ZUH-Filing
Privacy Policy
Effective July 8, 2026
Overview
ZUH-Filing is a clinical information system intended for authorized healthcare professionals. This policy explains how information is collected, used, stored, and protected when the ZUH-Filing website and mobile application are used.
Information We Process
ZUH-Filing may process the following information:
- User account information, including name, email address, phone number, user ID, role, and workplace information.
- Patient identification, demographic, and contact information.
- Health and medical information, including admissions, diagnoses, clinical forms, notes, laboratory results, care actions, transfers, and discharge summaries.
- Sensitive information recorded as part of legitimate clinical care.
- Clinical images, drawings, and files uploaded to patient records.
- Patient searches and application activity.
- Audit records, including access to patients, admissions, forms, and discharge summaries.
How Information Is Used
Information is processed to:
- Authenticate authorized users and enforce role-based access.
- Provide clinical documentation and patient-management functionality.
- Maintain medical records and support continuity of care.
- Protect the system from unauthorized access and misuse.
- Maintain audit trails and investigate security or operational incidents.
- Provide technical support and maintain system reliability.
ZUH-Filing does not sell personal information and does not use personal or medical information for advertising, marketing, or cross-app tracking.
Access and Disclosure
Information is available only to authorized healthcare personnel and system administrators according to their assigned permissions. It may be processed by infrastructure or service providers that are necessary to operate and secure the system. Those providers are expected to process information only to provide their contracted services.
Information may also be disclosed when required by law, an applicable regulatory obligation, a legitimate patient-care requirement, or an authorized institutional request.
Storage and Security
Information is transmitted using encrypted network connections. Access is protected through authenticated accounts, role-based permissions, and audit logging. Users must protect their credentials, secure their devices, and promptly report suspected unauthorized access.
No electronic system can guarantee absolute security, but reasonable technical and organizational safeguards are maintained to reduce unauthorized access, alteration, disclosure, or loss.
Data Retention
Clinical and audit records are retained according to the healthcare institution's medical-record retention requirements, applicable law, and legitimate operational requirements. Information removed from active systems may remain in protected backups for a limited period.
Privacy Requests
Requests to access, correct, restrict, or delete information must be submitted to the healthcare institution responsible for the relevant record or to its authorized ZUH-Filing administrator. Requests are handled according to applicable law and institutional medical-record policies. Some clinical and audit records cannot be deleted where retention is legally, medically, or operationally required.
Children's Information
ZUH-Filing is intended for authorized healthcare professionals and is not directed to children. Patient records may include information about minors when necessary for legitimate healthcare purposes.
Changes to This Policy
This policy may be updated to reflect changes to the service, institutional practices, or legal requirements. The effective date shown at the top of this page will be updated when changes are published.
Contact
For privacy questions or requests, contact the administration of the healthcare institution that provided your ZUH-Filing account or its authorized system administrator.
Application design and development by Mahmod Saber.