RAPHA RADIOLOGY PTE LTD — PATIENT PRIVACY POLICY
At Rapha Radiology, our priority is the health of our patients. We endeavour to deliver our service meeting the profession’s ethical standards of quality, confidentiality, and privacy. To deserve your trust and confidence, we protect your privacy while providing you with the best possible service and experience.
This Patient Privacy Statement sets out the Privacy Policy for Rapha Radiology Pte Ltd, its branches, and associated companies (“Centre”, “we”, “us”, or “our”) with regard to the collection, use, and disclosure of your personal data. All personal information in our possession is collected, used, processed, disclosed, and protected in accordance with the Singapore Personal Data Protection Act 2012 (“PDPA”) and applicable healthcare regulations.
1. Personal Data Collected
To deliver our medical and radiological services, data we may collect or record from you includes:
a. Personal Identification & Contact Details
- Full name, gender, date of birth, nationality, and marital status
- Contact information, including mailing address, email address, and telephone numbers
- National Identification numbers (NRIC, FIN, Passport number)
(Note: Full national identification numbers are collected and processed strictly where required by law under healthcare legislation, such as Ministry of Health guidelines, or where necessary to establish your identity to a high degree of fidelity for patient safety and medical record accuracy.)
- Photographs, video footage, and audio-visual recordings (e.g., CCTV security recordings)
- Employment and financial information (e.g., credit/debit card or bank account details for billing and processing)
b. Personal Health Information
- Current medication, medical treatments, and clinical history (including family medical history where relevant)
- Referral information, including details of any referring healthcare service provider or medical specialist
- Radiological scans, diagnostic images, and clinical reports
c. Transactional & Interaction Details
- Details of medical and diagnostic services provided to you
- Communication logs, including telephone records, email exchanges, and online portal interactions
2. Collection, Use, and Disclosure of Personal Data
a. Principles of Collection
We generally do not collect your personal data unless:
-
It is voluntarily provided by you directly or via an authorised representative (e.g., referring physician, family member) after you or your representative have been notified of the purposes for collection; or
-
Collection and processing without consent is permitted or required under the PDPA or other laws. We will seek your express consent before collecting additional data or using existing data for new purposes.
b. Purposes of Collection, Use, and Disclosure
We may collect, use, and disclose your personal data for the following purposes:
- Performing healthcare and radiological services requested by you or your referring doctor
- Verifying your identity accurately to ensure patient safety and correct clinical record-matching
- Responding to, handling, and processing queries, requests, applications, complaints, and feedback
- Managing your relationship with us
- Processing billing, payment, insurance, or credit transactions
- Sending updates, newsletters, or information regarding our new developments and medical services (you may opt out of receiving marketing communications at any time)
- Complying with applicable laws, regulations, healthcare codes of practice, or assisting in government investigations
- Transmitting to relevant third parties, including healthcare service providers, agents, external specialists, and regulatory authorities (in Singapore or abroad) as required to deliver comprehensive medical care
3. Withdrawing Your Consent
-
The consent you provide for the collection, use, and disclosure of your personal data remains valid until withdrawn in writing. You may withdraw consent at any time by contacting our Data Protection Officer (DPO) at the contact details below.
-
Upon receiving your written request, we will process it within 10 business days and inform you of any consequences of the withdrawal, including legal or medical implications (such as our inability to continue providing medical services).
-
Withdrawing consent does not affect our statutory right or obligation to continue collecting, using, or disclosing personal data where permitted or required without consent under applicable laws.
4. Access to and Correction of Personal Data
-
Access Requests: You may submit a written request to access a copy of your personal data held by us, or information regarding how it has been used or disclosed.
-
Correction Requests: You may submit a written request to correct or update any of your personal data.
-
Fees & Timelines: A reasonable fee may be charged for access requests to cover administrative costs, which will be communicated to you prior to processing. We will respond to access or correction requests within 30 calendar days. If we cannot respond within 30 days, we will inform you in writing of the revised timeline.
5. Protection and Security of Personal Data
-
To safeguard your personal data from unauthorised access, collection, use, disclosure, copying, modification, or disposal, we implement robust administrative, physical, and technical measures. These include technical firewalls, encryption, access controls, up-to-date antivirus software, and privacy safeguards.
-
Full or partial NRIC/FIN numbers will not be used as unencrypted user credentials or publicly accessible identifiers.
-
Data access within the organisation and to authorised third-party providers is restricted strictly on a need-to-know basis.
6. Data Breach Notification
In the event of a security incident affecting personal data, we will assess the breach promptly. Where required under the PDPA, we will notify the Personal Data Protection Commission (PDPC) and affected individuals within the timelines prescribed by law.
7. Accuracy and Retention of Personal Data
-
Accuracy: We rely on personal data provided by you (or your authorised representative). Please notify our DPO promptly in writing if there are any changes to your personal details to ensure our records remain accurate and complete.
-
Retention: In accordance with Singapore medical guidelines and legal standards, patient medical records are retained for a minimum period of lifetime + 6 years. Personal data will cease to be retained, or will be anonymised, as soon as retention is no longer required for medical, legal, or business purposes.
8. Data Protection Officer (DPO)
If you have any enquiries, feedback, or requests regarding our personal data protection policies and practices, please contact our DPO:
Data Protection Officer
Rapha Radiology Pte Ltd
320 Serangoon Road, #11-02
Centrium Square, Singapore 218108
Email: dpo@rapharad.asia
9. Effect of Policy and Updates
-
This Notice applies alongside any other notices, contractual clauses, or consent forms governing the collection, use, and disclosure of your personal data.
-
We may revise this Privacy Policy periodically to reflect changes in legal, regulatory, or operational requirements. Material changes will be published on our platform, and where required by law, we will seek your updated consent.
Effective Date: 1 July 2021
Last Updated: 14 September 2026