RECORDS MANAGEMENT/ INFORMATION LIFE CYCLE POLICY

Size: px
Start display at page:

Download "RECORDS MANAGEMENT/ INFORMATION LIFE CYCLE POLICY"

Transcription

1 RECORDS MANAGEMENT/ INFORMATION LIFE CYCLE POLICY Version: 6 Policy Number: Policy Lead/Author & position: Chief Information Officer Ward / Department: Information Governance Replacing Document: 5 Ratifying Committee: Policy Development, Monitoring and Review Group Date Approved/Ratified: January 2004 Previous Reviewed Dates: December 2007, August 2009, November 2010,November 2015 Date of Current Review: August 2015 Date of Next Review: August 2018 Relevant NHSLA Standard(s): Standard 1, Criterion 7 Standard 1. Criterion 8 Target Audience All Staff & Contractors 1

2 EQUALITY STATEMENT Barnet, Enfield and Haringey NHS Trust aims to design and implement services, policies and measures that meet the diverse needs of our service, population and workforce, ensuring that none are placed at a disadvantage over others. It takes into account the Equality Act (2010) including the Human Rights Act 1998 and promotes equal opportunities for all. This document has been assessed to ensure that no employee receives less favourable treatment on the protected characteristics of their age, disability, sex (gender), gender reassignment, sexual orientation, marriage and civil partnership, race, religion or belief, pregnancy and maternity. Members of staff, volunteers or members of the public may request assistance with this policy if they have particular needs. If the member of staff has language difficulties and difficulty in understanding this policy, the use of an interpreter will be considered. Barnet, Enfield and Haringey NHS Trust embraces the four staff pledges in the NHS Constitution. This policy is consistent with these pledges. 2

3 Version Control Summary Version Date Section Author Comments 1.0 January Several Director of New Policy 2004 Strategy and Performance 2.0 December No changes August November November November 2012 Duties Director of Strategy and Performance Several Lead Nurse Education and Practice Development Several Director of Strategy and Performance Several Chief Information Officer 7.6 Workforce Development Department Update to new approved policy format Reviewed to meet 2011/12 NHSLA guidance and ensure the policy is fit for purpose for the merged organisation with Enfield Community Services Points 7.5, 8.8.4, & appendix 1 reviewed to meet NHSLA 2013/14 guidance. Several documents replaced with links. Point Reference to appendix 5. Appendix 5 added Protecting the Privacy of Transgender Patients, Meeting Your Legal Obligations. Changes to accountabilities 7.0 August 2015 Several Information Governance Manager 2.2 information related to Public Records Act included types of records includes staff diaries added reference to Records Management Code of Practice Removed reference to Audit Commission removed reference to two types of Rio included reference to records taken off site removed reference to Connecting for Health. Removed reference to paper discharge summaries. 9.1 updated reference to training mechanism. 13 amended list of related Trust documentation. Appendices amended appendix one removing links to service lines. Removed reference to St Anns records library. Amended 1.7 Health Records Management & 1.8 health record keeping standards. Added guidelines related to the management of staff diaries. 3

4 Table of Contents Section Page 1 Policy Statement 5 2 Introduction 5 3 Aim 5 4 Scope 5 5 Purpose and Outcome 5 6 Definitions 6 7 Duties 6 8. Records management Overview of Records Management Types of Records Rationality for Managing Records Monitoring Performance in Records Management Legal and Professional Obligations Record Creation Record Keeping Record Maintenance Archiving Disclosure of Records Standard Issues Specific to Health Records Tracking and Storage of Paper Records Disclosure Retention and Destruction Confidentiality and Information Sharing Access to Health Records Electronic Records Training Incident Reporting Monitoring Compliance and Effectiveness Dissemination and Implementation Trust s related Documentation References Appendices 19 Appendix 1: Links to Health record-keeping audits 20 Appendix 2: Record Management Retention and Destruction 20 schedule Appendix 3: Health Records management standards 22 Appendix 4: Protecting the Privacy of Transgender Patients 23 Appendix 5: Diary Management guidelines Annexes 26 Annex A: Records Management Code of Practice, part Annex B: Records Management Code of Practice, part 2 26 Equality Impact Assessment 27 4

5 1 Policy Statement 1.1 Barnet, Enfield & Haringey Mental Health NHS Trust (the Trust) is committed to a systematic and planned approach to the management of its records, from their creation to their ultimate disposal. This will ensure that the Trust can control both the quality and quantity of the information that it generates, that it can maintain information effectively and dispose of it efficiently and securely when no longer required. 2 Introduction 2.1 Each NHS organisation is required to have in place an overall policy statement on how it manages all of its records, including electronic records. The statement should be endorsed by the Board and made readily available to all staff at all levels of the organisation, both on induction and through regular update training. 2.2 All NHS records are public records under the terms of the Public Records Act Until 2000, the Public Records Act 1958 had been substantially amended once (by the Public Records Act 1967) and in detail many times by other statutes and statutory instruments. Most of these minor changes brought bodies within the scope of the Act. In 2000, however, the Freedom of Information Act 2000 introduced very significant changes, which came into force in January The Secretary of State for Health and all NHS organisations have a duty under the Public Records Act to make arrangements for the safe keeping and eventual disposal of all types of their records. This is carried out under the overall guidance and supervision of the Keeper of Public Records, who is answerable to Parliament. 3 Aim 3.1 The aim of this policy is to establish good practice in the Trust in the handling of records 4 Scope 4.1 This policy relates to all clinical and non-clinical operational records held in any format by the Trust. These include: All administrative records (e.g. personnel, estates, financial and accounting records, notes associated with complaints); and All patient health records (for all specialties and including private patients, including x-ray and imaging reports, registers, etc). 5 Purpose and Outcome 5.1 This document sets out a framework within which the staff responsible for managing the Trust s records and to develop specific policies and procedures to ensure that records are managed and controlled effectively, and at best value, commensurate with legal, operational and information needs. The Records Management of this process is by the management all the aspects of records whether internally or externally generated and in any format or media type, from their creation, all the way through to their lifecycle to their eventual disposal. The variance of record keeping can raise issues related to risk to the employees and also users of the Trusts facilities. Other purposes are to: 5

6 establish an information governance framework for NHS records management in relation to the creation, use, storage, management and disposal of all types of records clarify the legal obligations that apply to NHS records explain the actions required by Chief Executives and other managers to fulfil these obligations explain the requirement to select records for permanent preservation indicate where further information on records management may be found. 6 Definitions: 6.1 Records Management is a discipline which utilises an administrative system to direct and control the creation, version control, distribution, filing, retention, storage and disposal of records, in a way that is administratively and legally sound, whilst at the same time serving the operational needs of the Trust and preserving an appropriate historical record. The key components of records management are: record creation; record keeping; record maintenance (including tracking of record movements); access and disclosure; closure and transfer; appraisal; archiving; and disposal. The term Records Life Cycle describes the life of a record from its creation/receipt through the period of its active use, then into a period of inactive retention (such as closed files which may still be referred to occasionally) and finally either confidential disposal or archival preservation. In this policy, Records are defined as recorded information, in any form, created or received and maintained by the Trust in the transaction of its business or conduct of affairs and kept as evidence of such activity. Information is a corporate asset. The Trust s records are important sources of administrative, evidential and historical information. They are vital to the Trust to support its current and future operations (including meeting the requirements of Freedom of Information legislation and Data Protection Act 1998), for the purpose of accountability, and for an awareness and understanding of its history and procedures. 7 Duties 7.1 The Chief Executive and senior managers They are personally accountable for records management within the Trust. They are required to take positive ownership of, and responsibility for, the records legacy of predecessor organisations and/or obsolete services. They are also responsible for clinician s adherence to the Health record keeping standards outlined in this policy 6

7 7.2 Chief Information Officer The Chief Information Officer has lead responsibility for records management in the Trust 7.3 Managers They are responsible for the records management function in their services and should work in close association with the manager or managers responsible for freedom of information, data protection and other information governance work areas. They are responsible for ensuring that there are local arrangements in place to quality assure the standards of health record keeping. 7.4 Employees All staff, whether clinical or administrative have a delegated responsibility for health records, those staff who manage the records libraries and other storage areas where health records are kept, must have an up-to-date knowledge of, or access expert advice on, the laws and guidelines concerning confidentiality, data protection (including subject access requests) and freedom of information and also adhere to this policy This responsibility also includes managing any records that they create or use in the course of their duties. Thus any records created by an employee of the Trust are public records and may be subject to both legal and professional obligations. There are particular duties for health professionals accessing and sharing health records (see below). A description of the legal and professional obligations can be found in Annex B Clinicians are responsible for adhering to the standards of health record keeping specified in this policy. 7.5 Clinical Audit Department The Clinical Audit Department reports on a monthly audit of health record keeping standards carried out by clinicians in all services of the Trust. Findings are disseminated through the Trusts governance systems. 7.6 Workforce Development Department The Workforce Development Team manage and monitor mandatory training and provide regular reports on compliance to senior management. Record keeping is included within the e-learning training package Information Governance Forum The Information Governance forum will be responsible for monitoring and reviewing the implementation of the Trust s Records Management lifecycle policy 8 Records Management 8.1 Overview of Records Management A systematic and planned approach to the management of records within an organisation, from the moment the need for a record to be created is identified, through its creation and maintenance to its ultimate disposal ensures that the organisation has ready access to reliable information. 7

8 An organisation needs to maintain that information in a manner that effectively serves its own business needs, those of Government and of the citizen, and to dispose of the information efficiently when it is no longer required. 8.2 Types of Records This policy applies to Trust records of all types (including records of Trust patients treated on behalf of the Trust in the private healthcare sector) regardless of the media on which they are held. These may consist of: health records, electronic or paper based records of private patients seen on Trust premises registers administrative records (including, for example, human resources, estates, financial and accounting records; notes associated with complainthandling) X-ray and imaging reports, output and images photographs, slides, and other images microform (ie microfiche/microfilm) audio and video tapes, cassettes, CD-ROM etc s computerised records scanned records text messages (both outgoing from the Trust and incoming responses from the patient) Staff diaries which includes any paper based organiser, notebook or loose-leaf organiser used to manage and record time and activity in relation to their work. 8.3 Rationality for Managing Records Records are a valuable resource because of the information they contain. Highquality information underpins the delivery of high-quality evidence-based healthcare and many other key service deliverables. Information has most value when it is accurate, up to date and accessible when needed. An effective records management service ensures that information is properly managed and is available whenever and wherever there is a justified need for that information and in whatever media it is required. Information may be needed: to support patient care and continuity of care to support day-to-day business which underpins the delivery of care to support evidence-based clinical practice to support sound administrative and managerial decision making, as part of the knowledge base for NHS services to meet legal requirements, including requests from patients under subject access provisions of the Data Protection Act or the Freedom of Information Act to assist clinical and other types of audits to support improvements in clinical effectiveness through research and also to 8

9 support archival functions by taking account of the historical importance of material and the needs of future research or to support patient choice and control over treatment and services designed around patients This policy, together with the supporting annexes, identifies the specific actions and managerial responsibilities for the effective management of all types of Trust records (ie both corporate and health records) from creation, as well as day-to-day use of records, storage, and maintenance to ultimate disposal procedures The Records Management NHS Code of Practice should be consulted for retention periods of various documentations and advised methods of destruction. 8.4 Monitoring Performance in Records Management A number of bodies monitor our performance in respect of records management. The Care Quality Commission monitors a core governance standard relating to broad records management as part of its annual assessment of performance. The NHS Litigation Authority also undertakes a risk assessment survey as an integral part of its regulatory function. Other bodies likely to comment on records management performance include the Health Service Ombudsman when investigating a complaint, and the Information Commissioner when investigating alleged breaches of Data Protection or Freedom of Information legislation or in promoting the Lord Chancellor s Code of Practice on Records Management under section 46 of the Freedom of Information Act. 8.5 Legal and Professional Obligations All individuals who work for an NHS organisation are responsible for any records which they create or use in the performance of their duties. Furthermore, any record that an individual creates is a public record. The key statutory requirement for compliance with records management principles is the Data Protection Act It provides a broad framework of general standards that have to be met and considered in conjunction with other legal obligations. The Act regulates the processing of personal data, held both manually and on computer. It applies to personal information generally, not just personal files held by employers, for example in finance, personnel and occupational health departments. All NHS records are Public Records under the Public Records Acts. The Trust will take actions as necessary to comply with the legal and professional obligations set out in the Records Management: NHS Code of Practice, in particular: The Public Records Act 1958; The Data Protection Act 1998; The Freedom of Information Act 2000; The Common Law Duty of Confidentiality; and The NHS Confidentiality Code of Practice Personal data is defined as data relating to a living individual that enables him/her 9

10 to be identified either from that data alone or from that data in conjunction with other information in the data controller s possession. It therefore includes such items of information as an individual s name, address, age, race, religion, gender and physical, mental or sexual health. Processing includes everything done with that information, i.e. holding, obtaining, recording, using, disclosing and sharing it. Using includes disposal, i.e. closure of the record, transfer to an archive or destruction of the record. More information on the application of the Data Protection Act is contained in Annex B.) Other legislation relating to personal and corporate information and the records management function generally can also be found in Annex B. Additionally, health professionals are under a duty to meet records management standards set by their professional regulatory bodies. 8.6 Record Creation Each service (for example finance, estates, people and organisational development, nursing) should have in place a process for documenting its activities in respect of records management Records of operational activities should be complete and accurate in order to allow employees and their successors to undertake appropriate actions in the context of their responsibilities, to facilitate an audit or examination of the Trust by anyone so authorised, to protect the legal and other rights of the Trust, its patients, staff and any other people affected by its actions and provide authentication of the records so that the evidence derived from them is shown to be credible and authoritative Records created by the Trust should be arranged in a record-keeping system that will enable the Trust to obtain the maximum benefit from the quick and easy retrieval of information. 8.7 Record Keeping Implementing and maintaining an effective records management service depends on knowledge of what records are held, where they are stored, who manages them, in what format(s) they are made accessible and their relationship to Trust functions (for example finance, estates, human resources, healthcare). An information survey or record audit and a corporate filing system is essential to meeting this requirement. This survey will also help to enhance control over the records, and provide valuable data for developing records appraisal and disposal policies and procedures Paper and electronic record keeping systems should contain descriptive and technical documentation to enable the system to be operated efficiently and the records held in the system to be understood, The documentation should provide administrative context for effective management of records The record keeping system, whether paper or electronic, should include a documented set of rules for referencing, titling, indexing and, where appropriate, the protective marking of records. These should be easily understood to enable 10

11 the efficient retrieval of information when it is needed and to maintain security and confidentiality Service users will have a single clinical record on Rio and where considered necessary a secondary paper record within the service working with them; with a maximum of one paper record per service. Any records kept at the service users homes must be retrieved upon discharge. The location of the record at a service users home as well as its retrieval must be recorded in Rio 8.8 Record Maintenance The following should be taken into consideration: The movement and location of records should be controlled to ensure that a record can be easily retrieved at any time, that any outstanding issues can be dealt with, and that there is an auditable trail of record transactions. Storage accommodation for current records should be clean and tidy, should prevent damage to the records and should provide a safe working environment for staff. For records in digital format, maintenance in terms of back-up and planned migration to new systems should be designed and scheduled to ensure continuing access to readable information. Equipment used to store current records on all types of media should provide storage that is safe and secure from unauthorised access and which meets health and safety and fire regulations but which also allow maximum accessibility of the information in accordance with its frequency of use. A contingency or business continuity plan should be in place to provide protection for all types of records that are vital to the continued functioning of the organisation. 8.9 Archiving When records are no longer required for the conduct of current business, their placement in a designated secondary storage area is a more economical and efficient way to store them. Procedures for handling records should take full account of the need to preserve important information and keep it confidential and secure. Health Records in paper format will be moved to off-site storage within three years after the patient last attended. For further information on archiving procedures for electronic records consult the Trust s IT provider, for physical health records contact local records department managers 8.10 Disclosure of Records There are a range of statutory provisions that limit, prohibit or set conditions in respect of the disclosure of records to third parties and similarly a range of provisions that require or permit disclosure. The key statutory requirements can be found in Annex B. There are also a range of guidance documents (for example the Information Commissioner s Use and Disclosure of Health Information) that interpret statutory requirements and there are staff within the Trust who have special expertise in, or can advise on, particular types of disclosure. Caldicott Guardians, Health Records Managers or Caldicott Advisors should be 11

12 involved in any proposed disclosure of confidential patient information, informed by the Trust policy Confidentiality Code of Practice Other points of consideration are: The mechanisms for transferring records from one organisation to another should also be tailored to the sensitivity of the material contained within the records and the media on which they are held. Health Records Managers and/or Information Security staff should be able to provide advice on appropriate safeguards. Records taken off site - All members of staff taking records off site are responsible for their safekeeping. Staff should be made aware of their responsibilities and ensure that adequate security arrangements are made. On no account should a record containing personal information be left in an unattended car overnight. Arrangements should be made to ensure records are not visible when left unattended. Retention and Disposal Arrangements. Detailed guidance on retention periods for a full range of NHS records is included in the Trust Retention and Disposal Policy. It is particularly important under freedom of information legislation that the disposal of records which is defined as the point in their lifecycle when they are either transferred to an archive or destroyed is undertaken in accordance with clearly established policies which have been formally adopted by the organisation and which are enforced by properly trained and authorised staff. A record of the destruction of records, showing their reference, description and date of destruction should be maintained and preserved by the Records Manager, so that the organisation is aware of those records that have been destroyed and are therefore no longer available. Disposal schedules would constitute the basis of such a record. If a record due for destruction is known to be the subject of a request for information, or potential legal action, destruction should be delayed until disclosure has taken place or, if the authority has decided not to disclose the information, until the complaint and appeal provisions of the Freedom of Information Act have been exhausted or the legal process completed Standard Issues Specific to Health Records Quality of the written record: The following applies: The Health and Social Care Information Centre, is working towards ensuring that all NHS health records will be kept in electronic format in the future. The NHS number has been adopted as the unique identifier for all Health records. Use of the NHS number will allow linkage of Health records across systems and organisations. It is envisaged that record linkage will improve effectiveness and efficiency of clinical care to patients. Use of the NHS number also supports the concept of a lifelong record. RIO is the electronic health record which has been implemented by the Trust, 12

13 it has been acknowledged that for the foreseeable future a paper record will still have to be kept for supplementary information. Please refer to Rio Procedural guidelines for documents identified to be retained in paper format In the mixed economy of paper and electronic records which will exist as the NHS CRS is developed it is essential that paper and electronic records are managed consistently to ensure that a complete health record is available at the point of need. This transitional period, during which the balance of paper and electronic records will change, will generate significant challenges, for example before patient data is migrated to the national data spine the data must be validated to ensure that duplicate registrations are eliminated and measures put in place in local systems to ensure that duplicate registrations are not created in the future Standards of Record keeping The following standards of record keeping are expected in all health records: All paper documentation must be clearly written and legible All entries into a health record must be concise, objective and accurate and will relate only to the healthcare episode All progress notes added by clinical staff will be classed as validated From the 1 st April 2013 progress notes added by students must be validated within 48 hours No entry must contain subjective or judgmental statements All entries must be clearly defined as to the date they were made and the time the entry was made using the 24 hour clock All entries in paper documentation must be signed with the signature printed alongside the first entry All entries in paper records must be made in black ink The use of terminology and jargon must be avoided wherever possible If abbreviations are used for the sake of speed, the full meaning must appear the first time the abbreviation is used Any alterations or additions in the paper records must be dated and timed, and must be made in a way which ensures that the original entry can still be read All entries must be in chronological order Every document in the record must contain the patient s name and record number Records should be written wherever possible with the involvement of the patient/carer and in terms that the patient can understand Parental responsibility must to be identified where the records relate to a child. Patient agreement/restrictions on information sharing must be documented Validation rights 13

14 The Trust have agreed on the following with regards to which staff will be provided with validation rights to sign off their own progress notes: All qualified members of staff All Healthcare Assistants (HCA s) Administrative staff, on the request of the department to facilitate the entry of non-clinical information when required. All clinical information is to be entered by a clinician, or, where arrangements are put in place, entered in the name of the clinician by administrative staff, and validated by the clinician Filing It essential that paper health records are filed away in the right place in the relevant case note as soon as reasonably practicable. Loose materials can be easily be mislaid and present a significant risk to the quality and safety of patient care as well as jeopardising patient confidentiality. Documentation should be uploading onto Rio as per the Rio procedural guidance which is available on the intranet The following applies: All documentation in the paper health record must be filed in the body of the case note in the appropriate section in a contemporaneous order. All staff using the paper health record have a responsibility to ensure that filing of all documentation is carried in accordance with this policy. Investigation results must be signed and dated by the medical staff and attached to the appropriate mount sheet with the most recent result on top Complaint and litigation correspondence must not be filed in the health record. This information must be filed separately so as to ensure that the complainant s ongoing care is not compromised and to assure them that concerns about treatment can be raised without prejudiced. All other patient related paper documentation must be uploaded onto Rio and/or filed as specified above in the health record Process for Ensuring a Contemporaneous Complete Record of Care In the mixed economy of paper and electronic records, staff must demonstrate one clear and contemporaneous record of the care being provided is available to those involved in the patient s treatment. Trust services are provided with scanners which are to be used to aid in this process. Paper documents relevant to an individual s care and treatment should be scanned and uploaded to the patient s electronic record where appropriate. Specific guidance as to how/where this uploaded documentation is to be filed on the electronic record is available on the Trust Intranet Procedural guides. In the event the document cannot be uploaded, a note is to be placed in the patient s progress notes (on the electronic system) identifying where the paper document can be found. 14

15 8.12 Tracking and Storage of Records All paper health records must be traceable at all times. When not in use for inpatient or outpatient care, all paper health records must be held in the Records Libraries or other designated storage areas: The Records Libraries and other designated storage areas will maintain an : Individual tracer system for each set of health records The tracer form/system will be used for all movement of health records from the Records Libraries Each relevant department will use a tracer system for recording the movement of health records in and out of that department. Health records must only be transported between sites by approved transport methods. Where health records need to be taken off Trust premises (e.g. for a home visit or for a multi-professional meeting), this should be documented through the tracer system and approved by the relevant service manager/team leader. Records that are taken off site must never be left unattended and must be returned to the work base as soon as possible. If it is necessary to retain them overnight, they must be securely stored. Records must never be left in a car. Health records must never be taken home except with the prior agreement of a senior manager, in addition data shall be relevant, adequate and not excessive in relation to the purpose/s that it s required. If a health record cannot be found for any period of time despite a full search, the Health Records Manager must be informed, who will then make a document all efforts made to locate the record. It should be noted that the permanent loss of a health record is a serious event therefore an incident form must be completed and the incident management process followed which should include a full investigation into the circumstances around the loss of the record. The Caldicott Guardian must be informed of all permanently lost health records. All staff are responsible for the safe custody of patient records in their use and all records must be accessible and/or track able 24 hours a day The Records Libraries and other designated storage areas will provide security of patient paper records. Where these records are in clinical use outside of the designated areas, they must be held securely. Where rooms containing case notes are unattended, they must be locked Disclosure Original health records are legal documents and belong to the Trust. From time to time requests may be made from other health care organisations, agencies or individuals for access to the records. The main original paper records should never be sent in response to such a request. Such requests should be dealt with by providing copies and sub-copies and summaries as necessary and bearing in mind legal requirements and Trust policy around access to health records and information sharing (see section below). Original patient records may not be sent to hospitals outside of the Trust. Photocopies of relevant sections must be made by the person sending the notes. In the case of electronic health records, relevant print-outs will be made. All requests for patient records from outside the Trust must be referred to the 15

16 relevant administration Managers. provide advice upon request. The Trust Health Records manager can 8.14 Retention and Destruction All records will be retained in accordance with The Records Management NHS Code of Practice. In summary, this is as follows: Mental Health 20 years after no further treatment considered necessary or 8 years after death Children and young people until the patient s 25th birthday, or 26th if the young person was 17 at conclusion of treatment Adults and older people (ECS) 8 years following discharge from treatment or death If records are required to be kept for a longer period than stated, e.g. in cases of litigation and for research purpose, they must be clearly marked as such on the outside of the patient record folder. See Appendix Destruction of patient records must be carried out by an approved contractor who will provide written confidentiality undertakings and written certification of destruction. Health records pertaining to deceased patients or to patients who have not attended for more than four years will be archived off site to an approved third party contractor to ensure that those arrangements meet all legal and best practice requirements. It is the responsibility of the Records Libraries to undertake regular archiving as required for records stored through the libraries. Where records are stored and managed in community based or other designated stores, it is the responsibility of the manager of that service to ensure that there are suitable archiving arrangements in place. Reference should be made to the Health Records Manager in respect of all archiving arrangements. Archiving and destruction of electronic records will be carried out on behalf of the Trust by the IT service provider in consultation with the Trust Confidentiality and Information Sharing The following are required: The information that patients provide to the NHS about themselves is confidential information. All staff are subject to the duty of confidence which is a term of their contract and part of all professional codes of conduct. All staff working within the NHS are also subject to the Trust Confidentiality Code of Conduct. A copy of this is on the intranet. One of the key requirements is the need to inform patients, service users and clients about how we will use their personal information, both paper and electronic and to provide wherever possible choice about the use of that information. All services must have in place an auditable process for demonstrating that patients have been informed and that patient agreement/choices have been documented. Where patients have placed any restrictions on the use of information, this should be noted clearly on the file and on any electronic database/system used to record information in that service area. Patients must also be informed of the risks and benefits associated with the use and restriction of use of any information. Provided that these arrangements are in place, health professionals do not as 16

17 a matter of course need to seek expressed consent to share patient information on an ongoing basis where this information is being used for the purposes of providing care to the patient in question Staff should always be able to justify the purpose and extent of sharing the information within this context. Where care is being provided by a number of agencies, relevant patient information may be shared with those involved in providing that care but subject to the provisos set out in relevant Information Sharing Agreements. (see Trust policies on Confidentiality and Information Sharing). Protecting the Privacy of Transgender Patients- The Gender Recognition Act Under the Gender Recognition Act, transgender people who experience severe gender variance, and have medical treatment for the condition, may apply to the Gender Recognition Panel (GRP) for a Gender Recognition Certificate (GRC). The GRC then entitles them to recognition of the gender stated on that certificate for all purposes. In addition to protection under the Data Protection Act, the law provides extra privacy protection under the Gender Recognition Act for those transsexual people who are applying for, or who already have, a Gender Recognition Certificate (GRC). see appendix 5 briefing note for clinical leaders 8.16 Access to Health Records The following are required: Under the Data Protection Act 1998, subject to certain exemptions, patients have right of access to personal data about themselves, irrespective of when it was created, whether this is held in computerised or manual form, personal representatives of deceased patients have right of access under the Access to Health Records Act All requests for access to patient records other than from health professionals involved in the care of the patient concerned must be referred to the local manager. All requests for access to health records within these provisions should dealt with in accordance with the access arrangements set out in local procedures. All health professionals should have access to the electronic record using the Trust s security arrangements. The range of access is defined by the health professionals role (role based access). The system will ask for a reason for accessing a record outside of the agreed access level. Viewing a health record without a legitimate reason will be treated as a breach of confidentiality and be viewed as gross misconduct (see the Trust s confidentiality policy) With regard to supplementary paper records there are arrangements for access during and outside office hours: During office hours (Monday to Friday 9am to 5pm) paper records may be accessed by contacting the relevant Records Department. If the record is not there an individual tracer system is in place which records 17

18 the last destination of the record. It is essential that the tracer system used is regularly updated. Outside office hours all records held in the records libraries are accessible - local procedures apply which should be made familiar to all staff see appendix 3 (a-c). Key principles are: that notes will only be accessible to authorised professionals; that this is a responsibility on those professionals to access only those notes relevant to the case they are dealing with; that a record is made of any notes removed and that notes are returned when no longer required. With regard to access to personnel records (see separate policy on the Trust s intranet) 8.17 Electronic Records The Trust s electronic health records system Rio, is the primary health record which is linked to the National Spine. Health records information will be uploaded onto Rio using appropriate agreed methods, for example scanning. Access to Rio is available via smartcard which has strict access control levels. Access to records is routinely monitored and in accordance with the Trust s confidentiality and records policies viewing a record without a legitimate reason will result in disciplinary action and may be considered as an act of gross misconduct. Health records that pre-date Rio are kept in paper format in records libraries or off site at the Trust archive data warehouse company, and are available via records staff. Staff guidance/policies and procedures on the use of Rio are available on the following link on the Trust intranet. RiO All scanned records should adhere to the need to protect the evidential value of the record, by copying and storing the record in accordance with British Standards, in particular the Code of Practice for Legal Admissibility and evidential weight of information stored electronically (BIP 0008) and the Document Scanning: Guide to Scanning Business Documents (PD 00 16) which provides guidance to evaluate scanners to user requirements. Further guidance available at: The management of all electronic records should not differ from the management of paper records, with regard to retention periods, access, retrieval, availability, confidentiality. 9 Training 9.1 All staff are required to undertake mandatory annual Information Governance training via the Trust approved e-learning system and should include records management. The Trust acknowledges there will be a very small cohort of staff who this may not be appropriate. Alternative arrangements can be made upon request and with agreement from their line manager. Trust Employees must be appropriately trained so that they are fully aware of their 18

19 personal responsibilities in respect of record keeping and records management, and that they are competent to carry out their designated duties. Training should also include guidance for staff in the use of electronic records systems. It should be done through both generic and specific training programmes, complemented by organisational policies and procedures and guidance documentation. Local induction should include basic record keeping requirements such as: what they are recording and how it should be recorded why they are recording it how to validate information with the patient or carers or against other records to ensure they are recording the correct data ` how to identify and correct errors so that they know how to correct errors and how to report errors if they find them the use of information so they understand what the records are used for (and therefore why timeliness, accuracy and completeness of recording is so important) and how to update information and add in information from other sources confidentiality 10 Incident Reporting 10.1 All incidents are to be reported in accordance with the Trust Incident Reporting Policy using the on-line DATIXWEB reporting system. Serious harm to an employee s health or dangerous occurrences may require the Head of Non-clinical Risk to complete a RIDDOR report form. 11 Monitoring Compliance and Effectiveness 11.1 See appendix 3 12 Dissemination and Implementation 12.1 This document will be made available to all Trust staff on the Trust Intranet and through line management cascade and brought to the attention of new staff via the induction process. This policy supersedes all previous policy implementation. 13 Related Trust Documentation 13.1 Confidentiality and Information Sharing) policy Personnel records Policy Human Resources Policies Annual training needs analysis Information Governance Policy Data Protection Policy Information Sharing Policy Risk Training Policy 14 References 14.1 Please refer to Appendix 2 19

20 15. APPENDICES Appendix 1 The link below is used by staff to provide information for monthly quality assurance audits. The audits are developed for individual Boroughs and teams and subject to change where quality needs are addressed. Appendix 2 RECORDS MANAGEMENT RETENTION AND DESTRUCTION SCHEDULE 1. BACKGROUND The destruction of records is an irreversible act, while the cost of preserving records worthy of permanent preservation is high and continuing. The criteria which follow are intended to give guidance on how long records should be kept for business purposes and on the identification of records of permanent value. 2. REFERENCES Records Management: NHS Code of Practice 2006 Data Protection Act 1998 Freedom of Information Act 2000 Many of the retention periods set out below are carried forward unchanged from the previous circular on this topic. The periods recommended thus reflect long-standing good practice and established thinking about the usefulness of the records for business and periods during which the records support necessary accountability. In the case of some records, especially ledgers, some contracts and certain financial records, statutory authorities apply; where this is known to be the case, the relevant legislation or regulation is mentioned in the Notes column of the table. 3. ACTION Corporate records managers and all those with a responsibility for holding records, both manual, computerised (including s) and in any other format must ensure that records no longer required for business use are reviewed as soon as practicable under the criteria set out below so that ill-considered destruction is avoided. This schedule identifies minimum retention periods. The review will determine whether records are to be selected for permanent preservation, destroyed or retained by the Trust for research or litigation purposes. Whenever the schedule is used, the guidelines listed below should be followed: I.Local business requirements/instructions must be considered before activating retention periods in this schedule. ii. Decisions should also be considered in the light of the need to preserve records whose use cannot be anticipated fully at the present time but which may be of value to future generations. iii. Recommended minimum retention periods should be calculated from the end of the calendar or accounting year following the last entry on the document. Records Management /Information Life Cycle Policy V6 August

21 iv Where the period of retention column is marked with an asterisk*, the documents described must be considered for permanent preservation and the advice of the chief archivist of an appropriate place of deposit obtained. A list of these approved places of deposit, with telephone and fax numbers which were fully up-to-date in the autumn of 1998, can be found in Appendix B3 of HSC 1999/053 For the Record. In cases where there is any doubt about the most appropriate place of deposit, advice should be sought from Archive Inspection Services, National Archives, Kew TW9 4DU (tel: ; fax: ). v. The selection of files for permanent preservation is partly informed by precedent (the establishment of a continuity of selection) and partly by the historical context of the subject (the informed identification of a selection). General rules should be drawn up locally, using the profile of material which has already been selected, and the history of the institution or organisation (including pioneering treatments and examples of excellence) within the context of its service to the local and wider communities. vi. The provisions of the Data Protection Act 1998 must also be complied with. The schedule does not seek to cater for all eventualities: the responsible records managers need to consider whether exceptional circumstances (e.g. events of local or national significance reflected in the records) require the long-term preservation of the records. By their nature these schedules are long and the following links are to guidance given in Schedule D of the Department of Health Records management: NHS code of practice: 1. Notes to accompany the NHS Records Retention and Disposal Schedules Annex D _NHS_Code_of_Practice_Part_2_second_edition.pdf 2. Health Records Retention Schedule - Annex D1 _NHS_Code_of_Practice_Part_2_second_edition.pdf This retention schedule details a Minimum Retention Period for each type of health record. Records (whatever the media) may be retained for longer than the minimum period. However, records should not ordinarily be retained for more than 30 years. Where a retention period longer than 30 years is required (eg to be preserved for historical purposes), or for any pre-1948 records, The National Archives should be consulted. Organisations should remember that records containing personal information are subject to the Data Protection Act Business and Corporate records (non-health) retention schedule Annex D2 _NHS_Code_of_Practice_Part_2_second_edition.pdf 4. Electronic/ audit trails - Annex D3 _NHS_Code_of_Practice_Part_2_second_edition.pdf Records Management /Information Life Cycle Policy V6 August

What NHS staff need to know

What NHS staff need to know St George s Healthcare NHS NHS Trust Surrey Health Informatics Service Sussex Health Informatics Service Records Management Explained What NHS staff need to know A guide to Records Management Contents

More information

CCG: IG06: Records Management Policy and Strategy

CCG: IG06: Records Management Policy and Strategy Corporate CCG: IG06: Records Management Policy and Strategy Version Number Date Issued Review Date V3 08/01/2016 01/01/2018 Prepared By: Consultation Process: Senior Governance Manager, NECS CCG Head of

More information

LORD CHANCELLOR S CODE OF PRACTICE ON THE MANAGEMENT OF RECORDS UNDER

LORD CHANCELLOR S CODE OF PRACTICE ON THE MANAGEMENT OF RECORDS UNDER LORD CHANCELLOR S CODE OF PRACTICE ON THE MANAGEMENT OF RECORDS UNDER SECTION 46 OF THE FREEDOM OF INFORMATION ACT 2000 NOVEMBER 2002 Presented to Parliament by the Lord Chancellor Pursuant to section

More information

INFORMATION LIFECYCLE & RECORDS MANAGEMENT POLICY

INFORMATION LIFECYCLE & RECORDS MANAGEMENT POLICY INFORMATION LIFECYCLE & RECORDS MANAGEMENT POLICY Unique Reference / Version Primary Intranet Location Information Management & Governance Secondary Intranet Location Policy Name Information Lifecycle

More information

FREEDOM OF INFORMATION (SCOTLAND) ACT 2002 CODE OF PRACTICE ON RECORDS MANAGEMENT

FREEDOM OF INFORMATION (SCOTLAND) ACT 2002 CODE OF PRACTICE ON RECORDS MANAGEMENT FREEDOM OF INFORMATION (SCOTLAND) ACT 2002 CODE OF PRACTICE ON RECORDS MANAGEMENT November 2003 Laid before the Scottish Parliament on 10th November 2003 pursuant to section 61(6) of the Freedom of Information

More information

Records Management Policy

Records Management Policy Once printed off, this is an uncontrolled document. Please check the Intranet for the most up to date copy Author Freedom of Information Lead Version 5.0 Issue Issue Date October 2011 Review Date October

More information

Records Management Policy

Records Management Policy Records Management Policy Document information Document type: Operational Policy Document title: Records Management Policy Document date: November 2014 Author: NHS South Commissioning Support Unit, Information

More information

Scotland s Commissioner for Children and Young People Records Management Policy

Scotland s Commissioner for Children and Young People Records Management Policy Scotland s Commissioner for Children and Young People Records Management Policy 1 RECORDS MANAGEMENT POLICY OVERVIEW 2 Policy Statement 2 Scope 2 Relevant Legislation and Regulations 2 Policy Objectives

More information

Records Management: NHS Code of Practice. Part 1

Records Management: NHS Code of Practice. Part 1 Records Management: NHS Code of Practice Part 1 DH INFORMATION READER BOX Policy HR/Workforce Management Planning Clinical Document Purpose Estates Performance IM & T Finance Partnership Working Best Practice

More information

Information Management Policy CCG Policy Reference: IG 2 v4.1

Information Management Policy CCG Policy Reference: IG 2 v4.1 Information Management Policy CCG Policy Reference: IG 2 v4.1 Document Title: Policy Information Management Document Status: Final Page 1 of 15 Issue date: Nov-2015 Review date: Nov-2016 Document control

More information

Record Management Policy

Record Management Policy Record Management Policy Author: Kate Ayres, Governance Facilitator Owner: Fiona Jamieson, Assistant Director of Healthcare Governance Publisher: Compliance Unit Date of first issue: March 2006 Version:

More information

SUBJECT ACCESS REQUEST PROCEDURE

SUBJECT ACCESS REQUEST PROCEDURE SUBJECT ACCESS REQUEST PROCEDURE Document History Document Reference: Document Purpose: IG31 This procedure sets out the responsibility for staff when receiving requests for information provided under

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Issued by: Senior Information Risk Owner Policy Classification: Policy No: POLIG001 Information Governance Issue No: 1 Date Issued: 18/11/2013 Page No: 1 of 16 Review Date:

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY Reference number RM001 Approved by Information Management and Technology Board Date approved 23 rd November 2012 Version 1.1 Last revised July 2013 Review date May 2015 Category Records Management Owner

More information

NHS LANARKSHIRE HEALTH RECORDS POLICY Management and Maintenance, Security, Storage, Distribution and Retention of Health Records

NHS LANARKSHIRE HEALTH RECORDS POLICY Management and Maintenance, Security, Storage, Distribution and Retention of Health Records NHS LANARKSHIRE HEALTH RECORDS POLICY Management and Maintenance, Security, Storage, Distribution and Retention of Health Records Author: Responsible Lead Executive Director: Endorsing Body: Governance

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY RECORDS MANAGEMENT POLICY Version 8.0 Purpose: For use by: This document is compliant with /supports compliance with: To outline the lifecycle of a record and to provide guidance on retention and disposal

More information

Records Management and Information Lifecycle Strategy

Records Management and Information Lifecycle Strategy LINCOLNSHIRE PARTNERSHIP NHS FOUNDATION TRUST Records Management and Information Lifecycle Strategy DOCUMENT VERSION CONTROL Document Type and Title: Strategy New or Replacing: Revised/Updated Version

More information

Lord Chancellor s Code of Practice on the management of records issued under section 46 of the Freedom of Information Act 2000

Lord Chancellor s Code of Practice on the management of records issued under section 46 of the Freedom of Information Act 2000 Lord Chancellor s Code of Practice on the management of records issued under section 46 of the Freedom of Information Act 2000 Lord Chancellor s Code of Practice on the management of records issued under

More information

Council Policy. Records & Information Management

Council Policy. Records & Information Management Council Policy Records & Information Management COUNCIL POLICY RECORDS AND INFORMATION MANAGEMENT Policy Number: GOV-13 Responsible Department(s): Information Systems Relevant Delegations: None Other Relevant

More information

Corporate Records Management Policy

Corporate Records Management Policy Corporate Records Management Policy Introduction Part 1 Records Management Policy Statement. February 2011 Part 2 Records Management Strategy. February 2011 Norfolk County Council Information Management

More information

Records Management Plan. April 2015

Records Management Plan. April 2015 Records Management Plan April 2015 Prepared in accordance with the Public Records (Scotland) Act 2011 and submitted to the Keeper of the Records of Scotland for their agreement on 28 April 2015 (Revised

More information

Records Management. 1. Introduction. 2. Strategic Plan Desired Outcomes

Records Management. 1. Introduction. 2. Strategic Plan Desired Outcomes Records Management Classification: Policy Name: First Issued / Approved: Last Reviewed: Council Policy Records Management 13/9/2011, CCS0036 12 August 2014, Cl9829 24 February 2015, C10054 Next Review:

More information

SOMERSET PARTNERSHIP NHS FOUNDATION TRUST RECORDS MANAGEMENT STRATEGY. Report to the Trust Board 22 September 2015. Information Governance Manager

SOMERSET PARTNERSHIP NHS FOUNDATION TRUST RECORDS MANAGEMENT STRATEGY. Report to the Trust Board 22 September 2015. Information Governance Manager SOMERSET PARTNERSHIP NHS FOUNDATION TRUST RECORDS MANAGEMENT STRATEGY Report to the Trust Board 22 September 2015 Sponsoring Director: Author: Purpose of the report: Key Issues and Recommendations: Director

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY RECORDS MANAGEMENT POLICY October 2015 1 Subject and version number of document: Serial Number: Records Management Policy COR/010/V2.00 Operative date: October 2015 Author: CCG Owner: Links to Other Policies:

More information

Information Governance Policy

Information Governance Policy Author: Susan Hall, Information Governance Manager Owner: Fiona Jamieson, Assistant Director of Healthcare Governance Publisher: Compliance Unit Date of first issue: February 2005 Version: 5 Date of version

More information

West Midlands Police and Crime Commissioner Records Management Policy 1 Contents

West Midlands Police and Crime Commissioner Records Management Policy 1 Contents West Midlands Police and Crime Commissioner Records Management Policy 1 Contents 1 CONTENTS...2 2 INTRODUCTION...3 2.1 SCOPE...3 2.2 OVERVIEW & PURPOSE...3 2.3 ROLES AND RESPONSIBILITIES...5 COMMISSIONED

More information

RECORDS MANAGEMENT FRAMEWORK

RECORDS MANAGEMENT FRAMEWORK RECORDS MANAGEMENT FRAMEWORK Policy Number: 253 Supersedes: Standards For Healthcare Services No/s 1, 19, 20 Version No: Date Of Review: Reviewer Name: 1.1 Nov 2011 Alison Gittins 1.2 Mar 2015 Alison Gittins

More information

SCOTTISH GOVERNMENT RECORDS MANAGEMENT: NHS CODE OF PRACTICE

SCOTTISH GOVERNMENT RECORDS MANAGEMENT: NHS CODE OF PRACTICE SCOTTISH GOVERNMENT RECORDS MANAGEMENT: NHS CODE OF PRACTICE (SCOTLAND) Version 1.0 June 2008 SECTION 1 FOREWORD... 5 Background... 5 Aims... 5 Types of Record covered by the Code of Practice... 6 SECTION

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Primary Intranet Location Information Management & Governance Version Number Next Review Year Next Review Month 7.0 2018 January Current Author Phil Cottis Author s Job Title

More information

Information Governance Strategy

Information Governance Strategy Information Governance Strategy Document Status Draft Version: V2.1 DOCUMENT CHANGE HISTORY Initiated by Date Author Information Governance Requirements September 2007 Information Governance Group Version

More information

9. GOVERNANCE. Policy 9.8 RECORDS MANAGEMENT POLICY. Version 4

9. GOVERNANCE. Policy 9.8 RECORDS MANAGEMENT POLICY. Version 4 9. GOVERNANCE Policy 9.8 RECORDS MANAGEMENT POLICY Version 4 9. GOVERNANCE 9.8 RECORDS MANAGEMENT POLICY OBJECTIVES: To establish the framework for, and accountabilities of, Lithgow City Council s Records

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Document Ref: DPA20100608-001 Version: 1.3 Classification: UNCLASSIFIED (IL 0) Status: ISSUED Prepared By: Ian Mason Effective From: 4 th January 2011 Contact: Governance Team ICT

More information

RECORD MANAGEMENT AND LIFE CYCLE POLICY AND STRATEGY. Dr Caroline Yates. Information Governance team

RECORD MANAGEMENT AND LIFE CYCLE POLICY AND STRATEGY. Dr Caroline Yates. Information Governance team RECORD MANAGEMENT AND LIFE CYCLE POLICY AND STRATEGY Document Owner: Developed in Consultation With: Document type: Version: Requirement: Date of ratification: Ratified By: Date to be reviewed: Dr Caroline

More information

Policy Information Management

Policy Information Management Policy Information Management Document Title: Policy Information Management Issue date: October 2013 Document Status: Approved IGC 23 Oct 2013 Review date: October 2014 Page 1 of 17 Document control Document

More information

INFORMATION GOVERNANCE STRATEGY

INFORMATION GOVERNANCE STRATEGY INFORMATION GOVERNANCE STRATEGY Page 1 of 10 Strategy Owner Valerie Penn, Head of Governance Strategy Author Caroline Law, Information Governance Project Manager Directorate Corporate Governance Ratifying

More information

Subject Access Request Policy Number ID ID # 2011 075 Author: Nicola Bateman Author Job Title: Information Governance Manager Division: Corporate Department: Clinical Informatics Version Number: 2.1 Ratifying

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY [Type text] RECORDS MANAGEMENT POLICY POLICY TITLE Academic Year: 2013/14 onwards Target Audience: Governing Body All Staff and Students Stakeholders Final approval by: CMT - 1 October 2014 Governing Body

More information

Policy Document Control Page

Policy Document Control Page Policy Document Control Page Title Title: Information Governance Policy Version: 5 Reference Number: CO44 Keywords: Information Governance Supersedes Supersedes: Version 4 Description of Amendment(s):

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Reference number Approved by Information Management and Technology Board Date approved 14 th May 2012 Version 1.1 Last revised N/A Review date May 2015 Category Information Assurance Owner Data Protection

More information

Records Management - Department of Health

Records Management - Department of Health Policy Directive Records Management - Department of Health Document Number PD2009_057 Publication date 24-Sep-2009 Functional Sub group Corporate Administration - Records Ministry of Health, NSW 73 Miller

More information

SCOTTISH GOVERNMENT RECORDS MANAGEMENT: NHS CODE OF PRACTICE (SCOTLAND) Version 2.1 January 2012

SCOTTISH GOVERNMENT RECORDS MANAGEMENT: NHS CODE OF PRACTICE (SCOTLAND) Version 2.1 January 2012 SCOTTISH GOVERNMENT RECORDS MANAGEMENT: NHS CODE OF PRACTICE (SCOTLAND) Version 2.1 January 2012 Records Management: NHS Code of Practice (Scotland) The Scottish Government, Edinburgh 2012 Crown copyright

More information

NHS SCOTLAND PERSONAL HEALTH RECORDS MANAGEMENT POLICY FOR NHS BOARDS

NHS SCOTLAND PERSONAL HEALTH RECORDS MANAGEMENT POLICY FOR NHS BOARDS INFORMATION GOVERNANCE RECORDS MANAGEMENT GUIDANCE NOTE NUMBER 002 NHS SCOTLAND PERSONAL HEALTH RECORDS MANAGEMENT POLICY FOR NHS BOARDS Guidance Note 002 1 1 HEALTH RECORDS MANAGEMENT POLICY 1.1 Introduction

More information

Policy Document Control Page. Title: Creation, Filing and Retention of Electronic Records Protocol

Policy Document Control Page. Title: Creation, Filing and Retention of Electronic Records Protocol Policy Document Control Page Title Title: Creation, Filing and Retention of Electronic Records Protocol Version: 4 Reference Number: CO63 Supersedes Supersedes: Version 3 Description of Amendment(s): Slight

More information

HERTSMERE BOROUGH COUNCIL

HERTSMERE BOROUGH COUNCIL HERTSMERE BOROUGH COUNCIL DATA PROTECTION POLICY October 2007 1 1. Introduction Hertsmere Borough Council ( the Council ) is fully committed to compliance with the requirements of the Data Protection Act

More information

COUNCIL POLICY R180 RECORDS MANAGEMENT

COUNCIL POLICY R180 RECORDS MANAGEMENT 1. Scope The City of Mount Gambier Records Management Policy provides the policy framework for Council to effectively fulfil its obligations and statutory requirements under the State Records Act 1997.

More information

Date of review: Information Governance Group January 2016. Policy Category: CONTENT SECTION DESCRIPTION PAGE

Date of review: Information Governance Group January 2016. Policy Category: CONTENT SECTION DESCRIPTION PAGE Title: Date Approved: January 2015 Division/Department: Corporate Services Corporate Records Policy Approved by: Date of review: Information Governance Group January 2016 Author (post-holder): Interim

More information

MENTAL HEALTH TRIBUNAL FOR SCOTLAND: RECORDS MANAGEMENT POLICY. Ensuring Information is Accurate and Fit for Purpose

MENTAL HEALTH TRIBUNAL FOR SCOTLAND: RECORDS MANAGEMENT POLICY. Ensuring Information is Accurate and Fit for Purpose MENTAL HEALTH TRIBUNAL FOR SCOTLAND: RECORDS MANAGEMENT POLICY Index: Introduction Information is a Corporate Resource Personal Responsibility Information Accessibility Keeping Records of what we do Ensuring

More information

Records Management Policy

Records Management Policy Records Management Policy Policy Reference Number Responsible Department Related Policies 34CP Corporate & Community Services Code of Conduct for Elected Members, Code of Conduct for Employees, Internet,

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Name of Policy Author: Name of Review/Development Body: Ratification Body: Ruth Drewett Information Governance Steering Group Committee Trust Board : April 2015 Review date:

More information

All CCG staff. This policy is due for review on the latest date shown above. After this date, policy and process documents may become invalid.

All CCG staff. This policy is due for review on the latest date shown above. After this date, policy and process documents may become invalid. Policy Type Information Governance Corporate Standing Operating Procedure Human Resources X Policy Name CCG IG03 Information Governance & Information Risk Policy Status Committee approved by Final Governance,

More information

Data Subject Access Request Procedure

Data Subject Access Request Procedure Data Subject Access Request Procedure Policy ID IG07 Version: 2.0 Ratified by: Executive Committee Name of originator/author: Justin Dix, Governing Body Secretary Name of responsible committee/individual:

More information

IS INFORMATION SECURITY POLICY

IS INFORMATION SECURITY POLICY IS INFORMATION SECURITY POLICY Version: Version 1.0 Ratified by: Trust Executive Committee Approved by responsible committee(s) IS Business Continuity and Security Group Name/title of originator/policy

More information

ARMAGH CITY, BANBRIDGE AND CRAIGAVON BOROUGH COUNCIL GPRC/P4.0/V1.0.

ARMAGH CITY, BANBRIDGE AND CRAIGAVON BOROUGH COUNCIL GPRC/P4.0/V1.0. ARMAGH CITY, BANBRIDGE AND CRAIGAVON BOROUGH COUNCIL Document Number: Reference GPRC/P4.0/V1.0. Title of Policy: Records Management Policy No of Pages 19 (including coversheet and policy screening) (including

More information

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY

MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY MONMOUTHSHIRE COUNTY COUNCIL DATA PROTECTION POLICY Page 1 of 16 Contents Policy Information 3 Introduction 4 Responsibilities 7 Confidentiality 9 Data recording and storage 11 Subject Access 12 Transparency

More information

Executive Board. Records Manager. Quality. Trustwide

Executive Board. Records Manager. Quality. Trustwide PROCEDURE REF. SABP/QUALITY/0035 NAME OF PROCEDURE REASON FOR PROCEDURE WHAT THE PROCEDURE WILL ACHIEVE? WHO NEEDS TO KNOW ABOUT IT? Integrated Paper and Electronic Health Records To ensure effective and

More information

An Approach to Records Management Audit

An Approach to Records Management Audit An Approach to Records Management Audit DOCUMENT CONTROL Reference Number Version 1.0 Amendments Document objectives: Guidance to help establish Records Management audits Date of Issue 7 May 2007 INTRODUCTION

More information

USE OF PERSONAL MOBILE DEVICES POLICY

USE OF PERSONAL MOBILE DEVICES POLICY Policies and Procedures USE OF PERSONAL MOBILE DEVICES POLICY Date Approved by Information Strategy Group Version Issue Date Review Date Executive Lead Information Asset Owner Author 15.04.2014 1.0 01/08/2014

More information

BSO Board. Hugh McPoland. Records Management Policy. Date of Meeting: 31 st March 2011. Purpose of this Report

BSO Board. Hugh McPoland. Records Management Policy. Date of Meeting: 31 st March 2011. Purpose of this Report BSO Paper 24/2011 To: From: Subject: Status: BSO Board Hugh McPoland Records Management Policy For Approval Date of Meeting: 31 st March 2011 Purpose of this Report At the February Board meeting it was

More information

Scanning of Physical Documentation Policy

Scanning of Physical Documentation Policy Scanning of Physical Documentation Policy DOCUMENT CONTROL: Version: 1 Ratified by: Risk Management Sub Group Date ratified: 17 February 2016 Name of originator/author: Records Manager Name of responsible

More information

CARE RECORDS MANAGEMENT POLICY

CARE RECORDS MANAGEMENT POLICY CARE RECORDS MANAGEMENT POLICY POLICY NUMBER & CATEGORY C 12 Clinical VERSION NUMBER & DATE 3 August 2009 RATIFYING COMMITTEE Clinical Governance Committee DATE RATIFIED 1 September 2009 NEXT REVIEW DATE

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Owner : Head of Information Management Document ID : ICT-PL-0099 Version : 2.0 Date : May 2015 We will on request produce this Policy, or particular parts of it, in other languages

More information

Data Protection Policy

Data Protection Policy Data Protection Policy CONTENTS Introduction...2 1. Statement of Intent...2 2. Fair Processing or Privacy Statement...3 3. Data Uses and Processes...4 4. Data Quality and Integrity...4 5. Technical and

More information

INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK

INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK Log / Control Sheet Responsible Officer: Chief Finance Officer Clinical Lead: Dr J Parker, Caldicott Guardian Author: Associate IG Specialist, Yorkshire

More information

Claims Management Policy

Claims Management Policy Claims Management Policy April 2015 Author: Responsibility: Janet Young, Governance & Risk Manager All Staff should adhere to this policy Effective Date: April 2015 Review Date: April 2017 Reviewing/Endorsing

More information

Subject Access Request (SAR) Procedure

Subject Access Request (SAR) Procedure Subject Access Request (SAR) Procedure East and North Hertfordshire Clinical Commissioning Group Page 1 of 16 DOCUMENT CONTROL SHEET Document Owner: Chief Finance Officer Document Author(s): Anne Ephgrave

More information

Information Governance Policy

Information Governance Policy Information Governance Policy UNIQUE REF NUMBER: AC/IG/013/V1.2 DOCUMENT STATUS: Approved by Audit Committee 19 June 2013 DATE ISSUED: June 2013 DATE TO BE REVIEWED: June 2014 1 P age AMENDMENT HISTORY

More information

Records Management Policy

Records Management Policy Records Management Policy Document Number SOP2006-073 File No. 07/7 Date issued 1 September 2006 Author Branch Records and Mail Services Unit Branch contact 9320.7722 Division Finance & Data Services Summary

More information

Data Quality Policy SH NCP 2. Version: 5. Summary:

Data Quality Policy SH NCP 2. Version: 5. Summary: SH NCP 2 Summary: Keywords (minimum of 5): (To assist policy search engine) Target Audience: The Trust provides a framework to ensure all data that is recorded by the Trust is accurate and complies to

More information

MANAGEMENT OF POLICIES, PROCEDURES AND OTHER WRITTEN CONTROL DOCUMENTS

MANAGEMENT OF POLICIES, PROCEDURES AND OTHER WRITTEN CONTROL DOCUMENTS MANAGEMENT OF POLICIES, PROCEDURES AND OTHER WRITTEN CONTROL DOCUMENTS Document Reference No: Version No: 6 PtHB / CP 012 Issue Date: April 2015 Review Date: January 2018 Expiry Date: April 2018 Author:

More information

Human Resources and Data Protection

Human Resources and Data Protection Human Resources and Data Protection Contents 1. Policy Statement... 1 2. Scope... 2 3. What is personal data?... 2 4. Processing data... 3 5. The eight principles of the Data Protection Act... 4 6. Council

More information

Corporate Records Management Policy and Procedure

Corporate Records Management Policy and Procedure Trust Policy Corporate Records Management Policy and Procedure Department / Service: Corporate Originator: Information Governance Manager Accountable Director: Director of Resources (SIRO) Approved by:

More information

How To Protect Your Personal Information At A College

How To Protect Your Personal Information At A College Data Protection Policy Policy Details Produced by Assistant Principal Information Systems Date produced Approved by Senior Leadership Team (SLT) Date approved July 2011 Linked Policies and Freedom of Information

More information

Recor Records Management Policy - A Guide For Senior Managers

Recor Records Management Policy - A Guide For Senior Managers RECORDS MANAGEMENT POLICY Title: Purpose of Policy: Directorate Responsible for Policy: Name and Title of Author: Records Management Policy To ensure that Trust staff follow a corporate approach towards

More information

NHS Business Services Authority Records Management Audit Framework

NHS Business Services Authority Records Management Audit Framework NHS Business Services Authority Records Management Audit Framework NHS Business Services Authority Corporate Secretariat NHSBSARM019 Issue Sheet Document Reference Document Location Title Author Issued

More information

Information Governance Strategy & Policy

Information Governance Strategy & Policy Information Governance Strategy & Policy March 2014 CONTENT Page 1 Introduction 1 2 Strategic Aims 1 3 Policy 2 4 Responsibilities 3 5 Information Governance Reporting Structure 4 6 Managing Information

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Information Governance Policy_v2.0_060913_LP Page 1 of 14 Information Reader Box Directorate Purpose Document Purpose Document Name Author Corporate Governance Guidance Policy

More information

Information Governance Policy. 2 RESPONSIBLE PERSON: Steve Beeho, Head of Integrated Governance. All CCG-employed staff.

Information Governance Policy. 2 RESPONSIBLE PERSON: Steve Beeho, Head of Integrated Governance. All CCG-employed staff. Information Governance Policy 1 SUMMARY This policy is intended to ensure that staff are fully aware of their Information Governance (IG) responsibilities, so that they can effectively manage and best

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Including the Information Governance Strategy Framework and associated Information Governance Procedures Last Review Date Approving Body N/A Governing Body Date of Approval

More information

Information Governance Strategy. Version No 2.1

Information Governance Strategy. Version No 2.1 Livewell Southwest Information Governance Strategy Version No 2.1 Notice to staff using a paper copy of this guidance. The policies and procedures page of LSW Intranet holds the most recent version of

More information

Policy Document RECORDS MANAGEMENT POLICY

Policy Document RECORDS MANAGEMENT POLICY The District Council Of Elliston Policy Document RECORDS MANAGEMENT POLICY Date Adopted: 16 th December 2005 Review Date: Ongoing, as necessary Minute Number: 300. 2005 E:\WPData\Jodie\My Documents\policies

More information

RECORD KEEPING IN HEALTHCARE RECORDS POLICY

RECORD KEEPING IN HEALTHCARE RECORDS POLICY RECORD KEEPING IN HEALTHCARE RECORDS POLICY Version 6.0 Key Points The Policy provides a framework for the quality of the clinical record facilitates high quality, safe patient care and that subsequently

More information

Version Number Date Issued Review Date V1 25/01/2013 25/01/2013 25/01/2014. NHS North of Tyne Information Governance Manager Consultation

Version Number Date Issued Review Date V1 25/01/2013 25/01/2013 25/01/2014. NHS North of Tyne Information Governance Manager Consultation Northumberland, Newcastle North and East, Newcastle West, Gateshead, South Tyneside, Sunderland, North Durham, Durham Dales, Easington and Sedgefield, Darlington, Hartlepool and Stockton on Tees and South

More information

BARNSLEY CLINICAL COMMISSIONING GROUP S REMOTE WORKING AND PORTABLE DEVICES POLICY

BARNSLEY CLINICAL COMMISSIONING GROUP S REMOTE WORKING AND PORTABLE DEVICES POLICY Putting Barnsley People First BARNSLE CLINICAL COMMISSIONING GROUP S REMOTE WORKING AND PORTABLE DEVICES POLIC Version: 2.0 Approved By: Governing Body Date Approved: Feb 2014 (initial approval), March

More information

Nursing Agencies. Minimum Standards

Nursing Agencies. Minimum Standards Nursing Agencies Minimum Standards 1 Contents Page Introduction 3 Values underpinning the standards 6 SECTION 1 - MINIMUM STANDARDS Management of the nursing agency 1. Management and control of operations

More information

Data Protection Act 1998 The Data Protection Policy for the Borough Council of King's Lynn & West Norfolk

Data Protection Act 1998 The Data Protection Policy for the Borough Council of King's Lynn & West Norfolk Data Protection Act 1998 The for the Borough Council of King's Lynn & West Norfolk 1 Contents Introduction 3 1. Statement of Intent 4 2. Fair Obtaining I Processing 5 3. Data Uses and Processes 6 4. Data

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY ENFIELD CLINICAL COMMISSIONING GROUP INFORMATION GOVERNANCE POLICY PLEASE DESTROY ALL PREVIOUS VERSIONS OF THIS DOCUMENT Enfield CCG Information Governance Policy Information Governance Policy (Policy

More information

Information Governance Management Framework

Information Governance Management Framework Information Governance Management Framework Responsible Officer Author Business Planning & Resources Director Governance Manager Date effective from October 2015 Date last amended October 2015 Review date

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version 1.1 Responsible Person Information Governance Manager Lead Director Head of Corporate Services Consultation Route Information Governance Steering Group Approval Route

More information

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19 Protection of Personal Data RPC001147_EN_D_19 Table of Contents Data Protection Rules Foreword From the Data Protection Commissioner Introduction From the Chairman Data Protection Rules Responsibility

More information

Data Protection policy approved by the Governing Body of Ifield Community College. Ifield Community College Data Protection Policy

Data Protection policy approved by the Governing Body of Ifield Community College. Ifield Community College Data Protection Policy Data Protection policy approved by the Governing Body of Ifield Community College Ifield Community College Data Protection Policy Introduction The school collects and uses certain types or personal information

More information

Life Cycle of Records

Life Cycle of Records Discard Create Inactive Life Cycle of Records Current Retain Use Semi-current Records Management Policy April 2014 Document title Records Management Policy April 2014 Document author and department Responsible

More information

Applicability: All Employees Effective Date: December 6, 2005; revised January 27, 2009 Source(s):

Applicability: All Employees Effective Date: December 6, 2005; revised January 27, 2009 Source(s): Title: Category: Administration Information Management Policy No.: B5010 Replaces: B5010 Applicability: All Employees Effective Date: December 6, 2005; revised January 27, 2009 Source(s): Approval: (President

More information

Information Management Advice 50 Developing a Records Management policy

Information Management Advice 50 Developing a Records Management policy Information Management Advice 50 Developing a Records Management policy Introduction This advice explains how to develop and implement a Records Management policy. Policy is central to the development

More information

Information Governance. and what it means for you

Information Governance. and what it means for you Information Governance and what it means for you 1 Content Introduction 3 Who are we? 4 What is Information Governance? 4 Purpose of Holding Information 5 Confidentiality and Security 5 Accuracy of Information

More information

RD SOP17 Research data management and security

RD SOP17 Research data management and security RD SOP17 Research data management and security Version Number: V2 Name of originator/author: Dr Andy Mee, R&I Manager Name of responsible committee: R&I Committee Name of executive lead: Medical Director

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY RECORDS MANAGEMENT POLICY ADOPTED BY COUNCIL 13 JUNE 2006 REVIEWED BY COUNCIL 6 NOVEMBER 2006 REVIEWED BY COUNCIL 10 MAY 2010 1. INTRODUCTION The State Records Act 1997 governs the obligations and responsibilities

More information

The post holder will be guided by general polices and regulations, but will need to establish the way in which these should be interpreted.

The post holder will be guided by general polices and regulations, but will need to establish the way in which these should be interpreted. JOB DESCRIPTION Job Title: Membership and Events Manager Band: 7 Hours: 37.5 Location: Elms, Tatchbury Mount Accountable to: Head of Strategic Relationship Management 1. MAIN PURPOSE OF JOB The post holder

More information

The Newcastle upon Tyne Hospitals NHS Foundation Trust. Occupational Health Records Management and Retention Operational Policy

The Newcastle upon Tyne Hospitals NHS Foundation Trust. Occupational Health Records Management and Retention Operational Policy The Newcastle upon Tyne Hospitals NHS Foundation Trust Occupational Health Records Management and Retention Operational Policy Version No. 1.0 Effective From: 9 October 2013 Expiry Date: 30 September 2016

More information

Policies, Procedures, Guidelines and Protocols

Policies, Procedures, Guidelines and Protocols Title Trust Ref No 1545/17322 Local Ref (optional) Main points the document covers Who is the document aimed at? Author Approved by (Committee/Director) Policies, Procedures, Guidelines and Protocols Document

More information

NHS Waltham Forest Clinical Commissioning Group Information Governance Policy

NHS Waltham Forest Clinical Commissioning Group Information Governance Policy NHS Waltham Forest Clinical Commissioning Group Information Governance Policy Author: Zeb Alam & David Pearce Version 3.0 Amendments to Version 2.1 Updates made in line with National Guidance and Legislation

More information