Patient Data Protection & GDPR Policy

Your Data 

Under the Data Protection Act (DPA) 2018, we are obliged to disclose how your data is collected, processed, stored, and used. In order to provide you with safe care and treatment, we need to store personal information about you, such as your name, address, date of birth, and contact details. Our medical record system will also store information about your medical history, including your care history, any diagnoses you may have had, your appointments and who you have seen, tests which you have had, treatments and medications you have been supplied, and the results of any scans or investigations which may have been performed. 

How your data is used

By registering with us and attending the practice, it is assumed that you are consenting to the sharing of your information both with the practice and with other organisations who may also provide you with care. We are also allowed by law to share this information. 

 It may not always be possible for your GP to handle all of your information. Where necessary, this responsibility may need to be delegated to others in the practice and, where necessary, to members of other organisations. If your care requires us to share information with others outside the practice, we will exchange whatever information is necessary to ensure that you receive the care you need. Where you have attended other care providers, such as hospitals or other clinics, we will receive details of the care which they have provided for you. The practice team, including clinicians, administration, and reception staff) will only access information which is necessary for them to perform their duties. 

In order to provide you with safe and effective care, we use your data for a number of purposes. Your medical records may be accessed by a computer program to identify whether you are in a group which is vulnerable to certain risks, such as heart disease, unplanned hospital admission, or seasonal diseases such as the flu. This is done in order to provide you with care as soon as possible. This process may require us to link information from your GP record to information from other health providers, NHS Trusts, or social care services which you have used.

This data may also be used by local Clinical Commissioning Groups (CCGs) to improve local services and commission new services where this is deemed necessary. The legal basis for this usage is laid out under Section 251 of the N​HS Act 2006, more information on which can be found here. Information which identifies you will only be seen by this practice.  

NHS England has been directed by the government to establish and operate the OpenSAFELY COVID-19 Service and the OpenSAFELY Data Analytics Service. These services provide a secure environment that supports research, clinical audit, service evaluation and health surveillance for COVID-19 and other purposes.
 
Each GP practice remains the controller of its own GP patient data but is required to let approved users run queries on pseudonymised patient data. This means identifiers are removed and replaced with a pseudonym.
 
Only approved users are allowed to run these queries, and they will not be able to access information that directly or indirectly identifies individuals.
 
Patients who do not wish for their data to be used as part of this process can register type 1 opt out with their GP.
 

Safeguarding

Sometimes it may be necessary for us to share your information with other medical professionals or organisations so that other people, including healthcare workers, children, vulnerable adults, and others with safeguarding needs, are safeguarded and protected from harm. It is rare for these circumstances to arise, but in the event that it is deemed necessary, such as in an emergency, we are able to share your information without your agreement or consent. Please see our Safeguarding Policy for more information.

Summary Care Records

In order to facilitate medical care outside of your GP practice, the NHS uses a system called the Summary Care Record (SCR). The Summary Care Record contains information about any medication allergies you may have and any medications you may be taken which might react adversely to common treatments. If additional information is included in the SCR, it may also include any major procedures you have had, your significant underlying disorders, reasons for prescribing medication, vaccinations you might have received, and information relating to anticipatory treatment and end-of-life care.

The SCR allows medical professionals such as A&E staff, Out of Hours care systems, and emergency service workers to access your information. It is important that emergency medical workers know your care history, such as whether you are allergic to any medications. Additional information can only be added to your SCR with your consent. You are legally allowed to request that you are opted out of the SCR system, but you should be aware that if you do so, your medical history will be unavailable to healthcare professionals who will use this information to provide you with the best and safest care path. 

Your information may also be accessed and shared for the following care protocols:

  • Clinical audits, such as the National Diabetes Audit.
  • Clinical research conducted by partner organisations. Your permission will always be sought in cases where your medical history will be shared for research purposes.
  • Individual Funding Requests made by your organisation, where requests are made for funding on your behalf and with your consent for treatment which falls outside the remit of the practice.
  • Invoice validation, where information such as your NHS number will be processed to ensure which Clinical Commissioning Group is responsible for paying for your healthcare. 
  • The National Fraud Initiative, which may access information without the consent of the concerned party. Read more about the ​NFI
  • National Registries, such as the Learning Disabilities Register, which may access patient data without the requirement to seek consent from each individual user.

For existing patients it is different in that it is assumed that you want your record uploaded to the Central NHS Computer System unless you actively opt out.

To opt-out of Chartfield Surgery sharing your records please complete an admin re​quest online using AccuRx.

To opt-out of the national NHS sharing your data for research and planning please visit the your NHS data matter​s page of the NHS website.

The NHS database

When you register with the NHS, your information is stored on the National Health Application and Infrastructure Service database.  This database contains your name, address, date of birth, and NHS number, but does not contain any information about your care history. The database is held by NHS Digital, a national organisation which has a legal responsibility to collect and store NHS data.

Read more about the ​NHS database 

How your data is stored

Our storage of patient data and records is governed by the Records Management N​HS Code of Practice ​for Health and Socia​l Care. The Code of Practice determines how records are created, managed, stored, and destroyed, and all Practice engagement with patient records is in line with this code. 

Phone system

All calls to and from the Practice are recorded for the purposes of training and monitoring. 

NHS App messaging service

We use the NHS Account Messaging Service provided by NHS England to send you messages relating to your health and care. You need to be an NHS App user to receive these messages. Further information about the service can be found at the privacy notice for t​he NHS App managed by NHS England.

We are required by law to provide you with the following information about how we handle your information and our legal obligations to share data.