DGS Health is a federation of GP practices across Dartford, Gravesham and Swanley. We were established in 2014, mainly in response to increased commissioning (purchasing) of healthcare services. We recognised that by working together at scale we could compete to offer locally led, high quality services for our patients.

We pride ourselves on being a clinically led and managerially enabled organisation. This helps us to ensure that our services are designed by clinicians to provide the very best possible clinical care, and supported by our management team to make it happen. At DGS Health, clinicians and non-clinicians work closely together to design and develop services. Everyone brings expertise, and by working together we can develop unique, high quality and safe services for our patients.

Our Board meets monthly and is comprised of local GPs, supported by a Chief Executive, Chief Nurse, Chief Pharmacist, and HR and Operations Directors. Our governance structure is underpinned by a range of meetings covering the key functional areas of HR, finance, audit, clinical quality, performance and operations. We hold an Annual General Meeting of our Shareholders each winter.

Information Governance

 

What is it?

Information Governance is a framework for managing information policy and processes that ensure security and confidentiality.

 

Why is it important?

Information Governance is the way in which the NHS handles all of its information, in particular personal and special category information relating to patients and employees. It provides a framework to ensure that personal information is dealt with legally, securely, efficiently and effectively in order to deliver the best possible care.

 

GDPR and the Data Protection Act

The GDPR and the Data Protection Act 2018 (both referred to here as the Data Protection legislation) give individuals (data subjects) certain rights regarding information held about them (personal data). The Data Protection legislation also place obligations on those who process personal data (data controllers).

The definition of ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person

Anyone processing personal data must also comply with the data protection principles set out in the data protection legislation

 

Personal data

Personal data shall be:

  • processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
  • collected for specified, explicit and legitimate purposes
  • adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’);
  • accurate and, where necessary, kept up to date;
  • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; (‘storage limitation’);
  • processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).

The Data Protection legislation sets out the right of a data subject to access personal data held about them. However, this right of access is subject to a number of exemptions that are set out in the Data Protection Act 2018.

The ICO’s website contains further information on the Data Protection legislation and the right of access.

The personal data recorded on this form will be used only to enable us to deal with your request and for no other purpose DGS Health can be found on this website.

 

Making a request

The form on the Contact Us page of this website may be used if you wish to make a subject access request under the Data Protection legislation to DGS Health for personal information that you believe we may hold about you.

A data controller is not obliged to comply with a request unless it is supplied with such information as it may reasonably require in order to satisfy itself as to the identity of the person making the request and to locate the information which that person seeks. Accordingly, while you may have already made a request to us by other means, we may still require you to supply us with additional information (as set out in this form).

 

Fee

There is no fee for processing a subject access request under the Data Protection legislation.

 

Identification

Unless DGS Health indicated otherwise, you should also provide identity documentation. More guidance on what type of documentation to provide can be found in the request form and in our Subject Access Request Policy.

 

Submitting the request

Please send the completed form and copy identity documentation using the form found on the Contact Us page of this website.

 

How will we process your request?

We will verify and shred your proof of identity documentation. We will aim to acknowledge receipt of your request within two working days. We may ask you to clarify the request where its terms are not clear to us or where we need additional information in order to search for the requested information.

Upon our receipt of a valid request, we will arrange for searches to be carried out for the requested personal information.

We may subsequently ask you whether you require copies of particular communications which we suppose may already be in your possession (e.g. correspondence previously sent to you by us or by other parties).

Where the personal information requested by you is contained in records of communications with third parties (e.g. an employer or contracting body, a regulator, or a public authority), we will normally seek the views of each such third party on the issue of disclosure. We do this to inform our decision-making as to whether the disclosure of certain information (e.g. the personal information of staff members of the third party) would be lawful.

We will send the response to you securely by email, or if you wish to received it by post, we will send it to your residential address or to the business address of your representative by recorded delivery.

 

Timeframe

There is a one calendar month timeframe for responding to subject access requests. We will endeavor to respond to your request within one calendar month of receipt of a valid request.

DGS Health Privacy Policy

Below explains how we use any information you give to us, and the ways in which we protect your privacy.

 

How we use your information

DGS Health is committed to ensuring that your privacy is protected. However, where you are receiving a service from DGS Health we are required to share that information with other organisations as part of your treatment and care. This is to ensure that your health records are accurate and up to date.

We may also use your information to inform, improve and maintain the services that we are delivering. This information may be included in reports that used by employed members of DGS Health to show how we are improving and maintaining services, however any identifiable information which can identify you will be removed and anonymised to preserve your privacy and confidentiality.

We will not sell, distribute or lease your information to any third parties, unless we have your permission to do so.

For more information on how we use your information please contact Umar Sabat, Data Protection Officer via e-mail on umar.sabat@ig-health.co.uk

 

 

 

DGS Health are one of the partner organisations to the Kent and Medway Care Record (KMCR). The KMCR is an electronic care record which links your health and social care information held in different provider systems, to one platform. This allows health and social care professionals who have signed up to the KMCR to access the most up to date information to ensure you receive the best possible care and support by those supporting you. In order to enable this sharing of information, organisations who use the KMCR have agreements in place that allow the sharing of personal and special category data. 

 

For further information about the Kent and Medway Care Record and the ways in which your data is used for this system please click here.

 

Data Protection

DGS Health is committed to ensuring that any information it collects and retains is kept safe and secure and in line with the Data Protection Act 2018 and General Data Protection Regulations (GDPR).

DGS Health has completed a number of requirements associated with changes in Data Protection law this includes

  • Appoint a Data Protection Officer
  • Continually reviewing and updating our policies and procedures
  • Reviewing our Information Asset Register – This is a register that lists all our databases which hold corporate and patient information
  • Ensuring that there are Data Protection Impact Assessments in place where it has been determined that the information being processed is high risk due to the amount of sensitivity of the information. A Data Protection Impact Assessment policy is now in place.
  • Ensuring that any privacy notices are in included or on documentation where this will require personal information to be used.

In addition to this, DGS Health will also ensure adherence to the 7 Caldicott Principles.

Principle 1 – Justify the purpose for using confidential information
Principle 2 – Don’t use personal confidential data unless it is absolutely necessary
Principle 3 – Use the minimum necessary personal confidential data
Principle 4 – Access to personal confidential data should be on a strict need to know basis
Principle 5 –  Everyone with access to personal confidential data should be aware of their responsibilities
Principle 6 – Comply with the law
Principle 7 – The duty to share information can be important as the duty to protect patient confidentiality

 

Security

We ensure your information is always secure. In order to prevent unauthorised access or disclosure we have put in place safeguards that protect physical, electronic and managerial procedures to secure information we collect. Please see our policies that show our commitment ensuring information is safe.

  1. Information Governance Policy
  2. Data Protection Impact Assessment Policy
  3. Confidentiality Policy
  4. Acceptable Use Policy

 

Employees and contractors 

DGS Health needs to process data about you because we enter in a contract with you. In Some cases, DGS Health also processes your data to comply with a legal obligation.

Therefore, we may process your data in several different ways

  1. Maintain accurate up to date employment record and contact details
  2. Operate and keep a record of disciplinary
  3. Keep a record of application form
  4. Obtain occupational health and support for you, sharing your information with consent
  5. Ensure effective HR and business administration
  6. Provide references on request for current and former employees.

In addition to this DGS Health works with appointed contractors that deliver clinical services on our behalf and your information will be shared with them for the purpose of delivering clinical care.

 

Further information

Questions, comments and requests regarding this privacy policy are welcome and should be addressed to: Data Protection Officer, DGS Health, The Old Rectory, Springhead Road, Northfleet, Gravesend, Kent DA11 8HN.

Freedom of Information

 

What is freedom of information?

The Freedom of Information (FOI) Act gives the public the right to request any recorded information from a public authority. The authority will then have 20 working days to provide this information subject to any exemptions.

How do we process freedom of information requests?

We pride ourselves on being an open organisation and will endeavour to respond to requests for information where we are required to under the guidance attributable to primary care. While we will provide as much information as it can, due to the sensitivity of some of this information, the organisation has a duty of confidence to both patients and staff. In line with FOI Act, this means that no information will be released which could lead to the identification of an individual.

DGS Health is a private organisation. However, the majority of our contracts are with NHS organisations, usually the Integrated Care Board (ICB) or Acute/Community Trusts. These contracts are held with public bodies and will fall under the remit of the FOI Act. It is best practice for you to contact the ICB or the Acute/Community Trust with whom we hold the contract to acquire any information related to contractual obligations for the purposes of FOI.

Some activities that DGS Health undertake are exempt from FOI legislation.

Where can you make your request?

​Any requests in the first instance should be made to the ICB or the Trust with whom we have the contract. If you require further information, please contact our Data Protection Officer: umar.sabat@ig-health.co.uk

How do I request information about me?

​Please refer to our privacy policy above.

 

Data Protection Officer

The Data Protection Officer is Umar Sabat. He is independent and oversees our data protection compliance and can be contacted at umar.sabat@ig-health.co.uk

© All rights reserved by DGS Health LTD.
Maintained by FoxSocialMedia

Contact

DGS Health GP Federation, The Old Rectory,
Springhead Road, Northfleet,
Kent, DA11 8HN

Fleet Health Campus
Building A, Vale Road
Northfleet, Kent, DA11 8BZ

T: 01474 55 55 30
(please do not call regarding a medical emergency)

E: dgs.health@nhs.net

If you need information about our services in different languages, please contact us on 01474 55 55 30

Jeśli potrzebujesz informacji o naszych usługach w różnych językach, skontaktuj się z nami pod numerem 01474 55 55 30.

Ak potrebujete informácie o našich službách v rôznych jazykoch, kontaktujte nás na telefónnom čísle 01474 55 55 30.

Jei jums reikia informacijos apie mūsų paslaugas įvairiomis kalbomis, susisiekite su mumis telefonu 01474 55 55 30

यदि आपको विभिन्न भाषाओं में हमारी सेवाओं के बारे में जानकारी चाहिए, तो कृपया हमसे 01474 55 55 30 पर संपर्क करें।

ਜੇ ਤੁਹਾਨੂੰ ਵੱਖ ਵੱਖ ਭਾਸ਼ਾਵਾਂ ਵਿਚ ਸਾਡੀਆਂ ਸੇਵਾਵਾਂ ਬਾਰੇ ਜਾਣਕਾਰੀ ਦੀ ਲੋੜ ਹੈ, ਤਾਂ ਕਿਰਪਾ ਕਰਕੇ ਸਾਡੇ ਨਾਲ 01474 55 55 30 ‘ਤੇ ਸੰਪਰਕ ਕਰੋ.

Privacy Preference Center