The HLH Imaging Group Privacy Policy
Our contact details:
Name: The HLH Imaging Group Limited
Address: 18 Tiverton Road, Ruislip, Middlesex HA4 0BW E-mail:
ICO Registration number: ZA772077
The type of personal information we collect
We may collect and process the following information:
• Personal identifiers, contacts and characteristics
• Your name, address and contact details
• Financial information, such as credit card details used to pay us
• Occupation
• Emergency contact details, including next of kin
• Background referral details
Special categories of personal data
We may collect and use more sensitive personal data (known as "special category data") about you, such as information relating to your physical and mental health. Special category data must be handled even more sensitively than “standard” personal data. For example, if you are a patient we will need to use personal data about your health in order to provide your care and diagnosis. Your special category personal data will be managed in accordance with the law and this Privacy Notice and also all applicable professional standards including guidance from the General Medical Council and British Medical Association.
The special category personal data we hold about may include the following:
• details of your current or former physical or mental health. This may include personal data about any healthcare services you have received (from other healthcare providers such as GPs or hospitals (private and/or NHS)) or need, including about clinic and hospital visits. This may also include details of previous healthcare services you have received from other healthcare providers in circumstances where medical negligence is alleged, or being investigated, against that third party provider.
The confidentiality of your medical information is important to The HLH Imaging Group. We make every effort to prevent unauthorised access to and use of information relating to your current or former physical and mental health. In doing so, The HLH Imaging Group complies with UK data protection law, including the Data Protection Act 2018, and all applicable medical confidentiality guidelines issued by professional bodies including, but not limited to, the Health & Care Professions Council (HCPC) (https://www.hcpc-uk.org/standards/standards-of-proficiency/radiographers/) and General Medical Council (GMC) (https://www.gmc-uk.org/).
If you change personal data which we already hold about you (for instance by changing a pre-populated form) then we will update our systems to reflect the changes, but our systems will also continue to hold the originally recorded personal data.
How we get the personal information and why we have it
We may collect personal data directly from you when you:
• enter into a contract with us for the provision of your care
• have remote consultations and imaging opinions with a healthcare professional including virtual or by telephone
• complete enquiry forms on our website
• send us a question including through our website, by email or by social media
• correspond with us by letter, email, telephone or social media, including where you reference The HLH Imaging Group in a public social media post
Our patients will often receive healthcare services from other organisations in addition to The HLH Imaging Group, and so in order to provide you with the best care possible we may have to collect personal data about you from other organisations. This may include medical record details from:
• your GP
• your healthcare professional (including their medical secretaries)
• the NHS or any private healthcare organisation
• mental health providers
We may also collect personal data about you from other third parties as follows:
• solicitors or other third parties acting on your behalf in connection with medico-legal proceedings
• your current or former employer, healthcare professional or other healthcare services or on your behalf in connection with healthcare provided by us.
• your insurance policy provider
• experts (including medical experts) and other service providers about your care
• NHS health service bodies about your care
If you (or the relevant other healthcare providers and other third parties outlined above) do not provide us with the personal data that we ask for, then we may be unable to provide your care or provide you with our services.
Medical records include personal data about your diagnosis, clinic and hospital visits and may include any imaging previously obtained during an episode of care or diagnosis.
How we use your personal data
We use (or “process”) your personal data for a number of different purposes but in all cases, we must have a legal basis for doing so. When we use “special category of personal data” such as personal data relating to a person’s health, (see section on Special categories of personal data above) we must have a specific additional legal basis to do so.
Generally we will rely on the following legal bases:
Contract:
• we need to use your personal data to take steps so that you can enter into a contract with us and/or a healthcare professional to provide your care
• your current or former employer, healthcare professional or other healthcare services or on your behalf in connection with healthcare provided by us.
• we need to use your personal data to provide your care in accordance with a contract between you and The HLH Imaging Group and/or a healthcare professional. We will rely on this for activities such as supporting your care and other benefits, supporting other healthcare professionals and providing other services to you; and/or
• we need to use your personal data to assist your investigation of potential medical negligence against another healthcare provider.
• The medico-legal assessment may be performed by one of our healthcare professionals.
Legitimate interests: we need to use your personal data for our legitimate business interest to process your personal data and such interest does not cause harm to you. We will rely on this for activities such as quality assurance, maintaining our business records, developing and improving our products and services and helping with medical research.
Legal obligation: we need to use your personal data to comply with our legal or regulatory obligations.
Legal claims: we need to use your special category personal data to establish, exercise or defend our legal claims.
Consent: you have given us your consent to use your personal data for this purpose.
How we protect your personal information
We are committed to looking after your personal data and have implemented appropriate physical, technical, and organisational security measures designed to protect against accidental loss and unauthorised access, use, alteration, or disclosure.
In doing so, we comply with UK data protection law, including the Data Protection Act 2018, the EU General Data Protection Regulation and all applicable medical confidentiality guidelines issued by professional bodies including, but not limited to, the Health & Care Professions Council (HCPC) and the General Medical Council GMC.
In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know it. They will only use your personal data on our instructions and they are subject to a duty of confidentiality.
Who we share your information with?
In order to provide you with our services we use the most up to date technology and in order to do this we need to share your information with them. The HLH Imaging Group have a contract and data processing agreement with Cimar UK Ltd who provide this technology. In order to comply with UK data protection legislation Cimar UK Ltd have their own policies and privacy notice which can be viewed at https://www.cimar.co.uk/privacy-policy/
Your data protection rights
Under data protection law, you have rights including:
Your right of access - You have the right to ask us for copies of your personal information.
Your right to rectification - You have the right to ask us to rectify personal information you think is inaccurate. You also have the right to ask us to complete information you think is incomplete.
Your right to erasure - You have the right to ask us to erase your personal information in certain circumstances.
Your right to restriction of processing - You have the right to ask us to restrict the processing of your personal information in certain circumstances.
Your right to object to processing - You have the right to object to the processing of your personal information in certain circumstances.
Your right to data portability - You have the right to ask that we transfer the personal information you gave us to another organisation, or to you, in certain circumstances.
You are not required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please contact us at info@HeartLungHealth.com if you wish to make a request.
Alternatively you can write to:
The Data Protection Officer STABE Ltd
Blacksmiths Lodge Shepherds Close Odstock
Shepherds Close Odstock
Salisbury Wiltshire
SP5 4JF
How to complain
If you have any concerns about our use of your personal information, you can make a complaint to us at:
The Data Protection Officer STABE Ltd
Blacksmiths Lodge Shepherds Close Odstock
Shepherds Close Odstock
Salisbury Wiltshire
SP5 4JF
You can also complain to the ICO if you are unhappy with how we have used your data.
The ICO’s address:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow Cheshire
SK9 5AF
Helpline number: 0303 123 1113 ICO
ICO website: https://www.ico.org.uk