<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://www.vetsurgeon.org/utility/feedstylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>GDPR communications</title><link>https://www.vetsurgeon.org/f/non-clinical-questions/26999/gdpr-communications</link><description> Hi, I&amp;#39;m wrestling with the ability to communicate client / patient data securely. Anyone have any magic solutions for this? Examples might be emails to referral practices, histories to and from other local practices and direct emails to clients. 
 Thanks</description><dc:language>en-US</dc:language><generator>Telligent Community 10</generator><item><title>RE: GDPR communications</title><link>https://www.vetsurgeon.org/thread/197336?ContentTypeID=1</link><pubDate>Thu, 17 May 2018 15:04:36 GMT</pubDate><guid isPermaLink="false">146601cc-3922-4be7-9974-7e1d4e45a66b:ed6a25cc-7eb4-41b4-9c54-331a3b34eea1</guid><dc:creator>Rob Loxley</dc:creator><description>&lt;p&gt;[quote user=&amp;quot;Martin Atkinson&amp;quot;][quote user=&amp;quot;robloxley&amp;quot;]If it contained confidential details (e.g. bank account details) you could consider, say, sending it as a password-protected PDF and separately communicate the password to the intended recipient.[/quote]I cannot think of any occasion that I would want to send such sensitive information.[/quote]&lt;/p&gt;
&lt;p&gt;Pay-monthly &amp;#39;pet health club&amp;#39; where using an external company to set up and administer the direct debit?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: GDPR communications</title><link>https://www.vetsurgeon.org/thread/197305?ContentTypeID=1</link><pubDate>Thu, 17 May 2018 09:37:51 GMT</pubDate><guid isPermaLink="false">146601cc-3922-4be7-9974-7e1d4e45a66b:1a86c985-c464-4d48-913b-36720d6626fb</guid><dc:creator>Martin Atkinson</dc:creator><description>&lt;p&gt;[quote user=&amp;quot;robloxley&amp;quot;]I think the question was more about security of data once we send it out,[/quote]It is a good point. Given we are supposed to have a contract with companies who process our data which states how they will deal with it securely should we have a similar arrangement with any practice that may request case histories etc? - that clearly is impractical. I seem to recall in my GDPR CPD that so long as you determine that the request is genuine,and thus in the client&amp;#39;s legitimate interest, then it is OK to send the information.&lt;/p&gt;
&lt;p&gt;[quote user=&amp;quot;robloxley&amp;quot;]Given we&amp;#39;re happy to post such data as you suggest, I&amp;#39;m happy to just email it.[/quote]There is a another level of responsibility with email rather than post, not just GDPR but the PECR regulations related to security of electronic communications.&lt;/p&gt;
&lt;p&gt;[quote user=&amp;quot;robloxley&amp;quot;]If it contained confidential details (e.g. bank account details) you could consider, say, sending it as a password-protected PDF and separately communicate the password to the intended recipient.[/quote]I cannot think of any occasion that I would want to send such sensitive information. If you have any doubt then simply contact the client and ask them if they want you to respond to the request.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: GDPR communications</title><link>https://www.vetsurgeon.org/thread/197277?ContentTypeID=1</link><pubDate>Wed, 16 May 2018 19:38:42 GMT</pubDate><guid isPermaLink="false">146601cc-3922-4be7-9974-7e1d4e45a66b:57999fc0-1014-44a8-8ca2-38b273188cfd</guid><dc:creator>Rob Loxley</dc:creator><description>&lt;p&gt;[quote user=&amp;quot;Martin Atkinson&amp;quot;]This is really all taken care of as mentioned in other threads by legitimate interest[/quote]&lt;/p&gt;
&lt;p&gt;I think the question was more about security of data once we send it out, not whether or not we are able to send the data? Given we&amp;#39;re happy to post such data as you suggest, I&amp;#39;m happy to just email it. If it contained confidential details (e.g. bank account details) you could consider, say, sending it as a password-protected PDF and separately communicate the password to the intended recipient.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: GDPR communications</title><link>https://www.vetsurgeon.org/thread/197261?ContentTypeID=1</link><pubDate>Wed, 16 May 2018 15:31:53 GMT</pubDate><guid isPermaLink="false">146601cc-3922-4be7-9974-7e1d4e45a66b:14a0fda8-9397-44b7-bdd9-887346c21511</guid><dc:creator>Martin Atkinson</dc:creator><description>&lt;p&gt;This is really all taken care of as mentioned in other threads by legitimate interest. The client has given de facto permission by requesting a referral/gone to another practice. If you&amp;#39;re worried and your PMS won&amp;#39;t allow you to do it, convert the clinical history to a Word file of similar and pseudonimify it by removing client details and then attach to your email.&lt;/p&gt;
&lt;p&gt;As for direct emails to clients if you are just communicating with them rather than sending marketing material then again I don&amp;#39;t see an issue, they have effectively given you permission with a &amp;#39;previous intention to purchase&amp;#39; and again legitimate interest, just give the option to opt out of further emails. Or send the communication by post.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: GDPR communications</title><link>https://www.vetsurgeon.org/thread/197250?ContentTypeID=1</link><pubDate>Wed, 16 May 2018 13:36:46 GMT</pubDate><guid isPermaLink="false">146601cc-3922-4be7-9974-7e1d4e45a66b:b6eb88c0-7f39-4b4a-a040-5abc197c6c03</guid><dc:creator>Bob Russell</dc:creator><description>&lt;p&gt;Why are you worrying?&lt;/p&gt;
&lt;p&gt;As long as you are using a fairly reputable email service then the security should be fair. Probably better not to keep messages on their servers any longer than necessary. Ours are deleted automatically after 30 days.&lt;/p&gt;
&lt;p&gt;Histories are imported to the patient records then deleted from the email server.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>