Practice Policies & Patient Information
Accessibility
Disabled Access
We are committed to providing accessible healthcare for all our patients.
Our surgery has step-free access at the main entrance and throughout the ground floor with a number of disabled parking bays on site. There are wide doorways suitable for wheelchair users, and 3 accessible toilets available. We have a lift in the main waiting room for anyone who is unable to use the stairs.
We have a hearing loop system at reception to support patients with hearing loss. Assistance dogs are welcome in the building. You are also welcome to bring along your person of choice for assistance or support during your appointment(s). If you do not have a person available but still need some assistance in getting around the practice, please do let us know either before your appointment or on arrival and one of the team will be more than happy to help.
If you require information in an alternative format, such as large print, easy-read, or need support with communication, please let our reception team know and we will do our best to accommodate your needs. We are also happy to liaise with you via email or text if this best suits your needs.
If you have any specific access requirements or would like to discuss how we can best support you during your visit, please contact the surgery in advance.
Call Recording Policy
-
Introduction
This policy outlines the Practice’s approach to the recording of telephone calls. Call recording is implemented to support operational quality, compliance with legal obligations, and staff/patient safety. This policy ensures that recordings are handled in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA), and the Telecommunications Act 1984.
-
Purpose
The purpose of call recording is to provide an exact record of incoming and outgoing calls which can:
- Protect the interests of both patients and staff
- Identify staff training and development needs
- Protect staff from abusive or nuisance calls
- Establish facts in the event of a complaint or incident
- Support investigations into medico-legal claims
- Improve processes and ensuring compliance with regulatory requirements
- Provide evidence in staff disciplinary or grievance matters
- Support clinicians with records of telephone consultations
-
Scope
This policy applies to:
- All external incoming and outgoing calls made via the practice telephone system
- Internal calls and call transfers
Recording automatically stops when the call is terminated by the staff member.
-
Call Recording Overview
- All calls are recorded via the practice telephone system
- Recordings are encrypted (256-bit) and stored on a secure server at the system provider’s headquarters as required by NHS Security standards.
- Access is strictly controlled and monitored by the Data Controller
- Calls can be accessed through password-protected logins
-
Informing Callers
The Practice will make all reasonable efforts to inform callers that calls are being recorded. This is done by:
- An automated pre-recorded message at the start of all incoming calls, also detailing the option to not have there clinical consultation recorded.
- A summary of this policy on the Practice website.
- Information displayed in the waiting room.
Continuing with the call after hearing the message is considered implied consent.
-
Playback and Monitoring
Playback or monitoring of calls will be undertaken by:
- GP Partners
- Senior management (Practice Business Manager, Assistant Practice Manager and Operations Manager)
Playback will occur in a private and secure setting
- Monitoring is only permitted for specific business reasons (e.g. training, complaint investigation, or legal compliance)
- Browsing recordings without valid reason is prohibited
-
Access, Retention, and Subject Requests
a) Access and Control
- Access to recordings is limited to authorised individuals
- Any request must state a clear, justified purpose
- Requests must include details such as date/time of call, parties involved, and relevant extensions
b) Subject Access Requests (SARs)
- Patients can request to hear or receive recordings of calls involving them
- All SARs must be submitted in writing under the provisions of the UK GDPR
- The Practice will respond in accordance with standard data protection timelines
- Where appropriate, patients may be invited to listen to recordings on-site
c) Third-Party & Legal Requests
- Requests from bodies such as the police must be directed to the Data Controller or Practice Business Manager
- In disciplinary matters, call recordings may be accessed only with written approval from the Data Controller
- Any breach of this policy or unauthorised access will be treated as a serious offence and may result in disciplinary action
-
Retention
Call recordings will be retained for up to 12 months, unless legally required to be held longer.
-
Opt-Out Policy
If a patient requests that their call is not recorded with a non-clinical member of the team, then they are to be advised that it is organisation policy to record all calls to ensure the safety and security of both patient and staff/Clinicians.
If a patient requests that their call is not recorded with a clinical member of the team, the recording will be paused for the remainder of their call.
-
Confidentiality and Compliance
- Recordings are treated as personal data under the UK GDPR
- All recordings must be stored and accessed in a way that protects individual privacy
- The Practice is registered with the Information Commissioner’s Office (ICO) for relevant processing activities
Any suspected or actual breach of this policy must be reported immediately to a line manager or the Data Controller.
Chaperone Policy
We will always respect your privacy, dignity and your religious and cultural beliefs particularly when intimate examinations are advisable – these will only be carried out with your express agreement and you will be offered a chaperone to attend the examination if you so wish.
You may also request a chaperone when making the appointment or on arrival at the surgery (please let the receptionist know) or at any time during the consultation.
Confidentiality
You can be assured that anything you discuss with any member of the surgery staff, whether doctor, nurse or receptionist, will remain confidential. Even if you are under 16, nothing will be said to anyone, including parents, other family members, care workers or teachers, without your permission. The only reason why we might want to consider passing on confidential information without your permission would be to protect either you or someone else from serious harm. In this situation, we would always try to discuss this with you first.
If you have any worries or queries about confidentiality, please ask a member of staff.
If you would like to discuss matters of a confidential nature, either with our receptionists or a member of the dispensary team, we have a side room available in reception for this purpose.
Consent To Treatment
Consent to treatment means a person must give permission before they receive any type of medical treatment, test or examination. This must be done on the basis of an explanation by a clinician. Consent from a patient is needed regardless of the procedure, whether it’s a physical examination or something else. The principle of consent is an important part of medical ethics and international human rights law. For consent to be valid, it must be voluntary and informed, and the person consenting must have the capacity to make the decision. The meaning of these terms are: If an adult has the capacity to make a voluntary and informed decision to consent to or refuse a particular treatment, their decision must be respected. This is still the case even if refusing treatment would result in their death, or the death of their unborn child. If a person does not have the capacity to make a decision about their treatment and they have not appointed a lasting power of attorney (LPA), the healthcare professionals treating them can go ahead and give treatment if they believe it’s in the person’s best interests. But clinicians must take reasonable steps to discuss the situation with the person’s friends or relatives before making these decisions. Read more about assessing the capacity to consent, which explains what someone can do if they know their capacity to consent may be affected in the future. Consent can be given: Someone could also give non-verbal consent, as long as they understand the treatment or examination about to take place – for example, holding out an arm for a blood test. Consent should be given to the healthcare professional responsible for the person’s treatment. This could be a: If someone’s going to have a major procedure, such as an operation, their consent should be secured well in advance so they have plenty of time to understand the procedure and ask questions. If they change their mind at any point before the procedure, they’re entitled to withdraw their previous consent. If they’re able to, consent is usually given by patients themselves. But someone with parental responsibility may need to give consent for a child up to the age of 16 to have treatment. Find out more about how the rules of consent apply to children and young people There are some exceptions when treatment may be able to go ahead without the person’s consent, even if they’re capable of giving their permission. It may not be necessary to obtain consent if a person: A person may be being kept alive with supportive treatments, such as lung ventilation, without having made an advance decision, which outlines the care they’d refuse to receive. In these cases, a decision about continuing or stopping treatment needs to be made based on what that person’s best interests are believed to be. To help reach a decision, healthcare professionals should discuss the issue with the relatives and friends of the person receiving the treatment. They should consider: Treatment can be stopped if there’s an agreement that continuing treatment is not in the person’s best interests. The case will be referred to the courts before further action is taken if: It’s important to note the difference between stopping a person’s life support and taking a deliberate action to make them die. For example, injecting a lethal medicine would be illegal. If you believe you have received treatment you did not consent to, you can make an official complaint. Find out more about feedback and complaints about NHS services on the NHS England websiteDefining consent
How consent is given
Consent from children and young people
When consent is not needed
Consent and life support
Complaints
Data Protection
In order to provide the right level of care, we are required to hold personal information about you on our computer systems and in paper records to help us to look after your health needs, and your doctor is responsible for their accuracy and safe-keeping. Please help to keep your record up to date by informing us of any changes to your circumstances.
Confidentiality and Personal Information
Doctors and staff in the practice have access to your medical records to enable them to do their jobs. From time to time information may be shared with others involved in your care if it is necessary. Anyone with access to your record is properly trained in confidentiality issues and is governed by both legal and contractual duty to keep your details private.
All information about you is held securely and appropriate safeguards are in place to prevent accidental loss.
In some circumstances we may be required by law to release your details to statutory or other official bodies, for example if a court order is presented, or in the case of public health issues. In other circumstance you may be required to give written consent before information is released – such as for medical reports for insurance, solicitors etc.
To ensure your privacy, we will not disclose information over the telephone or fax unless we are sure that we are talking to you. Information will not be disclosed to family, friends or spouses unless we have prior written consent, and we do not, leave messages with others.
You have a right to see your records if you wish. Please ask at reception if you would like further details about our patient information leaflet. An appointment may be required. In some circumstances a fee may be payable.
Focused Care
The practice has a Focused Care worker, based in house, working alongside the practice team.
Patients can be referred by practice staff when the usual care plan does not appear to be working. The Focused Care Practitioner then works with the patient’s household to begin to unpick situations, assessing need and using local health and community contacts in order to begin to bring stability to an often chaotic situation.
For further information visit the Focused Care website.
GP Earnings
All GP practices are required to declare the mean earnings (e.g. average pay) for GPs working to deliver NHS services to patients at each practice.
The average pay for GPs working in Wellfield Health Centre in the 2024/2025 financial year was £132,966 before tax and National Insurance. This is for 5 full time GPs and 3 part time GPs who worked in the practice for more than 6 months.
However, it should be noted that the prescribed method for calculating earning is potentially misleading because it takes no account of how much time doctors spend working in the practice, and should not be used to form any judgment about GP earnings, nor to make any comparison with any other practice.
Infection Control
We aim to keep our surgery clean and tidy and offer a safe environment to our patients and staff. We are proud of our modern, purpose built Practice and endeavour to keep it clean and well maintained at all times.
If you have any concerns about cleanliness or infection control, please report these to our Reception staff.
Our GPs and nursing staff follow our Infection Control Policy to ensure the care we deliver and the equipment we use is safe.
We take additional measures to ensure we maintain the highest standards:
- Encourage staff and patients to raise any issues or report any incidents relating to cleanliness and infection control. We can discuss these and identify improvements we can make to avoid any future problems
- Carry out an annual infection control audit to make sure our infection control procedures are working
- Provide annual staff updates and training on cleanliness and infection control
- Review our policies and procedures to make sure they are adequate and meet national guidance
- Maintain the premises and equipment to a high standard within the available financial resources and ensure that all reasonable steps are taken to reduce or remove all infection risk
- Use washable or disposable materials for items such as couch rolls, modesty curtains, floor coverings, towels etc., and ensure that these are laundered, cleaned or changed frequently to minimise risk of infection
- Make Alcohol Hand Rub Gel available throughout the building
IT Policy
This practice is committed to preserving, as far as is practical, the security of data used by our information systems. This means that we will take all reasonable actions to;
Maintain the Confidentiality of all data within the practice by:
- Ensuring that only authorised persons can gain access to our systems
- Not disclosing information to anyone who has no right to see it
Maintain the integrity of all data within the practice by:
- Taking care over input
- Ensuring that all changes are reported and monitored
- Checking that the correct record is on the screen before updating
- Reporting all apparent errors and ensuring that they are resolved
Maintain the availability of all data by:
- Ensuring that all equipment is protected from intruders
- Ensuring that backups are taken at regular, predetermined intervals
- Ensuring that contingency is provided for possible failure or equipment theft and that any such contingency plans are tested and kept up to date
Additionally we will take all reasonable measures to comply with our legal responsibilities under:
Personal Data
The following IT systems are in use at the practice:
- Referral Management (using NHS numbers in referrals)
- Electronic Appointment Booking (the facility to book routine appointments online and, similarly, to cancel appointments
- Online booking of repeat prescriptions
- Summary Care Record (uploading details of your current medication and allergies to the national “spine” so that these are available for doctors involved in your care elsewhere)
- GP to GP transfers (the electronic transfer of records from practice to practice when you re-register
- Patient Access to records (the facility to view your medical records online)
If you are not already registered for online access and would like to be please contact reception.
If you would like access to your medical records enabled or would like to opt out of the local or national summary care record, please contact reception.
Privacy Policy
Privacy Notice updated June 2025
How we use your information
Introduction
This privacy notice explains in detail why Wellfield Health Centre use your personal data which we, the Data Controller, collects and processes about you. A Data Controller determines how the data will be processed and used with the GP practice and with others who we share this data with. We are legally responsible for ensuring that all personal data that we hold and use is done so in a way that meets the data protection principles under the General Data Protection Regulation (GDPR) and Data Protection Act 2018. This notice also explains how we handle that data and keep it safe.
Caldicott Guardian
The GP Practice has a Caldicott Guardian. A Caldicott Guardian is a senior person within a health or social care organisation, preferably a health professional, who makes sure that the personal information about those who use its services is used legally, ethically and appropriately, and that confidentiality is maintained. The Caldicott Guardian for the GP practice is:
Dr Matthew Pickford
Gmicb-hmr.wellfieldhc@nhs.net
01706 397 600
Data Protection Officer (DPO)
Under GDPR all public bodies must nominate a Data Protection Officer. The DPO is responsible for advising on compliance, training and awareness and is the main point of contact with the Information Commissioner’s Office (ICO). The DPO for the practice is:
Mr Paul Fox
Locality Information Governance Manager (Heywood, Middleton and Rochdale)
gmicb-hmr.dpo@nhs.net
We will continually review and update this privacy notice to reflect changes in our services and to comply with changes in the Law.
Details we collect about you
Whenever you attend the surgery or use another health or care service, such as attending Accident & Emergency or using Community Care Services, important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment.
NHS Health records may be electronic, on paper or a mixture of both, and we use a combination of working practices and technology to ensure that your information is kept confidential and secure. The data the surgery holds will be relevant, adequate and limited to what is required for the surgery to fulfil its duty.
Records which Wellfield Health Centre may hold about you may include the following information:
- Details about you, such as your address, next of kin, date of birth, legal representative, emergency contact details
- Any contact the surgery has had with you, such as appointments, clinic visits, emergency appointments, etc.
- Notes and reports about your health
- Details about your treatment and care including medication
- Recordings of all telephone calls to and from the surgery
- Results of investigations such as laboratory tests, x-rays, etc
- Relevant information from other health professionals, relatives or those who care for you
In addition to providing direct care we also use your data to:
- Confirm your identity to provide these services and those of your family / carers
- Understand your needs to provide the services that you request
- Obtain your opinion on our services (with consent)
- Prevent and detect fraud and corruption in the use of public funds
- Make sure we meet our statutory obligations, including those related to diversity and equalities
- Adhere to a legal requirement that will allow us to use or provide information (e.g. a formal Court Order or legislation)
Definition of Data Types
We use the following types of information / data:
Personal Data
This contains details that identify individuals even from one data item or a combination of data items. The following are demographic data items that are considered identifiable: name, address, NHS Number, full postcode, date of birth, telephone number. Call recordings are also considered personal data.
Special categories of data (previously known as sensitive data)
This is personal data consisting of information as to: race, ethnic origin, political opinions, health, religious beliefs, trade union membership, sexual life and previous criminal convictions. Under UK GDPR, this now includes biometric data and genetic data.
Personal Confidential Data (PCD)
This term came from the Caldicott review undertaken in 2013 and describes personal information about identified or identifiable individuals, which should be kept private or secret. It includes personal data and special categories of data but it is adapted to include dead as well as living people and ‘confidential’ includes both information ‘given in confidence’ and ‘that which is owed a duty of confidence’.
Pseudonymised Data or Coded Data
Individual-level information where individuals can be distinguished by using a coded reference, which does not reveal their ‘real world’ identity. When data has been pseudonymised it still retains a level of detail in the replaced data by use of a key / code or pseudonym that should allow tracking back of the data to its original state.
Anonymised Data
This is data about individuals but with all identifying details removed. Data can be considered anonymised when it does not allow identification of the individuals to whom it relates, and it is not possible that any individual could be identified from the data by any further processing of that data or by processing it together with other information which is available or likely to be available.
Aggregated Data
This is statistical information about multiple individuals that has been combined to show general trends or values without identifying individuals within the data.
How long do we keep your personal data?
Whenever we collect or process your data, we will only keep it for as long as is necessary for the purpose it was collected. We comply with the Records Management NHS Code of Practice which states that we keep records for 10 years after date of death. Following this time, the records are securely destroyed if stored on paper or archived.
Destruction will only happen following a review of the information at the end of its retention period. Where data has been identified for disposal we have the following responsibilities:
- to ensure that information held in manual form is destroyed using a cross cut shredder or contracted to a reputable confidential waste company that complies with European Standard EN15713 and obtain certificates of destruction.
- to ensure that electronic storage media used to hold or process information are destroyed or overwritten to national standards.
Our data processing activities
The law on data protection under the GDPR sets out a number of different reasons for which personal data can be processed for. The law states that we have to inform you what the legal basis is for processing personal data and also if we process special category of data such as health data what the condition is for processing. The types of processing we carry out in the GP practice and the legal bases and conditions we use to do this are outlined below:
Provision of Direct Care and administrative purposes within the GP practice
| Type of Data | Personal Data – demographics Special category of data – Health data |
| Source of Data | Patient and other health and care providers |
| Legal basis for processing personal data and Condition for processing special category of data |
The processing of personal data in the delivery of direct care and providers’ administrative purposes and in support of direct care elsewhere is supported under the following Article 6 and 9 conditions of the GDPR:
Article 6 (1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority Article 9(2)(h) – Processing is necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health and social care or treatment or the management of health and social care systems |
| Common Law Duty of Confidentiality basis | Implied Consent |
Direct care means a clinical, social or public health activity concerned with the prevention, investigation and treatment of illness and the alleviation of suffering of individuals. This is carried out by one or more registered and regulated health or social care professionals and their team with whom the individual has a legitimate relationship with. In addition, this also covers administrative purposes which are in the patient’s reasonable expectations.
To explain this, a patient has a legitimate relationship with a GP in order for them to be treated and the GP practice staff process the data in order to keep up to date records and to send referral letters etc.
Other local administrative purposes include waiting list management, performance against national targets, activity monitoring, local clinical audit and production of datasets to submit for national collections.
This processing covers the majority of our tasks to deliver health and care services to you. When we use the above legal basis and condition to process your data for direct care, consent under GDPR is not needed. However, we must still satisfy the common law duty of confidentiality and we rely on implied consent. For example, where a patient agrees to a referral from one healthcare professional to another and where the patient agrees this implies their consent.
To deliver direct care we may offer you a consultation via telephone or videoconferencing. By accepting the invitation and entering the consultation you are consenting to this. Your personal/confidential patient information will be safeguarded in the same way it would with any other consultation. Further details can be found in our Call Recording Policy.
Accelerated Patient Access to Records
The NHS wants to give people better ways to see their personal health information online. We know that people want to be able to access their health records. It can help you see test results faster. It also lets you read and review notes from your appointments in your own time.
We are now letting you see all the information within your health record automatically. If you are over 16 and have an online account, such as through the NHS App, NHS website, or another online primary care service, you will now be able to see all future notes and health records from your GP.
This means that you will be able to see notes from your appointments, as well as test results and any letters that are saved on your records. This only applies to records from your GP from 01/11/2022.
Your GP may talk to you to discuss test results before you are able to see some of your information on the app. Your doctor GP may also talk to you before your full records access is given to make sure that having access is of benefit to you. There might be some sensitive information on your record, so you should talk to your doctor if you have any concerns.
These changes only apply to people with online accounts. If you do not want an online account, you can still access your health records by requesting this information by contacting reception. The changes also only apply to personal information about you. If you are a carer and would like to see information about someone you care for, speak to reception staff.
The NHS App, website and other online services are all very secure, so no one is able to access your information except you. You’ll need to make sure you protect your login details. Don’t share your password with anyone as they will then have access to your personal information.
If you do not want to see your health record, or if you would like more information about these changes, please speak to your GP or reception staff.
Medicines Management and Optimisation
| Type of Data | Personal Data – demographics Special category of data – Health data |
| Source of Data | GP Practice |
| Legal Basis and Condition for processing special category of data under GDPR | Article 6 (1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority
Article 9 (2)(h) – Processing is necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health and social care or treatment or the management of health and social care systems |
| Confidentiality basis | Implied Consent |
Heywood, Middleton and Rochdale ICB pharmacists and pharmacy technicians work with GP practices to provide advice on medicines and prescribing queries, process repeat prescription requests and review prescribing of medicines to ensure that it is safe and cost-effective. This may require the use of identifiable information.
In cases where identifiable data is required, this is done with practice agreement and in the case of repeat prescription processing with patient consent. No data is removed from the practice’s clinical system and no changes are made to patient’s records without permission from the GP. Patient records are viewed in the GP practice.
Identifiable data is also used by our pharmacists in order to review and authorise (if appropriate) requests for high cost drugs which are not routinely funded. In cases where identifiable data is used, this is done with the consent of the patients.
Greater Manchester Care Record (GMCR)/Share For You
| Type of Data | Personal Data – demographics Special category of data – Health data |
| Source of Data | Patient and other health and care providers |
| Legal basis for processing personal data and Condition for processing special category of data |
Article 6 (1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority
Article 9(2)(h) – Processing is necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health and social care or treatment or the management of health and social care systems |
| Common Law Duty of Confidentiality basis | Implied Consent |
Sharing your patient information is critical in supporting your care and treatment, especially in situations such as the COVID-19 pandemic.
The GM Care Record allows workers in health or social care easy access to patient information that is critical to support decision-making about patient care and treatment.
It shares important information about your health and care including:
- Any current health or care issues
- Your medications
- Allergies you may have
- Results of any recent tests that you may have had
- Details on any plans created for your care or treatment
- Information on any social care or carer support you may receive
The GMCR pulls patient information from several areas of health and care including:
- primary care e.g. GP practices
- community services
- mental health services
- social care
- secondary care e.g. hospitals
- specialist services e.g. NWAS
It means that patients won’t have to keep repeating their medical history to each professional in different organisations, care plans will be followed consistently, and clinicians will be better equipped to identify patterns and plan care more effectively to meet the patients’ needs.
The amount of data that the GMCR holds is increasing all the time. Data is constantly being added, so that a combined record can be developed for all our citizens to help better decision making and more informed care and treatment.
In response to the pandemic, the GMCR also includes information about when a patient has been diagnosed with COVID-19 and whether they are self-isolating at home or have been hospitalised. This ensures continuity of care across different care settings and alternatives such as digital support can be put in place.
You can opt out at any time if you prefer that we don’t share your care record to other health and social care services.
The project has been overseen by Health Innovation Manchester and the GM Health and Social Care Partnership, working on behalf of GM’s devolved health and care partners.
Summary Care Record
| Type of Data | Personal Data – demographics Special category of data – Health data |
| Source of Data | Patient and other health and care providers |
| Legal basis for processing personal data and Condition for processing special category of data |
Article 6 (1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority
Article 9(2)(h) – Processing is necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health and social care or treatment or the management of health and social care systems |
| Common Law Duty of Confidentiality basis | Implied Consent |
The Summary Care Record (SCR) is an electronic record which contains information about the medicines you take, allergies you suffer from and any bad reactions to medicines you have had.
Storing information in one place (The SCR) makes it easier for healthcare staff to treat you in an emergency, or when your GP practice is closed, or if you attend the 7 Day Access Clinic. This information could make a difference to how a doctor decides to care for you, for example which medicines they choose to prescribe for you.
Only healthcare staff involved in your care can see your Summary Care Record. It is not compulsory to have a summary care record. If you choose to opt out of the scheme please contact the GP Practice.
Purposes other than direct individual care and treatment
This is information which is used for non-healthcare purposes. Generally this could be for research purposes, audits, service management, safeguarding, commissioning, complaints and patient and public involvement.
When your personal information is used for secondary use this should, where appropriate, be limited and de-identified so that you cannot be identified and the process is confidential.
Safeguarding
| Type of Data | Personal Data – demographics Special category of data – Health data |
| Source of Data | Patient and other health and care providers |
| Legal Basis and Condition for processing special category of data under GDPR | Article 6 (1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority
Article 9 (2)(b) – Processing is necessary for the purposes of carrying out the obligations and exercising the specific rights of the controller or the data subject in the field of …social protection law |
| Common Law Duty of Confidentiality basis | Overriding Public Interest / children and adult safeguarding legislation |
Information is provided to care providers to ensure that adult and children’s safeguarding matters are managed appropriately. Access to personal data and health information will be shared in some limited circumstances where it’s legally required for the safety of the individuals concerned. For the purposes of safeguarding children and vulnerable adults, personal and healthcare data is disclosed under the provisions of the Children Acts 1989 and 2006 and Care Act 2014.
Risk Stratification
| Type of Data | Personal Data – demographics Special category of data – Health data |
| Source of Data | GP Practice and other care providers |
| Legal Basis and Condition for processing special category of data under GDPR | Article 6 (1)(c) – Processing is necessary for compliance with a legal obligation
Article 9(2)(h) – Processing is necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health and social care or treatment or the management of health and social care systems Section 251 NHS Act 2006 |
Risk stratification entails applying computer based algorithms, or calculations to identify those patients who are most at risk from certain medical conditions and who will benefit from clinical care to help prevent or better treat their condition. To identify those patients individually from the patient community would be a lengthy and time-consuming process which would by its nature potentially not identify individuals quickly and increase the time to improve care. A GP / health professional reviews this information before a decision is made.
The use of personal and health data for risk stratification has been approved by the Secretary of State, through the Confidentiality Advisory Group of the Health Research Authority (known as Section 251 approval). This approval allows your GP or staff within your GP Practice who are responsible for providing your care, to see information that identifies you, but CCG staff will only be able to see information in a format that does not reveal your identity.
NHS England encourages GPs to use risk stratification tools as part of their local strategies for supporting patients with long-term conditions and to help and prevent avoidable admissions.
Knowledge of the risk profile of our population helps to commission appropriate preventative services and to promote quality improvement.
Risk stratification tools use various combinations of historic information about patients, for example, age, gender, diagnoses and patterns of hospital attendance and admission and primary care data collected in GP practice systems.
If you do not wish information about you to be included in our risk stratification programme, please contact the GP Practice. We can add a code to your records that will stop your information from being used for this purpose. Please see the section below regarding objections for using data for secondary uses.
National Clinical Audits
| Type of Data | Personal Data – demographics Special category of data – Health data Pseudonymised Anonymised |
| Source of Data | GP Practice and other care providers |
| Legal Basis and Condition for processing special category of data under GDPR | Article 6 (1)(c) – Processing is necessary for compliance with a legal obligation
Article 9(2)(h) – Processing is necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health and social care or treatment or the management of health and social care systems Section 251 NHS Act 2006, NHS Constitution (Health and Social Care Act 2012) |
The GP practice contributes to national clinical audits (for example the National Diabetes Audit) and will send the data which are required by NHS Digital when the law allows. This may include demographic data such as data of birth and information about your health which is recorded in coded form, for example, the clinical code for diabetes or high blood pressure.
Clinical Research
| Type of Data | Personal Data – demographics Special category of data – health data |
| Source of Data | GP Practice |
| Legal Basis and Condition for processing special category of data under GDPR | Article 6 (1)(e) – Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority
Article 9 (2)(j) – Processing is necessary for…scientific or historical research purposes… Common law duty of confidentiality – explicit consent or if there is a legal statute for this which you will be informed of |
All NHS organisations (including Health & Social Care in Northern Ireland) are expected to participate and support health and care research. The Health Research Authority make sure they protect your privacy and comply with the law when they are involved in research. Health and care research may be exploring prevention, diagnosis or treatment of disease, which includes health and social factors in any disease area. Research may be sponsored by companies developing new medicines or medical devices, NHS organisations, universities or medical research charities. The research sponsor decides what information will be collected for the study and how it will be used.
Health and care research should serve the public interest, which means that research sponsors have to demonstrate that their research serves the interests of society as a whole. They do this by following the UK Policy Framework for Health and Social Care Research. They also have to have a legal basis for any use of personally-identifiable information.
How patient information may be used for research
When you agree to take part in a research study, the sponsor will collect the minimum personally-identifiable information needed for the purposes of the research project. Information about you will be used in the ways needed to conduct and analyse the research study. NHS organisations may keep a copy of the information collected about you. Depending on the needs of the study, the information that is passed to the research sponsor may include personal data that could identify you. You can find out more about the use of patient information for the study you are taking part in from the research team or the study sponsor. You can find out who the study sponsor is from the information you were given when you agreed to take part in the study.
For some research studies, you may be asked to provide information about your health to the research team, for example in a questionnaire. Sometimes information about you will be collected for research at the same time as for your clinical care, for example when a blood test is taken. In other cases, information may be copied from your health records. Information from your health records may be linked to information from other places such as central NHS records, or information about you collected by other organisations. You will be told about this when you agree to take part in the study.
Even though consent is not the legal basis for processing personal data for research, the common law duty of confidentiality is not changing, so consent is still needed for people outside the care team to access and use confidential patient information for research, unless under the Health Service (Control of Patient Information Regulations) 2002 (‘section 251 support’) applies.
Your choices about health and care research
If you are asked about taking part in research, usually someone in the care team looking after you will contact you. People in your care team may look at your health records to check whether you are suitable to take part in a research study, before asking you whether you are interested or sending you a letter on behalf of the researcher.
It’s important for you to be aware that if you are taking part in research, or information about you is used for research, your rights to access, change or move information about you are limited. This is because researchers need to manage your information in specific ways in order for the research to be reliable and accurate. If you withdraw from a study, the sponsor will keep the information about you that it has already obtained. They may also keep information from research indefinitely.
If you would like to find out more about why and how patient data is used in research, please visit the Understanding Patient Data website: https://understandingpatientdata.org.uk/what-you-need-know
To find out more about GDPR and using personal data for research, please visit the Health Research Authority website: https://www.hra.nhs.uk/hra-guidance-general-data-protection-regulation/
Current Research Projects
The practice supports medical research by sending some of the information from patient records to the Clinical Practice Research Datalink (CPRD). CPRD is a Government organisation that provides anonymised patient data for research to improve patient and public health. You cannot be identified from the information sent to CPRD. If you do not want anonymised information from your record used in research you can opt out by informing the GP Practice.
Complaints
| Type of Data | Personal Data – demographics Special category of data – health data |
| Source of Data | Data Subject, Primary Care, Secondary Care and Community Care |
| Legal Basis and Condition for processing special category of data under GDPR | Article 6 (1)(a) – Explicit Consent
Article 9 (2)(h) – Processing is necessary for the purposes of preventative or occupational medicine for the assessment of the working capacity of the employee, medical diagnosis, the provision of health and social care or treatment or the management of health and social care systems Common law duty of confidentiality – explicit consent |
If you contact the GP Practice or NHS England about a complaint, we require your explicit consent to process this complaint for you. You will be informed of how and with whom your data will be shared by us, including if you have or you are a representative you wish the GP practice to deal with on your behalf.
Purposes requiring consent
There are also other areas of processing undertaken where consent is required from you. Under GDPR, consent must be freely given, specific, you must be informed and a record must be made that you have given your consent, to confirm you have understood.
Patient and Public Involvement
| Type of Data | Personal Data – demographics |
| Source of Data | GP Practice |
| Legal Basis and Condition for processing special category of data under GDPR | Article 6 (1)(a) – Explicit Consent
Article 9 (2)(a) – Explicit Consent |
If you have asked us to keep you regularly informed and up to date about the work of the GP Practice or if you are actively involved in our engagement and consultation activities or patient participation groups, we will collect and process personal confidential data which you share with us.
We obtain your consent for this purpose. Where you submit your details to us for involvement purposes, we will only use your information for this purpose. You can opt out at any time by contacting us using our contact details at the end of this document.
How we protect your personal data
We will use the information we collect in a manner that conforms to the General Data Protection Regulations (GDPR) and Data Protection Act 2018. The information you provide will be subject to rigorous measures and procedures to make sure it can’t be seen, accessed or disclosed to any inappropriate persons. We have an Information Governance Framework that explains the approach within the GP practice, our commitments and responsibilities to your privacy and cover a range of information and technology security areas.
Access to your personal confidential data is password protected on secure systems and securely locked in filing cabinet when on paper.
Our IT Services provider, Greater Manchester Shared Service, regularly monitor our system for potential vulnerabilities and attacks and look to always ensure security is strengthened.
All our staff have received up to date data security and protection training. They are obliged in their employment contracts to uphold confidentiality, and may face disciplinary procedures if they do not do so. We have incident reporting and management processes in place for reporting any data breaches or incidents. We learn from such events to help prevent further issues and inform patients of breaches when required.
With whom do we share your data?
As stated above, where your data is being processed for direct care this will be shared with other care providers who are providing direct care to you such as:
- NHS Trusts / Foundation Trusts
- GPs
- Out of Hours Provider (BARDOC)
- NHS Commissioning Support Units
- GP Federation (Rochdale Health Alliance)
- Primary Care Network (Canalside PCN)
- Independent Contractors such as dentists, opticians, pharmacists
- Private Sector Providers
- Voluntary Sector Providers
- Ambulance Trusts
- Clinical Commissioning Groups
- Social Care Services
- Health and Social Care Information Centre (HSCIC)
- Local Authorities
- Education Services
- Fire and Rescue Services
- Police & Judicial Services
- Voluntary Sector Providers
- National Diabetes Audit
- Other ‘data processors’
We work with third parties and suppliers (data processors) to be able for us to provide a service to you. These include:
- EMIS and Docman to provide our electronic clinical system
- NHS Greater Manchester Shared service – to provide our IT services
- Risk Stratification QRisk software provided by EMIS
- SMS Text Services provided by MJOG and PATCHS
- Nova Healthcare Solutions for Document Management
- Shred-It for the on-site destruction of confidential paper documents
There may be occasions whereby these organisations have potential access to your personal data, for example, if they are fixing an IT fault on the system. To protect your data, we have contracts and/or Information Sharing Agreements in place stipulating the data protection compliance they must have and re-enforce their responsibilities as a data processor to ensure you data is securely protected at all times.
We will not disclose your information to any 3rd party without your consent unless:
- there are exceptional circumstances (life or death situations)
- where the law requires information to be passed on as stated above
- required for fraud management – we may share information about fraudulent activity in our premises or systems. This may include sharing data about individuals with law enforcement bodies
- It is required to be disclosed to the police or other enforcement, regulatory or government body for prevention and / or detection of crime
Where is your data processed?
Your data is processed within the GP surgery and by other third parties as stated above who are UK based. Your personal data is not sent outside of the UK for processing.
Where information sharing is required with a country outside of the EU you will be informed of this and we will have a relevant Information Sharing Agreement in place. We will not disclose any health information without an appropriate lawful principle, unless there are exceptional circumstances such as when the health or safety of others is at risk, where the law requires it, or to carry out a statutory functions i.e. reporting to external bodies to meet legal obligations.
What are your rights over your personal data?
You have the following rights over your data we hold:
Subject Access Rights – you can request access to and or copies of personal data we hold about you, free of charge (subject to exemptions) and provided to you within one calendar month. We request that you provide us with adequate information in writing to process your request such as full name, address, date of birth, NHS number and details of your request and documents to verify your identity so we can process the request efficiently. On processing a request, there may be occasions when information may be withheld if your GP believes that releasing the information to you could cause serious harm to your physical or mental health. Information may also be withheld if another person (i.e. third party) is identified in the record, and they do not want their information disclosed to you. However, if the other person was acting in their professional capacity in caring for you, in normal circumstances they could not prevent you from having access to that information.
To request a copy or request access to information we hold about you and / or to request information to be corrected if it is inaccurate, please contact The Practice Manager:
Wellfield Health Centre, 116 Oldham Road, Rochdale, OL11 1AD.
Email: gmicb-hmr.wellfieldhc@nhs.net
Right to rectification – The correction of personal data when incorrect, out of date or incomplete which must be acted upon within one calendar month of receipt of such request. Please ensure the GP practice has the correct contact details for you.
Right to withdraw consent – If we have your explicit consent for any processing we do, you have the right to withdraw that consent at any time.
Right to Erasure (‘be forgotten’) – If we obtain consent for any processing we do, you have the right to have that data deleted / erased. Please note this does not apply to health records.
Right to Data Portability – If we obtain consent for any processing we do, you have the right to have data provided to you in a commonly used and machine readable format such as excel spreadsheet, csv file.
Right to object to processing – you have the right to object to processing however please note if we can demonstrate compelling legitimate grounds which outweighs the interest of you then processing can continue. If we didn’t process any information about you and your health care if would be very difficult for us to care and treat you.
When Wellfield Health Centre is about to participate in any new data-sharing or scheme that requires the processing of patient data we will make patients aware by displaying prominent notices in the surgery and on our website at least four weeks before the scheme is due to start. We will also explain clearly what you have to do to ‘opt-out’ of each new scheme.
Right to restriction of processing – This right enables individuals to suspend the processing of personal information, for example, if you want to establish its accuracy or the reason for processing it.
Objections to processing your confidential information for research and planning and “Your Data Matters”
You have a choice about whether your confidential patient information can be used for NHS research and planning purposes. If you are happy with your information to be used in this way you do not need to do anything.
In England you can register your choice to opt out of sharing your information for NHS research and planning via the “Your Data Matters” webpage: https://www.nhs.uk/your-nhs-data-matters/
If you do choose to opt out you can still agree to take part in any research study you want to, without affecting your ability to opt out of other research.
If you do choose to opt out your confidential information will still be used to support your individual care and will not prevent anonymised data from being used for purposes beyond individual care where it is anonymised in line with the Information Commissioner’s code of anonymisation.
You can also change your choice about opting out at any time.
Please note that data being used for research and planning (and other purposes beyond individual care) does not include your data being shared with insurance companies or used for marketing purposes and data would only be used in this way with your specific agreement.
Complaints / Contacting the Regulator
If you feel that your data has not been handled correctly or you are unhappy with our response to any requests you have made to us regarding the use of your personal data, please contact our Data Protection Officer / Practice Manager at the following contact details:
Email us at: gmicb-hmr.wellfieldhc@nhs.net
Or write to us at: Wellfield Health Centre, 116 Oldham Road, Rochdale, OL11 1AD
If you are not happy with our responses and wish to take your complaint to an independent body, you have the right to lodge a complaint with the Information Commissioner’s Office.
You can contact them by calling 0303 123 1133
Or go online to www.ico.org.uk/concerns
Further Information / Contact Us
We hope that the Privacy Notice has been helpful in setting out the way we handle your personal data and your rights to control it. Should you have any questions / or would like further information, please visit the websites below and / or contact either our Caldicott Guardian / Data Protection Officer / Practice Manager at the following contact details:
Email us at: gmicb-hmr.wellfieldhc@nhs.net
Or write to us at: Wellfield Health Centre, 116 Oldham Road, Rochdale, OL11 1AD
Links
If you would like to find out more information on the wider health and care system approach to using personal information or other useful information, please click and / or search for the following on the internet:
- Information Commissioners Office
- Information Governance Alliance
- NHS Digital National Data Opt Out Programme
- NHS Constitution
- NHS Care Record Guarantee
- NHS Digital Guide to Confidentiality in Health and Social Care
- Health Research Authority
- Health Research Authority Confidentiality Advisory Group (CAG)
- Access to patient records through the NHS App
Rights & Responsibilities
Patients’ Responsibilities
- Arrive on time – if you are late you may NOT be able to see the doctor.
- Please let us know as soon as possible if you cannot keep your appointment. Patients who regularly fail to attend appointments risk being removed from the practice list.
- Please try not to save up multiple problems for a single appointment.
- Please only request an urgent appointment when it is necessary.
- Please see your dentist for dental problems.
- It is important that you do not ignore correspondence such as follow up appointments from the practice as you may be at risk of removal from our practice list.
Patients’ Rights
You have a right to expect a high standard of medical care from our practice and we try at all times to provide the very best care possible within the resources available.
Very occasionally a practice/patient relationship breaks down completely. In this situation the patient may to choose to register with another practice. The practice also has the right to remove the patient from the list. This would normally only follow when a warning has failed to remedy the situation and we would give the patient the reason for removal and information on how to register with another practice.
Summary Care Record
Your patient record is held securely and confidentially on the electronic system at your GP practice. If you require treatment in another NHS healthcare setting such as an Emergency Department or Minor Injury Unit, those treating you would be better able to give you appropriate care if some of the information from the GP practice were available to them.
This information can now be shared electronically via: The Summary Care Record, used nationally across England
The information will be used only by authorised health care professionals directly involved in your care. Your permission will be asked before the information is accessed, unless the clinician is unable to ask you and there is a clinical reason for access.
Your rights
You can choose not to share your SCR. However, this will mean healthcare professionals will not have access to important information about your healthcare. If you would like to inform us of your preference, please fill out this form.
A parent or guardian can request to opt out children under 16 but ultimately it is the GP’s decision whether to create the records or not, because of their duty of care to the child. If you are the parent or guardian of a child under 16 and feel that they are able to understand, then you should make this information available to them.
Who Has Access?
Across all health care settings, including urgent care, community care and outpatient departments in England.
Information Source
GP record
What information is shared
Your SCR contains details of your:
- medicines
- allergies and adverse reactions
- illnesses and health problems
- past operations and vaccinations
Training
GPs in Training
Our practice is approved to train fully qualified doctors who wish to specialise in general practice. Our GP registrar will have had 2-4 years of experience as a qualified hospital doctor working in various specialities. They consult patients on their own, under the mentorship of our trainer.
Occasionally we ask permission to video a consultation. You will always be asked in advance and are given the option not to take part, and this will not affect your care in any way. No recording will be taken without your consent and the camera will be switched off on request. These videos are used only for educational purposes with the doctor doing the consultation and are destroyed after use.
Medical Students
Medical students are sometimes attached to the practice for 2 – 3 weeks as part of their training. If you do not wish a student to be present during your consultation, please inform the receptionist.
Violence Policy
The Practice staff shall always show due respect and courtesy when dealing with patients and their representatives. We respectfully request that patients and their representatives do the same when dealing with members of the practice team.
The NHS operate a zero tolerance policy with regard to violence and abuse and the practice has the right to remove violent patients from the list with immediate effect in order to safeguard practice staff, patients and other persons.
No form of aggression (whether verbal or physical in nature) will be tolerated – any instances of such behaviour on the practice premises may result in the perpetrator being reported to the Police and removed from the practice’s List of Registered Patients.
Violence in this context includes actual or threatened physical violence or verbal abuse which leads to fear for a person’s safety. In this situation we will notify the patient in writing of their removal from the list and record in the patient’s medical records the fact of the removal and the circumstances leading to it.