1. Who is responsible
The website operator and the entity responsible for an enquiry must be identified as [LEGAL ENTITY, REGISTERED ADDRESS AND PRIVACY CONTACT]. A treating institution may be independently responsible for clinical care and its medical records. Where responsibilities are shared, the relevant arrangement and contact must be explained.
This review edition does not connect to a patient database or accept real submissions. Its disabled forms are for design review only. This draft is not a claim that a live service or particular certification is already in place.
2. Information used for a general enquiry
The proposed first-contact form asks for a name, contact email, country, preferred language, role and enquiry category. Its purpose is to direct and answer the request. It should not collect diagnoses, clinical files, photographs or payment information.
The live service must also describe technical records generated by its hosting and security systems, including the actual categories and retention. Those systems have not yet been identified in this draft.
3. Medical information for an authorised review
Where a review is appropriate, the responsible clinical team may request relevant records from you or your authorised healthcare providers. These can include the diagnosis, medicines and allergies, specialist reports, investigations, treatment history and other information needed for the stated clinical question.
The request must explain the recipients, purpose, secure transfer method and any overseas handling before records are sent. Please do not provide another person’s health information without the necessary authority. A family relationship alone should not be assumed to authorise every disclosure.
4. Why information may be processed
Purposes may include answering an enquiry, checking professional identity, considering a medical review, arranging permitted clinical care, maintaining product traceability, safety follow-up, handling a complaint and meeting legal or regulatory duties. Only purposes that apply to the actual service should be retained in the final notice.
The organisation must identify the legal basis for each purpose. Where EU/EEA or UK rules apply, health information needs the relevant special-category condition as well as the general processing basis. Consent must not be treated as the automatic basis for every care, safety or legal obligation. [S16]
5. Who may receive information
Depending on the authorised activity, recipients may include the referring clinician, proposed treating institution, designated medical and safety reviewers, relevant quality personnel, approved service providers and authorities where reporting is required. The final notice must identify the actual entities or meaningful categories, their roles and the limits of access.
A general enquiry should not automatically be shared with every prospective clinic, commercial agent or referral partner. A referral, records review or treatment arrangement does not provide permission for advertising use.
6. International transfers
Your country of residence, the reviewing team, the treating institution and service providers may be in different countries. Before an international medical-record transfer, the applicable recipient countries, safeguards and any relevant patient authorisation must be explained.
The final notice must describe the actual transfer arrangement and how information about its safeguards can be obtained. A generic statement that “data may be transferred worldwide” is not a substitute for this assessment.
7. How long records are retained
Retention depends on the purpose and the applicable clinical, safety, quality and legal requirements. The final schedule must specify periods or meaningful criteria for general enquiries, declined or withdrawn reviews, professional verification, treatment records, safety/product-traceability records, consent and complaints.
[INSERT APPROVED RETENTION SCHEDULE AND CONTACT FOR QUESTIONS.] No arbitrary universal deletion period is promised. Some records may need to be retained after a person stops treatment or withdraws optional consent.
8. Security and providers
The proposed service should use access-limited systems, appropriate secure transfer, controlled permissions and documented vendor responsibilities. The final description must match the systems actually implemented and tested. No website can promise absolute security.
The service must not use health enquiries, patient records or professional case materials for advertising audiences, session-replay tracking or sale of personal information. This is a proposed operating policy that must be reflected in the actual technical implementation and contracts.
9. Your choices and rights
Depending on the law that applies, you may have rights to information about processing, access, correction, deletion, restriction, objection, portability or withdrawal of consent. Rights may be subject to exceptions for care, safety, legal duties or the rights of others.
Use [VERIFIED PRIVACY CONTACT] for a request. The team may need to verify your identity and authority. The final notice must identify the appropriate regulator or complaint route for the countries served; a patient need not use an internal complaint process where the law allows a direct regulatory complaint.
10. Separate permissions
An enquiry is not consent to treatment. Permission to obtain records is not permission to use your photograph or story. Optional research, secondary data use and any optional communications must be addressed separately through the appropriate process.
Declining marketing or publicity must not determine medical eligibility. No publicity programme or marketing opt-in is included in this initial website design.
11. Children, representatives and decision-making capacity
This website does not invite children to submit their own health records. A request concerning a child or a person needing a representative requires a verified legal and clinical process, appropriate information and any required consent or assent. This does not mean that a paediatric KHC programme exists.
12. Automated decisions, updates and local notices
No automated medical-eligibility decision or chatbot diagnosis is part of this prototype. Any future automation would require a separate assessment and disclosure before use.
The final notice should show its effective date, explain material changes and provide the relevant local supplement. It must not claim that HIPAA applies to every health-related website; the US entity and service roles determine whether HIPAA duties apply. Other privacy obligations may also apply. [S17]