We are Guardians of Patient Privacy
Patient consent to collect, use and store personal data (February 2025)
Ensuring the confidentiality and security of patient information is paramount to our commitment to quality healthcare. As valued members of the Mediclinic family, it is crucial that each employee upholds the highest standards in data privacy.
As part of our ongoing efforts to ensure legal compliance and ethical standards in patient care, we do focus on proper consent collection. In healthcare, consent is not just a formality; it’s essential to providing the best and most compliant care possible. Medical assessments, surgery, nursing care and other clinical services can only be provided if the patient agrees (exception: emergency treatments). The consent builds part of the contract between patient and Mediclinic facility.
A consent is also needed to collect, use, store and otherwise process personal data. This consent is part of Mediclinic’s patient registration and consent form or can be a separate process, e.g. when onboarding patients on a digital service.
Key points to observe in the consent of a consent to process personal data are:
- Get clear consent from patients: Always ensure that consent is obtained through an active, clear, and visible action. A patient should confirm that he/she agrees to the collection and use of personal data. Therefore, it is crucial to have the patient registration and consent form signed upon each admission.
- Ensure patients are fully informed: Inform patients about how their personal health data will be used, stored, and shared. Informed consent means the patient understands the full scope of data collection and usage. The basic information is provided through the registration and consent form. Additional information is available in the patient privacy notice which is published on the Mediclinic website (main page, then scroll to the bottom).
- Consent is mandatory, not optional: In case a patient does not accept the consent form or parts of it, clearly communicate that consent is mandatory for the treatment to proceed. It is a specific regulatory requirement in the UAE that patients do expressively consent to the collection, use and processing of their personal data along with the consent to the treatment. The patient may not withdraw the consent during or after the treatment, and medical record related data must be kept for at least 25 years.
- Document consent properly: Always document when, how, and in what context the consent was obtained. Usually, the patient registration and consent form should be documented in a patient’s medical record. Proper documentation protects both the patient’s rights and the hospital’s compliance with legal standards.
- Consent for marketing purposes: In relation to marketing activities, patient surveys etc., the patient has a choice to opt out from his/her data being used for such purposes. The patient registration and consent form provides respective fields, and a consent or a withdrawal of a consent can be given at any point of time.
Purpose of using and sharing patient data: The patient registration and consent form provides transparency about the purposes patient data is being used and shared with third parties, e.g.,
- Use of anonymized patient data for research purposes;
- Use of medical data for billing purposes and sharing of medical data or medical records with health insurance companies;
- Sharing of medical records with Regulators and courts for dispute resolution;
- Sharing of medical data with various Regulators based on legal requirements, e.g. Nabidh (Dubai) and Malaffi (Abu Dhabi) health information exchange systems. (For Nabidh and Malaffi, specific processes apply in case a patient disagrees to have his/her data uploaded on these platforms.)
- The patient privacy notice provides more detailed insights.
Age and capacity verification: In some instances, the consent will not be obtained by the patient but by a parent or a legal guardian, e.g. for minors or for patients with a lack of mental or impaired decision-making capacity. Usually, these patients are accompanied by a parent or a guardian.
Access to Data: While consent cannot be withdrawn once healthcare services are in progress or completed, patients should be given ongoing access to their health data and treatment records. This is ensured through the established request of information (ROI) process or self-service access through the patient portal or the Mediclinic mobile app. Patients must be informed of their rights to access and correct their medical records as needed; this information is provided in the patient privacy notice.
Remember, our dedication to patient well-being extends beyond medical care; it includes safeguarding their privacy. Let us all contribute to fostering an environment where patients can trust that their information is handled with the utmost care and respect.
Thank you for your commitment to upholding the values that make Mediclinic a trusted healthcare provider.