Playbook, medical practice

Data questions at a practice arrive from patients and from organisations

Two very different people type this at a surgery. One is a patient who has read something about data sharing and wants to know who sees their record. The other is an organisation asking the practice to evidence its own information governance. The first is answered from the privacy notice. The second is not answered by software at all.

Why this is not the general answer

The handling pattern for security questionnaires holds across every trade. What follows is the part that does not.

  • The questioner here is usually a patient rather than a procurement team, and what they want is not a certificate, it is to know who sees their record and how to opt out of a particular sharing arrangement.
  • A practice sits on both sides of this: it answers assurance questions about itself, and it also has to run its own due diligence on anything it puts in front of patients, including any tool added to its own website.
  • A practice publishes a named data protection officer and an information governance contact, so unlike an organisation with a generic trust page there is a person to route this to, and naming them is part of the answer.
  • An assurance answer given to another organisation becomes a commitment the practice is held to at inspection, which is a much higher bar than a marketing page and no place for a generated sentence.

How it arrives

  • who can see my medical record
  • how do i opt out of my data being shared
  • does the surgery share records with researchers
  • who is your data protection officer
  • can you complete our information governance questionnaire
  • is this chat recording what i type

What has to be indexed for this to work

Material behind this answer
The privacy notice exactly as publishedNot a summary of it. Everything said here is the practice speaking about how it handles records, so the assistant should only ever repeat wording that has already been approved and published.
Each sharing arrangement you take part in, with its own opt outNamed individually with the route out of each. Patients ask about one arrangement and are usually given a general reassurance covering all of them, which answers nothing they can act on.
The data protection officer and information governance contactThe role and how to reach them, so a question that outgrows a published page has somewhere specific to go rather than landing in the general enquiry inbox.
What the chat itself collects, in one paragraphWhat a visitor types, what is stored, and what reaches the practice. Asked more often on a health site than anywhere else, and a practice should be able to answer it about its own website.

The reply

A reply worth copying
Our privacy notice sets out who has access to records here and the sharing arrangements we take part in, each with its own opt out route [1]. If you want a particular arrangement stopped, the route is on that page rather than through me, and I cannot change anything on a record [2]. The practice has a data protection officer and the contact details are on the same page. If you are an organisation asking us to complete an assurance questionnaire, please send it to the practice manager, and leave me your name and an email if you would like them to reply.

It answers the patient version from the published notice and from nothing else, because any improvisation here is the practice making a statement about how it handles records. The opt out is named as a route rather than as something it can do. And the organisational version is dealt with separately and briefly, which is the correct amount of attention for a questionnaire in a chat box.

Where it stops

The trigger. The visitor asks something the privacy notice does not answer, asks the practice to complete a questionnaire or sign an agreement, or asks about the handling of a named person's record.

The handover, worded
I can only repeat what our privacy notice says. Anything beyond it goes to our data protection officer or the practice manager. Leave me your name, an email and your question and it will be passed on.

It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.

Never say this here

Out of bounds

  • Never state where data is held, how it is protected, or which organisations handle it, beyond what your privacy notice already says.
  • Never say the practice holds a certification, an accreditation or an audit result.
  • Never confirm whether a named person's record has been shared, accessed or opted out.
  • Never agree to a term, a timescale or a data sharing arrangement on the practice's behalf.

Questions

Should a surgery answer these in a chat window at all?
The patient half, yes, because the privacy notice already exists and reading it aloud is exactly what this is good at. The assurance half, no. That is a document the practice manager returns under signature.
Patients ask whether the chat itself is recorded. What should it say?
Whatever your own privacy notice says about it, and nothing more. Deciding that, writing it down and indexing it is part of putting any tool on a practice website, and it is the first question a health audience asks.
Can it fill in a questionnaire we have been sent?
No. It cannot complete, sign or return a document, and an assurance answer is a commitment the practice will be held to. Routing the questionnaire to the practice manager is the only safe handling.

Keep reading

Try it on your own material

Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.