Patient Privacy Policy
Patient Confidentiality Policy

1. Introduction

Mater Dei Hospital respects the privacy, dignity and confidentiality of every patient. This Patient Privacy Notice explains how the Hospital collects, uses, stores, protects and, where necessary, shares personal information and health information relating to patients.
Mater Dei Hospital processes personal information in accordance with the Cyber and Data Protection Act [Chapter 12:07], applicable regulations, other relevant Zimbabwean laws and professional confidentiality obligations.
The Hospital is committed to processing personal information lawfully, fairly, transparently and securely.

2. Who this Notice Applies To

• Patients receiving healthcare services at Mater Dei Hospital.
• Parents and guardians of minor patients.
• Persons legally authorised to act on behalf of patients.
• Prospective patients.
• Former patients whose records remain in the Hospital's custody.
• Other individuals whose personal information is processed in connection with patient care.

3. Information We Collect

3.1 Identification and Contact Information
• Full name. • Date of birth. • Sex/gender. • National identification number or passport details. • Physical and postal address. • Telephone number. • Email address. • Emergency contact details.
3.2 Medical and Health Information
• Medical history and presenting complaints. • Diagnoses and clinical notes. • Treatment and medication information. • Allergies. • Laboratory results. • Radiology and imaging results. • Surgical and theatre records. • Nursing and maternity records. • Mental-health information where relevant. • Discharge summaries. • Other information necessary for healthcare.
Health information is sensitive personal information and is therefore subject to enhanced protection.
3.3 Billing and Financial Information
• Medical aid details and membership numbers. • Treatment authorisation information. • Invoices and payment records. • Billing and claims information. • Information required for payment, reconciliation or lawful debt recovery.
3.4 Other Information
• Photographs or CCTV footage where applicable. • Information provided by a parent, guardian or authorised representative. • Information provided by another healthcare provider. • Information relating to complaints or enquiries. • Information required for administrative, legal, audit or regulatory purposes.
  • 4. How We Collect Information
Mater Dei Hospital may collect information directly from patients or from other lawful sources.
• Patients.
• Parents, guardians or authorised representatives.
• Referring doctors and other healthcare providers.
• Medical aid societies and insurers.
• Laboratories, pharmacies and other healthcare service providers.
• Hospital registration, clinical and electronic systems.
• Forms, appointments and admissions processes.
• Telephone, email and other electronic communications.
• Other lawful sources where appropriate.
  • 4. How We Collect Information
Mater Dei Hospital may collect information directly from patients or from other lawful sources.
• Patients.
• Parents, guardians or authorised representatives.
• Referring doctors and other healthcare providers.
• Medical aid societies and insurers.
• Laboratories, pharmacies and other healthcare service providers.
• Hospital registration, clinical and electronic systems.
• Forms, appointments and admissions processes.
• Telephone, email and other electronic communications.
• Other lawful sources where appropriate.
  • 5. Why We Collect & Use Patient Information
5.1 Healthcare and Treatment
• Register and identify patients.
• Assess and diagnose medical conditions.
• Provide treatment and administer medication.
• Perform procedures and surgery.
• Monitor patient progress.
• Arrange referrals and coordinate care.
• Provide follow-up care.
• Promote patient safety and continuity of care.
5.2 Hospital Administration
• Manage patient records.
• Schedule appointments.
• Manage admissions and discharges.
• Manage theatre, pharmacy, laboratory and other clinical services.
• Quality assurance and clinical governance.
• Clinical audit and service improvement.
• Manage complaints and patient feedback.
• Maintain Hospital records and meet lawful administrative requirements.
5.3 Billing and Medical Aid Administration
• Prepare invoices.
• Process medical aid claims.
• Obtain treatment authorisation.
• Reconcile payments and claims.
• Communicate with medical aid societies and insurers.
• Recover outstanding amounts where lawful.
• Comply with financial, audit and regulatory requirements.

6. Lawful Basis for Processing

Mater Dei Hospital will process personal information only where there is an appropriate lawful basis. Depending on the circumstances, processing may be necessary to provide healthcare, comply with a legal obligation, protect vital interests, perform legitimate and lawful Hospital functions, obtain consent where consent is required, meet public-health or other legally authorised purposes, or where otherwise permitted or required by law.
The Hospital will not rely on consent merely for convenience where another lawful basis applies.

7. Confidentiality of Patient Information

Patient confidentiality is a fundamental responsibility of Mater Dei Hospital. Access to patient information is restricted to employees, healthcare professionals, contractors and other authorised persons who have a legitimate need to access the information.
• Staff must not access patient records without a legitimate reason.
• Patient information must not be discussed in public areas.
• Patient information must not be disclosed to unauthorised persons.
• Patient information must not be photographed, copied or removed without authorisation.
• Passwords and system credentials must not be shared.
• Patient information must not be disclosed through social media or other unauthorised channels.

8. Who May Receive Patient Information?

Where lawful and necessary, Mater Dei Hospital may share relevant patient information with:
• Treating doctors and healthcare professionals.
• Other healthcare facilities involved in the patient's care.
• Laboratories and pharmacies.
• Medical aid societies and insurers.
• Parents, guardians or authorised representatives where legally appropriate.
• Regulatory or government authorities where lawfully required.
• Law-enforcement authorities where legally required.
• Service providers processing information on behalf of the Hospital.
• Other persons where disclosure is authorised or required by law.
The Hospital will seek to limit disclosures to information that is relevant and reasonably necessary for the purpose.

9. Medical Aid and Insurance

Where a patient uses medical aid or insurance, the Hospital may need to share relevant information for treatment authorisation, claims processing, billing, reconciliation, membership verification, clinical review where applicable and payment of Hospital accounts.
Medical aid societies and insurers may have their own privacy policies and data-processing practices.

10. Children and Minors

Where a patient is a child or minor, Mater Dei Hospital will process information in accordance with applicable law. Information may be provided to or processed through a parent, legal guardian or other authorised person where legally permitted or required. The Hospital will take appropriate steps to protect children's personal information.

11. Your Rights

Subject to applicable legal requirements and limitations, patients may have rights concerning their personal information, including the right to:
• Request access to personal information held about them.
• Request correction of inaccurate or incomplete information.
• Request information about how their personal information is being processed.
• Exercise other rights available under applicable data-protection law.
Requests should be directed to the Data Protection Officer.

12. Correcting Your Information

Patients should inform Mater Dei Hospital if their personal information is inaccurate or incomplete, including names, contact details, identification information or medical aid details. The Hospital will assess and address correction requests in accordance with applicable law and its procedures.

13. Data Security

Mater Dei Hospital implements appropriate technical and organisational measures intended to protect patient information against unauthorised access, disclosure, loss, destruction, alteration, theft and other unlawful or unauthorised processing.
• Access controls and user authentication.
• Confidentiality obligations.
• Physical security measures.
• Secure storage and system controls.
• Staff training and awareness.
• Monitoring, auditing and incident response.
• Other reasonable security measures appropriate to the information and risks.
No information system can be guaranteed to be completely secure. The Hospital will nevertheless take reasonable and appropriate measures to protect patient information.

14. Data Breaches

If Mater Dei Hospital becomes aware of a personal-information security breach, it will follow its Data Breach and Incident Response Procedure. The Hospital will assess the nature and potential impact of the breach, take appropriate containment and remedial measures, and notify the relevant authority and/or affected individuals where required by law.

15. Retention of Patient Information

Mater Dei Hospital retains patient information only for as long as necessary for the purpose for which it was collected, or as required or permitted by applicable law, professional requirements, medical-record requirements, financial requirements or other legitimate Hospital purposes.
When information is no longer required, the Hospital will take appropriate measures for secure disposal, destruction or anonymisation, as applicable.

16. Patient Photographs and Images

Photographs, video recordings and other images may constitute personal information. Mater Dei Hospital will handle patient images confidentially and will not use patient photographs for publicity, marketing, social media or other non-care purposes without an appropriate lawful basis and, where required, consent.

17. CCTV

Mater Dei Hospital may operate CCTV cameras in certain areas for safety and security, protection of patients, visitors and staff, prevention and investigation of crime, protection of Hospital property and other legitimate security purposes.
CCTV footage will be handled securely and accessed only by authorised persons. Appropriate signage will be displayed in areas where CCTV monitoring takes place.

18. Electronic Communication

Patients should be aware that email, SMS, WhatsApp and other electronic communication may involve privacy and security risks. Mater Dei Hospital will take reasonable steps to protect information communicated electronically.
Patients should avoid sending unnecessary sensitive medical information through unsecured channels. Where possible, the Hospital may verify the identity of a person before disclosing patient information electronically.

19. International or Third Country Transfers

Where patient information needs to be transferred outside Zimbabwe, Mater Dei Hospital will take appropriate steps to ensure that the transfer is carried out in accordance with applicable data-protection requirements.

20. Your Responsibility

• Provide accurate information.
• Inform the Hospital when personal information changes.
• Protect your own passwords and login credentials.
• Avoid sharing confidential Hospital communications publicly.
• Verify the identity of anyone requesting information on your behalf.
• Promptly report suspected unauthorised access or disclosure of your information.

21. Questions, Requests and Complaints

If you have questions about how Mater Dei Hospital handles your personal information, or wish to exercise your rights under applicable data-protection law, please contact the Data Protection Officer.

Mater Dei Hospital

Physical Address: Btwn Chesterton Road & Burns Drive, Malindela, Bulawayo, Zimbabwe

Postal Address: P.O. Box 2133, Bulawayo, Zimbabwe

Telephone: +263 292 240000 / 4 or +263 772850478

General Email: info@materdeihospital.org

Data Protection Officer: Tendai Mutema

DPO Email: tendai@materdeihospital.org

Patients may also lodge a complaint with the relevant regulatory authority where they believe their data-protection rights have been infringed.

22. Changes To This Privacy Notice

Mater Dei Hospital may update this Privacy Notice from time to time to reflect changes in legislation, regulatory requirements, Hospital services, information systems, data-processing activities or privacy practices. The latest version will be made available through appropriate Hospital communication channels.

Your Privacy Matters

Mater Dei Hospital is committed to protecting your privacy and keeping your medical information confidential. If you have questions about your personal information or your privacy rights, please contact our Data Protection Officer.