Security of information
Confidentiality affects everyone: East Cheshire NHS Trust collects, stores and uses large amounts of personal data every day, such as medical records, personal records and computerised information. This data is used by many people in the course of their work.
We take our duty to protect your personal information and confidentiality very seriously and we are committed to taking all reasonable measures to ensure the confidentiality and security of personal data for which we are responsible, whether computerised or on paper.
At Trust Board level, we have appointed a Senior Information Risk Owner who is accountable for the management of all information assets and any associated risks and incidents. We also have a Caldicott Guardian who is responsible for the management of patient information and patient confidentiality.
Why do we collect information about you?
The doctors, nurses and team of healthcare professionals caring for you keep records about your health and any treatment and care you receive from the NHS. These records help to ensure that you receive the best possible care. They may be written down in paper records or held on computer. These records may include:
- Basic details about you such as name, address, date of birth, next of kin, etc.
- Contact we have had with you such as appointments or clinic visits.
- Notes and reports about your health, treatment and care.
- Results of x-rays, scans and laboratory tests.
- Relevant information from people who care for you and know you well such as health professionals and relatives.
It is essential that your details are accurate and up to date. Always check that your personal details are correct when you visit us and please inform us of any changes as soon as possible.
What is the legal basis on which we hold / process your information?
The legal basis on which we process personal data is:
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
The legal basis on which we process special categories of information (which include race; ethnic origin; politics; religion; trade union membership; genetics; biometrics (where used for ID purposes); health; sex life; or sexual orientation)is:
Necessary for the purpose of preventative or occupational medicines, for the assessment of working capacity, for medical diagnosis, provision of health or social care or treatment, or management of health or social care systems and services
How your personal information is used
Your records are used to direct, manage and deliver the care you receive to ensure that:
The doctors, nurses and other healthcare professionals involved in your care have accurate and up to date information to assess your health and decide on the most appropriate care for you.
Healthcare professionals have the information they need to be able to assess and improve the quality and type of care you receive.
Concerns, complaints and legal claims can be properly investigated.
Appropriate information is available if you see another doctor, or are referred to a specialist or another part of the NHS or other organisation such as social care.
How your personal information is used to improve the NHS
Your information will also be used to help us manage the NHS and protect the health of the public by:
- Using statistical information to look after the health and wellbeing of the general public and planning services to meet patient needs in the future.
- Assessing your condition against a set of risk criteria to ensure that you re receiving the best possible care.
- Ensuring the hospital receives payment for the care you receive.
- Preparing statistics on NHS performance for Department of Health and other bodies.
- Auditing NHS accounts and services.
- Clinical Audit and Service Development
- Research teams offering information to you on potential research studies / developments. Research seeks to investigate new treatments, interventions and management procedures so that patient care is continually improved.
- Helping to train and educate healthcare professionals.
- Contacting you to take part in surveys or consultations about our services.
You have a choice about whether you want your confidential information to be used in this way. To find out more about the wider use of confidential information and to register your choice to opt out if you do not want your data to be used in this way, please visit http://www.nhs.uk/your-nhs-data-matters (after 25th May 2018). If you choose to opt out you can still consent for your data being used for specific purposes.
The NHS Care Record Guarantee
The Care Record Guarantee is our commitment that we will use records about you in ways that respect your rights and promote your health and wellbeing. Copies of the full document can be obtained from: NHS Digital
Who do we share personal information with?
Everyone working within the NHS has a legal duty to keep information about you confidential. Similarly, anyone who receives information from us has a legal duty to keep it confidential.
We will share information with the following main partner organisations:
- Other NHS Trusts and hospitals that are involved in your care.
- Clinical Commissioning Groups, NHS Improvement and other NHS bodies.
- General Practitioners (GPs).
- Ambulance Services.
You may be receiving care from other people as well as the NHS, for example Social Care Services. We may need to share some information about you with them so we can all work together for your benefit if they have a genuine need for it or we have your permission. Therefore, we may also share your information, subject to strict agreement about how it will be used, with:
- Social Care Services.
- Education Services.
- Local Authorities.
- Voluntary and private sector providers working with the NHS.
We will not disclose your information to any other third parties without your permission unless there are exceptional circumstances, such as if the health and safety of others is at risk or if the law requires us to pass on information.
East Cheshire NHS Trust manages its records in line with the requirements of the Records Management Code of Practice for Health and Social Care 2016. This document is based on current legal requirements and professional best practice and was published on 20 July 2016 by the Information Governance Alliance (IGA).
The code of practice can be found by following the link: https://digital.nhs.uk/article/1202/Records-Management-Code-of-Practice-for-Health-and-Social-Care-2016
The Cheshire Care Record
The Cheshire Care Record is a shared system that allows Healthcare Professionals within the Cheshire Health and Social Care community to appropriately access the most up-to-date and accurate information about patients to deliver the best possible care.
If you would like to contact us for any further information or would like to discuss this further please contact the Data Protection Officer us using the contact details provided below.
Rights of the Data Subject
You have the right to know what information is being processed, for what purpose and on what legal basis. This Privacy Notice sets out that information.
The right to data portability allows individuals to obtain and reuse their personal data for their own purposes across different services. It allows them to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without hindrance to usability. This right only applies where processing takes place by an automated means.
Disclosure of information
You have the right to restrict or object to how and with whom we share the personal information in your records that identifies you. This must be noted explicitly within your records in order that all healthcare professionals and staff treating and involved with you are aware of your decision. By choosing this option, it may make the provision of treatment or care more difficult or unavailable. You can also change your mind at any time about a disclosure decision.
SMS text messaging
When attending the Trust for an outpatient appointment or a procedure you may be asked to confirm that the Trust has an accurate contact number and mobile telephone number for you. This can be used to provide appointment details via SMS text messages and automated calls to advise you of appointment times.
How you can access your records
You have a right to access the information we hold about you on our records. Requests must be made in writing to the Legal Services Department. Please refer to our Subject Access request policy for further information, which can be found on the following policies page: http://www.eastcheshire.nhs.uk/about-the-trust/policies/s/
The Trust has robust breach detection, investigation and internal reporting procedures in place.
The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority, within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in a high risk of adversely affecting your rights and freedoms, we will contact you without undue delay.
The Data controller responsible for keeping your information confidential is:
East Cheshire NHS Trust
2nd Floor, New Alderley
Macclesfield District General Hospital
Telephone: 01625 421000
The Data Protection Officer for East Cheshire NHS Trust is:
Data Protection Officer
East Cheshire NHS Trust
Top Floor, New Alderley
Macclesfield District General Hospital
Organisations processing personal data are required to lodge a notification with the Information Commissioner to describe the purposes for which they process personal information. These details are publicly available from:
Information Commissioner’s Office
Telephone: 08456 306060