Aug 20, 2025
31
Purpose
- To protect the confidentiality, security, and integrity of data and information.
- To identify the level of confidentiality maintained for different categories of data and information.
Policy Statement
- SSMC IT is committed to processing electronic data and personal information lawfully and fairly and to take all reasonable steps to protect and safeguard personal information.
- This policy describes the privacy principles for handling IT data and personal information.
Abbreviations
- SSMC-DKP: SmartSalem Medical Centre Dubai Knowledge Park
- SSMC-IMC: SmartSalem Medical Centre Index Mall
- SMC-CW: SmartSalem Medical Centre City Walk
- SSMC-HQ: SmartSalem Medical Centre Head Quarter
Definitions
- Consent: Specific and informed expression of will in terms of patient and customer agreeing processing of personal information relating to him or her.
- Personal Information: Information relating to identifiable, living, natural persons, and where it is applicable, and identifiable, including but not limited to:
- Race, gender, sex, color
- Pregnancy
- Marital status
- Sexual orientation
- Age
- Physical and mental health, well-being
- Disability
- Religion, conscience, belief
- Culture
- Language
- Education, medical, financial, criminal or employment history
Responsibilities
- Heads of departments are responsible and accountable for implementing the policy in their respective departments and to report any breach found to the IT Department.
- IT Managers will be responsible for the continuous monitoring, managing, and reporting of IT risks and implementation of mitigating actions/controls related to data and information privacy and confidentiality.
- The IT Director will be responsible for the continued optimal functioning and compliance of the Data privacy and confidentiality policy.
Procedure
- This policy will apply to all employees, contractors, consultants, temporaries, and other third parties associated with SSMC. It encompasses a regular assessment of the relevant information risks to the achievement of the business objectives, forming a basis for determining how the risks should be managed to an acceptable level. It also addresses the performance of subsequent risk assessments, the formal acceptance of residual risk, and the selection of mitigating actions/controls and monitoring of these risks on a continuous basis.
- This policy covers all personal information collected, processed, and stored by SSMC whether located at SSMC or non-SSMC locations, and by third parties who have access to SSMC’s information resources.
- Governing Principles:
- SSMC Data and Personal information are valuable to the SSMC.
- Collection, storage and use of SSMC and personal information through our daily undertakings form part of normal business activities. To treat this information with the highest standard of confidentiality and privacy, it is important that all employees comply with the requirements of SSMC data privacy and confidentiality policy.
- Ownership of Information:
- All information that is processed by SSMC, its employees and/or contractors on SSMC electronic equipment, in hard copy format and/or soft copy, or on any storage or transmission system is the property of SSMC and is deemed to be owned by SSMC.
- Information Collection:
- Collection of SSMC Data and Personal information must be lawfully and reasonably done giving due consideration to it being adequate, relevant, and not excessive for the specific business purposes that it will be used and required. It must be collected directly from the patient/customer unless:
- Information is obtained in a public record or has deliberately been made public by the patient/customer.
- Patient/customer has consented to the information being obtained from another source; and Compliance would prejudice a lawful purpose of collection.
- Collection of SSMC Data and Personal information must be lawfully and reasonably done giving due consideration to it being adequate, relevant, and not excessive for the specific business purposes that it will be used and required. It must be collected directly from the patient/customer unless:
- Consent:
- No personal information may be disclosed or processed in any way that is incompatible with the consent provided, unless subsequent consent has been obtained while conducting business.
- Notice:
- Notice should be provided to the customer/patient at the time of collection describing the purpose for which personal information is collected, whether the supply of personal information is voluntary or mandatory, the consequences of failure to provide the information and how personal information will be used.
- Use and Disclosure:
- Information must only be used for the purposes for which it was collected with due consideration or as required or authorized by or under the law.
- All suppliers and vendors who have access to any of the IT systems or collect business information must sign and abide to the SSMC Non-Disclosure Agreement.
- Information Sharing:
- Sharing of personal information with parties outside of SSMC (third parties) will only be permitted where the customer/patient consent has been obtained and where such third party affords the same level of protection for personal information as is required by law.
- Transfer of Personal Information outside United Arab Emirates.
- Transfer of personal information to third parties outside United Arab Emirates is prohibited unless:
- The customer/patient consents to the transfer.
- The transfer is necessary for the performance of a contract between the customer/patient and SSMC, or for the implementation of pre-contractual measures taken in response to the customer/patient’s request.
- The transfer is necessary for the conclusion or performance of a contract concluded in the interest of the customer/patient between SSMC and a third party; or
- The transfer is for the benefit of the customer/patient, and it is not reasonably practicable to obtain the consent of the customer/patient to that transfer; and if it were reasonably practicable to obtain such consent, the data subject would be likely to give it.
- Transfer of personal information to third parties outside United Arab Emirates is prohibited unless:
- Information Retention:
- All reasonable steps must be taken to ensure personal information is retained only for as long as needed to meet the purposes for which it was collected and in accordance with our IT backup and restore policy and Retention of medical records policy.
- Information Security:
- All reasonable steps must be taken, including physical, administrative, and technical safeguards, to protect personal information from loss, misuse, unauthorized access, disclosure, alterations, and destruction.
- Awareness and Education:
- SSMC will ensure that privacy issues are discussed on an annual basis to ensure staff understand the importance of this pertinent issue and have the means to deal with this in an appropriate manner.
- Incidents:
- All information privacy related incidents must be reported to the IT Department for investigation and resolution.
- Violation:
- Any discovery of violation on the above guidelines should be reported through incident reporting. Problems should be rectified, and actions should be taken as per the HR policies.
- Governing Principles:
Measures to be taken:
To avoid unauthorized access to Personal Data and Data protection the following security requirements shall be applied.
- Staff members must not be authorized to access the patient’s data without manager’s permission. These levels will be in accordance with the requirement to undertake their roles efficiently and effectively.
- IT will create different security groups on Active Directory (for data access control) and on HIS (for patient data access) to control the user access to respective sources.
- Staff must log off from their systems or their personal computer whenever they leave the terminal to avoid unauthorized access.
- No staff member should allow others to operate the patient systems using their password.
- Staff must keep passwords confidential and if a member of staff becomes aware that their password has been compromised, they must report it to the IT Department, who will help them to change the password.
- Regular back up will be scheduled by SSMC IT to protect the data from the occurrence of any unpleasant event.
