Privacy Policy
'St. Peter's Hospital' (hereinafter 'the Company') values your personal information and complies with the Act on Promotion of Information and Communications Network Utilization and Information Protection.
Through this Privacy Policy, the company informs customers of the purposes and manner in which the personal information they provide is used, and of the measures taken to protect that personal information. If the company revises this Privacy Policy, it will announce the revision through notices on the website (or by individual notice).
The Privacy Policy is organized as follows.
2. Purpose of collecting and using personal information
3. Retention and use period of personal information
4. Destruction procedures and methods
5. Provision and sharing of personal information
6. Rights of users and legal representatives and how to exercise them
7. Withdrawal of consent / membership cancellation
8. Installation/operation of devices that automatically collect personal information, and refusal thereof
9. Operation/management of video information processing devices
10. Measures to ensure the security of personal information
11. Personal Information Manager
12. Duty to give notice of policy changes
13. Consignment of personal information processing
Key personal information processing details
1. Personal information collected and methods of collection
The hospital collects only the minimum personal information necessary to use the service at sign-up.
To use our services, sign-up includes required fields and optional fields; optional fields such as whether to receive email may be left blank without any restriction on your use of the services.
[Items collected at the time of treatment]
• Required items: hospital registration number, name (in Korean), resident registration number, address, contact (phone number, mobile number)
• Health information: personal health information such as medical and family history that the medical team deems necessary to provide care
※ Unique identifying information and medical records must be retained under the Medical Service Act (no separate consent required)
[Items collected when paying medical fees]
• For credit card payment: card company name, card number and other payment approval information
[Items collected at website sign-up]
• Required items : ID, password, name, mobile number
• Optional items : email, email subscription
2. Purpose of collecting and using personal information
The hospital uses the personal information it collects for the following purposes.
All information you provide is used only for the purposes stated below, and your prior consent will be obtained if the purpose of use changes.
• Used for booking and checking appointments for care, tests and screenings, and for identity verification
• Used to provide test results and personalized text message and email information
• Securing communication channels for handling customer complaints and grievances
• Providing information on new services and events
• Providing administrative services such as billing, payment and refunds
• Minimum analytical data required for education/research
• Collection of consumer hazard information under Article 52 of the Framework Act on Consumers
3. Retention and use period of personal information
The hospital destroys your personal information without delay once the purpose of its collection or receipt has been achieved.
[Medical information]
• Retention period : medical records 10 years (extendable if necessary)
※ The retention period is counted from 10 years after the last entry in the medical record
[Website member information]
• When membership is cancelled or a member is expelled, or when one year has passed since the last login (Article 29 of the Act on Promotion of Information and Communications Network Utilization and Information Protection, and Article 16 of its Enforcement Decree)
• Records of consumer complaints or dispute resolution: 3 years (Act on Consumer Protection in Electronic Commerce)
• Records of the collection/processing and use of credit information: 3 years (Use and Protection of Credit Information Act)
• Records of identity verification: 6 months (Act on Promotion of Information and Communications Network Utilization and Information Protection)
• Visit records : 3 months (Protection of Communications Secrets Act)
※ However, even where the purpose of collection or of the provision has been achieved, we may retain your personal information where retention is required under the Commercial Act or other statutes.
4. Destruction procedures and methods
The hospital destroys personal information immediately once the 『Purpose of collection and use of personal information』 has been achieved. The destruction procedure and method are as follows.
[Destruction procedure]
• Information you entered to sign up is moved to a separate database (or a separate file cabinet for paper records) once its purpose has been achieved
• Under internal policy and other applicable laws (see retention and use period), data is stored for a set period and then destroyed.
• Personal information moved to a separate database is not used for any purpose other than its retention, except as required by law.
[Disposal method ]
• Personal information stored as electronic files is deleted using technical methods that make the records unrecoverable.
• Personal information printed on paper is destroyed by shredding or incineration.
5. Provision and sharing of personal information
Except with your consent or as provided by relevant statutes, we will under no circumstances use your personal information beyond the scope notified in 『Purposes of Collection and Use of Personal Information』, or provide it to any other person, company or organization.
• Submission of medical records to claim medical benefit costs from HIRA under the National Health Insurance Act
• Where necessary for statistics or academic research, provided in a form in which no individual can be identified
• Submission upon request from investigative authorities in accordance with statutory procedures and methods
6. Rights of users and legal representatives and how to exercise them
• Sign-up by children under the age of 14 ("children") is carried out through a separate form written in plain language that children can easily understand, and we always obtain the consent of a legal guardian when collecting personal information.
• To obtain the consent of a legal guardian, we collect the minimum information from the child, such as the guardian's name and contact details, and obtain the guardian's consent in the manner set out in this Privacy Policy.
• Users and legal guardians may exercise their rights by contacting the hospital in relation to personal information via the internet, by telephone or in writing, and the hospital will take the necessary measures without delay.
※ Personal information whose retention is required by law cannot be corrected or deleted during the retention period, even upon request.
7. Withdrawal of consent/membership cancellation
• You may withdraw at any time the consent you gave at sign-up to the collection, use and provision of your personal information. To cancel your membership, click 『Cancel Membership』 in My Page on the hospital website and complete identity verification, or contact the Personal Information Manager in writing, by telephone or by fax; we will then take the necessary measures without delay, including destroying your personal information.
8. Installation/operation of devices that automatically collect personal information, and refusal thereof
• The hospital operates ‘cookies’ and similar technologies that store and retrieve your information from time to time. A cookie is a very small text file sent to your browser by the server that runs the hospital's website, and it is stored on your computer's hard disk. The hospital uses cookies for the following purposes.
[Purpose of using cookies]
• Target marketing and personalized services based on analysis of access frequency and visit times of members and non-members, identification and tracking of user tastes and interests, and assessment of participation in various events and number of visits
• You have the right to choose whether cookies are installed. By setting options in your web browser, you may allow all cookies, be prompted each time a cookie is stored, or refuse the storage of all cookies.
[How to refuse cookies]
• To refuse cookie settings, you may select options in the web browser you use to allow all cookies, be prompted each time a cookie is stored, or refuse the storage of all cookies.
[How to configure]
• Example (Internet Explorer): Tools menu at the top of the web browser > Internet
• However, if you refuse to allow cookies, some services may be difficult to provide.
9. Operation/management of video information processing devices
The hospital operates and manages video information processing devices as follows.
[Grounds and purpose of installation]
Patient and facility safety, fire and crime prevention
[Number of cameras, locations and coverage]
Number installed: 116 in total Locations and coverage: parking lot, lobby, corridors, etc.
[Manager in charge]
Manager in charge: Head of Management Administration
[Recording hours, retention period and processing of video information]
Recording hours : 24 hours a day
Retention period : within 30 days from the recording date
Handling method: Matters concerning use of personal video information for purposes other than intended, provision to third parties, destruction and requests for access are recorded and managed, and upon expiry of the retention period the information is permanently deleted in a manner that makes recovery impossible (printed materials are shredded or incinerated).
[Measures for data subjects' requests to view video information]
If you wish to view your personal video information or confirm its existence, you may request this from the operator of the video information processing devices at any time. Such requests are limited, however, to personal video information in which you appear and personal video information clearly necessary for the urgent life, bodily or property interests of the data subject. Notwithstanding a data subject’s request to view such information, the request may be refused in the following cases.
- When personal video information is destroyed after its retention period expires
- Where other justifiable grounds exist to refuse the data subject's request for access or similar
[Technical, administrative and physical measures to protect video information]
The video information processed by our hospital is managed securely through measures such as encryption. As an administrative safeguard for the protection of personal video information, the hospital grants differentiated levels of access to personal information, and to prevent the forgery or alteration of personal video information it records and manages the date and time each recording was created as well as the purpose of viewing, the viewer, and the date and time of viewing. In addition, locking devices are installed for the safe physical storage of personal video information.
10. Measures to ensure the security of personal information
To ensure the security of our customers' personal information against loss, theft, leakage, alteration or damage, we take the following technical and administrative measures.
[Minimizing and training staff who handle personal information]
We keep the number of designated personal information handlers to a minimum and provide regular training.
[Regular self-inspections]
We carry out self-inspections at least once a year to ensure the safety of personal information handling.
[Encryption of personal information]
Among users' personal information, passwords are stored and managed in encrypted form so that only the individual knows them, and separate security functions such as encryption of files and transmitted data are used for important data.
[Technical measures against hacking]
To prevent leakage or damage of personal information by hacking, computer viruses and the like, we install security programs and update and inspect them periodically, and we install our systems in areas with controlled external access, monitoring and blocking them technically and physically.
[Restricting access to personal information]
We take the measures necessary to control access to personal information by granting, changing and revoking access rights to the database systems that process personal information, and we control unauthorized external access using an intrusion prevention system.
[Access control for unauthorized persons]
The personal information system holding personal data is kept in a separate physical location, with access control procedures established and operated.
11. Personal Information Manager
• To protect your personal information and handle related complaints, the hospital has appointed a Personal Information Manager as follows.
• Manager in charge : Yoon, Min Ha
• Position : Administrative Director
• Affiliation : St. Peter's Hospital
• Phone : 02-6200-3529
• You may report to our Personal Information Manager any complaint relating to the protection of personal information that arises while using our services. We will respond promptly and fully to matters you report. If you need to report or consult on any other infringement of personal information, please contact the organizations below.
■ Personal Information Dispute Mediation Committee (www.1336.or.kr/1366)
■ ePRIVACY Mark Certification Committee (www.eprivacy.or.kr/02-580-0533~4)
■ Supreme Prosecutors' Office Internet Crime Investigation Center (http://icic.sppo.go.kr/02-3480-3600)
■ National Police Agency Cyber Terror Response Center (www.ctrc.go.kr/02-392-0330)
12. Duty to give notice of policy changes
This Privacy Policy was established on September 30, 2011. If content is added, deleted or amended due to changes in statutes, policy or security technology, we will announce the reasons for and details of the change on the hospital website at least 7 days before the revised Privacy Policy takes effect.
13. Consignment of personal information processing
The hospital's outsourced personal information processors and the entrusted work are as follows.
| Consignee | Details of entrusted work | Entrusted personal information | Retention period of personal information | |
|---|---|---|---|---|
| M System Tech | Medical information system management | Patient personal information, medical information | Consignment contract Until termination |
|
| INFINITT Healthcare | Imaging system operation and maintenance | Medical imaging data | ||
| Daou Tech | KakaoTalk / SMS delivery | Phone number | ||
| Wise Body | Website maintenance | Name, date of birth, gender, phone number, address, email | ||
| Saerom Soft | NHIS Health Screening | Name, resident registration number, phone number, address, email | ||
| Samkwang Medical Foundation | Pathology (clinical pathology) test referral | Name, date of birth | ||
| Ewha (sub-consignment) | Pathology (clinical pathology) test referral | Name, date of birth | ||
| BIT Computer | Medication guidance | Name, gender, age, medication | ||
| NASCA Lab | Call center operations | Name, resident registration number, phone number, address | ||
| Human Radiology Clinic | External image reading | Medical imaging data (MRI) | ||
| M2Tech | Server maintenance | Server maintenance | ||
| Blue Shell | Kiosk maintenance | Patient personal information, payment card information | ||
| Tobicon | Mobile Document Issuance | Patient personal information, medical information | ||
| Dongsim Computer | Employee digital certificate issuance service | Name, resident registration number, ID, name of person in charge, their email and phone number | ||
| E-UN | Employee groupware / internal messenger system management | Date of birth, phone number, address, bulletin board content and messenger conversations | ||
Notice date : December 14, 2023
Effective date : December 14, 2023


-Appointment: name, gender, date of birth, phone number, etc.
-Appointments: issuing a hospital registration number for medical and health screening bookings
-Consignee: St. Peter's Hospital