1. Introduction
Mater Dei Hospital respects the privacy, dignity and confidentiality of every patient. This Patient Privacy Notice explains how the Hospital collects, uses, stores, protects and, where necessary, shares personal information and health information relating to patients.
Mater Dei Hospital processes personal information in accordance with the Cyber and Data Protection Act [Chapter 12:07], applicable regulations, other relevant Zimbabwean laws and professional confidentiality obligations.
The Hospital is committed to processing personal information lawfully, fairly, transparently and securely.
2. Who this Notice Applies To
• Parents and guardians of minor patients.
• Persons legally authorised to act on behalf of patients.
• Prospective patients.
• Former patients whose records remain in the Hospital's custody.
• Other individuals whose personal information is processed in connection with patient care.
3. Information We Collect
• Full name. • Date of birth. • Sex/gender. • National identification number or passport details. • Physical and postal address. • Telephone number. • Email address. • Emergency contact details.
• Medical history and presenting complaints. • Diagnoses and clinical notes. • Treatment and medication information. • Allergies. • Laboratory results. • Radiology and imaging results. • Surgical and theatre records. • Nursing and maternity records. • Mental-health information where relevant. • Discharge summaries. • Other information necessary for healthcare.
• Medical aid details and membership numbers. • Treatment authorisation information. • Invoices and payment records. • Billing and claims information. • Information required for payment, reconciliation or lawful debt recovery.
• Photographs or CCTV footage where applicable. • Information provided by a parent, guardian or authorised representative. • Information provided by another healthcare provider. • Information relating to complaints or enquiries. • Information required for administrative, legal, audit or regulatory purposes.
- 4. How We Collect Information
• Patients.
• Parents, guardians or authorised representatives.
• Referring doctors and other healthcare providers.
• Medical aid societies and insurers.
• Laboratories, pharmacies and other healthcare service providers.
• Hospital registration, clinical and electronic systems.
• Forms, appointments and admissions processes.
• Telephone, email and other electronic communications.
• Other lawful sources where appropriate.
- 4. How We Collect Information
• Patients.
• Parents, guardians or authorised representatives.
• Referring doctors and other healthcare providers.
• Medical aid societies and insurers.
• Laboratories, pharmacies and other healthcare service providers.
• Hospital registration, clinical and electronic systems.
• Forms, appointments and admissions processes.
• Telephone, email and other electronic communications.
• Other lawful sources where appropriate.
- 5. Why We Collect & Use Patient Information
• Register and identify patients.
• Assess and diagnose medical conditions.
• Provide treatment and administer medication.
• Perform procedures and surgery.
• Monitor patient progress.
• Arrange referrals and coordinate care.
• Provide follow-up care.
• Promote patient safety and continuity of care.
• Manage patient records.
• Schedule appointments.
• Manage admissions and discharges.
• Manage theatre, pharmacy, laboratory and other clinical services.
• Quality assurance and clinical governance.
• Clinical audit and service improvement.
• Manage complaints and patient feedback.
• Maintain Hospital records and meet lawful administrative requirements.
• Prepare invoices.
• Process medical aid claims.
• Obtain treatment authorisation.
• Reconcile payments and claims.
• Communicate with medical aid societies and insurers.
• Recover outstanding amounts where lawful.
• Comply with financial, audit and regulatory requirements.
6. Lawful Basis for Processing
The Hospital will not rely on consent merely for convenience where another lawful basis applies.
7. Confidentiality of Patient Information
• Patient information must not be discussed in public areas.
• Patient information must not be disclosed to unauthorised persons.
• Patient information must not be photographed, copied or removed without authorisation.
• Passwords and system credentials must not be shared.
• Patient information must not be disclosed through social media or other unauthorised channels.
8. Who May Receive Patient Information?
• Treating doctors and healthcare professionals.
• Other healthcare facilities involved in the patient's care.
• Laboratories and pharmacies.
• Medical aid societies and insurers.
• Parents, guardians or authorised representatives where legally appropriate.
• Regulatory or government authorities where lawfully required.
• Law-enforcement authorities where legally required.
• Service providers processing information on behalf of the Hospital.
• Other persons where disclosure is authorised or required by law.
The Hospital will seek to limit disclosures to information that is relevant and reasonably necessary for the purpose.
9. Medical Aid and Insurance
Medical aid societies and insurers may have their own privacy policies and data-processing practices.
10. Children and Minors
11. Your Rights
• Request access to personal information held about them.
• Request correction of inaccurate or incomplete information.
• Request information about how their personal information is being processed.
• Exercise other rights available under applicable data-protection law.
Requests should be directed to the Data Protection Officer.
12. Correcting Your Information
13. Data Security
• Access controls and user authentication.
• Confidentiality obligations.
• Physical security measures.
• Secure storage and system controls.
• Staff training and awareness.
• Monitoring, auditing and incident response.
• Other reasonable security measures appropriate to the information and risks.
No information system can be guaranteed to be completely secure. The Hospital will nevertheless take reasonable and appropriate measures to protect patient information.
14. Data Breaches
15. Retention of Patient Information
When information is no longer required, the Hospital will take appropriate measures for secure disposal, destruction or anonymisation, as applicable.
16. Patient Photographs and Images
17. CCTV
CCTV footage will be handled securely and accessed only by authorised persons. Appropriate signage will be displayed in areas where CCTV monitoring takes place.
18. Electronic Communication
Patients should avoid sending unnecessary sensitive medical information through unsecured channels. Where possible, the Hospital may verify the identity of a person before disclosing patient information electronically.
19. International or Third Country Transfers
20. Your Responsibility
• Inform the Hospital when personal information changes.
• Protect your own passwords and login credentials.
• Avoid sharing confidential Hospital communications publicly.
• Verify the identity of anyone requesting information on your behalf.
• Promptly report suspected unauthorised access or disclosure of your information.
21. Questions, Requests and Complaints
Mater Dei Hospital
Physical Address: Btwn Chesterton Road & Burns Drive, Malindela, Bulawayo, Zimbabwe
Postal Address: P.O. Box 2133, Bulawayo, Zimbabwe
Telephone: +263 292 240000 / 4 or +263 772850478
General Email: info@materdeihospital.org
Data Protection Officer: Tendai Mutema
DPO Email: tendai@materdeihospital.org