Privacy Policy
Last updated: 4 August 2026
1. Who is responsible for your information
Clinic EMR is used by many independent clinics. Each clinic’s records are kept separate from every other clinic’s, so responsibility is split:
- Your clinic or doctor is the Personal Information Controller. They decide what goes into your medical record, who on their staff may see it, and how long it is kept. Requests about the content of your records go to them first.
- KJUB Solutions is the Personal Information Processor. We build and operate the software and the server it runs on, strictly on the instructions of the clinics that use it. We do not use patient records for our own purposes.
If you registered as a patient and booked with a doctor through this site, that doctor’s practice is the controller of the record created for you.
2. What information is collected
Account information — your name, email address, mobile number and password (stored only as a cryptographic hash, never in readable form). If you switch on two-factor authentication, we store the secret your authenticator app uses.
Patient details — first, middle and last name, date of birth, sex, address, contact number, blood type.
Health information — the clinical record your doctor creates: chief complaints and consultation notes, diagnoses (ICD-10 coded), prescriptions, laboratory requests, vital signs, allergies, medical and family history, treatment plans, diagnostic imaging including X-ray, CT, MRI, ultrasound and DICOM files, and issued documents such as medical certificates, clearances and referrals.
Appointments and visits — bookings, visit type (in-clinic or online), clinic location, check-in and queue records, and consultation status.
Billing — invoices, charges, discounts, and payments recorded by clinic staff, including the payment method and a reference number where one applies. Card numbers and bank credentials are never collected or stored — payment is handled at the clinic, and the system records only that it happened.
Technical and security records — an audit log of who viewed or changed a record and when; sign-in attempts, including the email used and the originating IP address, kept to detect unauthorised access.
The system does not collect your location, contacts, advertising identifiers, or browsing activity on other sites, and contains no analytics or advertising trackers of any kind.
3. How the information is used
- To provide medical care, and to create and maintain your medical record.
- To book, confirm, remind you of and manage appointments and the clinic queue.
- To issue prescriptions, certificates, laboratory requests and referrals.
- To bill for services and record payments.
- To run online video consultations when you book one.
- To secure the system — authentication, access control, and audit logging.
- To meet the clinic’s legal, regulatory and professional record-keeping duties.
Health information is processed on the bases allowed by Section 13 of RA 10173, principally your consent and the provision of medical treatment by a healthcare professional bound by confidentiality. Your information is never sold, rented, or used for advertising.
5. The Clinic EMR mobile app
The Android app displays the same system as the website. It asks for these permissions only when a feature needs them:
- Camera and microphone — used solely for online video consultations, and only while a consultation is open. Nothing is recorded or stored by the app.
- Storage / downloads — used when you save a document or file, such as a prescription or an imaging file, to your device.
The app contains no advertising, no analytics, and no third-party software development kits. Your session stays signed in on your device until it expires or you log out, so protect your device with a screen lock and log out on shared phones.
6. How the information is protected
- All traffic between your device and the system is encrypted with HTTPS/TLS.
- Passwords are stored only as bcrypt hashes; nobody, including us, can read them.
- Optional two-factor authentication for clinic accounts.
- Repeated failed sign-ins temporarily lock an account against password guessing.
- Sessions expire automatically after a bounded period of use.
- Role-based access control: staff see only what their role requires, and every practice’s data is isolated from every other.
- Access to patient records is written to an audit log.
- Backups are taken on a nightly schedule so records can be restored.
No system can promise perfect security. If a breach occurs that puts your sensitive personal information at real risk, the National Privacy Commission and the affected individuals will be notified as RA 10173 requires.
7. How long information is kept
Your clinic decides how long to keep your medical record, and must follow the retention periods that apply to medical practice in the Philippines. Clinical records are typically retained for years after your last visit, and cannot simply be deleted on request while that duty applies. Audit logs and backups are kept for security and recovery purposes. When information is no longer needed and no legal duty requires it, it is deleted or anonymised.
8. Your rights under the Data Privacy Act
As a data subject you have the right to:
- Be informed whether your personal data is being processed, and why.
- Access your personal data and the details of how it is handled.
- Have inaccurate data corrected.
- Object to processing, and to withdraw consent — noting that care may not be able to continue without the records it depends on.
- Request erasure or blocking of data that is unlawfully obtained, no longer necessary, or wrongly processed.
- Data portability — obtain a copy of your data in an electronic format.
- Claim damages for a violation of your rights.
- Lodge a complaint with the National Privacy Commission.
To exercise these rights over your medical record, contact your clinic, which controls it. You may also write to us at the address below and we will route your request to the right clinic and assist them in answering it.
9. Deleting your account and data
You may ask for your Clinic EMR account to be deleted at any time by emailing mdnovate@gmail.com from the address on your account, or by asking your clinic directly.
Deleting your account removes your sign-in credentials and your ability to log in. Your clinical records may have to be retained by your clinic even after the account is closed, because medical records carry legal retention duties that outlive an online account. Where that applies, the record stays with your clinic under this policy, and is not used for anything other than those duties.
10. Children and minors
Records for minors are created by the clinic with the consent of a parent or guardian, who may exercise the rights above on the child’s behalf. Accounts on this site are intended for adults; a minor’s care should be arranged through their parent or guardian’s account or directly with the clinic.
12. Changes to this policy
This policy may be updated as the system changes or the law requires. The date at the top always reflects the current version. Material changes affecting how health information is handled will be communicated through the clinics that use the system.
13. How to contact us
For questions about this policy, or to make a data-privacy request:
KJUB Solutions
Email: mdnovate@gmail.com
For anything about the content of your medical record, contact your clinic first — they control that record.
You may also raise a concern with the National Privacy Commission, 5th Floor, Delegation Building, PICC Complex, Roxas Boulevard, Pasay City 1307 — privacy.gov.ph.