Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form

PRACTICE PRIVACY NOTICE

How we use your information

This privacy notice explains why we as a Practice collect information about our patients, what we collect and how we use that information.

Honiton Surgery manages patient information in accordance with existing laws and with guidance from organisations that govern the provision of healthcare in England such as the Department of Health and the General Medical Council.

We are committed to protecting your privacy and will only use information collected lawfully in accordance with:

Data Protection Act 1998

Human Rights Act 1998

Common Law Duty of Confidentiality

Health and Social Care Act 2012

NHS Codes of Confidentiality and Information Security

As data controllers, GPs have fair processing responsibilities under the Data Protection Act 1998. In practice, this means ensuring that your personal confidential data (PCD) is handled clearly and transparently, and in a reasonably expected way.

The Health and Social Care Act 2012 changed the way that personal confidential data is processed, therefore it is important that our patients are aware of and understand these changes, and that you have an opportunity to object and know how to do so.

The health care professionals, who provide you with care, maintain records about your health and any NHS treatment or care you have received (e.g. NHS Hospital Trust, GP Surgery, Walk-in clinic, etc.). These records help to provide you with the best possible healthcare.

NHS health records may be processed electronically, on paper or a mixture of both; a combination of working practices and technology are used to ensure that your information is kept confidential and secure. Records held by this GP practice may include the following information:

Details about you, such as name, address next of kin, gender, D.O.B, email address, phone number

Any contact the practice has had with you, including appointments (emergency or scheduled), clinic visits, etc.

Notes and reports about your health

Details about treatment and care received within Honiton medical practice and other healthcare settings that you may have been referred to

Results of investigations, such as laboratory tests, x-rays, etc.

Relevant information from other health professionals, relatives or those who care for you

The special categories of personal data concerned are:

Racial

Ethnic origin

Health data

Data concerning a natural person’s sex life

Sexual orientation

The practice collects and holds data for the sole purpose of providing healthcare services to our patients under the legal basis of legitimate interests, or vital interest where appropriate. We will ensure that the information is kept confidential. However, we can disclose personal information if:

It is required by law

You provide consent – either implicitly or for the sake of their own care, or explicitly for other purposes

It is justified to be in the public interest

Some of this information will be held centrally and used for statistical purposes. Where we hold data centrally, we take strict and secure measures to ensure that individual patients cannot be identified.

Information may be used for clinical audit purposes to monitor the quality of service provided and may be held centrally and used for statistical purposes. Where we do this, we ensure that your personal information cannot be identified.

Sometimes your information may be requested to be used for clinical research purposes – the practice will always gain your consent before releasing the information.

Improvements in information technology are also making it possible for us to share data with other healthcare providers with the objective of providing you with better care.

Patients can choose to withdraw their consent to their data being used in this way. When the practice is about to participate in any new data-sharing scheme we will make patients aware by displaying prominent notices in the surgery and on our website at least four weeks before the scheme is due to start. We will also explain clearly what you have to do to ‘opt-out’ of each new scheme.

A patient can object to their personal information being shared with other health care providers but if this limits the treatment that you can receive then the doctor will explain this to you at the time.

 

Mobile Telephone

If you provide us with your mobile phone number we may use this to send you reminders about any appointments or other health screening information being carried out.

Our Website does use cookies to optimise your experience. The ‘Remember my details’ feature on our online prescription form uses first party cookies on your computer to store your information. This information is only used to remember your details and is never passed to any third party (cookies must be enabled for this to work).

Using this feature means that you agree to the use of cookies as required by the EU Data Protection Directive 95/46/EC. You have the option to decline the use of cookies on your first visit to the website.

 

CCTV

CCTV is in place in internal areas of our practice.

It has been installed solely for the safety and security of our patients and staff, to prevent and deter crime.

Images are recorded 24 hours a day and stored on the hard drives of the recording devices that are situated in secure areas and only the practice managers and those delivering technical support services will have access to the system.

The CCTV only records images and does not record audio.

All CCTV recordings are stored on our recording devices for approximately 2 months before being deleted.

There are signs in the practice telling you that CCTV is in place and we have registered this with the Information Commissioner.

We will only ever share information with the relevant authorities in connection with the safety and security of patients and staff and will not share with any other third parties.

Visitors to the practice have the right to request to see images of themselves on CCTV as part of a request made under the privacy legislation. Like all subject access requests, it must be made in writing. There may be a charge made for this service.


We have followed the CCTV guidelines produced by the Information Commissioners’ Office.

 

Telephone Calls

All telephone calls to and from the practice will be recorded in order to check any instructions given to us, for training purposes, for crime prevention and to improve the quality of our services. A message will inform you of this each time you ring the practice. Please be aware that calls will also be recorded when anyone from the practice rings you.

The recordings are stored within our telephone system and are deleted after approximately 6 months.

 

Risk Stratification

Risk stratification is a process for identifying and managing patients who are at high risk of requiring emergency or urgent care and planning the management for that patient. Typically this is because patients have a long term condition such as COPD, cancer or other medical condition at risk of sudden worsening. NHS England (the national Commissioning Board) encourages GPs to use risk stratification tools as part of their local strategies for supporting patients with long-term conditions and to provide care plans and planned care with the aim to prevent avoidable admissions or other emergency care.

Information about you is collected through the clinical systems from a number of sources including NHS Trusts and from this GP practice. A risk score is then arrived at through an analysis of your de-identified information using software provided by NHS North East and West Devon CCG as the data processor and is provided back in an identifiable form to your GP or member of your care team as data controller.

Risk stratification enables your GP to focus on preventing ill health and not just the treatment of sickness. If necessary your GP may be able to offer you additional services.

Please note that you have the right to opt out of Risk Stratification.

 

Opting Out

Should you have any concerns about how your information is managed or wish to opt out of any data collection at the practice, please contact the practice, or your healthcare professional to discuss how the disclosure of your personal information can be limited.

Patients have the right to change their minds and reverse a previous decision. Please contact the practice, if you change your mind regarding any previous choice.

 

Invoice Validation

If you have received treatment within the NHS your personal information may be shared within a strictly monitored, secure and confidential environment in order to determine which Clinical Commissioning Group should pay for the treatment or procedure you have received.

Information such as your name, address, GP practice and date of treatment may be passed on to enable the billing process - these details are held in a secure environment and kept confidential. This information will only be used to validate invoices and will not be shared for any further commissioning purposes.

 

How do we maintain the confidentiality of your records?

We are committed to protecting your privacy and will only use information collected lawfully in accordance with the Data Protection Act 1998 (which is overseen by the Information Commissioner’s Office), Human Rights Act, the Common Law Duty of Confidentiality, and the NHS Codes of Confidentiality and Security. Every staff member who works for an NHS organisation has a legal obligation to maintain the confidentiality of patient information.

All of our staff, contractors and committee members receive appropriate and regular training to ensure they are aware of their personal responsibilities and have legal and contractual obligations to uphold confidentiality, enforceable through disciplinary procedures. Only a limited number of authorised staff have access to personal information where it is appropriate to their role and is strictly on a need-to-know basis.

We maintain our duty of confidentiality to you at all times. We will only ever use or pass on information about you if others involved in your care have a genuine need for it. We will not disclose your information to any third party without your permission unless there are exceptional circumstances (i.e. life or death situations), or where the law requires information to be passed on.

 

Who are our partner organisations?

We may also have to share your information, subject to strict agreements on how it will be used, with the following organisations:

NHS Trusts

Specialist Trusts

Independent Contractors such as dentists, opticians, pharmacists

Private Sector Providers

Voluntary Sector Providers

Ambulance Trusts

Clinical Commissioning Groups

Social Care Services

Local Authorities

Education Services

Fire and Rescue Services

Police

Other ‘data processors’

 

How long do we keep data for?

In line with the Department of Health Code, we will retain / store your health record for your lifetime. When a patient dies, we will review the record and generally it will be destroyed 10 years later, unless there is a reason to keep it for longer.

If you move away or register with another practice, your records will be forwarded on to the new practice.

 

Access to personal information

You have a right under the Data Protection Act 1998 to access/view information the practice holds about you, and to have it amended or removed should it be inaccurate. This is known as ‘the right of subject access’. If we do hold information about you we will:

give you a description of it

tell you why we are holding it

tell you who it could be disclosed to

let you have a copy of the information in an intelligible form

If you would like to make a ‘subject access request’ please contact the practice manager in writing. We will not charge you for making a subject access request although an admin fee may be charged if a request clearly has no basis in fact or is excessive and/or repetitive. In the majority of circumstances, a request will be completed within one month of receipt. Any changes to this notice will be published on our website and on the practice notice board.

The practice is registered as a data controller under the Data Protection Act 1998. The registration number is Z5632954 and can be viewed online in the public register on their website

 

Change of Details

It is important that you tell the person treating you if any of your details such as your name or address have changed or if any of your details such as date of birth is incorrect in order for this to be amended. You have a responsibility to inform us of any changes so our records are accurate and up to date for you.

 

Notification

The Data Protection Act 1998 requires organisations to register a notification with the Information Commissioner to describe the purposes for which they process personal and sensitive information. This information is publicly available on the Information Commissioners Office website . The practice is registered with the Information Commissioners Office (ICO).

 

Data Controller

The Data Controller, responsible for keeping your information secure and confidential can be contacted at the surgery by telephoning 01404 548544 or by via the practice email D-CCG.InformationHonitonSurgery@nhs.net  Any changes to this notice will be published on our website and displayed in prominent notices in the surgery.

The Partnership is registered as a data controller under the Data Protection Act 1998 Z5632954. Our registration can be viewed on-line in the public register on their website.

 

Consent

By consenting to this privacy notice you are giving us permission to process your personal data for the purposes identified.

Further information

Further information about the way in which the NHS uses personal information and your rights in that respect can be found in:

The NHS Care Record Guarantee

The NHS Constitution

NHS Digital’s Guide to Confidentiality in Health & Social Care

An independent review of information about patients is shared across the health and care system led by Dame Fiona Caldicott was conducted in 2012. The report, Information: To share or not to share? The Information Governance Review, be found here.

NHS England – Better Data, Informed Commissioning, Driving Improved Outcomes: Clinical Data Sets provides further information about the data flowing within the NHS to support commissioning.

Please visit the NHS Digital website for further information about their work. Information about their responsibility for collecting data from across the health and social care system can be found.

The Information Commissioner’s Office is the Regulator for the Data Protection Act 1998 and offer independent advice and guidance on the law and personal data, including your rights and how to access your personal information. For further information please visit their website 

Adult Practice Privacy Leaflet can be found here

Child Practice Privacy Leaflet can be found here

 


 

Website Privacy Policy

We are committed to protecting the privacy of all individuals using this website.

This policy explains how we use any personal information we collect from you through this website.

 

Collection of personal information

You can access most of the pages on our website without giving us your personal information. However, you may choose to provide us with your personal information on some pages of the website by completing an on-line form.

By submitting your personal information, you consent to our use of the information as set out in this privacy policy.

 

Use of personal information

We shall use any personal information you give to us, in accordance with this policy, and with any additional statements appearing on forms used for submitting your personal information. We shall not disclose your personal information to any third parties without obtaining your prior consent unless we are required by law to do so. In particular:

We shall use your personal information to administer, and may respond to, your request.

We shall securely store the information you supply together with any response we may provide.

If you contact us regarding the website we may use your details to reply to you. If you make a comment or complaint about other aspects of the service we may use your details to investigate your comments.

 

Website privacy

This website uses https to ensure data is encrypted in transmission. This encryption, known as TLS encryption protocol, allows us to protect your privacy. You can usually verify that the page is encrypted by seeing a small lock symbol in the upper left corner of your browser and the website address is prefixed with https://.

 

Data storage

All data obtained by us is held and used in compliance with the Data Protection Act 2018.

 

Cookie Policy

Please click here to read our Cookie Policy.

 

Links

This website contains links to other sites. We are not responsible for the privacy practices of third parties that run any other websites. Please refer to their own privacy policies for more information.

 

Access to your personal information

You have a right under the Data Protection Act 2018 to ask us to provide you with the information we hold about you and to have any inaccuracies corrected. If you would like to access a copy of your information, please contact the Practice Manager using the following contact details in the heading above.

Thank you! Your submission has been received!

Oops! Something went wrong while submitting the form

Surgery NewsChange your Contact DetailsConditions and TreatmentsFind Local Services
Self Help Advice and Tools

Self Help Advice and Tools

NHS 111

NHS 111

111 is the NHS non-emergency number. It’s fast, easy and free. Call 111 and speak to a highly trained adviser, supported by healthcare professionals.

Friends and Family Test

Patient Survey

How likely are you to recommend this Surgery to friends and family if they needed similar care or treatment?  Please spend 2 minutes to take the Friends and Family Test.
Click here to view our results.

NHS Choices

NHS Choices

NHS Choices is the online 'front door' to the NHS.  Get insights into the factors that influence visits to NHS Choices provided by the NHS Choices reporting team.

Patient UK

Patient UK

Patient is one of the most trusted medical resources online, supplying evidence based information on a wide range of medical and health topics to patients and health professionals.

Top of Page