Data Processing

Data Processing

Will you be sharing the data? If yes, with whom and why. Consider principle of transparency and if you require a data sharing agreement.
Data is not shared with any external organisations. Patient demographic information is synchronised from the clinical systems (EMIS/TPP) and stored in the GP-Billing database. GP-Billing can write back to the care record in the clinical system. All integration is accredited with IM1.

Will other organisations be involved in the processing of the data? If yes, state who and why?
Data is stored in our internally managed AWS data centre - no other organisations have access to the information or are involved in processing data.

What processes will be in place to delete the data?
30 days after termination of the contract, the GP-Billing database and all backups for the practice is deleted.

Are you signed up to an approved code of conduct or certification scheme?
We are IS-27001 certified, on the GPITF framework and all integration is accredited with IM1.

Will you be using a Data Processing Agreement? If yes, give full details of why and what steps you had to take to ensure protection of data to include a contract with the processor.
Please see https://support.gpbilling.co.uk/portal/en/kb/gp-billing for details of policies and licensing.

Provide details of how the personal data will be kept secure:

a)
IT Software security provisions
  1. Login to the application is synchronised with the clinical system and provided using single sign-on.
  2. Full annual penetration testing of application and infrastructure.
b) Audit trails of user activity
  1. All system and user activity is audited as per GPITF requirements and available through the user interface.
c) Encryption
  1. Data is transmitted via 128bit SSL encrypted connections.
  2. Data is stored in an encrypted SQL database.
  3. All media is encrypted.
d) Backup
  1. Daily backup is automatically performed and retained for 30 days.
e) Secure cabinets
  1. N/A - AWS cloud.
f) Business continuity plans
  1. 24x7 high availability resilience has been implemented across multiple zones.
  2. Dual load balanced HSCN network connectivity.
  3. Multiple load balanced application servers.
  4. Realtime data mirroring between production and disaster recovery database servers.
  5. SIP based phone systems and cloud based helpdesk allowing support teams to work from any location.
  6. Full BCP plan tested every year.
g) Cyber security measures
  1. Full monitoring and security has been implemented as set out in the cloud security good practice guide.
h) Cyber essentials
  1. We have Cyber Essentials and ISO-27001.

    • Related Articles

    • Data Breach Procedure

      Introduction The following procedure ensures that we consistently manage any data breaches that impact personal identified information, ensuring we notify the relevant stakeholders in a timely manner and take any learning from the incident. Types of ...
    • Missing Data from Medical System in GP-Billing

      If you are noticing that data isn't being synced with GP-Billing from the medical system correctly, for example, you are missing customers or bills, the most common cause is that the version of GP-Billing you have installed on your computer is ...
    • Online Training

      Training We can tailor training to suit availability of your resources and match roles within your Practice. Typically training follows these sessions: Session 1 (Up to 3 hours) Provide assistance with the installation of GP-Billing on your desktop ...
    • Quickbooks

      The following guides you through the steps required to transfer data between GP Billing and QuickBooks. You will need a copy of the [Quickbooks.xlsm] or [Quickbooks – SinglePatientAccount.xlsm] spreadsheets and Microsoft Excel 2010 or above. Please ...
    • Refunds

      GP-Billing has a wizard simplifying the process of issuing refunds to customers. From the [Billing] dashboard, click the [View Account] button. Use the following buttons to find or add the customer account: [Sync Patient]                    ...