About the Kent and Medway Care Record (KMCR)
The Kent & Medway Care Record (KMCR) is an Electronic Care Record that links data held in different provider systems for the purpose of providing health and care. The KMCR also includes a number of electronic or e-forms which are populated and updated by care professionals from these organisations as part of an Integrated Care Plan.
The KMCR which is provided by SystemC Graphnet, brings together information about citizens from different health and care organisations in a secure manner. System C Graphnet processes the data held in the KMCR on behalf of these organisations. System C Graphnet do not have any control over that data.
Benefits of such a system are:
- Improved quality of care – information about your care will be instantly available to professionals to enable accurate diagnosis and on-going treatment. Duplication of tests will be avoided.
- Improved patient safety – there will be greater visibility for health and social care providers about your current medications, allergies and adverse reactions.
- Reduced delays in care – test results will be readily available reducing waiting times.
The KMCR pulls information about individuals from several important areas of health and care including:
- Primary care, for example, GP practices
- Community services
- Mental health services
- Social care
- Secondary care, for example, hospitals
- Specialist services, for example, South East Coast Ambulance Service (SECAmb)
- Hospices
- Out of hours providers
- GP Federations
- PCNs
- Pharmacies.
The KMCR will also be used to collect data that is only held in the system, by health and care professionals. This data is held in e-forms in the KMCR. These forms are typically used for assessments and planning of care, for example:
- Frailty assessment
- Falls assessment
- Nutrition assessment
- Respiratory assessment
- Heart failure care plan
- End of life care plan
- Integrated care and support plan.
All organisations take the duty to protect your personal information and confidentiality very seriously and are committed to taking all reasonable measures to ensure the confidentiality and security of personal information for which they are responsible. The KMCR has been built in such a way as to ensure its use can be audited at any time. This allows confidentiality to be monitored where necessary.
Information recorded about you across the NHS and care organisations
When you contact an NHS or care organisation as a patient/service user, organisations collect information about you and keep records about the care and services provided. If you contact organisations for a reason other than your direct care, they may also record information about you, for example, complaints or dealing with Freedom of Information requests.
All partner organisations listed are registered with the Information Commissioner’s Office to process your personal information in accordance with the current Data Protection Act 2018 and any subsequent revisions. The data protection notifications for all participating organisations can be found on the Information Commissioner’s website. This guidance explains the types of information that is recorded about you, why this is necessary and the ways in which this information may be used.
The categories of personal information
Dependent on the purpose of processing, different categories of data may be used either within or from the KMCR. Data can be categorised using the following terms:
Anonymised data – data where personal identifiable identifiers have been removed. Data protection laws and the Common Law of Confidentiality to do not apply to anonymised data.
Pseudonymised data – data where any information which could be used to identify an individual has been replaced with a fake identifier. Pseudonymised data remains personal data and as such the Common Law Duty of Confidentiality and Data Protection legislation apply and there must be a lawful reason for using such data.
Person identifiable information (or personal data) - any information about an individual from which, either on its own or together with other information, that person may be identified. The Common Law Duty of Confidentiality and Data Protection legislation apply and there must be a lawful reason for using such data.
To find out more about the data processed for each purpose, please click on the links below (The Purpose(s) of Sharing).
In addition to the above types of data, some information is considered protected regardless of the purpose of processing; this information does not form part of your shared care record and is not disclosed to any other third parties without your permission unless there are exceptional circumstances, such as if the health and safety of others is at risk or if the law requires us to pass on such information. An example of this protected information that will be left out is fertility treatment records.
The purpose(s) of sharing
The KMCR facilitates the sharing of data for the following purposes:
- Direct care
- Secondary use
- Live test data
- My care record.
Please click on the above links to find out more about exactly how we will share your data for each of the stated purposes.
What is the lawful basis for the sharing?
Each purpose of sharing has its own lawful basis and these can be found in detail on the associated links above.
Organisations we share your personal information with
Personal Data (including special category data) will only be shared between the health and social care organisations which have signed the KMCR Joint Controller or Data Processing Agreement. These currently include:
- Dartford and Gravesham NHS Trust (D&G)
- East Kent Hospitals University NHS Foundation Trust (EKHUFT)
- Medway Maritime Hospital - Medway NHS Foundation Trust (MFT)
- Maidstone and Tunbridge Wells NHS Trust (MTW)
- Kent and Medway Partnership NHS and Social Care Partnership Trust (KMPT)
- North East London Foundation Trust (NELFT)
- Kent Community Health NHS Foundation Trust (KCHFT)
- HCRG Care Group Limited
- Medway Community Healthcare (MCH)
- General Practitioners
- South East Coast Ambulance Service (SECAmb)
- Out of Hours providers (currently IC24, Invicta Health, Channel Health Alliance, DGS Health, MCH and KCC Children’s Services)
- Kent and Medway Integrated Care Board (KM ICB)
- Kent County Council (children and adults social care departments) (KCC)
- Medway Council (children and adults social care departments) (MWC)
- Primary Care Networks (PCN’s)
- Kent and Medway Hospices (Marie Curie, Pilgrims Hospice, Demelza, Ellenor, Weald, Wisdom, Heart of Kent)
- GP Federations
- Community Interest Companies.
In the future it is likely that the KMCR will be extended to a wider range of health and care providers. This may include:
- Other Providers of community health and care services
- Community Pharmacies (Chemists).
How will the information be made available?
The information is accessed in real time for acute trusts and within a 24-hour period following automated upload for all other providers. Access to your information depends on the user having access in their own clinical systems, so professionals can only see information regarding individuals that are being referred for care or treatment or those that are currently being treated by them.
The majority of information within KMCR is presented as a read only view; meaning that the information from a provider’s local record cannot be changed. However, KMCR also provides an e-forms function which enables additional information about health, health assessments and planning of services to be created and stored within KMCR; these are only available within the KMCR system and are not transferred to any other clinical system.
How long do we keep your record?
Your records are kept for as long as necessary by local partners in accordance with their associated purpose. The retention schedules are aligned to the best practice outlined by NHS . This information can be found in a document called “Records Management Code of Practice 2021” and can be found on NHSX Records Management Code of Practice 2021.
How we keep your personal information safe and secure?
To protect personal and special category data, we ensure the information we hold is kept in secure locations and access to information is restricted to authorised personnel only.
Our appropriate technical and security measures include:
- ensuring that all employees and contractors who are involved in the processing of Personal Data are suitably trained, on an annual basis, in maintaining the confidentiality and security of the Personal Data and are under contractual or statutory obligations of confidentiality concerning the Personal Data.
- robust policies and procedures, for example, password protection
- technical security measures to prevent unauthorised access
- use of ‘user access authentication’ mechanisms to ensure that all instances of access to any Personal Data under the Kent Medway Care Record (KMCR) system are auditable against an individual; i.e. role-based access and Smartcard use to ensure appropriate and authorised access reminding staff of their responsibilities in complying with Data Protection Legislation;
- encrypting information transmitted between partners;
- implementing and maintaining business continuity, disaster recovery and other relevant policies and procedures
- completion of the NHS Data Security and Protection (DSP) Toolkit introduced in the National Data Guardian review of data security, consent and objections, and adhere to robust information governance management and accountability arrangements;
- Regular audit of policies and procedures to ensure adherence against these criteria.
The NHS Digital Code of Practice on Confidential Information applies to all staff who access the KMCR; they are required to protect your information, inform you of how your information will be used, and allow you to decide if and how your information can be shared.
What are your rights?
Under the Data Protection Legislation, you have the right:
- To be informed of the uses of your data - this enables you to be informed how your data is processed.
- Of access - this enables you to have sight of or receive a copy of the personal information held about you and to check the lawful processing of it.
- To rectification - this enables you to have any incomplete or inaccurate information held about you corrected.
- To erasure - this enables you to request that we erase personal data about you that we hold. This is not an absolute right, and depending on the legal basis that applies, we may have overriding lawful grounds to continue to process your data.
- To restrict processing - this enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it.
- To data portability - this enables you to transfer your electronic personal information to another party, where appropriate.
- To object - this enables you to object to processing of personal data about you on grounds relating to your particular situation. The right is not absolute and we may continue to use the data if we can demonstrate compelling legitimate grounds. For further information regarding your right to object, please click here.
- In relation to automated decision making & profiling - this enables you to be told if your data is being processed using automated software in relation to automated decision making and profiling note: there is no automated decision making or profiling in KMCR.
If you wish to exercise your rights in any of the ways described above, you should in the first instance contact the IG team at the care giving organisation.
Right to complain
You can get further advice or report a concern directly to the KMCR IG Team at kentchft.kmcrinformationgovernance@nhs.net.
You also have the right to contact the UK’s data protection supervisory authority (Information Commissioner’s Office) by:
- Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- 0303 123 1113 (local rate) or 01625 545745 (national rate)
- ICO website
Further information about the way in which the NHS uses personal information and your rights is published by NHS Digital.
The NHS Constitution
The NHS Constitution establishes the principles and values of the NHS in England. It sets out the rights patients, the public and staff are entitled to. These rights cover how patients access health services, the quality of care you will receive, the treatments and programmes available to you, confidentiality, information and your right to complain if things go wrong.
NHS England
NHS England collects health information from the records health and social care providers keep about the care and treatment they give, to promote health or support improvements in the delivery of care services in England.
More privacy information on
The NHS defines direct care as a ‘clinical, social or public health activity concerned with the prevention, investigation and treatment of illness and the alleviation of suffering of individuals.’
The KMCR allows authorised health and care workers easy access to information that is critical to support decision making about your care and treatment and providing integrated care; this may include preventative action.
The KMCR includes information about:
- Current health or care issues
- Medications
- Allergies
- Results of any recent tests
- Details on assessments and plans created for care or treatment
- Information about social care or carer support.
GP Connect
In order to support access to this information for direct care purposes, we use a facility called GP Connect which shares information from your GP direct to the shared care record. GP Connect makes patient information available to all appropriate clinicians when and where they need it, to support direct patients care, leading to improvements in both care and outcomes. GP Connect is not used for any purpose other than direct care.
GP Connect allows authorised Clinicians such as GPs, NHS 111 Clinicians, Secondary Care Trusts, Social Care Clinicians to be able to access the GP records of the patients they are treating via a secure NHS England service which is fed into the KMCR.
The NHS 111 service (and other services, for example other GP practices in a Primary Care Network) will be able to book appointments for patients at GP practices and other local services.
The categories of personal information:
The personal data that is collected and shared for the purposes of direct care includes:
- Person Identifiable Data:basic details about yourself e.g. Forename, Surname, Address, Date of Birth, Gender, Age, Postal Address, Postcode, Telephone Number, Email address, NHS Number and Hospital ID.
- Special categoriesof Personal Data: Racial or Ethnic origin, Physical/Mental health or condition, Biometric and Genetics data. For example, contact we have had with you such as appointments or clinic visits; notes and reports about your health, treatment and care; results of x-rays, scans and laboratory tests; relevant information from people who care for you and know you well such as health staff and relatives /carers; alerts and/or notifications for example high risk medicines.
- Criminal Offence Data: summary offence data for patients being managed on inpatient units within mental health trusts, summary offence data and forensic histories of citizens accessing the criminal liaison service when in police custody.
- Third Party Identifying Data: basic details about other individuals that may be involved in providing your care or support services, e.g. emergency contacts, relatives, mobility service providers, home care support.
It is essential that your details are accurate and up to date. Always check that your personal details are correct and please inform us of any changes as soon as possible. If you think any information is inaccurate or incorrect then please contact your health or care provider to discuss this further. This could be your GP practice or the health or social care staff that provided, or are currently providing, your treatment and care.
What is the lawful basis for the sharing?
The processing (accessing/sharing/amending) of personal data for direct care purposes is permitted under Articles 6(1)(c), 6(1)(d) and 6(1) (e) of the UK General Data Protection Regulation (UK GDPR) and UK Data Protection Act 2018 (DPA):
- Article 6(1)(c) Legal Obligation: the processing is necessary for you to comply with the law (not including contractual obligations).
- Article 6(1)(d) Vital Interest: processing is necessary in order to protect the vital interests of the data subject or of another natural person.
- Article 6(1)(e) Public Task: the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
The processing of special categories of personal data via the KMCR system is permitted under Article 9 (2) (b) and (h) and Article 10 (criminal convictions) of the UK GDPR and the UK Data Protection Act 2018 (DPA):
- Article 9(2)(b) Legal Obligation: processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorised by Union or Member State law or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject;
- Article 9(2)(h) Direct Care and Administration: processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards.
The legal obligation relies on the Health and Social Care Act 2012 s251(b) (as amended by the Health and Social Care (Safety and Quality) Act 2015 which created a statutory ‘duty to share’).
We will also recognise your rights established under UK case law collectively known as the “Common Law Duty of Confidentiality” to keep information about you confidential.
Article 10 Criminal Convictions and Offences: Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.
Note: Criminal offence data is limited to that which relates to your health or care, a comprehensive register of criminal convictions will not be kept and the condition of Article 10 of the UK GDPR as well as s10(5) of the DPA 2018 has been fulfilled.
Ahead of any Partner Organisation flowing information into the live KMCR system, it is essential that the feed of data is tested to ensure that it meets the data field requirements and allows a smooth flow of data into the platform. Where possible Graphnet will request dummy or fictional data from the Controller organisation to use within the test environment however; this sample may not provide adequate variations to meet and test all data feed specifications sufficiently.
In these circumstances a sample of live patients from the Controller’s source system may be used to meet the test criteria. All such data will be deleted from the test system immediately upon completion of the tests, and in any event no later than 2 weeks following completion of the test process. The IG Lead for the Controlling organisation will maintain responsibility for assessing and approving the case for using live test data.
The categories of personal information:
The personal data that is collected and shared for the purposes of live testing includes:
- Person Identifiable Data:basic details about yourself e.g. Forename, Surname, Address, Date of Birth, Gender, Age, Postal Address, Postcode, Telephone Number, Email address, NHS Number and Hospital ID.
- Special categoriesof Personal Data: Racial or Ethnic origin, Physical/Mental health or condition. For example, contact we have had with you such as appointments or clinic visits; notes and reports about your health, treatment and care; results of x-rays, scans and laboratory tests; relevant information from people who care for you and know you well such as health staff and relatives /carers; alerts and/or notifications for example high risk medicines.
What is the lawful basis for processing?
The processing of personal data for the purposes of live testing is permitted under UK GDPR Article 6(1)(f) of the UK General Data Protection Regulation (UK GDPR) and UK Data Protection Act 2018 (DPA):
- Article 6(1)(f) Legitimate interests: the processing is necessary for your legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect the individual’s personal data which overrides those legitimate interests.
The processing of special categories of personal data for live testing should be avoided at all times. However, if this is considered an absolute necessity it will be processed under the following Article 9 condition:
- Article 9(2)(h) Direct Care and Administration: processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards.
Whenever you use a health or care service, such as visiting your GP or attending Hospital or using Care services in the community, important information about you is collected in a patient/client record for that service. This is known as data processing for direct care purposes. Collecting this information helps to ensure you get the best possible care and treatment.
If this information collected about you is used for and shared with other organisations for purposes beyond your individual care, this is known as data processing for Secondary (indirect) care purposes.
Examples include:
- Planning, implementing and evaluating population health strategy - describing population health needs, understanding where the gaps are, the levels of ill health and reasons for them, and designing and implementing services to improve health.
- Managing finances, quality and outcomes - understanding costs of services delivered, allocating budgets to invest and improve them, and using information to ensure those services are fit for purpose.
- Risk stratification for early intervention and prevention - identifying which of our residents are in greatest need and ensuring our services are delivered in a timely and effective manner to improve their health.
- Co-ordinating and optimising patient or service user flows - using service activity data and contact data to optimise health care use by citizens of hospitals and other care facilities whilst improving health and care outcomes.
- Undertaking research - working with approved researchers to utilise the best possible methods to analyse data and give useful recommendations for planning and delivery of services.
- Public Health including analysis and reduction of healthcare inequalities - ensuring that delivery of health and healthcare services is equal and equitable for the whole population, for example: Health Checks Equity Audit (audit of access to relevant health services, and how related outcomes are distributed across the population).
Using information as described can only happen when there is a reason supported by the law. Confidential information about your health and care is only used when a legal purpose has been identified.
What is the lawful basis for the sharing?
The processing (accessing/sharing/amending) of personal data for secondary use purposes is permitted under Articles 6(1)(e) and 6(1)(f) of the UK General Data Protection Regulation (UK GDPR) and UK Data Protection Act 2018 (DPA):
- Article 6(1)(e) Public Task: the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
- Article 6(1)(f) Legitimate Interests: the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The legislation which underpins the reliance on Article 6(1)(e) will depend upon the organisation requesting the data for the purposes of carrying out its duties; in the absence of this Article 6(1)(f) will apply.
The processing of special categories of personal data via the KMCR system is permitted under Article 9(2)(h) and 9(2)(i) of the UK GDPR and the UK Data Protection Act 2018 (DPA):
- Article 9(2)(h) Direct Care and Administration: processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards.
- Article 9(2)(i) Public Interest: processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices
We will also recognise your rights established under UK case law collectively known as the “Common Law Duty of Confidentiality” to keep information about you confidential. Even though consent is not the legal basis for processing personal data for secondary purposes such as service evaluations and audit, the common law duty of confidentiality is not changing, therefore consent is still needed for people outside the care team to access and use confidential patient information for clinical audit, unless you have support under the Health Service (Control of Patient Information Regulations) 2002 (‘section 251 support’) applying via the Confidentiality Advisory Group in England and Wales or similar arrangements elsewhere in the UK.
Health and Care Analytics
Kent and Medway Shared Health and Care Analytics Board (SHcAB), a partnership of health and social care organisations who are instructed to use citizen’s data to help prevent ill health, encourage wellbeing and join up services to better meet the needs of the population of Kent and Medway.
The SHcAB will receive requests to use data collected routinely by organisations across the Kent and Medway Integrated Care System and make sure it is allowed by law. The information from more than one source may be joined together and used.
Details of each project, including the legal basis, can be found on Projects | Kent KERNEL.
SHcAB will on occasions seek to use data from the KMCR, but the data will always be anonymised or pseudonymised to protect the identity of the individual. The research and analytics may be carried out by internal NHS or external research organisations, but both KMCR and SHcAB retain responsibility to protect the data and confidentiality of the care data.
Your NHS data matters and the national data opt-out
The national data opt-out is a service that allows patients to opt out of their confidential patient information being used for research and planning. Visit the website below to find out more information or to opt-out of having your patient information being used for research and planning.
Whenever you use a health or care service, such as attending Accident & Emergency or using Community Care services, important information about you is collected in a patient record for that service. Collecting this information helps to ensure you get the best possible care and treatment.
The information collected about you when you use these services can also be used and provided to other organisations for purposes beyond your individual care, for instance to help with:
- Improving the quality and standards of care provided
- Research into the development of new treatments
- Preventing illness and diseases
- Monitoring safety
- Planning services.
This may only take place when there is a clear legal basis to use this information. All these uses help to provide better health and care for you, your family and future generations.
Confidential patient information about your health and care is only used like this where allowed by law.
Most of the time, anonymised data is used for research and planning so that you cannot be identified in which case your confidential patient information isn’t needed.
You have a choice about whether you want your confidential patient information to be used in this way. If you are happy with this use of information, you do not need to do anything. If you do choose to opt out your confidential patient information will still be used to support your individual care.
To find out more or to register your choice to opt out, please visit Your NHS data matters. On this page you will:
- See what is meant by confidential patient information
- Find examples of when confidential patient information is used for individual care and examples of when it is used for purposes beyond individual care
- Find out more about the benefits of sharing data
- Understand more about who uses the data
- Find out how your data is protected
- Be able to access the system to view, set or change your opt-out setting
- Find the contact telephone number if you want to know any more or to set/change your opt-out by phone
- See the situations where the opt-out will not apply.
You can also find out more about how patient information is used at:
HRA wesbite which covers health and care research); and Understanding patient data website (which covers how and why patient information is used, the safeguards and how decisions are made)
You can change your mind about your choice at any time.
Data being used or shared for purposes beyond individual care does not include your data being shared with insurance companies or used for marketing purposes and data would only be used in this way with your specific agreement.
KMCR is compliant with the national data opt-out policy.
How can I object to my data being shared via KMCR?
You have the right to object to your information being shared on the KMCR on grounds relating to your particular situation. The right is not absolute and we may continue to use the data if we can demonstrate compelling legitimate grounds. When considering your objection, we will consider whether you can still be provided with safe individual care.
There are three types of UK GDPR objection codes that can be applied should you decide to opt out with each having a different impact.
By opt‑out type
Type 1 opt‑out (9Nu0)
- Data is shared for:
- local shared care records
- direct care
- Data is not shown as going beyond this into national or wider datasets.
National data opt‑out
- Data is shared for:
- local shared care records
- direct care
- Data is not shared for wider uses such as national datasets, de‑identified or pseudonymised data for research and planning.
No opt‑out or objection
- Data is shared across all stages, including:
- local and direct care
- de‑identified data
- pseudonymised data
- NHS Digital
- This represents full data sharing for care, planning and research.
GDPR objection code (93c1)
- No data leaves the GP practice at all
- This is the strictest option shown
Overall flow
The diagram moves from:
- local and direct care use
across to - wider secondary uses of data (such as research, planning and national systems)
As restrictions increase, data sharing reduces from full sharing to none.
We ask you to think carefully before making this decision. Sharing your health and social care information will make it easier for services to provide the best treatment and care for you when you most need it.
Health and social care staff use your confidential information to help with your treatment and care. For example, when you visit a hospital your consultant may need to know the medicines you take.
If you do wish to object, you should contact your health or social care provider involved in your care and ensure you understand what it means for you.
If you choose to object:
- You may have to answer questions repeatedly because your full history may not be available to the care professional assessing you.
- Decisions about your care may take longer, even in emergency situations, as history needs to be confirmed.
- Some medical tests may get repeated unnecessarily e.g. if you had a blood test with your hospital consultant, your GP may not be able to see this.
Further information and national guidance can be found on the following links:
Reviews of and changes to this privacy notice
We will review the information contained within this notice regularly and update it as required. We therefore recommend that you check this webpage regularly to remain informed about the way in which we use your information.