Privacy statement
We have written this privacy statement for respondents/patients who participate in the research we conduct. The privacy statement also tells care service providers what we do with patient/respondent data.
Mediquest attaches great importance to transparency in care services. In this privacy statement, we provide respondents with information about the points given below, as well as background information to further explain our privacy policy.
Who are we?
General
Our mission is to make healthcare more transparent so that the quality and affordability of the care can be improved. One of the ways we do that is by providing patients, clients, care service providers and health insurers with the information they need to make better-informed choices. To enable us to do so, we collect, process and report a large amount of personal data relating to respondents (patients) and care service providers.
Our role
We support care service providers by conducting research on their behalf. Our role is implementation/processing for the care service providers. They are responsible for providing us with personal details of the respondents, and we collect the information supplied by the respondent.
We collect personal data at different levels:
◾ Client level. These are Mediquest clients such as care service providers, health insurers and patient associations.
◾ Respondent level. These are respondents (patients and care service users) who participate in research studies and measurements at the request of a client.
What is personal data?
Personal data is information about an individual, or data that would identify that person. As a respondent, you share personal data with Mediquest if you participate in a patient satisfaction survey. You then give us personal information which includes your contact details, such as name, address, telephone number and e-mail address, plus any other information linked to you as an individual, such as age, gender and details relating to treatment, as well as the answers you give to the questionnaire.
What do we do with business data?
Business data, such as names of specialists working in hospitals, is not necessarily personal data, as this information does not refer to an individual’s position within the organisation. A central telephone number is not personal data, nor is a work e-mail address. In Mediquest’s opinion, this kind of information, which is often publicly accessible, relates to the contact details linked to a position/role within an organisation and the GDPR (general data protection regulation) does not apply here.
What is our approach to data security?
Data collection, processing and management make up the mainstay of our work. That’s why we are committed to protecting all personal and other data during our work, and to conducting our activities in compliance with relevant legislation and regulations. And it’s why we have set up quality management and data security practices at all levels within our organisation.
We believe that we should work together to safeguard the quality and security of our information. In order to learn and improve, we should always be critical of ourselves and our procedures. That’s why we have created an open and safe culture in which all Mediquest employees, whatever their position, can report an incident, deviation or point for improvement (the so-called warning signs).
Mediquest has a data security manager, data protection official and quality managers who are responsible for data security policy and implementation. We are required to comply with a number of data security standards relating to the healthcare sector (ISO27001 and NEN7510) and quality management (ISO9001). An independent external auditor supports us in our compliance with these standards and with legislation and regulation.
What do we do with your personal information?
What can you expect from us?
What are your personal data rights?
As a respondent you have the following rights:
- access: the right to see your processed personal data
- to be informed: the right to transparency and information about how your personal data is processed
- to be forgotten: the right to have your data deleted
- rectification: the right to have processed personal data corrected
- restrict processing: the right to have less data processed
- data portability: the right to transfer your personal data
When we collect and process data on behalf of a care service provider, you can make a request to the care service provider (data controller) for any of the above. They can identify you and will pass on the request to us on your behalf, so we can respond to your request.
We keep your data secure
We treat your data with the utmost care. Attaching importance to the protection of personal data means ensuring that our systems are set up in such a way that we can do this securely and reliably. Part of this security is regular data security testing plus the encryption of systems, communication and data. We also ensure the security of your personal data with certification, audits, risk analyses and privacy impact assessments (PIA) for high-risk projects.
Apart from ISO 9001:2015 certification, we also thought it important to achieve certification to meet both the international ISO 27001 and the Dutch NEN 7510 standards for data security (in healthcare). These certificates are annually reviewed by an independent external auditor, with a specific focus on personal data security. A comprehensive risk assessment is part of this certification. That includes measures to ensure the reliability, integrity and security needed for processing and supplying personal data. Since May 2018, we also do a PIA for privacy risk-sensitive projects.
We comply with current legislation and regulations as well as relevant standards
We work in compliance with current legislation and regulations relating to personal data processing. All our work is done in accordance with the General Data Protection Regulation (GDPR), as well as National Health Care Institute quality guidelines. We also have additional certification (international and Dutch standards: ISO 27001 and NEN 7510) relating to data security.
We process data in accordance with current legislation and regulations. This means that our client owns the data. So we never supply third parties with data without explicit consent from the data controller. It is the responsibility of the data controller to obtain your consent in the appropriate way.
Cookies and tracking
Mediquest uses functional and analytical cookies to enable its website(s) to perform well. Cookies are small pieces of information that your browser stores on your computer.
Functional cookies
The purpose of functional cookies is to enable the site to function properly. No personal data is processed for this purpose.
Analytical cookies
The purpose of analytical cookies is to improve the website. These cookies tell us how the site is used. The data we collect with these cookies is combined and used for statistical analysis. We do that with Google Analytics.
Regarding the use of Google Analytics, we have agreements with Google to protect your personal data:
- we have not given Google permission to use the data obtained for any other Google services
- we have a processing agreement with Google
- the last numbers of your IP address are masked
- unless mentioned otherwise below, we do not use Google Analytics in combination with other Google services
For this website (home.mediquest.nl) we use Google Ads as well as Google Analytics.
IP logging
When you visit our website (or use one of our services), your web browser automatically sends connection data (IP address) so that we can show you our website page. We only store this IP address if that is necessary for our system to function properly. The data that we store to compile visitor statistics is anonymised.
E-mail
We send out large e-mailings using address like noreply@mediquestmail.nl. This address has built-in options for us to (possibly) receive automatic confirmation that you have opened the e-mail. We cannot remove these options. E-mail from <name>@mediquest.nl does not enable tracking, unless our employees explicitly ask for e-mail receipt confirmation.
Questions and feedback
After reading this privacy statement, you may have questions or remarks about how we process data. We are happy to answer them. Please get in touch with us via:
Mediquest B.V.
Burgemeester Reigerstraat 89
3581 KP Utrecht
The Netherlands
+ 31 (0)88 – 126 39 00
info@mediquest.nl
Data Protection Officer
All organisations involved in large-scale processing of sensitive personal data are required to appoint a data protection officer. The data protection officer ensures compliance with the GDPR.
If you have any questions or remarks about the use of your personal data, please get in touch with our Data Protection Officer, Mr J. Homberg, via fg@mediquest.nl.
What do we do with your personal information?
What is my personal data used for?
The data we process is only used for the purposes that the care service provider discussed with you beforehand.
We also collect (publicly accessible) information on healthcare professionals, including job title and specialisation, and maintain these lists for our clients for use on healthcare websites. These lists contain no other personal data.
Satisfaction surveys
We process data from different kinds of patient satisfaction surveys, i.e.:
- Patient Reported Experience Measure (PREM) is used to measure the quality of care provided.
- Consumer Quality Index (CQI) is a standardised questionnaire to measure patient experiences of healthcare.
- Continuous Patient Satisfaction Survey (Continuous PSS) is used to do continuous research on patient satisfaction.
Patient satisfaction surveys use your personal data to gain better insight into the quality of the care given. We can then provide patients, care service providers, health insurers and people who refer patients with benchmark data based on anonymised data. That information enables them to make better choices and to improve the care given. Anonymised data cannot be used to identify individuals.
The open-ended responses you provide in the patient experience survey (such as compliments or suggestions for improvement) may be analyzed using an automated tool that applies artificial intelligence (AI). This tool assigns predefined categories to your answers, such as communication or information provision.
The purpose of this analysis is to provide healthcare providers with better insight into patient experiences. Your data will not be used to further train the AI model. Processing takes place within a secure environment (within the EU), and your privacy is safeguarded. Only your open-ended responses are used for this purpose.
Outcome measurements
Besides patient satisfaction surveys, we also measure the outcome of care with Patient Reported Outcome Measurements (PROMs). PROM measurements are not initially anonymised, as the results are added to your medical record and you can discuss the outcome with your doctor during a consultation. For PROM measurements, your personal data is anonymised at a later date, as it can then be included in benchmarks and reporting.
Who receives my personal data?
Your personal information is only used for the research itself and not for any other purpose. Participation in surveys is completely voluntary and has no effect on the care you are given, nor on your health insurance premiums and cover. Your healthcare provider will not know whether or not you have completed the questionnaire for a patient satisfaction survey (PREM, CQI, CPSS). Nor can your healthcare provider find out which answers you have given.
The invitation to take part in a PROM measurement made it clear that your participation is not anonymous. That means the healthcare professional treating you can see the outcome. The answers you give are immediately passed on as feedback. This is done for good reason, providing an opportunity for you to discuss the outcome with the person treating you during a consultation. Together you can assess whether the treatment is going as planned and desired.
Guidelines and working in partnership
We only share your information when that is necessary, and only with our partners who are certified to handle sensitive information. According to the certification standards, for example, we may only store personal data in the Netherlands, and we are obliged to evaluate our partnerships with suppliers on a regular basis. We also expect our suppliers to comply with the same guidelines and regulations relating to personal data processing, and they sign additional agreements with us to do this.
How long is my data stored?
We keep your personal data for an agreed retention period. This depends on the type of research. If we measure, process and analyse personal data for research conducted on behalf of clients, this data is immediately deleted when it is no longer required for further research and reporting. The research data is then anonymised. The anonymous data is stored for a period of five years.
What can you expect from us?
What are your personal data rights?
As a respondent you have the following rights:
- access: the right to see your processed personal data
- to be informed: the right to transparency and information about how your personal data is processed
- to be forgotten: the right to have your data deleted
- rectification: the right to have processed personal data corrected
- restrict processing: the right to have less data processed
- data portability: the right to transfer your personal data
When we collect and process data on behalf of a care service provider, you can make a request to the care service provider (data controller) for any of the above. They can identify you and will pass on the request to us on your behalf, so we can respond to your request.
We keep your data secure
We treat your data with the utmost care. Attaching importance to the protection of personal data means ensuring that our systems are set up in such a way that we can do this securely and reliably. Part of this security is regular data security testing plus the encryption of systems, communication and data. We also ensure the security of your personal data with certification, audits, risk analyses and privacy impact assessments (PIA) for high-risk projects.
Apart from ISO 9001:2015 certification, we also thought it important to achieve certification to meet both the international ISO 27001 and the Dutch NEN 7510 standards for data security (in healthcare). These certificates are annually reviewed by an independent external auditor, with a specific focus on personal data security. A comprehensive risk assessment is part of this certification. That includes measures to ensure the reliability, integrity and security needed for processing and supplying personal data. Since May 2018, we also do a PIA for privacy risk-sensitive projects.
We comply with current legislation and regulations as well as relevant standards
We work in compliance with current legislation and regulations relating to personal data processing. All our work is done in accordance with the General Data Protection Regulation (GDPR), as well as National Health Care Institute quality guidelines. We also have additional certification (international and Dutch standards: ISO 27001 and NEN 7510) relating to data security.
We process data in accordance with current legislation and regulations. This means that our client owns the data. So we never supply third parties with data without explicit consent from the data controller. It is the responsibility of the data controller to obtain your consent in the appropriate way.
Cookies and tracking
Mediquest uses functional and analytical cookies to enable its website(s) to perform well. Cookies are small pieces of information that your browser stores on your computer.
Functional cookies
The purpose of functional cookies is to enable the site to function properly. No personal data is processed for this purpose.
Analytical cookies
The purpose of analytical cookies is to improve the website. These cookies tell us how the site is used. The data we collect with these cookies is combined and used for statistical analysis. We do that with Google Analytics.
Regarding the use of Google Analytics, we have agreements with Google to protect your personal data:
- we have not given Google permission to use the data obtained for any other Google services
- we have a processing agreement with Google
- the last numbers of your IP address are masked
- unless mentioned otherwise below, we do not use Google Analytics in combination with other Google services
For this website (home.mediquest.nl) we use Google Ads as well as Google Analytics.
IP logging
When you visit our website (or use one of our services), your web browser automatically sends connection data (IP address) so that we can show you our website page. We only store this IP address if that is necessary for our system to function properly. The data that we store to compile visitor statistics is anonymised.
E-mail
We send out large e-mailings using address like noreply@mediquestmail.nl. This address has built-in options for us to (possibly) receive automatic confirmation that you have opened the e-mail. We cannot remove these options. E-mail from <name>@mediquest.nl does not enable tracking, unless our employees explicitly ask for e-mail receipt confirmation.
Questions and feedback
After reading this privacy statement, you may have questions or remarks about how we process data. We are happy to answer them. Please get in touch with us via:
Mediquest B.V.
Burgemeester Reigerstraat 89
3581 KP Utrecht
The Netherlands
+ 31 (0)88 – 126 39 00
info@mediquest.nl
Data Protection Officer
All organisations involved in large-scale processing of sensitive personal data are required to appoint a data protection officer. The data protection officer ensures compliance with the GDPR.
If you have any questions or remarks about the use of your personal data, please get in touch with our Data Protection Officer, Mr J. Homberg, via fg@mediquest.nl.