Electronic Medical Record (EMR) Privacy Policy
1. Purpose and Scope
This Privacy Policy governs the collection, processing, storage, protection, and disclosure of personal data through the Electronic Medical Record (EMR) managed by CFA Longcare Medical Laboratory ("Facility," "We," "Us," or "Our").
This policy applies to all patients, referring physicians, clinical staff, medical technologists, administrative personnel, and system operators who access or utilize our EMR platform. It is established in strict compliance with the Philippines’ Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations (IRR), and applicable guidelines set forth by the National Privacy Commission (NPC), the Department of Health (DOH), and the Philippine Health Insurance Corporation (PhilHealth).
2. Types of Data Collected
To conduct diagnostic evaluations, release clinical laboratory reports, and manage administrative workflows, CFA Longcare Medical Laboratory collects and processes Personal Information (PI) and Sensitive Personal Information (SPI):
A. Personal Information (PI)
- Identification Data: Full name, date of birth, age, sex, civil status, home address, contact number, and email address.
- Administrative Identifiers: PhilHealth Identification Number (PIN), Tax Identification Number (TIN), National ID (PhilID), government-issued ID details, and Laboratory Patient ID / Accession Number.
- Emergency & Representative Contact: Name, relationship, address, and contact details of next of kin or authorized representative.
B. Sensitive Personal Information (SPI) & Diagnostic Data
- Clinical & Diagnostic Information: Referring physician's name, clinical history, diagnostic test orders, specimen types, laboratory examination findings (e.g., hematology, clinical chemistry, microbiology, serology, histopathology), and diagnostic reports.
- Financial & Insurance Data: Health maintenance organization (HMO) details, PhilHealth benefit claim details, corporate account billing, and payment transaction logs.
- Biometric & Technical Data: Digital signatures of medical technologists and pathologists, system access logs, IP addresses, audit trail entries, and user authentication credentials.
3. Purpose and Lawful Basis of Processing
Pursuant to Sections 12 and 13 of RA 10173, CFA Longcare Medical Laboratory processes personal data based on explicit consent, medical contract fulfillment, legal compliance, or public health protection for the following purposes:
- Diagnostic Service Delivery: Processing laboratory orders, performing diagnostic testing, generating laboratory results, and providing diagnostic reports to referring physicians and patients.
- Quality Control & Laboratory Operations: Validating test accuracy, conducting internal and external quality assessments, and managing sample tracking/chain of custody.
- Statutory & Insurance Claims Processing: Submitting diagnostic claims to PhilHealth, HMOs, or private health insurers for billing and reimbursement.
- Regulatory Reporting & Public Health Surveillance: Complying with mandatory DOH reporting guidelines for communicable diseases, epidemic outbreaks, and national health statistics.
- System Management & Security: Monitoring EMR stability, tracking user access, preventing unauthorized disclosure, and maintaining immutable audit trails.
4. Data Collection Methods and Consent
- Direct Collection: Data is gathered directly from patients during registration, specimen collection, or via digital booking portals.
- Referring Health Providers: Patient data and test requests submitted directly by referring doctors, clinics, or partner hospitals.
- Informed Consent: Patients review and execute a Patient Data Privacy Consent Form prior to specimen collection or diagnostic procedure.
- Emergency / Vital Interest Processing: Under Section 13(d) of RA 10173, sensitive health data may be processed without prior written consent when necessary to safeguard life and health during a medical emergency where the data subject is physically or legally incapable of giving consent.
5. Data Disclosure and Sharing
CFA Longcare Medical Laboratory enforces strict confidentiality standards. Diagnostic records and personal health data will only be disclosed under controlled conditions:
| Recipient / Partner | Purpose of Disclosure | Safeguards & Legal Basis |
|---|---|---|
| Referring Physicians & Clinics | Transmittal of diagnostic test results for clinical evaluation | Role-based verification and professional medical confidentiality |
| PhilHealth & DOH | E-claims submission, mandatory disease surveillance, and quality audit | Statutory mandate under Universal Health Care Act and DOH directives |
| HMOs / Corporate Accounts | Pre-authorization, diagnostic verification, and account billing | Explicit patient consent provided during registration or consultation |
| External Reference Laboratories | Referral of specialized or esoteric diagnostic tests | Executed Data Sharing Agreements (DSA) compliant with NPC Circular 16-02 |
| IT & Cloud Infrastructure Partners | System hosting, database management, and backup recovery | Executed Data Outsourcing Agreements with explicit cybersecurity controls |
6. Data Retention and Disposal
- Retention Period: Laboratory records and diagnostic test results within the EMR are retained in strict accordance with DOH rules on laboratory record management (generally a minimum of ten (10) years from the date of release, or longer for specialized medical registries and legal requirements).
- Secure Disposal: Expired physical and electronic records undergo secure disposal. Digital files are wiped using standards equivalent to DoD 5220.22-M cryptographic sanitization, ensuring data cannot be retrieved or reconstructed.
7. Data Protection and Security Measures
In adherence to NPC Circular 16-01 (Security of Sensitive Personal Information), CFA Longcare Medical Laboratory implements robust safeguards:
A. Organizational Security
- Designation of a dedicated Data Protection Officer (DPO) to oversee data privacy compliance.
- Mandatory data privacy and security awareness training for all laboratory staff, medical technologists, and IT personnel.
- Binding non-disclosure and confidentiality agreements signed by all personnel and third-party vendors.
B. Technical & Cybersecurity
- Role-Based Access Control (RBAC): Strict privilege tiers restricting personnel access solely to data required for their specific role.
- Encryption Standards: Full end-to-end encryption for data in transit (TLS 1.3) and data at rest (AES-256).
- Multi-Factor Authentication (MFA): Multi-factor authentication enforced for all EMR accounts and remote portal log-ins.
- System Audit Trails: Immutable logs recording every instance of data entry, viewing, modification, printing, or exporting.
C. Physical Security
Secured server infrastructure, restricted-access computer terminals in testing areas, automated screen timeouts, and strict clean-desk policies.
8. Rights of Data Subjects (Patients)
Under Chapter IV, Sections 16–18 of the Data Privacy Act of 2012, patients of CFA Longcare Medical Laboratory possess the following rights:
- Right to be Informed: To know how their personal data is collected, processed, stored, and shared.
- Right to Access: To request official copies of their laboratory results and personal health records stored in the system.
- Right to Rectification: To request corrections to inaccurate or incomplete demographic information.
- Right to Erasure or Blocking: To request the suspension, withdrawal, or blocking of data processing upon valid grounds, subject to DOH laboratory record retention rules.
- Right to Data Portability: To obtain a copy of their laboratory results in an electronic, usable format.
- Right to File a Complaint: To raise grievances with the laboratory's Data Protection Officer or directly with the National Privacy Commission (NPC).
- Right to Damages: To be indemnified for damages sustained due to inaccurate, outdated, or unlawfully processed personal data.
9. Incident Management and Breach Protocol
CFA Longcare Medical Laboratory maintains a comprehensive Data Breach Management Plan. In the event of a security incident or unauthorized access affecting sensitive health data:
- The Data Protection Officer (DPO) and Incident Response Team will immediately isolate and secure the affected system.
- Pursuant to NPC Circular 16-03, the National Privacy Commission (NPC) and affected Patients / Data Subjects will be formally notified within seventy-two (72) hours from knowledge of a reportable breach.
10. Policy Updates and Amendments
We reserve the right to revise this Privacy Policy to reflect updates in legal requirements, health regulations, or technology standards. Revisions will be posted within our facility, on our official patient portal, and across authorized communication channels.
11. Contact Details of Data Protection Officer (DPO)
For inquiries, requests to exercise data privacy rights, or concerns regarding the processing of personal data, please contact: