Privacy Policy
<Hanaro Medical Foundation> respects the freedom and rights of individuals and complies with the Personal Information Protection Act and other relevant laws and regulations. We lawfully process personal information and manage it safely.
In accordance with Article 30 of the Personal Information Protection Act, this Privacy Policy explains the procedures and standards for processing personal information, and aims to ensure that any grievances related to personal information are handled promptly and smoothly.
Purpose of Processing Personal Information
<Hanaro Medical Foundation> processes personal information for the following purposes.
The personal information we collect will not be used for any purpose other than those specified below.
If the purpose of use is changed, we will take necessary measures such as obtaining separate consent from the individual in accordance with Article 18 of the Personal Information Protection Act.
1. We process personal information when it is required by law or is unavoidable for compliance with legal obligations.
This includes verifying membership intent, identifying and authenticating users for member-based services, maintaining and managing membership status, verifying identity under the limited identification system, preventing fraudulent use of services, confirming the consent of legal guardians when processing the personal information of children under the age of 14, and providing various notices and communications.
| Related Law |
Purpose of Processing |
| Medical Service Act and its Enforcement Regulations |
Preparation of various records such as medical application forms, medical records, nursing records, patient lists, and prescriptions; provision and issuance of copies of patient medical records |
| National Health Insurance Act and its Enforcement Decree |
Referral for medical benefits |
| Electronic Financial Transactions Act |
Payment and receipt of medical fees |
| Infectious Disease Control and Prevention Act |
Reporting of patients, suspected patients, or carriers of infectious diseases |
| Framework Act on Health and Medical Services |
Reporting and notification of identified or suspected patients with diseases |
| Occupational Safety and Health Act and its Enforcement Decree |
General health examinations and special health examinations |
2. Provision of Health Checkup Services
- A. To verify identity and provide all types of medical services
- B. To provide administrative services such as appointment scheduling, payment processing, delivery of examination results, and issuance of medical certificates
- C. To manage and monitor health checkup results continuously, and to provide health consultations based on those results
Personal information is processed for the above purposes.
3. Use for Marketing Related to Events (Optional)
A. Personal information is processed for purposes such as providing information on annual campaigns, discount promotions, and medical information.
4. Website Services
A. Personal information is processed for purposes such as providing one-on-one consultations, online health checkup reservations (for individuals and organizations), and customer feedback services.
5. Customer Service Inquiries (Call Center)
A. Personal information is processed for purposes such as responding to inquiries regarding customer guidance, health checkup reservations, and consultation of examination results.
Retention and Use Period of Personal Information
① <Hanaro Medical Foundation> retains and uses personal information within the period prescribed by relevant laws or within the retention and use period agreed upon by the data subject at the time of collection.
② The respective retention and use periods for each category of personal information are as follows:
- 1. When retention is required by law or unavoidable for compliance with legal obligations
(Article 22, Paragraph 2 of the Medical Service Act and Article 15 of its Enforcement Regulations)
- Patient register: 5 years
- Medical records: 10 years
- Prescriptions: 2 years (3 years for insurance claim cases)
- Surgical records: 10 years
- Laboratory test records and test reports: 5 years
- Radiographic images (including digital images) and related medical opinions: 5 years
- Copies of medical certificates and related documents: 3 years
- 2. Use for Marketing Related to Events (Optional)
- Retained for 1 year after consent
- 3. Website Services
- Retained for 2 years after collection
- 4. Customer Service Inquiries (Call Center)
- Retained for 2 years after collection
③ However, personal information may be retained until the following situations are resolved:
- 1. When an investigation or inquiry related to a violation of applicable laws is ongoing — retained until the completion of such investigation or inquiry
- 2. When any debt or credit relationship resulting from website use remains unresolved — retained until the relevant relationship is settled
Items of Personal Information Processed
① <Hanaro Medical Foundation> processes the following personal information to comply with legal obligations under relevant laws.
- 1. When required by law or unavoidable for compliance with legal obligations
- Medical Records
· Required items : Medical and family history, chief complaints, diagnosis results or diagnosis name, treatment progress, details of treatment (injections, prescriptions, procedures, etc.), and date and time of treatment
- Patient Register
· Required items : Address, name, unique identification information (resident registration number, alien registration number, or passport number), and telephone number
- Reporting Obligations for Patients, Suspected Patients, or Pathogen Carriers of Infectious Diseases
· Required items : Name, resident registration number, telephone number, occupation, gender, address, type of infectious disease, occurrence details, reporting medical institution, and information reported to the public health center
- Obligations for Emergency Patient Transfer
· Required items : Patient’s name and address, guardian’s name, address, and telephone number, patient’s condition before and after emergency treatment, and details of emergency care provided
- 2. Provision of Health Checkup Services
- Required items : Name, gender, date of birth, telephone number, resident registration number (for medical examinations or for those subject to National Health Insurance Corporation and special health examinations)
- Optional items: Email address, home address, employer name, and employee number
- 3. Use for Marketing Purposes
- Required items : Name and telephone number (information provided during reservation or registration)
- 4. Website Services
- Health Checkup Reservation
· Required items : Name, gender, date of birth, mobile phone number, and address
· Optional items : Email address and employee number
- One-on-One Consultation
· Required items : Name, contact information (email address or mobile phone number, one of the two), and post password
- Customer Feedback – “It’s Inconvenient”
· Required items : Name and contact information (email address or mobile phone number, one of the two)
- Customer Feedback – “Compliments”
· Required items : Name, email address, and post password
- 5. Customer Service Inquiries (Call Center)
- Required items : Name, mobile phone number, and recorded call data
② <Hanaro Medical Foundation> may collect and use resident registration numbers, unique identification information, and sensitive information without the data subject’s consent when required by law or necessary to fulfill statutory medical obligations.
Provision of Personal Information to Third Parties
① <Hanaro Medical Foundation> processes personal information only within the scope explicitly stated to the data subject.
Personal information is provided to third parties only in cases that fall under Article 17 and Article 18 of the Personal Information Protection Act, such as when consent is obtained from the data subject or when specifically permitted by law.
Except for these cases, personal information will not be provided to any third party.
② In accordance with relevant laws, <Hanaro Medical Foundation> provides personal information as follows:
| Recipient |
Purpose of Provision |
Items Provided |
Legal Basis |
| Health Insurance Review and Assessment Service |
Claim for medical care benefit costs |
Name, resident registration number, diagnosis name, prescription details |
Article 19 of the Enforcement Regulations of the National Health Insurance Act |
| Korea Disease Control and Prevention Agency (KDCA) |
Reporting results of infectious disease diagnostic tests |
Name, date of birth, infectious disease name, date of onset, gender |
Article 22-3 of the Enforcement Decree of the Infectious Disease Control and Prevention Act |
| National Health Insurance Service (NHIS) |
Claiming examination fees and registering health checkup results |
Name, resident registration number, alien registration number, general health checkup results, cancer screening results |
Article 52 of the National Health Insurance Act, Article 81 of its Enforcement Decree, and Article 13 of the Enforcement Decree of the Framework Act on Health Examinations |
| Korea Occupational Safety and Health Agency (KOSHA) |
Claiming and registering special health examination results |
Name, resident registration number, results by special examination item |
Article 117 of the Enforcement Decree of the Occupational Safety and Health Act |
| Ministry of Food and Drug Safety (MFDS) |
Reporting narcotics usage history |
Name, resident registration number (or passport number / alien registration number), disease classification code, administration date, type and dosage of narcotics |
Article 28-2 of the Enforcement Decree of the Narcotics Control Act |
③ In accordance with Article 11 of the Emergency Medical Service Act, medical records necessary for patient care may be provided to another medical institution when transferring an emergency patient.
④ <Hanaro Medical Foundation> may provide personal information to a third party without prior consent from the data subject in cases where the data subject or his/her legal representative is unable to express intent, or where prior consent cannot be obtained due to unknown address or other reasons, and it is clearly deemed necessary to protect the urgent life, body, or property interests of the data subject or a third party.
⑤ In accordance with Article 21, Paragraph 3 of the Medical Service Act, <Hanaro Medical Foundation> may allow access to or issue copies of patient records in cases applicable under the relevant provisions.
Entrustment of Personal Information Processing
① <Hanaro Medical Foundation> entrusts certain personal information processing tasks to external service providers to ensure the smooth handling of personal information operations, as follows:
Entrusted Party (Processor) |
Entrusted Task |
Retention and Use Period |
| Seoul Clinical Laboratories (SCL) |
Blood / Tissue / Cell / Microorganism / Sputum testing |
Until the termination of the consignment contract |
| SCL Holdings |
IT system operation and management |
Not applicable |
| SHC |
Genetic testing |
5 years |
| AH Shred Co., Ltd. |
Document destruction |
Not applicable |
| Gwanghwamun Post Office |
Delivery of test preparation materials and examination result reports |
Retained for 1 year after shipment |
| BioCore Co., Ltd. |
Genetic testing |
5 years |
| NICE Information Service |
Mobile phone identity verification |
1 year |
| LG CNS |
Notification messages and SMS transmission |
2 months |
| Hanaro Leaders Healthcare |
Health checkup operations |
Not applicable |
| ToBeCon |
Certificate issuance |
Until completion of issuance application |
② When concluding a consignment contract, <Hanaro Medical Foundation> specifies in writing the matters stipulated in Article 26 of the Personal Information Protection Act, including prohibiting personal information processing for purposes other than the entrusted task, implementing technical and managerial safeguards, restricting re-entrustment, managing and supervising the entrusted party, and defining liability for damages. The Foundation also supervises the entrusted parties to ensure that personal information is processed safely.
③ In the event of any changes to the details of the entrusted tasks or the entrusted parties, such changes will be promptly disclosed through this Privacy Policy.
Procedures and Methods for Destruction of Personal Information
① <Hanaro Medical Foundation>promptly destroys personal information when the retention period has expired, the purpose of processing has been achieved, medical services have been discontinued, or when the personal information is otherwise deemed unnecessary.
② Even if the retention period consented to by the data subject has expired or the processing purpose has been achieved, if it is required by other relevant laws to continue preserving the personal information, the Foundation will transfer such information to a separate database (DB) or store it in a different location.
③ In the event of business closure or suspension, <Hanaro Medical Foundation> transfers medical records, health examination records, and other related treatment or examination documents that are recorded and preserved to the head of the competent public health center.
④ The procedures and methods for destruction of personal information are as follows:
- 1. Destruction Procedures
<Hanaro Medical Foundation> identifies personal information that has become subject to destruction and proceeds with its disposal after obtaining approval from the Foundation’s Chief Information Security Officer (CISO).
- 2. Destruction Methods
Personal information recorded and stored in electronic file format is destroyed in a manner that makes the records irrecoverable.
Personal information recorded and stored in paper documents is destroyed by shredding or incineration.
Rights and Obligations of Data Subjects and Their Legal Representatives, and Methods of Exercise
① Data subjects may exercise the following rights with respect to <Hanaro Medical Foundation> at any time:
- 1. Request to view records related to the patient(self)
- 2. Request to access, correct, delete, or suspend the processing of other personal information
※ Requests for access, correction, or deletion of personal information related to a child under the age of 14 must be made directly by the child’s legal representative.
For minors aged 14 or older, the data subject may exercise their own rights regarding their personal information, or such rights may be exercised through their legal representative.
② The rights listed above may be exercised through the following methods:
- Access to patient’s (self) medical records: Present a valid identification document to <Hanaro Medical Foundation> for identity verification.
- Requests for access, correction, deletion, or suspension of other personal information: Submit a written or email request in accordance with Article 41(1) of the Enforcement Decree of the Personal Information Protection Act.
* However, in accordance with Article 15 of the Enforcement Regulations of the Medical Service Act, deletion is not permitted during the legally required retention period.
③ Each of the above rights may also be exercised by the data subject’s legal representative or a delegated agent.
- Access to patient’s (self) medical records: When a representative designated by the patient submits a request that meets the requirements prescribed by the Ministry of Health and Welfare, including the patient’s consent form and documentation proving power of attorney, the following documents must be provided:
- A. A copy of the identification card of the person requesting record access or a copy issuance
- B. The patient’s handwritten consent form (Form No. 9-2) and power of attorney (Form No. 9-3) as prescribed in the Enforcement Regulations of the Medical Service Act.
In the case of a minor under the age of 14, these forms must be completed by the legal representative, and documents verifying the legal relationship (e.g., family relation certificate) must be attached.
- C. A copy of the patient’s identification card (except for patients under 17 years of age who have not been issued a resident registration card under Article 24(1) of the Resident Registration Act).
- Requests for access, correction, deletion, or suspension of processing of other personal information: Submit a power of attorney in accordance with Form No. 11 of the Public Notice on Personal Information Processing Methods (Notice No. 2020-7).
④ The exercise of rights under each item above may be restricted in the following cases:
- Access to patient’s (self) medical records: When it may interfere with national security or ongoing audits or investigations conducted under other laws.
- Requests for access, correction, deletion, or suspension of other personal information: When the request falls under the provisions of Article 35(4) or Article 37(2) of the Personal Information Protection Act.
⑤ <Hanaro Medical Foundation> verifies whether the individual exercising the rights under Paragraph ① is the data subject or an authorized representative.
Measures to Ensure the Security of Personal Information
<Hanaro Medical Foundation>takes the following measures to ensure the security and integrity of personal information:
- 1. Administrative Measures : Establishment and implementation of internal management plans, operation of a dedicated data protection team, and regular training for employees.
- 2. Technical Measures : Management of access rights to personal information processing systems, installation of access control systems, encryption of personal information, and installation and regular updates of security programs.
- 3. Physical Measures : Access control for computer rooms, data storage rooms, and other areas where personal information is physically stored.
Personal Information Protection Officer
① <Hanaro Medical Foundation>designates a Personal Information Protection Officer who is responsible for the overall management of personal information processing and for handling complaints and providing remedies related to personal information protection. The details are as follows:
[Personal Information Protection Officer]
- Name : Jae-woon Lee
- Position : Executive Director
- Contact : privacy@hanaromf.com
Department Responsible for Receiving and Processing Requests for Access to Personal Information
[Request for Access to Personal Information]
Data subjects may submit a request to access their personal information in accordance with Article 35 of the Personal Information Protection Act to the department listed below.
<Hanaro Medical Foundation> will make every effort to ensure that such requests are processed promptly and efficiently.
[Department for Receiving and Processing Access Requests]
Requests for access to personal information are handled by the Personal Information Protection Department under the section “Personal Information Protection Officer.”
Remedies for Infringement of Data Subjects’ Rights
[Remedies for Infringement of Rights]
① Data subjects may apply for dispute resolution or consultation to the Personal Information Dispute Mediation Committee or the Personal Information Infringement Report Center operated by the Korea Internet & Security Agency (KISA) in order to seek relief from damages caused by personal information infringement.
For reports or consultations regarding other personal information violations, please contact the organizations below:
1. Personal Information Dispute Mediation Committee : (no area code) 1833-6972 (www.kopico.go.kr)
2. Personal Information Infringement Report Center (KISA) : (no area code) 118 (privacy.kisa.or.kr)
3. Supreme Prosecutors’ Office : (no area code) 1301 (www.spo.go.kr)
4. National Police Agency Cyber Bureau : (no area code) 182 (ecrm.cyber.go.kr)
② In accordance with Articles 35 (Access to Personal Information), 36 (Correction or Deletion of Personal Information), and 37 (Suspension of Personal Information Processing) of the Personal Information Protection Act, any individual who has suffered infringement of rights or interests due to a disposition or omission made by the head of a public institution may file an administrative appeal as prescribed by the Administrative Appeals Act.
- Central Administrative Appeals Commission : (no area code) 110 (www.simpan.go.kr)
Operation and Management of Video Surveillance Systems
① <Hanaro Medical Foundation> installs and operates video surveillance systems (CCTVs) in accordance with the Personal Information Protection Act as follows:
1. Legal Basis and Purpose of Installation:
A. To ensure the safety of patients and facilities, and to prevent fires and crimes.
2. Number of Cameras, Installation Locations, and Coverage Areas:
| Number of Cameras |
Installation Locations and Coverage Areas |
| 13 units |
Reception area, waiting areas, and recovery rooms |
A. The number, location, or coverage of cameras may be subject to change as necessary to improve operational efficiency.
3. Manager, Responsible Department, and Authorized Personnel for Access to Video Data:
| Department |
Position |
Name |
| General Affairs Team |
Managing Director |
Min-taek Lim |
4. Recording Time, Retention Period, Storage Location, and Processing Method:
| Recording Time |
Retention Period |
Storage Location |
| 24-hour recording |
30 days from the time of recording |
Server room |
5. Method and Location for Accessing Video Information :
A. To access recorded video information, a prior request must be submitted to the General Affairs Team (Tel: 02-590-1356).
6. Measures Regarding Requests for Access or Deletion by Data Subjects :
A. Data subjects may request confirmation of the existence of or access to personal video footage.
Access will be granted only when the footage involves the data subject or when it is clearly necessary to protect the life, body, or property of the data subject.
7. Technical, Administrative, and Physical Measures for Video Data Protection:
A. Establishment of internal management plans, access control and restriction of access rights, application of secure storage and transmission technologies, maintenance of processing logs and tamper-prevention measures, and installation of secure storage facilities with locking devices.
8. Outsourcing of Installation and Management of Video Surveillance Systems:
<Hanaro Medical Foundation> outsources the installation and management of video surveillance systems as follows and includes necessary provisions in the consignment contract to ensure the safe management of personal information in accordance with relevant laws and regulations.
| Contractor |
Contact Person |
Contact Information |
| KT Telecop |
Customer Service Center |
1588-0112 |
9. Revisions to the Video Surveillance Operation and Management Policy:
A. This policy on the operation and management of video surveillance systems was established on July 19, 2022.
Any additions, deletions, or modifications due to changes in laws, policies, or security technologies will be promptly announced on the Foundation’s website along with the reasons and details of such changes.