How it works
A small clinic, patient notes, and a supplier abroad.
Northbrook Clinic is made up, but its position is ordinary: sensitive information about patients, two suppliers involved, and nobody whose job is data protection. Six steps follow the clinic from its first entry to a finished document it can hand over.
Write down one thing you do
Northbrook Clinic starts with one job: keeping patient notes for consultations. The clinic types it in its own words. Because patient notes are health information, Prudence asks one extra question and says why it appeared, instead of leaving the clinic to guess.
Health, ethnicity, religion and a few other kinds of information are protected more strictly. The law calls them special categories, and they need a second reason on top of the ordinary one. Prudence asks for it at the moment it matters.
New activity · Northbrook Clinic
What do you do?
Keep patient records for consultations
Whose data is it?
Patients
What kind of data?
Contact details, appointment history, clinical notes
Clinical notes are health data, so the GDPR requires a second condition in addition to your lawful basis.
Suggested: providing health care. You can change it. Prudence records why the question appeared.
Name the suppliers who touch it
Two suppliers are involved: the practice system that stores the notes, and the typing service that transcribes dictation. The typing service works from the United States, so the notes leave Europe. Prudence spots that on its own.
Who touches this data
- Northbrook ClinicYou
- Practice systemSoftware supplier, Ireland
- Transcription serviceSub-supplier, United StatesLeaves the EU
You named two suppliers. Prudence identified that one of them sends data outside the EU, which requires a transfer agreement that is not yet on file.
See what is missing
Prudence says it in two sentences. Patient notes are going to the United States with no agreement in place to protect them. A supplier is handling patient data with no signed contract. Nobody had to spot either one, and nobody typed them in.
Fix the underlying entry and the warning disappears by itself. There is no second list to keep tidy.
Gaps identified · 2
The transcription service sends data to the United States
Transfer agreementAdd a transfer agreement before this activity can be approved.
Open the record ↗No signed contract with the practice system supplier
ContractA supplier that handles patient data requires a written agreement.
Open the record ↗
Give the work to someone
Each problem becomes a task with a person's name and a date. The task will not close on somebody's word: it closes when the signed contract or the agreement is attached. That is why the file still stands up a year later.
Task · Get the transfer agreement signed
- RaisedFrom the gap above
- OwnerPractice manager
- DueIn 21 days
- EvidenceSigned agreement attached
Attach the evidence before marking this task complete. The record then stands on its own at review.
Produce the document when asked
A regulator, an insurer or a large customer asks what the clinic does with personal data. Prudence produces the document from what the clinic has already entered, for one site or for all of them. The law calls it the record of processing activities and expects it on request.
Record of processing activities · generated now
- What
- Patient records for consultations
- Why
- Providing health care
- Who
- Patients
- Kept for
- 8 years after last appointment
- Shared with
- Practice system supplier · Transcription service
- Leaves the EU
- Yes. United States, agreement on file
Answer a patient in time
A patient asks for a copy of their notes. There is one month to answer, and the month starts the day the email arrives. Prudence starts the count, lists the systems that hold the data so nothing is missed, and shows the days remaining.
Data subject request · access
- Day 0A patient asks for a copy of their record
- Day 2Identity checked, request logged
- Day 9Clinical notes gathered from both systems
- Day 30Deadline, answered with two days to spare
Prudence starts the one-month clock when the request is logged and reports the remaining time each day until it is answered.
Under the hood
How the simple surface holds up.
None of this is required knowledge for daily use. It is documented because the structure underneath is what makes the simple surface reliable.
Everything sits in one place
Activities, suppliers, documents, requests and tasks are all the same kind of entry underneath, so they can point at each other instead of living in five separate spreadsheets.
Connections read as sentences
This activity runs on that system, which is operated by that supplier. You can follow the chain in either direction.
Warnings are worked out, not stored
Every warning is recalculated from your own entries each time you look, so it cannot go out of date and cannot be dismissed without actually fixing something.
Nothing is marked done without proof
A status that claims something is finished only becomes available once the supporting document is attached.
Several sites, brands or companies
Each site keeps its own entries, and any report can cover one site or all of them.
Built and hosted in the EU
Your data stays in the European Union, no customer can see another's, and every change is written to a history that cannot be edited.
The law, mapped underneath
Every question maps to a specific part of the regulation. You never need to read it, and the mapping is there when an auditor asks. The compliance guide shows the whole map.
If you want more detail: try the free demo, read the plain English guide to the regulation, look through every field, or ask for a walkthrough.