Privacy Policy
This policy explains how HIITS collects, uses, protects, and shares personal data and protected health information in compliance with applicable data protection laws and healthcare regulations.
1. Overview & Scope
Who We Are
HIITS (Healthcare Integrated Intelligent Technology Solutions) is a healthcare technology company providing hospital information systems, electronic health record (EHR) software, patient safety management tools, accreditation compliance platforms, and clinical analytics solutions to healthcare institutions across the Middle East.
Scope of This Policy
This Privacy Policy applies to all personal data and protected health information (PHI) processed through HIITS software platforms, websites, mobile applications, APIs, and related services. It governs data collected from healthcare institution clients, their patients, clinical staff, administrators, and visitors to our corporate website.
Regulatory Framework
HIITS operates in compliance with the Saudi Personal Data Protection Law (PDPL) and its implementing regulations, the Jordan Personal Data Protection Law, applicable GCC data protection frameworks, international standards including ISO 27001 and ISO 27799 (health informatics), and accreditation body requirements from JCI, CBAHI, and MOH.
2. Data We Collect
Healthcare Institution Data
When a hospital or healthcare facility subscribes to HIITS services, we collect: institution name, registration and licensing numbers, authorized administrator contact details (name, title, work email, work phone), billing and contract information, and technical configuration data required to provision the platform.
Clinical & Patient Data (PHI)
HIITS processes protected health information on behalf of our healthcare institution clients as a data processor. This includes patient demographics, clinical records, diagnostic data, medication histories, incident reports, and credentialing records. HIITS does not own this data — the healthcare institution is the data controller and is responsible for obtaining appropriate patient consent under applicable law.
Staff & User Data
For clinical staff, administrators, and other authorized users of the HIITS platform, we collect: full name, professional credentials and license numbers, role and department, work email address, system access logs, and activity records within the platform for audit and compliance purposes.
Website & Technical Data
When you visit our corporate website, we may collect: IP address, browser type and version, pages visited, time spent, referral source, and device information. This data is used solely for website performance analysis and security monitoring.
3. How We Use Your Data
Service Delivery
We use collected data to provision, operate, maintain, and support the HIITS platform; to authenticate users and enforce access controls; to generate clinical reports, dashboards, and analytics; and to process incident reports, accreditation workflows, and credentialing records as directed by the healthcare institution.
Compliance & Accreditation
Data is processed to support healthcare institutions in meeting their JCI, CBAHI, MOH, and other regulatory reporting obligations. Audit logs and access records are maintained as required by applicable healthcare regulations and accreditation standards.
Security & Fraud Prevention
We analyze access patterns and system logs to detect unauthorized access, data breaches, and security threats. This processing is necessary for the protection of patient data and the integrity of clinical systems.
Product Improvement
We may use aggregated, de-identified, and anonymized data to improve platform features, develop new capabilities, and conduct research. No individually identifiable patient or staff data is used for this purpose without explicit consent.
4. Data Sharing & Disclosure
We Do Not Sell Your Data
HIITS does not sell, rent, or trade personal data or protected health information to any third party for commercial purposes.
Service Providers
We engage carefully vetted sub-processors (cloud infrastructure providers, security monitoring services, and technical support partners) who process data solely on our instructions under binding data processing agreements that meet PDPL and applicable international standards.
Healthcare Institution Clients
Patient and clinical data is shared with the healthcare institution that is the data controller for that data. HIITS acts as a data processor and follows documented instructions from the institution regarding data access, retention, and deletion.
Legal Requirements
We may disclose data when required by applicable law, court order, or regulatory authority — including the Saudi National Cybersecurity Authority (NCA), the Saudi Data & AI Authority (SDAIA), or equivalent bodies in other jurisdictions where we operate. We will notify the relevant data controller where legally permitted.
5. Data Security
Technical Safeguards
HIITS implements industry-standard security controls including AES-256 encryption at rest and TLS 1.3 in transit, role-based access control (RBAC) with least-privilege principles, multi-factor authentication for all administrative access, continuous intrusion detection and monitoring, and regular penetration testing by independent security firms.
Organizational Safeguards
All HIITS personnel with access to client data undergo background checks, sign confidentiality agreements, and receive annual data protection and security training. Access to production systems is restricted to authorized personnel on a need-to-know basis.
Incident Response
In the event of a data breach affecting personal data, HIITS will notify affected healthcare institution clients within 72 hours of becoming aware of the breach, in accordance with PDPL Article 24 and applicable notification requirements. We maintain a documented incident response plan tested annually.
Data Residency
Healthcare institution data is stored in data centers located within the Kingdom of Saudi Arabia or the client's specified jurisdiction unless otherwise agreed in writing. Cross-border transfers are conducted only under appropriate legal mechanisms as required by PDPL.
6. Your Rights
Rights Under PDPL and Applicable Law
Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data where no legal retention obligation applies; object to or restrict certain processing; and receive a copy of your data in a portable format. Healthcare institutions may exercise these rights on behalf of their patients in accordance with applicable clinical data regulations.
How to Exercise Your Rights
Submit a written request to [email protected]. We will respond within 30 days. For requests relating to patient data held within a healthcare institution's HIITS deployment, we will direct you to the relevant institution as the data controller.
Retention & Deletion
We retain personal data for as long as necessary to provide services and meet legal obligations. Clinical records are retained in accordance with the healthcare institution's retention policy and applicable MOH regulations. Upon contract termination, client data is securely deleted or returned within 90 days per the terms of the data processing agreement.
7. Contact Our Data Protection Team
For privacy inquiries, data subject rights requests, or to report a data protection concern, contact our Data Protection Officer:
We will acknowledge your request within 5 business days and provide a substantive response within 30 days. For urgent matters involving potential data breaches, please call our security hotline directly.