PRIVACY NOTICE AND COMPLIANCE WITH THE PROTECTION OF PERSONAL INFORMATION ACT OF 2013 (“POPIA”)


Any reference in this privacy notice to “us”, “our”, “we” shall mean the Mayo Clinic Group of Companies, including but not limited to Mayo Theatre Company (Pty) Ltd, Amekpyw (Pty) Ltd, Valley Flora Shareblock ( Pty) Ltd, W Wypkema Trust , Life Extension Institute (Pty) Ltd (NPO)and its subsidiary companies.

This privacy notice is here for YOU, our valued patient, client, lessee, customer and or supplier to better understand our practices pertaining to your Personal Information, how we shall treat it and how we shall inform you of your rights in relation to any of your Personal Information.

Mayo Clinic Group of Companies hereby sets out this privacy notice in order to inform you of the basis in which we shall collect any Personal Information from you, or which Personal Information you may provide to us, how it will be used, disclosed, processed and or stored.

By providing us with your Personal Information, or by making use of any of our services, our website and or any other digital/online platform(s) you are consenting to accepting of the practices and policies as described and referred to in this privacy notice.

YOUR PERSONAL INFORMATION / DATA:

-

Any reference to your Personal Information shall mean any information about you, that enables us to identify you as a living natural person as defined in the POPIA. (ie. name, surname, email address, telephone number, physical and postal address, gender, ethnicity and date of birth).

-

We may use and hold any of your Personal information as a client, customer, employee, patient, student or supplier or in any other capacity and in accordance with the relevant national health and privacy laws.

-

Such Personal Information may include Special Personal Information, such as information relating to your health as defined in POPIA, depending on the services you receive or require from us.

WHEN DO WE COLLECT PERSONAL INFORMATION FROM YOU?:

We may collect Personal Information from you when you:

-

are referred by a doctor, or any other organisation for our services;

-

are admitted as a patient or register as customer/client/supplier with us or book to receive any of our diagnostic or complementary health services;

-

browse our websites or visit our offices;

-

apply to be employed by us;

-

rent property from us ( Medical suites and office space);

-

enquire about any of our services;

-

use or request to use any of our online services;

-

fill in any form or survey;

-

carry out any transaction on our website;

-

participate in a promotion or marketing activity;

-

make any payments to us;

-

contact us by email, telephone or social media;

-

participate in interactive features on any of our online platforms;

-

make use of our facilities.

-

when filing insurance claims, or incident reports;

-

when issuing parking permits to tenants.

LEGAL AND LAWFUL BASIS IN COLLECTING PERSONAL INFORMATION:

-

In order to process any of your information, POPIA states that there should be a lawful basis and reason in doing so, which must be at least one of the following:

>

processing information necessary for the protection of our/ your legal interest;

>

processing information which is necessary for the performance of a contract or legal obligation;

>

processing any information by virtue of your consent thereto.

-

Any Special Personal Information which is any information relating to your health, may be processed if the processing of such information is necessary for:

>

your proper treatment and or care,

>

the administration of our professional practice or where such processing is necessary for the work conducted by insurance companies, medical schemes, medical scheme administrators and/or managed health care organisations.

-

The National Health Act of 2003 furthermore permits us to disclose your Personal Information in the following instances:

>

when you consent to such disclosure in writing;

>

when a court order or any other law requires that disclosure; or

>

when the non-disclosure of such information represents a serious threat to the public health.

-

We may further process your Personal Information for a number of lawful reasons and as set out in this privacy notice, having assessed and taking into account all your relevant interests and rights.

SECURITY AND STORAGE OF YOUR PERSONAL INFORMATION:

-

Our IT infrastructure as well as storage of physical records meets all acceptable security standards which are required to by compliant with POPIA.

-

Your Personal Information will be kept confidential at all times and shall be secured and unless you agree otherwise, it shall only be used for the purpose(s) for which it was collected and in accordance with our privacy notice, and national health laws.

ORGANISATIONAL AND TECHNICAL SECURITY MEASURES:

-

All our organisational and technical security measures have been implemented appropriately in order to prevent unauthorised access or unlawful processing of Personal Information and to prevent Personal Information being lost, destroyed or damaged.

-

Our information systems are monitored in order to ensure that our ongoing security remains safeguarded, for purposes of ensuring that all your Personal Information is securely stored.

-

Where a password is created by yourself or given to you which enables you to access certain parts of our website and information systems, you shall be responsible for keeping that password confidential, and we request that you do not share your password with anyone.

-

Any transmission of information via the internet cannot be guaranteed as completely secure.

-

Once you share your information with us we shall use strict procedures and security features in an endeavour to prevent unauthorised access measures.

-

If and when you request us to do so, we may occasionally transfer your Personal Information to you via email, or you may elect to transfer same to us via email.

-

It must be noted that email is not a secure method of information transmission; if you choose to send or receive such information via email, you shall do so at your own risk.

IP ADDRESS AND COOKIES:

-

When accessing any of our website servers, all your information relating to your IP address shall automatically be collected and stored as part of your access to the server.

-

All information usage through our website serves as indicator of how visitors make use of the web page, the amount of times such web page is accessed, the frequency of all users in general to each web page, the registered IP addresses as well as the time period of each access and visit of the website and web page.

-

As we endeavour to ensure that your IP address is not processed in a manner that infringes on your privacy, should there be a security breach, the IP address will be used to identify the user by the internet service provider and contact shall be made thereafter.

-

What are cookies? Cookies are simple text files that are stored on your computer or mobile device by a website’s server. Each cookie is unique to your web browser. It will contain some anonymous information such as a unique identifier, digits and numbers and website’s domain name.

-

Use of Cookies: Our website currently uses analytical cookies i.e. Google Analytics. These cookies enable us and third-party services to collect aggregated data for statistical purposes on how our visitors use the website. These cookies do not contain personal information such as names and email addresses and are used to help us improve your user experience of the website.

-

How to delete cookies? If you want to restrict or block the cookies that are set by our website, you can do so through your browser setting. Alternatively, you can visit www.internetcookies.org , which contains comprehensive information on how to do this on a wide variety of browsers and devices. You will find general information about cookies and details on how to delete cookies from your device.

TRANSFER OF PERSONAL INFORMATION OUTSIDE THE SOUTH AFRICAN JURISDICTION:

-

We may process Personal Information collected from you, transfer and store it to destinations outside the jurisdiction of South Africa.

-

Such information may also be processed by staff operating outside the South African jurisdiction including but not limited to any of our staff operating outside the jurisdiction of South Africa or staff who may work for any of our suppliers.

-

Where such Personal Information is transferred outside of South Africa, we will seek to ensure that the adequate protections are in place for your rights relating to such Personal Information to be in compliance with POPIA.

-

By providing and submitting your Personal Information to us, you hereby agree to the above transfer, storing and processing.

-

We shall take all steps necessary to ensure that your information is treated securely and in accordance with this Privacy Notice.

DISCLOSURE OF YOUR PERSONAL INFORMATION:

-

To the extent necessary and during the course of our usual business we may disclose your Personal Information to certain third party organisations for purposes of supporting the delivery of our services.

-

These include but are not limited to the day clinic, Life Extension Institute, facility, its staff and health care providers such as doctors, pathologists, radiologist, pharmacists, specialists, therapists and other allied healthcare professionals or auxiliary medical professionals, whom may collects, process and disclose your confidential information, including information relating to diagnosis and treatment (herein referred to as “Personal and Health Information”), as is necessary in the following circumstances:

>

For the day clinic, Life Extension Institute, facility, its staff and healthcare providers involved in your treatment to provide the necessary services to you for the purpose of your treatment and care at our facilities;

>

To enable the hospital or clinical staff to properly perform their duties;

>

This will apply to services rendered to you during your current admission and or any future admissions to any of our facilities;

>

This will also include any services rendered to you by our pharmacy staff for the purposes of providing you with suitable pharmaceutical treatment and or medicines in relation to your medical condition and or diagnosis;

>

To obtain authorisation for treatments and or payment of your account from any medical scheme or insurance or plan, other institution, person or company; and

>

To facilitate the due and proper administration of the operations of the Mayo Group of Companies as a healthcare institution, in order to ensure that you as our patient receive quality healthcare.

-

Where any of the Mayo Group of Companies does share your Personal and Health Information with any the parties as described above, we undertake to share only those aspects of such information which is necessary, or to the extent necessary to prevent a threat to public health, while preserving the privacy, security and confidentiality of that information as far as readily possible. Furthermore, we may be required to disclose your personal and health information in terms of a court order or any other relevant law.

-

Upon your request we shall notify you of the recipients and or category of recipients with whom we share your Personal Information, as well as the relevant category of information shared (ie. Health information, special information, demographic information).

-

Furthermore and in addition to the above recorded instances, you grant Mayo Group of Companies the right to process your personal and health information, for the following purposes:

>

to share your Personal Information (limited only to your name and contact number) with our third party service providers for the purposes of conducting our post-discharge survey. In addition, should you subsequently change your mind after having initially opted in to the post-discharge survey or for other marketing content, we will cease from processing your information any further for these purposes;

>

to share your information with business partners, suppliers and sub-contractors for the performance of services we provide to you as set out in the privacy notice;

>

in respect of any outstanding hospital account, to share your information with third parties assisting us in recovering payment on the account from you (such as debt recovery agents or attorneys);

>

to share your information with our relevant internal investigation team in the event that an incident related to your treatment occurs, as part of the hospital’s quality, internal complaints and incident investigation process

>

to share your information with third parties such as attorneys and other professionals acting on your behalf who may, on your instruction or with your knowledge and authorisation, seek access to your personal and health information for your benefit either for litigious or non-litigious reasons, or to share your information with our own attorneys and/ or other professionals for instituting or defending any potential legal and/or medico-legal claims and/ or evaluating any treatment

>

to share your information with non-clinical third parties such as our auditors, for the purposes of running and administering our day-to-day operations and subject to them being bound to confidentiality

>

to share your information with our clinical engineering staff, third party clinical equipment suppliers and maintenance technicians to the extent that your information is stored or recorded on any of the clinical equipment used for the purposes of providing you with proper treatment and care. In these instances, we undertake to ensure the confidentiality, privacy and security of your information as far as reasonably possible;

>

to share your information with organisations providing IT systems support and software development, and for hosting in relation to the IT systems on which your information is stored and subject to confidentiality undertakings;

>

to share your information with third party service providers for the purposes of storage of information and confidential destruction

>

to share your information with delivery companies for the purposes of transportation;

>

to share your information with third party marketing companies for the purpose of sending marketing emails, subject to obtaining appropriate consent

>

Where a third party supplier is used, we shall endeavour to ensure that they operate under contractual restrictions with regard to confidentiality and security, in addition to their obligations under POPIA

>

In the case of independent consultants, the consultant is the responsible party of your Personal Information, and will be required to maintain their own records in accordance with POPIA and applicable clinical confidential guidelines and retention periods;

>

In an emergency and if you are incapacitated, we may also process your Personal Information (including Special Personal Information) or make Personal Information available to third parties on the basis of protecting your ‘vital interest’ (i.e. your life or your health);

>

We participate in national audits and initiatives to help ensure that patients are getting the best possible outcomes from their treatment and care. Confidentiality will be applied to your Personal Information in accordance with POPIA. Anonymous, pseudonymous or aggregated information may be used by us, or disclosed to others;

>

Regulators: We may be requested – and in some cases can be required - to share certain information (including Personal Information and Special Personal Information) about you and your care with regulators such as the Department of Health, the Health Professions Council or the NICD. We will ensure that we do so within the framework of the law and with due respect to your privacy;

>

We may also share your information with Medikredit and other members of the health information exchange (such as other healthcare providers and medical schemes involved in your treatment and care), for the purposes of the health information exchange (HIE) where you have provided us with your consent to do so.

HEALTH INFORMATION EXCHANGE:

-

We may process your Personal and Health information through Medikredit health information exchange (HIE), however this shall only be done once you or your legal guardian have provided and signed to confirm your consent to participate in such HIE.

-

A more detailed consent and privacy notice relating to the Health Information Exchange will be made available to you at the appropriate relevant time of such consent.

RESEARCH AND STATISTICAL PURPOSES:

-

Your personal and health information may also be retained for statistical, research and or historical purposes.

-

In these instances, we shall maintain the confidentiality of all your information by making use of adequate security measures such as anonymisation and de-identification of the information concerned.

SUPPLIERS AND VENDORS:

-

Your Personal Information may be processed to the extent that may be necessary and as required for our legitimate business interests and during the course of our ordinary running of our business.

-

These may include but are not limited to the use during:

>

computing sustainability measures;

>

our BEE scoring;

>

quality audits;

>

internal and external investigations;

>

vendor assessments that may be carried out if and when so required; when submitting tenders and other proposals to and by us.

-

We may also process your information during business due diligence and when processing your information for commercial and market research purposes.

SALE OF OUR BUSINESS:

-

Your Personal Information may also be disclosed to third parties in the event that we may sell or buy any business or assets as a going concern or to the extent where it is required to do so by law.

CCTV CAMERA AND VIDEO RECORDING:

-

Most of our premises are surveyed and controlled by CCTV cameras and video recording for the purposes of security and the safe provision of care and to the extent where necessary required to do so by law.

-

These images and video recordings may be retained for a limited time period.

YOUR RIGHTS RELATING TO THIS PRIVACY NOTICE AND THE CONTENTS THERETO:

-

Where legally permissible, you have the following further rights in relation to your Personal Information:

>

Right of access: the right to make a written request for details of your Personal Information and a copy of that Personal Information;

>

Right to restriction of processing: the right to request that your Personal Information is only used for restricted purposes;

>

Right to rectification: the right to have inaccurate information about you corrected or removed;

>

Right to erasure ('right to be forgotten'): the right to have certain Personal Information about you erased;

>

You have the right to object to the processing of your personal information in terms of section 11(3) of POPI. Right to object: the right to object to processing of your Personal Information in cases where our processing is based on the performance of a task carried out in the public interest or we have let you know the processing is necessary for our or a third party’s legitimate interests;

>

Right to withdraw consent: the right to withdraw any consent you have previously given us to handle your Personal Information. If you withdraw your consent, this will not affect the lawfulness of our use of your Personal Information prior to the withdrawal of your consent and we will let you know if we will no longer be able to provide you your chosen product or service;

>

Right to information portability: the right to ask for the Personal Information you have made available to us to be transferred to you or a third party in machine-readable formats;

>

Right in relation to automated decisions: you have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you, unless it is necessary for entering into a contract with you, it is authorised by law or you have given your explicit consent. We will let you know when such decisions are made, the lawful grounds we rely on and the rights you have.

-

Kindly take notice that your rights are not absolute: they do not always apply in all cases and we will let you know in our correspondence with you how and whether we will be able to comply with your request.

-

If you believe that your information is not processed in a correct manner, or that your information is being used for a purpose other than that for what it was originally intended, or if you wish to request access to the information we hold of you, please contact our Information Officer below. You have the right to request us to delete, destroy, limit, update or correct such data. Such requests are to be made in writing to the email address provided below. Where we are unable to resolve your request to your satisfaction, you have the right to contact an Information Regulator accordingly.

INFORMATION OFFICER:

Name:

AGATHA JANE SMITH

Contact Number:

+27 (011) 670 3408

Email:

management@mayoclinic.co.za

WEB HOSTING:

Our website is hosted by:

Xneelo

Registered address:

Belvedere Office Park, unit F, Bella Rosa Street, Durbanville, 7550

VAT Number:

4630 185 538

CHANGES TO THIS PRIVACY POLICY:

-

Should we be required to change our privacy policy at any given time, we will do so.

-

It may be necessary should existing laws change or be updated, and/or if we need to change the way we conduct our business.

-

Any changes will be updated on our website. We recommend that you check our policy frequently for latest information.

-

Last updated 5 July 2021. (All rights reserved).

-

Mayo Centre, Joseph Lister Street, Constantia Kloof, Florida