windfarmImage: Leena Kent

Main Privacy Notice - Direct Care (routine care and referrals)

< Back to policies & procedures

Introduction

This Privacy Notice has been written in line with the EU General Data Protection Regulation (GDPR) 2016, Data Protection Act 2018 and guidance from the Information Commissioner (IC)

 

What is this Privacy Notice about? 

Privacy Notice is the conditions which must be met for any activity involving personal data or special categories of personal data to be lawful. Being transparent and providing accessible information to individuals about how an organisation will use their personal information is a key element of data protection legislations. The most common way to provide this information is in a Privacy Notice.

This Privacy Notice tells you about information we collect and hold about you, the legal bases for collecting and holding the information, what we do with it, how we keep it secure (confidential), who we might share it with and what your rights are in relation to your information.

 

Who we are

Invicta Health CIC has been formed by a federation of General Practitioners working in the Canterbury and South Kent Coast areas of East Kent. Our aim is to provide local, high-quality services for local people by collaborating with other established organisations in the health and social care community.

In 2009 nearly twenty local practices, representing almost 200,000 patients and 120 doctors, felt that the establishment of such an organisation would ensure that the development of local services would build on the values of General Practice and best suit the needs of local people. Since then, additional practices have joined from Ashford and South Kent, and we now have 33 member practices covering around 400,000 patients. The directors of the company are GPs from our member practices. We provide integrated services with local practices, the acute and community trusts, the ambulance trust, and other organisations.

 

Types of information we use

We use the following types of information/data:

  • Personal data or sensitive personal/special categories of personal data such as:
    • demographics – name, address, date of birth, postcode, NHS number
    • racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, medical/health data, sexual life or sexual orientation data.
  • Pseudonymised - about individuals but with identifying details (such as name or NHS number) replaced with a unique code.
  • Anonymised - about individuals but with identifying details removed.
  • Aggregated - anonymised information grouped together so that it doesn't identify individuals.
 

What we use your personal data and special categories of personal data (known as or sensitive personal) for

We use and share information about you in several ways. These include:

  • Primary uses - information from your GP medical record which can be made available to other NHS and public sector organisations, including doctors, nurses, and care professionals in order to help them make the best-informed decision, and provide you with the best possible direct care delivery. 
  • Secondary uses - information from your GP medical record involves extracting identifiable data and (usually) sharing that data with other NHS organisations, for the purpose of indirect care. Examples include using your information for research, auditing, and healthcare planning (population health management).
 

Our identity and contact details 

Corporate Office Contact Details

  • Monday to Friday: 9am to 5pm 
  • Corporate Service, Birchington Medical Centre, Birchington, Kent, CT7 9HQ
  • Telephone: 0800 242 5199 
  • Telephone: 01227 470 057

Birchington Medical Centre

  • Minnis Road, Birchington–on–Sea, Birchington, CT7 9HQ 
  • Telephone: 01843 848818

Orchard House Surgery - branch surgery of Birchington Medical Centre

  • Bleak Road, Romney Marsh, Lydd, Kent, TN29 9AE
  • Telephone: 01797 320 307

East Cliff Practice

  • The Montefiore Medical Centre, Dumpton Park Drive, Ramsgate, CT11 8AD
  • Telephone: 01843 855800

Church Lane Health Centre

  • Church Lane, New Romney, Kent, TN28 8ER
  • Telephone: 01797 364756

Martello Health Centre

  • 20 Chapel Road, Dymchurch, Romney Marsh, Kent, TN29 0TD
  • Telephone: 01303 875 700

St James Surgery

  • 2 Harold Street, Dover, Kent, CT16 1SF
  • Telephone: 01304 225 559

St Peters Surgery

  • 6 Oaklands Avenue, Broadstairs, CT10 2SQ
  • Telephone: 01843 608 860
 

Our Data Protection Officers

For Invicta Health Corporate Office and Non-Practice Functions:

  • Richard Newell (Your-DPO) – Contactable via the Corporate Office.

Our Practices: 

 

Organisations we share your personal information with

We share information about you with other GPs, NHS acute or mental health trusts, local authorities, community health providers, pharmacists, commissioning organisations, medical research organisations and some specific non NHS organisations for the purposes of direct and indirect care delivery of care. 

We are required under the law to provide you with the following information:

  • How we process your personal data
  • the purpose of processing
  • recipient/categories of your personal data
  • the identity of our Data Protection Office
  • how long we retain personal information about you
  • the lawful bases for the sharing/processing, and,
  • your rights - to view, request access copies of your personal information, or object to the processing.

Please contact us to receive the full version of this information including a table of the organisations we share information about you with split into the following categories. In all cases, Controller and Data Protection Officer are as listed in section 6 and 7 above.

 

What is EMIS Systems or Vision System Local Record Sharing?

Your GP medical record is held on our secure clinical system called EMIS Web. This clinical system allows for local record sharing with other healthcare providers who are commissioned in your area to provide care (e.g. acute hospitals, mental and community health). Through this record sharing, clinicians are able to see clinical information entered by other organisations who are party to the EMIS Web local record sharing agreement.

This local sharing is used to provide direct patient care for services such as continued extended access, home visits, universal offers, musculoskeletal service, GP at front door and other neighbourhood services in line the local Care delivery strategy and the NHS ICS.
It also enables specific GPs identify their patients with highly complex, multiple morbidity and/or frailty, who might benefit from targeted multi-disciplinary team support as part of case management and care planning (the "Case Finding Purpose").

How will my information be made available?

The information is accessed in real time and on-demand, meaning that data from your GP record is neither extracted, nor uploaded, nor sent anywhere. The data remains within your GP EMIS database and users are allowed read-view access only. If you have any concerns regarding EMIS local record sharing you can opt out by speaking to your GP Surgery.

 

What do we use anonymised data for?

We use anonymised data to plan health care services. Specifically we use it to:

  • check the quality and efficiency of the health services we provide;
  • prepare performance reports on the services we provide and,
  • review the healthcare we provide in order they are of the highest standard.
 

Details of data linkage with other datasets 

Data may be de-identified and linked so that it can be used to improve health care and development and monitor NHS performance. Where data is used for these statistical purposes, stringent measures are taken to ensure individual patients cannot be identified.

When analysing current health services and proposals for developing future services it is sometimes necessary to link separate individual datasets to be able to produce a comprehensive evaluation.  This may involve linking primary care GP data with other data such as secondary uses service (SUS) data (inpatient, outpatient, and A&E).  In some cases, there may also be a need to link local datasets which could include a range of acute-based services such as radiology, physiotherapy, audiology etc, as well as mental health and community-based services such as Improving Access to Psychological Therapies (IAPT), community nursing, podiatry etc.  When carrying out this analysis, the linkage of these datasets is always done using a unique identifier that does not reveal a person’s identity.

The organisation responsible for processing de-identified and linked data under this category, on behalf of the Practice is South Coast Kent ICB We ensure that the data processor is legally and contractually bound to operate and prove security arrangements are in place where data that could or does identify a person are processed. 

 

What safeguards are in place to ensure data that identifies me is secure?

We only use information that may identify you in accordance with the UK GDPR and DPA 2018. These legislations require us to process your data only if there is a lawful basis for doing so and that any processing must be fair, lawful and transparent.

We also ensure the information we hold is kept in secure locations, restrict access to information to authorised personnel only, protect personal and confidential information held on equipment such as laptops with encryption (which masks data so that unauthorised users cannot see or make sense of it).

Our appropriate technical and security measures include: 

  • The ability to ensure ongoing confidentiality, integrity, availability and resilience of our systems;
  • the ability to quickly restore availability and access to personal information in the event of a physical or technical incident; and
  • a process regularly testing, assessing and evaluating the effectiveness of security measures, and ensure they comply with the concept of privacy by design and default.

The NHS Digital Code of Practice on Confidential Information applies to all of our staff, and they are required to protect your information, inform you of how your information will be used, and allow you to decide if and how your information can be shared. All staff are trained to ensure information is kept confidential.

We are registered with the Information Commissioner’s Office (ICO) as a data controller and collects data for a variety of purposes. A copy of the registration is available through the ICO website. You can search using ‘Invicta Health’ or your practice name or ICO Data Protection Register number Z1491690.

 

What are your rights?

Where information from which you can be identified is held, you have the:

  • Right of access to view or request copies of the records 
  • Right to rectification of inaccurate personal data or special categories of personal data
  • Right to restriction of the processing of your data where accuracy of the data is contested, processing is unlawful or where we no longer need the data for the purposes of the processing
  • Right to object to any automated individual decision-making
  • Right to data portability by requesting the data which you provided to us (not data generated by us) in a structured, commonly used machine readable format. Your right to portability applies only where:
    • data is processed by automated means, and
    • you provided consent to the processing or,
    • the processing is necessary for the fulfilment of a contract

These rights will only apply where we cannot demonstrate compelling legitimate grounds for continued processing of your personal data for the purposes of direct provision of care, and compliance with a legal obligation to which we are subject.

Your right to erasure (right to be forgotten) will only apply where you had given ‘consent’ to process your personal health data and later withdrew the consent, and does not apply to the extent where the processing of your personal health data is necessary for:

You can exercise your rights at any time by contacting the Practice (data controller) or the Data Protection Officer (DPO) at the address below, although we will first need to explain how this may affect the care you receive and any overriding legitimate grounds for the processing that may apply.

 

Gaining access to the data we hold about you

You have the right to see or have a copy of personal data we hold that can identify you. You do not need to give a reason to see your data. However, some information may be withheld under some exceptional circumstances.

If you want to access your personal information you can make a request in writing (including email) or you can speak with a member of our staff.  You may be asked to complete our Subject Access Request (SAR) form with the details of your request – we can support with this as needed.  Please navigate to our ‘Accessing Medical Records’ area of our website for more information on this. 

 

What is the right to know?

The Freedom of Information Act 2000 (FOIA) gives people a general right of access to information held by or on behalf of public authorities, promoting a culture of openness and accountability across the public sector.

What sort of information can I request?

In theory, you can request any information that the Practice holds that does not fall under an exemption under the FOI Act. You may not ask for information that is covered by the Data Protection Act or EU General Data Protection Regulation (GDPR) under FOIA.  However, you can request this under a Subject Access Request – see section above ‘Gaining access to the data we hold about you’.

How do I make a request for information?

Your request must be in writing. 

For postal applications (the applicant’s name and address should be included):

  • Address: Freedom of Information, FOI Lead, Invicta Health CIC, Corporate Service, Birchington Medical Centre, Birchington, Kent, CT7 9HQ
  • For email applications (must include the applicant’s name) Contact us online
 

Glossary of Terms

Common Law of Duty of Confidentiality

Is not written out in one document like the GDPR or an Act of Parliament. Common Law is also referred to as ‘judge-made’ or case law. In practice, this means that all patient/client information, whether held on paper, computer, visually or audio recorded, or held in the memory of the professional, must not normally be disclosed without the consent of the patient/client. However, where the disclosure/sharing of the patient/client information is for the purpose of Direct Care consent to such disclosure/sharing may be implied where it is informed, given there is a legitimate relationship between the patient/client and the health professional.

Learn more online on the Department of Health website

Personal Data

Means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Special Categories of Personal Data

Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.

INVICTA HEALTH

Invicta Health Head Office
Corporate Service
Birchington Medical Centre
Birchington
Kent, CT7 9HQ

Tel: 0800 242 5199 or 01227 470057

Registered address: Camburgh House, 27 New Dover Road, Canterbury, Kent, CT1 3DN