Practice Policies
Complaints Policy
- Within 6 months of the incident that caused the problem; or
- Within 6 months of discovering that you have a problem, provided this is within 12 months of the incident.
- Find out what happened and what went wrong.
- Make it possible for you to discuss what happened with those concerned, if you would like this.
- Make sure you receive an apology, where this is appropriate.
- Identify what we can do to make sure the problem does not happen again.
Proxy Access
Proxy Access refers to giving a third party access to online services on behalf of a patient. Family members or carers can access a patient’s medical records online only in circumstances where the patient has consented to this, or if the patient lacks capacity AND the applicant can provide evidence that they have been granted the power to manage the patient’s affairs.
Patients will be advised about the risks associated with doing this as part of their access application. Proxy access is the recommended alternative to sharing login details.
A person with parental responsibility who wishes to access some or all of the records of a competent child aged between 11 and 16 should only be allowed to do so if the child or young person consents, and it does not go against the child’s best interests. If the records contain information given by the child or young person in confidence you should not normally disclose the information without their consent.
A person with parental responsibility for a child aged under 12 normally has automatic rights to access a child’s records – although not all parents have parental responsibility. Proxy access for people with parental responsibility to a child’s record is a practice-level decision.
Data Sharing
From 30th September 2021, your data will be shared with NHS Digital. NHS Digital will collect, analyse, publish and share this patient data to improve health and care services for everyone.
The NHS needs data about the patients it treats in order to plan and deliver its services and to ensure that care and treatment provided is safe and effective. For example patient data can help the NHS to:
- monitor the long-term safety and effectiveness of care
- plan how to deliver better health and care services
- prevent the spread of infectious diseases
- identify new treatments and medicines through health research
GP practices already share patient data for these purposes, but this new data collection will be more efficient and effective. Read more here.
Privacy Notices
GP Net Earnings
Records and Confidentiality
Most patient information is held on computer. All personal and clinical information is confidential and the consent of individual patients is needed before it can be given to anyone else. Sometimes, we may need to share information with other professionals involved in your care, but they also have a legal duty to keep it confidential. You are entitled to see your health records. If you want to do this, please ask at reception for details.
CQC
We are continually working to provide a Safe, Effective, Caring, Responsive and Well-Led Service in line with CQC guidance. This is a responsibility all staff take seriously. There is more information on our registration and inspections with the CQC at this link. Our named staff members for each of the CQC key questions are outlined below:
- Safe – Dr Surgeoner and Dr Keeble
- Effective – Dr Fraser and Dr Wallace
- Caring – Paula Culverhouse and Lisa Hornby
- Responsive – Christine Bunton and Danielle Sweeney
- Well-Led – Christine Bunton, Danielle Sweeney, Paula Culverhouse, Reception Supervisor, Data Management Supervisor, the Partners
Zero Tolerance
This practice has a zero tolerance approach and any patient who is violent, aggressive or abusive to GPs, nurses, practice staff or other patients may be taken off the practice’s list.
Information Governance
Use of Recording in Consultations at Our Practice
At our practice, we are using a new software to help with note-taking during consultations. This tool listens to the conversation between you and your doctor (with your permission) and provides a summary of the consultation for your doctor to review. This summary is designed to help us focus more on your care and less on typing notes during your visit.
Here’s how it works:
- What We Record: We only record the conversation during your consultation. This helps us create an accurate summary of the visit.
- What Happens Next: After the consultation, the tool generates a summary using advanced technology (called Large Language Models or LLMs). Your doctor will carefully check the summary before adding it to your medical record.
- Your Privacy: All recordings and summaries are stored securely in the UK.
- Your Choice: Before each consultation, we will always ask if you’re happy for the conversation to be recorded for this purpose. If you prefer not to be recorded, we will take notes manually instead.
What is Heidi and How Does It Work?
Heidi is an ambient voice technology (AVT) powered by artificial intelligence (AI). It uses speech recognition technology to accurately transcribe your consultation with your doctor, creating a written summary of your visit.
This software is designed to assist with administrative tasks and is not used in any way to aid in diagnosing medical issues.
FAQs
How Do We Obtain Information and Why Do We Need It?
Information is gathered during a consultation recording, either through a web browser or on a mobile device, between you, the patient, and your doctor.
The personal information we collect is provided directly by you for the following reasons:
- To improve our clinical workflow and efficiency
- To focus on more patient-centred care
- To obtain and structure your personal medical history
- To streamline administrative tasks
What Information Do We Collect?
| Category | Details |
| Personal Information | Information that can identify you, such as age, date of birth, and gender. |
| Sensitive Health Information | Health details related to your current medical issue, past medical history, previous investigations, current and previous medications, and any current or past specialist input. This information is volunteered by you during the consultation and may also be noted by the clinician if relevant. |
| Information Collected for Business Improvement (‘Pseudonymised Data’) | Your data is ‘de-identified’, meaning all personal identifiers are removed, making it highly unlikely you can be ‘re-identified’. This is done to improve software performance. |
| Information Collected by Cookies | The software, accessible via a web browser, may collect ‘de-identified’ data to enhance performance. |
Who Do We Share the Information With?
Heidi has strict agreements with third-party organisations and does not allow them access to or use of your personal information beyond the necessary purposes listed above. Third parties are bound by zero-retention policies, meaning no data is retained after processing, ensuring your information cannot be reused or accessed for any other purpose.
How Is My Information Stored?
Your information is securely stored within the UK and is not saved on international platforms. Heidi prioritises data processing and storage security and has robust agreements with third-party processors, including standard contractual clauses to ensure data is stored safely. Heidi has also pseudonymised the data by replacing personal identifiers with unique references or codes.
Heidi employs multiple security measures, including mandated industry-level encryption standards, regular audits, and real-time security monitoring to maintain the highest security standards.
What Are My Data Protection Rights?
Below is a list of your data protection rights:
- Your right of access – You have the right to request copies of your personal information (known as a subject access request).
- Your right to rectification – You have the right to ask us to correct any information you believe is inaccurate or to complete information you feel is incomplete.
- Your right to erasure – You have the right to request the deletion of your personal information in certain circumstances.
- Your right to restrict processing – You can ask us to restrict the processing of your personal information in certain situations.
- Your right to object to processing – You have the right to object to the processing of your personal data in certain circumstances.
- Your right to data portability – You can request that we transfer the personal information you provided to another organisation, or directly to you, in certain circumstances.
