Your health data will be shared within the hospital as part of your care. We may also share your data outside the hospital if necessary for the purposes stated.
Within UZ Gent
In the context of your care, your health data will be recorded in the electronic patient dossier (EPD). Employees of the UZ Gent are given access to your file if they need this data to perform their function (e.g. the treating care provider, whether or not in training, an administrative employee commissioned by the treating care provider, etc.).
Through a combination of technical and organisational measures, we ensure that they can only access the personal data they absolutely need to perform their tasks:
- A 'static' access control allows a role (doctor, nurse, secretarial assistant, etc.) to be linked to a user.
- A 'dynamic' access control allows to additionally fine-tune whether a user in a certain role is involved in the treatment of a specific patient and therefore needs access to that record.
In addition, other employees can also gain access to your data, for example from a support department, but only if absolutely necessary for the purposes listed.
All UZ Gent employees who need access to patient personal data for the performance of their duties undertake to respect the provisions of this privacy statement, of the GDPR, as well as all other data protection principles when processing and consulting patient files. They are always bound by professional secrecy or an equivalent statutory or contractual duty of confidentiality and must respect the duty of discretion set out by UZ Gent.
Outside UZ Gent
Under no circumstances will we disclose or sell your personal data for commercial use.
We may share your data with the following recipients to the extent necessary for the purposes listed:
- You or your representatives: within the limits of the Patient Rights Act
- External treating healthcare providers: as part of your care (via www.patiëntconsent.be), you may give an informed consent (with the option to withdraw your consent) to share your health data electronically and securely. Download the CoZo privacy statement (pdf).
- Your health insurance fund and the INAMI-RIZIV (National Institute for Sickness and Disability Insurance)
- Insurance institutions such as your hospitalisation insurance and the hospital's professional liability insurer
- External processors we call upon to process your personal data and who work on the instructions of and under the supervision of UZ Gent
- Government bodies authorised to do so by a government decision
- Other bodies insofar as required by law or with your consent
In principle, we do not transfer patients' personal data to countries outside the EEA. If we do, we will inform you in advance and check whether the destination country offers an adequate level of protection. If the country to which we wish to transfer data does not provide adequate safeguards, we will enforce them ourselves through model agreements, made available by the European Commission, or other accepted measures.