
Privacy
Your privacy is of utmost importance to us.
Please see below for information on how we collect and manage your data.
MINT HEALTH CLINIC PRIVACY NOTICE
GEN-108 v2.1
Effective Date: 1st Mar 2025
Introduction:
Mint Health Clinic is committed to protecting and respecting the privacy of our patients, staff, and stakeholders in compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This policy outlines how we collect, store, use, and protect personal data. It also explains our data retention periods, storage locations, and access controls to ensure your information is handled securely and responsibly.
Information We Collect:
Mint Health Clinic collects and processes the following categories of personal data:
-
Patient Information: Name, date of birth, contact details, medical history, treatment records, and payment details.
-
Employee Information: Name, contact details, payroll information, employment records.
-
Supplier/Partner Information: Business names, contact details, contracts, payment details.
How We Use Your Information:
Your information is used to:
Provide you with healthcare services.
Communicate with you about your care.
Process payments or insurance claims.
Conduct healthcare operations such as quality assessments and clinic management.
Legal Basis for Processing Personal Data
We process personal data based on the following lawful grounds:
-
Consent: Where patients provide explicit consent for the processing of their data for specific purposes (e.g., signing consent forms for treatment).
-
Contractual Obligation: To fulfil contracts with patients or staff (e.g., processing payments or managing employment records).
-
Legal Obligation: To comply with legal requirements, such as tax records or medical data reporting.
-
Legitimate Interest: Where it is necessary for the day-to-day operations of Mint Health Clinic (e.g., storing contact information to manage appointments).
How Long We Store Personal Data
Mint Health Clinic retains personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal and regulatory requirements. Retention periods for specific categories of data are as follows:
-
Patient Medical Records: Retained for 8 years following the last patient interaction, in line with NHS guidelines, or longer where required by law.
-
Employee Records: Retained for 6 years after employment ends, in compliance with UK employment law.
-
Financial Records: Retained for 6 years for tax and accounting purposes, as required by law.
-
Supplier and Partner Data: Retained for 6 years after the end of the business relationship.
Where Personal Data is Stored
-
Electronic Data: All personal data is stored securely on encrypted servers. Our servers are hosted in data centers that comply with GDPR standards within the UK and the European Economic Area (EEA).
-
Paper Records: Paper records will not be held, any paper copies of medical records will be shredded as soon as data is transferred to electronic servers.
-
Backup and Disaster Recovery: Regular backups are conducted, and backup data is stored securely and encrypted to prevent data loss.
Access to Personal Data
Access to personal data is restricted to individuals who need it to perform their job responsibilities. The following groups have controlled access to specific types of personal data:
-
Clinical Staff (Phlebotomists): Have access to patient medical records and treatment information as necessary for patient care.
-
Administrative Staff: Have access to patient contact details, appointment information, and payment records to manage appointments and billing.
-
Clinic Manager and HR Team: Have access to patient medical records, employee records, contracts, and payroll information for employment management purposes.
-
IT Department and External Providers: Have access to the systems storing personal data to ensure data security and technical support. These third-party providers are vetted and required to comply with GDPR standards through data processing agreements.
Access is governed by strict internal policies, and all staff receive regular training on data protection best practices. Unauthorized access to personal data is strictly prohibited and subject to disciplinary action.
Sharing Personal Data
We will not share personal data with third parties unless required to do so by law or with the individual's consent. Where necessary, we may share data with:
-
Healthcare Providers: To ensure continuity of care (e.g., referring patients to specialists).
-
Regulatory Authorities: To comply with legal obligations (e.g., health authorities).
-
External Service Providers: Such as payment processors or IT providers, under strict data processing agreements.
-
Legal Advisors: In the event of legal proceedings or compliance audits.
Data Security
We implement the following measures to protect personal data:
-
Encryption: All electronic personal data is encrypted both at rest and in transit.
-
Access Control: Access to data is limited to authorized personnel only, based on job roles and responsibilities.
-
Regular Audits: We conduct regular audits of our data protection processes to ensure compliance with GDPR and internal policies.
-
Staff Training: All employees undergo GDPR training to ensure they understand their obligations when handling personal data.
-
Physical Security: No paper records are retained by Mint Health. Paper records taken are shredded at the end of each day.
Data Breach Procedure
In the event of a data breach, Mint Health Clinic will:
-
Contain the Breach: Take immediate steps to contain and mitigate any risks posed by the breach.
-
Notify Affected Individuals: Inform affected individuals if there is a risk to their personal rights and freedoms.
-
Report to the ICO: Notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the breach if required.
-
Investigation: Conduct a full investigation to determine the cause of the breach and implement corrective actions.
-
Data Subject Rights
Under GDPR, individuals have the following rights regarding their personal data:
-
Right to Access: Request a copy of the personal data we hold about them.
-
Right to Rectification: Request corrections to any inaccurate or incomplete data.
-
Right to Erasure (Right to be Forgotten): Request deletion of their personal data, subject to legal and regulatory requirements.
-
Right to Restrict Processing: Request limits on how their data is processed in certain circumstances.
-
Right to Data Portability: Request a copy of their data in a structured, commonly used format.
-
Right to Object: Object to the processing of their personal data in certain cases.
To exercise these rights, individuals can contact Mint Health Clinic using the details provided below.
Contact Information
If you have any questions or concerns about this GDPR policy or the handling of your personal data, please contact:
Data Protection Officer
Mint Health Clinic
Ian Thomas
Ian.Thomas@Mint-Health.com
Policy Review
This policy will be reviewed annually or sooner if required by changes in legislation or clinic practices. Any changes will be communicated to staff and stakeholders.
Acknowledgment:
By using our services, you acknowledge that you have read and understand this privacy notice.
