Trust & Privacy
This page is maintained by the haematology service to answer common questions about how the Haematology Consults portal handles patient data, access and privacy. It is app-owned editable content and is not an independent certification or a legal document; the definitive privacy notice and data protection terms are those approved by the hosting organisation’s Data Protection Officer.
Draft copy — requires DPO review
What this portal is for
The portal lets medical and surgical teams submit a haematology consultation request and lets the haematology team triage, assign and reply to those requests. It is an internal clinical tool for the haematology service.
Who can access what
- Referral submission is open to any clinician with the portal link.
- Reading and responding to referrals requires signing in and being approved by a service administrator.
- Approvals are managed by the haematology service; access can be revoked at any time from the admin console.
- Only approved users can be assigned a consult; only administrators can permanently delete a record.
What data is collected
- Patient identifiers: MRN, name, date of birth, sex, ward.
- Clinical context provided by the referrer: reason, specific question, history, medications, recent bloods, imaging and biopsy results.
- Referrer identity: name, mobile number and HSE email.
- Triage state: status, assigned clinician and the haematology recommendation.
Referrers are asked to submit only the information needed for the haematology team to triage the consult safely.
Legal basis (to be confirmed by the DPO)
Under GDPR, processing of health data is a special category and requires both an Article 6 basis and an Article 9 condition. The intended bases are Article 6(1)(e) – task carried out in the public interest – and Article 9(2)(h) – provision of health or social care. The final wording must be confirmed by the hosting organisation’s DPO before it is relied on.
Where data is stored
Referrals and audit records are stored in a managed cloud database hosted in the EU with encryption in transit (TLS) and at rest, provided by the service’s managed backend (Lovable Cloud). Access to the database is restricted to service administrators and the application itself.
How long data is kept (retention)
Each referral is tagged with a retention date. The default retention period is 7 years from the date of submission, aligned with typical clinical-record retention practice; the definitive retention schedule is the one set by the hosting organisation. When a record passes its retention date it appears in the admin purge queue and can be permanently deleted. Every deletion is written to the audit log with the reason and a snapshot of the removed record’s identifiers.
Auditing
The portal keeps an audit log of who viewed a consultation, who changed its status or assignment, who edited the haematology recommendation, and who purged a record. Only administrators can view the audit log. Audit entries are used for clinical governance and security review, not for performance monitoring of individual clinicians.
Patient rights and requests
Requests from patients to access, correct or erase their data, or to object to processing, should be directed to the hosting organisation’s Data Protection Officer using the contact details published in the organisation’s privacy notice. The haematology service will assist the DPO in locating and, where appropriate, correcting or deleting records held in this portal.
Security incidents
Suspected security incidents involving this portal should be reported to the haematology service lead and to the hosting organisation’s information security team without delay so that the statutory 72‑hour breach assessment window can be met.
Shared responsibility
The portal relies on managed cloud infrastructure for hosting, authentication and the database. The infrastructure provider is responsible for platform-level security controls; the haematology service is responsible for who is approved, what data is submitted, how long it is retained, and for responding to patient requests. Referrers are responsible for submitting only the information needed for the consult and for contacting the haematology registrar by phone for urgent cases.
Last reviewed: pending · Owner: Haematology service