Skip to content

SUSTAINABILITY

Governance

HM Hospitales promotes good governance and transparency through various internal principles, standards and internal policies that inspire ethics in our actions.

Data protection and cybersecurity 

At HM Hospitales we are firmly committed to protecting the personal data of our patients, clients, collaborators and employees. We guarantee compliance with all current privacy regulations and laws, implementing rigorous policies to ensure that the information entrusted to us is treated confidentially, securely and responsibly. 

We strictly comply with the regulations established by Spanish and European legislation, adopting the necessary measures to ensure that personal data is processed legally, transparently and securely. We are committed to collecting only the necessary data, using it for specific purposes, and ensuring its accuracy, integrity, and confidentiality. We also implement clear processes that allow our users to exercise their rights, and we have advanced security protocols to protect personal information against any unauthorized access or accidental loss. 

We understand that the protection of personal data is a fundamental right and an essential principle of our activity, and we work continuously to ensure that our practices and policies are aligned with the best data protection practices and legal safeguards, guaranteeing the protection and privacy of the personal data of our patients, clients, collaborators, and employees. 

Management has decided to strengthen information security through certification under the UNE-EN ISO/IEC 27001:2023 standard and the National Security Framework (ENS), regulated by Royal Decree 311/2022 of May 3. 

Main functions of the Information Security Committee:

  • To approve privacy standards and procedures
  • To monitor the Privacy Management System
  • To investigate and implement security measures in response to incidents that may pose a risk to privacy protection
  • To evaluate and coordinate the implementation of specific controls for security measures applied to information systems and services
  • To monitor compliance with privacy regulations
  • To support the DPO in their functions and promote the establishment of a privacy culture within the organization regarding the processing of personal data
facebookinstagramlinkedinxyoutubetravelgroupcalendar_todaysearchmenuclosekeyboard_arrow_leftkeyboard_arrow_right