Measures to protect the confidentiality of personal information

Background of the Personal Information Protection Law
The development of today's information-based society and the widespread use of information technology, including computers and networks, has made it possible to accumulate and use large and diverse volumes of personal information. These technologies provide major benefits, making it possible to ascertain individual needs and to provide services rapidly, among other applications. For this reason, the handling of such personal information is expected to continue expanding.
On the other hand, due to the nature of personal information, improper handling leading to unauthorized use or leakage may result not only in infringement of individual privacy rights, but damage that is not easily remedied.
The Personal Information Protection Law was established and implemented in May 2003 to specify correct methods for handling personal information, thereby seeking to establish a secure foundation for the convenience and benefits of IT society promised by convenient access to personal information. Becoming fully effective on April 1, 2005, the law clarifies specific obligations for companies that handle personal information (such as health insurance societies), as well as penalties.

The Sony Health Insurance Society's efforts
As a company that handles personal information, the Sony Health Insurance Society must meet a range of responsibilities. A health insurance society works on administration concerning health insurance and provides various health insurance services to its insured individuals and family members, based on the Health Insurance Law. The basis for providing these services is the personal information obtained from the society's members.
While we have always administered and managed personal information in an appropriate manner, we believe that we must continue to seek the confidence of our members by heightening awareness of the significance of personal information and ensuring that all personnel involved in its operations handle such information in an accurate and secure manner. For this reason, we have established our own Private Information Protection Policy; clarified the purposes of use of personal information; and established regulations to protect and manage personal information. We make every effort to ensure the confidentiality and security of personal information, based on these regulations.