Call Centre Privacy, Confidentiality & Data Security Policy
Staff Acknowledgement Policy
Purpose
At eye2eye marketing 360, we are entrusted with sensitive client and patient information. The purpose of this policy is to ensure all team members understand their responsibilities regarding privacy, confidentiality, data security, and the proper handling of client information.
Compliance with this policy is a condition of employment.
1. Confidentiality Obligations
All information accessed during employment with eye2eye marketing 360 is strictly confidential.
This includes, but is not limited to:
-
Patient names
-
Contact details
-
Recall information
-
Appointment details
-
Client business information
-
Practice management system information
-
Reports and campaign results
-
Internal business processes
Employees must not disclose, discuss, copy, share, download, photograph, print, or distribute confidential information to any person outside the organisation.
Confidentiality obligations continue after employment ends.
2. Authorised Use of Information
Patient and client information may only be accessed for the purpose of performing authorised work duties.
Staff must not:
-
Access information out of curiosity
-
Access records unrelated to assigned work
-
Share information with friends or family
-
Use information for personal purposes
-
Retain copies of client information
All access must be work-related and authorised.
3. Workstation Security
To protect patient information, all staff must:
-
Lock their workstation whenever leaving their desk
-
Ensure computer screens are not visible to unauthorised persons
-
Maintain secure passwords
-
Never share passwords with other staff
-
Log out of systems when work is completed
All company computers automatically lock after periods of inactivity.
4. Clean Desk Policy
Staff must maintain a clean and secure workspace.
The following are prohibited:
-
Leaving patient information visible on desks
-
Writing patient details on personal notebooks
-
Leaving printed reports unattended
-
Taking client information home
Any printed documents containing patient information must be securely destroyed when no longer required.
5. Mobile Phones & Personal Devices
To protect patient privacy:
-
Personal mobile phones must not be used to photograph screens, reports, patient lists, or client information.
-
Patient information must not be stored on personal devices.
-
Personal email accounts must never be used for work-related data.
Any breach of this requirement may result in disciplinary action.
6. Email & File Sharing
Staff must only use approved company systems when handling client information.
Patient information must not be:
-
Sent to personal email accounts
-
Uploaded to unauthorised cloud storage platforms
-
Shared through social media, messaging apps, or personal devices
Approved systems include company-authorised platforms such as Monday.com, Google Workspace, client-authorised systems, and approved remote access software.
7. Remote Access Systems
Where access to client practice management software is provided:
-
Access must only be used for authorised work purposes.
-
Credentials must remain confidential.
-
Access must not be shared with any other person.
-
Staff must log out immediately after completing work.
-
Any suspected security issue must be reported immediately.
8. Telephone Conduct
As representatives of our clients:
-
Staff must maintain professional communication at all times.
-
Patient information must only be discussed with the patient or authorised representative where appropriate.
-
Conversations must be conducted discreetly to avoid disclosure of private information.
Staff should always verify they are speaking with the correct patient before discussing appointment or recall information.
9. Reporting Security Incidents
Employees must immediately report:
-
Lost devices
-
Unauthorised access
-
Suspicious emails
-
Accidental disclosure of information
-
Incorrectly sent emails or files
-
Any suspected privacy breach
Prompt reporting allows issues to be investigated and contained quickly.
10. Breaches of Policy
Failure to comply with this policy may result in:
-
Additional training
-
Formal warnings
-
Removal of system access
-
Disciplinary action
-
Termination of employment
Serious breaches involving patient information may also expose individuals to legal consequences under privacy legislation.
Section Title
This is a Paragraph. Click on "Edit Text" or double click on the text box to start editing the content and make sure to add any relevant details or information that you want to share with your visitors.
List Title
This is a Paragraph. Click on "Edit Text" or double click on the text box to start editing the content and make sure to add any relevant details or information that you want to share with your visitors.
List Title
This is a Paragraph. Click on "Edit Text" or double click on the text box to start editing the content and make sure to add any relevant details or information that you want to share with your visitors.
List Title
This is a Paragraph. Click on "Edit Text" or double click on the text box to start editing the content and make sure to add any relevant details or information that you want to share with your visitors.
List Title
This is a Paragraph. Click on "Edit Text" or double click on the text box to start editing the content and make sure to add any relevant details or information that you want to share with your visitors.
