Our privacy policy under the Data Protection Act 1998 has been reviewed and updated to underline the new rights for individuals within the new laws of the General Data Protection Regulation (GDRP) from the 25 th of May 2018. This major change has occurred to help protect and unify the way that an individual’s data is managed throughout the European Union (EU). We at LWF Physiotherapy collect information relating to patients’ health and personal details. This information is classed as sensitive data and termed as special category data. Under the new GDPR, patients have a right to know why their information is collected, for what purpose it is used and how it is kept safe.
Under the GDPR LWF Physiotherapy has a legitimate interest in the patients’ information and is part of the contract between a health professional and their patient. For a detailed and accurate assessment and treatment to take place, we need to collect and keep information about patients and their health on our records.
Your personal details are used for the following reasons
We will only ask for and keep information that is necessary. We will attempt to keep it as accurate and up to date as possible. We will explain the need for any information we ask for if you are unsure why it is needed. We ask you to inform us about any relevant changes that we should know about including personal contact information.
All staff at LWF Physiotherapy are bound by patient confidentiality laws, the standards of conduct, performance and ethics of CORU (Regulating Health & social care professionals) and the Irish Society of Chartered Physiotherapists (ISCP) code of conduct. Your information will not be shared outside LWF Physiotherapy unless you have given consent, except when;
Access to your records is regulated to ensure that they are used only to the extent necessary to enable the employee in question, whether secretary, manager, or healthcare professional perform their tasks for the proper functioning of the practice. In this regard, patients should understand that practice staff may have access to their records for:
We commit to retaining your information securely. There are robust security measures on the computer to prevent and minimise the risk of information theft. All our software is password protected and is updated every 30 days
If recording were made, we are committed to ensuring that any audio, visual or photographic recordings of you, in which you are identifiable, should only be made with express consent. The recordings will be kept confidential as a part of your record. We will do all we reasonably can to protect confidentiality of the recording. We will get consent before sharing such videos, photos or other images
We will only take images of you on your practitioner personal mobile device when necessary for the care been received and with your permission.
Such images will not identify a patient and shall only be kept for the minimum time necessary.
Under the GDPR all individuals have the right to have incorrect information that is held about them amended. If this was to arise within the notes held by LWF Physiotherapy the notes would become restricted, i.e not used until the issue was resolved
You have the right of access to all the personal information held about you by this practice. You can make a formal written access request to the practice secretary and the matter can be dealt with formally. All requests will be answered in the time frame of one month unless you are notified of a difference to this time scale. There will be no fee for information provided.
We hope this policy has explained any issues that might arise. In the unlikely event that this safety was compromised you will be notified immediately as will the Data Protection Commissioner.