Privacy and Confidentiality Policy
Boston medical center is committed to protecting the privacy and confidentiality of our patients’ personal and medical information. This policy outlines how we collect, use, disclose, and secure your data in compliance with the laws of the United Arab Emirates and the regulations of the Ministry of Health and Prevention (MOHAP).
1. Collection of Patient Information
We collect a range of information necessary for providing high-quality healthcare, including:
- Personal Identification Data: Your name, Emirates ID, date of birth, contact details (phone number, email address, address), and nationality.
- Medical and Health Data: This includes your medical history, current symptoms, diagnosis, treatment plans, lab results, radiology images, and other clinical notes.
- Financial and Insurance Information: Details related to your health insurance, billing information, and payment records.
This information is collected from you directly, from other healthcare providers (with your consent), and through the use of our electronic health records system.
2. Use of Patient Information
Your information is used for the following purposes:
- Provision of Medical Care: To diagnose and treat your medical conditions, coordinate with other healthcare professionals, and provide you with a safe and effective treatment plan.
- Administrative and Financial Management: For billing, insurance claims processing, appointment scheduling, and other administrative tasks.
- Quality Improvement and Audits: To monitor and improve the quality of our services, conduct internal audits, and ensure compliance with regulatory standards.
- Compliance with Legal Obligations: To meet legal requirements, including reporting to the relevant health authorities (e.g., MOHAP) and responding to lawful requests from judicial bodies.
3. Disclosure and Sharing of Information
Patient information is strictly confidential and will not be disclosed to any third party without your express written consent, except in the following situations as permitted or required by UAE law:
- Coordination of Care: Information may be shared with other licensed healthcare professionals involved in your treatment.
- Insurance and Billing: Your data may be shared with your insurance provider to process claims and verify coverage.
- Public Health and Safety: We may disclose information to public health authorities for the purpose of disease prevention or public health initiatives.
- Judicial and Legal Requests: In compliance with a court order, a legal process, or a request from a competent judicial authority.
- Medical Research: Anonymized or de-identified data may be used for scientific research purposes, provided that your identity is not disclosed.
As per Federal Law No. (2) of 2019, all health facilities are required to contribute to a national health information system. This means your data may be uploaded to a central government-controlled system (like Reayati or the relevant MOHAP system in Ras Al Khaimah) to enable the exchange of information among authorized healthcare providers.
4. Patient Rights
As a patient, you have the following rights regarding your health data:
- Right to Access: You have the right to request access to and receive a copy of your medical records.
- Right to Amendment: You have the right to request corrections to any inaccuracies in your medical record.
- Right to Confidentiality: You have the right to have your information kept confidential and secure.
- Right to Complaint: You have the right to file a complaint if you believe your privacy rights have been violated.
5. Data Security
We implement robust technical, administrative, and physical safeguards to protect your data from unauthorized access, loss, or alteration. These measures include:
- Electronic Health Records (EHR): Using secure, encrypted EHR systems.
- Access Control: Limiting access to patient records to authorized personnel on a need-to-know basis.
- Physical Security: Securing all physical records in locked cabinets and restricted areas.
- Training: All staff receive regular training on patient privacy protocols and data protection laws.
6. Data Retention
In compliance with UAE health regulations, medical records are retained for a minimum period of 25 years from the date of the last procedure or consultation. After this period, records will be securely disposed of.