Privacy Notice - Heidi Health

 

Use of Heidi Health in NHS GP Consultations

This privacy notice explains how our GP practice uses patient data when incorporating Heidi Health, an AI-powered medical scribe, into consultations. Heidi Health assists clinicians by transcribing medical consultations to improve documentation and reduce administrative workload while maintaining patient care quality and confidentiality.

Purpose of Processing The use of Heidi Health aims to

  • Enhance accuracy and efficiency in medical record-keeping.
  • Reduce administrative workload for clinicians.
  • Improve patient-clinician interaction by allowing clinicians to focus on care rather than note-taking.

How Data is Collected and Processed

  • During a consultation, Heidi Health transcribes real-time discussions between patients and clinicians.
  • The transcribed information is reviewed and validated by the clinician before being added to the patient’s medical record.
  • Data is processed within a secure environment, ensuring compliance with NHS Digital and UK GDPR requirements.

Data Sharing and Security Measures

  • Heidi Health does not share patient data with third parties without explicit consent, except where legally required (e.g., safeguarding, legal obligations).
  • Data is encrypted and stored securely in the UK, in compliance with NHS data governance policies.
  • Access to patient data is restricted to authorised healthcare professionals within the practice.

Patient Rights Under data protection laws, patients have the following rights

  • Right to Access: You can request a copy of your consultation records by contacting the practice.
  • Right to Rectification: If you believe your records contain inaccuracies, you can request corrections.
  • Right to Object: You can object to the use of Heidi Health in your consultation by informing your clinician.
  • Right to Restrict Processing: In certain circumstances, you may request limitations on how your data is processed.

Legal Basis

Legal Basis for Processing The legal bases for processing personal data under UK GDPR and the Data Protection Act 2018 include:

  • Article 6(1)(e) – Performance of a task carried out in the public interest or in the exercise of official authority.
  • Article 9(2)(h) – Processing necessary for the provision of health or social care.

Recipient Or Categories of Recipients of The Shared Data

Categories of Data Processed The following types of personal data may be processed when using Heidi Health:

  • Patient identifiers (name, date of birth, NHS number)
  • Consultation transcripts (including symptoms, diagnoses, and treatment plans)
  • Voice recordings (if applicable)

Retention Period Retention Period

  • Transcribed consultation records are stored as part of the patient’s electronic medical record and retained in accordance with NHS retention guidelines.
  • Any temporary data processed by Heidi Health is securely deleted once incorporated into the medical record. This is set to delete within 24hours by The Orchard Practice. No data is held by Heidi Health.

Opt-Out Option

If you prefer not to have your consultation transcribed by Heidi Health, you can opt out at any time by informing your clinician before or during your appointment.

Data Controller Contact Details

The Orchard Practice, Orchard Gardens, Chessington, Surrey KT9 1AG

Data Protection Officer

Should you have any data protection questions or concerns, please contact our Data Protection Officer, Ellie Roberts, via the surgery at: The Orchard Practice, Orchard Gardens, Chessington, Surrey KT9 1AG