JHAH respects your privacy and is committed to protecting your personal data. This policy describes the types of information we may create or obtain about you and the ways in which we may we collect, use and disclose your personal data. It also describes your rights and certain obligations we have regarding the processing of your personal data in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia, and its Implementing Regulations (the “PDPL”).
Personal data is any information, regardless of its source or form, about an individual from which that person can be identified, directly or indirectly. Therefore, your personal data is any information that can be attributed to you personally, and includes, for example, your name, address, identification number, date of birth and contact details. Personal data also includes more sensitive personal data, for example, personal data relating to your racial or ethnic origin, religious, intellectual or political beliefs, criminal offenses, biometric data, genetic data and health information.
The personal data which we process includes, but may not be limited to, the following: full name, address, contact number, email address, marital status, date of birth, gender, age, ethnicity, nationality, religion, contact details of parent/guardian/agent, emergency contact/next of kin or nearest relative details, national ID number, medical record number, health ID number, health/medical information (including appointments, hospital visits, tests, diagnoses, treatments, operations, medications, allergies, disabilities, comorbidities, other health conditions, biometrics (such as height and weight), biological information (such as blood type), x-rays, scans, ultrasound images, genetic data, and family medical history), information from research/clinical trials, insurance details or other financial information on payments, and any images that have been captured by CCTV security cameras in our hospital.
JHAH routinely and legitimately collects personal data in the course of a patient’s enrollment, examination, care or treatment in JHAH’s facilities and/or those of its network of health care providers. The personal data we process is largely collected directly from you, but sometimes, we may also be need to collect information about you from a third party (such as a relative or another health service provider).
Where we ask you to provide personal data to us on a mandatory basis, we will inform you of this at the time of collection. Failure to provide certain information when requested, may mean that JHAH will not be able to provide you with the required healthcare services.
We collect and use your personal data in order to provide you with health care services and for administrative and internal business purposes related to your attendance at JHAH. We always use the minimum personal data needed and anonymize data where personal data is not required for the purpose.
JHAH will only process personal data where it has a legal basis for doing so. We generally process your personal data under one or more of the following basis:
Your personal data may be stored in various forms, including electronic and/or physical (paper) form in accordance with customary practices. JHAH has put in place appropriate technical, organizational and security measures to ensure your personal data is stored securely and protected from misuse, loss, unauthorized access, alteration, disclosure or destruction. We use technologies and processes such as access control procedures, network firewalls, encryption and physical security to protect your personal data.
The following categories generally describe the ways by which JHAH may use and/or disclose your personal data. While every use or disclosure is not listed, all of the ways by which we use and/or disclose your personal data will fall within one of the following categories:
JHAH will only use your personal data for the purposes for which it was collected. Outside of the purposes stated above, other uses and disclosures of your personal data will be made only with your consent, unless we are otherwise permitted or required by law to do so.
JHAH may disclose your personal data to third parties for the purposes stated above. JHAH (or third parties acting on our behalf) may also store or process your personal data in jurisdictions outside the Kingdom of Saudi Arabia. Where we disclose or transfer your personal data outside of the Kingdom of Saudi Arabia, we will take the necessary steps to ensure that your personal data is protected to the standard required by the PDPL.
Under the PDPL, you have the following rights regarding the personal data we maintain about you:
JHAH will only retain personal data for as long as necessary to fulfil the purposes for which it was collected and in order to comply with any legal or regulatory requirements. To determine the appropriate retention period for personal data, we consider whether there is an ongoing relationship, the nature and sensitivity of the personal data, any applicable legal or regulatory requirements and our legitimate business needs.
If you have any questions, concerns or complaints regarding this policy, the information we hold about you, or if you wish to exercise your rights, you can contact our DPO using the details below.
By email: JHAHClinicalInformatics@JHAH.com
By mail: Johns Hopkins Aramco Healthcare, Clinical Informatics Department, Data Protection Officer, P.O. Box 76, Dhahran 31311, Saudi Arabia
JHAH may change or update this policy at any time. The current policy will be published to JHAH’s website or can be obtained by contacting us.
You acknowledge that you have read and understand this policy and, by signing the Consent to General Treatment, that you consent to JHAH processing your personal data as described within this policy.