Effective Date: 15 October 2025
Last Updated: 15 October 2025
Introduction
Dr. Nor Azhari Bin Mohd Zam (“Dr. Azhari Urology,” “we,” “us,” or “our”) is committed to protecting the privacy and confidentiality of your personal data. This Privacy Policy outlines how we collect, use, disclose, and protect your personal information in accordance with the Personal Data Protection Act 2012 (PDPA) of Singapore and relevant healthcare regulations. By using our services, visiting our clinic, or accessing our website at drazhariurology.com.sg, you acknowledge that you have read and understood this Privacy Policy.
1. Personal Data We Collect
In the course of providing urological healthcare services, we may collect the following categories of personal data:
Medical and Health Information
- Medical history and conditions
- Symptoms and diagnoses
- Treatment plans and procedures
- Medication records and prescriptions
- Laboratory and imaging results
- Surgical and procedural notes
- Vaccination records
- Allergies and adverse reactions
Personal Identification Information
- Full name and preferred name
- NRIC/FIN/Passport number
- Date of birth and age
- Gender
- Nationality and residency status
- Photograph (if required for identification)
Contact Information
- Residential address
- Mailing address
- Telephone numbers (mobile and home)
- Email address
- Emergency contact details
Financial and Insurance Information
- Insurance policy details
- Claim information
- Payment and billing records
- Credit/debit card information (processed securely through payment gateways)
- Corporate billing information (if applicable)
Employment and Referral Information
- Employer details (if relevant to billing)
- Referring physician information
- Occupation (if medically relevant)
Technical Information
- IP address
- Browser type and version
- Device information
- Website usage data and cookies
- Pages visited and time spent
2. How We Collect Personal Data
We may collect your personal data through various methods:
Direct Collection
- Registration forms and intake questionnaires
- Medical consultations and examinations
- Telephone conversations
- Email correspondence
- Appointment scheduling systems
- Patient feedback forms
Indirect Collection
- Referral letters from other healthcare providers
- National Electronic Health Record (NEHR) system
- Insurance companies and third-party administrators
- Laboratory and diagnostic imaging centers
- Pharmacies and medical suppliers
- Family members or legal representatives (with appropriate authorization)
Automated Collection
- Website cookies and analytics tools
- Appointment reminder systems
- Patient portal access logs
3. Purposes of Collection, Use, and Disclosure
We collect, use, and disclose your personal data for the following purposes:
Primary Healthcare Purposes
- Providing urological diagnosis, treatment, and care
- Conducting medical examinations and procedures
- Prescribing and managing medications
- Ordering and interpreting diagnostic tests
- Monitoring treatment progress and outcomes
- Managing follow-up care and appointments
- Maintaining accurate medical records
- Coordinating care with other healthcare providers
Administrative Purposes
- Patient registration and identification
- Appointment scheduling and reminders
- Billing and payment processing
- Insurance claims and verification
- Medical certificate issuance
- Managing patient inquiries and feedback
- Maintaining clinic operations
Legal and Regulatory Compliance
- Complying with Singapore Ministry of Health (MOH) requirements
- Meeting Singapore Medical Council (SMC) obligations
- Responding to legal proceedings and investigations
- Fulfilling statutory reporting requirements
- Maintaining professional indemnity records
Quality Improvement and Research
- Clinical audits and quality assurance (anonymized where possible)
- Medical research and studies (with appropriate consent)
- Training of medical professionals (with de-identification)
- Healthcare services improvement
Communication Purposes
- Sending appointment reminders via SMS, email, or phone
- Providing test results and medical updates
- Sharing health education materials
- Responding to patient inquiries
- Conducting patient satisfaction surveys
Emergency Situations
We may collect, use, or disclose your personal data without consent in emergency situations that threaten life, health, or public safety.
4. Disclosure of Personal Data
We may disclose your personal data to the following parties for the purposes stated above:
Healthcare Providers
- Referring physicians and specialists
- Allied health professionals (physiotherapists, dietitians, etc.)
- Hospitals and medical facilities
- Laboratory and diagnostic imaging centers
- Pharmacies
- National Electronic Health Record (NEHR) system participants
Administrative and Support Services
- Medical billing and coding services
- Insurance companies and third-party administrators
- Corporate clients (for employee health services)
- IT service providers and cloud storage services
- Medical equipment and supply vendors
- Professional advisors (legal, accounting, auditing)
Regulatory and Legal Authorities
- Singapore Ministry of Health (MOH)
- Singapore Medical Council (SMC)
- Personal Data Protection Commission (PDPC)
- Law enforcement agencies (when legally required)
- Courts and legal representatives
Third-Party Service Providers
- Appointment scheduling platforms
- Payment processors
- Email and SMS service providers
- Website hosting and analytics services
- Customer relationship management systems
We ensure that all third parties who receive your personal data are contractually obligated to protect your information and use it only for the specified purposes.
5. Consent
Obtaining Consent
We typically obtain your consent at the time of collecting your personal data through:
- Written consent forms
- Electronic acknowledgment (website, patient portal)
- Verbal consent (documented in medical records)
- Implied consent (for routine medical care)
Deemed Consent
In certain circumstances under the PDPA, your consent may be deemed when:
- The purpose of collection, use, or disclosure is reasonably expected
- You voluntarily provide the data for that purpose
- It is not reasonable to require express consent
Withdrawal of Consent
You may withdraw your consent for the collection, use, or disclosure of your personal data at any time by:
- Submitting a written request to our Data Protection Officer
- Sending an email to [email protected]
- Calling our clinic during operating hours
Please note that withdrawing consent may affect our ability to provide certain healthcare services to you. We will inform you of the likely consequences before processing your withdrawal request.
Exceptions to Consent
We may collect, use, or disclose your personal data without consent in the following situations:
- Emergency situations threatening life or health
- Legal or regulatory requirements
- Investigations or proceedings
- National or public interest
- Evaluative purposes (with appropriate safeguards)
6. National Electronic Health Record (NEHR)
As a participating healthcare provider in Singapore’s National Electronic Health Record (NEHR) system, we may contribute to and access your medical information through this secure platform.
Purpose of NEHR Participation
The NEHR system aims to facilitate:
- Continuity of care across different healthcare providers
- Reduction of duplicate tests and procedures
- Improved clinical decision-making
- Enhanced patient safety
Your NEHR Rights
You have the right to:
- Access your NEHR records
- Restrict certain healthcare providers from accessing your NEHR
- Opt out of NEHR participation entirely
To manage your NEHR preferences, please visit the HealthHub portal at www.healthhub.sg or contact the NEHR team directly.
7. Data Protection and Security
We implement appropriate technical, physical, and organizational measures to protect your personal data from unauthorized access, collection, use, disclosure, copying, modification, disposal, or similar risks.
Technical Safeguards
- Encrypted data transmission (SSL/TLS)
- Secure password-protected systems
- Regular security updates and patches
- Firewall and anti-virus protection
- Access controls and authentication mechanisms
- Secure cloud storage with reputable providers
- Regular data backups
Physical Safeguards
- Restricted access to physical records storage areas
- Locked filing cabinets and secure storage rooms
- Visitor access controls and monitoring
- Secure disposal of physical documents (shredding)
- CCTV surveillance in appropriate areas
Organizational Safeguards
- Staff training on data protection and confidentiality
- Clear data handling policies and procedures
- Confidentiality agreements with employees and contractors
- Role-based access controls (need-to-know basis)
- Regular audits and compliance reviews
- Incident response and breach notification procedures
Limitation of Security
While we implement reasonable security measures, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your personal data.
8. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations.
Retention Periods
- Medical Records: Minimum of 6 years from the last consultation or as required by the Singapore Medical Council
- Financial Records: 5 years from the last transaction or as required by tax regulations
- Marketing Communications: Until you withdraw consent or unsubscribe
- Website Analytics: Typically 26 months or as configured
Disposal
When personal data is no longer required, we will:
- Securely delete electronic records
- Shred or incinerate physical documents
- De-identify data used for statistical or research purposes
- Ensure third-party service providers properly dispose of data
9. Access and Correction Rights
You have the right to:
- Request access to your personal data held by us
- Request correction of inaccurate or incomplete personal data
- Receive a copy of your medical records
How to Make a Request
To exercise your access or correction rights:
- Submit a written request to our Data Protection Officer
- Provide sufficient information to verify your identity
- Specify the personal data you wish to access or correct
Processing Your Request
- We will respond to your request within 30 days
- A reasonable fee may be charged for access requests to cover administrative costs
- We may refuse requests in certain circumstances permitted by law (e.g., legal privilege, threat to safety)
- We will provide written reasons for any refusal
Medical Records Access
You may obtain copies of your medical records by:
- Submitting a formal request at our clinic
- Providing valid identification
- Paying the applicable administrative fee
10. Transfer of Personal Data Outside Singapore
In certain circumstances, we may transfer your personal data outside Singapore to:
- International specialists for second opinions
- Overseas medical facilities for continued care
- Cloud service providers with servers located abroad
- International medical research collaborators
When transferring personal data overseas, we will:
- Ensure the recipient country has comparable data protection laws, or
- Obtain your consent for the transfer, or
- Enter into contractual agreements to protect your data
11. Cookies and Website Analytics
Our website uses cookies and similar technologies to enhance user experience and analyze website performance.
Types of Cookies Used
- Essential Cookies: Required for website functionality
- Analytics Cookies: Google Analytics and similar tools to understand visitor behavior
- Functional Cookies: Remember your preferences and settings
- Marketing Cookies: May be used for targeted advertising (with consent)
Managing Cookies
You may disable cookies through your browser settings. However, this may affect certain website functionalities. For more information, please refer to our separate Cookie Policy.
12. Marketing and Communications
We may send you marketing communications about our services, health tips, and educational materials if you have:
- Provided consent, or
- Been our patient and the communication relates to similar services
Opting Out
You may opt out of marketing communications at any time by:
- Clicking the “unsubscribe” link in emails
- Replying “STOP” to SMS messages
- Contacting our clinic directly
- Updating your preferences in the patient portal
Opting out of marketing communications will not affect:
- Essential service-related communications (appointment reminders, test results)
- Legal or regulatory notifications
- Billing and payment communications
13. Children and Minors
We recognize the need for additional protection when handling personal data of children and minors (individuals below 21 years of age in Singapore). When treating minors, we:
- Obtain consent from parents or legal guardians where required
- Balance the minor’s autonomy with parental involvement
- Respect medical confidentiality in age-appropriate situations
- Comply with relevant laws regarding minors’ medical care
14. Third-Party Websites
Our website may contain links to third-party websites for your convenience. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal data.
15. Data Breach Notification
In the event of a data breach that is likely to result in significant harm or impact to you, we will:
- Notify the Personal Data Protection Commission (PDPC) as required by law
- Notify affected individuals without undue delay
- Provide information about the breach and steps taken to address it
- Recommend actions you can take to protect yourself
16. Your Responsibilities
To help protect your personal data:
- Keep your passwords and login credentials confidential
- Update your contact information promptly
- Review your medical records for accuracy
- Report any suspected unauthorized access to your data
- Be cautious when sharing personal information online
- Verify the identity of individuals requesting your information
17. Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect:
- Changes in our practices
- Legal or regulatory requirements
- Technological developments
- Feedback from patients and stakeholders
We will:
- Post the updated Privacy Policy on our website
- Indicate the effective date of changes
- Notify you of significant changes through appropriate means
Your continued use of our services after changes indicates acceptance of the updated Privacy Policy.
18. Contact Information
If you have questions, concerns, or complaints about this Privacy Policy or our data protection practices, please contact: Data Protection Officer Dr. Azhari Urology Mount Alvernia Hospital 820 Thomson Road Medical Centre Block A #05-03 Singapore 574623 Email: [email protected] Phone: +65 6252 4015
Complaints
If you believe your personal data has been mishandled, you may:
- Contact our Data Protection Officer to file a complaint
- Lodge a complaint with the Personal Data Protection Commission (PDPC) at:
- Website: www.pdpc.gov.sg
- Email: [email protected]
- Phone: 1800-275-7332
19. Governing Law
This Privacy Policy is governed by the laws of the Republic of Singapore, including:
- Personal Data Protection Act 2012 (PDPA)
- Healthcare Services Act
- Singapore Medical Council Ethical Code and Ethical Guidelines
- Other relevant healthcare regulations
20. Language
This Privacy Policy is prepared in English. In the event of any inconsistency between the English version and any translation, the English version shall prevail.
Acknowledgment
By providing your personal data to Dr. Azhari Urology, you acknowledge that:
- You have read and understood this Privacy Policy
- You consent to the collection, use, and disclosure of your personal data as described
- You understand your rights regarding your personal data
- You may withdraw consent subject to legal and contractual restrictions
Dr. Nor Azhari Bin Mohd Zam MBBS (NUS) | MRCS (Edin.) | MMed Surgery (NUS) | FAMS (Urology)
Committed to excellence in urological care and patient privacy protection.
