Avenue Healthcare limited Patient Data Map
1. Data Collection
Sources of Data: M360 HMIS
- Patient registrations
- Electronic Health Records (EHR) for Outpatients
- Lab and Radiology Diagnostic reports
- Drug Prescriptions
- Admission Data
- Op Visit Data
Types of Personal Data Collected:
- Personal Information (Name, Address, DOB, Gender)
- Medical History
- Treatment Plans
- Area of Residence
- Billing Information
- Emergency Contacts
Data Processing:
Purpose of Processing:
- Providing medical services
- Billing and payment processing
- Appointment scheduling
- Medical research (if applicable, with patient consent)
3. Legal Basis for Processing
- Patient consent
- Legal obligation (providing medical care)
- Vital health interests (emergency medical situations)
4. Data Processing Activities:
- Data entry into M360 HMIS system
- Sharing information with healthcare professionals within the organization
- Billing and insurance claims processing
- Medical research data analysis (if applicable)
5. Data Storage:
On-site servers at our Parklands Hospital and Orbit Place
6. Data Retention Periods:
Define how long different types of data are retained (e.g.,
patient records might be retained for a
specific number of years after the last treatment)
7. Data Sharing:
a) Internal Sharing:
- Healthcare professionals within the organization
- Administrative staff for scheduling and billing purposes
b) External Sharing:
- Insurance companies (for billing)
- Other healthcare providers as may be relevant (with patient consent)
- Public health authorities (as required by law)
8. Security Measures:
a) Encryption:
- Data transmission via a secure private MPLS network in a hub-spoke network architecture
to our primary data center in Parklands
b) Access Controls:
- Role-based access control to patient records on M360 HMIS
- Periodic access audits
9. Training:
Regular staff training on data protection policies and procedures
10. Data Subject Rights (Patients' Rights):
Right to Access: Patients can request access to their record by completing a
Data Access Request Form. These requests are fulfilled within 7-14 days.
Right to Rectification: Patients can request rectification to data by
requesting a change to their data.
Right to Erasure: Patients can request rectification to data to be deleted
within the boundaries of the law, i.e., not involved in a medico-legal case.
Right to Portability: Patients can currently get some of their medical data
in a portable format such as their Diagnostic or medical reports either in printed or soft
format. We do not currently have an end-to-end portable EMR at this time, however.
11. Incident Response:
For more on our Data Breach Procedure please refer here