...
Briefly, as the privacy policy mentions, we are registered with the UK's ICO and comply with the DPA Data Protection Act 2018 and GDPR for EEA patients. All our UK customer data are hosted in a UK NHS N3 data centre and we do not transfer the data outside the EEA. Note that you, the patient, may still copy your data or give consent for the viewing of the data, by a third party outside of the EEA, e.g. a US physician. But that would be under your consent and control.
Regarding the security of the data, we host UK data in a secure NHS N3 data centre, to ISO 27001 standard. We also encrypt each patient's record with a unique public key, and only the patient – and the people the patient chooses – have the key with which to decrypt the record. No third parties (including PKB) have access to that decryption key so none of them can access a patient's data without that patient's permissionAccess to your data is only authorised by you, the data controller or local laws.
I do hope the information provided is helpful and please do let me know if you have any further queries.
...
PKB private ID or email address of requestor:
Patient wants to de-register
Response (refer the patient to organisation):
Thanks for getting in contact with Patients Know Best and I'm sorry to hear you wish to unsubscribe from our service.
The [organisation] have requested that we refer any requests like this to them directly. Therefore, please could you kindly send your de-registration request to [organisation support email], including your reasons and concerns. The team will soon be in touch to support you.
Response (PKB support)
Sorry to hear you wish to unsubscribe from our service.
Please can you let us know why you no longer wish to access your Patients Know Best record? We'd be happy to offer you any support or guidance if you'd think it would be helpful? Hopefully, we'll be able to resolve your issue and allow you to continue to enjoy the benefits an online patient portal brings, such as immediate access to your appointment information.
If you decide to proceed with de-registration, we’ll contact your hospital team to put this in motion. You will no longer receive notifications about changes to your record and your login will be disabled.