ประกาศโรงพยาบาลจักษุสุราษฎร์
เรื่อง นโยบายเกี่ยวกับการใช้สื่อสังคมออนไลน์ (Social Media) และการคุ้มครองข้อมูลส่วนบุคคล
โรงพยาบาลจักษุสุราษฎร์ตระหนักถึงความสำคัญของการใช้สื่อสังคมออนไลน์ (Social Media)
ซึ่งเป็นช่องทางสำคัญในการสื่อสาร การประชาสัมพันธ์ การให้ความรู้ด้านสุขภาพ การแลกเปลี่ยนข้อมูลข่าวสาร
และการติดต่อประสานงานทั้งภายในและภายนอกองค์กร ทั้งนี้ การใช้สื่อสังคมออนไลน์อย่างไม่เหมาะสมอาจก่อให้เกิด
ความเสียหายต่อสิทธิและเสรีภาพของผู้รับบริการ บุคลากร และบุคคลอื่น รวมทั้งอาจส่งผลกระทบต่อความลับของข้อมูลส่วนบุคคล
ความมั่นคงปลอดภัยของข้อมูล ภาพลักษณ์ และชื่อเสียงของโรงพยาบาล
เพื่อให้การเก็บรวบรวม ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลผ่านสื่อสังคมออนไลน์เป็นไปอย่างเหมาะสม มีความมั่นคงปลอดภัย
และสอดคล้องกับพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 พระราชบัญญัติว่าด้วยการกระทำความผิดเกี่ยวกับคอมพิวเตอร์
กฎหมายที่เกี่ยวข้อง หลักจริยธรรมแห่งวิชาชีพ ตลอดจนระเบียบและนโยบายของโรงพยาบาล โรงพยาบาลจึงกำหนดนโยบายและแนวทางปฏิบัติสำหรับบุคลากรทุกระดับ ดังต่อไปนี้
หมวดที่ 1 การคุ้มครองข้อมูลส่วนบุคคลและความลับของผู้รับบริการ
ข้อ 1 คำนิยาม
- “สื่อสังคมออนไลน์ (Social Media)” หมายถึง สื่อหรือช่องทางดิจิทัลที่ใช้ในการสื่อสาร แลกเปลี่ยน ส่งต่อ เผยแพร่ หรือแสดงความคิดเห็นต่อบุคคล กลุ่มบุคคล หรือสาธารณะ ผ่านเว็บไซต์ โปรแกรมประยุกต์ หรือระบบสารสนเทศที่เชื่อมต่อกับเครือข่ายอินเทอร์เน็ต เช่น LINE, Facebook, Messenger, Instagram, TikTok, YouTube, X และสื่อสังคมออนไลน์อื่นในลักษณะเดียวกัน
- “ข้อมูลส่วนบุคคล” หมายถึง ข้อมูลเกี่ยวกับบุคคลซึ่งทำให้สามารถระบุตัวบุคคลนั้นได้ ไม่ว่าทางตรงหรือทางอ้อม ตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562
- “ข้อมูลส่วนบุคคลที่มีความอ่อนไหว (Sensitive Personal Data)” หมายถึง ข้อมูลส่วนบุคคลตามที่กำหนดไว้ในมาตรา 26 แห่งพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 ซึ่งรวมถึงข้อมูลสุขภาพ ประวัติการรักษาพยาบาล และข้อมูลอื่นที่เข้าลักษณะตามที่กฎหมายกำหนด ทั้งนี้ การพิจารณาว่าข้อมูลใดเป็นข้อมูลส่วน
บุคคลที่มีความอ่อนไหว ให้เป็นไปตามกฎหมายและหลักเกณฑ์ที่เกี่ยวข้อง
- “บุคลากร” หมายถึง ผู้บริหาร แพทย์ ทันตแพทย์ พยาบาล เภสัชกร เจ้าหน้าที่ ลูกจ้าง ผู้ปฏิบัติงาน นักศึกษาฝึกงาน ผู้รับจ้าง และบุคคลอื่นที่ปฏิบัติงานให้โรงพยาบาลตามความสัมพันธ์หรือหน้าที่ที่โรงพยาบาลกำหนด
ข้อ 2 การรักษาความลับและการคุ้มครองข้อมูลส่วนบุคคล
บุคลากรต้องรักษาความลับและคุ้มครองข้อมูลส่วนบุคคลของผู้รับบริการ บุคลากร และบุคคลอื่นที่โรงพยาบาลมีหน้าที่เก็บรวบรวม ใช้ หรือเปิดเผยอย่างเคร่งครัด
ห้ามบุคลากรนำข้อมูลส่วนบุคคลไปใช้ เปิดเผย เผยแพร่ ส่งต่อ ทำซ้ำ หรือดำเนินการอื่นใดผ่านสื่อสังคมออนไลน์ เว้นแต่มีฐานทางกฎหมายที่เหมาะสมและการดำเนินการดังกล่าวอยู่ภายในขอบเขตหน้าที่
อำนาจ วัตถุประสงค์ และมาตรการที่โรงพยาบาลกำหนด โดยเฉพาะข้อมูลสุขภาพ ประวัติการรักษาพยาบาล ผลการตรวจวินิจฉัย เวชระเบียน ภาพถ่ายทางการแพทย์ ภาพถ่ายผู้รับบริการ ข้อมูลการนัดหมาย เลขที่ผู้ป่วย และข้อมูลอื่นใด ที่สามารถระบุตัวผู้รับบริการได้ทั้งทางตรงหรือทางอ้อม
ข้อ 3 การเผยแพร่ภาพถ่าย วิดีโอ และข้อมูลของผู้รับบริการ
ห้ามบุคลากรเผยแพร่หรือส่งต่อภาพถ่าย วิดีโอ เสียง เอกสาร เวชระเบียน ผลตรวจ ภาพทางการแพทย์ หรือข้อมูลอื่นใดของผู้รับบริการผ่านสื่อสังคมออนไลน์
เว้นแต่มีฐานทางกฎหมายที่เหมาะสม และดำเนินการภายในขอบเขตหน้าที่ อำนาจ วัตถุประสงค์ และมาตรการที่โรงพยาบาลกำหนด
กรณีมีความจำเป็นต้องนำข้อมูลหรือภาพของผู้รับบริการไปใช้เพื่อการศึกษา วิจัย การฝึกอบรม การประชาสัมพันธ์ หรือวัตถุประสงค์อื่นที่ต้องได้รับความยินยอมตามกฎหมาย
ต้องดำเนินการขอความยินยอมจากเจ้าของข้อมูลส่วนบุคคลก่อน และต้องแจ้งวัตถุประสงค์และรายละเอียดที่เกี่ยวข้องให้เจ้าของข้อมูลส่วนบุคคลทราบตามที่กฎหมายกำหนด
การปกปิดหรือเบลอข้อมูลระบุตัวบุคคลเพียงบางส่วน เช่น ชื่อ ใบหน้า ดวงตา หมายเลขผู้ป่วย หรือข้อมูลอื่นใด ไม่ถือเป็นการทำให้ข้อมูลดังกล่าวพ้นจากการเป็นข้อมูลส่วนบุคคลโดยอัตโนมัติ
หากยังสามารถเชื่อมโยงหรือระบุตัวบุคคลได้ไม่ว่าทางตรงหรือทางอ้อม บุคลากรต้องประเมินความสามารถในการระบุตัวบุคคลและความเสี่ยงก่อนนำข้อมูลไปใช้หรือเผยแพร่ทุกครั้ง
ข้อ 4 การใช้บัญชีสื่อสังคมออนไลน์ส่วนบุคคล
บุคลากรไม่ควรใช้บัญชีสื่อสังคมออนไลน์ส่วนบุคคลเป็นช่องทางหลักในการติดต่อ สื่อสาร หรือให้บริการทางการแพทย์แก่ผู้รับบริการ
โดยเฉพาะการรับ ส่ง หรือแลกเปลี่ยนข้อมูลสุขภาพ เวชระเบียน ผลการตรวจ หรือข้อมูลส่วนบุคคลที่มีความอ่อนไหว เว้นแต่โรงพยาบาลได้อนุญาตและกำหนดมาตรการที่เหมาะสม
ในการคุ้มครองข้อมูลส่วนบุคคลและรักษาความมั่นคงปลอดภัยของข้อมูล
การสื่อสารกับผู้รับบริการเกี่ยวกับการรักษาพยาบาล การนัดหมาย ผลการตรวจ หรือข้อมูลสุขภาพ ให้ดำเนินการผ่านระบบหรือช่องทางที่โรงพยาบาลกำหนดหรืออนุมัติ
และต้องปฏิบัติตามมาตรการรักษาความมั่นคงปลอดภัยของข้อมูลและแนวทางปฏิบัติที่โรงพยาบาลกำหนด
หมวดที่ 2 การใช้สื่อสังคมออนไลน์และระบบสื่อสารภายในโรงพยาบาล
ข้อ 5 ความรับผิดชอบกรณีการเปิดเผยข้อมูลผ่าน LINE หรือสื่อสังคมออนไลน์
ข้อมูลส่วนบุคคล ข้อมูลสุขภาพ ข้อความ ภาพถ่าย เอกสาร หรือข้อมูลอื่นใดที่บุคลากรได้รับหรือเข้าถึงจากการปฏิบัติหน้าที่ผ่าน LINE Group หรือสื่อสังคมออนไลน์ของโรงพยาบาล
บุคลากรต้องใช้หรือเปิดเผยเฉพาะเท่าที่จำเป็นและสอดคล้องกับวัตถุประสงค์ในการปฏิบัติงาน ตลอดจนต้องปฏิบัติตามกฎหมาย นโยบาย และมาตรการคุ้มครองข้อมูลส่วนบุคคลของโรงพยาบาลอย่างเคร่งครัด
การที่เจ้าของข้อมูลส่วนบุคคลได้ให้ความยินยอมในการเปิดเผยข้อมูลผ่าน LINE หรือสื่อสังคมออนไลน์ ไม่ถือเป็นการอนุญาตให้บุคลากรนำข้อมูลดังกล่าวไปใช้หรือเปิดเผยต่อในวัตถุประสงค์อื่น
นอกเหนือจากวัตถุประสงค์ ขอบเขต หรือเงื่อนไขที่เจ้าของข้อมูลส่วนบุคคลได้รับทราบและให้ความยินยอมไว้ ทั้งนี้ การใช้หรือเปิดเผยข้อมูลส่วนบุคคลต้องมีฐานทางกฎหมายและเป็นไปตามหลักเกณฑ์ที่กฎหมายกำหนด
ในกรณีที่บุคลากรนำข้อมูลส่วนบุคคลหรือข้อมูลที่เป็นความลับไปใช้ เปิดเผย ส่งต่อ เผยแพร่ หรือแสวงหาประโยชน์โดยไม่ได้รับอนุญาต หรือฝ่าฝืนนโยบาย ระเบียบ หรือมาตรการของโรงพยาบาล
และการกระทำดังกล่าวก่อให้เกิดความเสียหาย บุคลากรผู้กระทำอาจต้องรับผิดเป็นการเฉพาะตัวตามกฎหมาย ระเบียบ ข้อบังคับ หรือสัญญาที่เกี่ยวข้อง
บุคลากรต้องตรวจสอบผู้รับ กลุ่มสนทนา บัญชีผู้ใช้งาน ไฟล์หรือข้อมูลที่แนบ และความถูกต้องของข้อมูลก่อนส่งทุกครั้ง โดยเฉพาะข้อมูลส่วนบุคคลและข้อมูลสุขภาพ
หากส่งข้อมูลผิดบุคคล ผิดกลุ่ม หรือผิดช่องทาง ให้ถือเป็นเหตุการณ์ที่ต้องรายงานตามกระบวนการจัดการเหตุละเมิดข้อมูลส่วนบุคคลของโรงพยาบาลโดยไม่ชักช้า
ทั้งนี้โรงพยาบาลจะไม่มีส่วนรับผิดต่อการกระทำหรือความผิดนั้น ๆ กรณีการละเมิดข้อมูลส่วนบุคคลผ่าน LINE หรือสื่อสังคมออนไลน์ ให้พิจารณาความรับผิดตามข้อเท็จจริงและบทบาทของแต่ละฝ่าย โดยรวมถึงกรณีต่อไปนี้
- การละเมิดจากบุคลากรภายในโรงพยาบาล — กรณีโรงพยาบาลจัดให้มี LINE Group หรือช่องทางสื่อสารภายในเพื่อใช้ในการปฏิบัติงาน และบุคลากรนำ
ข้อมูลส่วนบุคคล ข้อมูลสุขภาพ ข้อความสนทนา รูปภาพ เอกสาร หรือข้อมูลอื่นที่ได้รับหรือเข้าถึงจากช่องทาง
ดังกล่าวไปเปิดเผย ส่งต่อ เผยแพร่ หรือใช้เพื่อประโยชน์ส่วนตนหรือประโยชน์ของบุคคลอื่นโดยไม่ได้รับอนุญาต หรือ
เกินขอบเขตหน้าที่และอำนาจที่ได้รับ บุคลากรผู้กระทำอาจต้องรับผิดตามกฎหมาย ระเบียบ ข้อบังคับ หรือสัญญาที่
เกี่ยวข้อง รวมถึงอาจถูกดำเนินการทางวินัยตามระเบียบของโรงพยาบาล ทั้งนี้ โรงพยาบาลจะดำเนินการตรวจสอบข้อเท็จจริง ประเมินเหตุละเมิด และพิจารณาหน้าที่
และความรับผิดของโรงพยาบาลและบุคลากรแต่ละรายตามบทบาท หน้าที่ อำนาจ และข้อเท็จจริงของเหตุการณ์
- การละเมิดระหว่างองค์กรหรือระหว่างหน่วยงาน — กรณีมีการสื่อสารหรือแลกเปลี่ยนข้อมูลส่วนบุคคลระหว่างโรงพยาบาลหรือสถานพยาบาลกับหน่วยงานหรือ
องค์กรอื่นผ่าน LINE Group หรือสื่อสังคมออนไลน์ และเกิดการเข้าถึง ใช้ หรือเปิดเผยข้อมูลส่วนบุคคลโดยไม่ชอบ
ด้วยกฎหมายให้โรงพยาบาลดำเนินการตรวจสอบข้อเท็จจริงและพิจารณาบทบาทของแต่ละฝ่ายว่าเป็นผู้ควบคุมข้อมูล
ส่วนบุคคล ผู้ประมวลผลข้อมูลส่วนบุคคล หรือบุคคลที่ได้รับมอบหมายหรือได้รับอนุญาตให้เข้าถึงข้อมูล แล้วแต่กรณี
ผู้ที่กระทำการเปิดเผยหรือใช้ข้อมูลโดยไม่มีอำนาจหรือเกินขอบเขตหน้าที่ อาจต้องรับผิดตามกฎหมายที่
เกี่ยวข้องเป็นการเฉพาะตัว แล้วแต่กรณี ทั้งนี้ ไม่ตัดหน้าที่หรือความรับผิดของโรงพยาบาลหรือหน่วยงานที่เกี่ยวข้อง
ในส่วนที่กฎหมายกำหนด
- การละเมิดจากบุคคลภายนอกหรือบุคลากรที่พ้นสภาพการปฏิบัติงาน — กรณีบุคลากรพ้นจากหน้าที่ หรือสิ้นสุดการปฏิบัติงานแล้ว แต่ยังสามารถเข้าถึง LINE Group ระบบสารสนเทศ หรือช่องทางสื่อสารของโรงพยาบาล และนำข้อมูลส่วนบุคคล ข้อมูลสุขภาพ ข้อความ รูปภาพ เอกสาร หรือข้อมูลอื่นไปเปิดเผย ส่งต่อ หรือเผยแพร่โดยไม่ได้รับอนุญาต บุคคลดังกล่าวอาจต้องรับผิดตามกฎหมายและข้อกำหนดที่เกี่ยวข้องเป็นการเฉพาะตัว โรงพยาบาลต้องดำเนินการยกเลิกหรือระงับสิทธิการเข้าถึงของบุคลากรที่พ้นสภาพการปฏิบัติงานโดยเร็ว
และเมื่อพบเหตุหรือมีเหตุอันควรสงสัยว่าเกิดการละเมิดข้อมูลส่วนบุคคล ต้องดำเนินการตรวจสอบ ประเมิน
ความเสี่ยง ระงับหรือจำกัดผลกระทบ เก็บรักษาหลักฐานและดำเนินการตามกระบวนการจัดการเหตุละเมิดข้อมูล
ส่วนบุคคลของโรงพยาบาลและตามที่กฎหมายกำหนด
- การละเมิดจากบุคคลภายนอก — กรณีบุคคลภายนอกที่ไม่ได้รับอนุญาตให้เข้าถึงข้อมูลส่วนบุคคลของโรงพยาบาลสามารถเข้าถึง นำไปใช้ เปิดเผยหรือเผยแพร่ข้อมูลส่วนบุคคลโดยมิชอบ โรงพยาบาลต้องดำเนินการตามมาตรการรักษาความมั่นคงปลอดภัยและกระบวนการจัดการเหตุละเมิดข้อมูลส่วนบุคคลที่กำหนดไว้ รวมทั้งประเมินสาเหตุและดำเนินการแจ้งสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคลหรือแจ้งเจ้าของข้อมูลส่วนบุคคล แล้วแต่กรณี เมื่อเข้าหลักเกณฑ์และภายในระยะเวลาที่กฎหมายกำหนด ทั้งนี้ การพิจารณาหน้าที่และความรับผิดของบุคลากร โรงพยาบาล หรือบุคคลที่เกี่ยวข้อง ให้พิจารณาจากข้อเท็จจริง พฤติการณ์ เจตนา หรือระดับความประมาท บทบาท หน้าที่และอำนาจในการควบคุมหรือเข้าถึงข้อมูล
ตลอดจนกฎหมาย ระเบียบ ข้อบังคับ มาตรการรักษาความมั่นคงปลอดภัย และสัญญาที่เกี่ยวข้อง แล้วแต่กรณี
ข้อ 6 การรักษาความมั่นคงปลอดภัยของบัญชีผู้ใช้งาน
บุคลากรต้องรักษาชื่อผู้ใช้งาน รหัสผ่าน รหัสยืนยันตัวตน และข้อมูลสำหรับเข้าถึงระบบสื่อสารหรือระบบสารสนเทศของโรงพยาบาลเป็นความลับ
ห้ามเปิดเผยรหัสผ่านให้บุคคลอื่นใช้บัญชีผู้ใช้งานของตน หรือปล่อยให้บุคคลอื่นสามารถเข้าถึงบัญชีผู้ใช้งานหรืออุปกรณ์ที่ใช้เข้าถึงข้อมูลของโรงพยาบาลโดยไม่ได้รับอนุญาต
หากพบหรือสงสัยว่าบัญชีผู้ใช้งาน อุปกรณ์ หรือระบบของโรงพยาบาลถูกเข้าถึงหรือใช้งานโดยไม่ได้รับอนุญาต ต้องแจ้งผู้บังคับบัญชา หน่วยงานที่รับผิดชอบด้านเทคโนโลยีสารสนเทศ
หรือเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (Data Protection Officer: DPO) ตามช่องทางที่โรงพยาบาลกำหนดโดยทันที
ข้อ 7 การใช้ข้อมูลตามวัตถุประสงค์และเท่าที่จำเป็น
บุคลากรต้องใช้หรือเปิดเผยข้อมูลส่วนบุคคลเท่าที่จำเป็นและสอดคล้องกับวัตถุประสงค์ในการปฏิบัติงาน อยู่ภายในขอบเขตหน้าที่และอำนาจที่ได้รับมอบหมาย
และต้องไม่ใช้หรือเปิดเผยข้อมูลส่วนบุคคลเพื่อประโยชน์ส่วนตนหรือเพื่อวัตถุประสงค์อื่นที่ไม่เกี่ยวข้องกับหน้าที่ เว้นแต่มีฐานทางกฎหมายที่เหมาะสม หรือได้รับอนุญาตตามที่กฎหมายกำหนด
หมวดที่ 3 การบริหารจัดการช่องทางสื่อสารทางการของโรงพยาบาล
ข้อ 8 การจัดทำ Official Page หรือ Account
การจัดทำ Page, Group, Account เว็บไซต์ หรือช่องทางสื่อสังคมออนไลน์ใด ๆ ในนามของโรงพยาบาลหรือหน่วยงานภายในโรงพยาบาล ต้องได้รับอนุมัติจากผู้มีอำนาจตามที่โรงพยาบาลกำหนดก่อนดำเนินการ
ต้องกำหนดผู้รับผิดชอบและผู้ดูแลระบบอย่างชัดเจน รวมทั้งกำหนดสิทธิการเข้าถึงให้เหมาะสมกับหน้าที่และความรับผิดชอบ
เมื่อบุคลากรพ้นจากหน้าที่ เปลี่ยนตำแหน่ง โอนย้าย ลาออก สิ้นสุดการจ้าง หรือสิ้นสุดสิทธิในการเข้าถึงข้อมูลหรือระบบของโรงพยาบาล โรงพยาบาลต้องดำเนินการทบทวน ปรับเปลี่ยน ระงับหรือเพิกถอนสิทธิการเข้าถึงที่เกี่ยวข้องโดยเร็วตามความเหมาะสม
การปรับเปลี่ยน ระงับ หรือเพิกถอนสิทธิให้ครอบคลุมถึงบัญชีผู้ใช้งาน กลุ่มสนทนา (Group) Page บัญชี Social Media ระบบ Cloud อีเมล LINE Application, VPN และระบบสารสนเทศหรือช่องทางอื่นของโรงพยาบาลที่บุคลากรมีสิทธิในการเข้าถึง
ทั้งนี้ ให้ดำเนินการตามกระบวนการควบคุมสิทธิการเข้าถึงของโรงพยาบาล
บุคลากรที่พ้นจากหน้าที่ต้องส่งคืนหรือส่งมอบอุปกรณ์ บัญชี สิทธิการเข้าถึง ข้อมูล และทรัพย์สินดิจิทัลของโรงพยาบาลที่อยู่ในความครอบครองหรือความรับผิดชอบของตน
และต้องไม่เก็บรักษา คัดลอก ใช้ หรือเข้าถึงข้อมูลหรือระบบของโรงพยาบาลภายหลังสิ้นสุดสิทธิ เว้นแต่ได้รับอนุญาตจากโรงพยาบาลหรือมีหน้าที่ตามกฎหมาย
ข้อ 9 การเผยแพร่ข้อมูลในนามโรงพยาบาล
การเผยแพร่ข่าวสาร ประชาสัมพันธ์ ความรู้ทางการแพทย์ ภาพถ่ายกิจกรรม หรือข้อมูลอื่นใดในนามของโรงพยาบาล ต้องผ่านการตรวจสอบและได้รับอนุมัติตามขั้นตอนที่โรงพยาบาลกำหนดก่อนเผยแพร่
ผู้เผยแพร่ต้องตรวจสอบความถูกต้อง ความเหมาะสม สิทธิหรืออำนาจในการนำข้อมูลมาใช้ และต้องไม่เปิดเผยข้อมูลส่วนบุคคลหรือข้อมูลที่เป็นความลับ โดยไม่ได้รับอนุญาตหรือไม่มีฐานทางกฎหมายรองรับ
ข้อ 10 การแสดงความคิดเห็นในฐานะส่วนบุคคล
บุคลากรสามารถใช้สื่อสังคมออนไลน์ในฐานะส่วนบุคคลได้ แต่ต้องไม่แสดงข้อความหรือพฤติการณ์ที่อาจทำให้บุคคลทั่วไปเข้าใจว่าเป็นการแถลงการณ์หรือความคิดเห็นอย่างเป็นทางการของโรงพยาบาล
เว้นแต่ได้รับมอบหมายหรือได้รับอนุญาตจากโรงพยาบาล ในกรณีที่การแสดงความคิดเห็นอาจทำให้เกิดความเข้าใจว่าเป็นการแสดงความคิดเห็นในนามโรงพยาบาล
บุคลากรต้องระบุให้ชัดเจนว่าเป็นความคิดเห็นส่วนบุคคลและไม่ใช่การแถลงการณ์หรือจุดยืนอย่างเป็นทางการของโรงพยาบาล
หมวดที่ 4 การรักษาข้อมูลภายในและทรัพย์สินทางปัญญา
ข้อ 11 การรักษาข้อมูลภายในและทรัพย์สินทางปัญญา
ห้ามบุคลากรนำข้อมูลภายใน ข้อมูลที่เป็นความลับ ข้อมูลทางธุรกิจ ข้อมูลของคู่ค้า เอกสารภายใน แบบฟอร์ม ระบบงาน ฐานข้อมูล คู่มือ กระบวนการทำงาน เครื่องหมายการค้า ภาพถ่าย
หรือทรัพย์สินทางปัญญาของโรงพยาบาล ไปเผยแพร่ ทำซ้ำ ดัดแปลง หรือใช้เพื่อประโยชน์ส่วนตนหรือบุคคลภายนอกโดยไม่ได้รับอนุญาต
การนำข้อมูลดังกล่าวไปเผยแพร่ต้องได้รับอนุญาตจากผู้มีอำนาจของโรงพยาบาล และต้องไม่ขัดต่อกฎหมาย สิทธิของบุคคลอื่น หรือข้อกำหนดตามสัญญา
ข้อ 12 การใช้ปัญญาประดิษฐ์และบริการออนไลน์ของบุคคลภายนอก
ห้ามบุคลากรนำเข้า ป้อน อัปโหลด ส่ง หรือเปิดเผยภาพถ่าย เสียง วิดีโอ ข้อมูลส่วนบุคคล ข้อมูลสุขภาพ ข้อมูลภายใน หรือข้อมูลที่เป็นความลับของผู้รับบริการ บุคลากร แพทย์ หรือบุคคลอื่นที่ได้รับหรือเข้าถึงจากการปฏิบัติงาน
เข้าสู่ระบบปัญญาประดิษฐ์ (Artificial Intelligence: AI) ระบบสร้างหรือดัดแปลงภาพ เสียง หรือสื่อสังเคราะห์ หรือบริการออนไลน์ของบุคคลภายนอก เพื่อการสร้าง แก้ไข ดัดแปลง วิเคราะห์ ประมวลผล หรือวัตถุประสงค์อื่นใด
เว้นแต่ได้รับอนุมัติตามนโยบายและขั้นตอนของโรงพยาบาล มีฐานทางกฎหมายที่เหมาะสม และผ่านการประเมินด้านการคุ้มครองข้อมูลส่วนบุคคล ความมั่นคงปลอดภัยของข้อมูล และความเสี่ยงที่เกี่ยวข้องตามที่โรงพยาบาลกำหนด
การใช้ผลลัพธ์หรือเนื้อหาที่สร้างหรือประมวลผลโดยระบบ AI หรือบริการออนไลน์ของบุคคลภายนอกในการปฏิบัติงานหรือเผยแพร่ในนามของโรงพยาบาล
ต้องผ่านการตรวจสอบความถูกต้อง ความเหมาะสม สิทธิในการนำไปใช้ และความเสี่ยงด้านการคุ้มครองข้อมูลส่วนบุคคลและทรัพย์สินทางปัญญาตามขั้นตอนที่โรงพยาบาลกำหนดก่อนนำไปใช้หรือเผยแพร่
หมวดที่ 5 การใช้สื่อสังคมออนไลน์อย่างเหมาะสม
ข้อ 13 การแสดงความคิดเห็นอย่างเหมาะสม
บุคลากรพึงใช้สื่อสังคมออนไลน์ด้วยความสุภาพ มีความรับผิดชอบ และเคารพสิทธิและเสรีภาพของบุคคลอื่น ห้ามเผยแพร่ข้อความ ภาพ เสียง หรือเนื้อหาที่เป็นเท็จหรือบิดเบือนโดยมีเจตนาให้เกิดความเสียหาย
หมิ่นประมาท หรือมีลักษณะละเมิดสิทธิส่วนบุคคล เปิดเผยข้อมูลหรือความลับของผู้รับบริการ หรืออาจก่อให้เกิดความเสียหายแก่บุคคลอื่นหรือโรงพยาบาล ทั้งนี้ การใช้สื่อสังคมออนไลน์ต้องไม่ขัดต่อกฎหมาย ระเบียบ ข้อบังคับ และนโยบายของโรงพยาบาล
ข้อ 14 การไม่แอบอ้างโรงพยาบาล
ห้ามบุคลากรสร้างบัญชี เว็บไซต์ Page หรือ Group หรือช่องทางสื่อสังคมออนไลน์อื่นใด โดยใช้ชื่อ ตราสัญลักษณ์ เครื่องหมาย หรือข้อมูลของโรงพยาบาล
ในลักษณะที่อาจทำให้บุคคลทั่วไปเข้าใจว่าเป็นช่องทางการสื่อสารอย่างเป็นทางการของโรงพยาบาลโดยไม่ได้รับอนุญาต
ข้อ 15 การตอบข้อร้องเรียนและการแสดงความคิดเห็นของผู้รับบริการ
บุคลากรต้องไม่เปิดเผยข้อมูลส่วนบุคคล ข้อมูลสุขภาพ ประวัติการรักษาพยาบาล ผลการตรวจวินิจฉัย เวชระเบียน ภาพถ่ายทางการแพทย์ ข้อมูลการนัดหมาย หรือข้อมูลอื่นใดที่สามารถระบุตัวผู้รับบริการได้ไม่ว่าทางตรงหรือทางอ้อม
เพื่อโต้ตอบ ชี้แจง หรือแสดงความคิดเห็นต่อรีวิว ความคิดเห็น ข้อร้องเรียน หรือการสื่อสารของผู้รับบริการบนสื่อสังคมออนไลน์
การตอบข้อซักถาม ข้อคิดเห็น หรือข้อร้องเรียนของผู้รับบริการในนามโรงพยาบาล ให้ดำเนินการผ่านช่องทางและโดยผู้ที่โรงพยาบาลกำหนด โดยต้องไม่เปิดเผยข้อมูลส่วนบุคคล ข้อมูลสุขภาพหรือข้อมูลที่เป็นความลับของผู้รับบริการต่อสาธารณะ
และหากจำเป็นต้องตรวจสอบข้อมูลเฉพาะราย ให้ดำเนินการผ่านช่องทางที่เหมาะสมและมีมาตรการรักษาความมั่นคงปลอดภัยตามที่โรงพยาบาลกำหนด
หมวดที่ 6 การรายงานและจัดการเหตุละเมิดข้อมูลส่วนบุคคล
ข้อ 16 หน้าที่ในการรายงานเหตุละเมิดข้อมูลส่วนบุคคล
หากบุคลากรพบหรือสงสัยว่าเกิดเหตุการณ์ดังต่อไปนี้ ต้องแจ้งผู้บังคับบัญชา หน่วยงานที่รับผิดชอบด้านเทคโนโลยีสารสนเทศ ฝ่ายบริหาร หรือเจ้าหน้าที่คุ้มครองข้อมูลส่วนบุคคล (Data Protection Officer: DPO) โดยเร็วที่สุด ตามช่องทางที่โรงพยาบาลกำหนด
- ข้อมูลส่วนบุคคลของผู้รับบริการ บุคลากร หรือบุคคลอื่นที่ถูกเข้าถึง ใช้ เปิดเผยโดยไม่ได้รับอนุญาต
- มีการส่งข้อมูลส่วนบุคคลผิดบุคคล ผิดกลุ่มสนทนา หรือผิดช่องทาง
- มีการโพสต์หรือเผยแพร่ข้อมูลส่วนบุคคลบนสื่อสังคมออนไลน์โดยไม่ได้รับอนุญาต
- บัญชีผู้ใช้งาน ระบบ อุปกรณ์ หรือช่องทางสื่อสารของโรงพยาบาลถูกเข้าถึงโดยไม่ได้รับอนุญาต หรือมีเหตุอันควรสงสัยว่าถูกเข้าถึงโดยไม่ได้รับอนุญาต
- ข้อมูลส่วนบุคคลมีการสูญหาย ถูกขโมย หรือมีเหตุอันควรสงสัยว่าข้อมูลส่วนบุคคลอาจถูกเข้าถึง ใช้ เปลี่ยนแปลง เปิดเผยหรือทำลายโดยไม่ได้รับอนุญาต
บุคลากรต้องให้ความร่วมมือในการเก็บรักษาหลักฐาน ระงับเหตุ และดำเนินการตามกระบวนการจัดการเหตุละเมิดข้อมูลส่วนบุคคลของโรงพยาบาล
รวมทั้งต้องไม่ดำเนินการใดที่อาจทำให้หลักฐานที่เกี่ยวข้องสูญหาย ถูกเปลี่ยนแปลง หรือไม่สามารถตรวจสอบข้อเท็จจริงได้
ข้อ 17 การดำเนินการเมื่อเกิดเหตุละเมิดข้อมูลส่วนบุคคล (Personal Data Breach)
เมื่อโรงพยาบาลทราบหรือมีเหตุอันควรสงสัยว่าเกิดเหตุละเมิดข้อมูลส่วนบุคคล โรงพยาบาลจะดำเนินการตรวจสอบข้อเท็จจริง ประเมินระดับความเสี่ยงและผลกระทบที่อาจเกิดขึ้นต่อสิทธิและเสรีภาพของเจ้าของข้อมูลส่วนบุคคล
ระงับหรือจำกัดผลกระทบ เก็บรักษาหลักฐาน และดำเนินการตามกระบวนการจัดการเหตุละเมิดข้อมูลส่วนบุคคลของโรงพยาบาลและกฎหมายที่เกี่ยวข้อง
ในกรณีที่เหตุละเมิดข้อมูลส่วนบุคคลเข้าหลักเกณฑ์ที่ต้องแจ้งสำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล โรงพยาบาลในฐานะผู้ควบคุมข้อมูลส่วนบุคคลจะดำเนินการแจ้งโดยไม่ชักช้า และภายใน 72 ชั่วโมงนับแต่ทราบถึงเหตุละเมิดข้อมูลส่วนบุคคล
หรือตามระยะเวลาและหลักเกณฑ์ที่กฎหมายกำหนด
หากเหตุละเมิดข้อมูลส่วนบุคคลมีความเสี่ยงสูงต่อสิทธิและเสรีภาพของเจ้าของข้อมูลส่วนบุคคล โรงพยาบาลจะดำเนินการแจ้งเจ้าของข้อมูลส่วนบุคคลโดยไม่ชักช้า และดำเนินมาตรการที่เหมาะสมตามหลักเกณฑ์ที่กฎหมายกำหนด
ในการตรวจสอบหรือจัดการเหตุละเมิดข้อมูลส่วนบุคคล โรงพยาบาลอาจเก็บรักษาหลักฐานที่เกี่ยวข้อง เช่น ภาพหน้าจอ (Screenshot), URL, วันและเวลาที่เกิดเหตุ ข้อมูลการติดต่อสื่อสาร และข้อมูลของผู้เกี่ยวข้องเท่าที่จำเป็นต่อการตรวจสอบและจัดการเหตุ
ทั้งนี้ การเก็บรวบรวม ใช้ หรือเปิดเผยหลักฐานดังกล่าวต้องดำเนินการเท่าที่จำเป็น จำกัดสิทธิการเข้าถึง และรักษาความลับและความมั่นคงปลอดภัยของข้อมูลตามที่โรงพยาบาลกำหนด
กรณีหลักฐานมีความสำคัญต่อการดำเนินการทางวินัย การดำเนินคดี หรือการใช้สิทธิตามกฎหมาย ให้ดำเนินการเก็บรักษาและควบคุมหลักฐานตามกระบวนการที่โรงพยาบาลกำหนด เพื่อให้สามารถตรวจสอบที่มา ความถูกต้อง และการเปลี่ยนแปลงของหลักฐานได้ตามความเหมาะสม
หมวดที่ 7 การฝ่าฝืนนโยบายและความรับผิด
ข้อ 18 การดำเนินการกรณีฝ่าฝืน
บุคลากรผู้ใดฝ่าฝืนนโยบายฉบับนี้ อาจถูกดำเนินการทางวินัย ตามระเบียบ ข้อบังคับ หรือสัญญาที่เกี่ยวข้องของโรงพยาบาล แล้วแต่กรณี
หากการกระทำดังกล่าวเป็นการฝ่าฝืนกฎหมายหรือก่อให้เกิดความเสียหายแก่โรงพยาบาล ผู้รับบริการ บุคลากร หรือบุคคลอื่น ผู้กระทำอาจต้องรับผิดตามกฎหมายที่เกี่ยวข้อง ทั้งทางแพ่ง ทางอาญา หรือทางปกครอง แล้วแต่กรณี
ทั้งนี้ การพิจารณาความรับผิดของบุคลากร โรงพยาบาล หรือบุคคลที่เกี่ยวข้อง ให้พิจารณาตามข้อเท็จจริง พฤติการณ์ บทบาท หน้าที่และความรับผิดชอบ อำนาจในการควบคุมหรือเข้าถึงข้อมูล
เจตนาหรือระดับความประมาท ความเสียหายที่เกิดขึ้น ตลอดจนกฎหมาย ระเบียบ ข้อบังคับ และสัญญาที่เกี่ยวข้อง ทั้งนี้ การที่บุคลากรฝ่าฝืนนโยบาย ระเบียบ หรือคำสั่งของโรงพยาบาล ไม่ทำให้โรงพยาบาลพ้นจากหน้าที่หรือความรับผิดตามที่กฎหมายกำหนดโดยอัตโนมัติ
ข้อ 19 ความรับผิดชอบของบุคลากร
บุคลากรต้องรับผิดชอบต่อการใช้บัญชีผู้ใช้งาน อุปกรณ์ และข้อมูลที่อยู่ในความครอบครองหรือการควบคุมของตน และต้องปฏิบัติตามมาตรการรักษาความมั่นคงปลอดภัยของข้อมูลของโรงพยาบาลอย่างเคร่งครัด
บุคลากรต้องไม่กระทำการใด ๆ ที่อาจทำให้ข้อมูลส่วนบุคคลของผู้รับบริการ บุคลากรหรือบุคคลอื่น ถูกเข้าถึง ใช้ เปลี่ยนแปลง เปิดเผย สูญหาย หรือทำลายโดยไม่ได้รับอนุญาต
หมวดที่ 8 การบังคับใช้และการทบทวนนโยบาย
ข้อ 20 การบังคับใช้
นโยบายฉบับนี้ให้ใช้บังคับกับบุคลากรทุกระดับของโรงพยาบาล รวมถึงบุคคลภายนอกที่ได้รับอนุญาตให้เข้าถึงข้อมูล ระบบสารสนเทศ หรือทรัพย์สินดิจิทัลของโรงพยาบาล ในส่วนที่เกี่ยวข้องกับการปฏิบัติงาน
ทั้งนี้ บุคลากรทุกคนมีหน้าที่ศึกษา ทำความเข้าใจ และปฏิบัติตามนโยบายฉบับนี้ รวมถึงนโยบาย มาตรการ และระเบียบอื่นของโรงพยาบาลที่เกี่ยวข้องกับการคุ้มครองข้อมูลส่วนบุคคลและการรักษาความมั่นคงปลอดภัยของข้อมูล
ข้อ 21 การทบทวนและปรับปรุงนโยบาย
โรงพยาบาลจะทบทวนและปรับปรุงนโยบายฉบับนี้ให้เหมาะสมกับการเปลี่ยนแปลงของกฎหมาย เทคโนโลยี รูปแบบการใช้สื่อสังคมออนไลน์ และความเสี่ยงด้านการคุ้มครองข้อมูลส่วนบุคคลและความมั่นคงปลอดภัยของข้อมูลอย่างสม่ำเสมอ
เพื่อให้นโยบายมีความเหมาะสมและสอดคล้องกับสถานการณ์และกฎหมายที่ใช้บังคับ
หากข้อความใดในนโยบายฉบับนี้ขัดหรือแย้งกับกฎหมายที่มีผลใช้บังคับ ให้ถือปฏิบัติตามกฎหมายที่เกี่ยวข้องเป็นสำคัญ
นโยบายเกี่ยวกับการใช้สื่อสังคมออนไลน์ (Social Media) และการคุ้มครองข้อมูลส่วนบุคคล มีผลใช้บังคับตั้งแต่วันที่ 1 มิถุนายน 2565 เป็นต้นไป
SURAT EYE HOSPITAL ANNOUNCEMENT
Subject: Policy on the Use of Social Media and Personal Data Protection
Surat Eye Hospital recognizes the importance of the use of social media as an important channel for communication, public relations, the provision of health information, information exchange, and coordination both within and outside the organization. However, inappropriate use of social media may adversely affect the rights and freedoms of patients, personnel, and other individuals, and may also affect the confidentiality of Personal Data, data security, and the image and reputation of the Hospital.
To ensure that the collection, use, or disclosure of Personal Data through social media is carried out appropriately, securely, and in compliance with the Personal Data Protection Act B.E. 2562 (2019), the Computer-Related Crime Act, other applicable laws, professional ethical standards, as well as the Hospital's regulations and policies, the Hospital has established the following policies and guidelines for all personnel:
Section 1 Personal Data Protection and Confidentiality of Patients
Clause 1 Definitions
- “Social Media” means digital media or channels used to communicate, exchange, transfer, disseminate, or express opinions to individuals, groups of individuals, or the public through websites, applications, or information systems connected to the Internet, such as LINE, Facebook, Messenger, Instagram, TikTok, YouTube, X, and other similar social media platforms.
- “Personal Data” means any information relating to an individual that enables the identification of such individual, whether directly or indirectly, in accordance with the Personal Data Protection Act B.E. 2562 (2019).
- “Sensitive Personal Data” means Personal Data as prescribed under Section 26 of the Personal Data Protection Act B.E. 2562 (2019), including health data, medical treatment history, and other information falling within the categories prescribed by law. The determination of whether any information constitutes Sensitive Personal Data shall be in accordance with applicable laws and relevant criteria.
- “Personnel” means executives, physicians, dentists, nurses, pharmacists, officers, employees, workers, interns, contractors, and other persons performing work for the Hospital in accordance with the relationship or duties prescribed by the Hospital.
Clause 2 Confidentiality and Personal Data Protection
Personnel shall strictly maintain the confidentiality of and protect the Personal Data of patients, Personnel, and other individuals whose Personal Data the Hospital is responsible for collecting, using, or disclosing.
Personnel are prohibited from using, disclosing, disseminating, transferring, reproducing, or otherwise processing Personal Data through social media, unless there is an appropriate legal basis and such processing is within the scope of the duties, authority, purposes, and measures prescribed by the Hospital. This applies in particular to health data, medical treatment history, diagnostic results, medical records, medical images, photographs of patients, appointment information, patient numbers, and any other information that may identify a patient, whether directly or indirectly.
Clause 3 Publication of Photographs, Videos, and Patient Information
Personnel are prohibited from publishing or transferring photographs, videos, audio recordings, documents, medical records, test results, medical images, or any other information relating to patients through social media, unless there is an appropriate legal basis and such processing is carried out within the scope of the duties, authority, purposes, and measures prescribed by the Hospital.
Where it is necessary to use patient information or images for educational, research, training, public relations, or other purposes for which consent is required by law, Personnel shall obtain consent from the Data Subject in advance and shall provide the Data Subject with information regarding the purposes and relevant details as required by law.
Partially concealing or removing identifying information, such as a name, face, eyes, patient number, or other information, does not automatically render such information no longer Personal Data if the individual can still be linked to or identified from the information, whether directly or indirectly. Personnel shall assess the possibility of identifying the individual and the risk of identification before using or publishing such information each time.
Clause 4 Use of Personal Social Media Accounts
Personnel should not use personal social media accounts as the primary channel for contacting, communicating with, or providing medical services to patients, particularly for receiving, sending, or exchanging health data, medical records, test results, or Sensitive Personal Data, unless the Hospital has authorized such use and established appropriate measures to protect Personal Data and maintain data security.
Communication with patients regarding medical treatment, appointments, test results, or health data shall be conducted through systems or channels designated or approved by the Hospital and shall comply with the data security measures and guidelines prescribed by the Hospital.
Section 2 Use of Social Media and Internal Hospital Communication Systems
Clause 5 Responsibility for Disclosure of Information through LINE or Social Media
Personal Data, health data, messages, photographs, documents, or any other information that Personnel receive or have access to in the course of their duties through LINE Groups or the Hospital's social media channels shall be used or disclosed only to the extent necessary and consistent with the purposes of their work. Personnel shall also strictly comply with applicable laws, the Hospital's policies, and the Hospital's Personal Data protection measures.
The consent given by a Data Subject to the disclosure of information through LINE or social media does not constitute authorization for Personnel to use or further disclose such information for other purposes beyond the purposes, scope, or conditions of which the Data Subject has been informed and to which the Data Subject has consented. Any use or disclosure of Personal Data must have an appropriate legal basis and comply with the requirements prescribed by law.
Where Personnel use, disclose, transfer, disseminate, or otherwise seek to benefit from Personal Data or confidential information without authorization, or in violation of the Hospital's policies, regulations, or measures, and such action causes damage, the Personnel responsible may be held personally liable under applicable laws, regulations, rules, or contracts.
Personnel shall verify the recipient, chat group, user account, attached files or information, and the accuracy of the information before sending it each time, particularly Personal Data and health data. If information is sent to the wrong person, group, or channel, such incident shall be treated as an incident that must be reported without delay in accordance with the Hospital's Personal Data breach incident management process.
The Hospital shall not be responsible for such acts or violations. In the event of a Personal Data breach through LINE or social media, liability shall be considered based on the facts and the role of each party, including the following cases:
(1) Breach by Personnel within the Hospital
Where the Hospital provides a LINE Group or internal communication channel for work purposes and Personnel disclose, transfer, disseminate, or use Personal Data, health data, conversation messages, images, documents, or other information received or accessed through such channel for their own benefit or for the benefit of another person without authorization, or beyond the scope of their assigned duties and authority, the Personnel responsible may be held liable under applicable laws, regulations, rules, or contracts and may also be subject to disciplinary action in accordance with the Hospital's regulations.
The Hospital shall investigate the facts, assess the breach, and determine the duties and liability of the Hospital and each individual Personnel based on their respective roles, duties, authority, and the facts of the incident.
(2) Breach between Organizations or Departments
Where Personal Data is communicated or exchanged between the Hospital or a healthcare facility and another department or organization through a LINE Group or social media, and Personal Data is unlawfully accessed, used, or disclosed, the Hospital shall investigate the facts and determine the role of each party, whether as a Data Controller, Data Processor, or a person assigned or authorized to access the data, as applicable.
Any person who discloses or uses information without authority or beyond the scope of their duties may be held personally liable under applicable laws, as the case may be. This shall not relieve the Hospital or relevant organization of any duties or liability imposed by law.
(3) Breach by External Persons or Personnel Who Have Ceased Performing Their Duties
Where Personnel have ceased to hold their position or have ended their employment but continue to have access to a LINE Group, information system, or communication channel of the Hospital and disclose, transfer, or disseminate Personal Data, health data, messages, images, documents, or other information without authorization, such persons may be held personally liable under applicable laws and relevant requirements.
The Hospital shall promptly revoke or suspend the access rights of Personnel who have ceased performing their duties. Where an incident occurs or there are reasonable grounds to suspect that a Personal Data Breach has occurred, the Hospital shall investigate the incident, assess the risks, mitigate or limit the impact, preserve evidence, and take action in accordance with the Hospital's Personal Data Breach incident management process and applicable laws.
(4) Breach by External Persons
Where an external person who is not authorized to access the Hospital's Personal Data gains unauthorized access to, uses, discloses, or disseminates such Personal Data, the Hospital shall take action in accordance with the established security measures and Personal Data breach incident management process. The Hospital shall also assess the incident and determine whether notification to the Personal Data Protection Committee or the Data Subject is required, as applicable, when the relevant criteria are met and within the period prescribed by law.
In determining the duties and liability of Personnel, the Hospital, or any relevant person, consideration shall be given to the facts, circumstances, intent or degree of negligence, roles, duties and authority relating to the control of or access to the data, as well as applicable laws, regulations, rules, security measures, and contracts, as applicable.
Clause 6 Security of User Accounts
Personnel shall keep usernames, passwords, authentication codes, and information used to access the Hospital's communication systems or information systems confidential. Personnel must not disclose their passwords, allow another person to use their user account, or allow another person to access their user account or any device used to access the Hospital's information without authorization. If Personnel discover or suspect that a user account, device, or Hospital system has been accessed or used without authorization, they must immediately notify their supervisor, the department responsible for information technology, or the Data Protection Officer (DPO) through the channels designated by the Hospital.
Clause 7 Use of Data for Specified Purposes and to the Extent Necessary
Personnel shall use or disclose Personal Data only to the extent necessary and consistent with the purposes of their work, within the scope of their assigned duties and authority, and shall not use or disclose Personal Data for their own benefit or for purposes unrelated to their duties, unless there is an appropriate legal basis or authorization as prescribed by law.
Section 3 Management of the Hospital’s Official Communication Channels
Clause 8 Establishment of Official Pages or Accounts
The establishment of any Page, Group, Account, website, or social media channel in the name of the Hospital or any department within the Hospital must be approved in advance by the authorized person designated by the Hospital. A responsible person and system administrator must be clearly designated, and access rights must be appropriately assigned based on their respective duties and responsibilities. When Personnel cease to perform their duties, change positions, are transferred, resign, have their employment terminated, or otherwise cease to have access rights to the Hospital's information or systems, the Hospital shall promptly review, modify, suspend, or revoke the relevant access rights, as appropriate.
Any modification, suspension, or revocation of access rights shall cover user accounts, chat groups, Pages, social media accounts, cloud systems, email, LINE applications, VPNs, and the Hospital's information systems or other communication channels to which Personnel have access. Such actions shall be carried out in accordance with the Hospital's access control procedures.
Personnel who cease to perform their duties must return or hand over any equipment, accounts, access rights, information, and digital assets of the Hospital in their possession or under their responsibility. They must not retain, copy, use, or access the Hospital's information or systems after their access rights have ended, unless authorized by the Hospital or required by law.
Clause 9 Publication of Information on Behalf of the Hospital
The publication of news, public relations materials, medical information, photographs of activities, or any other information on behalf of the Hospital must be reviewed and approved in accordance with the procedures prescribed by the Hospital prior to publication. The person responsible for publication must verify the accuracy and appropriateness of the information, as well as their rights or authority to use such information, and must not disclose Personal Data or confidential information without authorization or an appropriate legal basis.
Clause 10 Expression of Personal Opinions
Personnel may use social media in their personal capacity, provided that they do not make statements or engage in conduct that may lead the public to believe that they are expressing an official statement or opinion on behalf of the Hospital, unless they have been assigned or authorized by the Hospital to do so. Where an expression of opinion may give rise to an understanding that the opinion is expressed on behalf of the Hospital, Personnel must clearly state that it is their personal opinion and does not constitute an official statement or position of the Hospital.
Section 4 Protection of Internal Information and Intellectual Property
Clause 11 Protection of Internal Information and Intellectual Property
Personnel must not disclose, publish, reproduce, modify, or use the Hospital's internal information, confidential information, business information, information relating to business partners, internal documents, forms, work systems, databases, manuals, work processes, trademarks, photographs, or intellectual property for their own benefit or for the benefit of any external person without authorization. Any disclosure or publication of such information must be authorized by the person designated by the Hospital and must not violate applicable laws, the rights of other persons, or contractual requirements.
Clause 12 Use of Artificial Intelligence and Third-Party Online Services
Personnel must not import, input, upload, transmit, or disclose photographs, audio, videos, Personal Data, health data, internal information, or confidential information of patients, Personnel, physicians, or other persons that they receive or have access to in the course of their duties into Artificial Intelligence (AI) systems, systems for generating or modifying images, audio, or synthetic media, or third-party online services for the purposes of creating, editing, modifying, analyzing, processing, or any other purpose, unless such use has been approved in accordance with the Hospital's policies and procedures, there is an appropriate legal basis, and the relevant Personal Data protection, information security, and risk assessments have been conducted in accordance with the requirements prescribed by the Hospital.
The use of any output or content generated or processed by AI systems or third-party online services in the course of work or for publication on behalf of the Hospital must undergo verification of its accuracy, appropriateness, rights to use, and risks relating to Personal Data protection and intellectual property in accordance with the procedures prescribed by the Hospital before such output or content is used or published.
Section 5 Appropriate Use of Social Media
Clause 13 Appropriate Expression of Opinions
Personnel should use social media in a courteous and responsible manner and respect the rights and freedoms of others. Personnel must not publish or disseminate any false or misleading statements, images, audio, or other content with the intent to cause damage, defame any person, or otherwise violate personal rights, disclose information or confidential information of patients, or cause or potentially cause damage to any person or the Hospital. The use of social media must not violate applicable laws, regulations, rules, or the Hospital's policies.
Clause 14 Prohibition of Impersonation of the Hospital
Personnel must not create an account, website, Page, Group, or any other social media channel using the Hospital's name, logo, trademark, or information in a manner that may cause the general public to believe that such channel is an official communication channel of the Hospital without authorization.
Clause 15 Responding to Complaints and Comments from Patients
Personnel must not disclose Personal Data, health data, medical history, medical examination results, medical records, medical images, appointment information, or any other information that may directly or indirectly identify a patient for the purpose of responding to, clarifying, or commenting on reviews, comments, complaints, or communications from patients on social media.
Responses to inquiries, comments, or complaints from patients on behalf of the Hospital shall be made through the channels and by the persons designated by the Hospital. Such responses must not disclose Personal Data, health data, or confidential information of patients to the public.
Where it is necessary to verify information relating to a specific patient, such verification shall be conducted through an appropriate channel and with security measures in accordance with the requirements prescribed by the Hospital.
Section 6 Reporting and Management of Personal Data Breaches
Clause 16 Duty to Report Personal Data Breaches
If Personnel become aware of or suspect that any of the following incidents has occurred, they must notify their supervisor, the department responsible for information technology, the management, or the Data Protection Officer (DPO) as soon as possible through the channels designated by the Hospital:
- Personal Data of patients, Personnel, or other persons has been accessed, used, or disclosed without authorization.
- Personal Data has been sent to the wrong person, chat group, or channel.
- Personal Data has been posted or disseminated on social media without authorization.
- A user account, system, device, or communication channel of the Hospital has been accessed without authorization, or there are reasonable grounds to suspect that it has been accessed without authorization.
- Personal Data has been lost or stolen, or there are reasonable grounds to suspect that Personal Data may have been accessed, used, altered, disclosed, or destroyed without authorization.
Personnel must cooperate in preserving evidence, containing the incident, and taking action in accordance with the Hospital's Personal Data breach incident management process. Personnel must not take any action that may cause relevant evidence to be lost, altered, or become unavailable for factual investigation.
Clause 17 Actions in the Event of a Personal Data Breach
When the Hospital becomes aware of or has reasonable grounds to suspect that a Personal Data breach has occurred, the Hospital shall investigate the facts, assess the level of risk and potential impact on the rights and freedoms of the Data Subjects, contain or limit the impact, preserve evidence, and take action in accordance with the Hospital's Personal Data breach incident management process and applicable laws.
Where a Personal Data breach meets the criteria requiring notification to the Personal Data Protection Committee, the Hospital, as the Data Controller, shall notify the Personal Data Protection Committee without delay and within 72 hours from the time the Hospital becomes aware of the breach, or within such period and in accordance with such criteria as prescribed by law.
Where a Personal Data breach is likely to result in a high risk to the rights and freedoms of the Data Subjects, the Hospital shall notify the Data Subjects without delay and take appropriate measures in accordance with the criteria prescribed by law.
In investigating or managing a Personal Data breach, the Hospital may retain relevant evidence, such as screenshots, URLs, the date and time of the incident, communication records, and information relating to persons involved, to the extent necessary for the investigation and management of the incident. The collection, use, or disclosure of such evidence shall be limited to what is necessary, access shall be restricted, and the confidentiality and security of the information shall be maintained in accordance with the requirements prescribed by the Hospital.
Where evidence is material to disciplinary proceedings, legal proceedings, or the exercise of legal rights, such evidence shall be retained and controlled in accordance with the procedures prescribed by the Hospital to enable, as appropriate, verification of the origin, accuracy, and integrity of the evidence.
Section 7 Policy Violations and Liability
Clause 18 Actions in the Event of a Violation
Any Personnel who violates this Policy may be subject to disciplinary action in accordance with the Hospital's applicable regulations, rules, or contracts, as applicable. If such conduct constitutes a violation of applicable law or causes damage to the Hospital, patients, Personnel, or any other person, the person responsible may be held liable under applicable law, whether civil, criminal, or administrative, as applicable.
In determining the liability of Personnel, the Hospital, or any relevant person, consideration shall be given to the facts, circumstances, roles, duties and responsibilities, authority to control or access the information, intent or degree of negligence, resulting damage, as well as applicable laws, regulations, rules, and contracts. The violation of this Policy, the Hospital's regulations, or orders by Personnel shall not automatically relieve the Hospital of any duties or liability imposed by law.
Clause 19 Responsibilities of Personnel
Personnel shall be responsible for the use of user accounts, devices, and information in their possession or under their control, and shall strictly comply with the Hospital's information security measures. Personnel must not engage in any act that may result in the Personal Data of patients, Personnel, or any other person being accessed, used, altered, disclosed, lost, or destroyed without authorization.
Section 8 Enforcement and Review of the Policy
Clause 20 Enforcement
This Policy shall apply to all levels of Personnel of the Hospital, as well as external persons who are authorized to access the Hospital's information, information systems, or digital assets in connection with their work. All Personnel are responsible for studying, understanding, and complying with this Policy, as well as other policies, measures, and regulations of the Hospital relating to Personal Data protection and information security.
Clause 21 Review and Amendment of the Policy
The Hospital shall regularly review and amend this Policy as appropriate to reflect changes in applicable laws, technology, patterns of social media use, and risks relating to Personal Data protection and information security, in order to ensure that the Policy remains appropriate and consistent with prevailing circumstances and applicable laws.
If any provision of this Policy conflicts or is inconsistent with applicable law, the applicable law shall prevail.
The Policy on the Use of Social Media and Personal Data Protection shall take effect from 1 June 2022 onwards.
(Dr. Banyong Chinkulkitnivat)
Director
Surat Eye Hospital