Important Notice: This page provides information about the Non-Disclosure Agreement (NDA) used by the Philippine Health Insurance Corporation (PhilHealth). The agreement is designed to protect confidential information shared between PhilHealth and its various stakeholders.
The Philippine Health Insurance Corporation (PhilHealth), as the national health insurance provider in the Philippines, implements a Non-Disclosure Agreement (NDA) to safeguard sensitive information exchanged during official interactions. This legal document establishes a confidential relationship between PhilHealth and parties such as employees, contractors, healthcare providers, researchers, and other entities that may access confidential data.
The PhilHealth NDA serves multiple purposes: protecting member information, securing operational strategies, preserving intellectual property, and maintaining the integrity of healthcare data. It is aligned with Philippine laws, including the Data Privacy Act of 2012, ensuring that personal information collected by the corporation is protected against unauthorized disclosure.
PhilHealth requires signing of the NDA in various situations, including but not limited to:
The PhilHealth NDA defines confidential information broadly to ensure comprehensive protection. This includes:
Parties who sign the PhilHealth NDA assume several key responsibilities:
PhilHealth NDAs typically establish confidentiality obligations that extend beyond the duration of the specific engagement or relationship. Commonly, the NDA remains in effect during the relationship and continues for a specified period afterward, often ranging from three to five years, depending on the sensitivity of the information involved. For particularly sensitive information, obligations may continue indefinitely.
The enduring nature of these obligations ensures that long-term protection is maintained for PhilHealth's most critical information, while recognizing that some information may eventually become public or lose its confidential status over time.
While PhilHealth NDAs are comprehensive, certain standard exceptions to confidentiality are included:
Violations of the PhilHealth NDA can result in significant consequences for individuals and organizations:
The PhilHealth NDA operates in conjunction with the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations. This comprehensive data protection law establishes requirements for the processing of personal information and sensitive personal information in both government and private sectors.
The NDA reinforces these legal obligations by establishing contractual security measures that go beyond minimum legal requirements. This dual structure ensures that PhilHealth's approach to data protection is both legally compliant and practically robust, addressing not only regulatory requirements but also practical concerns about information security.
As a government corporation, PhilHealth develops various intellectual properties related to healthcare financing, administration systems, and service delivery models. The NDA explicitly protects these intellectual property rights while clarifying that access to confidential information does not transfer any ownership or license rights to the receiving party.
This protection extends to software applications, processes, methodologies, documentation, and other innovations developed by PhilHealth. The corporation maintains exclusive rights to these assets regardless of access provided under the NDA.
PhilHealth NDAs typically include provisions for resolving disputes that may arise from confidentiality matters. These commonly begin with amicable consultation between parties, providing an opportunity to resolve issues through discussion and compromise.
If amicable resolution is not possible, the NDA may specify arbitration or mediation procedures before pursuing court action. This approach helps maintain professional relationships while ensuring that serious breaches are addressed through appropriate formal mechanisms.
PhilHealth's approach to non-disclosure agreements reflects broader best practices in the healthcare industry and data-intensive government agencies:
The comprehensive nature of PhilHealth's NDAs provides several key benefits:
Anyone who may access confidential information in relation to their engagement with PhilHealth typically needs to sign an NDA. This includes employees, contractors, healthcare providers, researchers, and other parties who may handle sensitive data.
The duration varies depending on the sensitivity of information involved. Most PhilHealth NDAs maintain obligations for 3-5 years after the relationship ends, though some particularly sensitive information may be protected indefinitely.
Confidential information may only be shared with colleagues who have a legitimate "need to know" and who are bound by confidentiality obligations no less restrictive than those in your PhilHealth NDA.
If you suspect a potential breach of confidentiality, you should immediately report it to the designated PhilHealth contact person or department specified in your NDA. Prompt reporting helps minimize potential damage.
No, PhilHealth does not charge fees for signing NDAs. This is a standard requirement for individuals and entities that need access to confidential information in their engagement with PhilHealth.
