Privacy Notice

  1. About OneHealth
    • OneHealth is a specialized network of clinics providing world-class medical care services, enabling a high-quality and unique healthcare journey for customers in Egypt. OneHealth intends to transform the healthcare experience into a convenient and seamless one, whether within branches located throughout Cairo or through available medical services via phone and video consultations.
  1. Policy Statement
    • OneHealth is committed to protecting patient privacy by maintaining the confidentiality of patient health information and outlining these privacy practices to data subjects.
    • OneHealth uses or discloses patient health information in strict compliance with the privacy practices described in this policy, ensuring maximum protection of data subjects’ privacy rights.
    • OneHealth reserves the right to amend the privacy practices described in this policy at any time. Any such amendments will apply to all health information retained by the company. OneHealth will publish the updated notice on its official website and/or make it available to patients. In the event of material changes to data processing activities, patients will be notified through effective communication channels.
  1. Purpose
    • This notice provides patients with comprehensive information regarding how their personal and health data is collected, processed, and utilized in practice, as well as the specific circumstances that may necessitate data disclosure between OneHealth and third parties.
  1. Data Processing and Principles
    • OneHealth collects and processes patient personal and clinical data strictly to provide healthcare services, manage patient health affairs, and execute directly related administrative matters, including clinical claims, financial/insurance payments, medical auditing, accreditation, and internal business operations (such as staff training).
  1. Categories of Collected Personal Data
    • OneHealth processes two categories of data in accordance with the Egyptian Data Protection Law (No. 151/2020) and GDPR:
    • Standard Personal Data: This includes names, dates of birth, national identification numbers, addresses, and contact information (mobile phone numbers and email addresses).
    • Sensitive Personal Data (Health & Biometric Data): This includes comprehensive medical information such as medical history, prescriptions, known allergens, clinical complications, preventive care records, social and family medical history, and clinical risk factors. It also includes laboratory samples, diagnostic x-rays, medical record numbers, and healthcare identifiers.
    • Insurance Data: This includes insurance numbers for identification, claims, and policy-related information provided by the patient or their designated insurance provider.
    • Video Surveillance (CCTV): Certain public areas within the medical centers are monitored with surveillance cameras for security and safety purposes. Surveillance strictly excludes examination rooms and private clinical areas. Recorded footage is retained securely for a maximum of three (3) months and is accessed strictly by authorized security personnel for incident investigations (e.g., theft, fraud, or client complaints).
  1. Methods of Collecting Personal Information
    • OneHealth collects personal and medical data through the following channels:
    • Direct Collection: Information provided by the patient during their initial registration at OneHealth clinics or during the clinical consultation process.
    • Digital Platforms: Information collected when downloading, activating, or utilizing OneHealth’s official mobile applications, website, online appointment booking systems, or helpline.
    • Third-Party Sources: Information legally acquired from authorized third parties, which includes:
      • Legal guardians or authorized representatives acting on behalf of the patient.
      • External healthcare providers, specialists, or community health professionals involved in the patient’s care.
      • Contracted diagnostic laboratories, imaging centers, and hospitals.
      • The patient’s insurance company or employer, where the medical service is funded or sponsored by them.
  1. Sharing Patient Personal Information
    • OneHealth may disclose personal data to authorized third parties operating as insurance providers, healthcare facilitators, or contracted service providers. These categories include, but are not limited to:
    • Certified electronic payment gateways and financial aggregators.
    • Contracted medical laboratories and diagnostic radiology centers.
    • Licensed pharmaceutical platforms and medication delivery services.
    • All disclosures are governed by binding Data Processing Agreements (DPAs) or confidentiality clauses, ensuring that third parties implement technical and organizational measures equivalent to OneHealth’s standards to protect data confidentiality.
  1. Storage, Protection, and Retention of Data
    • Patient data may be stored in various formats, including electronic health records (EHR), secure paper files, and authorized audio/visual recordings. OneHealth enforces strict access control policies, ensuring that only authorized personnel with a legitimate “need-to-know” basis can access patient records.
    • OneHealth has implemented robust technical, physical, administrative, and organizational safeguards designed to protect collected information from loss, misuse, unauthorized access, disclosure, modification, and destruction.
    • Patients are responsible for maintaining the security of their own digital credentials. They must take adequate precautions to protect their passwords, mobile devices, and computers against unauthorized access (e.g., logging out of shared devices and selecting strong passwords). OneHealth bears no liability for unauthorized account access resulting from a patient’s failure to safeguard their login credentials.
    • Credit/debit card details and financially sensitive identifiable information processed via online portals will not be stored, sold, exchanged, or rented to any unauthorized third parties.
    • Patient personal data, clinical records, and call recordings are retained in compliance with applicable Egyptian laws and healthcare regulations. Retention periods range from a minimum of three (3) months (for security footage and standard logs) up to a statutory maximum of ten (10) years for core medical records, depending on the legal requirements of the specific processing purpose. Upon the expiration of the retention period, data is securely and permanently deleted or anonymized.
  1. Data Subject Rights (Patients’ Rights)
    • In accordance with the Egyptian Data Protection Law (No. 151/2020) and AXA Group requirements, data subjects have specific rights regarding their personal and medical data. If a patient has any concerns or complaints concerning their data, they can contact OneHealth’s Data Protection Officer (DPO) via email at Compliance@One-health.com. However, these rights are subject to statutory limitations governing the healthcare sector in Egypt:
    • Right of Access: Data subjects have the right to request access to and obtain a copy of their personal data and medical records held by OneHealth. This information is provided free of charge. However, OneHealth reserves the right to charge a reasonable administrative fee for any unfounded, repetitive, or excessive requests.
    • Right to Rectification: Data subjects have the right to request the correction, update, or completion of any inaccurate or incomplete personal information stored in OneHealth’s systems. OneHealth encourages patients to verify and update their information regularly.
    • Exclusion of the Right to Erasure (Data Deletion): The right to data erasure or deletion does not apply to medical records and clinical data managed by OneHealth. In compliance with Egyptian healthcare regulations, medical ethics, and statutory record-retention laws, OneHealth is legally mandated to preserve patients’ medical histories and cannot delete clinical records upon request.
    • Right to Restriction and Objection: Data subjects have the right to object to, or request the restriction of, the processing of your personal data for specific non-clinical purposes, such as direct marketing or promotional communications.
    • Right to Data Portability: Data subjects have the right to receive their personal data in a structured, commonly used format, or to request its transfer to another healthcare provider, provided it is technically feasible and does not violate medical confidentiality protocols.
    • Right to Withdraw Consent: Where data processing is based solely on explicit consent (and is not required for medical treatment or legal compliance), data subjects may withdraw their consent at any time by contacting OneHealth’s customer service.
    • Exercise of Rights: To exercise any of their applicable rights, data subjects must submit a formal written request to OneHealth’s Data Protection Department via email at Compliance@One-health.com. OneHealth will review and respond to verified requests within thirty (30) days.
    • Unofficial Communication Channels: OneHealth strictly prohibits the use of unofficial messaging applications (such as WhatsApp) for medical consultations or exchanging clinical data between doctors and patients. OneHealth bears no liability for data shared via these channels, as their security is entirely controlled by third-party providers (e.g., Meta).
    • Confidentiality and Disclosure: Data subjects’ data will remain confidential and will not be disclosed to third parties without their consent, except where required by Egyptian law, court orders, or to fulfill contractual operations with their designated health insurance provider.
  1. Personal Data Transfers
    • When utilizing OneHealth services for the first time, patients agree to enable OneHealth to transfer necessary personal or medical data to authorized third parties to facilitate medical care, as detailed in this policy.
    • OneHealth may share clinical information with contracted third-party medical diagnostic institutions and laboratories when additional examinations, analyses, or medical opinions are required.
    • In alignment with AXA Group requirements, OneHealth may store or process patient personal data inside of the Arab Republic of Egypt. In accordance with Article (14) of the Egyptian Data Protection Law (No. 151/2020), any cross-border transfer will strictly occur only after obtaining the necessary licenses or approvals from the Egyptian Data Protection Center (EDPC), utilizing Standard Contractual Clauses (SCCs) or Binding Corporate Rules (BCRs).
    • Patient personal and medical information may be disclosed without prior consent under the following strict statutory exemptions:
      • When required or authorized by applicable Egyptian laws or judicial orders.
      • When necessary to mitigate or prevent a serious, imminent threat to the patient’s life, health, safety, or to public health and safety, particularly when obtaining immediate patient consent is impracticable.
      • In medical emergencies where the disclosure of identifying clinical data is essential to safeguard the patient’s well-being.
      • When legally requested by competent authorities to assist in locating a missing person.
      • When necessary for the establishment, exercise, or defense of a legitimate legal claim, or within confidential dispute settlement proceedings.
      • When there is a statutory mandate requiring the mandatory notification of specific infectious diseases or public health risks (e.g., Covid-19) to regulatory health authorities.
      • For internal quality auditing and training purposes, patients’ identifying traits are completely removed (anonymized) before data is analyzed outside OneHealth’s core systems. Access to identifiable data is restricted strictly to personnel for whom such information is operationally necessary.
  1. Approvals and General Consent
    • All OneHealth patients are required to sign a formal consent form in accordance with corporate operational policies (General Consent).
    • This General Consent is systematically obtained when the patient registers for their clinic visit, whether through physical front-desk registration, online web portals, or the official OneHealth Mobile Application.
  1. Direct Marketing and Commercial Communications
    • By utilizing OneHealth services, patients acknowledge that OneHealth may process standard personal data (such as names and contact channels) to communicate health awareness updates, announcement of new clinical services, or promotional offers.
    • In compliance with Article (17) of the Egyptian Data Protection Law, such marketing communications are restricted to pre-existing relationships or explicit opt-in scenarios.
    • Patients retain an absolute right to opt-out of receiving commercial communications at any time. Every promotional email or SMS will feature a clear, free-of-charge “Unsubscribe” mechanism. Alternatively, patients can easily opt-out by contacting the OneHealth Call Center directly at 15292. Upon exercising this right, OneHealth will cease processing data for marketing purposes within seven (7) business days.
  1. Data Breach Management and Notification
    • OneHealth maintains robust cybersecurity and technical frameworks to protect patient records against unauthorized access, exposure, or alteration.
    • In the unlikely event of a data breach compromising the confidentiality or integrity of personal or medical data, OneHealth will immediately initiate its corporate Incident Response Plan.
    • In compliance with statutory requirements, OneHealth is committed to notifying the Egyptian Data Protection Center (EDPC) within seventy-two (72) hours of discovering any data breach that poses a risk to data subjects’ rights.
    • If the breach constitutes a high risk to patient privacy or security, OneHealth will notify the affected individuals directly and without undue delay via their registered communication channels (email or SMS).
  1. Children’s Privacy and Guardianship
    • Due to the provision of pediatric and family healthcare services, OneHealth processes personal and clinical data of minors under the age of 18.
    • OneHealth strictly prohibits the collection or processing of a minor’s data without the explicit verification and consent of their legal guardian or parent.
    • Legal guardians retain the full legal capacity to exercise all data subject rights outlined in Section 9 on behalf of the minor under their custody.
  1. Automated Decision-Making and Profiling
    • OneHealth does not subject patients to decisions based solely on automated digital processing or profiling that produce legal or significantly adverse clinical effects.
    • Algorithmic tools, digital triaging systems, or automated health-tech platforms utilized by OneHealth are designed exclusively to assist clinical professionals, ensuring that final medical and administrative decisions always involve human intervention.
  1. Privacy Complaints and Contact Information
    • OneHealth takes privacy-related inquiries and complaints seriously. Patients who have concerns regarding how their data is handled must express their feedback in writing to the Customer Care department via email at: customerfeedback@one-health.com. OneHealth will investigate and address the issue promptly in accordance with internal compliance procedures.
    • For technical inquiries regarding data processing activities or to formally exercise statutory data rights under the Data Protection Law, data subjects or their legal representatives may directly contact the Data Protection Officer (DPO) via email at: Compliance@One-health.com.