MEMBER CONSENT AND DATA PRIVACY TERMS
(For Maxicare Healthcare Corporation, Maxicare Health Services, Inc., and Maxicare Life Insurance Corporation)
This Member Consent applies to and is effective for:
Collectively, the above are referred to as the “Maxicare Group.” Your consent shall be
deemed as having been provided to the Maxicare Group as a whole, directly to the
company providing services to you, or indirectly for services and purposes empowered by
data sharing.
I. PURPOSE
This Consent governs how the Maxicare Group collects, uses, processes, stores, shares,
retains, and disposes of your personal data and sensitive personal information in
accordance with:
- Republic Act No. 10173 or the Data Privacy Act of 2012;
- Its Implementing Rules and Regulations and
- NPC Circular No. 2023-04 on the Guidelines on Consent.
II. DEFINITION OF TERMS
For purposes of this Member Consent, the following terms shall have the meanings set forth below:
-
“Agreement” - Refers to any Service Agreement, Policy Contract, Membership
Agreement, Application Form, Letter of Authorization (LOA), Conforme Letter, Terms and
Conditions, endorsement, addendum, schedule, rider, digital acceptance, or any other
document governing the relationship between the Member and any entity within the
Maxicare Group.
-
“Authorized Representatives” - Refers to directors, officers, employees, agents, affiliates,
subsidiaries, parent companies, service providers, contractors, auditors, consultants,
brokers, and other persons or entities duly authorized to process personal data on behalf of
the Maxicare Group.
-
“Consent” - Refers to any freely given, specific, informed, and unambiguous indication of
will by which the data subject agrees to the processing of personal data relating to him or
her, evidenced by written, electronic, or recorded means, pursuant to Republic Act No.
10173 and NPC Circular No. 2023-04.
-
“Core Services” - Refers to healthcare, clinic, insurance, wellness, teleconsultation,
vaccination, claims processing, policy administration, and other services necessary for the
performance of the Agreement.
-
“Data Privacy Act” or “DPA” Refers to Republic Act No. 10173 or Data Privacy Act of
2012, its Implementing Rules and Regulations, and issuances of the National Privacy
Commission.
-
“Data Subject” - Refers to an individual whose personal data is processed under this
Member Consent, including the Principal Member and any Dependents.
-
“Dependent” - Refers to a person enrolled under a Principal Member’s coverage,
including but not limited to spouse, children (including legally adopted children), parents, or
other eligible beneficiaries as defined under the applicable Agreement.
-
“Legitimate Interest” - Refers to lawful processing necessary for purposes pursued by the
Maxicare Group or a third party, provided such interest is not overridden by fundamental
rights and freedoms of the data subject.
-
“Legitimate Interest” - Refers to lawful processing necessary for purposes pursued by the
Maxicare Group or a third party, provided such interest is not overridden by fundamental
rights and freedoms of the data subject.
-
“Maxicare Group” - Collectively refers to:
- Maxicare Healthcare Corporation (“Maxicare”)
- Maxicare Health Services, Inc. (“Maxihealth”)
- Maxicare Life Insurance Corporation (“Maxicare Insurance”)
Each entity may act as a Personal Information Controller (PIC) independently or jointly
depending on the specific processing activity, or as a Personal Information Processor (PIP)
for certain transactions and services.
-
“Member” - Refers to a Principal Member or Dependent who is eligible and accepted for
membership, insurance coverage, or healthcare services under an Agreement.
-
“Personal Data” - Refers collectively to Personal Information, Sensitive Personal
Information, and Privileged Information as defined under the Data Privacy Act.
-
“Personal Information” - Refers to any information, whether recorded in material form or
not, from which the identity of an individual is apparent or can reasonably and directly be
ascertained.
-
“Sensitive Personal Information” - Refers to personal information:
- About an individual’s health, medical history, diagnosis, treatment, or condition;
- Concerning race, ethnicity, marital status, age, religion, or affiliations;
- Issued by government agencies (e.g., SSS, GSIS, PhilHealth, TIN);
- Classified as sensitive under the Data Privacy Act.
-
“Processing” - Refers to any operation or set of operations performed upon personal
data including, but not limited to:
Collection, recording, organization, storage, updating, modification, retrieval, consultation,
use, consolidation, blocking, sharing, disclosure, erasure, or destruction.
Processing may be manual or automated.
-
“Representatives” - Refers to healthcare providers, hospitals, clinics, laboratories,
insurers, underwriters, third-party administrators, IT providers, hosting providers, analytics
partners, sub-processors/ third-party service provider, government agencies, and other
entities that may receive personal data for legitimate purposes.
-
“Retention Period” - Refers to the duration for which personal data is stored in accordance with:
- Legal and regulatory requirements
- Contractual obligations
- Legitimate business purposes
- Defense of legal claims
- Thereafter securely disposed or anonymized
-
“Super App” - Refers to the integrated digital platform of the Maxicare Group intended to
consolidate healthcare, clinic, and insurance services and manage digital consent. (future
service)
-
“Company/ Customer” - Refers to an employer, corporate client, group policyholder, or
contracting entity that has entered into an Agreement with any member of the Maxicare
Group for the benefit of the Member.
-
“Third-Party Service Provider” - Refers to any external entity contracted by the Maxicare
Group to provide services involving the processing of personal data, subject to data sharing
agreements and confidentiality obligations.
III. PERSONAL INFORMATION COLLECTED
Personal data processed may include, but are not limited to:
-
Personal Information
- Name, address, contact details
- Date of birth, gender, civil status
- Employment information
- Membership and policy details
-
Sensitive Personal Information
- Health and medical records
- Diagnostic results
- Consultation and treatment records
- Claims data
- Medical utilization
-
Other Information
- Photos and CCTV footage, where applicable and within premises
- Voice recordings (during inbound or outbound calls or teleconsultation)
- Video recording (during teleconsultation)
- AI Video Recording
- Portal/app logs and digital identifiers
IV. PURPOSES OF PROCESSING
-
Core Healthcare and Insurance Services
Your personal data may be processed for purposes that are necessary for:
- Enrollment, membership validation, and activation
- Policy coverage
- Issuance of LOAs and policy documents
- Claims adjudication and benefit management
- Healthcare coordination
- Healthcare clinic, teleconsult, and insurance services
- Billing, co-pay, and Administrative Services Only (ASO) arrangements
- Compliance with:
- Universal Health Care Act or RA No. 11223
- Mandatory Reporting of Notifiable Diseases Act or RA No. 11332
- Other applicable laws and reporting requirements
Processing for these purposes may be based on:
- Performance of Contract – to provide healthcare, clinic, insurance, and related services under the Agreement;
- Compliance with Legal Obligation – including reporting and regulatory requirements under applicable laws;
- Protection of Life and Health – where processing is necessary for medical treatment or emergency;
- Legitimate Interest – where lawful and not overridden by fundamental rights and freedoms;
- Consent – where required under the Data Privacy Act.
-
Intra-Group Data Sharing
Your data may be shared internally within the Maxicare Group as necessary for:
- Member benefit coordination
- Continuity of care
- Underwriting (where applicable)
- Risk management
- Service quality improvement
- Internal analytics (where practicable, de-identified)
-
Third-Parties & Government Disclosures
Your personal data will only be shared with:
- Accredited healthcare providers
- Government agencies (such as but not limited to DOH, PhilHealth, NPC, Insurance Commission)
- Third-party service providers (IT, hosting, cloud, analytics)
All recipients will be contractually bound to safeguard your data.
-
Additional Consent
The Maxicare Group shall also process your personal information for the following purposes:
- Marketing communications
- Surveys or research participation
- Promotional and partner offers
-
Withdrawal of Consent
You may withdraw consent in accordance with Article VII of this policy. However, the
Maxicare Group shall not comply with your instruction unless you confirm that you are fully
aware of the consequences of such withdrawal for any purpose, including any impairment of
services to you, and that you waive any and all claims of liability for the impairment of
services due to your withdrawal of consent.
- Marketing communications
- Surveys or research participation
- Promotional and partner offers
V. RETENTION AND DISPOSAL
Personal data shall be retained:
- While you remain active under a membership or policy
- For claims and reimbursements records
- For billing and financial records
- For legal compliance and regulatory obligations
- As necessary to establish, exercise, or defend legal claims
- For legitimate business purposes
After retention periods expire, data will be securely disposed or anonymized.
VI. DATA SUBJECT RIGHTS
Under the Data Privacy Act of 2012, you have the right to:
- Be informed
- Access your data
- Rectify inaccuracies
- Object to processing
- Withdraw consent
- Request erasure, blocking or suspension
- File a complaint with the National Privacy Commission
- Seek damages for unlawful processing
Data Protection Officer (DPO) Contact Information:
VII. WITHDRAWAL OF CONSENT
You may withdraw consent at any time via:
- Super App (future service)
- Official Opt-Out Link
- Email to the appropriate DPO
VIII. AUTHORITY FOR DEPENDENTS
If signing on behalf of minor dependent(s), you warrant that:
- You are duly authorized to consent on their behalf;
- You have informed dependents about data processing.
IX. FAIR AND TRANSPARENT PROCESSING
All personal information processing shall be:
- Fair and lawful
- Transparent and specific
- Limited to stated purposes
- Proportionate and necessary
X. CONSENT & SIGNATURE
By signing below or clicking “I Agree,” you confirm that you have read and understood this Member Consent and Data Privacy Terms.
You acknowledge that the Maxicare Group may process your personal data and that of your enrolled minor dependent/s for the purposes stated above, in accordance with the Data
Privacy Act of 2012, its Implementing Rules and Regulations, and applicable issuances of the National Privacy Commission.
Where consent is required under applicable law, You freely, voluntarily, and explicitly consent to the processing of your personal information and sensitive personal information, including health and medical information, strictly for the purposes stated above.
You authorize the Maxicare Group and its Authorized Representatives to:
- Collect, record, organize, store, update, retrieve, consult, use, consolidate, share, disclose, block, erase, or destroy your personal data;
- Process personal information, sensitive personal information, privileged information, and medical records;
- Process personal information, sensitive personal information, privileged information, and medical records;
- Share personal data within the Maxicare Group and with accredited healthcare providers, regulators, and authorized third-party service providers for legitimate and lawful purposes described above.
You agree to receive marketing and promotional communications from the Maxicare Group.
You agree to participate in surveys or research activities conducted by the Maxicare Group.
You understand that these marketing, promotional, survey and research consents are not required for the provision of healthcare or insurance services and that you may withdraw your consent at any time through the official opt-out mechanism or by contacting the appropriate Data Protection Officer, without affecting your membership or benefits.
Confirmation of Related Documents
You confirm that you have read, understood, and agree to the following documents of the Maxicare Group, as made available to me:
-
Maxicare Healthcare Corporation – Terms and Conditions and Privacy Notice
-
Maxicare Health Services, Inc. (Maxihealth) – Membership Terms and Conditions and Privacy Policy
-
Maxicare Life Insurance Corporation (Maxicare Insurance ) – Membership Terms and Conditions and Privacy Policy
You understand that these documents form part of your Agreement with the applicable entity of the Maxicare Group and govern the processing of your personal data.
You have reached the end of the Consent and Data Privacy Agreement. Please click "I Agree & Accept" below to confirm your acceptance.