Practice Privacy Notice / Data protection (GDPR)

How we use your personal information

This fair processing notice explains why the GP practice collects information about you and how that information may be used.

The health care professionals who provide you with care maintain records about your health and any treatment or care you have received previously (e.g. NHS Trust, GP Surgery, Walk-in clinic, etc.). These records help to provide you with the best possible healthcare.

NHS health records may be electronic, on paper or a mixture of both, and we use a combination of working practices and technology to ensure that your information is kept confidential and secure. Records which this GP practice holds about you may include the following information:

  • details about you, such as your address, carer, legal representative, emergency contact details
  • any contact the surgery has had with you, such as appointments, clinic visits, emergency appointments, etc
  • notes and reports about your health
  • results of investigations such as laboratory tests, x-rays, etc
  • relevant information from other health professionals, relatives or those who care for you

To ensure you receive the best possible care, your records are used to facilitate the care you receive. Information held about you may be used to help protect the health of the public and to help us manage the NHS. Information may be used within the GP practice for clinical audit to monitor the quality of the service provided.

Some of this information will be held centrally and used for statistical purposes. Where we do this, we take strict measures to ensure that individual patients cannot be identified. Sometimes your information may be requested to be used for research purposes. Tamar Valley Health is an approved ‘Research Ready’ practice, but we will always gain your consent before releasing the information for this purpose. Tamar Valley Health also works with Oak Tree Surgery on research projects, subject to a data sharing agreement.

Risk stratification

Risk stratification data tools are increasingly being used in the NHS to help determine a person’s risk of suffering a particular condition, preventing an unplanned or (re)admission and identifying a need for preventative intervention. Information about you is collected from a number of sources including NHS Trusts and from this GP practice.

A risk score is then arrived at through an analysis of your de-identified information using services contracted by NHS Kernow, and is only provided back to your GP as data controller in an identifiable form. Risk stratification enables your GP to focus on preventing ill health and not just the treatment of sickness. If necessary your GP may be able to offer you additional services. Please note that you have the right to opt out of your data being used in this way.

Medicine management

The Practice may conduct Medicines management reviews of medications prescribed to its patients. This service performs a review of prescribed medications to ensure patients receive the most appropriate, up to date and cost effective treatments. This service is provided to practices within Kernow Integrated Care Board.

How do we maintain the confidentiality of your records?

We are committed to protecting your privacy and will only use information collected lawfully in accordance with:

  • Data Protection Act 2018
  • Human Rights Act 1998
  • Common Law Duty of Confidentiality
  • Health and Social Care Act 2012
  • NHS Codes of Confidentiality, Information Security and Records Management
  • Information: to Share or Not to Share review

Every member of staff who works for an NHS organisation has a legal obligation to keep information about you confidential.

We will only ever use or pass on information about you if others involved in your care have a genuine need for it. We will not disclose your information to any third party without your permission unless there are exceptional circumstances (i.e. life or death situations), where the law requires information to be passed on and / or in accordance with the new information sharing principle following Dame Fiona Caldicott’s information sharing review (Information to share or not to share) where “The duty to share information can be as important as the duty to protect patient confidentiality”.

This means that health and social care professionals should have the confidence to share information in the best interests of their patients within the framework set out by the Caldicott principles. They should be supported by the policies of their employers, regulators and professional bodies.

Who are our partner organisations?

We may also have to share your information, subject to strict agreements on how it will be used, with the following organisations:

  • NHS Trusts / Foundation Trusts
  • Other GP Practices
  • NHS Commissioning Support Units
  • Independent Contractors such as dentists, opticians, pharmacists
  • Private Sector Providers
  • Voluntary Sector Providers
  • Ambulance Trusts
  • Integrated Care Boards
  • Our Primary Care Network
  • Social Care Services
  • Health and Social Care Information Centre (HSCIC)
  • Local Authorities
  • Education Services
  • Fire and Rescue Services
  • Police and Judicial Services
  • Other ‘data processors’ which you will be informed of

Who are our partner software suppliers / businesses?

Name
Description
Can employees of the organisation access patient information?
GDPR statement & NHSE DSP Toolkit Link
TPP SystmOne
Clinical system & Patient online access holds patient demographic and medical information.
The servers are securely stored off-site, access is encrypted.  SystmOne support staff are able to remotely connect with the consent of our staff for problem solving.
Klinik
Klinik provides automated digital solutions to healthcare providers to help triage and prioritize patients based on the symptoms they provide
The personal data processed by Klinik’s Medical Engine is ‘pseudonymized’ meaning that the identifiers have been removed such that you cannot be directly identified from it without using additional information, but it is still considered personal data in a legal sense.
Crowbytes
IT Support
Engineers can remotely connect with the consent of our staff for problem solving.  Engineers attend site to resolve IT issues with the consent of our staff.
CITS (Cornwall IT Services)
IT Support
Engineers can remotely connect with the consent of our staff for problem solving.  Engineers attend site to resolve IT issues with the consent of our staff.
Restore Datashred
Shred paper on which is recorded patient or other confidential data
Representative comes to site and collects the shredding bins full of paper and shreds on site.
x-on (Surgery Connect)
Telephone call recording system
x-on support staff are able to dial in remotely with the consent of our staff for problem solving.
MDU / MPS / MDDUS
Indemnity organisations
We will sometimes send by email or discuss by phone identifiable information when the organisation is supporting a GP in a patient complaint or litigation. Information will be redacted where possible.
AccuRx
Numed provides software and support for SMS and video consultations
AccuRx support staff can remotely connect to our computers, only with the consent of our staff, for the purposes of problem solving.
First DataBank (UK)
FDB provides AnalyseRx and OptimiseRx
OptimiseRx and AnalyseRx are systems which fully integrate with your GP Practice patient medical record.  Personal data does not leave the GP practice clinical system. Only the prescriber at your GP practice will see this information. Your personal data in respect to OptimiseRx and OptimiseRx is not shared with anyone else.
Ardens
Ardens provides software and support for our Clinical computer system, such as templates, documents and referral letters
Ardens support staff can remotely connect to our computers, only with the consent of our staff, for the purposes of problem solving.
GE Healthcare (Cardiosoft)
GE Healthcare provides software (Cardiosoft) and support for Bosvena’s ECG machines.
GE Healthcare support staff can remotely connect to our computers, only with the consent of our staff, for the purposes of problem solving.
Lexacom
Lexacom provides software and support for Bosvena’s Dictation system.
Lexacom support staff can remotely connect to our computers, only with the consent of our staff, for the purposes of problem solving.
Jayex
Jayex provides software and support for Bosvena Waiting Room information screen and patient calling system
Jayex support staff can remotely connect to our computers, only with the consent of our staff, for the purposes of problem solving.
LumiraDx Care Solutions (INRStar)
LumiraDx Care solutions provides software (INRStar) and support which enable us to provide INR readings and treatment
LumiraDx Care Solutions support staff can remotely connect to our computers, only with the consent of our staff, for the purposes of problem solving.
NHS South, Central and West Commissioning Support Unit – Child Health Information Services (CHIS)
Monitoring and inviting parents of new-born babies for vaccinations
Personal data is collected from the child’s GP record to enable health screening, physical examination and vaccination services to be monitored to ensure that every child has access to all relevant health interventions.
SECA
Seca Analytics software integrates ECG recordings directly into our patient records.
Seca support staff can remotely connect to our computers, only with the consent of our staff, for the purposes of problem solving.
Cortrium
Cortrium’s Apex Software processes and records 24 hour ECG patient readings to your GP patient record.
Cortrium process 24 hour ECG results.  Data is ‘pseudonymized’ meaning that the identifiers have been removed such that you cannot be directly identified from it without using additional information, but it is still considered personal data in a legal sense.
Joy App
Pungo Ltd’s “Joy App”.  A social prescribing case management tool and service library.
Some of your personal data is processed when you agree to a referral to the social prescribing service “Joy”.  This information is retained for a three-year period in case of re-referral.
iGPR
iGPR process Medical & Insurance reports and Subject Access Requests
iGPR limit access to your personal information to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information on our instruction and they are subject to a duty of confidentiality.
Devon and Cornwall Care Record
Clinical System holds patient demographic and medical information
Secure Login to EMIS Now to report any problems, remote connection/dial in can be done remotely with the consent of our staff for problem solving
NHS England
Data Extraction
Data is Anonymised
DocMail
Data Sharing – patients names and addresses
To send bulk invite letters to patient for flu clinics/recall letters – bulk transfer is encrypted
Express Diagnostics
Express Diagnostics provides software and support for our ECG machine.
Express Diagnostics support staff and recordings are transmitted electronically and interpreted and sent back by secure email (nhs.net)
Medacy
Medacy provides clinical pharmacists to provide remote clinical services for Primary Care Networks.
The clinical pharmacists have access to patient personal data including medical records.  The Pharmacists follow the same processes and guidelines as any other member of our clinical teams.
NHS South, Central and West (NHS SCW) 
SCW will provide aggregated returns on NHS Health Checks to Cornwall Council, on behalf of the GP practice
SCW staff can see the number of NHS health Checks completed.  No personal data is extracted.
Cornwall Council
Cornwall Council Commission statutory services through the GP Practice
Council Staff have access aggregated information sufficient to ensure services have been delivered to patients
Heidi Health
Heidi is an ai (artificial intelligence platform platform) that with patient consent listens are provides a summary of a consultation.
No
LIVI
LIVI Provides Remote GP Appointments for Patients
LIVI Clinicians have full access to your medical records

You will be informed who your data will be shared with and in some cases asked for explicit consent for this to happen when this is required.

We may also use external companies to process personal information, such as for archiving or mailing proposes. These companies are bound by contractual agreements to ensure information is kept confidential and secure.

Access to personal information

You have a right under the General Data Protection Regulations 2018 to request access to view or to obtain copies of what information the surgery holds about you and to have it amended should it be inaccurate. In order to request this, you need to do the following:

  • your request should be made verbally or in writing, including via email to the Practice – for information from the hospital you should write direct to them
  • there is not normally a charge to have a printed copy of the information held about you (in some cases a charge may be applied)
  • we are required to respond to you within 1 calendar month
  • you will need to give adequate information (for example full name, address, date of birth, NHS number and details of your request) so that your identity can be verified and your records located

The national data opt out

You can choose whether your confidential patient information is used for research and planning. The national data opt-out implements the opt-out model proposed by the National Data Guardian, as accepted by the Government and the Department of Health and Social Care.

Patients have a right under the NHS Constitution to request that their personal confidential data is not used beyond their direct care and the national data opt-out provides an easy and accessible way for patients to exercise this right.

You do not need to do anything if you are happy about how your confidential patient information is used. You can change your choice at any time.

National data opt-outs are not recorded at the GP practice and instead you can change your national data opt-out using the online service: www.nhs.uk/your-nhs-data-matters or by calling NHS Digital:

NHS Digital Contact Centre

Telephone: 0300 303 5678
Monday to Friday, 9am to 5pm (excluding bank holidays)

All health and care organisations in England are required to apply your national data opt-out by March 2020, including hospitals and GP practices.

Young adults from the age of 13 can set and change their own national data opt-out.

NHS Kernow as a data controller must take note and apply national data opt-outs whenever confidential patient information is to be shared either internally or outside of the organisation. The national data opt-out does not apply to information that is anonymised or is aggregate or count type data. For further information and support relating to national data opt out please refer to the following: www.digital.nhs.uk – Opt out of sharing your health records.

Devon and Cornwall care record

Health and social care services in Devon and Cornwall have developed a system to share patient data efficiently and quickly and, ultimately, improve the care you receive.

This shared system is called the Devon and Cornwall care record.

It is important that anyone treating you has access to your shared record, so they have all the information they need to care for you. This applies to your routine appointments and in urgent situations such as going to A&E, calling 111 or going to an out-of-hours appointment.

It is also quicker for staff to access a shared record than to try to contact other staff by phone or email.

Only authorised health and care staff can access the Devon and Cornwall care record and the information they see is carefully checked so that it relates to their job. Also, systems do not share all your data – just data that services have agreed is necessary to include.

For more information about the Devon and Cornwall care record, or for information on how to register an objection to your information being shared please go to www.devonandcornwallcarerecord.nhs.uk.

Phones and email addresses

If you provide us with your mobile phone number or email address we may use this to send you reminders about any appointments or other health screening information being carried out. We may also use this information to advise you on new services to benefit your health that are available in the practice. Please speak to reception if you wish to opt-out of receiving these types of communication.

Call recording

All of our calls in and out of the Practice are recorded and stored securely with our telephony provider. Recordings are deleted in line with our data retention policy

Objections / Complaints

Should you have any concerns about how your information is managed by the Practice, please contact the senior management team.

If you are still unhappy following a review by the GP practice, you can then complain to the Information Commissioners Office (ICO) via their website (www.ico.gov.uk).

If you are happy for your data to be extracted and used for the purposes described in this privacy notice then you do not need to do anything. If you have any concerns about how your data is shared then please contact the practice.

Change of Details

It is important that you tell the person treating you if any of your details such as date of birth of birth is incorrect in order for this to be amended. You have a responsibility to inform us of any changes so our records are accurate and up to date for you.

Notification

The Data Protection Act 2018 requires organisations to register a notification with the Information Commissioner to describe the purposes for which they process personal and sensitive information.

The information is publicly available on the Information Commissions Office website www.ico.org.uk.

The practice is registered with the Information Commissioners Office (ICO).

Who is the Data Controller?

The Data Controller responsible for keeping your information secure and confidential is:

Launceston Medical Centre

Who is the Data Protection Officer?

The Data Protection Officer for Launceston Medical Centre is:

Umar Sabat

Email: cioicb.dpo@nhs.net
Telephone: 07894 826 037

IG Health, 71 – 75 Shelton Street, London, WC2H 9JQ, UK

Complaints

Should you have any concerns about how your information is managed by the Practice please contact the Practice Manager.

Launceston Medical Centre, Landlake Road, Launceston, Cornwall. PL15 9HH

If you are still unhappy following a review by the Practice you can then complain to the Information Commissioners Office (ICO). www.ico.org.ukcasework@ico.org.uk, telephone: 0303 123 1113 (local rate) or 01625 545 745