Informaon Governance eassessment FACT SHEET

Size: px
Start display at page:

Download "Informaon Governance eassessment FACT SHEET"

Transcription

1 Based on the Core Skills Framework Informaon Governance eassessment FACT SHEET Wrien by Developed in collaboraon with Information Governance and Health Records Audit and Compliance Manager Data protecon Freedom of Informaon Act 2000 Informaon security RUH golden rules Contact details eassessment Produced by: Learning & Development Page 1 Please note: there are only 2 a empts at the eassessment.

2 Introducon This fact sheet will give you key guidance on Informaon Governance. It aims to provide you with an update on the importance of maintaining data confidenality and security. Further informaon can be found on the Trust intranet site or by compleng one of the 3 elearning programmes on ESR. You might like to refresh your training with this factsheet if you are about to aempt the online eassessment. Learning Objecves The following learning outcomes reflect a minimum standard understand the principles of Informaon Governance and how they apply in every day working environments understand within the context of their specific role how to provide a confidenal service to pa- ents and service users in line with the duty of confidenality know how to ensure and maintain good record keeping. understand fundamentals of data protecon, confidenality and the Caldico Principles understand the responsibilies of healthcare organisaons under the Freedom of Informaon Act 2000 understand individual responsibilies in responding to a Freedom of Informaon request understand the principles of good record keeping. understand, within the context of their role, how they can apply and maintain informaon security guidelines. know where they can gain local access to policies, procedures and further informaon on Informaon Governance. Training Protect yourself by ge8ng trained. Staff who have been trained have not been prosecuted when making accidental breaches. Below is a list of the elearning available on ESR: 000 Introducon to Informaon Governance Staff with access to paent and/or staff informaon. 000 The Beginners Guide to Informaon Governance Staff with no access to paent and/or staff informaon 000 Informaon Governance The Refresher Module All staff who have already done the elearning before. Page 2

3 Secon 1: Data Protecon Act (DPA) UK law in the form of the Data Protection Act 1998 governs how organisations may use personal information (about living people), including how they acquire, store, share or dispose of it. The Information Commissioners Office (ICO) is the UK s independent regulator set up to uphold the public s information rights by promoting data privacy for individuals (and openness by public bodies). The ICO investigates complaints made by the public and provides guidance for the public and organisations. Under the Act, organisations that process personal information must notify the ICO (unless they are exempt). The organisations details are entered on a public register (available on the internet). Failure to notify is a criminal offence. The DPA concerns any data that is idenfiable, e.g. name, postcode, address, dates of birth, about living individuals. We must comply with 8 principles of the act: 1. Fair and lawful processing (consent must be provided). 2. Specified purpose. 3. Adequate and not excessive. 4. Accurate and kept up to date (data quality). 5. Should not be kept longer than necessary. 6. Rights of access. 7. Should be kept secure. 8. Should not be transferred to a country outside the EEA, without adequate protecon. Strengthening the ICO Powers In April 2010, the ICO was given new powers. It can now fine organisaons (including Government Departments) and individuals 500,000 for serious data security breaches such as deliberately or recklessly breaking the data protecon principles. I could be fined 500,000! The new powers also permit the ICO to carry out spot checks on the data protecon pracces of Government departments without their permission and without prior noce. Page 3

4 Secon 2: Freedom of Informaon Public Authories (including NHS Trusts, Local Authories, Densts, Doctors, Eye Care Services and Pharmacists), are subject to the legal obligaons of the Freedom of Informaon (FOI) Act Public Authories have only 20 working days to respond to wrien informaon requests. This is the limit set out by law. Speak to the Informaon Governance Manager if you are unsure about the trusts procedures for dealing with FOI requests. The Informaon Commissioners Office (ICO) is the independent regulator (for FOI in England and Wales) set up to uphold people s informaon rights by promong openness for public bodies (and data privacy for individuals). The ICO invesgates complaints made by the public and provides guidance for the public and organisaons. Some sensive informaon might not be made available to members of the public. Trusts can turn down a freedom of informaon request if they think it will cost more than 450 to deal with. Secon 3: Sharing data outside of the NHS Paent or staff confidenal informaon should not normally be used (which includes sharing and disclosing) unless one of the following criteria are met. 1. The person has given consent for the disclosure. For paents: Consent may be implied for care purposes and related purposes that support or check the quality of care provided. For other purposes consent should be explicit and obtained in wring, e.g. for a surgical procedure. 2. There is a legal basis which permits or requires disclosure of confidenal informaon, e.g. Childrens Act 3. There are exceponal circumstances (e.g. invesgaon or prevenon of serious crime) where the overriding public interest outweighs the duty of confidenality. What to do if you get a request If there is a request or business need to share informaon outside of the NHS, then you should obtain authorisaon from your Informaon Asset owner or the Informaon Governance Manager as there are some legal implicaons to consider (such as the Data Protecon Act). To find out who the Informaon Asset Owner for your department or area is, contact the Informaon Governance Manager on ext 5556 who can advise, or check the list of IAO s published on the Intranet under Staff Resources, About Governance, Informaon Governance. Page 4

5 Secon 4: Informaon security Transmission & Storage Check What does trust policy say? Important Faxing Could this informaon be sent via NHS mail instead? Ensure the correct number before sending a fax. Google must not be used to look up fax numbers. Is it encrypted and Only use NHS.net Some hospital secure? accounts. Only these accounts are not encrypted accounts are encrypted e.g. mary.smith@glos.nhs.uk and secure. Disk, CD, Is it encrypted? Only use encrypted When destroying or archiv- Memory sck memory scks for paent and staff data ing use the Trust destrucon template. Paper Who can see it? No handover, ward or theatre lists to go off site When destroying or archiving use the Trust destrucon template Telephone Do you know who you are talking to? Validate by calling back? Security Quesons for GP surgeries/nhs Bodies Validate: The paent s Medical Records number (RUH Number) or NHS Number, who their GP is, and the paent s full name. Mobile Phone Do you know who you are talking to? Validate by calling back? No paent idenfiable informaon saved on personal equipment Security Quesons for GP surgeries/nhs Bodies Validate: The paent s Medical Records number (RUH Number) or NHS Number. Who their GP is. The paents full name. Computer Only share paetnt Don t save to the C drive Do not put any paent iden- idenfiable data with Don t share passwords/ fiable data or images on those who need to smartcards social networking sites. know. Who can see my screen? Only access paents records if you have a legimate relaonship Ensure paent data is not lem visible on screen to others who don t need to see it. Laptop Is it encrypted? Only use encrypted laptops for paent and staff data. No paent idenfiable informaon saved on personal equipment. Don t save to the laptop desktop use a memory sck for paent idenfiable data. Page 5

6 Sharing very large files outside of the Trust is subject to size limits and is not always the most suitable way of sending large files larger than 5 MB. Another method is to use what is called the Secure File Transfer Service. This allows those with NHS.net accounts to transfer large amounts of data, avoiding having to send an . Informaon on this if required is available from the website hps://nww.sm.nhs.uk/sm/upload1. Secon 5: NHS Constuon The NHS Constuon was first published on 21 January 2009 and was updated amer public consultaon in March It describes the principles of the NHS in England and the rights and responsibilies of paents, public and staff. One such right is that paents can expect the NHS to keep their confidenal informaon safe and secure. All NHS bodies and private and third sector providers supplying NHS services are required by law to take account of the NHS Constuon in their decisions and acons. The NHS Constuon will be renewed every ten years. Other reasons why we should work hard on maintaining confidenality are: 1. For paents to disclose confidenal informaon to us they have to trust that we will keep it secure 2. Paents have a right to a private life (European Convenon of Human Rights and Human Rights Act 1998) 3. NHS Contracts of employment require confidenality 4. We are a public service 5. Damage to reputaon 6. Legal imperave we could be fined 7. Hippocrac oath for physicians Secon 6: Caldico Principles (1997) In 1997 a review was carried out into the use of paent idenfiable informaon in the NHS. This was carried out because there were concerns about how paent informaon was being handled and transferred. Dame Fiona Caldico chaired the Caldico Review. The report set out principles and recommendaons for the security of paent informaon. An important recommendaon was that a senior clinician should be nominated in each NHS Trust to act as the Trust s conscience for the uses of paent idenfiable informaon. These senior clinicians are known as Caldico Guardians. At the RUH the role of Caldico Guardian is held by the Medical Director. Page 6

7 The Caldico Principles are: 1. Jus fy the purpose of using confiden al informa on 2. Only use it when absolutely necessary 3. Use the minimum required 4. Allow access on a strict need-to-know basis 5. Understand your responsibility 6. Understand and comply with the law 7. The duty to share informa on can be as important as the need to protect pa ent confiden ality. The duty to share informa on can be as important as the need to protect pa ent confiden ality Caldico 2 report 26th April 2013 Sec on 7: Informa on Quality Accuracy is just one quality that we expect in records. But other quali es are also needed for the informa on to be useful, e.g. it would be pointless having informa on which was 100% accurate but wasn t available in me for it to be used. Informa on is used to make decisions throughout the health sector each day in all sorts of situa ons. Some mes this informa on needs to be extremely high quality, such as quick and accurate test results to help decide a pa ent s urgent condi on and treatment. Other informa on may be less urgent or the level of accuracy may be less vital, such as an annual na onal comparison of flu injec ons for forward planning. Whatever the situa on, the right informa on should be in the right place at the right me - and that needs to be achieved every me. Poor quality informa on is bad for pa ent care, bad for funding and bad for reputa on, e.g.: Incomplete, inadequately analysed data can lead to serious failures in service. Poor demographic data results in duplicate and confused entries on pa ent record systems. Confused pa ent iden ty numbers can lead to the wrong pa ent being treated. Inadequate records lead to poorly planned care. Poor data results in poor: commissioning monitoring planning and financing of services. The NHS takes Informa on Quality very seriously because the consequences can be vital to pa ent outcomes or, in the case of planning, result in too much or not enough service provision. Page 7

8 High quality means: C A R A T Complete Accurate Relevant Accessible Timely Secon 8: RUH 8 Golden Rules 1. Don t save to the C drive 2. Don t share passwords/smartcards 3. Don t save paent idenfiable data on personal equipment 4. Do ensure handover, ward or theatre lists don t go off site 5. Do access paents records only if you have a legimate relaonship 6. Do use encrypted memory scks and laptops 7. Do share paent idenfiable data with those who need to know 8. Do use the Trust destrucon template when destroying or archiving. Secon 9: Responding to verbal requests Security Quesons for GP surgeries/nhs Bodies: The paents Medical Records number (RUH Number) or NHS Number Who their GP is The paents full name. Page 8

9 Secon 10: Fines and breaches Informaon Commissioners Office (ICO) have levied a number of fines on trusts. Below are some examples. Date What happened Trust Fine 1 st June 2012 Hard drives sold on Ebay, amer supplier Brighton and Sussex 325K engaged without contract NHS Trust 19 th June 2012 Thousands of records lem at disused sites Belfast Health and Social Care 225K 12 th July leers sent to an old address St George s Healthcare NHS Trust 60K 15 th Feb 2013 Fined for sending un-ecrypted discs for serious case review to hotel discs never arrived. Nursing Midwifery Council (NMC) 150K Recent accidental breaches Breaches must be reported to the NHS Commissioning Board. Below are some recent breaches. Fortunately, the staff involved had all been trained in Informaon Governance and the breaches were accidental. Date Incident 19/6/13 Diary with details of 8 paents lem in car park 10/7/13 Request for consultant s opinion about a 73 year paent found outside Waitrose in Bath 22/7/13 Oncology leer sent to wrong paent (same name) 2/8/13 Endocrine and Breast surgery handover sheet found in PAW corridor 27/8/13 A paent received their leer plus 15 more leers about other paents 150K thanks Page 9

10 Secon 11: Contacts Trust Lead Job Title Contact details Simon Edwards Informaon Governance Lead 5556 Dr Tim CraM Trust Caldico Guardian 6192 David Davis Chief Informaon Officer 6250 IT Service Desk 5444 Sarah Truelove Finance Director 4308 File Locaon: \\Tatooine\educaon\Shared Folders\10 \02 )\11 \01 \10 Informaon Governance Date of Publicaon : December 2013 Royal United Hospital Bath NHS Trust Page 10

INFORMATION GOVERNANCE STAFF HANDBOOK

INFORMATION GOVERNANCE STAFF HANDBOOK INFORMATION GOVERNANCE STAFF HANDBOOK Contents Why do YOU need to know about Information Governance (IG)?... 2 Keeping Information Safe... 2 Confidentiality... 2 Deciding to Communicate Important Information...

More information

Information Governance Manual Training Booklet

Information Governance Manual Training Booklet Information Governance Manual Training Booklet Introduction This booklet is aimed at staff who do not access a computer whilst working for the Trust. If you have access to a computer, you must complete

More information

Everyone in the workplace has a legal duty to protect the privacy of information about individuals. AEP/BELB/LJ/2010 Awareness Session

Everyone in the workplace has a legal duty to protect the privacy of information about individuals. AEP/BELB/LJ/2010 Awareness Session Everyone in the workplace has a legal duty to protect the privacy of information about individuals AEP/BELB/LJ/2010 Awareness Session During 2007 alone, 36,989,300 people in the UK have had their private

More information

MAKING A COMPLAINT. Problem with a Health or Mental Health care provider?

MAKING A COMPLAINT. Problem with a Health or Mental Health care provider? MAKING A COMPLAINT Problem with a Health or Mental Health care provider? (e.g. Hospital, Nurse, Psychiatrist, Chiropractor, Physio, Den'st, Doctor, Psychologist, etc) HOW THE HEALTH CONSUMERS COUNCIL CAN

More information

Merthyr Tydfil County Borough Council. Data Protection Policy

Merthyr Tydfil County Borough Council. Data Protection Policy Merthyr Tydfil County Borough Council Data Protection Policy 2014 Cyfarthfa High School is a Rights Respecting School, we recognise the importance of ensuring that the United Nations Convention of the

More information

Information Governance

Information Governance CONTROLLED Information Governance Caldicot Version-Workbok Non Caldicott Version - Workbook Version 12 January 2015 40 1 Don t Get Bitten by the Data Demon Notes Using this Workbook The objective of this

More information

INFORMATION GOVERNANCE AND DATA PROTECTION POLICY

INFORMATION GOVERNANCE AND DATA PROTECTION POLICY INFORMATION GOVERNANCE AND DATA PROTECTION POLICY WN CCG Information Governance & Data Protection Policy July 2013 1 Document Control Sheet Name of Document: Information Governance & Data Protection Policy

More information

Criminal Injuries Compensation Authority. Data protection audit report

Criminal Injuries Compensation Authority. Data protection audit report Criminal Injuries Compensation Authority Data protection audit report Executive summary January 2016 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with

More information

Data Protecon and E-Safety Policy

Data Protecon and E-Safety Policy Data Protecon and E-Safety Policy From Staff Policies Contents 1 Relevant legislaon 2Purpose 3 Principles 4Detail 5 Roles and Responsibilies 6 Monitoring and Evaluaon 7 Related Documents and Locaons 8

More information

Information Governance Policy

Information Governance Policy Information Governance Policy 1 Introduction Healthwatch Rutland (HWR) needs to collect and use certain types of information about the Data Subjects who come into contact with it in order to carry on its

More information

Build a HIPAA- Compliant Prac5ce. Wes Strickling, Founder & CEO

Build a HIPAA- Compliant Prac5ce. Wes Strickling, Founder & CEO Build a HIPAA- Compliant Prac5ce Wes Strickling, Founder & CEO Agenda What is HIPAA Compliance? What does it mean to your prac5ce? What should you do? Q & A What Is HIPAA Compliance? Health Insurance Portability

More information

Findings from ICO audits and reviews of community healthcare providers. June 2013 to December 2014

Findings from ICO audits and reviews of community healthcare providers. June 2013 to December 2014 Findings from ICO audits and reviews of community healthcare providers June 2013 to December 2014 Introduction The Information Commissioner s Office (ICO) is the regulator responsible for ensuring that

More information

Secure Storage, Communication & Transportation of Personal Information Policy Disclaimer:

Secure Storage, Communication & Transportation of Personal Information Policy Disclaimer: Secure Storage, Communication & Transportation of Personal Information Policy Version No: 3.0 Prepared By: Information Governance, IT Security & Health Records Effective From: 20/12/2010 Review Date: 20/12/2011

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Version: V1 Ratified by: Operational Management Executive Committee Date ratified: 26 September 2013 Name and Title of originator/author(s): Chris Brady, FOI, Data Protection and

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Version 1.3 April 2014 Contents 1 POLICY STATEMENT...2 2 PURPOSE....2 3 LEGAL CONTEXT AND DEFINITIONS...2 3.1 Data Protection Act 1998...2 3.2 Other related legislation.....4 3.3

More information

DATA PROTECTION CORPORATE POLICY

DATA PROTECTION CORPORATE POLICY DATA PROTECTION CORPORATE POLICY Information Management V1.1 03 July 2012 Not protectively marked This policy must be complied with fully by all Members, Officers Agents and Contractors of Plymouth City

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Responsible Officer Author Date effective from July 2009 Ben Bennett, Business Planning & Resources Director Julian Lewis, Governance Manager Date last amended December 2012 Review

More information

Staff Information Governance Manual. All you need to know about Information Governance in one place

Staff Information Governance Manual. All you need to know about Information Governance in one place Staff Information Governance Manual All you need to know about Information Governance in one place CONTENTS Page 1. The roles of the Caldicott Guardian and the Senior Information Risk Owner 1 2. Fair Processing

More information

FTC Data Security Standard

FTC Data Security Standard FTC Data Security Standard The FTC takes the posi6on (Being tested now in li6ga6on) that Sec6on 5 of the FTC Act requires Reasonable Security under the circumstances: that companies have reasonable controls

More information

HIPAA Breaches, Security Risk Analysis, and Audits

HIPAA Breaches, Security Risk Analysis, and Audits HIPAA Breaches, Security Risk Analysis, and Audits Derrick Hill Senior Health IT Advisor Kentucky REC What cons?tutes PHI? HIPAA provides a list of 18 iden?fiers that cons?tute PHI. Any one of these iden?fiers

More information

Human Resources Policy documents. Data Protection Policy

Human Resources Policy documents. Data Protection Policy Policy documents Aims of the Policy apetito is committed to meeting its obligations under data protection law. As a business, apetito handles a range of Personal Data relating to its customers, staff and

More information

Patient Information Whose information is it anyway? Your health records

Patient Information Whose information is it anyway? Your health records Patient Information Whose information is it anyway? Your health records Derriford Hospital Derriford Road Plymouth PL6 8DH Tel: 0845 155 8155 www.plymouthhospitals.nhs.uk Your health record We ask you

More information

HIPAA Privacy Policy (Revised Feb. 4, 2015)

HIPAA Privacy Policy (Revised Feb. 4, 2015) Valley Bone & Joint Clinic HIPAA Privacy Policy (Revised Feb. 4, 2015) 1. PURPOSE Valley Bone & Joint Clinic is commi2ed to protec6ng the rights of our pa6ents. In compliance with the Health Insurance

More information

Information Governance Strategy

Information Governance Strategy Information Governance Strategy To whom this document applies: All Trust staff, including agency and contractors Procedural Documents Approval Committee Issue Date: January 2010 Version 1 Document reference:

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version 1.1 Responsible Person Information Governance Manager Lead Director Head of Corporate Services Consultation Route Information Governance Steering Group Approval Route

More information

Record keeping. Guidance for nurses and midwives

Record keeping. Guidance for nurses and midwives Record keeping Guidance for nurses and midwives 1 We are the nursing and midwifery regulator for England, Wales, Scotland, Northern Ireland and the Islands. We exist to safeguard the health and wellbeing

More information

HIPAA Basics. Health Insurance Portability and Accountability Act of 1996

HIPAA Basics. Health Insurance Portability and Accountability Act of 1996 HIPAA Basics Health Insurance Portability and Accountability Act of 1996 HIPAA: What Is HIPAA? Protects the privacy of healthcare informa@on for all Americans, including the individuals you support Protects

More information

So the security measures you put in place should seek to ensure that:

So the security measures you put in place should seek to ensure that: Guidelines This guideline offers an overview of what the Data Protection Act requires in terms of information security and aims to help you decide how to manage the security of the personal data you hold.

More information

Electronic health records: data protection issues in Europe

Electronic health records: data protection issues in Europe Electronic health records: data protection issues in Europe By Clare Sellars and Dr Amanda Easey IPM&T Group, McDermott Will & Emery UK LLP This article has been published in the April 2008 issue of BNAI

More information

Data Breach Trends October 2015

Data Breach Trends October 2015 Data Breach Trends October 2015 Introduction In October 2015 the Information Commissioner s Office (ICO) published the latest data breach trends including incidents by quarter, type of incident and incidents

More information

Data Protection and Information Security Policy and Procedure

Data Protection and Information Security Policy and Procedure Data Protection and Information Security Policy and Procedure Document Detail Category: Data Protection Authorised By: Full Governing Body Author: School Business Manager Version: 1 Status: Approved May

More information

INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK

INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK Log / Control Sheet Responsible Officer: Chief Finance Officer Clinical Lead: Dr J Parker, Caldicott Guardian Author: Associate IG Specialist, Yorkshire

More information

Data Protection Act 1998 The Data Protection Policy for the Borough Council of King's Lynn & West Norfolk

Data Protection Act 1998 The Data Protection Policy for the Borough Council of King's Lynn & West Norfolk Data Protection Act 1998 The for the Borough Council of King's Lynn & West Norfolk 1 Contents Introduction 3 1. Statement of Intent 4 2. Fair Obtaining I Processing 5 3. Data Uses and Processes 6 4. Data

More information

ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY

ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY ROEHAMPTON UNIVERSITY DATA PROTECTION POLICY Originated by: Data Protection Working Group: November 2008 Impact Assessment: (to be confirmed) Recommended by Senate: 28 January 2009 Approved by Council:

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY DATA PROTECTION POLICY Document Control Information Title Data Protection Policy Version V1.0 Author Diana Watt Date Approved 21 February 2013 Review Date Annually, on the anniversary

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Name of Policy Author: Name of Review/Development Body: Ratification Body: Ruth Drewett Information Governance Steering Group Committee Trust Board : April 2015 Review date:

More information

Data Security and Extranet

Data Security and Extranet Data Security and Extranet Derek Crabtree Schools ICT Support Manager derek.crabtree@merton.gov.uk Target Operating Model 2011 Merton Audit Organisation name: London Borough of Merton Periodic plan date:

More information

DATA PROTECTION IT S EVERYONE S RESPONSIBILITY. An Introductory Guide for Health Service Staff

DATA PROTECTION IT S EVERYONE S RESPONSIBILITY. An Introductory Guide for Health Service Staff DATA PROTECTION IT S EVERYONE S RESPONSIBILITY An Introductory Guide for Health Service Staff 1 Message from Director General Dear Colleagues The safeguarding of and access to personal information has

More information

DATA PROTECTION AND DATA STORAGE POLICY

DATA PROTECTION AND DATA STORAGE POLICY DATA PROTECTION AND DATA STORAGE POLICY 1. Purpose and Scope 1.1 This Data Protection and Data Storage Policy (the Policy ) applies to all personal data collected and dealt with by Centre 404, whether

More information

INFORMATION GOVERNANCE AND SECURITY 1 POLICY DRAFTED BY: INFORMATION GOVERNANCE LEAD 2 ACCOUNTABLE DIRECTOR: SENIOR INFORMATION RISK OWNER

INFORMATION GOVERNANCE AND SECURITY 1 POLICY DRAFTED BY: INFORMATION GOVERNANCE LEAD 2 ACCOUNTABLE DIRECTOR: SENIOR INFORMATION RISK OWNER INFORMATION GOVERNANCE AND SECURITY 1 POLICY DRAFTED BY: INFORMATION GOVERNANCE LEAD 2 ACCOUNTABLE DIRECTOR: SENIOR INFORMATION RISK OWNER 3 APPLIES TO: ALL STAFF 4 COMMITTEE & DATE APPROVED: AUDIT COMMITTEE

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Owner : Head of Information Management Document ID : ICT-PL-0099 Version : 2.0 Date : May 2015 We will on request produce this Policy, or particular parts of it, in other languages

More information

Policy Document Control Page

Policy Document Control Page Policy Document Control Page Title Title: Information Governance Policy Version: 5 Reference Number: CO44 Keywords: Information Governance Supersedes Supersedes: Version 4 Description of Amendment(s):

More information

RD SOP17 Research data management and security

RD SOP17 Research data management and security RD SOP17 Research data management and security Version Number: V2 Name of originator/author: Dr Andy Mee, R&I Manager Name of responsible committee: R&I Committee Name of executive lead: Medical Director

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Reference: Information Governance Policy Date Approved: April 2013 Approving Body: Board of Trustees Implementation Date: April 2013 Version: 6 Supersedes: 5 Stakeholder groups

More information

INFORMATION GOVERNANCE HANDBOOK

INFORMATION GOVERNANCE HANDBOOK INFORMATION GOVERNANCE HANDBOOK Information Governance Handbook_V1.0 1 Information Reader Box Function Purpose Document Purpose Document Name Author Corporate Governance Guidance Procedures Information

More information

How To Share Your Health Records With The National Health Service

How To Share Your Health Records With The National Health Service HOW WE USE YOUR PERSONAL INFORMATION Information Leaflet Your Health. Our Priority. Page 2 of 9 Introduction This Leaflet explains why the NHS collects information about you and how it is used, your right

More information

DATA AND PAYMENT SECURITY PART 1

DATA AND PAYMENT SECURITY PART 1 STAR has teamed up with Prevention of Fraud in Travel (PROFiT) and the Fraud Intelligence Network (FIN) to offer our members the best advice about fraud prevention. We recognise the increasing threat of

More information

Auditing data protection a guide to ICO data protection audits

Auditing data protection a guide to ICO data protection audits Auditing data protection a guide to ICO data protection audits Contents Executive summary 3 1. Audit programme development 5 Audit planning and risk assessment 2. Audit approach 6 Gathering evidence Audit

More information

What NHS staff need to know

What NHS staff need to know St George s Healthcare NHS NHS Trust Surrey Health Informatics Service Sussex Health Informatics Service Records Management Explained What NHS staff need to know A guide to Records Management Contents

More information

Information Governance Management Framework

Information Governance Management Framework Information Governance Management Framework Responsible Officer Author Business Planning & Resources Director Governance Manager Date effective from October 2015 Date last amended October 2015 Review date

More information

Safe Haven Policy. Equality & Diversity Statement:

Safe Haven Policy. Equality & Diversity Statement: Title: Safe Haven Policy Reference No: 010/IT Owner: Deputy Chief Officer Author Information Governance Lead First Issued On: November 2012 Latest Issue Date: March 2015 Operational Date: March 2015 Review

More information

Policy. Social Media Acceptable Use Policy. Executive Lead. Review Date. Low

Policy. Social Media Acceptable Use Policy. Executive Lead. Review Date. Low Policy Social Media Acceptable Use Policy Date approved by - ISG Version Issue Date Review Date Executive Lead 11/6/2013 1.0 11/6/2013 11/6/2015 Mike Robson Executive Director Finance Procedure/Policy

More information

Top Practices in Health IT Compliance. Data Breach & Leading Program Prac3ces

Top Practices in Health IT Compliance. Data Breach & Leading Program Prac3ces Top Practices in Health IT Compliance Data Breach & Leading Program Prac3ces Overview Introduc3on to ID Experts & Secure Digital Solu3ons Healthcare Data Breach Trends & Drivers Data Incident Management

More information

Information Security Adults Services. Practice guidance. Revised Version: 1.2 Effective from: August 2014 Next review date: August 2015

Information Security Adults Services. Practice guidance. Revised Version: 1.2 Effective from: August 2014 Next review date: August 2015 Information Security Adults Services Practice guidance Revised Version: 1.2 Effective from: August 2014 Next review date: August 2015 Sign off: Jenny Daniels Title: Head of Health and Social Care Practice

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Including the Information Governance Strategy Framework and associated Information Governance Procedures Last Review Date Approving Body N/A Governing Body Date of Approval

More information

Scottish Rowing Data Protection Policy

Scottish Rowing Data Protection Policy Revision Approved by the Board August 2010 1. Introduction As individuals, we want to know that personal information about ourselves is handled properly, and we and others have specific rights in this

More information

INTERNATIONAL SOS. Data Protection Policy. Version 1.05

INTERNATIONAL SOS. Data Protection Policy. Version 1.05 INTERNATIONAL SOS Data Protection Policy Document Owner: LCIS Division Document Manager: Group General Counsel Effective: December 2008 Revised: 2015 All copyright in these materials are reserved to AEA

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Title Author Approved By and Date Review Date Mike Pilling Latest Update- Corporation May 2008 1 Aug 2013 DATA PROTECTION ACT 1998 POLICY FOR ALL STAFF AND STUDENTS 1.0 Introduction 1.1 The Data Protection

More information

HERTSMERE BOROUGH COUNCIL

HERTSMERE BOROUGH COUNCIL HERTSMERE BOROUGH COUNCIL DATA PROTECTION POLICY October 2007 1 1. Introduction Hertsmere Borough Council ( the Council ) is fully committed to compliance with the requirements of the Data Protection Act

More information

Information Governance Framework and Strategy. November 2014

Information Governance Framework and Strategy. November 2014 November 2014 Authorship : Committee Approved : Chris Wallace Information Governance Manager CCG Senior Management Team and Joint Trade Union Partnership Forum Approved Date : November 2014 Review Date

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY Reference number Approved by Information Management and Technology Board Date approved 14 th May 2012 Version 1.1 Last revised N/A Review date May 2015 Category Information Assurance Owner Data Protection

More information

Data protection policy

Data protection policy Data protection policy Introduction 1 This document is the data protection policy for the Nursing and Midwifery Council (NMC). 2 The Data Protection Act 1998 (DPA) governs the processing of personal data

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Information Governance Policy Issue Date: June 2014 Document Number: POL_1008 Prepared by: Information Governance Senior Manager Insert heading depending on Insert line heading

More information

The Care Record Guarantee Our Guarantee for NHS Care Records in England

The Care Record Guarantee Our Guarantee for NHS Care Records in England The Care Record Guarantee Our Guarantee for NHS Care Records in England January 2011, version 5 Introduction In the National Health Service in England, we aim to provide you with the highest quality of

More information

RECORDS MANAGEMENT POLICY

RECORDS MANAGEMENT POLICY RECORDS MANAGEMENT POLICY Version 8.0 Purpose: For use by: This document is compliant with /supports compliance with: To outline the lifecycle of a record and to provide guidance on retention and disposal

More information

Data Protection and Community Councils Briefing Note

Data Protection and Community Councils Briefing Note Data Protection and Community Councils Briefing Note This briefing note has been prepared in response to specific queries raised by Community Councils in Marr in relation to their Data Protection requirements.

More information

The Breastfeeding Network. Information Governance Policy

The Breastfeeding Network. Information Governance Policy All correspondence to: The Breastfeeding Network PO Box 11126, Paisley PA2 8YB Tel: 0844 412 0995 e-mail: admin@breastfeedingnetwork.org.uk www.breastfeedingnetwork.org.uk The Breastfeeding Network Information

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY Directorate of Performance Assurance INFORMATION GOVERNANCE POLICY Reference: DCP074 Version: 2.5 This version issued: 27/03/15 Result of last review: Minor changes Date approved by owner (if applicable):

More information

Data Transfer Policy London Borough of Barnet

Data Transfer Policy London Borough of Barnet London Borough of Barnet DATA PROTECTION 11 Document Control Document Description Data Transfer Policy Version v.2 Date Created December 2010 Status Authorisation Name Signature Date Prepared By: IS Checked

More information

CORE SKILLS FRAMEWORK INFORMATION GOVERNANCE LESSON NOTES AND TIPS FOR A SUGGESTED APPROACH

CORE SKILLS FRAMEWORK INFORMATION GOVERNANCE LESSON NOTES AND TIPS FOR A SUGGESTED APPROACH CORE SKILLS FRAMEWORK INFORMATION GOVERNANCE LESSON NOTES AND TIPS FOR A SUGGESTED APPROACH These notes are designed to be used in conjunction with the core training PowerPoint slides. The purpose of the

More information

Data controllers and data processors: what the difference is and what the governance implications are

Data controllers and data processors: what the difference is and what the governance implications are ICO lo : what the difference is and what the governance implications are Data Protection Act Contents Introduction... 3 Overview... 3 Section 1 - What is the difference between a data controller and a

More information

Information Governance Policy

Information Governance Policy Author: Susan Hall, Information Governance Manager Owner: Fiona Jamieson, Assistant Director of Healthcare Governance Publisher: Compliance Unit Date of first issue: February 2005 Version: 5 Date of version

More information

INFORMATION RISK MANAGEMENT POLICY

INFORMATION RISK MANAGEMENT POLICY INFORMATION RISK MANAGEMENT POLICY DOCUMENT CONTROL: Version: 1 Ratified by: Steering Group / Risk Management Sub Group Date ratified: 21 November 2012 Name of originator/author: Manager Name of responsible

More information

How to revalidate with the NMC Requirements for renewing your registration

How to revalidate with the NMC Requirements for renewing your registration How to revalidate with the NMC Requirements for renewing your registration CONTENTS WHAT DOES THIS DOCUMENT DO?...3 WHAT IS REVALIDATION?...5 CHECKLIST OF REQUIREMENTS AND SUPPORTING EVIDENCE... 7 THE

More information

INFORMATION SHARING AGREEMENT. Multi-Disciplinary Team (MDT): Service Information Sharing

INFORMATION SHARING AGREEMENT. Multi-Disciplinary Team (MDT): Service Information Sharing INFORMATION SHARING AGREEMENT Multi-Disciplinary Team (MDT): Service Information Sharing SCOPE NAME OF LEAD Multi-Disciplinary Team (MDT) for high risk people: this agreement is for the patient and management

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Page 1 of 46 Policy Title: Executive Summary: Information Governance Policy This policy seeks to identify the actions required to ensure that information is appropriately

More information

technical factsheet 176

technical factsheet 176 technical factsheet 176 Data Protection CONTENTS 1. Introduction 1 2. Register with the Information Commissioner s Office 1 3. Period protection rights and duties remain effective 2 4. The data protection

More information

Privacy Impact Assessment and Information Governance Checklist

Privacy Impact Assessment and Information Governance Checklist Privacy Impact Assessment and Information Governance Checklist Review and Amendment Log / Control Sheet Responsible Officer: Clinical Chief Officer Clinical Lead: Author: Dr. Dave Mitchell Medical Director/Caldicott

More information

Information Incident Management and Reporting Procedures

Information Incident Management and Reporting Procedures Information Incident Management and Reporting Procedures Compliance with all policies, procedures, protocols, guidelines, guidance and standards is a condition of employment. Breach of policy may result

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Policy Summary This policy outlines the organisation s approach to the management of Information Governance and information handling. It explains the accountability and reporting

More information

Reneaué Railton Sr. Informa2on Security Analyst, Duke Medicine Cyber Defense & Response

Reneaué Railton Sr. Informa2on Security Analyst, Duke Medicine Cyber Defense & Response Reneaué Railton Sr. Informa2on Security Analyst, Duke Medicine Cyber Defense & Response Incident Response What is the most importance component of an Incident Response Program? Tools? Processes? Governance?

More information

Data Transfer Policy. Data Transfer Policy London Borough of Barnet

Data Transfer Policy. Data Transfer Policy London Borough of Barnet Data Transfer Policy Data Transfer Policy London Borough of Barnet Document Control POLICY NAME Data Transfer Policy Document Description Policy surrounding data transfers (electronic and paper based).

More information

Information Incident Management. and Reporting Policy

Information Incident Management. and Reporting Policy Information Incident Management and Reporting Policy Policy ID IG10 Version: 1 Date ratified by Governing Body 21/3/2014 Author South CSU Date issued: 21/3/2014 Last review date: N/A Next review date:

More information

How to complain about a doctor. England

How to complain about a doctor. England How to complain about a doctor England This booklet is for patients in England. Our procedures are the same throughout the UK, but healthcare and support organisations do vary. We have therefore also produced

More information

Burton Hospitals NHS Foundation Trust. On: 16 January 2014. Review Date: December 2015. Corporate / Directorate. Department Responsible for Review:

Burton Hospitals NHS Foundation Trust. On: 16 January 2014. Review Date: December 2015. Corporate / Directorate. Department Responsible for Review: POLICY DOCUMENT Burton Hospitals NHS Foundation Trust INFORMATION SECURITY POLICY Approved by: Executive Management Team On: 16 January 2014 Review Date: December 2015 Corporate / Directorate Clinical

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY ENFIELD CLINICAL COMMISSIONING GROUP INFORMATION GOVERNANCE POLICY PLEASE DESTROY ALL PREVIOUS VERSIONS OF THIS DOCUMENT Enfield CCG Information Governance Policy Information Governance Policy (Policy

More information

Mobility and Young London Annex 4: Sharing Information Securely

Mobility and Young London Annex 4: Sharing Information Securely Young London Matters April 2009 Government Office For London Riverwalk House 157-161 Millbank London SW1P 4RR For further information about Young London Matters contact: younglondonmatters@gol.gsi.gov.uk

More information

Information governance

Information governance Information governance Staff handbook RDaSH 88 02 Information governance Introduction to information governance Overview 88 03 Information governance or IG - includes information security and confidentiality,

More information

Information Governance. and what it means for you

Information Governance. and what it means for you Information Governance and what it means for you 1 Content Introduction 3 Who are we? 4 What is Information Governance? 4 Purpose of Holding Information 5 Confidentiality and Security 5 Accuracy of Information

More information

Encrypted Email Opening and Replying to a Secure Message

Encrypted Email Opening and Replying to a Secure Message First Time User Registration Opening a Secure Encrypted Email Where to go for Help Frequently Asked Questions Information Technology Encrypted Email Opening and Replying to a Secure Message First Time

More information

Originator: Chris Parkin Date: 4 March 2015 Approved by: Senior Management Team Type: Policy. Computer Security Policy

Originator: Chris Parkin Date: 4 March 2015 Approved by: Senior Management Team Type: Policy. Computer Security Policy Originator: Chris Parkin Date: 4 March 2015 Approved by: Senior Management Team Type: Policy Computer Security Policy Contents 1 Scope... 3 2 Governance... 3 3 Physical Security... 3 3.1 Servers... 3 3.2

More information

Reporting of HIPAA Privacy/Security Breaches. The Breach Notification Rule

Reporting of HIPAA Privacy/Security Breaches. The Breach Notification Rule Reporting of HIPAA Privacy/Security Breaches The Breach Notification Rule Objectives What is the HITECH Act? An overview-what is Protected Health Information (PHI) and can I protect patient s PHI? What

More information

How to complain about a doctor

How to complain about a doctor How to complain about a doctor England This booklet is for patients in England. Our procedures are the same throughout the UK, but healthcare and support organisations do vary. We have therefore also produced

More information

Islington Data Protection Policy. A council-wide information policy Version 1.1 June 2014

Islington Data Protection Policy. A council-wide information policy Version 1.1 June 2014 A council-wide information policy Version 1.1 June 2014 Copyright Notification Copyright London Borough of Islington 2014 This document is distributed under the Creative Commons Attribution 2.5 license.

More information

Policy: IG01. Information Governance Incident Reporting Policy. n/a. Date ratified: 16 th April 2014

Policy: IG01. Information Governance Incident Reporting Policy. n/a. Date ratified: 16 th April 2014 Policy: IG01 Information Governance Incident Reporting Policy Version: IG01/01 Ratified by: Trust Management Team Date ratified: 16 th April 2014 Title of Author: Head of Governance Title of responsible

More information

Data Protection Policy. Information Security Review Group. Version Date Author Notes on Revisions

Data Protection Policy. Information Security Review Group. Version Date Author Notes on Revisions Document Control Table Document Title: Author(s) (name, job title and Division): Version Number: Document Status: Date Approved: Approved By: Effective Date: Date of Next Review: Superseded Version: Data

More information

Information Management Handbook for Schools. Information Management Handbook for Schools London Borough of Barnet

Information Management Handbook for Schools. Information Management Handbook for Schools London Borough of Barnet Information Management Handbook for Schools London Borough of Barnet Document Name Document Description Information Management Handbook for Schools This document is intended for use by Barnet Borough Schools.

More information

Caedmon College Whitby

Caedmon College Whitby Caedmon College Whitby Data Protection and Information Security Policy College Governance Status This policy was re-issued in June 2014 and was adopted by the Governing Body on 26 June 2014. It will be

More information

A common sense guide to the Data Protection Act 1998 for volunteers

A common sense guide to the Data Protection Act 1998 for volunteers A common sense guide to the Data Protection Act 1998 for volunteers Why is it necessary? The Data Protection Act 1998 is a law introduced to control the way information held about individuals is handled

More information

Corporate ICT & Data Management. Data Protection Policy

Corporate ICT & Data Management. Data Protection Policy 90 Corporate ICT & Data Management Data Protection Policy Classification: Unclassified Date Created: January 2012 Date Reviewed January Version: 2.0 Author: Owner: Data Protection Policy V2 1 Version Control

More information