Privacy policy
- Measures to safeguard personal information and the IBM Japan Health Association's efforts
- Basic policy regarding protection of personal information (Privacy Policy)
- Disclosure of purpose of use of personal information held by the IBM Japan Health Insurance Association
- About personal data held
- Providing personal information to third parties
- Anonymized information
- Inquires
- Accredited Personal Information Protection Organization the Association belongs to
Measures to safeguard personal information and the IBM Japan Health Association's efforts
As part of its routine activities, the Health Insurance Association handles personal information concerning insured persons and dependents, including eligibility and benefits information and medical care records.
While the Association has always handled personal information with the utmost care, the standards and other rules with which the Association must comply when handling personal information have been codified since full enactment of the Personal Information Protection Act in April 2005.
We will provide here an overview of the Health Insurance Association’s various measures to safeguard personal information. Note that certain exceptions and other considerations may apply; please contact the Association for more information.
- Specified purposes of use, restrictions on use for other purposes
When handling personal information, the Association will specify whenever and to the extent possible the purposes for which such information is used. It will refrain from using the information for any other purpose without prior consent from the individual in question. - Notification and announcement of purposes of use
When it obtains personal information, the Association will notify the individuals in question of the purposes of use, either by notifying individuals personally or by announcement via pamphlets, the Association website, or other means. - Obtaining personal information by appropriate means and ensuring the accuracy of personal data
The Association will never seek to obtain personal information through inappropriate means. Additionally, to the degree possible, it strives to ensure the accuracy of the personal data obtained, given the purpose of use. - Safeguards, security measures and supervision of employees and subcontractors
In addition to maintaining and publishing rules on protecting personal information, the Association strives to ensure the secure management of such information. It also supervises employees and business subcontractors assigned responsibility for handing personal information. - Restrictions on providing personal data to third parties
In principle, personal data will not be provided to third parties without consent from the individuals in question. - Disclosure, correction, and cessation of use of personal information
If the individual to whom the personal information pertains requests the disclosure of such information or asks through appropriate procedures to have it corrected or its use suspended, the Association will generally comply with such request. It will also seek to respond to complaints as quickly as possible.
Basic policy regarding protection of personal information (Privacy Policy)
The IBM Japan Health Insurance Association takes the following measures to safeguard information concerning individual members and employees (“personal information” hereinafter), based on a philosophy of respect for individual rights.
- The Health Insurance Association implements appropriate safety measures to safeguard personal information it obtains concerning members against leaks, loss, damage, or unauthorized access.
- The Health Insurance Association uses the personal information provided by members solely for purposes considered beneficial for members, including health maintenance and health promotion. It uses Individual Numbers only within the scope of the purposes specified in the Act on the Use of Numbers to Identify a Specific Individual in Administrative Procedures.
- Except when it has obtained prior consent from the member in question, the Health Insurance Association will not provide personal information to any third party. Nor will it provide personal information containing Individual Numbers (“identifying personal information” hereinafter), whether or not the individual has consented, except in the cases specified in the Act on the Use of Numbers to Identify a Specific Individual in Administrative Procedures. However, it may provide personal information on members other than identifying personal information to third parties without obtaining advance consent from members in cases that fall under any of the Subparagraphs in Article 27, Paragraph 1 of the Act on the Protection of Personal Information (Act no. 57 of May 30, 2003).
- In addition to implementing activities related to training and promoting awareness among employees regarding the protection of personal information, the Health Insurance Association will strive to manage personal information appropriately by assigning persons responsible for such management within each section that handles personal information.
- When subcontracting business operations, the Health Insurance Association will carry out reviews and implement improvements to strengthen personal information protection measures. When concluding business subcontracting agreements, it will fully review the competence of subcontractors and incorporate provisions in such agreements that provide for personal information protection.
- A member who wishes to review, revise, or otherwise access his or her personal information may contact the Health Insurance Association’s Privacy Contact. The contact will respond swiftly to such requests within the extent reasonable.
- In addition to complying with laws, regulations, and other standards concerning the handling of personal information and with its personal information protection management system, the Health Insurance Association will continually review and strive to improve this Privacy Policy.
IBM Japan Health Insurance Association
Shunichi Yamaguchi, Chairman of the Board
Established: July 15, 2004
Revised: February 22, 2024
Disclosure of purpose of use of personal information held by the IBM Japan Health Insurance Association
Personal information held by the Association for business purposes
Main purposes of use expected in ordinary operations of the Health Insurance Association
About personal data held
The following are matters that must be made readily accessible to the individual in question (including cases in which replies will be made without delay to requests from the individual in question) pursuant to the Act on the Protection of Personal Information and JIS standards:
(1) Name, address, and representative of business operator handling personal information
Name: The IBM Japan Health Insurance Association
Address: 36-2 Nihonbashi Hakozakicho, Chuo-ku, Tokyo
Name of representative: Shunichi Yamaguchi
(2) Title, affiliation, and contact information of person in charge of management of personal information protection
Title: Managing Director
For contact information, see "Inquiries."
(3) Personal information held by the Health Insurance Association
See "Personal information held by the Association for business purposes."
(4) Main purposes of use expected in ordinary operations of the Health Insurance Association
See "Main purposes of use expected in ordinary operations of the Health Insurance Association."
(5) Where to submit complaints concerning handling of personal data held
See "Inquiries."
(6) Name of accredited personal information protection organization and complaint resolution contact
See "Accredited Personal Information Protection Organization the Association belongs to."
(7) Procedures in response to requests for disclosure, etc.
For security purposes, the Health Insurance Association discloses personal information subject to disclosure to members in writing and through other means after completing the designated procedures in writing, including reviews of personal identification documents. However, information may not be disclosed, in whole or in part, in the following cases:
- (1) Cases in which disclosure may be detrimental to the life, safety, property, or other interests of the individual concerned or of a third party
- (2) Cases in which disclosure may markedly impede the appropriate execution of Health Insurance Association operations
- (3) Cases in which disclosure would violate laws and regulations
Procedures for personal data disclosure
Articles 25 and 29 of the Act and Articles 7 and 8 of Cabinet Order No. 507 require the Health Insurance Association to establish procedures for requesting the disclosure of personal data held by it. The Association's procedures are outlined below. However, disclosure of rezepts will be handled in accordance with the June 20, 2011 notice (HIB No. 0620-1) from the Director of the Health Insurance Bureau of the Ministry of Health, Labour and Welfare, “Partial revision of ‘Disclosure of medical cost details and other information to insured persons.’”
- Disclosure may be requested by: the individual in question or his or her agent
- Agents: (A) Legal agent of a minor or an adult ward
(B) An agent entrusted by the individual in question to submit/handle the request for disclosure - How to submit requests for disclosure: In writing (Spoken requests and requests submitted by telephone, fax, email, or other means will not be accepted.) Requests may be submitted by post if delivery in person would be difficult.
- Submit to: Managing Director, IBM Japan Health Insurance Association
- Required information: Applicant name (and name of agent if submitting request via an agent), date and time of request, personal data for which disclosure is requested (indicate whether disclosure requested is for all or only part of such data—for example, data for a certain period of time)
- Document to attach: Document certifying that the applicant is the individual in question (or his or her agent)
Procedures for correction or cessation of use of personal data
Pursuant to the Health Insurance Act, personal data held by the Health Insurance Association concerning its members cannot in principle be deleted at the member’s request, since most information comes from sources such as notices pursuant to the Health Insurance Act. Except for voluntarily and continuously insured persons or special-case retired insured persons, each member must be covered by the health insurance of the association his or her employer joins. As was the case previously, corrections and additions require submission of notices of change or correction. While members retain the right to demand the cessation of use of personal data, in most cases, this would result in the inability to provide benefits or administer health examinations and is likely to be counter to the interests of the member with respect to other health activities.
- How to submit requests: In writing (Spoken requests and requests submitted by telephone, fax, email, or other means will not be accepted.) However, for ordinary corrections, please continue to submit the required notice.
- Submit to: Managing Director, IBM Japan Health Insurance Association
- Required information: Applicant name, date and time of request, nature of request, reason for request
Note: Please explain your request in the greatest possible detail. Identify the personal data and clearly indicate whether the request concerns all or part of the data.
(8) Measures implemented for safe management of personal data held
- Formulation of basic policies
The Association formulates basic policies on matters such as compliance with applicable laws, regulations, and guidelines and contact points for questions and complaints to ensure the appropriate handling of personal data. - Maintenance of rules on handling of personal data
The Association formulates rules on handling of personal data, covering matters such as methods of handling, persons responsible and in charge, and their duties, for each stage including data collection, use, storage, provision, and deletion/disposal. - Organizational measures for safe management
In addition to appointing persons responsible for handling personal data, the Association clearly defines which employees handle personal data and the scope of the personal data handled by them. The Association maintains structures for reporting to and communicating with the persons responsible in the event that a violation of laws or rules on handling is discovered or suspected.
The state of handling of personal data is subject to periodic self-inspections, as well as audits by other sections or external parties. - Personnel measures for safe management
Periodic training is provided for employees concerning points to note regarding the handling of personal data.
Contacts are concluded with employees on the confidentiality of personal data. - Physical measures for safe management
In addition to controlling employee entry to and exit from zones in which personal data is handled and controlling devices and other items brought into such zones, measures are implemented to prevent unauthorized persons from viewing personal data.
In addition to measures to prevent incidents such as theft or loss of devices, digital media, documents, and other materials used in the handling of personal data, measures are taken to ensure that personal data cannot be readily identified when transporting such devices, digital media, etc., including transportation within a business site. - Technological measures for safe management
Systems are adopted to implement access controls, limit persons in charge and scope of personal information databases and other information handled, and protect information systems used to handle personal data from unauthorized access and malware.
Providing personal information to third parties
Pursuant to the Ministry of Health, Labour and Welfare guidelines mentioned above, the Association provides the following notices concerning the provision of personal information to third parties. The insured person or other individual in question is regarded to have given his or her implied and comprehensive consent when no explicit objection or reservation is raised by him or her in cases in which the purpose is to engage in actions and measures that would benefit the insured person, cases in which obtaining explicit consent would impose unreasonable burdens due to changes in current methods of notification of medical care costs, amounts of benefits paid, or other information, or cases in which obtaining explicit consent may prove unreasonable from the point of view of the individual in question. Since notification of medical care costs and amounts of benefits paid includes items concerning family members in addition to insured persons, this also applies to family members.
- To provide notification of medical care costs, notification of determination of benefits and notification of generic drug paid for the entire household, including dependents (family members)
- To provide statutory and additional benefits (including funeral expenses, injury and sickness allowance, childbirth and childcare lump-sum grant, and maternity allowance) through the employer
- To enable automated payment of high-cost medical care benefits through the employer without application by the individual in question
- For the following purposes to avoid duplicated benefits when a rezept involves aid for medical care costs from a municipal government or other government agency:
- a) To consult with the medical care institution to confirm whether the insured person paid the cost
- b) To consult with municipal government or other government agency to confirm whether public medical aid is available
- To allow payment of subsidies through the employer when the insured person applies for subsidies in health activities undertaken by the Health Insurance Association
- To send notices of eligibility information to insured persons in household units
Cases not qualifying as provision to third parties under the Act on Protecting Personal Information
- Cases that fall under any of Subparagraphs in Article 27 (Restriction of Provision to A Third Party), Paragraph 1 of the Act are not deemed as provision to third parties.
- In cases that fall under any of Subparagraphs in Article 27, Paragraph 5 of the Act, those who receive provision of personal information are not deemed as third parties.
(A) Items of personal data subject to shared use |
---|
|
|
(B) Scope of parties involved in shared use |
|
(C) Purposes of use of parties involved in shared use |
For activities undertaken with the National Federation of Health Insurance Associations pursuant to Article 2 of the Additional Rules to the Health Insurance Act For activities related to the Health Insurance Association undertaken with the employer ((1) various health promotion programs, (2) analysis for planning and drafting of disease-prevention programs, (3) activities related to health insurance) |
(D) Party responsible for management |
IBM Japan Health Insurance Association 36-2 Nihonbashi Hakozakicho, Chuo-ku, Tokyo Chairman of the Board Shunichi Yamaguchi |
Anonymized information
The IBM Japan Health Insurance Association hereby publishes the following information regarding anonymously processed information.
- The Association periodically prepares anonymized information by deleting the following items from rezepts and health examination information or replacing them with other descriptions, rendering the original data unrecoverable.
Deleted: Member names, dates of birth, ages, insured person codes, doctors' names
Replaced: Names of medical care institutions, rezept IDs, member IDs - Anonymized information is provided periodically to third parties through established secure methods for purposes such as benchmarking analysis with other health insurance societies and epidemiological studies.
Information provided to: IQVIA Solutions Japan G.K.
: PREVENT Inc.
Inquires
The IBM Japan Health Insurance Association
Personal information protection office
(Available hours: 9:00 - 17:00, Monday - Friday excl. national holidays)
In case you may contact by Web
Accredited Personal Information Protection Organization the Association belongs to
The IBM Japan Health Insurance Association is certified as an independent agency to adequately safeguard personal information and to be in compliance with the Japan Industrial Standard JISQ 15001.
If you have any inquiries or complaints about the Association processing of personal information, you may contact as below.
JIPDEC Personal Information Protection Consultation Service Office.
〒106-0032Roppongi First Building, 9-9 Roppongi 1-chome,
Minato-ku Tokyo
Tel: 03-5860-7565, 0120-700-779