Document control
| Item | Details |
|---|---|
| Policy owner | Chief Executive Officer, supported by Human Resources and Compliance |
| Approval authority | Board of Directors |
| Effective date | Upon Board approval |
| Review cycle | At least annually and after any material legal, regulatory or business change |
| Applies to | Directors, officers, employees, interns, temporary staff and contract personnel; relevant obligations extend to third parties acting for the Company |
| Related documents | Whistleblowing Procedure; Anti-Bribery and Corruption Procedure; Gifts and Hospitality Register; Conflict Declaration; Personal Data and Information Security Policies; Employee Handbook |
Message from the Board
MediLink-Global’s reputation depends on trust. We administer healthcare relationships, claims information, provider networks and technology-enabled services that can affect people at vulnerable moments. We therefore expect lawful, honest, respectful and careful conduct in every decision, record and interaction.
No commercial target, client request or management instruction justifies bribery, falsification, misuse of health information, retaliation or any other breach of this Code. When the right course is unclear, pause, protect the person and the information involved, and ask for guidance.
How to use this Code
Use the following test before acting:
- Is it lawful and consistent with this Code, Company policy and the relevant contract?
- Is it honest, fair and in the legitimate interests of members, patients, clients, providers and the Company?
- Would I be comfortable if the decision, record or message were reviewed by the Board, a regulator or the affected person?
- Have I disclosed any conflict, protected confidential information and obtained the approval required by the Delegation of Authority?
- If I am unsure, have I stopped and sought advice before proceeding?
1. Purpose, scope and status
This Code states the minimum conduct expected throughout MediLink-Global. It supports—not replaces—applicable law, employment obligations, professional duties, contracts and detailed Company procedures.
It applies at work, on business travel, at work-related events, in remote work, on Company systems and in personal conduct that has a material connection with the Company or its reputation.
Third parties acting for or representing the Company must comply with relevant provisions through due diligence, written contracts, monitoring and, where appropriate, training.
Where laws or contractual rules differ, follow the stricter lawful standard and obtain advice. Nothing in this Code authorises a person to breach local law.
2. Individual and leadership responsibilities
Everyone must read, understand and follow this Code; complete required training; keep accurate declarations; cooperate with lawful reviews; and report suspected misconduct promptly.
Managers must model the Code, make it safe to raise concerns, act on warning signs, prevent retaliation, seek specialist advice and document decisions. A manager must never investigate a serious allegation alone or promise absolute confidentiality.
The Board and senior management are responsible for adequate procedures, resources, oversight and periodic review. Performance or revenue never excuses misconduct.
3. Honest, lawful and fair conduct
Deal honestly and fairly with members, patients, clients, providers, suppliers, regulators, competitors and colleagues. Do not mislead, conceal material facts, manipulate records or take unfair advantage of another person.
Obtain required licences, approvals and delegated authority before committing the Company. Do not sign, promise, invoice, approve or communicate on behalf of the Company beyond your authority.
Escalate suspected fraud, false claims, duplicate billing, identity misuse, document alteration, unauthorised benefit changes or improper system access immediately.
4. Anti-bribery and corruption
Bribery is prohibited in every form. Never offer, promise, give, request, receive or authorise money, gifts, employment, discounts, donations, favours, commissions, confidential information or any other advantage to obtain or retain business, influence a decision or reward improper conduct.
The prohibition applies to dealings with public officials and private persons and to conduct through agents, introducers, consultants, providers, suppliers, charitable bodies or any other intermediary.
Facilitation payments and secret commissions are prohibited. If a payment is demanded under an immediate threat to health or safety, prioritise safety, make no false record and report the incident as soon as possible.
All payments must have a legitimate purpose, appropriate approval, supporting documentation and an accurate accounting entry. No off-book account, false invoice or misleading description is permitted.
Political contributions using Company funds, assets or name are prohibited unless lawful and specifically approved by the Board. Charitable donations and sponsorships require due diligence, written purpose, conflict review and approval under the Delegation of Authority.
5. Gifts, hospitality and business courtesies
Never give or accept cash, cash equivalents, personal loans, kickbacks or lavish, concealed, frequent or sexually inappropriate hospitality.
A modest business gift with a value not exceeding RM300 may be accepted only when lawful, infrequent, transparent, not connected to a tender, claim, provider appointment, audit, dispute or pending decision, and recorded in the Gifts and Hospitality Register. This threshold is not an entitlement or automatic approval.
A gift above RM300 must normally be declined or returned. If return would cause genuine offence or is impracticable, surrender it to the Company and obtain a written decision from the CEO or delegated Compliance authority.
Hospitality must have a legitimate business purpose, be reasonable in value and frequency, and include appropriate Company representation. Travel or accommodation paid by a third party requires prior written approval.
Any gift or hospitality involving a public official, regulator or person able to affect a claim, provider credential, procurement or contract requires prior written Compliance approval regardless of value.
6. Conflicts of interest
Avoid situations where personal interests conflict, appear to conflict or could reasonably be perceived to conflict with the Company’s interests or duties to stakeholders.
Disclose promptly any outside employment, directorship, ownership, investment, close personal relationship, family interest, referral arrangement or other connection that may affect a decision. Update the declaration when circumstances change and at least annually.
Do not participate in selection, supervision, claims decisions, procurement, payment or performance assessment involving yourself, a close relative, household member, romantic partner or associated business. Follow the documented mitigation or recusal decision.
Corporate opportunities, confidential information and Company position may not be used for personal gain.
7. Healthcare, claims and provider integrity
Protect the independence of clinical professionals and the integrity of benefit and claims administration. Do not make an unauthorised clinical decision, alter medical information, misstate entitlement, override controls or favour a provider or claimant for an improper reason.
Represent plan benefits, exclusions, provider status, system capabilities, service levels and claim outcomes accurately. Where a decision is governed by a client contract or benefit schedule, apply the authorised terms consistently and document any exception.
Potential fraud, waste or abuse must be assessed fairly and confidentially. Do not presume guilt, retaliate or disclose an investigation outside the need-to-know team.
Provider credentialling, panel appointment, referrals and payments must follow approved criteria, segregation of duties and auditable records. Do not accept inducements linked to patient steering, claim volume or favourable treatment.
8. Personal data, confidentiality and professional secrecy
Member, patient and health information is sensitive personal data and must receive enhanced protection. Access, use and disclose it only for an authorised, necessary and lawful purpose and only to the minimum extent required.
Follow privacy notices, customer instructions, access controls, retention schedules and secure transfer rules. Verify identity and authority before disclosing information. Do not discuss confidential matters in public places or use personal accounts, unapproved messaging, storage or removable media.
The duty of confidentiality continues after employment or engagement ends. Return Company information and devices and do not retain copies.
Report any loss, mistaken disclosure, phishing, malware, unauthorised access or suspected personal-data breach immediately through the security incident channel. Do not contact affected individuals, authorities or the media unless authorised by the incident-response team.
The Data Protection Officer or Privacy Lead coordinates compliance, rights requests, cross-border transfers and notifications. The Company remains accountable for compliance and data processors must meet applicable security duties.
9. Cybersecurity, acceptable use and artificial intelligence
Use Company systems, accounts and devices only for authorised purposes. Protect credentials, use multi-factor authentication where provided, lock unattended devices, install only approved software and follow security updates and classification rules.
Never share passwords or one-time codes, bypass controls, connect unapproved devices, test security without authority or forward Company information to personal accounts. Report suspicious messages and security weaknesses; do not exploit them.
Do not enter member, patient, employee, client, source-code, credential, contract or other confidential information into a public or unapproved generative-AI service. Use only approved AI tools, datasets and purposes.
AI-assisted output must be checked by a competent person for accuracy, bias, confidentiality, intellectual property, security and contractual restrictions. Material decisions affecting claims, access, employment or rights require meaningful human oversight and an auditable rationale.
10. Competition and fair dealing
Compete independently and lawfully. Do not agree with competitors on prices, discounts, fees, bids, customers, suppliers, territories, output or other competitively sensitive matters.
Do not exchange non-public pricing, cost, strategy, customer, provider or tender information with competitors unless Legal or Compliance has confirmed a lawful and documented purpose with appropriate safeguards.
Leave any meeting where improper competition topics arise, ensure your objection is recorded and report the incident. Contracts involving exclusivity, bundling, resale restrictions or market power require legal review.
Gather market information only through lawful, ethical sources. Do not induce breach of confidentiality or misrepresent identity.
11. Accurate records, finance, tax and procurement
Create records that are complete, accurate, timely, understandable and traceable. Never falsify a claim, time record, expense, invoice, approval, credential, audit evidence or financial entry.
Follow budgets, procurement controls, competitive sourcing rules, segregation of duties and the Delegation of Authority. Do not split purchases, create fictitious vendors or manipulate comparisons to avoid approval.
Retain and dispose of records under the approved schedule and legal holds. Never destroy, alter or conceal a record because an audit, complaint, investigation, litigation or regulatory request is expected or underway.
Cooperate honestly with auditors and regulators. Questions and responses must be coordinated by the authorised function without delay, obstruction or retaliation.
12. Company assets, intellectual property and communications
Protect Company money, equipment, facilities, information, brands, software, licences and intellectual property from loss, misuse, theft and unauthorised disclosure.
Respect third-party copyright, licences, trademarks, patents, trade secrets and open-source conditions. Do not copy software, images, text, datasets or reports without permission.
Only authorised spokespersons may speak for the Company. Communications, presentations, social-media posts and marketing must be accurate, respectful and approved where required. Do not disclose confidential matters or imply Company endorsement of a personal view.
13. Respectful, inclusive and safe workplace
Treat every person with dignity. Harassment, sexual harassment, bullying, threats, violence, retaliation and unlawful discrimination are prohibited whether in person or through digital channels.
Employment decisions must be based on legitimate role requirements, performance, capability and lawful business needs. Reasonable workplace support should be considered where required by law and practicable.
Comply with occupational safety and health procedures, report hazards, injuries and near misses, and stop work when there is a serious and immediate danger. Never punish a person for raising a genuine safety concern.
Do not work while impaired by alcohol, illegal drugs or misused medication. Smoking and vaping are permitted only where law and Company rules allow.
14. Human rights, community and environment
The Company rejects forced labour, child labour, human trafficking, abusive recruitment, unlawful withholding of identity documents and unsafe or degrading conditions.
Suppliers and labour providers must meet applicable employment, wage, working-time, safety and immigration requirements. Credible concerns require risk-based review and remediation.
Use resources responsibly, prevent pollution where practicable, comply with environmental requirements and make accurate sustainability statements.
Community programmes and donations must be transparent, non-discriminatory, properly approved and free from conflicts or improper influence.
15. Third parties and international business
Conduct proportionate due diligence before appointing agents, introducers, providers, suppliers, consultants, technology vendors or other partners. Risk factors include government interaction, commission-based compensation, sensitive data, overseas transfer, subcontracting and unusual payment requests.
Contracts must state the required conduct, data-security, confidentiality, audit, notification, records and termination rights appropriate to the risk. Pay only for legitimate, documented services to an account belonging to the contracting party unless an exception is independently verified and approved.
Monitor performance and warning signs. Do not ignore misconduct because it is committed by a third party or outside Malaysia.
16. Speaking up, non-retaliation and investigations
Raise concerns in good faith through your manager, Human Resources, the CEO, the designated whistleblowing channel, or the Chair of the Board when senior management may be involved. Immediate risks to life, safety, data or evidence must be escalated at once.
Anonymous reports may be considered where permitted, but sufficient detail is needed to assess the concern. Confidentiality will be protected as far as reasonably practicable and lawful; it cannot be guaranteed absolutely.
Retaliation against a person who raises, supports or participates in a good-faith concern is prohibited. Report suspected retaliation immediately.
Investigations must be impartial, timely, appropriately authorised and respectful of due process. Preserve relevant information and cooperate honestly. Do not conduct your own investigation, confront witnesses, interfere with evidence or disclose restricted details.
A report made honestly will not attract discipline merely because it is unsubstantiated. Knowingly false or malicious allegations, obstruction and breaches of confidentiality may lead to action.
17. Breaches, discipline and remediation
Breaches may result in counselling, control changes, recovery of loss, disciplinary action up to dismissal, termination of a third-party relationship, and referral to regulators or law-enforcement authorities, subject to law and fair process.
Managers who direct, approve, conceal or wilfully ignore misconduct, or fail to respond appropriately, may also be accountable.
The Company will address root causes, protect affected persons, improve controls and track remediation. No person may waive this Code for convenience. Any exceptional interpretation must be lawful, documented and approved by the Board or authorised committee.
18. Training, certification and review
Induction and periodic training will be risk-based. Higher-risk roles receive additional training on anti-bribery, claims integrity, privacy, cybersecurity, procurement, competition and workplace conduct.
Directors and personnel must complete annual declarations covering Code acknowledgement, conflicts and required disclosures. The Company will review this Code at least annually and communicate material changes.
Reporting routes
| Concern | Route |
|---|---|
| General conduct or conflict | Manager, Human Resources or CEO |
| Bribery, fraud, procurement or financial record | CEO, Compliance/Internal Audit, or Board Chair where senior management is implicated |
| Harassment or employment concern | Human Resources; another manager if the usual route is involved |
| Privacy or data incident | Security incident channel and Data Protection Officer / Privacy Lead immediately |
| Urgent safety threat | Emergency services where required, then manager and safety representative |
| External protected disclosure | An appropriate Malaysian enforcement agency or other lawful channel; obtain independent advice on statutory protection |
Acknowledgement
I acknowledge that I have received, read and understood the MediLinkGlobal (M) Sdn. Bhd. Code of Conduct. I agree to comply with it, complete required training, disclose conflicts and report suspected breaches. I understand that the Code is not an employment contract and may be amended in accordance with law and Company governance.
Name: ________________________________________________________________
Position / Department: ________________________________________________________________
Signature: ________________________________________________________________
Date: ________________________________________________________________
