Practice Policies & Patient Information
Data Protection
This Practice complies with the General Data Protection Regulation 2016 and the Data Protection Act 2018.
We use your Information to provide you with Health Care services, and share you information with other organisations involved in your care.
GDPR
How we Use Your Information
The Sheldon Practice will be what’s known as the ‘Controller’ of your personal data. We collect basic personal data about you and location-based information. This does include name, address and contact details such as email and mobile number etc. We will also collect sensitive confidential data known as “special category personal data”, in the form of health information, religious belief (if required in a healthcare setting) ethnicity and sex life information that are linked to your healthcare, we may also receive this information about you from other health providers or third parties.
Patient Communication
Because we are obliged to protect any confidential information, we hold about you and we take this very seriously, it is imperative that you let us know immediately if you change any of your contact details.
We may contact you using SMS texting to your mobile phone if we need to notify you about appointments and other services that we provide to you involving your direct care, therefore you must ensure that we have your up-to-date details. This is to ensure we are sure we are contacting you and not another person. As this is operated on an ‘opt out’ basis we will assume that you give us permission to contact you via SMS if you have provided us with your mobile telephone number. Please let us know if you wish to opt out of this SMS service. We may also contact you using the email address you have provided to us. Please ensure that we have your up-to-date details.
There may be occasions where authorised research facilities would like you to take part in research. Your contact details may be used to invite you to receive further information about such research opportunities.
Privacy Policy
The NHS Long Term plan published in 2019 requires the digitisation of all primary care paper medical records, commonly known as ‘Lloyd George’ records or ‘A4 medical records’
Having paper based medical records restricts the use of technology to provide ‘joined up’ services and therefore the current paper records will be transferred to a digital format and then destroyed.
This will involve the current patient paper medical records being scanned and then entered directly into a patient’s electronic medical record. This work will be completed by a third party supplier, Northgate Public Services, whose security standards have been reviewed by NHS Birmingham and Solihull Clinical Commissioning Group.
We are required by Data Protection law to provide you with the following information about how we handle your information.
Data Controller contact details
|
Dr B Jheeta
The Sheldon Practice | 169-171 | Church Road | Sheldon | Birmingham | B26 3TT 0121 743 5511 |
Data Protection Officer contact details
|
Paul Couldrey Director PCIG Consulting Ltd7 Westacre Drive, Quarry Bank, Dudley, West Midlands, DY5 2EE. 0115 838 6770 |
Purpose of the processing
|
Transferring the current paper medical records into patients’ electronic medical records.
|
Lawful basis for processing
|
The following provisions of the General Data Protection Regulation permit us to digitise existing paper medical records:
Article 6(1)(e) – ‘processing is necessary…in the exercise of official authority vested in the controller…’’
Article 9(2)(h) – ‘processing is necessary for the purpose of preventative…medicine…the provision of health or social care or treatment or the management of health or social care systems and services…’ |
Recipient or categories of recipients of the processed data
|
The paper patient records will be shared with Northgate Public Services, who will scan and digitise the current paper medical records before destroying them. |
Right to access and correct | You have the right to access your medical record and have any errors or mistakes corrected. Please speak to a member of staff or look at our ‘subject access request’ policy on our website The Sheldon Practice – NHS GP Surgery based in Sheldon (digipractice.org) |
Retention period
|
GP medical records will be kept in line with the law and national guidance. Information on how long records can be kept can be found at: https://digital.nhs.uk/article/1202/Records-Management-Code-of-Practice-for-Health-and-Social-Care-2016 or speak to the practice.
The paper medical records will be destroyed three months after they are transferred to an electronic format. |
The practice holds medical records to provide medical treatment and advice and patients have a relationship with a GP in order for them to be provide health and care service to you. We therefore do not require your consent to transfer these papers records to an electronic format.
If you have any questions about this project, please contact Dr Jheeta or DPO Paul Couldrey.
Details of Supplier
Northgate Public Services
Queens Court
Wilmslow Road
Alderley Edge
Cheshire
SK9 7RR
SafeGaurding
The Practice is dedicated to ensuring that the principles and duties of safeguarding adults and children are holistically, consistently, and conscientiously applied with the wellbeing of all, at the heart of what we do.
Our legal basis for processing For the General Data Protection Regulation (GDPR) purposes is: –
Article 6(1)(e) ‘…exercise of official authority…’.
For the processing of special categories data, the basis is: –
Article 9(2)(b) – ‘processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law…’
Your Rights Relating to Your Summary Care Record
Regardless of your past decisions about your Summary Care Record preferences, you will still have the same options that you currently have in place to opt out of having a Summary Care Record, including the opportunity to opt-back in to having a Summary Care Record or opt back in to allow sharing of Additional Information.
You can exercise these rights by doing the following:
- Choose to have a Summary Care Record with all information shared. This means that any authorised, registered and regulated health and care professionals will be able to see a detailed Summary Care Record, including Core and Additional Information, if they need to provide you with direct care.
- Choose to have a Summary Care Record with Core information only. This means that any authorised, registered and regulated health and care professionals will be able to see limited information about allergies and medications in your Summary Care Record if they need to provide you with direct care.
- Choose to opt-out of having a Summary Care Record altogether. This means that you do not want any information shared with other authorised, registered and regulated health and care professionals involved in your direct care. You will not be able to change this preference at the time if you require direct care away from your GP practice. This means that no authorised, registered and regulated health and care professionals will be able to see information held in your GP records if they need to provide you with direct care, including in an emergency.
Zero Tolerance Policy
The NHS operate a zero tolerance policy with regard to violence and abuse and the practice has the right to remove violent patients from the list with immediate effect in order to safeguard practice staff, patients and other persons. Violence in this context includes actual or threatened physical violence or verbal abuse which leads to fear for a person’s safety. In this situation we will notify the patient in writing of their removal from the list and record in the patient’s medical records the fact of the removal and the circumstances leading to it.