available channels (e.g. online, during admission, or through our medical personnel and representatives);
b. you provide personal information to your doctor/s who may have referred you to DLSMC for diagnosis and treatment, whether as an in-patient or out-patient;
c. you get in touch with us via e-mail or voice call to inquire about something, file a complaint, or request for a service;
d. you take part in our research and surveys;
e. you participate in various activities sponsored by us or any other organization acting on our behalf, such as symposia, conferences, focus group discussions, promotional events and the like;
f. you apply for an internship program or medical training with us to fulfill your academic and clinical requirements; and
g. you apply for a job with us.
Use and Processing of Personal Information
The following categories generally describe the ways by which DLSMC processes your Personal Information. While this is not intended to be a very specific and detailed listing of each process per category, all the ways by which we process your Personal Information fall under one of these categories:
a. Your diagnosis and treatment: we use your Personal Information, particularly your medical background and information to allow us to appropriately provide medical care and services, including diagnostics and treatment. DLSMC will disclose your Personal Information to our physicians and healthcare providers, our affiliates, subsidiaries, related entities and authorized partners (including third party providers) as part of our regular business operations for these purposes.
b. For benefits, payments and claims: We may process your Personal Information for purposes of billing and payment for medical and other related services rendered. Bills may be collected from you, your insurance company, Philippine Health Insurance Corporation, your company or any third party provider. For this purpose, we may have to disclose the nature and type of your treatment and other related information that will be required for the settlement of your account.
c. For our business operations: Your Personal Information will be processed as part of DLSMC’s operations. This includes our general business management operations, quality control and assessment, employee and/or staff evaluation and financial performance reporting.
d. Performance of a legal obligation: Under the law, DLSMC is required to share your Personal Information to government authorities in certain instances. This may occur for instance when DLSMC may be required to provide documentary and/or testimonial evidence in court proceedings that may require the disclosure of your Personal Information. We may also be required to provide sensitive personal information or health information in compliance with RA 11332 or Law on Reporting of Communicable Diseases to proper government authorities.
e. Marketing and other legitimate commercial purposes. We may also use your Personal Information to contact you with newsletters, information campaigns, marketing or promotional materials and other information that may be related to the services we provide, and also to further improve the quality of our services.
Other uses and disclosures of your Personal Information
Outside of the purposes stated above, other uses and disclosures of your Personal Information will only be made:
a. with your express consent,
b. in case of an emergency, or
c. when otherwise permitted or required by law. Such circumstances include the disclosure of your Personal Information pursuant to an order of a court or tribunal, or when such disclosure is required under existing laws and regulations such as but not limited to RA 11332 or the Mandatory Reporting of Notifiable Diseases and Health Events of Public Health Concern Act and Administrative Order No. 2016-0002 or the Health Privacy Code.
d. when filling up DLSMC’s Online Health Declaration Form and for contact tracing as provided under Department Memorandum 2020 – 0189 of the DOH, or the Updated Guidelines on Contact Tracing of Close Contacts of Confirmed Coronavirus Disease Cases.
In like manner, we may use and disclose your Personal Information to:
a. your visitors when they wish to inquire about you in the patient directory, and
b. other people involved in, or interested in your healthcare, such as your family members, loved ones or any other person you identify as being involved in your healthcare. In case you are not capable of agreeing or objecting to such disclosure, we will use our judgment in determining whether the use or disclosure is in your best interest.
In these cases, we ensure that your Personal Information is disclosed on a confidential basis, and is always subject to the applicable Privacy Laws. We will never share or sell your personal information to third party providers not affiliated with DLSMC except in circumstances determined in our Data Privacy Policy.
Who has access to your Personal Information?
The following will have access to your Personal Information:
a. Healthcare professionals including but not limited to members of DLSMC’s medical staff, nurses and other healthcare providers, either pursuant to an employment contract or any other arrangement. They will have access to your Personal Information because they are authorized to enter information into your medical records, as well as to review or update the same.
b. All departments and units in DLSMC who will need your personal information in the performance of their functions. For example, certain treatments or procedures require that your Personal Information be shared across different departments of DLSMC.
c. Any member of a volunteer, religious or charitable/non-profit organization who is allowed to provide assistance within DLSMC. This includes priests, pastors or heads of other religious organizations who provide religious rites to patients or the deceased.
d. All of our non-medical employees, staff or personnel who may need access to your information in the performance of their duties. For example, our employees will access your Personal Information in order to prepare your billing statement. Likewise, your medical information will be needed for your dietary needs during your confinement.
e. All entities operating within the premises of DLSMC, including, but not limited to housekeeping and security. DLSMC may share your personal information with these entities for the purposes stated above.
How do we secure and protect your Personal Information?
Our Privacy Notice applies to your Personal Information that we have collected. DLSMC creates and maintains a record of your Personal Information in its offices to serve you better. Under the DPA, DLSMC is likewise required to protect your Personal Information, and to process such data only in accordance with the following data privacy principles:
a. Transparency: We are obligated to inform you of the nature, purpose and extent of why we are processing of your Personal Information, including the risks and safeguards involved, the identity of the persons involved in the processing of your Personal Information, your rights as data subject, and how these rights can be exercised.
b. Legitimate purpose: We will only process your Personal Information for a legitimate purpose, compatible with our declared and specified purpose, and not contrary to the law, accepted morals and public policy.
c. Proportionality: We will process your Personal Information as adequate, relevant, suitable, necessary and not excessive in relation to the declared and specific purpose.
Your Personal Information is stored in a manner that reasonably protects it from misuse and loss, and from unauthorized access, modification or disclosure. We strictly enforce our Privacy Policy and have put in place technical, organizational and physical security measures that are designed to protect your Personal Information from unauthorized access, use, alteration, and disclosure.
When your Personal Information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to dispose or permanently anonymize the said data. However, most of the personal information is or will be stored in files that will be kept by us for the minimum period provided under existing laws and regulations.
How can I access my Personal Information?
You may gain access to the Personal Information that we have lawfully collected from you in order to update and/or correct it, subject to certain exceptions. If you wish to access your Personal Information, please contact us in writing and we will respond to you within a reasonable timeframe. Please take note that our ability to respond to your request may depend on the circumstances regarding our collection of your Personal Information. We may charge a reasonable administrative fee for providing a copy of your Personal Information.
In order to protect your Personal Information, we may require identification from you before releasing the requested information.
On another note, we may be restricted by law or certain regulation from giving you access to a Personal Information without proper authorization as required by law or existing regulations.
Links to Other Websites
Our website may contain links that enable you to easily visit other websites of interest. However, once you have clicked a link that leads you away from our site, please take note that we do not have any control over other websites. Therefore, we cannot be responsible for the protection and privacy of any information that you have provided whilst visiting such sites. Moreover, such sites are not governed by this privacy statement. Therefore, we advise you to exercise caution and read the privacy statement (if applicable) of the website/s that you are visiting.
Changes to the Privacy Notice and Privacy Policy
From time to time, we may change or update our Privacy Notice or Privacy Policy and related practices to comply with government and regulatory requirements, to adapt to new technologies and protocols, to align with industry practices, or for other legitimate purposes.
Know More
As data subjects, you are afforded certain rights in relation to your Personal Information under the Data Privacy Act of 2012. As such, we constantly ensure that we have your consent to collect, use, disclose, retain and dispose your Personal Information for the purposes that we have identified. You have the right to be informed of these specific rights, to object to the processing of your Personal Information, to access, update and correct your Personal Information, and to withdraw your consent and/or edit your consent preferences at any time.