Important - Important Announcement!
99 Horton Park Avenue, Bradford, West Yorkshire, BD7 3EG
Telephone: 01274087646
We're open
See our other Locations
New Hey Surgery, 2 Brompton Road, Bradford, West Yorkshire, BD4 7JD | Telephone: 01274 723953
Please read this privacy notice (‘Privacy Notice’) carefully, as it contains important information about how we use the personal and healthcare information we collect on your behalf.
How we use your personal information
This privacy notice explains why the practice collects information about patients, members of staff and visitors to the practice, known as Data Subjects and how we use your information.
So that we can provide you with the best possible service, a variety of information is collected about you from a range of sources, such as your local NHS hospitals. This information is used to support your healthcare. Under the UK General Data Protection Regulation (UK GDPR) information about your physical and mental health, racial or ethnic origin and religious belief are considered as special category (sometimes known as sensitive) personal information and is subject to strict laws governing its use. This page explains why the Practice collects personal information about you, the ways in which such information may be used, and your rights under the UK General Data Protection Regulation. The Practice is legally responsible for ensuring its processing of personal information is in compliance with the general data protection regulation. The practice becomes what is known as the data controller, which simply means that we are responsible for maintaining the security and confidentiality of the personal information that you provide us with.
Security of Information
Confidentiality affects everyone: Horton Park Medical Practice collect’s, stores and uses large amounts of personal and sensitive personal data every day, such as medical records, personnel records and computerised information. This data is used by many people in the course of their work.
We take our duty to protect personal information and confidentiality very seriously and we are committed to comply with all relevant legislation and to take all reasonable measures to ensure the confidentiality and security of personal data for which we are responsible, whether computerised or on paper.
The partners have appointed a Senior Information Risk Owner who is accountable for the management of all information assets and any associated risks and incidents, and a Caldicott Guardian who is responsible for the management of patient information and patient confidentiality.
Legal Basis for processing your information
Under UK GDPR the Practice are mandated to identify a legal basis to process your personal information.
Special Category data (Sensitive Data including Health Records)
For personal data
Why do we collect information about you
All clinicians and health and social care professionals caring for you keep records about your health and any treatment and care you receive from the NHS. These records help to ensure that you receive the best possible care. They may be paper or electronic and they may include:
It is essential that your details are accurate and up to date. Always check that your personal details are correct when you visit us and please inform us of any changes to your contact details. This minimises the risk of you not receiving important correspondence.
By providing the Practice with their contact details, patients are agreeing to the Practice using those channels to communicate with them about their healthcare, i.e. by letter (postal address), by voice mail or voice message (telephone or mobile number), by text message (mobile number) or by email (email address).
How your personal information is used
In general, your records are used to direct, manage, and deliver the care you receive to ensure that:
The NHS care record guarantee
The Care Record Guarantee is our commitment that we will use records about you in ways that respect your rights and promote your health and wellbeing. Copies of the full document can be obtained from:
https://digital.nhs.uk/binaries/content/assets/legacy/pdf/1/8/care_record_guarantee.pdf
The Records Management Code of Practice
This Records Management Code of Practice for Health and Social Care 2020 is a guide for the NHS to use in relation to the practice of managing records. It is relevant to organisations who work within, or under contract to NHS organisations in England. This also includes public health functions in Local Authorities and Adult Social Care where there is joint care provided within the NHS.
The Code is based on current legal requirements and professional best practice.
https://www.nhsx.nhs.uk/information-governance/guidance/records-management-code/
How long are records retained
All records are retained and destroyed in accordance with the NHS Records Management Code of Practice.
The Practice does not keep patient records for longer than necessary and all records are destroyed confidentially once their retention period has been met, and the Practice has made the decision that the records are no longer required.
When do we share information about you
We share information about you with others directly involved in your care; and share more limited information for indirect care purposes, both of which are described below.
Everyone working within the NHS has a legal duty to keep information about you confidential. Similarly, anyone who receives information from us also has a legal duty to keep it confidential.
Direct Care Purposes
You may be receiving care from other people as well as the NHS, for example Social Care Services. We may need to share some information about you with them so we can all work together for your benefit if they have a genuine need for it or we have your permission. Therefore, we may also share your information, subject to strict agreement about how it will be used, with:
Indirect Care Purposes:
We also use information we hold about you to:
Refusing or withdrawing consent
Nationally there are strict controls on how your information is used for these purposes. These control whether your information has to be de-identified first and with whom we may share identifiable information. You can find out more about these purposes, which are also known as secondary uses, on the NHS England and NHS Digital’s websites:
National Data Opt Out
“How the NHS and care services use your information”
Whenever you use a health or care service, such as attending Accident & Emergency or using Community Care services, important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment.
The information collected about you when you use these services can also be used and provided to other organisations for purposes beyond your individual care, for instance to help with:
This may only take place when there is a clear legal basis to use this information. All these uses help to provide better health and care for you, your family and future generations. Confidential patient information about your health and care is only used like this where allowed by law.
Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information isn’t needed.
You have a choice about whether you want your confidential patient information to be used in this way. If you are happy with this use of information you do not need to do anything. If you do choose to opt out your confidential patient information will still be used to support your individual care.
To find out more or to register your choice to opt out, please visit www.nhs.uk/your-nhs-data-matters. On this web page you will:
You can also find out more about how patient information is used at:
https://www.hra.nhs.uk/information-about-patients/ (which covers health and care research); and
https://understandingpatientdata.org.uk/what-you-need-know (which covers how and why patient information is used, the safeguards and how decisions are made)
You can change your mind about your choice at any time.
Data being used or shared for purposes beyond individual care does not include your data being shared with insurance companies or used for marketing purposes and data would only be used in this way with your specific agreement.
OpenSAFELY COVID-19 Service
The NHS England OpenSAFELY COVID-19 Service is a secure, transparent, open-source software platform for analysis of electronic health data. The system provides access to de-identified (pseudonymised) personal data to support Approved Users (academics, analysts, and data scientists) to undertake approved projects for COVID-19 research, COVID-19 clinical audit, COVID-19 service evaluation and COVID-19 health surveillance purposes.
The purposes for processing are to identify medical conditions and medications that affect the risk or impact of COVID-19 infection on individuals; this will assist with identifying risk factors associated with poor patient outcomes as well as information to monitor and predict demand on health services.
Further information can be found here
The NHS England OpenSAFELY COVID-19 service – privacy notice – NHS Digital
Data Subjects Rights
Under the UK General Data Protection Regulation (UK GDPR)
Your right to object
You have the right to restrict how and with whom we share information in your records that identifies you. If you object to us sharing your information we will record this explicitly within your records so that all healthcare professionals and staff involved with your care are aware of your decision. If you choose not to allow us to share your information with other health or social care professionals involved with your care, it may make the provision of treatment or care more difficult or unavailable.
Please discuss any concerns with the clinician treating you so that you are aware of any potential impact. You can also change your mind at any time about a disclosure decision.
SMS Text messaging
When attending the Practice for an appointment or a procedure you may be asked to confirm that the Practice has an accurate contact number and mobile telephone number for you. This can be used to provide appointment details via SMS text messages and automated calls to advise you of appointment times.
CCTV
We employ surveillance cameras (CCTV) on and around our practice in order to:
You have a right to make a Subject Access Request of surveillance information recorded of yourself and ask for a copy of it. Requests should be directed to the address below and you will need to provide further details as contained in the section ‘How you can access your records’. The details you provide must contain sufficient information to identify you and assist us in finding the images on our systems.
We reserve the right to withhold information where permissible by the UK General Data Protection Regulation (GDPR) 2018 and we will only retain surveillance data for a reasonable period or as long as is required by law. In certain circumstances (high profile investigations, serious or criminal incidents) we may need to disclose CCTV data for legal reasons. When this is done there is a requirement for the organisation that has received the images to adhere to the UK GDPR.
How you can access your health records
The UK GDPR gives you a right to access the information we hold about you on our records. Requests must be made in writing to the Practice. The Practice will provide your information to you within one month (this can be extended dependent on the complexity of the request) from receipt of your application.
Write to:
The Access to Records Department
Horton Park Medical Practice
99 Horton Park Avenue
BD73EG
How long are records retained
All records are retained and destroyed in accordance with the NHS Records Management Code of Practice.
The Practice does not keep patient records for longer than necessary and all records are destroyed confidentially once their retention period has been met, and the Practice has made the decision that the records are no longer required.
We carefully consider any personal information that we store about you, and we will not keep your information for longer than is necessary for the purposes as set out in this Privacy Notice.
Freedom of Information
The Freedom of information Act 2000 provides any person with the right to obtain certain information held by the Practice, subject to a number of exemptions. If you would like to request some information from us, please contact us
Please note: if your request is for information we hold about you (for example, your health record), please instead see above, under “How You Can Access Your Records”.
We may amend this privacy notice at any time so please review it frequently. The date at the top of this page will be amended each time this notice is updated
Data Controller
The Data Controller responsible for keeping your information confidential is:
Horton Park Medical Practice
Angela Worobel – Practice Manager
Dr Robert Amedzro- GP Partner and Caldicott Guardian
Data Protection Officer (DPO)
The appointed DPO is Daljeet Sharry-Khan – Daljeet.sharry-khan@nhs.net
Raising a concern
Patients who have a concern about any aspect of their care or treatment at the Practice or about the way their records have been managed, should contact the Practice Manager.
If you have any concerns about how we handle your information you have a right to complain to the Information Commissioners Office about it.
UK GDPR requires organisations to lodge a notification with the Information Commissioner to describe the purposes for which they process personal information. These details are publicly available from:
Information Commissioner’s Office
Wycliffe House, Water Lane
Wilmslow, SK9 5AF
Telephone: 0303 123 1113
Website: www.ico.org.uk
————————————————————————————————————————————————————————
For Patients Aged 13 and Over
A ‘data privacy notice’ is a statement created by an organisation, which explains how personal and confidential information about patients is collected, processed, used and shared. This may also be called a privacy statement, fair processing statement/notice or privacy policy. This data privacy notice is issued by Horton Park Medical Practice (referred to as ‘the Practice’ and ‘we’/’us’/’our’ from this point onwards).
Why we need your information and how it will be used by health staff for your healthcare
The health professionals who work with you to provide your care will keep records about the treatment and support you receive. Having this information available will help these professionals to work together and share vital information about your health and wellbeing needs.
Health and social care professionals will be able to use the information to assess your needs and work in partnership with you to decide the most suitable treatment or support. We also use your information to inform you of services, for example reminding you of an appointment. We do not use your information for marketing purposes.
Who will be controlling your information?
The Practice (we) will be controlling your data and healthcare information.
All of our partners are required to maintain the same standard as the practice when processing your information.
Each of our partners has a legal duty to protect your personal information and act as data controller. We take your confidentiality very seriously. We are committed to make sure all personal and identifiable information is managed in accordance with the relevant legalisation to ensure your information is safe, secure and confidential.
The data we are sharing
It is important that the Horton Park Medical Practice has up to date and accurate information about you to make sure you receive the best quality care possible.
Your care record with the Practice contains key information such as:
Please be aware that our records may contain information about your parent(s) or guardian(s), if they are named as your next of kin.
What is the lawful basis for sharing your information?
In order for the Practice to process your information, we need what we call a ‘lawful basis’ to do so. There are a number of lawful bases that the Practice uses to process your data, depending on the information we need to collect.
In the majority of cases, the lawful basis will be for your care. Other bases may be a legal requirement, public task, or a mandatory obligation on the practice for the protection of individuals. We may also use consent.
How will your information be used and accessed?
Personal information contained in your health records will only be used with a lawful basis.
Only authorised individuals are allowed to access personal information.
The information within your health record is used to provide you with the most suitable care and support that you need. The information in your health record helps professionals make better decisions about your care in conjunction with you and ensure it is safe and effective.
How long do we keep your information?
Records are retained according to NHS guidance and any statutory or legal requirements for prescribed time spans.
Who will see and share your information?
The Practice releases your information to other authorised parties that it has a legal duty to share it with, those who you may have given consent to, those who need to know to continue your care and those who have a lawful basis.
Your information will only be shared with authorised parties who are providing you with direct care, or third parties authorised by the Practice (who do not have a lawful basis), only if you have first given your consent.
Where disclosure is necessary to safeguard you, or others, or is in the public interest
Where there is a legal duty to do so, for example a court order or prevention of crime.
Your data might be shared in exceptional circumstances with countries other than the UK, where it is required for continuation of care.
Your rights as a ‘Data Subject’
Under the Data Protection Act 2018, you have certain rights:
These rights are:
Some of these rights are dependent on the circumstances around which the information is held.
If at any point you believe the information we hold or process is incorrect, please contact the Data Protection Officer by emailing the details below.
If you wish to raise a concern or a complaint you can do so by contacting the care professional providing your care or treatment, or the organisation’s Data Protection Officer.
If you are not satisfied with the response you receive or believe we are processing your personal data not in accordance with the law, you can make a complaint with the Information Commissioner’s Office (ICO): https://ico.org.uk/
If you have a question regarding you or your child’s data, please contact:
Daljeet Sharry-Khan – Data Protection Officer at Daljeet.Sharry-Khan@nhs.net 07395796639