Privacy & Confidentiality Policies
Your privacy is important to us. We are committed to protecting your personal and health information with transparency, integrity and confidentiality while delivering quality healthcare services.
Privacy & Confidentiality Policy
Sri Lakshmi Multi Speciality Hospital recognises that protecting patient privacy and maintaining medical confidentiality are fundamental ethical, professional and legal responsibilities. Every patient has the right to expect that personal, medical and financial information shared with the Hospital will be treated with respect, confidentiality and appropriate security throughout the course of care.
This Privacy & Confidentiality Policy has been developed with reference to applicable Indian laws and recognised healthcare standards, including the Digital Personal Data Protection Act, 2023, the ethical obligations prescribed under the National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023, applicable provisions of the Information Technology Act, 2000, and the patient information management principles promoted by the National Accreditation Board for Hospitals & Healthcare Providers (NABH).
Purpose of this Policy
The purpose of this policy is to establish a comprehensive framework for the responsible collection, use, storage, protection, retention and disclosure of patient information. The Hospital is committed to safeguarding patient privacy while ensuring that authorised healthcare professionals have access to the information necessary to deliver safe, effective and continuous medical care.
This policy supports responsible information management, transparency and accountability in accordance with applicable Indian healthcare laws, ethical medical practice and recognised quality standards.
Privacy
Respecting every patient's personal and medical information.
Security
Protecting records through appropriate physical, technical and administrative safeguards.
Confidentiality
Information is disclosed only to authorised persons or where permitted or required by law.
Compliance
Supporting ethical healthcare and recognised Indian legal and regulatory requirements.
Scope of this Policy
This policy applies to all patient information collected, received, generated, maintained or processed by Sri Lakshmi Multi Speciality Hospital, irrespective of whether the information is maintained in paper records, electronic health records, laboratory systems, imaging systems, pharmacy systems or other authorised Hospital information systems.
The policy applies to all doctors, registered medical practitioners, nurses, pharmacists, laboratory personnel, allied health professionals, consultants, administrative employees, contractors and any authorised individual who accesses patient information while performing official duties.
"Protecting patient privacy is a shared responsibility. Every member of the Hospital workforce is expected to maintain confidentiality, professionalism and responsible information handling at all times."
Our Commitment to Privacy & Confidentiality
Sri Lakshmi Multi Speciality Hospital is committed to protecting patient information throughout its entire lifecycle—from collection and clinical use to secure storage, authorised access, lawful disclosure, retention and confidential disposal. We maintain appropriate administrative, physical and technical safeguards designed to reduce the risk of unauthorised access, disclosure, alteration, loss or misuse of confidential information.
Regulatory & Quality Commitment
Sri Lakshmi Multi Speciality Hospital is committed to continually strengthening its privacy and confidentiality practices with reference to the Digital Personal Data Protection Act, 2023, Information Technology Act, 2000, National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023, and the Information Management System principles promoted under NABH Standards for Hospitals.
Collection of Patient Information
Sri Lakshmi Multi Speciality Hospital collects only the personal and health information that is reasonably necessary for providing healthcare services, ensuring patient safety, meeting legal obligations and supporting hospital administration.
Information is collected directly from patients, authorised representatives or other lawful sources whenever required for diagnosis, treatment, billing, insurance processing and continuity of care.
Information We May Collect
- Patient identification details.
- Contact and emergency contact information.
- Medical history and previous treatments.
- Laboratory and diagnostic reports.
- Prescription and medication records.
- Insurance and billing information.
Collection Principle
We collect only the information reasonably necessary for patient care, hospital operations and applicable legal or regulatory requirements.
Use of Personal & Medical Information
Patient information is used only for legitimate healthcare purposes, including diagnosis, treatment, nursing care, pharmacy services, laboratory investigations, follow-up care, hospital administration, billing, insurance processing, quality improvement and other activities directly related to healthcare delivery.
The Hospital does not use confidential patient information for purposes unrelated to healthcare unless authorised by the patient or otherwise permitted or required under applicable Indian law.
"Patient information is used responsibly, ethically and only for purposes connected with healthcare delivery, hospital operations or legal obligations."
Patient Consent & Information Sharing
Sri Lakshmi Multi Speciality Hospital respects every patient's right to control the disclosure of personal and medical information. Confidential information will normally be shared only with authorised healthcare professionals directly involved in the patient's care.
Information may also be disclosed where the patient has given informed consent or where disclosure is permitted or required under applicable law, court orders or directions issued by competent government authorities.
Medical Confidentiality
Maintaining medical confidentiality is a fundamental ethical duty of every healthcare professional. Doctors, nurses, pharmacists and all Hospital employees who have authorised access to patient information are expected to preserve the confidentiality of medical records and information obtained during the course of treatment.
Confidential information will not be discussed, disclosed or accessed by unauthorised persons. Access to patient records is restricted according to professional responsibilities and operational requirements.
Professional Confidentiality
The Hospital upholds the ethical obligations relating to patient confidentiality recognised under the National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023, while respecting patient rights and applicable Indian law.
Secure Records Management
Sri Lakshmi Multi Speciality Hospital maintains patient records using secure administrative, physical and technical safeguards designed to preserve confidentiality, integrity and availability throughout the information lifecycle. Medical records are protected against unauthorised access, alteration, loss or destruction.
Access to patient records is granted only to authorised healthcare professionals and employees whose duties require such access for patient care, hospital operations or legal obligations.
Record Protection
- Secure storage of paper medical records.
- Controlled access to patient files.
- Protection against unauthorised disclosure.
- Regular monitoring of record security.
- Confidential handling throughout the record lifecycle.
Information Integrity
We maintain accurate, complete and reliable medical records to support safe patient care, clinical continuity and regulatory requirements.
Electronic Health Information
Patient information maintained within electronic health record systems, laboratory information systems, pharmacy systems, radiology systems and other authorised digital platforms is protected through appropriate technical and organisational safeguards.
Electronic records are managed using secure authentication, controlled user access, password protection and other information security measures designed to reduce the risk of unauthorised access or data compromise.
"Electronic health information is managed using secure systems designed to protect confidentiality, integrity and availability."
Data Security & Access Control
Sri Lakshmi Multi Speciality Hospital follows a role-based access approach, ensuring that patient information is available only to authorised personnel who require access to perform their professional duties.
Administrative, technical and physical safeguards are implemented to minimise the risk of unauthorised access, accidental disclosure, cyber threats and misuse of confidential patient information.
Information Retention & Secure Disposal
Patient records are retained for the period prescribed by applicable Indian laws, professional regulations and hospital record retention policies. Following the expiry of the applicable retention period, confidential records are securely archived or disposed of using approved procedures designed to prevent unauthorised disclosure.
Secure disposal methods may include confidential shredding of paper records, secure deletion of electronic data and other approved information destruction practices, depending upon the nature of the information.
Record Lifecycle Management
From collection through secure disposal, patient information is managed responsibly to protect confidentiality, support continuity of care and comply with applicable legal, regulatory and professional obligations.
Patient Rights Regarding Personal Information
Sri Lakshmi Multi Speciality Hospital respects every patient's right to privacy and supports transparency in the management of personal and medical information. Patients may request access to their health records, seek correction of inaccurate information where appropriate and understand how their information is used, subject to applicable legal and regulatory requirements.
Hospital Responsibilities
Sri Lakshmi Multi Speciality Hospital is responsible for maintaining effective governance, administrative controls and information security practices that protect patient privacy and confidentiality throughout the organisation.
Our Responsibilities
- Maintain confidentiality of patient information.
- Implement appropriate privacy safeguards.
- Provide confidentiality training to staff.
- Investigate privacy incidents promptly.
- Continuously strengthen information security.
Privacy Governance
Privacy protection is integrated into our clinical, administrative and information management practices to support safe, ethical and patient-centred healthcare.
Policy Review & Compliance
This Privacy & Confidentiality Policy will be reviewed periodically to reflect changes in healthcare practices, information security requirements, technological developments and applicable Indian laws and regulations.
Hospital management will encourage continuous improvement of privacy practices through staff education, internal audits, risk assessments and quality improvement initiatives.
Reporting Privacy Concerns
Patients who have questions regarding the privacy of their information or believe their confidentiality has not been maintained are encouraged to contact the Hospital. Concerns will be reviewed respectfully, confidentially and in accordance with the Hospital's grievance handling procedures.
"Protecting patient privacy requires openness, accountability and continuous improvement."
Contact Us
For questions regarding this Privacy & Confidentiality Policy or the handling of patient information, please contact us.
Sri Lakshmi Multi Speciality Hospital
Address:
No. 5/91, Near Apollo Hospital OMR,
Church Road, Perungudi,
Chennai – 600096, Tamil Nadu, India.
Phone: +91 98407 92932
Email: contactus@slmsh.com
Regulatory & Standards Reference
This Privacy & Confidentiality Policy has been developed with reference to applicable Indian laws, recognised healthcare standards and professional ethical principles. These references guide the Hospital's approach to protecting patient privacy and maintaining medical confidentiality.
Applicable Indian Laws
- Digital Personal Data Protection Act, 2023.
- Information Technology Act, 2000.
- National Medical Commission (Registered Medical Practitioner – Professional Conduct) Regulations, 2023.
- Applicable Central and State Government healthcare regulations.
Quality & Professional Standards
- National Accreditation Board for Hospitals & Healthcare Providers (NABH) – Information Management System Principles.
- Recognised healthcare information management practices.
- Professional medical ethics relating to confidentiality.
- Hospital quality improvement and clinical governance principles.
"Sri Lakshmi Multi Speciality Hospital is committed to continually strengthening patient privacy, information security and medical confidentiality while progressing towards nationally recognised healthcare quality standards, including future NABH accreditation."
