MASLAK MEDICAL CENTER INFORMATION TEXT ON THE PROCESSING AND PROTECTION OF PERSONAL DATA OF PATIENTS RECEIVED SERVICE
Confidentiality of data belonging to clients and patients receiving health services from Derman Sağlık Hizmetleri ve Medikal Ürünleri Limited Şirketi (Brand name is Maslak Medical Center, henceforth referred to as Maslak Medical Center), located at the address of Ayazağa, Mustafa Kemal Atatürk Cd 1-2, 34396 Sarıyer/İstanbul. and pays utmost attention to safety. As Maslak Medical Center, through this clarification text, within the scope of the Law on the Protection of Personal Data No. 6698, the Regulation on the Processing of Personal Health Data and the Ensuring Privacy, and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation of Clarification; to parents and legal representatives,
A. DEFINITIONS UNDER THE LAW ON THE PROTECTION OF PERSONAL DATA
In this text; Personal Data: Information pertaining to an identified or identifiable natural person, Sensitive Personal Data: Race, ethnic origin, political opinion, philosophical belief, religion, sect, other beliefs, dress, association, foundation or union membership belonging to the person concerned, Criminal conviction and security measures, health, sexual life, biometric and genetic data, Personal Data Processing: Obtaining, recording, storing, keeping, changing, rearranging, disclosing, transferring, transferring, making available, classifying personal data, All kinds of activities carried out in the process from collection to deletion, destruction or anonymization, including prevention of use,
KVKK: Law on the Protection of Personal Data No. 6698,
Data Controller: Refers to Maslak Medical Center, which determines the purposes and means of processing Personal Data and is responsible for the establishment and management of the data recording system.
In this context, by taking all necessary technical and administrative measures as Maslak Medical Center data controller; Within the framework of all legislation on the protection of personal data and privacy, especially the Constitution, international conventions to which our country is a party, KVKK and the regulations of the Ministry of Health, in the 4th article of the KVKK; It will operate in accordance with the principles of being in compliance with the law and honesty, being accurate and up-to-date when necessary, being processed for specific, clear and legitimate purposes, being limited and proportional to the purposes of processing, being kept for the period required by the relevant legislation or for the purpose for which they are processed. (You can also review our Policy regarding the retention period.)
B. FOR WHAT PURPOSES IS YOUR PERSONAL DATA PROCESSED?
In accordance with Articles 4 and 10 of the KVKK, your personal data in the following category;
• Identity Data; To be able to carry out operational activities in the diagnosis and treatment processes, to determine whether you have an occupational disease, to identify and verify
• Communication Data; Keeping you informed when necessary by following up and reminding the appointment, providing you with information, conducting the campaign processes, obtaining the legal approvals that we are obliged to obtain and storing them in the digital environment, •
Financial Data; Making and tracking payments by you, issuing invoices, sharing information requested by contracted institutions/organizations, especially private insurance companies within the scope of financing health services, and performing identity verification,
• Sensitive Personal Data; Protection of public health, preventive medicine, medical diagnosis, treatment and care services, supply of drugs and/or medical equipment and/or devices specific to treatment, execution of activities in accordance with the legislation, management of the relationship with you, management of treatment processes, • Visual Data
; To be able to follow the course of treatment, to make the diagnosis and diagnosis, to be able to use it as evidence in favor of a possible court process, to ensure the safety of the physical space,
• Computing Data; To enable you to use our website more effectively, easily and quickly, to customize the services and activities of the website according to your needs, to offer you more useful and appropriate service offers from third party websites, to make the necessary improvements so that you can benefit from our services and activities, to cooperate with regulatory and supervisory authorities, related online visitor data To fulfill our legal obligations as stipulated and mandated by legal regulations, such as processing in accordance with the legislation
In terms of all data, it is processed for the purposes of providing information to authorized persons, institutions and organizations upon request and within the scope of supervision, to fulfill our archiving obligation, to ensure operational activities and security as a data controller, and to carry out contractual processes. We store them in archives or closed system digital servers.
PERSONAL DATA CATEGORIZATION TYPES OF PERSONAL DATA RECEIVED WITHIN THIS SCOPE
Identity Information Name, Surname, TR Identity Number and/or passport number and/or temporary TR Identity Number, date of birth, marital status, gender, health insurance, profession, insurance card number, signature, workplace registry and/or patient identification number and other identification data that can identify you
Contact Information Address, phone number and e-mail address
Financial Information Personal data owner; bank account information, IBAN number, credit card information, billing and billing information, your private health insurance data and payer institution information such as Social Security Institution
Special Quality Personal
Data1 Medical reports, diagnostic data, blood type, hereditary history, pregnancy or breastfeeding status, laboratory results, test results, examination data, doctor analysis and comments, appointment information, prescription information, health reports, ongoing health problems, Medicines, biopsy samples, history of surgery, history of disease, but not limited to all kinds of health information and data obtained during and/or as a result of medical diagnosis, treatment and care services, and sexual life data.
Visual Data Photograph (before-after), visual data collected from camera recording
2 Information – Transaction Data, device information, log records and your IP data (Source and destination information), regarding your visit to the internet address; connection/exit date and time information, use of cookies
C. METHOD OF COLLECTING DATA AND LEGAL REASON FOR COLLECTION
Your personal data; patient registration and appointment procedures, camera records kept in the physical area of Maslak Medical Center, printed treatment follow-up forms, records kept by doctors, nurses, laboratory workers and other health professionals who are employees of Maslak Medical Center, examinations,
1 During your visits to Maslak Medical Center during the Covid 19 Pandemic process, the HEPP Code is also confirmed, and no listing or archiving activities are carried out in this context.
2Click on the layered lighting text regarding the camera recordings from the boards in the waiting room of Maslak Medical Center.
3 from medical test/examination results, from the reports submitted by imaging centers or medical laboratories that we cooperate with, from patient logbook records, from Maslak Medical Center website, e-mail, telephone and other online and/or offline electronic communication platforms or social media channels. It can be collected through communication channels, online visits on the website, written or visual records taken within the scope of treatment and care during working hours, and all kinds of past reports and documents including surgery records, photographs, laboratory and test results shared by you.
The processing activity performed by the clinic pursuant to the provisions of KVKK 5/2 and 6/3;
• It is stipulated in the law in terms of all the data received, for the fulfillment of our legal obligations, for the establishment, use or protection of your right and for the establishment or performance of the service contract between you and Maslak Medical Center, it is directly related, necessary and compulsory
, and
being compulsory within the scope of the legitimate interests of Maslak Medical Center, provided that it does not violate your freedoms ,
• Special categories of personal data and visual data; Maslak Medical Center, which has a confidentiality obligation, is carried out on the basis of legal reasons that it is compulsory for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and financing4.
D. TO WHOM IS YOUR PERSONAL DATA TRANSFERRED TO?
• The MEDISIS system, whose identity, communication and financial data are provided by the secretariat to perform the patient registration at Maslak Medical Center, and your health data is provided by the authorized doctor or health personnel assistant in case you start the treatment process, • To lawyers, auditors, contracted banks, to whom we receive services (such as financial advisors)
. ) third parties,
3 Maslak Medical Center cooperates with imaging centers, medical laboratories and university or private hospital laboratories for PCR testing. Your blood results may be carried by the employee of the relevant institution from time to time. In this context, all necessary confidentiality agreements have been signed. Our agreement with these institutions does not oblige you to receive reports or audit results from these institutions. Within the scope of the registrations you have made with these institutions, your reports and results are also stored in the database of these institutions independently of Maslak Medical Center. The relevant institution itself is responsible for the clarifications to be made and the express consent statements to be received when you go on this subject, you should definitely convey your requests to these institutions.
4 If you give your explicit consent, your photos before and after the treatment can be shared on social media or on the website using images that will prevent you from being diagnosed.
5The forms prepared in order to fulfill your requests within the scope of your private health insurance will be hand-delivered to you, and the Clinic does not directly transfer to insurance companies.
• Your identity and contact information in order to fulfill our legal obligations to the official institutions and organizations, including the Ministry of Health, SSI and District Health Directorate, and to the automations connected to these institutions6
,
It can be transferred to your authorized representatives and representatives within the scope of Maslak Medical Center’s legal obligations, if necessary, limited to the request, pursuant to Article 8 of the KVKK and within the legal reasons and purposes specified, and with your explicit consent.
E. WHAT ARE YOUR RIGHTS UNDER PROCESSING?
Regarding your personal data;
A. Teaching whether your personal data has been processed,
if your personal data is processed, information requests, C. Kişiselveriler , whether or not your personal data can not be used in
the process of processing , F.KVKK within the framework of the conditions stipulated in Article 7 requesting the deletion / destruction of transactions, g.(e) and (f) requesting the notification of the third parties to whom the data is transferred,
h. You have the right to object to the emergence of a result against the person by analyzing your processed data exclusively through automated systems,
Within the scope of your rights, you can submit your requests by registered mail, in person or through a notary public, or by contacting us via your e-mail address ([email protected]), if you have an e-mail address that you have previously informed us and registered in our system . At the same time, you can request the third parties to whom your data has been or may be transferred to be informed about your destruction and/or correction request. This
6 The data in the patient protocol book, which is physically kept, is processed in these automations. Details of the complaint or diagnosis are not included, examination, control, etc., limited to the purpose of the visit. processes and notifications are made. At the same time, notifications to systems such as Medula, e-pulse, GEBLİS are made within the framework of legal obligations. Even if no transfer is made by us, your blood results are kept by the laboratories that cooperate and carry out the examination.
7 With the utmost care to your privacy, sharing will be made on a limited basis, if necessary, by requesting a confidentiality decision, if it is related and related to the court process.
In this context, you can request attention from Maslak Medical Center about why the destruction method chosen by Maslak Medical Center was chosen. By evaluating your request for destruction and correction, we will evaluate which method is appropriate according to the conditions of the concrete case and will be finalized within 30 days at the latest. As stated in the Communiqué on Application Procedures and Principles to the Data Controller, your requests in your application will be answered free of charge, however, if your application is answered in writing, 1 TL for each page on the first ten pages and if the answer is given in a recording medium such as flash memory, it will not exceed the cost of the recording medium. A fee may be charged by you. If your application is due to our fault, the fee will be refunded to you.
You can reach all details regarding our personal data processing, storage and transfer processes by reviewing the Data Retention and Disposal Policy and the Personal Data Processing Policy and by contacting us.
As Maslak Medical Center, we would like to remind you that Maslak Medical Center’s privacy principles will only be applied on our digital platform if there are links to other sites on the website, and we are not responsible for any other linked sites. This clarification text is a whole with the Explicit Consent Text, Personal Data Processing Policy, Cookie Policy and Data Storage and Disposal Policy on the site.
MASLAK MEDICAL CENTER PATIENT EXPRESS CONSENT TEXT
As the data controller of Maslak Medical Center, I have provided information on the transfer of my health data within the scope of the “Clarification Text for the Processing and Protection of Personal Data of Patients” read and approved by me, and hereby declare that I accept the consent request with this consent form. I do;
Medical reports, diagnostic data, blood type, hereditary history, pregnancy or breastfeeding status, laboratory results, test results, examination data, doctor analysis and comments, appointment information, prescription information, health reports, ongoing health problems, medications used, biopsy samples My health data from the (Special Quality) Personal Data Category obtained from all kinds of documents obtained during and/or as a result of medical diagnosis, treatment and care services, including but not limited to, surgery history, disease history; For the purpose of regular patient registration, keeping and monitoring the records of diagnosis and treatment processes,
Personal data numbered 6698 for my other personal/private personal data for which all necessary administrative and technical measures are taken to ensure the security of my health data, I can always withdraw my explicit consent in a way that will not create any adverse situation, and if I withdraw my express consent, your explicit consent is not required for processing. I have been informed that it will be processed within the scope of the exceptions listed in the provisions of 5/2 and 6/3 of the Data Protection Law.
I declare that the clarification and explicit consent texts have been submitted to me by Maslak Medical Center before the processing activity, that I have read, understood, informed and given my free will.