Who we are and what we do:
We are contracted by the NHS to provide local care services. Our services are currently formed of unscheduled primary care, urgent care services, NHS 111 services, pharmacy, GP led health centres and walk in centres, ED support, roving GP service, community nursing, health and justice services and integrated technology solutions.
You can find an up to date list of all of our services here: http://www.ic24.org.uk/services/our-current-services/
And more information on who we are here: http://www.ic24.org.uk/why-ic24/
This means that we are a business partner of the NHS and complete an annual toolkit (a very large and thorough assessment) to ensure we meet the high standards on all things handling data, which we do.
Coronavirus (COVID-19) response transparency notice
We are undertaking a range of work to support the NHS Digital and government response to the coronavirus outbreak. This notice is to inform you of our legal bases for processing personal data in the course of this work.
The Secretary of State for Health and Social Care has issued a Notice under Regulation 3(4) of the National Health Service (Control of Patient Information Regulations) 2002 (COPI) to require us to share confidential patient information with organisations entitled to process this under COPI for COVID-19 purposes.
The notice states;
The health and social care system is taking action to manage and mitigate the spread and impact of the current outbreak of COVID-19. Action to be taken will require the sharing of confidential patient information amongst health organisations and other appropriate bodies for the purposes of protecting public health, providing healthcare services to the public and monitoring and managing the outbreak.
This means that IC24 will be in receipt of more data such as the vulnerable and shielding individual list and their details and sharing data with relevant authorities such as those patients that have COVID-19 symptoms to enable them to receive treatment and be included in national statistics. This notice has currently been issued until 30th September but may be reviewed if necessary, however, the information collected and shared for this specific purpose will not be held by IC24 post the COVID-19 response.
GDPR and DPA 2018
Our legal bases for processing personal data under the General Data Protection Regulation (GDPR) and Data Protection Act 2018 (DPA 2018) are:
- GDPR Article 6 (1) (c) – processing is necessary to comply with a legal obligation
- GDPR Article 6 (1) (e) – processing is necessary for the performance of a task carried out in the public interest
- GDPR Article 9 (2) (g) – processing is necessary for reasons of substantial public interest
- DPA 2018 – Schedule 1, Part 2, (6) (1) – statutory etc and government purposes
- GDPR Article 9 (2) (h) – processing is necessary for the management of health or social care systems and services
- DPA 2018 – Schedule 1, Part 1, (2) (2) (f) – Health or social care purposes
- GDPR Article 9 (2) (i) – processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health
- DPA 2018 – Schedule 1, Part 1, (3) – public health
Please note that it is the NHS 111 online service are providing the self-isolate notes.
NHS Digital has more in depth information on how all health care services are sharing and using data at this time to ensure a combined and thorough response to the coronavirus. See their website for more information: https://digital.nhs.uk/coronavirus/coronavirus-covid-19-response-information-governance-hub
Data we collect and have shared with us:
The data that we collect and that is shared with us is needed to enable us to provide you with direct care.
This includes data not only from the call you are placing at the time with our services, but also data you have previously provided, data that we retrieve from the NHS Spine and Summary Care Record and data that is shared with us from your other health providers to ensure you receive a fast and effective integrated service.
We do not hold your full health and care (medical) records as your GP would, but do hold the following:
- your name, date of birth, address and contact details
- your NHS number, which makes sure your records are linked to you and you alone
- details of health conditions and illnesses
- medicines and other treatments
- records of contact you've previously had with us
- voice recordings
- Palliative care information
How and why we use your data:
Data Protection law allows us to use your data for specific purposes where we have a legal basis to do so. We have set out the reasons and lawful basis below:
Our main reasons:
Providing healthcare in the public interest on behalf of the NHS
As a healthcare provider we are performing a task carried out in the public interest on behalf of the NHS. We are subject to statutory duty to collect (process) and to share information about our patients for their direct care.
As most of the information by its very nature of being health related is sensitive personal (special category) data we only use this for medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems.
This includes local administrative tasks which support this purpose such as:
- waiting list management
- performance against national targets
- activity monitoring
- local clinical audit
- production of datasets to submit for commissioning purposes and national collections
It also covers instances where we participate in activities with a statutory basis such as responding to a public health emergency. For example we encounter infectious diseases which may endanger the safety of others, such as meningitis or measles (but not HIV/AIDS).
Safeguarding children and vulnerable adults under a task carried out in the public interest.
Personal and health data is collected and shared with appropriate local authorities, other NHS bodies and if necessary the police. This is done to ensure that patients receive the right services at the right time.
We will always be open and honest with patients and their family (where appropriate) from the outset about why, what, how and with whom information will, or could be shared, and seek their agreement, unless it is unsafe or inappropriate to do so.
Sharing data where it is necessary for IC24 to comply with a legal obligation by assisting Commissioners.
The NHS 111 service is staffed 24 hours a day, 7 days a week by a team of fully trained advisers. They will ask questions to assess your symptoms and, depending on the situation, will then:
- give you self-care advice
- connect you to a nurse, emergency dentist or GP
- book you a face-to-face appointment
- send an ambulance directly, if necessary
- direct you to the local service that can help you best with your concern
Phone numbers given will be used for IC24's automated comfort calling process; it ensures all patients are contacted if there are delays within the services. It will be in the form of a text or call with a message being read.
Calls to 111 and our offices are recorded and most calls made from us to you across our services are recorded.
Sometimes, calls may not be record if;
- there's a technical fault with the telephony system
- a member of staff is using equipment which does not let calls be recorded
We record on screen pathways assessments during calls for the primary purpose of improving clinical safety and improving patient experience. But also for the reporting and management of software issues.
All calls and the records created are maintained securely, and will only be shared with others directly involved with your care and IC24’s Clinical Governance Team in the unlikely event that you are unhappy with your experience and they are investigating a complaint on your behalf.
You are able to advise that you do not want for them to do this, but this may restrict the investigation and therefore affect the outcome.
For more information on complaints see: https://www.ic24.org.uk/get-in-touch/listening-to-you/
Data is also shared where appropriate and necessary with NHS Digital to improve NHS 111, for further information on how NHS Digital use your data see the following website:
NHS 111 online
If you use the NHS 111 online service they will pass your answers and personal details to us as the healthcare service you have selected if you (or the person you are contacting them about), choose to be referred.
By agreeing to NHS 111 online referring you to another healthcare provider you are also agreeing that your data can be forwarded to us so that we can provide care.
For more information on this please see their website: https://111.nhs.uk/Help/Privacy
Your completed notes will be passed onto your GP to ensure continuity of care and ensure that there is a full record of your care held centrally.
You are able to object to this sharing of data as we have an obligation to consider the common law duty of confidentiality, however, if we feel that not sharing the data would cause you serious harm we will consider your vital interests. This will be fully explained to you at the end of each period of care.
We are continuously striving to improve our services and your feedback is paramount to this.
We do this by sending out patient experience questionnaires to randomly selected patients via mail and text message.
We only send a text where we have received consent to do so. You can also complete an online questionnaire within the base you visit or via our website.
Your response via text or online will be matched back to you and your incident of care and so will not be anonymous, should you wish to give anonymous feedback you can do so by writing in to our main office.
For more information please see https://patientexperience.ic24.org.uk/
Clinically-led statutory NHS bodies responsible for the planning and commissioning of health care services for their local area use this data to assess local needs, decide priorities and strategies and then buy services on behalf of the local population from providers such as hospitals, clinics etc to meet the need.
Only the minimum data necessary is shared for each purpose and this is reviewed regularly. Where it is possible to offer a choice over this sharing of data under the common law duty of confidentiality we will make this clear.
Sharing and using data for research purposes in the public and our legitimate interests
IC24 shares data with other NHS bodies and Clinical Commissioning Groups to assist health research for scientific research purposes, statistical purposes to develop and monitor NHS performance.
Where data is used for statistical purposes, stringent measures are taken to ensure individual patients cannot be identified.
Where it is not sufficient to use anonymised information, personal or sensitive (special category) data will be used, but only for essential NHS purposes.
In these circumstances, where it is not practical to obtain your explicit consent, we are informing you through this notice.
Where research is being conducted by IC24 it is in line with our legitimate interests as a business to enable us to be innovative and assist the NHS in creating new systems and services. You will be fully informed and asked for your consent under the common law duty of confidentiality, in these circumstances to proceed.
Duty of Confidentiality
Everyone working for the NHS is subject to the Common Law Duty of Confidentiality. Information provided in confidence will only be used for the purposes described below, unless there are other circumstances covered by the law. Under the NHS Confidentiality Code of Conduct, all our staff are also required to protect your information, inform you of how your information will be used, and allow you to decide if and how your information can be shared.
Organisations with whom we share your personal information
Unless you tell us not to, we will share information with the following main partner organisations:
- your GP practice
- NHS Digital
- NHS Pathways
- NHS England
- NHS trusts;
- your local hospital
- other NHS 111 providers;
- ambulance services
- local Clinical Commissioning Groups
As we cover a number of different geographical locations we work with a number of CCGs and they require us to share data with specific services within your local area, however you will be informed of the exact local service that your data is shared at the time of contact and can ask for data not to be shared in circumstances where we are not legally bound to share.
Your individual rights
The following will explain your rights over your data with IC24.
- the right to be informed;
You have a right to be informed about the collection and use of your data. This notice is one of the ways that we are informing you but if at any time you wish to have further details on the categories of data we’re processing or the purposes for a specific instance then you have a right to ask for this.
- the right of access;
You have the right to obtain confirmation that we are processing your personal data and a copy of that data.
This includes the right to ask for supplementary information about the third parties it is shared with, the parties we have collected it from, if any and how long it is stored for.
We will provide you with the information within one month of your request.
You should be aware that in certain circumstances your right to see some details in your health records may be limited in your own interest or where it adversely affects the rights and freedoms of other (e.g. another person’s confidentiality). We will however, tell you if we can’t meet your request for that reason.
If you want to access your health records you should make a written request to the Clinical Governance Team at IC24, Kingston House, The Long Barrow, Orbital Park, Ashford, Kent, TN24 0GP or via email to CG.email@example.com
National Data Opt Out
Information about you can also be used and provided to other organisations for purposes beyond your individual care, for research and planning to help provide better health and care for you, your family and future generations. This may only take place when there is a clear legal basis to use this information.
Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information isn’t needed.
You have a choice about whether you want your confidential patient information to be used in this way. If you are happy with this use of information you do not need to do anything. If you do choose to opt out, your confidential patient information will still be used to support your individual care.
To find out more or to register your choice to opt out, please visit www.nhs.uk/your-nhs-data-matters. On this web page you will:
- See what is meant by confidential patient information
- Find examples of when confidential patient information is used for individual care and examples of when it is used for purposes beyond individual care
- Find out more about the benefits of sharing data
- Understand more about who uses the data
- Find out how your data is protected
- Be able to access the system to view, set or change your opt-out setting
- Find the contact telephone number if you want to know any more or to set/change your opt-out by phone
- See the situations where the opt-out will not apply
You can also find out more about how patient information is used at:
https://www.hra.nhs.uk/information-about-patients/ (which covers health and care research); and
https://understandingpatientdata.org.uk/what-you-need-know (which covers how and why patient information is used, the safeguards and how decisions are made)
You can change your mind about your choice at any time.
Health and care organisations have until 2020 to put systems and processes in place so they can be compliant with the national data opt-out and apply your choice to any confidential patient information they use or share for purposes beyond your individual care. Our organisation is currently working towards compliance with the policy by March 2020.
The right to rectification
You have a right for to have inaccurate personal data rectified, or completed if it is incomplete. You can make a request verbally or in writing and we will respond to you within a month.
- the right to erasure;
This right is to have personal data erased; however, where we are processing data for public health purposes in the public interest this right does not apply. You can make a request and we will advise accordingly.
- the right to restrict processing;
You have the right to request the restriction or suppression of your personal data.
- the right to data portability;
You have a right to have your data transferred to another service, as we do not currently use online portals we do not have information we can transfer to another service.
- the right to object;
You have the right to object to the processing of your personal data in certain circumstances. We will adhere to this in circumstances where we do not believe we have a compelling reason for doing so.
You can make an objection verbally or in writing and we have one calendar month to respond to an objection.
You have the right to lodge a complaint regarding our use of your data
Please tell us first, so we have a chance to address your concerns. If we fail in this, you can address any complaint to the UK Information Commissioner’s Office, either by calling their helpline 0303 123 1113or directed on their website at www.ico.org.uk or via post:
Information Commissioner's Office
How secure is the data we collect?
We have physical, electronic, and Information Governance procedures in place to safeguard and secure the information we collect.
We have a whole host of managers that take responsibility and are accountable for ensuring that the data we collect and use is done so in a lawful and ethical manner. They ensure that all of the relevant and most up to date security measures are taken to protect the data and question each secondary use regularly.
The Information Governance Team, including the Data Protection Officer, a Caldicott Guardian and a Senior Information Risk Officer (SIRO).
All new, or changes to existing, information systems or information sharing processes, for healthcare purposes, will undergo a Data Protection Impact Assessment to ensure the security and confidentiality of personal confidential data. These are reviewed throughout the use of the data to ensure that the data remains the same as does the purpose of the use.
With all of the above in place we hope to reduce the possibility of any breaches of data however if you believe your privacy has been breached please contact us immediately on IGteam.firstname.lastname@example.org
For further information see our Security Statement.
IC24 do not transfer or store your data outside the EEA.
IC24 has adopted the retention periods set out in the Records Management Code of Practice for Health and Social Care 2016, Appendix 3.
The retention schedule will be reviewed annually or as necessary to reflect changes in law.
The retention schedule as set out in the Records Management Code of Practice for Health and Social Care 2016 can be found here: https://digital.nhs.uk/data-and-information/looking-after-information/data-security-and-information-governance/codes-of-practice-for-handling-information-in-health-and-care/records-management-code-of-practice-for-health-and-social-care-2016
Last updated: April 2020