Privacy Policy

Sairaala KL Oy patient data register

Sairaala KL Oy maintains and protects its patient data register in accordance with applicable legislation.

Respecting and protecting patient privacy is an extremely important matter in 

Sairaala KL Oy's business operations. Operations comply with laws and regulations that concern

private healthcare. Patient data collected by Sairaala KL Oy

is processed in accordance with the privacy policy.

Updated on September 20, 2018

1. Data controller

Sairaala KL Oy (2045978-3)

2. Contact person

Elina Salmi

elina.salmi@sairaalakl.fi

Uudenmaankatu 38 E

00120 Helsinki

+358 20 766 9390

3. Name of the register

Centralized patient data register of Sairaala KL Oy and its professionals

4. Purpose of processing personal data

  • planning patient examinations and treatment, as well as implementing treatment and archiving;
  • planning, statistics, monitoring, and evaluation of healthcare activities, as well as scientific research;
  • billing and collection.

5. Sources of information in the register

  • the person themselves or the guardian of a minor;
  • healthcare professional, information, responses, and statements arising in connection with examinations and treatment;
  • documents obtained from other care units with the consent of the person or the guardian of a minor.

6. Data content of the register

  • patient's name, personal identification number, and contact details;
  • the contact person or guardian designated by the patient;
  • preliminary information and health information necessary for the patient's treatment;
  • laboratory and research data;
  • appointment and billing information;
  • information about the author or reader of the entry;
  • information on the arrival, source, and transfer of documents.

7. To whom the data is disclosed

  • Patient data is mainly disclosed with the patient's written consent;
  • If the patient is unable to assess the significance of consent, the information may also be disclosed to the patient's legal representative.
  • Based on the law, information may be disclosed to authorities, research institutes, and insurance companies.
  • Generally, data will not be transferred outside the EU or EEA.

8. Protection of patient data registers and grounds for data processing

  • Patient data may only be processed by healthcare professionals involved in the patient's care and their assistants. Data is only processed to the extent required by the procedures.
  • Data is processed using a unique user ID and password;
  • Paper archives are stored in lockable archives located in secure premises;
  • Patient data is stored in Sairaala KL Oy's centralized patient data register on the basis of written consent.
  • Individuals have the right to refuse to allow their data to be stored for shared use. In such cases, only the attending physician will have the right to read and make entries in the patient record. Billing information, appointment details, and notes on examination results will remain visible.
  • The patient has the right to request that their information be marked as confidential;
  • Digitally stored data can only be viewed and processed using individual user IDs issued by Sairaala KL Oy.
  • Patient data systems are actively monitored by tracking log data.

9. Right to review and correct data

  • Patients have the right to inspect their own patient data and log data once a year free of charge.
  • The patient has the right to request that incorrect information be corrected. The request must include the reasons for the correction. Patient data shall be corrected in accordance with the law so that both the correction and the original entry are visible in the patient data register.
  • The request must be submitted in writing to Sairaala KL Oy, Elina Salmi, Uudenmaankatu 38 E, 00120 Helsinki;
  • The requested information will be provided in writing. The patient's identity will be verified before the information is disclosed.

10. Retention period for personal data in patient records

  • Patient data is stored in accordance with the Ministry of Social Affairs and Health's decree on patient records (298/2009).
  • Log data is stored for at least 12 years after the data is generated;
  • Other information related to the patient data register is stored for as long as necessary for data processing (billing and collection) or as required by accounting legislation.