Ear Eden Data Protection Policy


Ear Eden is committed to ensuring the security of personal data held by the business.

Confidentiality

  • Access to personal data is on a ‘need to know’ basis only. Access to information is monitored and breaches of security will be dealt with swiftly

  • Personal data is regularly reviewed, updated and deleted in a confidential manner when no longer required. For example, we keep patient records for at least 10 years

  • All data and documents are stored on an online practice management system. No physical documents are held or stored.

  • The online practice management system, Cliniko, complies with both EU GDPR and UK GDPR requirements and has a Data Processing Addendum (DPA) in place

Information Held on Computers

  • Hardware used to store patient data online (i.e laptop) is stored securely, and not left unattended in car parks or other public locations.

  • Passwords are only known to those who require access to the information, are changed on a regular basis and are not written down or kept near or on the computer for others to see

  • Ear Eden uses Cliniko, a secure healthcare practice management system, to store patient records, appointment information, consent records, and clinical notes. Cliniko employs industry-standard encryption, secure data storage, and routine backups to protect patient information. Data is processed in accordance with applicable UK GDPR and Data Protection Act 2018 requirements. Access to patient records is restricted to authorised personnel involved in the provision of care.

  • Precautions are taken to avoid loss of data through the introduction of computer viruses