GDPR INFORMATION CLAUSE FOR THE PATIENT
Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) of 27 April 2016, I provide information concerning the processing of personal data of patients and, where applicable, their legal representatives, caregivers, authorized persons and contact persons.
1. Data controller
The data controller is Claudia Baluta-Górecka, conducting business under the name Claudia Baluta-Górecka - indywidualna specjalistyczna praktyka lekarska - HOLISTICA , with its registered office at ul. Pustynnej 53 lok. R, 93-479 Łódź.
NIP: 7251793243
REGON: 101512578
E-mail: kontakt@holistica.pl
Phone: 730 888 010
The Controller has not appointed a Data Protection Officer. For all matters concerning personal data you may contact the Controller directly.
2. Whose data are processed
Processing may concern in particular:
patients receiving healthcare services, including teleconsultations;
minor patients;
legal representatives, parents and actual caregivers;
persons authorized by the patient to obtain information about health status or access medical records;
contact persons;
payers, if payment for the service is made by another person;
persons contacting the practice for organizational, complaint or patient rights matters.
3. Categories of processed data
The Controller may process the following categories of data:
identification data, in particular first name, last name, PESEL, date of birth, identity document number, and in the case of minors also data of the legal representative;
contact data, in particular residential address, correspondence address, telephone number, e-mail address;
health data, in particular information provided during medical history taking, data on health status, diagnoses, symptoms, treatment, prescribed medications, recommendations, e-prescriptions, e-referrals, e-sick notes (e-ZLA), certificates and course of the provided service;
data contained in medical records;
data concerning authorizations to receive information about health status and access medical records;
billing and accounting data, in particular data for a bill, invoice or payment confirmation;
data concerning communication with the patient, including the content of e-mail correspondence, SMS messages, information about appointment dates, cancellations, changes of dates and teleconsultation links;
technical data related to the use of the website or online forms, if such forms are used.
4. Purposes and legal bases for data processing
Personal data are processed for the following purposes:
4.1. Provision of healthcare services
Data are processed to provide healthcare services, including psychiatric consultations and teleconsultations, assessment of health status, conducting diagnostic and therapeutic processes, issuing e-prescriptions, e-referrals, e-sick notes (e-ZLA), certificates and recommendations.
Legal basis:
Article 9(2)(h) GDPR — processing of health data for medical diagnosis, provision of health care or treatment;
Article 6(1)(c) GDPR — compliance with legal obligations incumbent on the Controller as a medical practitioner.
4.2. Maintaining medical records
Data are processed to maintain, store, secure and archive medical records.
Legal basis:
Article 6(1)(c) GDPR;
Article 9(2)(h) GDPR;
the provisions of the Patients' Rights Act and the Ombudsman for Patients and implementing regulations concerning medical records.
4.3. Appointment registration and organization of teleconsultations
Data are processed to register appointments, set dates, send appointment confirmations, teleconsultation links, appointment reminders, contact for organizational matters and to verify the patient's identity before providing the service.
Legal basis:
Article 6(1)(b) GDPR — taking steps prior to entering into a contract or performance of a contract to provide healthcare services;
Article 6(1)(f) GDPR — legitimate interest of the Controller in efficient organization of services, patient service and ensuring the security of the teleconsultation process;
with regard to health data — Article 9(2)(h) GDPR.
4.4. Post-visit contact with the patient
Data may be processed to handle post-visit contact, including responses to organizational questions, providing information regarding continuation of treatment, medical documents, e-prescriptions, certificates or other matters related to the provided service.
Legal basis:
Article 6(1)(b), (c) or (f) GDPR, depending on the nature of the matter;
with regard to health data — Article 9(2)(h) GDPR.
4.5. Providing medical records and health information
Data are processed to exercise patients' rights, in particular the right of access to medical records, the right to authorize others to access the records and the right to authorize others to obtain information about health status.
Legal basis:
Article 6(1)(c) GDPR;
Article 9(2)(h) GDPR;
the provisions of the Patients' Rights Act and the Ombudsman for Patients.
4.6. Billing, payments and accounting obligations
Data are processed to receive payments, issue bills or invoices, keep accounting records and fulfill tax obligations.
Legal basis:
Article 6(1)(b) GDPR — performance of a contract;
Article 6(1)(c) GDPR — fulfillment of tax and accounting obligations.
4.7. Handling complaints, claims, requests and legal actions
Data may be processed to consider complaints, claims and requests from patients, contact public authorities, establish, pursue or defend claims.
Legal basis:
Article 6(1)(f) GDPR — legitimate interest of the Controller in protecting rights and defending against claims;
Article 6(1)(c) GDPR — if an obligation arises from law;
with regard to health data — Article 9(2)(f) or (h) GDPR.
4.8. Exercising rights under the GDPR
Data are processed to handle requests regarding personal data, including the right of access, rectification, restriction of processing, objection, data portability or withdrawal of consent.
Legal basis:
Article 6(1)(c) GDPR.
4.9. Data security and incident handling
Data may be processed to ensure system security, access control, backups, documenting personal data breaches and taking remedial actions.
Legal basis:
Article 6(1)(c) GDPR — performance of obligations under the GDPR;
Article 6(1)(f) GDPR — legitimate interest of the Controller in ensuring data security and continuity of practice operations.
4.10. Marketing of own services
Data may be processed for marketing purposes only where the patient has given a separate, voluntary consent.
Legal basis:
Article 6(1)(a) GDPR — consent;
with regard to electronic or telephone communications — also applicable rules on electronic communications.
Marketing consent is not a condition for using healthcare services and may be withdrawn at any time.
5. Recipients of data
Personal data may be disclosed to entities cooperating with the Controller only to the extent necessary to achieve the processing purposes.
Recipients may include in particular:
the provider of the electronic medical records system Medifile, including MedLife Club — if actually used by the practice;
the platform ZnanyLekarz / DocPlanner — for appointment registration, profile management, calendar, organizational communication, online booking or payments, if such functionalities are active;
providers of hosting, e-mail, telecom services, IT tools and technical support;
payment operators, banks or online payment providers, if used;
accounting office or advisors serving the practice;
law firms, insurers or advisors — if necessary to pursue claims, defend rights or handle disputes;
public authorities and other entities authorized under applicable law, in particular courts, prosecutors, the Patient Ombudsman, the President of UODO, tax authorities or other competent institutions.
6. Transfers outside the European Economic Area
As a rule the Controller does not intend to transfer patients' data outside the European Economic Area.
However, if the use of certain technological, hosting, analytics, communication, payment services or external providers' functions were to result in a transfer outside the EEA, this would take place only using mechanisms provided for in the GDPR, in particular an adequacy decision, Standard Contractual Clauses or other required safeguards.
The scope of any transfers depends on the current documentation of providers and active functionalities used by the Controller.
7. Retention period
Personal data will be retained for the period necessary to achieve the purpose for which they were collected, and then for the period required by law or necessary to protect the Controller's rights.
In particular:
medical records are generally retained for 20 years, counting from the end of the calendar year in which the last entry was made, taking into account exceptions provided for by law;
accounting and tax data are retained for the period required by tax and accounting law, generally 5 years from the end of the tax year;
data related to appointment registration and organizational contact are retained for the period necessary to handle the appointment, the patient relationship and protection against claims, and if they become part of medical records — for the period of retention of those records;
data concerning disclosure of medical records, authorizations and patient statements are retained for the period resulting from provisions on medical records and the obligation to demonstrate proper exercise of patient rights;
data processed on the basis of consent are retained until withdrawal of consent or cessation of the processing purpose;
data related to complaints, claims or legal actions are kept until the matter is concluded and the limitation period for claims has expired;
documentation concerning personal data breaches and the fulfillment of GDPR obligations is retained for the period necessary to demonstrate accountability.
8. Rights of the data subject
Data subjects have the rights set out in the GDPR, in particular:
the right of access to data;
the right to receive a copy of the data;
the right to rectification;
the right to restriction of processing;
the right to erasure — to the extent not contradicted by provisions requiring retention of medical records or other legal obligations of the Controller;
the right to data portability — in cases provided for by the GDPR;
the right to object to processing based on legitimate interest;
the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO).
To exercise rights you may contact the Controller at the e-mail address: kontakt@holistica.pl.
9. Obligation to provide data
Providing data necessary to identify the patient, register an appointment, provide a healthcare service, keep medical records and fulfill legal obligations is required to use the healthcare service.
Failure to provide data necessary to identify the patient or provide the service may make it impossible to conduct an appointment or teleconsultation.
Providing data for marketing purposes is voluntary and does not affect the possibility of using healthcare services.
10. Source of data
Data are generally obtained directly from the patient.
In the case of minor patients or persons who are not acting independently, data may be obtained from a legal representative, actual caregiver or authorized person.
Data may also be obtained via registration platforms, online forms, e-mail, telephone or systems used to organize appointments.
11. Automated decision-making
The Controller does not make decisions concerning patients based solely on automated processing, including profiling, which would produce legal effects concerning the patient or similarly significantly affect them.
Diagnostic and therapeutic decisions are always made by a physician.
