Accessing someone else’s information
Accessing someone else’s information
As a parent, family member or carer, you may be able to access services for someone else. We call this having proxy access. We can set this up for you if you are both registered with us.
To requests proxy access:
- collect a proxy access form from reception from 10am to 6pm
Linked profiles in your NHS account
Once proxy access is set up, you can access the other person’s profile in your NHS account, using the NHS App or website.
The NHS website has information about using linked profiles to access services for someone else.
Comments & Complaints
We aim to provide the best service to our patients. If you have comments, suggestions or complaints to make, please put them in writing to our practice manager.
A full Complaints Procedure is available from the Reception Desk in the surgery.
Confidentiality, Data Protection and GDPR
We ask you for personal information so that you can receive appropriate care and treatment. This information is recorded in your notes and on the computer and we are registered under the Data Protection Act. The practice will ensure that patient confidentiality is maintained at all times by all members of the practice team. However, for the effective functioning of a multi-disciplinary team it is sometimes necessary that medical information about you is shared between members of the practice team.
You do have the right to access your records in accordance with the Access To Records Act 1990, but before you do this you will have to give your signed consent to disclose information to third parties.The only exceptions are the provision of information when making a referral to another doctor, or disclosure by statute.
Freedom Of Information – Publication Scheme
The Freedom of Information Act 2000 obliges the practice to produce a Publication Scheme.
A Publication Scheme is a guide to the ‘classes’ of information the practice intends to routinely make available.
This scheme is available from reception.
How We Use Your Information
Our Privacy Notice explains why we collect your information and how that information may be used.
Under the Data Protection Act 1998 we must ensure that your personal confidential data (PCD) is handled in ways that are transparent and that you would reasonably expect. The Health and Social Care Act 2012 has altered the way that personal confidential data are processed. Consequently, you must be aware and understand these changes and that you have the opportunity to object and understand how to exercise that right.
Health care professionals who provide you with care are required by law to maintain records about your health and any treatment or care you have received within any NHS organisation. These records help to provide you with the best possible healthcare.
NHS health records may be processed electronically, on paper or a mixture of both and through established working procedures and best practice coupled with technology we ensure your personal data is kept confidential and secure. Records held by us may include the following:
- Your personal data, such as address and next of kin;
- Your history with us, such as appointments, vaccinations, clinic visits, emergency appointments, etc;
- Notes and reports about your health;
- Details about your treatment and care;
- Results of investigations and referrals such as blood tests, x-rays, etc; and
- Relevant information from other health professionals, relatives or those who care for you.
We obtain and hold data for the sole purpose of providing healthcare services to our patients and we will ensure that the information is kept confidential. We can disclose your personal information if:
- It is required by law;
- You consent – either implicitly or for the sake of your own care or explicitly for other purposes; and
- It is justified in the public interest
Some of this information is held centrally and used for statistical purposes. Where we hold data centrally, we take strict measures to ensure that individual patients cannot be identified. Sometimes your information may be requested to be used for research purposes – the Practice will always endeavour to gain your consent before releasing the information.
The Health and Social Care Information Centre (HSCIC), under the powers of the Health and Social Care Act 2012 (HSCA), can request Personal Confidential Data (PCD) from GP
Practices without seeking patient consent. The Care. Data Programme allows PCD to be collected by the HSCIC to ensure that the quality and safety of services is consistent across the country. Improvements in information technology are also making it possible for us to share data with other healthcare providers with the objective of providing you with better care.
You may choose to withdraw your consent to personal data being used in this way. When we are about to participate in a new data-sharing project we will make patients aware by displaying prominent notices in the Practice and on our website at least four weeks before the scheme is due to start. Instructions will be provided to explain what you have to do to ‘opt out’ of each new scheme.
A patient can object to their personal information being shared with other health care providers but if this limits the treatment that you can receive then the doctor will explain this to you at the time.
Privacy Notices
Commissioning, planning, risk stratification, patient identification
Direct Care – routine care and referrals
Risk Stratification
Risk Stratification is a process that helps your family doctor (GP) to help you manage your health. By using selected information from your health records, a secure NHS computer system will look at any recent treatments you have had in hospital or in the surgery and any existing health conditions that you have. This will alert your doctor to the likelihood of a possible deterioration in your health. The clinical team at the surgery will use the information to help you get early care and treatment where it is needed. NHS Central Southern CSU DSCRO (the regional processing centre) supports GP Practices with this work. NHS security systems will protect your health information and patient confidentiality at all times.
Please note that you have the right to opt out of Risk Stratification
Should you have any concerns about how your information is managed, or wish to opt out of any data collection at the Practice, please contact the practice, or your healthcare professional to discuss how the disclosure of your personal information can be limited.
Patients have the right to change their minds and reverse a previous decision. Please contact the practice, if you change your mind regarding any previous choice.
Invoice validation
We will use limited information about individual patients when validating invoices received for your healthcare, to ensure that the invoice is accurate and genuine. This will be performed in a secure environment and will be carried out by a limited number of authorised CSU staff. These activities and all identifiable information will remain with the Controlled Environment for Finance (CEfF) approved by NHS England. Where possible we will strive to use the NHS number as a quasi-identifier to preserve your confidentiality.
Our partner organisations
We may need to share your information, subject to agreement on how it will be used, with the following organisations:
- NHS Trusts
- Health & Social Care Information Centre (HSCIC)
- Specialist Trusts
- Independent Contractors such as dentists, opticians, pharmacists
- Private Sector Providers
- Voluntary Sector Providers
- Ambulance Trusts
- Clinical Commissioning Groups
- Commissioning Support Units
- Social Care Services
- Local Authorities
- Education Services
- Fire and Rescue Services
- Police
- Other ‘data processors’
Access to personal information held about you
Under the Data Protection Act 1998, you have a right to access/view information we hold about you, and to have it amended or removed should it be inaccurate. If we do hold information about you we will:
- give you a description of it;
- tell you why we are holding it;
- tell you who it could be disclosed to; and
- let you have a copy of the information in an intelligible form.
If you would like to make a ‘subject access request’, please contact the Practice Manager in writing. There may be a charge for this service.
Any changes to this notice will be published on our website and in a prominent area at the Practice.
We are registered as a data controller under the Data Protection Act 1998. The registration can be viewed online in the public register at:
How we keep your personal information confidential
We are committed to protecting your privacy and will only use information collected lawfully in accordance with the Data Protection Act 1998 (which is overseen by the Information
Commissioner’s Office), Human Rights Act, the Common Law Duty of Confidentiality, and the NHS Codes of Confidentiality and Security.
Extended Hours care
Pickhurst Surgery are working in collaboration with Hayeswick PCN to offer our patients appointments outside of the core GP hours which include GP appointments after 6.30pm in the evening and on Saturdays and nurse appointments on Saturdays. Please speak with reception if this is the type of appointment you require.
Privacy Notice – Accurx
As part of the Digital First National programme of work, GP Practices are required to provide a tool for patients to access primary care services.
The aim of the Accurx platform is to improve communications between healthcare staff and patients resulting in improved outcomes and productivity. The platform facilitates digital communications between the practice and our patients. If you have a non-urgent healthcare concern or need to contact the Practice for any medical or admin reason, click on the online via our website or via NHS app or via NHS website. Fill out the online form, which will then be reviewed and processed by our healthcare professionals to decide the right care for you. We will respond to online requests within 2 working days for medical queries and 5 working days for admin queries. Accurx is approved by NHS England to be used by GP practices and the other systems involved in patient care. NHS England has a lengthy assurance process to make sure they meet the highest standards of safety and security. Your data is safe and is shared only with your GP Practice for the purposes of your direct care. Your data is stored and sent securely using industry best practices, and Accurx only collect the data that is necessary to allow your GP Practice to provide you with care. The Practice uses the following Accurx features: · Online consultations · Video consultations · AccuMail · SMS · Friends and Family test · Record Views The Accurx privacy notice can be found on their website here: Accurx | Privacy Policy. |
1) Controller
contact details
Forge Close Surgery
2) Data Protection Officer contact details | GP Data Protection Officer |
3) Purpose of the processing | The aim of the Accurx platform is to improve communications between healthcare staff and patients resulting in improved outcomes and productivity. The platform facilitates digital communications between the practice and our patients. |
4) Lawful basis for processing | Under UK GDPR and DPA 2018 –
6(1)(e) ‘…necessary for the performance of a task carried out in the public interest or in the exercise of official authority…’. 9(2)(h) ‘…medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems…’ |
5) Recipient or categories of recipients of the shared data | Data may be shared with Accurx, and their sub-processors such as cloud services used for Accurx’ own storage, communications, security, engineering, and similar purposes. |
6) Rights to object | You have the right under Article 21 of the UK GDPR to object to your personal information being processed. Please contact the Practice if you wish to object to the processing of your data. You should be aware that this is a right to raise an objection which is not the same as having an absolute right to have your wishes granted in every circumstance. |
7) Right to access and correct | You have the right to access copies of the data that is being shared and have any inaccuracies corrected. There is no right to have accurate medical records deleted except when ordered by a court of Law. |
8) Retention period | The data will be retained for active use during the processing and thereafter according to NHS Policies and the law. |
9) Right to Complain. | You have the right to complain to us about the way your data is handled or processed. To so, please contact the Practice using the following details:
Forge Close Surgery Forge Close, Hayes, Bromley, Kent BR2 7LL
If you remain unsatisfied with our response, you have a right to complain to the Information Commissioner’s Office. To do so, you can use this link or call their helpline Tel: 0303 123 1113 (local rate) or 01625 545 745 (national rate) There are National Offices for Scotland, Northern Ireland and Wales, (see ICO website). |
Privacy Notices
Summary Care Record
Your Summary Care Record (SCR) is a new way of caring for you in an emergency. The SCR is an electronic copy of information from us. Your SCR has only the most important information about your health like; medicines you take, allergies you have and any medicines that make you ill. If you need further information please do not hesitate to contact us. Please advise your family and friends.
The Health & Social Care Information Centre (HSCIC) part of NHS England, will start to extract confidential information from your medical records that can be used by the NHS to improve the services offered so we can provide the best possible care for everyone. This information along with your postcode and NHS number but not your name, are sent to a secure system where it can be linked with other health information. This allows those planning NHS services or carrying out medical research to use information from different parts of the NHS in a way which does not identify you. If you need further information please do not hesitate to contact us. Please advise your family and friends.