Patient Privacy Notice
Midlands Community Services Ltd
Version 1.0 | September 2026
Midlands Community Services Ltd (MCS) takes the confidentiality, privacy and security of patient information seriously.
This notice explains what personal information we collect and use, why we use it, how it may be shared, how long it is retained and your rights in relation to that information.
It applies to healthcare and related services provided by MCS, including referrals, consultations, procedures, online consultations and questionnaires, consent processes, communications with patients and healthcare professionals, clinical administration and digital or AI-assisted systems.
1. Who we are
Midlands Community Services Ltd (MCS) is a separate legal organisation providing NHS and other healthcare services.
Midlands Community Services Ltd is registered in England and Wales under company number 05500202.
Registered office:
The Surgery
Kiddemore Green Road
Brewood
Stafford
ST19 9BQ
MCS works very closely with Brewood Medical Practice and shares a number of clinical, administrative, information-governance and information-technology arrangements with the Practice.
2. Our relationship with Brewood Medical Practice
Although Midlands Community Services Ltd and Brewood Medical Practice are separate organisations, MCS does not operate an entirely separate clinical information infrastructure.
A substantial proportion of the clinical, administrative and information-technology systems used to support MCS services are operated, administered or managed through Brewood Medical Practice.
As a result, information relating to MCS patients may be stored, accessed, communicated or otherwise processed using systems managed through Brewood Medical Practice.
These arrangements may include electronic patient-record systems, secure patient communications, NHS clinical systems, shared-care information systems, referral systems and other healthcare information services.
Depending on the particular service, system and purpose involved, Midlands Community Services Ltd and Brewood Medical Practice may act as separate data controllers, as joint data controllers, or one organisation may undertake administrative, technical or data-processing functions in support of the other.
Both organisations apply shared information-governance, confidentiality, records-management and information-security standards.
3. Further information about systems managed through Brewood Medical Practice
Brewood Medical Practice publishes a detailed privacy notice explaining many of the clinical systems, NHS services and information flows that it manages.
Because a number of those systems are also used to support Midlands Community Services, we recommend that the Brewood Medical Practice privacy notice is read alongside this MCS Privacy Notice.
This may be relevant even if Brewood Medical Practice is not your registered GP practice, because information relating to an MCS service may still be processed using systems operated or administered through Brewood Medical Practice.
View the Brewood Medical Practice Privacy Information
Where information in the Brewood notice relates specifically to patients registered with Brewood Medical Practice, it will not necessarily apply to all MCS patients. This notice explains the additional arrangements relating specifically to MCS services.
4. What information we may collect and use
We collect and use information that is relevant to providing healthcare, administering our services, maintaining appropriate clinical records, meeting our legal and contractual obligations and maintaining safe and effective services.
This may include:
- your name, date of birth, NHS number and other patient identifiers;
- address, telephone number, email address and communication preferences;
- details of your GP and other healthcare professionals involved in your care;
- referral letters and associated clinical information;
- medical history, diagnoses, symptoms and examination findings;
- medicines, allergies and adverse reactions;
- investigation results, diagnostic reports and clinical correspondence;
- previous and proposed treatment;
- information relating to consultations, procedures and follow-up;
- information relating to consent, decisions and treatment preferences;
- information provided through online consultations, questionnaires and pre-operative forms;
- clinical photographs or images where appropriate;
- information relevant to communication, accessibility, mobility, aftercare or support needs;
- information relevant to safeguarding or patient safety;
- payment information where a privately funded or chargeable service is provided; and
- technical and security information associated with access to our digital systems.
Information about your health is classed as special category personal data and receives additional protection under data-protection law.
5. Where we obtain information from
We may receive information directly from you when you contact us, attend an appointment, complete an online consultation or questionnaire, provide information to a member of staff or communicate with us electronically.
We may also receive information from your GP, another healthcare provider, NHS referral services, hospitals, community services, diagnostic providers, laboratories, Integrated Care Boards, commissioners or other organisations involved in your healthcare.
Where appropriate and authorised, MCS clinicians and staff may also access relevant information through electronic clinical records, shared-care records and connected NHS healthcare systems.
6. Why we use your information
We primarily use your information to provide safe and effective healthcare.
This may include:
- receiving and reviewing referrals;
- assessing whether a service or treatment is appropriate for you;
- arranging appointments;
- undertaking consultations, investigations and procedures;
- providing information about proposed treatment;
- obtaining and documenting consent;
- providing follow-up and aftercare;
- communicating with you;
- communicating with your GP and other healthcare professionals;
- maintaining appropriate clinical records;
- patient-safety and safeguarding activities;
- complaints and incident investigation;
- clinical governance and quality assurance;
- clinical audit and service evaluation;
- meeting NHS commissioning and reporting requirements;
- financial and contractual administration; and
- complying with legal and regulatory requirements.
Where possible, information used for longer-term audit, statistics, service evaluation or planning will be anonymised or minimised.
We do not sell patient information.
7. Our legal basis for using your information
Data-protection law requires us to have a lawful basis for processing personal information and an additional legal condition when processing health information and other special-category data.
For NHS healthcare and associated clinical administration, the principal legal bases will normally include:
- UK GDPR Article 6(1)(e) – processing necessary for a task carried out in the public interest or in the exercise of official authority; and
- UK GDPR Article 9(2)(h) – processing necessary for the provision of health or social care or treatment, or the management of health or social care systems and services.
Other legal bases may apply in particular circumstances, including:
- Article 6(1)(c) – compliance with a legal obligation;
- Article 6(1)(d) – protection of vital interests;
- Article 6(1)(b) – where processing is necessary to provide a privately arranged service requested by you; and
- consent where we specifically ask permission for an optional use of information.
Consent to medical examination or treatment is different from consent as a legal basis under data-protection law. We do not normally rely on data-protection consent to maintain information that is necessary to provide and document your healthcare.
8. Electronic patient records and connected NHS systems
Much of the clinical and administrative information used by MCS is handled using systems operated or administered through Brewood Medical Practice.
Depending on the service and the permissions available, these may include:
- electronic patient-record systems, including EMIS Web;
- AccuRx and other secure patient-communication systems;
- NHS referral and messaging systems;
- Summary Care Record and other shared-care information where access is authorised;
- laboratory, diagnostic and clinical correspondence systems;
- NHSmail and other approved secure communication services; and
- systems used to exchange information with GPs, hospitals, commissioners and other healthcare providers.
MCS staff and clinicians may access or use information through these systems when delivering an MCS service, and communications sent on behalf of MCS may be generated using systems administered through Brewood Medical Practice.
Information may therefore move between connected healthcare systems where this is necessary to provide your care, maintain an appropriate clinical record or communicate safely with other healthcare professionals.
Access is restricted to authorised users and must be for an appropriate clinical or administrative purpose.
9. Information recorded in your clinical record
Clinically relevant information arising from an MCS service will be recorded in, or communicated to, an appropriate healthcare record.
This may include relevant history, findings, investigations, treatment decisions, consent discussions, patient-specific concerns, procedures undertaken, follow-up information and other information needed for safe continuing care.
Where your registered GP is another practice, relevant clinical information may be sent to that practice to support continuity and safety of care.
We aim to record the clinically relevant patient-specific information needed for your care without unnecessarily reproducing internal administrative material, detailed system templates or operational information that is not required within the clinical record.
10. Online consultations, questionnaires and forms
MCS may use secure online forms, questionnaires, referral-processing systems and consultation tools to obtain or process information relating to your care.
A detailed online submission may contain more information than needs to be permanently reproduced within your main clinical record.
Where this occurs, relevant patient-specific clinical information, decisions, concerns and consent information will be incorporated into the appropriate healthcare record.
The original online submission may then be treated as a temporary working record and deleted in accordance with our retention arrangements.
Versions of information and consultation materials
We may retain controlled master versions of patient-information materials, questionnaires, online consultation processes, risk information, consent wording and other clinical materials that were in use at a particular point in time.
These master records do not normally contain patient-specific information. They allow us to establish what information was provided, what questions were asked and what process was in use at the time.
Your clinical record may therefore refer to the particular version of an information or consultation process that you completed without reproducing the entire underlying document or online form within your medical record.
11. Artificial intelligence and computer-assisted processing
MCS may use artificial intelligence and other computer-assisted technologies to support authorised staff and clinicians in providing and administering healthcare services.
These systems may assist with activities such as:
- reviewing and organising referral information;
- extracting relevant information from clinical documents;
- identifying missing or inconsistent information;
- supporting referral and pathway triage;
- reviewing information submitted through online consultations and questionnaires;
- pre-operative assessment and administrative processing;
- preparing structured summaries for clinical records;
- identifying information that requires clinician review;
- supporting consent and information processes; and
- clinical audit, governance and service-quality processes.
These systems may process personal identifiers and health information where this is necessary to perform the relevant task safely.
We aim to use only the information reasonably necessary for the purpose and apply appropriate access, confidentiality and security controls.
12. Human involvement in clinical decisions
MCS does not currently use artificial intelligence to make solely automated final decisions about whether a patient will receive treatment or undergo a clinical procedure.
Artificial intelligence is used to support authorised administrative staff and healthcare professionals rather than replacing appropriate human judgement.
Clinically significant decisions remain subject to appropriate human review, clinical assessment and professional judgement.
Where a procedure is being considered, an AI-assisted process does not replace appropriate clinical assessment, discussion of the proposed treatment, consideration of risks and alternatives, or the requirement for valid consent.
If you have concerns about the use of an AI-assisted process in relation to your care, you may ask us for further information or request appropriate human review.
13. Technology providers and organisations processing information on our behalf
We use specialist organisations and technology providers to support healthcare delivery, clinical systems, secure communications, website hosting, online forms and other digital services.
Where another organisation processes personal information on our behalf, appropriate contractual, confidentiality, security and data-protection requirements apply.
Some AI-assisted functions may use specialist external technology providers to process information securely on our behalf.
Patient information submitted through our clinical AI systems is not provided for the purpose of training general-purpose artificial-intelligence models.
Depending on the particular technology and contractual arrangements in use, limited technical copies of information may be retained temporarily by a technology provider for security, abuse-prevention or service-protection purposes.
We keep these arrangements under review and seek to minimise both the information transmitted and the period for which temporary copies are retained.
14. Who we may share information with
Where necessary and lawful, information may be shared with organisations or individuals involved in your healthcare or in the safe operation and governance of the service.
These may include:
- your GP practice;
- other NHS healthcare professionals;
- hospitals and community healthcare services;
- diagnostic and laboratory providers;
- NHS referral services;
- Integrated Care Boards and NHS commissioners;
- clinical-system and secure communication providers;
- website, hosting and digital technology providers;
- specialist AI and data-processing providers;
- payment providers where a chargeable service is provided;
- professional advisers and indemnity organisations where necessary;
- regulators and statutory bodies; and
- organisations involved in safeguarding, patient safety or legal processes where disclosure is justified or required.
Information will only be shared where there is an appropriate purpose and legal or confidentiality basis for doing so.
15. Confidentiality and information security
Patient information is protected by data-protection legislation, professional duties of confidentiality and the Common Law Duty of Confidentiality.
MCS and Brewood Medical Practice use technical and organisational measures appropriate to the sensitivity of health information.
These include measures such as:
- access restricted to authorised users;
- individual user accounts;
- authentication and multi-factor authentication where appropriate;
- secure clinical and communication systems;
- controlled access to online systems;
- information-governance and confidentiality policies;
- staff training;
- audit and access records;
- secure handling of patient documents; and
- processes for identifying, reporting and investigating information-security incidents.
No electronic system can be guaranteed to be entirely free from risk. We therefore review our security arrangements and take appropriate action where new risks or incidents are identified.
16. How long we keep your information
We retain personal information only for as long as it is required for the purpose for which it is being used and in accordance with NHS records-management requirements, legal and regulatory obligations and the needs of patient care.
Clinical records
Information that forms part of an ongoing GP medical record is retained in accordance with the retention requirements applicable to GP records.
Other adult clinical records created in connection with MCS healthcare services will normally be retained for at least 8 years following the end of the relevant episode of care or last relevant clinical contact, unless another retention requirement applies.
Temporary online records and uploads
Information submitted to temporary online consultation, referral, questionnaire or document-processing systems will normally be deleted from the live web-processing system within 30 days after the relevant processing has been completed, provided that the clinically relevant information has been incorporated into, or transferred to, the appropriate healthcare record.
The temporary online system is not intended to replace the patient’s definitive clinical record.
Temporary administrative communications
Temporary administrative emails and working copies containing patient information will be deleted when they are no longer operationally required, normally within 30 days after they have been appropriately actioned and the relevant information filed elsewhere.
Audit and governance information
Formal clinical audit reports and appropriate audit records will normally be retained for 5 years.
Wherever practicable, longer-term audit information will be anonymised or minimised and will not contain direct patient identifiers.
Exceptions
Information may be retained for longer where it is relevant to a complaint, patient-safety investigation, legal claim, court process, statutory inquiry, safeguarding matter or another legal or regulatory requirement.
Information deleted from a live system may remain temporarily within protected system backups until the relevant backup cycle has expired.
17. Clinical audit, governance and service improvement
We have a responsibility to monitor and improve the quality and safety of the healthcare we provide.
Clinical and administrative information may therefore be reviewed for clinical audit, quality assurance, patient safety, governance and service-improvement purposes.
Where possible, information retained for longer-term audit purposes will be anonymised so that individual patients cannot readily be identified.
For digital and AI-assisted systems, we may retain limited governance information such as:
- the version of the system or clinical rules that was used;
- the type of recommendation generated;
- whether the recommendation was accepted or changed;
- the type of error or learning point identified;
- system performance information; and
- relevant review or approval information.
We may also retain historical master versions of clinical rules, patient-information materials, questionnaires, online forms and digital processes so that we can establish what process or information was in use at a particular point in time.
Where these master versions contain no patient information, they are not themselves patient personal data.
18. Processing outside the United Kingdom
Some technology suppliers may provide services, infrastructure or technical support from outside the United Kingdom.
Where personal information is transferred internationally, we require an appropriate lawful transfer mechanism and safeguards in accordance with UK data-protection legislation.
Further information about material international processing arrangements can be requested from us where applicable.
19. Research, planning and the National Data Opt-Out
Information required for your individual healthcare is not generally affected by the National Data Opt-Out.
Where confidential patient information is used for purposes beyond individual care, such as particular forms of research or planning, we will comply with the applicable legal requirements and the National Data Opt-Out where it applies.
Wherever possible, service-planning, statistical and audit information will be anonymised or minimised.
20. Your data-protection rights
Depending on the circumstances and the legal basis for processing, you may have rights including the right to:
- be informed about how your personal information is used;
- request access to information held about you;
- ask us to correct inaccurate or incomplete information;
- request restriction of processing in appropriate circumstances;
- object to particular types of processing;
- request erasure where the legal requirements for erasure are met;
- receive or transfer information in a portable format where the right to data portability applies;
- withdraw consent where a particular use of information relies specifically on consent; and
- raise concerns about automated decision-making and request appropriate human involvement where applicable.
These rights are not absolute. Healthcare organisations may have legal, professional or patient-safety reasons for retaining an accurate clinical record even where a patient asks for information to be deleted.
We will normally respond to a valid data-protection request within one month, subject to the provisions of data-protection legislation.
21. Keeping your information accurate
Please tell us if important personal or contact information changes or if you believe information we hold about you is inaccurate.
Clinical records should provide an accurate history of the care provided. If a previous clinical entry is later found to be incorrect, it may be appropriate to retain the original entry together with a clear correction or clarification rather than deleting the historical record.
22. Data Protection Officer
Data Protection Officer support for Midlands Community Services is provided through the information-governance arrangements shared with Brewood Medical Practice.
The Data Protection Officer is:
Paul Couldrey
PCIG Consulting Limited
7 Westacre Drive
Quarry Bank
Dudley
West Midlands
DY5 2EE
Email: Couldrey@me.com
When contacting the Data Protection Officer about an MCS service, please quote “Brewood Medical Practice”.
You can also find the current Data Protection Officer contact details in the Brewood Medical Practice privacy information .
23. Concerns or complaints about use of your information
If you are concerned about how we have collected, used, shared or protected your personal information, please contact Midlands Community Services or our Data Protection Officer so that the matter can be investigated.
You also have the right to raise a concern with the UK’s independent data-protection regulator, the Information Commissioner’s Office (ICO).
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Telephone: 0303 123 1113
24. Changes to this Privacy Notice
Healthcare services, technology and data-protection requirements change over time. We will therefore review this Privacy Notice periodically and update it where there are material changes to the way patient information is processed.
The current version and publication date will be shown on this page.
Current version: 1.0
Published: September 2026