Loading...

This site uses cookies to store information on your computer. Some cookies on this site are essential, and the site won't work as expected without them. Read More

Mayfield Medical Centre

Mayfield Medical Centre

national health service

REPEAT PRESCRIPTIONS ARE TAKING A BIT LONGER THAN USUAL AND TYPICALLY TAKE BETWEEN 5 and 7 WORKING DAYS. PLEASE ORDER REPEATS NO MORE THAN 10 DAYS BEFORE THE END OF YOUR CURRENT END DATE. OUR APOLOGIES FOR THE TEMPORARY INCONVENIENCE.
Search:  
Choose font size: A A A

How we use your personal information

 

This privacy notice explains what information this GP practice holds about you, why we hold that information and how that information may be used. The healthcare professionals who provide you with care maintain records about your health and any treatment or care you have received previously (e.g. NHS Trust, GP Surgery, Walk-in clinic, etc.). These records help to provide you with the best possible healthcare.

 

NHS health records may be electronic, on paper or a mixture of both, and we use a combination of working practices and technology to ensure that your information is kept confidential and secure. Records which this GP Practice hold about you may include the following information;

 

Details about you, such as your address, carer, legal representative, emergency contact details. We also hold the following:

  • Any contact the surgery has had with you, such as appointments, clinic visits, emergency appointments, etc.
  • Notes and reports about your health
  • Details about your treatment and care
  • Results of investigations such as laboratory tests, x-rays etc.

 

Relevant information from other health professionals, relatives or those who care for you to ensure you receive the best possible care, your records are used to facilitate the care you receive. Information held about you may be used to help protect the health of the public and to help us manage the NHS. Information may be used within the GP practice for clinical audit to monitor the quality of the service provided.


Some of this information will be held centrally and used for statistical purposes. Where we do this, we take strict measures to ensure that individual patients cannot be identified. Sometimes your information may be requested to be used for research purposes – the surgery will always gain your consent before releasing the information for this purpose.

 

 

How do we ensure your records are held confidentiality?

We are committed to protecting your privacy and will only use information collected lawfully in accordance with:

 

  1. Data Protection Act 2018
  2. General Data Protection Regulations 2018
  3. Human Rights Act 1998
  4. Common Law Duty of Confidentiality
  5. Health and Social Care Act 2012
  6. NHS Codes of Confidentiality
  7. Information Security and Records Management
  8. Information: To Share or Not to Share Review

 

Every member of staff who works for an NHS organisation has a legal obligation to keep information about you confidential.

 

We will only ever use or pass on information about you if others involved in your care have a genuine need for it. We will not disclose your information to any third party without your permission unless there are exceptional circumstances (i.e. life or death situations), where the law requires information to be passed on and in accordance with the new information sharing principle following Dame Fiona Caldicott’s information sharing review (Information: To share or not to share) where “The duty to share information can be as important as the duty to protect patient confidentiality.”

 

This means that health and social care professionals should have the confidence to share information in the best interests of their patients within the framework set out by the Caldicott principles. They should be supported by the policies of their employers, regulators and professional bodies.

 

CQC accessing records and GDPR 

CQC has powers under the Health and Social Care Act 2008 to access and use information where we consider this is necessary for us to carry out our functions as a regulator. Where possible inspectors should explain why they are asking to look at certain records. They will consider any concerns and objections raised to them, and whether they can achieve CQC’s purpose by accessing the records of someone else. However, CQC relies on its legal powers to access information rather than consent, therefore may use its powers to access records even in cases where objections have been raised.

 

More detail on how we ensure compliance with data protection law (including GDPR) and our privacy statement is available on our website. As part of their own compliance with GDPR, providers’ own privacy statements should inform people of CQC’s powers to ensure their staff, people using services and their families are aware. It would be helpful for providers to include a link to CQC’s privacy statement in their own. The ICO provides more information and resources on GDPR compliance and can be contacted for advice.

 

 

Change of Details

It is important that you tell the practice if any of your details such as your name or address have changed or if any of your details such as date of birth is incorrect in order for this to be amended. You have a responsibility to inform us of any changes so your record is accurate and up to date.

 

You have the right to object to our sharing your data in these circumstances but we have an overriding responsibility to do what is in your best interests. Please see below.

 

We are required by Articles in the General Data Protection Regulations to provide you with the information in the following 9 subsections.

 

 

 

1)

Data Controller contact details 

 

 

Mayfield Medical Centre

Croyde close

Farnborough

Hampshire

GU14 8UE

 

2)

Data Protection Officer contact details

 

 

Caroline Sims

c/o Mayfield Medical Centre

via the Practice Manager

3)

Purpose of the  processing

Direct Care is care delivered to the individual alone, most of which is provided in the surgery. After a patient agrees to a referral for direct care elsewhere, such as a referral to a specialist in a hospital, necessary and relevant information about the patient, their circumstances and their problem will need to be shared with the other healthcare workers, such as specialist, therapists, technicians etc. The information that is shared is to enable the other healthcare workers to provide the most appropriate advice, investigations, treatments, therapies and or care.

4)

Lawful basis for  processing

The processing of personal data in the delivery of direct care and for providers’ administrative purposes in this surgery and in support of direct care elsewhere is supported under the following Article 6 and 9 conditions of the GDPR:

Article 6(1)(e) ‘…necessary for the performance of a task carried out in the public interest or in the exercise of official authority…’.

 

Article 9(2)(h) ‘necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services...” 

 

We will also recognise your rights established under UK case law collectively known as the “Common Law Duty of Confidentiality”*

5)

Recipient or categories of recipients of the processed data

The data will be shared with Health and care professionals and support staff in this surgery and at hospitals, diagnostic and treatment centres who contribute to your personal care.

We are currently preparing detailed privacy notices for each of the ways in which we use your information. These will be available in the practice and on the website.

6)

Rights to object

You have the right to object to some or all the information being processed under Article 21. Please contact the Data Controller or the practice. You should be aware that this is a right to raise an objection, that is not the same as having an absolute right to have your wishes granted in every circumstance

7)

Right to access and correct

You have the right to access the data that is being shared and have any inaccuracies corrected. There is no right to have accurate medical records deleted except when ordered by a court of Law. Your request may be made either verbally or in writing to the practice.



8)

Retention period

The data will be retained in line with the law and national guidance. https://digital.nhs.uk/article/1202/Records-Management-Code-of-Practice-for-Health-and-Social-Care-2016    or speak to the practice.

 

 

9) 

Right to Complain.

If you are happy for your data to be extracted and used for the purposes described in this privacy notice then you do not need to do anything. If you have any concerns about how your data is shared then please contact the practice. Please contact the Practice Manager in the first instance

 

Philip Owen-Halley Mayfield.reception@nhs.net

 

 

You have the right to complain to the Information Commissioner’s Office, you can use this link

 

https://ico.org.uk/global/contact-us/ 

 

or calling their helpline Tel: 0303 123 1113 (local rate) or 01625 545 745 (national rate)


There are National Offices for Scotland, Northern Ireland and Wales, (see ICO website)


 

GP Website from Wiggly-Amps Ltd. | Total visitors:264296 | Disclaimer