NHS Business Services Authority Information Governance Policy NHS Business Services Authority Corporate Secretariat NHSBSAIGM002
Issue Sheet Document reference NHSBSAIGM002 Document location F:\CEO\IGM\Info Gov Mgt\BSA Title NHS Business Services Authority Information Governance Policy Author Gordon Wanless Issued to All NHSBSA staff Why issued For information / action Last Reviewed 3 November 2010 Revision Details Version Date Amended by Approved by Details of amendments Initial Release 31.05.2007 - IGSG The third last bullet point in 3.1.1 to include reference to EIR and PSI. Amend affordable in the last bullet point in 3.1.1 to be cost-effective. The fourth bullet point in 3.1.2 to include reference to EIR and PSI. Add within cost and resource restraints at the end of the third bullet point in 3.1.4. Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 2 of 13
Contents Page 1 Introduction 4 2 Policy Statement 5 3 Principles 5 4 Scope of this Policy 7 5 Policy 8 6 Information Governance Responsibilities 9 7 Validity of this Policy 10 Appendix A 11 IGMS Graphical Representation 12 IG Documentation & Materials Overview 13 Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 3 of 13
1 Introduction 1.1 The information held by the NHS Business Services Authority (NHSBSA) represents one of our most valuable assets. Without that information the NHSBSA could not operate. It is therefore essential that all information and information systems at the NHSBSA's sites are protected against the many threats which may affect confidentiality and overall service provision. Such threats can range from accidental damage to deliberate disclosure of sensitive information. 1.2 Information security is the responsibility of every member of staff in the NHSBSA. The information systems currently in use employ technical processes to help in maintaining the confidentiality, integrity and availability of the information they hold. However these security measures can be weakened through careless actions such as writing down or sharing a password. 1.3 The scope of this Information Governance (IG) Policy is to support the protection, control and management of NHSBSA s information assets. The policy is concerned with all information systems, electronic and non-electronic, and will apply to all divisions, sites and departments in the NHSBSA, to all NHSBSA staff and as appropriate to its contractors and third party service providers. It will cover all information within the NHSBSA, which could include data and information that is: Stored on computers Transmitted across internal and public networks such as email or Intranet/Internet Stored within databases Printed or hand written on paper, white boards etc. Sent by facsimile (fax), telex or other communications method Stored on removable media such as CD-ROMs, hard disks, tapes and other similar media Stored on fixed media such as hard disks and sub-systems Held on film or microfiche Presented on slides, overhead projectors, using visual and audio media Spoken during telephone calls and meetings or conveyed by any other method Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 4 of 13
1.4 The NHSBSA is committed to properly protecting the information that it holds. This policy and associated practices and procedures have been agreed by the NHSBSA Leadership Team and Senior Management of the Authority. 2. Policy Statement 2.1 This document defines the IG Policy for the NHSBSA. 2.2 The IG Policy applies to all information obtained and processed by the NHSBSA and the NHSBSA s employees. 2.3 This document: Sets out the NHSBSA s policy for the protection of all information obtained and processed Establishes the responsibilities for IG 3 Principles 3.1 There are four key, interlinked, strands to this policy: Openness Legal Compliance Information Security Quality Assurance 3.1.1 Openness The NHSBSA recognises the need for an appropriate balance between openness and confidentiality in the management and use of information Information will be defined and where appropriate kept confidential, underpinning the principles of Caldicott and the regulations outlined in the Data Protection Act 1998 (DPA). Non-confidential information about the NHSBSA and services will be available to the public through a variety of means, one of which will be the provisions of the Freedom of Information Act 2000 (FOIA) There will be clear procedures and arrangements for handling queries from members of the public The NHSBSA will have clear procedures and arrangements for liaison with the press and broadcasting media Integrity of information will be developed, monitored and maintained to ensure that it is appropriate for the purposes intended Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 5 of 13
Availability of information for operational purposes will be maintained within set parameters relating to its importance via appropriate procedures and computer system resilience The NHSBSA regards all identifiable personal information relating to members of the public as confidential, compliance with legal and regulatory framework will be achieved, monitored and maintained The NHSBSA regards all identifiable personal information relating to staff as confidential except where national policy on accountability and openness requires otherwise The NHSBSA will establish and maintain policies and procedures to ensure compliance with the DPA, Human Rights Act 1998 (HRA), the common law duty of confidentiality, Environmental Information regulations 2004 (EIR), the Re-use of Public Sector Information regulations 2005 (PSI) and the FOIA Awareness and understanding of all staff, with regard to their responsibilities, will be routinely assessed, recorded and appropriate training and awareness provided Risk assessment, in conjunction with overall priority planning of NHSBSA activity will be undertaken to determine appropriate, cost-effective IG controls are in place 3.1.2 Legal Compliance The NHSBSA regards all identifiable personal information relating to members of the public as confidential The NHSBSA will undertake or commission annual assessments and audits of its compliance against legal requirements The NHSBSA regards all identifiable personal information relating to staff as confidential except where national policy on accountability and openness requires otherwise The NHSBSA will establish and maintain policies and procedures to ensure compliance with the DPA, HRA, the common law duty of confidentiality, EIR, PSI and the FOIA The NHSBSA will establish and maintain policies for the controlled and appropriate sharing of patient identifiable information with other agencies, taking account of relevant legislation (e.g. Health and Social Care Act, Crime and Disorder Act, Protection of Children Act) 3.1.3 Information Security The NHSBSA will establish and maintain policies for the effective and secure management of its information assets and resources Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 6 of 13
Audits will be undertaken or commissioned to assess information and IT security arrangements The NHSBSA s Incident Reporting system will be used to report, monitor and investigate all breaches of confidentiality and security 3.1.4 Information Quality Assurance The NHSBSA will establish and maintain policies for information quality assurance and the effective management of records Audits will be undertaken or commissioned of the NHSBSA s quality of data and records management arrangements Managers will be expected to take ownership of, and seek to improve, the quality of data within their services within cost and resource restraints Wherever possible, information quality will be assured at the point of collection The NHSBSA will promote data quality through policies, procedures/user manual and training 3.2 This policy and any associated procedures will be reviewed periodically by the NHSBSA Leadership Team. Where review is necessary due to legislative change this will happen immediately. 3.3 In accordance with the Authority's Equal Opportunities policy, this policy will not discriminate, either directly or indirectly, on the grounds of gender, race, colour, ethnic or national origin, sexual orientation, marital status, religion or belief, age, union membership, disability, offending background or any other personal characteristic. 4 Scope of this Policy 4.1 This policy covers all forms of information held by the NHSBSA, including (but not limited to): Information about members of the public Non NHSBSA employees on NHSBSA premises Staff and Personnel information Organisational, business and operational information Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 7 of 13
4.2 This policy applies to all aspects of information handling, including (but not limited to): Structured record systems - paper and electronic Information recording and processing systems whether paper, electronic, video or audio records Information transmission systems, such as fax, e-mail, portable media, post and telephone 4.3 This policy covers all information systems purchased, developed and managed by / or on behalf of, the NHSBSA and any individual directly employed or otherwise by the NHSBSA. 5 Policy 5.1 IG is the function of Corporate Governance that ensures the Confidentiality, Integrity and Availability of the NHSBSA s information assets. It is concerned with the facilitation of delivering accurate contextual information to those who require it for a recognised purpose, whether they be manager, administrator, supporting staff, service user or a member of the public, whilst complying with the legal and regulatory framework. 5.2 An Information Governance Management System (IGMS), including associated policies, procedures, protocols and guidelines and the ongoing monitoring thereof, ensures that the risks to such information assets are identified, assessed and adequately controlled in compliance with: The current legislative framework Applicable NHS codes of practice and regulations Recognised best practice for information handling and information security Information Governance Toolkit requirements 5.3 Developing an overall IGMS will include: The definition of an IG Policy and Strategy The identification (audit) of all existing information assets and the documentation thereof in a suitable Information Asset Register Completion of a formal Risk Assessment, identify threats and vulnerabilities to assets and systems and the potential associated impacts on delivery that each risk eventually would cause Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 8 of 13
Assessment, costing, selection and implementation of appropriate controls, and the developing of procedure and process-related documentation Production of a Statement of Applicability (SOA) and the final combining of documentation to allow, if desired, formal accreditation to the adopted standard of Information Security (ISO/IEC 27001:2005 (formerly BS 7799-2:2002)) The ongoing monitoring of the effects of the IGMS and SOA and the review of controls accordingly Management of the IG Toolkit 6 Information Governance Responsibilities 6.1 It is the role of the NHSBSA Leadership Team to define the NHSBSA s policy in respect of IG, taking into account legal and NHS requirements. The NHSBSA Leadership Team is also responsible for ensuring that sufficient resources are provided to support the requirements of the policy. 6.2 The NHSBSA Leadership Team members, whilst retaining their legal responsibilities, have delegated IG compliance to the NHSBSA Information Governance and Security Group (IGSG). 6.3 The IGSG is responsible for overseeing day to day IG issues; developing and maintaining policies, standards, procedures and guidance, coordinating IG in the NHSBSA and raising awareness of IG. 6.4 Managers within the NHSBSA are responsible for ensuring that this policy and its supporting standards and guidelines are built into local processes and that there is on-going compliance. 6.5 All staff, whether permanent, temporary or contracted, and contractors are responsible for ensuring that they are aware of the requirements incumbent upon them and for ensuring that they comply with these on a day to day basis. 7 Validity of this Policy 7.1 This policy is designed to avoid discrimination and be in accordance with the HRA and its underlying principles. 7.2 This policy should be reviewed annually under the authority of the NHSBSA Leadership Team members. Associated IG Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 9 of 13
standards should be subject to an ongoing development and review programme. Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 10 of 13
Appendix A IGMS Graphical Representation IG Documentation & Materials Overview Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 11 of 13
Information Governance Management System Information Governance Management System Data Protection Freedom of Inform ation Inform ation Security Business Continuity Records Management Inform ation Governance Policy Procedure Policy Procedure Policy Procedure Policy Policy Records Register Policy Strategy Procedure Subject Access Requests Requests for Inform ation E-mail Disclaimer Inform ation Governance Confidentiality Code of Practice Internal Review Incident Reporting Acceptable Use (inc. M onitoring) Policy Asset Register
Information Governance Documentation & Materials Overview Policy Information Governance Management System (Consists of policies on Data Protection, Freedom of Information, Acceptable Use, Information Security, Business Continuity, Records Management & Information Governance) The IG management system sets high level direction and required standards across the Authority. This is supported where necessary by procedures and specific guidance documents, where the required controls are explained in detail. Procedure & Guidance Data Protection Procedure Freedom of Information Procedure E-mail Guidance Document Internet Guidance Document Records Register Responsibilities and key awareness messages for all staff are contained in the IGMS and guidance documents, but also in two key documents that have been written specifically to be accessible to all staff as detailed below: Awareness All Staff Confidentiality Code of Practice Summary Leaflet Acceptable Use Staff Agreement In addition to the Code of Practice leaflet and the Acceptable Use Staff Agreement, a reference pack of guidance will be available online. Reference Available to all Information handling reference pack Includes awareness materials for staff and public, guidance on providing access to patient type records (patients, relatives, children, deceased & solicitors). Information sharing documentation (Police, research, children). Freedom of Information process documentation. Communication guidance (fax, phone etc.) This pack will be updated regularly Computer based materials Screen saver, Acceptable use challenge, DP/FOI/IS Awareness Training. Meeting\NHSBSAIGM002 - NHSBSA Information Governance Policy.doc Page 13 of 13