7 Common GDPR Mistakes That Doctors Make

GDPR might not be the sexiest of topics, but it’s really important to get it right as private practice doctors, or it can land you in some serious hot water.

Here are seven of the top GDPR mistakes we see clinicians making – and some of these you may unwittingly be making yourself.

  1. Not being registered with the ICO H2 – the information commissioner’s office.

If you’re responsible for collecting personal data, you need to be registered with the ICO – and that means you as a private practice clinician. It costs about £40 to do so, and it’s a really simple process to sign up online.

  1. Dumping the GDPR stuff on your secretary.

Here’s the thing – you’re the clinician and you’re the data controller – not your secretary, so if the poop hits the fan, it’s your responsibility, not his or hers. Getting stuck into what’s needed to be GDPR legit will give you a proper understanding of what it all means, and that way, you will know how to stay compliant.

  1. Thinking that a privacy notice and a bit of email encryption ticks all the boxes.

There’s a lot more to the GDPR than a privacy notice on your website and using encrypted email such as Egress. We see time and time again doctors trying to re-vamp generic templates to use as a privacy notice. In order to construct a privacy notice, you have to have carried out what’s called a data flow audit. It’s a bit like a very granular log that details how you handle data, where it’s stored, how it’s moved about etc. If you mess up with a patient’s data, the ICO is likely to want to see your documentation about how you use and store data, and your data flow audit will help you here.

  1. Using consent as your ‘lawful basis’ for processing patient’s data.

It’s really important that you separate out the idea of consent in the clinical setting from ‘consent’ in the GDPR sense. As a doctor or surgeon, you may need to gain a patient’s consent for a procedure, but in the GDPR setting, using consent as a lawful basis for processing data is actually a bad idea.

If you draw up a fancy form, asking patients to consent to allowing your process their data, a patient can later declare that they want to withdraw that consent. That leaves you in a very difficult position, because you’re obliged to keep medical records, and you may need to refer to them in a medicolegal situation.

Instead, you should use ‘legal obligation’ as your reasons for processing sensitive data, because the 2008 health and social care act that obliges you to keep up to date, accurate clinical records.

  1. Not having data processor to controller agreements in place.

What the heck are those you might be thinking? As Doctors, we’re considered to be data controllers, and anytime we use the services of other people to handle patient data, we need to think of those people as being data controllers.

So, who might data controllers be? Well it could be a medical transcription or billings company, but it also includes email providers, and companies you use to store data with. Whenever you’re using a processor to process your patients’ data, you need to ensure that they are GDPR compliant and a written contract needs to be in place between you and that data processor.

  1. Not encrypting your hardware.

This seems so basic, but it’s so often forgotten. If you are using a Windows laptop or a Macbook or a dictation device, they need to be encrypted, in case it’s lost or stolen.

Don’t forget this includes external drives that you might be using for backups. On more than one occasion I’ve found a forgotten, unencrypted USB device containing patient MRI pics sticking out of hospital PC. Don’t let this happen to you.

  1. Using free or personal software for handling patient data.

What do I mean here? Using software such as personal Gmail and personal Dropbox means you fall foul of being GDPR compliant, because they are not able to provide you with a data processor to controller agreement, plus, they tend to get hacked.

You need to have GDPR compliant service providers (such as Office 365 and Onedrive for business), and we strongly recommend using encryptions software to dove tail with email, such as Egress. Another really good reason for not using a personal gmail address is that it comes across as unprofessional – and as clinicians it’s really important that we develop a professional brand.

If you need help getting your GDPR act together, get in touch at drcath@clinic-alchemy.com

Get your Private Practice Goal Planner and our video and blog series. Each week we’ll show you how to accelerate your Private Practice, Grow Your Brand and Personal Wealth – and it’s FREE.