Privacy Policy
Hip2Knee Clinic | Data Protection & Patient Confidentiality Notice
1. Introduction & Overview
At Hip2Knee Clinic, the private medical practice of Mr Lebur Rohman, Consultant Orthopaedic Surgeon, preserving patient privacy and upholding strict clinical confidentiality is fundamental to our practice. This Privacy Notice explains how we collect, process, store, and safeguard your personal information when you use our website (www.hip2knee.net), submit an inquiry, or undergo outpatient consultation and surgical care.
Mr Lebur Rohman is registered as a Data Controller with the UK Information Commissioner’s Office (ICO) and complies fully with UK GDPR and General Medical Council (GMC) ethical guidance on medical data handling.
2. Personal & Health Data We Collect
To provide high-quality, safe orthopaedic care and manage private consultation logistics, we collect information falling into two categories:
A. General Personal Data
- Contact Identification: Full name, date of birth, title, residential address, email address, and preferred contact telephone number.
- Administrative Data: Insurance policy details, pre-authorisation codes, self-pay billing address, and appointment communication history.
- Technical Website Data: IP address, browser type, and basic analytics collected when browsing www.hip2knee.net.
B. Special Category Data (Health Data)
Medical data is classified as "Special Category Data" under UK GDPR and is processed under strict conditions of medical confidentiality mandated by law and GMC guidelines.
- Clinical history, symptom details, past surgeries, and joint rehabilitation records.
- Diagnostic imaging reports (MRI scans, CT scans, X-rays) and compartment testing results.
- Referral letters from GPs, physiotherapists, or sports medicine consultants.
- Surgical consent forms, operative notes, and postoperative follow-up reports.
3. Lawful Basis for Processing Data
We process your personal and medical data under the following UK GDPR legal bases:
- Provision of Healthcare (Article 9(2)(h)): Medical information is processed for clinical assessment, surgical diagnosis, operative care, and medical treatment management.
- Legal & Regulatory Compliance (Article 6(1)(c)): Fulfilling statutory obligations, medical record retention requirements, and clinical audit guidelines.
- Contractual Necessity (Article 6(1)(b)): Managing private consultation bookings, invoicing insurers or self-pay accounts, and processing appointments.
- Legitimate Interests (Article 6(1)(f)): Improving website performance, maintaining security, and answering patient inquiries.
4. Who We Share Your Data With
Your medical information is strictly confidential. We only share relevant data with authorized third parties required for your direct clinical care and administrative management:
- Hospital Facilities: Private hospital providers where Mr Rohman practices—specifically Woodlands Hospital (Darlington) and Tyneside Surgical Services (Gateshead)—for booking rooms, scheduling operating theatres, and admitting inpatient/day-case care.
- Healthcare Professionals: Your NHS or private GP, referring physiotherapists, radiologists, and consultant anaesthetists involved in your direct care pathway.
- Private Medical Insurers: Subject to your authorization, sharing diagnostic reports and billing codes (e.g., Bupa, AXA, Aviva, Vitality, WPA) to settle claims.
- Practice Management Providers: Secure, encrypted cloud medical record systems and secretarial support compliant with UK medical data security standards.
We never sell, lease, or rent your personal data to third-party marketing companies.
5. Third-Party Web Widgets & Cookies
Our website uses targeted scripts to display verified patient feedback and improve user experience:
- Doctify & Google Widgets: We embed independent rating widgets from Doctify and Google to show verified patient reviews. These scripts may collect anonymized IP addresses and device parameters necessary to render the widget interface.
- Cookies: Small text files stored on your device to ensure core website performance and layout responsiveness. You can adjust your browser settings to block cookies if preferred.
6. Data Security & Storage Period
All electronic medical records and communications are stored on secure, encrypted, password-protected platforms meeting NHS Digital and UK GDPR security standards.
In accordance with UK Department of Health regulations and medical defense guidelines, adult clinical records are retained for a minimum of 8 years following the conclusion of treatment (or longer where legally required for specialized surgical audits).
7. Your Rights Under UK GDPR
Under UK data protection law, you have specific rights regarding your personal information:
- Right of Access (Subject Access Request): You have the right to request a copy of the personal and medical data held about you by Hip2Knee Clinic.
- Right to Rectification: You may ask us to correct inaccurate or incomplete medical contact records.
- Right to Restriction or Objection: You can request limitations on processing or object to certain administrative data uses.
- Right to Data Portability: Requesting transfer of your contact details to another provider where applicable.
To exercise any of these rights, please contact the practice secretary in writing using the details below.
8. Contact Information & ICO Complaints
If you have any questions regarding this Privacy Policy or wish to exercise your data rights, please contact:
- Data Controller: Mr Lebur Rohman, Consultant Orthopaedic Surgeon
- Practice Email / Contact: Via official contact forms at www.hip2knee.net
- Woodlands Hospital Practice: Morton Park, Darlington DL1 4PT | 📞 01325 341700
- Tyneside Surgical Services Practice: Team Valley, Gateshead NE11 0NZ | 📞 0191 737 1089
If you remain dissatisfied with how your data is handled, you have the right to lodge a complaint with the UK supervisory authority:
Information Commissioner’s Office (ICO): Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF | ico.org.uk | 📞 0303 123 1113