Last Updated: 14/08/2024
Introduction
Cedarcrest Hospitals LTD (“Cedarcrest”, “we”, “us”, or “our”) is committed to protecting the privacy of our patients, visitors, and employees in accordance with the Nigeria Data Protection Regulation (NDPR) and other relevant Nigerian laws. This Privacy Policy describes the types of information we collect, how we use it, and the choices you have about your information.
Information We Collect
We collect information that you provide to us directly, as well as information that we collect automatically.
Information You Provide:
- Patient Information: When you receive care at Cedarcrest, we collect personal and health information, including:
- Name, address, date of birth, contact information
- Medical history, diagnoses, treatments, medications
- Insurance information
- Emergency contact information
- Website Information: When you visit our website, we may collect information you provide, such as:
- Name, email address, phone number
- Information you submit through forms or surveys
- Feedback and comments
Information We Collect Automatically:
- Website Usage Data: We collect information about how you use our website, such as:
- IP address, browser type, operating system
- Pages visited, links clicked, time spent on pages
- Device Information: We may collect information about your device, such as:
- Device type, operating system, unique device identifiers
How We Use Your Information
We use your information for the following purposes:
- Providing Healthcare Services: To provide you with medical care, including diagnosis, treatment, and follow-up.
- Billing and Insurance: To process your bills and claims with insurance companies.
- Operations: To manage our hospitals, including scheduling appointments, managing records, and improving our services.
- Communication: To communicate with you about your care, appointments, and other important information.
- Website Improvement: To improve our website, analyze traffic, and personalize your experience.
- Research and Development: To conduct research and develop new treatments and services, with your explicit consent and appropriate data anonymization.
- Compliance: To comply with legal and regulatory requirements, including the NDPR, the Nigerian Medical Association (NMA) ethical guidelines, and any relevant state-level data protection laws.
Sharing Your Information
We may share your information with:
- Healthcare Providers: Other healthcare providers involved in your care, with your consent or as required by law.
- Insurance Companies: To process your bills and claims, with your consent or as required by law.
- Government Agencies: To comply with legal and regulatory requirements, including the NDPR, and as required by law.
- Business Associates: Companies that provide services to us, such as billing, marketing, and data analysis, with appropriate data processing agreements in place and ensuring compliance with the NDPR.
- Other Third Parties: With your explicit consent or as required by law.
Your Data Protection Rights
Under the NDPR, you have the following rights regarding your information:
- Access and Correction: You can request access to your information and have it corrected if it is inaccurate.
- Erasure: You can request the erasure of your personal data, subject to legal and regulatory requirements.
- Restriction of Processing: You can request the restriction of processing your personal data, subject to legal and regulatory requirements.
- Data Portability: You can request a copy of your information in a portable format.
- Objection: You can object to the processing of your personal data, subject to legal and regulatory requirements.
- Withdrawal of Consent: You can withdraw your consent to the processing of your personal data at any time.
Security
We take appropriate technical and organizational measures to protect your information from unauthorized access, use, disclosure, alteration, or destruction. These measures include:
- Encryption: We use encryption to protect sensitive information.
- Access Control: We restrict access to your information to authorized personnel.
- Regular Security Audits: We conduct regular security audits to identify and address vulnerabilities.
- Employee Training: We provide our employees with training on data protection and security, including the NDPR requirements.
Children’s Privacy
Our website and services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13.
Data Breach Reporting
In accordance with the NDPR, we have a data breach response plan in place. We will report any data breaches to the National Information Technology Development Agency (NITDA) and affected individuals within the required timeframe.
Data Protection Officer (DPO)
Cedarcrest Hospitals LTD has appointed a Data Protection Officer (DPO) to oversee our data protection practices and ensure compliance with the NDPR.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post any changes on our website and notify you via email or other appropriate means.
Contact Us
If you have any questions about this Privacy Policy or your data protection rights, please contact our Data Protection Officer at:
- Email: info@cedarcresthospitals.com
Effective Date
This Privacy Policy is effective as of 14/08/2024