Return to Home
Privacy Policy Terms and Conditions
Staff Portal
HIMS Logo

Republic of the Philippines • Department of Health

Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS)

Hospital Information Management System (HIMS)

Privacy Policy

System Privacy Notice • Republic Act No. 10173 Reference • Effective: September 2026

Document Title System Privacy Notice & Data Protection Policy Document Reference DPA-2012-HIMS-POL
Release Version Version v1.0 (Operational) Effective Date September 2026
Governing Institution Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS)
Data Protection Officer Office of the Data Protection Officer DPO Contact Email [email protected]
Applicability All authorized healthcare personnel, pharmacists, supply chain officers, warehouse custodians, and system administrators.
Supervising Authority National Privacy Commission (NPC) & Institutional Governance Statutory Framework Republic Act No. 10173 (DPA 2012), IRR, NPC Circulars

This is the privacy policy of Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS). This document explains Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS)'s policies for the collection, use, and disclosure of personal information processed through the Hospital Information Management System (HIMS).

1. Data Controller Information

The personal data processed in this system is controlled by Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS) ("Hospital"), operating as the Personal Information Controller (PIC) pursuant to Republic Act No. 10173, otherwise known as the Data Privacy Act of 2012 (DPA), and its Implementing Rules and Regulations (IRR).

Personal Information Controller: Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS)
Institutional Address: Tala, Caloocan City, Metro Manila, Philippines
Data Protection Officer (DPO): Office of the Data Protection Officer
DPO Contact Email: [email protected]
Contact Telephone: +63 (2) 8962-8209

2. The Information We Collect

Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS) collects information by various methods including information actively provided by authorized personnel, system administrators, and automated operational telemetry.

The system processes employee identity and contact details, profile images, institutional account and role data, authentication and device-security records, IP/device/browser and optional audit-location data, operational actor attribution, supplier authorized-representative and delivery-personnel contact details, data-subject request records, security-incident records, notifications, and AI-assistant conversations or attachments submitted by authorized users. Passwords remain one-way hashed; MFA secrets and designated sensitive database fields use application encryption.

Clinical Data Distinction: HIMS is a logistics, procurement, and warehouse platform and defines no patient chart, diagnosis, or treatment-record fields. Users must not place patient data, credentials, or unrelated personal information in free-text fields or uploads; submitted free text may still become part of the relevant operational record.

3. How We Use This Information

This information is used to aid in the provision of hospital operations, pharmaceutical tracking, procurement workflows, stock movements, and user account governance.

Lawful Basis for Processing

The configured purposes for processing workforce information identify the following potential bases under Section 12 of Republic Act No. 10173. The institutional DPO must validate the applicable basis for each real processing activity rather than relying on generic consent checkboxes:

  • Fulfillment of Employment / Contractual Role (Sec. 12[b]): Necessary for provisioning staff login credentials, maintaining duty assignments, and executing warehouse, procurement, or pharmacy tasks.
  • Compliance with Legal & Regulatory Obligations (Sec. 12[c]): Meeting statutory mandates of the Department of Health (DOH), Food and Drug Administration (FDA), and Commission on Audit (COA) to maintain verifiable medicine chain-of-custody.
  • Legitimate Interests of the Health Facility (Sec. 12[f]): Safeguarding hospital assets against theft or discrepancies, ensuring supply chain continuity, and securing internal systems.
  • Security Safeguards (Sec. 20): Capturing audit events, IP addresses, device and browser context, approximate IP-derived location, and session timestamps to prevent unauthorized access and protect data integrity. With the user's explicit browser permission, HIMS may instead retain rounded, device-reported coordinates for the current signed-in session and record them with subsequent audit events.

4. Who We Share This Information With

Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS) does not share personal information with any third parties except as disclosed in this policy or required by law. Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS) may provide personal information to internal institutional auditors, statutory regulatory bodies, and contracted technology service providers (which shall be bound by strict confidentiality and data protection agreements) to assist Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS) in the operations disclosed herein.

  • Configured email and SMS delivery providers: receive the destination address or number and the minimum security-message content needed for OTP, password-reset, or device-security delivery.
  • Google Gemini, when enabled: may receive pattern-sanitized prompts, minimized operational context, and sanitized extracted text from supported text-based attachments. Raw image and PDF files are not sent to the provider. Automated redaction reduces risk but is not a substitute for users avoiding personal or clinical data.
  • Audit location: device coordinates remain inside HIMS and are converted to coarse place labels using the application's local lookup; they are not sent to public reverse-geocoding services.

5. Cookies & Technical Storage

HIMS utilizes only strictly necessary technical session tokens required for authentication, CSRF security, and automated inactivity timeouts. No marketing, advertising, or third-party tracking cookies are utilized.

Cookie / Token Classification Purpose Duration
hims-session Strictly Necessary Maintains authenticated staff session and CSRF protection. Session / Idle Timeout
hims_inactivity Strictly Necessary Enforces automatic logout upon inactivity to safeguard hospital terminals. Browser session
XSRF-TOKEN Strictly Necessary Mitigates cross-site request forgery risks during state-changing requests. Session

6. Retention, Deactivation & Immutable Audit Trail

Personal data and administrative logs are retained in accordance with hospital governance guidelines and statutory audit obligations:

  • Deactivation vs. Deletion: When staff resign or transfer departments, user accounts are deactivated to immediately revoke login access. Account records and historic transaction attributions are preserved to maintain pharmaceutical custody trails.
  • Immutable Audit Trail: All operations captured in the Audit Trail (audit_logs) are append-only. They cannot be modified or purged through the user interface, ensuring complete evidentiary reliability.
  • AI Conversations & Attachments: Deleted by the scheduled retention sweep after 30 days without conversation activity.
  • DSAR Export Packages: Private downloadable packages expire after 7 days and are disposed by the retention sweep; the request case and its decision remain for accountability.
  • Ephemeral Records: Read notifications are removed after the configured 90-day period, and resolved recovery records after 180 days.
  • Other Operational Records: Supplier, procurement, logistics, inventory, and account-attribution records are preserved because HIMS does not define an approved automated disposal period for them. Their final retention or disposal requires the hospital's authorized records schedule and legal review.
  • Password Security: Passwords are one-way hashed using salted bcrypt and cannot be retrieved in plaintext by any user or administrator.

7. Security Safeguards

To support the hospital's privacy program, HIMS incorporates the following application-level safeguards; organizational and physical safeguards remain the institution's responsibility:

  • Production HTTPS/TLS is required by the deployment configuration; the deployed endpoint must be independently verified because TLS terminates outside Laravel.
  • Multi-Factor Authentication (MFA) via time-based one-time password (TOTP) protocols and secure email channels.
  • Granular Role-Based Access Control enforcing the Principle of Least Privilege across Pharmacy, Warehouse, Management, and Administration.
  • Intrusion rate-limiting and automatic account lockout defenses against brute-force credential attacks.

8. Your Rights as a Data Subject

Under Section 16 of Republic Act No. 10173 and Rule VIII of its IRR, data subjects have rights including information, access, correction, objection, and qualified blocking, removal, or destruction. Requests remain subject to lawful retention and evidentiary obligations:

Statutory Right Legal Scope & Application in HIMS
Right to be Informed (Sec. 16a) To be notified of the nature, purpose, and legal basis of inventory data processing operations.
Right to Access (Sec. 16c) To request an electronic export of your personal information recorded in the system.
Right to Rectification (Sec. 16d) To dispute inaccuracy or error in your personal employee data and have it corrected.
Right to File a Complaint (Sec. 16a) To lodge a formal complaint with the National Privacy Commission (privacy.gov.ph).
Exercising Your Rights: Authorized staff may submit a formal Data Subject Request directly to the Data Protection Officer through your Account Settings.

9. Inquiries, Concerns & DPO Contact Information

For inquiries concerning this Privacy Notice, the exercise of data privacy rights, or to report an information security concern, please direct communications to:

Dr. Jose N. Rodriguez Memorial Hospital and Sanitarium (DJNRMHS)

Office: Office of the Data Protection Officer

Data Protection Officer: Office of the Data Protection Officer

Email: [email protected]

NPC Registration: Not configured; verify with the DPO

National Privacy Commission: [email protected]

10. Document Control & Approval Record

Role / Action Designated Office / Authority Formal Verification Action Date
Prepared By: Hospital Data Privacy Compliance Team [Compliance Team Verified] September 2026
Reviewed By: Institutional Data Protection Officer [DPO Statutory Review Verified] September 2026
Approved By: Medical Center Chief / Hospital Administrator [Executive Directive Approved] September 2026