Privacy Notice
Framlingham Medical Practice
Framlingham takes privacy seriously and we want to provide you with information about your rights, who we share your information with and how we keep it secure.
Please use the links below to find more information about the practice and data protection.
Information Sharing in Suffolk
Privacy / Transparency Notice
In response to receiving a completed Processing Activities Log which Framlingham Medical Practice has confirmed is an accurate and complete record of processing carried out by the practice, the following suggested Privacy / Transparency Notice has been drafted.
It is intended to satisfy all the requirements for privacy notices listed by the Information Commissioner and set out below.
Framlingham Medical Practice and Your Information
Framlingham Medical Practice takes your privacy very seriously. We are registered with the Information Commissioner’s Office as a Data Controller and our registration number is Z751095X.
If you have any questions or wish to make a request in relation to your information, please contact us at;
Framlingham Medical Practice
Pembroke Road
Framlingham
Woodbridge
IP13 9HA
Data Protection Officer: Emma Cooper emma.cooper35@nhs.net
Framlingham Medical Practice aims to provide you with the highest quality health care. To do this we must keep records about you, your health and the care we have provided or plan to provide to you.
Your doctor and other health professionals caring for you, such as nurses or physiotherapists, keep records about your health and treatment so that they are able to provide you with the best possible care.
These records are called your ‘health care record’ and may be stored in paper form or on computer and electronic systems and may include Personal Data;
- basic details about you, such as address, date of birth, NHS number, and next of kin
as well as Sensitive Personal Data;
- contact we have had with you, such as clinical visits
- notes and reports about your health
- details and records about your treatment and care
- results of x-rays, laboratory tests etc.
Healthcare providers are permitted to collect, store, use and share this information under Data Protection Legislation which has a specific section related to healthcare information.
What do we do with your information?
- Refer you to other healthcare providers when you need other service or tests
- Share samples with laboratories for testing (like blood samples)
- Share test results with hospitals or community services (like blood test results)
- Allow out of hours or extended hours GPs to look at your health record when you are going to an appointment
- Send prescriptions to a pharmacy
- Patients are texted in relation to healthcare services
- Samples are provided to the courier for delivery to pathology
- Share reports with the coroner
- Receive reports of appointments you have attended elsewhere such as with the community nurse or if you have had a stay in hospital
Follow this link Appendix A – Framlingham Medical Practice Routine Sharing Partners to see a list of the partners that we usually share with.
Framlingham Medical Practice has signed a Suffolk Wide Information Sharing Agreement which allows health and social care providers to agree a secure and lawful way to share your information.
What else do we do with your information?
Along with activities related directly to your care, we also use information in ways which allow us to check that care is safe and provide data for the improvement and planning of services.
- Quality / payment / performance reports are provided to service commissioners
- As part of clinical research – information that identifies you will be removed, unless you have consented to being identified
- Undertaking clinical audits within the practice
- Supporting staff training
Sharing when Required by Law
Sometimes we will be required by law to share your information and will not always be able to discuss this with you directly. Examples might be for the purposes of detection or prevention of crime, where it is in the wider public interest, to safeguard children or vulnerable adults, reporting infectious diseases or where required by court order.
Information Access and Rights
Data protection law provides you with a number of rights that the practice is committed to supporting you with;
Right to Access
You have the right to obtain:
- confirmation that your information is being used, stored or shared by the practice
- a copy of information held about you
If you only require a particular part of your record, tell us and this may mean we can respond quicker.
We will respond to your request within one month of receipt or will tell you when it might take longer.
We are required to validate your identity including the identity of someone making a request on your behalf
Right to Object or Withdrawn Consent
We mainly use, store and share your information because we are permitted in order to deliver your healthcare but you do have a right to object to us doing this.
Where we are using, storing and sharing your information based on explicit consent you have provided, you have a right to withdraw that consent at any time.
Our Data Protection Officer will be happy to speak with you about any concerns you have.
Right to Correction
If information about you is incorrect, you are entitled to request that we correct it
There may be occasions, where we are required by law to maintain the original information – our Data Protection Officer will talk to you about this and you may request that the information is not used during this time
We will respond to your request within one month of receipt or will tell you when it might take longer.
Complaints
You also have the right to make complaints and request investigations into the way your information is used. Please contact our Data Protection Officer or visit the link below for more information.
For more detailed information on your rights visit ICO Guide to the general data protection regulation gdpr / individual rights
Case Finding
Sometimes your information will be used to identify whether you need particular support from us.
Those involved in your care might look at particular ‘indicators’ (such as particular conditions) and contact you or take action for healthcare purposes. For example, this might be to prevent you from having to visit accident and emergency by supporting you in your own home or in the community.
We will use automated technology to help us to identify people that might require support but ultimately, the decision about how or whether to provide extra support you is made by those involved in your care.
Our Data Protection Officer will be happy to speak to you about this if you have concerns or objections.
Information Technology
The practice will use third parties to provide services that involve your information such as;
- Removal and destruction of confidential waste
- Provision of clinical systems
- Provision of connectively and servers
Data analytics or warehousing (these allow us to make decisions about care or see how effectively the practice is run – personal data will never be sold or made available to organisations not related to your care delivery)
We have contracts in place with these third parties that prevent them from using it in any other way that instructed. These contracts also require them to maintain good standards of security to ensure your confidentiality.
Please visit this link Appendix A – Framlingham Medical Practice Routine Sharing Partners to find out more about our sharing partners and providers.
How do we Protect your Information?
We are committed to ensuring the security and confidentiality of your information. There are a number of ways we do this;
Staff receive annual training about protecting and using personal data
Policies are in place for staff to follow and are regularly reviewed
We check that only the minimum amount of data is shared or accessed
We use ‘smartcards’ to access systems, this helps to ensure that the right people are accessing data – people with a ‘need to know’
We use encrypted emails and storage which would make it difficult for someone to ‘intercept’ your information
We report and manage incidents to make sure we learn from them and improve
We put in place contracts that require providers and suppliers to protect your data as well
We do not send your data outside of the EEA
How Long Do We Keep Your Information?
In line with the Department of Health Code, we will retain / store your health record for your lifetime. When a patient dies, we will review the record and generally it will be destroyed 10 years later, unless there is a reason to keep it for longer.
If you move away or register with another practice, we will send your records to the new practice.
Framlingham use the following organisations to process data on our behalf. They are contractually bound to manage your information securely.
Processing Activities |
Sharing Partners (including any third party providers of services) |
Link |
|||
Referral / Test Results |
Ipswich Hospital |
||||
West Suffolk Hospital |
|||||
Norfolk and Norwich Hospital. |
|||||
Addenbrookes Hospital. |
|||||
West Suffolk Disability Resource Centre | Papworth Trust |
www.papworthtrust.org.uk/locations/west-suffolk-disability-resource-centre |
||||
Guy's & St Thomas |
|||||
Great Ormond Street |
|||||
Aldeburgh Community Hospital |
|
||||
James Paget Hospital |
|||||
Colchester Hospital |
|||||
Broomfield Hospital |
http://www.meht.nhs.uk/patients-and-visitors/our-hospitals/broomfield-hospital/ |
||||
UCLH |
|||||
Royal Marsden Hospital |
|||||
Moorfields Eye Hospital |
|||||
Royal National Orthopaedic Hospital |
|||||
Nuffield Health, Ipswich |
|||||
BMI St Edmunds Hospital |
https://www.bmihealthcare.co.uk/hospitals/bmi-st-edmunds-hospital |
||||
Spire Cambridge Lea Hospital |
https://www.spirehealthcare.com/spire-cambridge-lea-hospital/ |
||||
Spire Norwich Hospital |
|||||
Suffolk Community Health |
|||||
Norfolk & Suffolk Foundation Trust |
|||||
Mills Meadow Care Home |
|||||
CareUK |
www.careuk.com/care-homes/our-care-homes/our.../improving-services-in-suffolk |
||||
Express Diagnostics (24hr ECGS |
www.expressdiagnostics.co.uk/patients/heart-tests/24-hour-holter-ecg/ |
||||
Foxearth Nursing Home |
https://www.carehome.co.uk/carehome.cfm/searchazref/20001515FOXA |
||||
St Nicolas Hospice |
|||||
The Pathology Partnership |
https://www.healthwatchsuffolk.co.uk/.../the-pathology-partnership-riverside-clinic-ip… |
||||
St Elizabeths Hospice Ipswich |
|||||
Macmillan |
https://www.macmillan.org.uk/fundraising/inyourarea/england/suffolk/suffolk.aspx |
||||
In-health Community Endoscopy |
http://www.inhealthendoscopy.co.uk/location/ipswich-ravenswood |
||||
Turning Point |
http://www.turning-point.co.uk/suffolk-recovery-network-ipswich.aspx |
||||
One Life Suffolk |
|||||
Allied Physios. |
|||||
HR Service Provider |
Suffolk GP Federation |
||||
EPS |
Framlingham Pharmacy |
|
|||
Debenham Pharmacy |
|
||||
Lloyds Pharmacy |
|
||||
Boots Woodbridge |
https://www.boots.com/stores/134-woodbridge-thoroughfare-ip12-1al |
||||
Boots Harleston |
https://www.boots.com/stores/5951-harleston-norfolk-ip20-9ah |
||||
Hado Pharmacy |
https://www.nhs.uk/Services/pharmacies/Overview/DefaultView.aspx?id=89838 |
||||
Welbeing Pharmacy Diss |
https://www.nhs.uk/Services/pharmacies/Overview/DefaultView.aspx?id=6418 |
||||
Pharmacy 2U |
|||||
Fresenius Homecare |
|||||
Select Home Delivery |
|||||
Fittleworth |
|||||
Jade Euromed |
|||||
Salts Medilink |
|||||
Charter Ltd |
|||||
Alphamed |
|||||
NWOS |
|||||
Sia Healthcare |
|||||
Discharge notices |
Ipswich Hospital |
||||
West Suffolk Hospital |
|||||
Norfolk and Norwich Hospital. |
|||||
Addenbrookes Hospital. |
|||||
West Suffolk Disability Resource Centre | Papworth Trust |
www.papworthtrust.org.uk/locations/west-suffolk-disability-resource-centre |
||||
Aldeburgh Community Hospital |
|
||||
James Paget Hospital |
|||||
Colchester Hospital |
|||||
Broomfield Hospital |
http://www.meht.nhs.uk/patients-and-visitors/our-hospitals/broomfield-hospital/ |
||||
UCLH |
|||||
Royal Marsden Hospital |
|||||
Moorfields Eye Hospital |
|||||
Royal National Orthopaedic Hospital |
|||||
Nuffield Health, Ipswich |
|||||
BMI St Edmunds Hospital |
https://www.bmihealthcare.co.uk/hospitals/bmi-st-edmunds-hospital |
||||
Spire Cambridge Lea Hospital |
https://www.spirehealthcare.com/spire-cambridge-lea-hospital/ |
||||
Spire Norwich Hospital |
|||||
Guy's & St Thomas |
|||||
Great Ormond Street |
|||||
Confidential waste removal |
Avena |
||||
Patient Texts/Clinical System |
TPP System One |
||||
Pathology Courier |
Ipswich Hospital |
||||
Courier | ERS Medical | ersmedical.co.uk | |||
North East Essex, Suffolk Pathology Service | |||||
PCSE Notes |
City Sprint |
||||
Coroner reports |
Ipswich Coroners |
https://www.suffolk.gov.uk/births-deaths-and-ceremonies/the-coroner-service/ |
|||
Norfolk Coroners |
https://www.norfolk.gov.uk/births-ceremonies-and-deaths/deaths/the-coroner |
||||
Commissioner Reports |
West Suffolk CCG |
||||
Ipswich and East Suffolk CCG |
|||||
Provision of IT Systems and Support |
North East London CCG |
||||
Provision of clinical system |
TPP (SystmOne) |
||||
Health Software | AccurX | https://www.accurx.com/ | |||
Airmid | (SMS and Email direct from clinical system) https://tpp- uk.com/products/airmid/ | ||||
C the Signs | https://cthesigns.co.uk/ | ||||
Child Health Provide | https://www.provide.org.uk/ | ||||
Eclipse Solutions | www.eclipsegroup.co.uk/ | ||||
E-Referrals | https://digital.nhs.uk/services/e-referral-service | ||||
Pinnacle (COVID Vaccinations) | https://www.oasisgroup.com/services/notespace.6453.html | ||||
Infectious Diseases |
Anglia Health Protection Team |
https://www.gov.uk/guidance/contacts-phe-health-protection-teams |
|||
Health Hardware | Northwest Ostomy Supplies | www.nhs.uk/service-search/pharmacies/profile/55423 Spacelabs https://www.spacelabshealthcare.com/ | |||
Payroll |
SAGE |
|
|||
Telecomms | X-on Connect |
https://www.x-on.co.uk/service/surgery-connect/healthcare-phone-system.htm |
|||
IT Service Provider | Jayex | ||||
Training Provider | Blue Stream | ||||
Dispex | |||||
e-LH | |||||
M & K Training | |||||
Translation Service | DA Languages | ||||
Website Provider | WebAdore | ||||
Other Providers |
Broomwell Healthwatch |
||||
iPlato | |||||
Arden& Gem CSU |
|||||
Thurd Party Audit | Xyla Health & Wellbeing | ||||
Managed Disclosure | UCheck | www.ucheck.co.uk |
Please find our staff policy for Data Security and Protection