Policies
GDPR Data Protection Policy
Purpose:
Me 2 You Phlebotomy is committed to protecting all personal information in accordance with UK GDPR and the Data Protection Act 2018.
We will:
- Only collect information needed to provide our service.
- Keep information secure.
- Never sell patient information.
- Only share information when necessary for patient care or when legally required.
- Keep records only for as long as necessary.
- Ensure electronic devices are password protected.
- Dispose of confidential paperwork securely.
Record Retention Policy
Me 2 You Phlebotomy will:
- Keep patient records only for as long as necessary or professionally required.
- Store paper records securely.
- Password protect electronic records.
- Permanently delete electronic records when no longer required.
- Shred confidential paper documents before disposal.
Confidentiality Policy
All patient information is confidential.
Information will only be discussed with:
- The patient
- Healthcare professionals directly involved in the patient's care.
- The requesting laboratory or GP where appropriate.
- Anyone else where required by law.
No information will be shared with family members or other third parties without the patient's consent unless there is a legal obligation to do so.
Data Breach Procedure
If personal information is lost, stolen or accidentally disclosed:
- Secure the information immediately.
- Assess the risk.
- Record the incident.
- Notify affected individuals where appropriate.
- Report to the ICO if required by law.
- Review procedures to prevent recurrence.
Patients Rights
Patients have the right to:
- Access their personal information.
- Correct inaccurate information.
- Request deletion where appropriate.
- Restrict processing in certain circumstances.
- Complain to the Information Commissioner's Office (ICO).