How we collect and use your information
Your health records
- Overview
- Current page section : How we collect and use your information
- Accessing your information
- How we use children and young people's information
- Staff privacy notice
We keep records about your health, care and treatment. This information may come directly from you or from other health and care organisations involved in your care
Information we collect
We may collect information about:
- your personal details, such as your name, address, date of birth, NHS number and contact details
- your appointments, referrals, admissions and discharge from hospital
- your health, care and treatment, including clinical notes, diagnoses and treatment plans
- test results, scans, X-rays and clinical photographs
- medicines, allergies and adverse reactions
- information shared by other health and care organisations involved in your care
- carers, relatives or others involved in supporting your care
We only collect information that is relevant and necessary for your care and for carrying out our NHS responsibilities.
Most information is stored electronically, although some records may be kept in paper form where required. Our main electronic patient record system is called Epic.
It is important that the information we hold about you is accurate and up to date. Please tell us if any of your personal details change.
How we use your information
We use your information to help us:
- provide safe, effective care and treatment
- support your care across different services and organisations
- make sure health professionals have the information they need to support your care
- contact you about appointments, test results and treatments
- improve the quality and safety of our services
- plan and manage NHS services
- educate and train health professionals
- carry out approved research and innovation
- meet our legal and regulatory responsibilities
If we use your information for purposes other than your direct care, we will only do so where the law allows it and with appropriate safeguards in place.
We may invite you to share your feedback through surveys, such as the Friends and Family Test or national patient surveys. We may share limited contact details with approved survey providers so they can contact you. Taking part is voluntary and will not affect your care.
If you would like to opt out of these surveys, please contact the patient experience team by emailing [email protected].
For national vaccination programmes, we may share limited information within the NHS to check whether you are eligible, invite you for vaccination, record your vaccination and update your health record. This helps support public health and is required by law.
Visit the NHS England and NHS Improvement website for more information about how personal data is used in the national COVID-19 and flu vaccination programmes.
If you are referred for genomic testing, we may share relevant information with NHS Genomic Laboratory Hubs and other organisations involved in providing genomic services. This information helps support your diagnosis and treatment.
Where organisations work together to provide these services, they may share responsibility for how your information is used and protected.
We only use and share the information needed for a specific purpose.
Sharing your information
We may share your information with health and care professionals involved in your care to help provide safe, joined-up care.
This may include:
- your GP practice
- other NHS organisations, such as hospitals
- community health services
- social care services
- other organisations providing services as part of your care
We only share information when it is necessary and lawful to do so.
Epic is our electronic patient record system. Relevant information may be shared with partner NHS organisations that use Epic to support your care.
This helps health professionals involved in your care access up-to-date information and provide safe, coordinated treatment. Access is limited to authorised staff and is monitored and audited.
Read more about how your information is used and protected in Epic.
The London Care Record allows authorised health and care professionals involved in your care to securely access relevant information, such as medicines and allergies.
This helps staff provide safe, joined-up care when you use different health and care services across London. Access is limited to authorised staff and is monitored and audited.
You can object to your information being shared through the London Care Record, although this may affect the care you receive in some situations.
Read more about the London Care Record and how to object to sharing, or speak to your care team.
The Trust uses a Secure Data Environment (SDE) in some specialist services where information from different NHS organisations needs to be brought together to support your care.
This can help healthcare professionals build a more complete picture of your health, particularly for people with complex or long-term conditions. Where appropriate, information from hospital records and GP records may be used.
The SDE is a highly secure NHS system. Access is limited to authorised professionals, and all activity is monitored and audited to help keep your information safe.
MyChart is a secure website and app that lets you access parts of your health record and manage aspects of your care online. It is part of our Epic electronic patient record system
You can use MyChart to:
- view test results and hospital letters
- manage appointments
- update your personal details
- complete questionnaires before appointments
- join video consultations
- allow someone you trust to help manage your care through proxy access
If you use NHS login to access MyChart or manage your appointments, NHS England will check your identity to help keep your information secure.
NHS England is responsible for the information you provide to create and manage your NHS login account. This does not affect any information you provide directly to us.
Sharing your information for other purposes
We may also share information when necessary with organisations such as:
- NHS England and other NHS organisations
- organisations that regulate, inspect or audit NHS services, such as the Care Quality Commission (CQC), the Department of Health and Social Care, and auditors
- public health organisations
- organisations involved in planning, funding and improving NHS services
- the police, local authorities or safeguarding organisations where we have a legal duty to share information
We only share information when it is necessary, lawful and appropriate. We follow the Caldicott Principles, which help NHS organisations use and protect confidential health and care information safely and appropriately.
Sometimes we work with other organisations to provide shared services or use shared systems. In these situations, we may act as a joint data controller, meaning we share responsibility for how your information is used.
We have clear agreements in place with our partner organisations to define responsibilities and protect your information.
If we are acting as a joint data controller with another organisation, you can exercise your data protection rights with either organisation. We will work together to make sure your request is handled lawfully and without unnecessary delay.
Where possible, we use information that has been anonymised or pseudonymised.
- Anonymised information means identifying details have been removed so that individuals cannot be identified.
- Pseudonymised information means identifying details have been replaced or removed, but the information can still be linked back to an individual using a separate key.
This information may be used for planning services, reporting, research and improving care. We use anonymised information whenever possible. If this is not possible, we only use the minimum information needed and apply appropriate safeguards.
The Trust's Caldicott Guardian is responsible for ensuring confidential patient information is used appropriately, lawfully, safely and in line with NHS confidentiality standards.
The Caldicott Guardian provides oversight to make sure we follow the Caldicott Principles when using and sharing confidential information.
Research and improving services
We support health and care research to help improve treatments, services and patient outcomes.
Where possible, information used for research, planning and service improvement is anonymised so that individuals cannot be identified. If identifiable information is needed, this will only be used where there is a lawful basis and appropriate safeguards are in place.
Research findings never identify individual patients.
You can choose whether your confidential patient information is used for research and planning purposes beyond your individual care.
Your choice will not affect the care or treatment you receive.
The National data opt-out does not apply where information is used for your direct care, where sharing is required by law, or where information has been anonymised and individuals cannot be identified.
Find out more about the National data opt-out and how to set or change your preference, or call 0300 303 5678.
Communicating with you
We use your contact details to communicate with you about your care, appointments and treatment.
we aim to communicate with you in a clear, timely and convenient way.
Where appropriate, we may contact you by:
- text message
- secure patient portals, such as MyChart
Please let us know if your contact details change. You can also tell us if you have preferences about how we contact you. In some circumstances, we may need to use an alternative method to make sure important information reaches you.
To help keep your information secure, emails containing sensitive information may be encrypted.
We may offer video appointments as an alternative to face-to-face appointments. These appointments use secure NHS systems and are treated in the same way as in-person consultations.
If you are unable or prefer not to use video technology, please speak to your care team. A face-to-face or telephone appointment may be available.
Other uses of personal information
We use personal information about staff, volunteers and job applicants for purposes such as recruitment, employment, training, payroll and meeting our legal obligations.
We use CCTV, body-worn cameras and other security systems in some areas to help keep people safe, protect property and prevent crime.
Signs are displayed where these systems are in use. Recordings are only kept for as long as necessary and may be retained longer where needed for investigations or legal purposes.
Where appropriate, we may use personal information to manage donations, enquiries, newsletters and other communications. We will only do this where there is a lawful reason to do so and, where required, with your consent.