Thammasat Advanced Medical Center (the “Company”) is committed to protecting your personal data as a recipient of our medical examinations, treatments, and other services. Your personal data will be protected in accordance with the Personal Data Protection Act B.E. 2562 (2019) (PDPA). As the Data Controller, the Company has a legal obligation to provide this document to inform you of the purposes and methods by which we collect, use, or disclose your personal data, as well as to inform you of your rights as a data subject.
1. Objectives
The Company processes your personal data within the scope prescribed by the Personal Data Protection Act B.E. 2562 (2019) (PDPA) and only to the extent necessary for such operations. The Company has summarized the use of your personal data and explained the lawful bases of processing as follows:
Purposes
Types of Data
Lawful Basis of Processing
1. For the Purpose of Medical Treatment and Healthcare Services
Provision of Medical Services within the Company's Facilities
The Company's team of physicians, nurses, and/or other healthcare personnel will record your personal data, use your personal data for consultation with physicians or medical personnel, including taking still images and videos for treatment monitoring, and/or perform any actions in accordance with relevant professional standards throughout the period you receive our services. The Company will provide detailed explanations for your understanding prior to proceeding and allow you the opportunity to ask questions until you are satisfied.
Provision of Medical Services in Cases Requiring Data Linkage among Affiliated Healthcare Facilities
For the benefit of providing medical services to you, the Company's physicians, nurses, and/or other relevant personnel may disclose your personal data to affiliated healthcare facilities in cases where the exchange of data among such facilities is necessary for certain types of services. In this regard, the Company has implemented personal data protection measures through mutual agreements among affiliated healthcare facilities to prevent any unlawful or unauthorized processing of your personal data.
For Patient Referral between Healthcare Facilities
In the event that the Company makes or receives a request to transfer a patient from one healthcare facility to receive further medical treatment at another healthcare facility, or makes or receives a request to admit a patient from another healthcare facility to receive treatment at the Company's facility in accordance with the patient referral process, the Company shall proceed according to the patient referral process established by the Company's standards. Your personal data will be used solely for the purpose of patient referral and will not be used for any other purposes.
Identity Data
Contact Data
Health Data
Financial Data
For Sensitive Personal Data: To prevent or suppress a danger to a person’s life, body, or health in the event that the data subject is incapable of giving consent, such as receiving emergency care or for patient referral between hospitals (Section 26 (1)).
2. For the Purpose of Analytical Studies to Improve Healthcare Quality without Identifying the Data Subject
The Company may use your personal data for analytical studies to improve the quality of medical care. This will be conducted in the form of an aggregated report that does not identify the data subject. The Company will strictly maintain the confidentiality of such data.
Statistical Data
3. Disclosure of Personal Data to Insurance Companies with Which You or the Company Have Entered into a Contract for the Purpose of Claiming Insurance Benefits or Medical Expense Reimbursements
The Company is required to disclose your personal data to insurance companies for the performance of a contract that you or the Company have entered into with such insurance companies, for the benefit of claiming insurance benefits or exercising the right to medical expense reimbursement. In this regard, the Company will not disclose your personal data to any other unrelated parties.
Identity Data
Contact Data
Health Data
Upon obtaining your explicit consent to disclose your personal data, which is health data, to insurance companies for the purpose of claiming insurance benefits or exercising the right to medical expense reimbursement (Section 26).
4. Disclosure of Personal Data to the Referring Entity or the Payor, Subject to Your Consent
In the event that an agency or organization, whether public, private, or a state enterprise, refers you to the Company for medical examinations or treatments, or acts as the payor for your medical bills, the Company will disclose your medical results and treatment data—which constitutes sensitive personal data—to such entity only if you have granted explicit consent for such disclosure. If you do not provide your consent, the Company will deliver the medical results directly to you.
Identity Data
Contact Data
Health Data
Upon obtaining your explicit consent to disclose your personal data (Section 26).
5. For the Purpose of Linking Electronic Medical Record Databases Between Healthcare Facilities via a Mobile Application
Upon obtaining your consent, the Company will enter your personal data into our computer system in the form of a mobile application to facilitate your medical consultations and enable you to manage your data through the application. To provide maximum benefit, the system will link electronic medical record databases across affiliated healthcare facilities, allowing you to access and view your personal data held within the network via various electronic devices. The Company has established mutual agreements with these affiliated healthcare facilities to ensure that your personal data is protected in compliance with the Personal Data Protection Act B.E. 2562 (2019).
Identity Data
Contact Data
Health Data
Upon obtaining your explicit consent to disclose your personal data (Section 26).
6. For the Company's Marketing Purposes
The Company may collect, use, and process your personal data to analyze your health conditions and contact you to communicate, provide medical news, and offer promotions, products, and services to you, subject to your consent.
Identity Data
Contact Data
Marketing and Communications Data
The Company will only be able to proceed with this matter upon obtaining your explicit consent to use your health data for marketing purposes (Section 26).
In addition to the purposes stated above, the Company will not use your personal data for any other purposes, except as permitted by the Personal Data Protection Act B.E. 2562 (2019), such as:
Upon obtaining your consent (Section 24), or upon obtaining your explicit consent in the case of using sensitive personal data (Section 26).
For research or statistical purposes, provided that appropriate safeguards are in place to protect the personal data, rights, and freedoms of the data subject (Section 24 (1)).
To prevent or suppress a danger to a person’s life, body, or health (Section 24 (2)).
For the performance of a contract between the Company and you (Section 24 (3)).
For the performance of a task carried out in the public interest by the Company (Section 24 (4)).
For the legitimate interests of the Company or any other persons or legal entities, except where such interests are overridden by the fundamental rights of the data subject (Section 24 (5)).
For compliance with a law to which the Company is subject (Section 24 (6)).
To prevent or suppress a danger to a person’s life, body, or health in cases where the data subject is incapable of giving consent, by whatever reason, for the use of sensitive personal data (Section 26 (1)).
For the establishment of legal claims (Section 26 (4)).
For public interest in public health or other social protection, provided that the Company has implemented appropriate measures to protect the fundamental rights and interests of the data subject (Section 26 (5) (b)).
For the necessity of complying with laws concerning labor protection, provision of medical benefits, and social security (Section 26 (5) (c)).
2. Definitions
“Personal Data” means any information relating to a person, which enables the identification of such person, whether directly or indirectly, but not including the information of the deceased persons in particular.
“Sensitive Personal Data” means personal data pertaining to racial, ethnic origin, political opinions, cult, religious or philosophical beliefs, sexual behavior, criminal records, health data, disability, trade union information, genetic data, biometric data (e.g., facial recognition data, iris recognition data, fingerprint recognition data), or of any data which may affect the data subject in the same manner, as prescribed by the Personal Data Protection Committee.
“Medical Treatment Data” means the following information:
Date of receiving medical treatment
History of drug allergy and adverse drug reactions
History of food allergy
Names of diagnosed diseases, medical procedures, and surgeries
Blood test results, laboratory test results, pathological biopsy results, radiological images, and radiological reports
List of medications prescribed by the physician
Other information such as symptoms, physician's advice, and diagnosis details, etc.
“Process” or “Processing” means the collection, use, or disclosure.
“Data Controller” means a person or a juristic person having the power and duties to make decisions regarding the collection, use, or disclosure of the personal data.
“Data Processor” means a person or a juristic person who operates in relation to the collection, use, or disclosure of the personal data pursuant to the orders given by or on behalf of a Data Controller, whereby such person or juristic person is not the Data Controller.
“Thammasat Advanced Medical Center” means the network of Thammasat University Hospital, both currently existing and to be established in the future, whether registered in Thailand or abroad, which includes Thammasat University Hospital.
“Affiliated Healthcare Facilities” means healthcare facilities within the group or network of Thammasat University Hospital, operating either in Thailand or abroad.
3. Personal Data We Collect
Your personal data collected by the Company can be classified into the following categories:
Types of Personal Data
Details
Personal Data
First name, last name, identification card number, ID, facial photograph, gender, date of birth, passport, or other identification numbers.
Contact Data
Address, telephone number, email address.
Financial Data
Billing information, credit or debit card information, receipt information, quotation/invoice details.
Marketing Data
Information used for newsletter registration and participation in marketing activities.
Technical Data
Computer IP address, browser type, Cookies data, time zone setting, operating system, platforms, and technology of the devices used to access the website and the Online Appointment System.
Health Data
Medical treatment data, reports relating to physical and mental health, patient healthcare, laboratory test results, diagnosis, names of diagnosed diseases, information related to medication usage and drug allergies, history of food allergy, blood test results, laboratory examination results, pathological biopsy results, radiological images and radiological test reports, list of medications prescribed by the physician, information necessary for providing medical services, feedback data, and treatment outcomes.
4. Sources of Personal Data
The Company collects your personal data from the following sources:
1. Personal Data Obtained Directly from You
In the event that you are a recipient of medical examinations and treatments: The Company obtains your personal data when you contact the Company to inquire about our services, or when you register to receive medical treatments and other services from the Company in person, including registration via electronic channels.
2. Personal Data Obtained Indirectly
Persons closely related to you, such as relatives, spouses, etc.
Persons authorized by you to act on your behalf in contacting the hospital.
Affiliated healthcare facilities, in the event that you have given consent to such affiliated facilities to disclose your personal data.
Persons, juristic persons, or agencies, whether public, private, or state enterprises, that refer you to receive medical treatments or services with the Company, or that act as the payor for your service fees.
5. Disclosure or Sharing of Personal Data
The Company will not disclose your personal data to third parties, except as permitted by law where necessary for operational purposes. The Company may disclose your personal data in the following cases:
Disclosure to government agencies, competent authorities, or any persons when required or authorized by law, including compliance with court orders.
Disclosure to persons or juristic persons where the Company is required to perform a contract or act for your benefit as the data subject. The Company requires these persons or juristic persons to maintain confidentiality and protect your personal data in accordance with the standards prescribed by the Personal Data Protection Act B.E. 2562 (2019). This includes, but is not limited to, the following entities:
Affiliated healthcare facilities: To the extent necessary for providing medical examinations and healthcare services to you. The Company will disclose only the strictly necessary personal data and will maintain the confidentiality of your data in accordance with its obligations under relevant laws, such as the Sanatorium Act B.E. 2541 (1998), the National Health Act B.E. 2550 (2007), and the Medical Profession Act B.E. 2525 (1982).
Insurance companies or their claims management service providers (Third-Party Administrators).
Receiving healthcare facilities for patient referrals.
Entities referring you for medical treatments or services at our facility, or payors settling service fees on your behalf.
Data Processors necessary for the Company's operations, such as contractors or service providers for laboratory testing, data processing, telecommunications, computer systems, payment processing, or technology outsourcing.
Cloud Computing Storage: The Company may store personal data on a Cloud Computing system using third-party service providers, whether located in Thailand or abroad. The Company has entered into contracts with such parties with due care, taking into consideration the security systems and measures provided by the Cloud Computing service provider for the protection of personal data.
6. Retention Period of Personal Data
The Company applies the retention standards for medical records in accordance with the Sanatorium Act B.E. 2541 (1998) and its latest amendments. The Company will retain your medical records and any associated personal data within the hospital’s system for a period of at least 5 years from the date of creation. However, for the benefit of your ongoing medical treatment, such records will be retained until you have not contacted the Company for more than 10 years since the date of your last medical visit. Upon the expiration of the said 10-year period, all original medical records, copies, and electronic medical records will be destroyed.
In the event that the Company is required to comply with laws or regulations of other professional councils, adhere to court orders, or establish legal claims for any dispute resolution processes, the Company may retain the personal data for the duration of the statutory limitation period prescribed by such laws or regulations, or until the dispute has reached a final conclusion, as the case may be.
7. Measures for Retaining and Processing Personal Data
The Company will maintain the retention of personal data with security measures no less than the standard prescribed by law, utilizing appropriate systems to safeguard and secure such personal data. This includes using security protocols like Secure Sockets Layer (SSL), firewall protection, passwords, and other technical measures for data encryption over the internet, as well as storing physical document-based personal data in facilities with restricted access controls.
The Company restricts access to personal data that may be accessed by employees, agents, partners, or third parties. Third-party access to personal data will only be permitted as specified or instructed, and such third parties are strictly obligated to maintain confidentiality and protect the personal data.
The Company implements technological methods to prevent unauthorized access to its computer systems.
The Company maintains a monitoring system to manage the destruction of personal data that is no longer necessary for the Company’s operations.
In the case of sensitive personal data, the Company will implement robust security measures for both physical documents and electronic data regarding access and usage control. A usage system, backup system, and emergency contingency plan are provided, along with regular system risk assessments and audits.
8. Cross-Border Transfer of Personal Data
In certain cases, the Company may need to transfer your personal data to a foreign country. The Company may do so only after informing you of the purpose of such transfer and obtaining your consent, whereby the Company will notify you if the destination country may not have adequate personal data protection standards.
The Company may transfer your personal data without obtaining your consent in cases where such cross-border transfer is for the performance of a contract to which you are a party, or to prevent or suppress a danger to a person's life, body, or health, or to take steps at your request prior to entering into a contract, or as otherwise prescribed under the Personal Data Protection Act B.E. 2562 (2019).
10. Rights of the Data Subject
As a data subject, you have the right to request the Company to take actions regarding your personal data within the scope permitted by law, as follows:
Right to withdraw consent: You have the right to withdraw your consent for the processing of your personal data that you have previously provided to the Company at any time throughout the period your personal data is retained by the Company.
Right of access: You have the right to access your personal data and request the Company to provide a copy of such personal data, including requesting the Company to disclose the acquisition of personal data for which you have not given your consent.
Right to rectification: You have the right to request the Company to rectify inaccurate data or supplement incomplete data.
Right to erasure: You have the right to request the Company to erase or destroy your data for certain reasons.
Right to restriction of processing: You have the right to request the Company to restrict the use of your personal data for certain reasons.
Right to data portability: You have the right to transfer the personal data you provided to the Company to another Data Controller or to yourself for certain reasons.
Right to object: You have the right to object to the processing of your personal data for certain reasons.
To exercise any of the aforementioned rights, you may contact Thammasat Advanced Medical Center or our Data Protection Officer (DPO) to submit a request at:
Address: 95, 8 Phaholyothin Frontage Rd, Khlong Nueng, Khlong Luang District, Pathum Thani 12120
Telephone: 0 2078 0000
Email: thamc.official@gmail.com
11. Policy Updates
The Company may review and amend this Personal Data Protection Policy in the future to enhance and improve personal data protection. In this regard, the Company will notify you every time this policy is changed or updated.
12. Contact Us
Address: 95, 8 Phaholyothin Frontage Rd, Khlong Nueng, Khlong Luang District, Pathum Thani 12120
Telephone: 0 2078 0000
Email: thamc.official@gmail.com
Last updated 1 January 2024