Privacy Notice – Patients

What information do we collect?

We collect your information from you and other healthcare providers who may be caring for you, for example your GP or district nurse. We keep records about your treatment and care both on paper and electronically. Details of the information we process include, but are not limited to:

  • Your name and contact details e.g. address, phone number and e-mail address
  • Your medical records including assessments, diagnosis, treatment, services attended, status and care planning
  • Your holistic care needs including spiritual, social and psychological
  • Information about your next of kin, close family, friends and carers

Why do we process your information?

Your information is used for direct care purposes:

  • To assess suitability of our services for you
  • To provide you and the people that care for you with our care and support services
  • To ensure that we have a record and that other healthcare providers who are part of your direct care team are kept informed about the services and treatment that has been provided

We may also use your information for purposes that are not related to your direct care:

  • To investigate queries, complaints or legal claims
  • To manage our services
  • For research and planning purposes. Your personal information will not be used for this purpose if you have signed up to the National Data Opt Out. For more information, relating to the National Data Opt Out, click the following link: https://digital.nhs.uk/services/national-data-opt-out

Please note: St Ann’s will not use your sensitive/personal identifiable information unless it is absolutely essential. This means that when we are processing your information for non-direct care purposes, we will endeavour to either anonymise it which means that all personal identifiable information is removed with no possibility of tracing the information back to you in the future; or pseudonomise it which means that all personal identifiable data is replaced, and highly restricted access is applied to the pseudonimisation code.

We may also share your information with other organisations when we are required to do so by law, for example:

  • If we are sent a request from the Police under the Crime and Disorder Act 1998
  • If we receive a formal order from a court acting in their judiciary capacity
  • If there is a public health need such as preventing the spread of infectious diseases
  • If there is a safeguarding need (vulnerable adults or children)

How do we process your information lawfully?

In the Data Protection Act 2018 and the General Data Protection Regulations, processing of your personal information must be done fairly, lawfully and transparently. St Ann’s will only process information relating to you as long as there is a lawful basis in line with the legislation and it is necessary for us to do so. The following legal bases are commonly relied upon for the delivery of direct care:

  • Public Interest – to process personal information to deliver our care and support services to you, and to your close family, friends and carers. This is underpinned by the Health and Social Care Act 2012.
  • Provision of Health and Social Care Services – to process your sensitive personal information (e.g. medical information, race, religion) to deliver our care services to you. This performed under our contracts with NHS Clinical Commissioning Groups.
  • Legal Obligation – to manage your personal records in line with the Records Management for Health and Social Care 2016.

Which other organisations do we work with?

In order for St Ann’s to operate, we need to engage with other organisations for the provision of some services. The organisations that we work with must only act with our written approval, and must not sub-contract their services without our written consent. Examples of contracted services includes:

  • Data Management – all patient health records and related reporting/correspondence are managed through an electronic database called EMIS Web, which is used widely across the healthcare sector. This is the same system used by most GP practices in Greater Manchester.
  • Record Retention – Paper copies of medical records are archived securely both at the Hospice and off site. The off-site storage is managed by Oasis.
  • Incident Reporting – all incidents are recorded in an electronic database called Sentinel, which is hosted by Vantage.
  • Continuous Improvement – we work with other healthcare providers e.g. the NHS to help with identifying areas for improvement and future investment.
  • Video Consultations – we use software provided by AccuRX to hold video consultations with our patients.