Policies

 

GDPR Data Protection Policy

Purpose:

Me 2 You Phlebotomy is committed to protecting all personal information in accordance with UK GDPR and the Data Protection Act 2018.

We will:

  • Only collect information needed to provide our service.
  • Keep information secure.
  • Never sell patient information. 
  • Only share information when necessary for patient care or when legally required. 
  • Keep records only for as long as necessary. 
  • Ensure electronic devices are password protected. 
  • Dispose of confidential paperwork securely. 

Record Retention Policy

Me 2 You Phlebotomy will:

  • Keep patient records only for as long as necessary or professionally required. 
  • Store paper records securely. 
  • Password protect electronic records. 
  • Permanently delete electronic records when no longer required. 
  • Shred confidential paper documents before disposal. 

Confidentiality Policy 

All patient information is confidential. 

Information will only be discussed with:

  • The patient 
  • Healthcare professionals directly involved in the patient's care.
  • The requesting laboratory or GP where appropriate. 
  • Anyone else where required by law.

No information will be shared with family members or other third parties without the patient's consent unless there is a legal obligation to do so.

Data Breach Procedure

If personal information is lost, stolen or accidentally disclosed:

  1. Secure the information immediately. 
  2. Assess the risk.
  3. Record the incident. 
  4. Notify affected individuals where appropriate. 
  5. Report to the ICO if required by law. 
  6. Review procedures to prevent recurrence. 

Patients Rights

Patients have the right to:

  • Access their personal information. 
  • Correct inaccurate information. 
  • Request deletion where appropriate. 
  • Restrict processing in certain circumstances. 
  • Complain to the Information Commissioner's Office (ICO).