Patient Information Notice

From NCPeH CY
Jump to navigation Jump to search

Patient Information Notice regarding cross-border transfer of personal health data

The following information is provided to fulfil the requirement of the EU General Data Protection Regulation to inform citizens about the processing of their personal data.

What is the eHealth Digital Service Infrastructure?

MyHealth@EU, also called the eHealth Digital Service Infrastructure (eHDSI), enables safe and easy access to your health data for healthcare professionals involved in your treatment and the provision of medicines - anytime and anywhere within the EU. This is done by electronic means through secure gateways provided by National Contact Points for eHealth (NCPeH) designated by each country.

Each country identifies which organization assumes the responsibility as a data controller for the processing of your data, as this is subject to the country's legislation.

See the last page for information specific to Cyprus.

The categories of your personal health data concerned

Patient Summary- It is a basic medical dataset that is transferred for the purpose of receiving treatment in another country. It includes important patient data such as allergies, current medication, previous illnesses and surgeries, that is necessary to treat the patient properly abroad.

Electronic prescription and dispensation - you can get a prescription for medicine from a healthcare provider in one country and receive medication through a pharmacy in another EU country. The electronic prescription contains essentially the same information as a regular paper prescription, i.e. identification of the prescriber, the patient and the medicine prescribed. The electronic dispensation includes information about the medicine dispensed. This information will be sent by the pharmacy back to the country that issued the prescription.

Laboratory Results - clinical documents containing the results of laboratory tests, stored in the home Country.

Imaging Reports - clinical documents containing the reports on images studies and, when requested, the images (e.g. in DICOM standard), stored in the home Country.

Discharge Reports - clinical document generated by the healthcare provider where the patient was treated, both as an inpatient and an outpatient, which gathers the main findings, stored in the Country of Affiliation.

Original documents containing your health information, such as laboratory results, hospital discharge letters, and medical images.

This personal health data is available in so far as it is already recorded in electronic form in your home country.

The source(s) of this data varies from country to country.

What is the legal basis for the use of your personal data?

The eHDSI services will become available for you only upon your explicit consent. Although emergency situations may justify the use of your data for your treatment without consent, if you don’t give explicit consent before travelling, your data will not be available through the eHDSI system when you are in another country, not even in case of emergency. When you are abroad in an actual care situation, your Patient Summary data will be recorded in the country of treatment in accordance with the EU General Data Protection Regulation (GDPR), the laws of that country and the practices of the particular healthcare institution.

What is the purpose of processing?

Your medical data will only be used for your personal treatment or provision of medicine . In Cyprus, the data collected for inclusion in your Patient Summary will not be used for secondary purposes, other than for statistical purposes after it has been completely anonymised. Information about the purposes of such further processing according to the laws of various countries is available at the eHDSI website.

Who processes and has access to this data?

Your Patient Summary data will be accessible only by authorised and identifiable health professionals involved in your treatment, under professional secrecy, in the country of treatment. These are health professionals in the healthcare organization where you receive your treatment or the pharmacy where you receive your prescribed medicine. Each country of treatment participating in the eHDSI system has undertaken to ensure that the participating health professionals and healthcare providers on their territory have adequate information and training about their duties. Please refer to the eHDSI website for details of the participating countries. The Patient Summary data and Electronic Prescriptions will be transferred through a secure gateway provided by the eHealth National Contact Point designated by each country.

Where and how long is the personal data stored?

The Patient Summary data may be stored for 15 years from the last update for permanent residents of Cyprus and is automatically deleted after this period. However, for visitors from other European countries, the Patient Summary is not stored at all. The retention period may vary in other countries that offer Electronic Cross-Border Health Services, with relevant information available on the eHDSI website. The storage period in other participating countries may vary. Information about the storage periods is available on the eHDSI website.

Your access rights

If you consent to the processing of your Patient Summary data by the eHDSI system, you must explicitly provide your consent. You have the right to: a) rectify any inaccurate data in your Patient Summary data, according to Article 16 of the GDPR. b) obtain the erasure of your Patient Summary data, according to Article 17 of the GDPR. c) object to the processing of your Patient Summary data on grounds relating to your particular situation, according to Article 21 of the GDPR.

You have the right to withdraw your consent at any time.

If you do not consent for your personal data to be processed by the eHDSI system, your data will not be available for you through this system when you are in another country, not even in case of emergency.

Finally, you have the right to lodge a complaint with a supervisory authority either in Cyprus or in the country of treatment, depending on the factual situation.


Contact details

Data controller

Rafael Michael

67A Limassol Avenue, 2021, Aglantzia, Cyprus

Email: Rafael.michael@neha.org.cy

Call Center: +357 22 436004

Data processor

Vanthia Toumpouri

67A Limassol Avenue, 2021, Aglantzia, Cyprus

Email: Vanthia.toumpouri@neha.org.cy

Call Center: +357 22 436031

Supervisory authority in Cyprus

Office of the Commissioner for Personal Data Protection

Address: 15, Kypranoros, 1061 Nicosia,

P.O.Box: 23378, 1682

Telephone: +357 22818456

Fax: +357 22304565

Email: commissioner@dataprotection.gov.cy