PRIVACY NOTICE - DATA MATTERS
Freedom of information, your rights and how to exercise them
YOUR MEDICAL RECORDS
Information we collect about you
At Streatham Hill Group Practice, we only collect relevant information “data” that we need to help us keep you healthy, such as; your name, address, next of kin, records of visits, telephone calls, treatments and medicines, investigations such as; results, X-rays and any other information that would enable us to care for you better.
Processors of personal data
In order to deliver the best possible service, the practice contracts Processors to process personal data, including patient data on our behalf.
When we use a Processor to process personal data we will always have an appropriate legal agreement in place to ensure that they keep the data secure, that they do not use or share information other than in accordance with our instructions and that they are operating appropriately. Examples of functions that may be carried out by a Processor include:
• Companies that provide IT services & support, including our core clinical systems; systems which manage patient facing services (such as our website and service accessible through the same); data hosting service providers; systems which facilitate appointment bookings or electronic prescription services; document management services etc.
• Delivery services (for example if we were to arrange for delivery of any medicines to you).
• Payment providers (if for example you were paying for a prescription or a service such as travel vaccinations).
How we use your information?
We share your medical records with other healthcare professionals who are involved in providing you with care and treatment and on a need-to-know basis. Some of your data is automatically copied to the shared Summary Care Record. We share some of your data with local out-of-hours providers: Lambeth Hubs or Seldoc. Data about you is used to manage national screening campaigns such as, cervical screening, diabetes prevention, bowel screening and flu.
We share information when the law requires us to, for instance when we are inspected or reporting certain illnesses or safeguarding vulnerable adults and children.
Your data is used to check the quality of care provided by the NHS.
We may also share medical records for medical research.
The data about you is used to manage the NHS and make payments.
How to access your records?
We encourage patients to sign up to patient online services (Patient Access) where you can access your medical records, results, request for repeat medication and book appointments. Please ask at reception for more details.
If you want to see what is written about you, you have a right to access the information we hold on you, but you will need to complete a form called Subject Access Request (SAR). Please ask at reception for a SAR form and you will be given further information. You may request to view all or only certain parts of your records if you prefer. Moreover, should you identify information in your record which may be incorrect you have the right to have the data corrected.
Don’t want to share?
All patients can choose not to share their information.
Should you wish to opt out of data collection, please contact a member of the admin staff, alternatively you can set your opt-out preferences at https://www.nhs.uk/your-nhs-data-matters/ You will need your NHS number and a valid email address or telephone number which is on the GP record or on the Personal Demographics Service database to register their decision to opt out.
Patients who are unable to use the online facility can use a phone helpline to manage their choice on 0300 303 5678. A paper print-and-post form is also available at https://www.nhs.uk/your-nhs-data-matters/manage-your-choice/other-ways-to-manage-your-choice/
Alternatively, please contact a member of the admin staff for support.
Have a question?
If you have any questions, you can contact the Practice’s data controller via email at firstname.lastname@example.org. GP practices are data controllers for the data they hold about their patients. Ask to speak to the Practice Manager Mr Holicka, Data Protection Champion and Controller.
If you are not pleased with your information is managed
We understand that sometimes things can go wrong. If you are not pleased with any part of our data-processing methods, you can make a complaint by visiting The Information Commissioner’s Office: https://ico.org.uk/your-data-matters/raising-concerns/.
We always make sure the information we give you is up-to-date. Any updates will be published on our website, in our and leaflets, and on our posters. This policy will be reviewed in May 2019. For more information see Our Healthier South East London Privacy Notice
LOCAL CARE RECORDS
Local Care Records enables real time sharing and viewing of patient information with local Hospitals: Kings College Hospital, Guys and St. Thomas' Hospital and mental health trust Maudsley Hospital that delivers huge benefits to GPs and patients.
NHS Digital has a statutory role to collect and process health and social care information which is set out in the Health and Social Care Act 2012.
NHS Digital's fair processing materials, available at http://content.digital.nhs.uk/patientconf explains and provide further information on:
- what NHS Digital collects - the types of information the NHS Digital collects and what it's used for
- personal information choices - people's rights regarding care information
- information requests from organisations - how organisations can ask NHS Digital to collect or provide access to care information
- assurance bodies and processes - how the information requests NHS Digital receive are carefully looked at
The NHS Digital is absolutely committed to keeping all of the data it handles safe and secure and applies the same principle to any data that is released outside of the organisation. Information is only ever shared with organisations that have gone through a strict application process, who can demonstrate they have a legitimate reason to access the data to use it for the benefit of health and care purposes, as per the new protections introduced as part of the Care Act 2014, and who have signed a legally binding agreement. So for instance, third party or commercial companies cannot receive information for insurance or marketing purposes.
As part of the application process the Data Access Advisory Group, an independent group, hosted by the NHS Digital, considers all applications for data that are identifiable or de-identified for limited access. The NHS Digital also regularly publishes a register of data releases at: http://content.digital.nhs.uk/dataregister showing where data has been released, to which organisation and for which purposes. If your patients do require any further information that is not already covered within our web pages we can be contacted by Email email@example.com or telephone us on 0300 303 5678.