JOB DESCRIPTION POST TITLE: Information Governance Manager DIRECTORATE: ACCOUNTABLE TO: BAND: LOCATION: CSS Head of Information Governance 8a CSS Job Purpose The Information Governance Manager will ensure that the constituent Clinical Commissioning Group Customers of the CSS have a managed and co-ordinated approach to the implementation of Information Governance initiatives and are compliant through the transition to the new NHS architecture with law and best practice on information governance. The Information Governance manager will provide specialised knowledge to senior management and staff, and clear guidance and performance assessment to ensure that the organization meets its meets both its statutory and legal obligations. The post holder will work closely with the commissioners, including Clinical Commissioning Groups to develop robust information governance systems and processes that meet statutory and NHS requirements in particular in regards to Access rights and records management. Key Relationships: Cluster Head of IG, SIRO, Caldicott Guardian, Cluster Directors, Senior Managers and managers, CCGs, Independent contractors and their staff, Information Commissioners Office, Solicitors, police, social services and other relevant organisations in relation to sharing of information.
Main Duties and Responsibilities: Strategic Context Information Governance is a standards-based approach to improving the way in which NHS organisations manage information. The post holder will take the Strategic lead & operational lead for: Information Governance Management Data Protection Freedom of Information Confidentiality Records Management Information Governance Training Connecting for Health (IG) Information Governance Management To lead and co-ordinate an Information Governance continuous improvement work programme within the Cluster in relation to; o Code of Confidentiality (Caldicott, Data Protection, Access to Health Records) o Records Management (Corporate Information Assurance) o Information Security Assurance (BS7799 / ISO17799) o Freedom of Information o Communications, Training and Awareness To identify, manage, co-ordinate and deliver projects as required to ensure the efficient and effective implementation of information governance. To develop and implement Cluster wide Information Governance Strategy and policies to support the information governance framework requirements. To ensure that Information Governance initiatives are integrated into the core business functions and plans for the Cluster. To lead the continuous improvement and monitor the quality and use of information within the Cluster PCTs and providers Lead the development and implementation of policies and procedures to support the delivery of Information Governance. Lead the development and delivery of training and awareness programmes to support Information Governance Maintenance of appropriate evidence base for Information Governance Toolkit
To lead and manage the Cluster annual assessment, work programme and action plans in line with the requirements of the NHS Information Governance Toolkit and update as required Submit information governance returns to DOH, SHA ensuring accuracy and timely submission to meet mandatory deadlines Preparation of reports to the Cluster Information Governance Steering Group on a regular basis, providing updates on progress. To represent the cluster at local, regional and national information governance related meetings. To develop and monitor indicators to measure local performance. To maintain the organisations notification with the Information Commissioner (Registration under the Data Protection Act) Dissemination of the information and policies to all staff ensuring they are aware of standards which need to be adhered to and to ensure the monitoring for compliance occurs and to keep up to date on information governance aspects To provide specialist advice and technical support in relation to information governance in the requirements/implications of new systems, products and services. Data Protection To be responsible for compliance with the Data Protection Act. To provide specialist advice and guidance on the Data Protection issues for all new projects that deal with the use of confidential information To provide advice and guidance to the Cluster, GPs, pharmacists and dentists on any new developments and legislative changes in relation to Data Protection. Lead the development and delivery of training and awareness programmes to support Data Protection within the Trust, and to GPs, pharmacists and dentists Freedom of Information To support the Corporate Services team and IG senior Officer to ensure CSU and Customer compliance with the Freedom of Information Act To support the Corporate Services team and IG Officers in raising awareness of the Freedom of Information agenda within the Trust.
To provide expert advice and guidance in line with legislation and ethics of decisions under information law, including Freedom of Information and its associated code of conducts and keep up to date with new developments including legal requirements within Freedom of Information Caldicott / Confidentiality Code of Practice To manage, with the Caldicott Guardian, the implementation of policies and procedures to ensure that the Cluster progresses towards compliance with the Caldicott requirements and the Confidentiality Code of Practice. To work closely with the Caldicott Guardian in promoting the safe use of patient information and the production of returns as necessary and to ensure that information and records management strategies and polices are in line with current guidance and legislation. To provide expert advice based upon the legislation and ethics of information related decisions in relation to confidentiality and deal with Caldicott enquiries. To lead, develop and implement a programme to ensure all staff within the Cluster are aware of Confidentiality. Serious Incident Reporting Support Officer To work with the SIRO to develop the Information Risk Management policy, and strategy for implementing the policy within the existing Information Governance framework. Take ownership of risk assessment process for information risk, including review of the annual information risk assessment to support and inform the Statement of Internal Control. Ensure that the Information Governance Steering Group are kept up to date on all information risk issues. Review and agree action in respect of identified information risks. Provide a focal point for the resolution and/or discussion of information risk issues. Ensure that identified information security threats are followed up and incidents managed To ensure that there are effective mechanisms in place for reporting and managing Serious Untoward Incidents relating to Information occurring within the Cluster and disseminating lessons learnt.
Information Security, BS7799 & ISO17799 To coordinate specialist advice on information security from internal and external advisors and coordinate this throughout the organisation in accordance with ISO27001 To develop and maintain the information security management programme. To assist with the security documentation process to make progress auditable and ensure the management of change. To carry out initial information assets risk assessment. To assist in the development, develop and implement a programme to ensure all staff with the Cluster are aware of Information Security Information Quality Assurance To be the Strategic lead on Information quality assurance in respect of IG for the Cluster Work with the Cluster Business Intelligence team and other IT & Records staff to provide and receive feedback which enable the proactive identification of local issues and areas of risk that impact on data quality, implementing preventive measures and taking remedial action as necessary To provide advice and assistance, implementation, monitoring and review of Information Quality Assurance standards, policies and procedures in line with national and local requirements in respect of IG. To provide advice and assistance for the continual development of the Cluster data quality program in line with changing NHS policy and guidance and local requirements in respect of IG Work with IM&T staff to ensure data quality issues of IG are addressed as part of the implementation of the National Programme for IT. To assist and advise in raising the profile of Data Quality Management in the Cluster ensuring that the Cluster Board and senior management are kept up to date of issues and risks as a key component of Information Governance and Information Quality Assurance and to keep up to date with new developments within information quality assurance To lead, develop and implement a programme to ensure all staff with the Cluster are aware of information quality assurance
Records Management To be the Strategic lead on records management (health and corporate records) for the Cluster To provide guidance and advice on records management issues to all Cluster staff To be the lead for developing and implementing information sharing arrangements and protocols with partner organisations. To ensure that all new developments (with particular relevance to Connecting for Health) meet all Information, Records and Data Management arrangements. To implement the NHS Records Management Code of Conduct and related road map in the Cluster To ensure that core standards in the creation, use and storage of records are implemented in the Cluster To monitor and audit records management for the Cluster Privacy Officer To ensure privacy alerts in relation to Summary Care Records access are reviewed and investigate inappropriate accesses Specific Programme Accountabilities: DoH IG Assurance Programme QIPP Programme Planning and Organising As per key duties & responsibilities Service Delivery and Improvement BAU (Business as usual) Service Delivery IG Specific Projects Information Risk & Security, Confidentiality, Information Quality/ Records Management Internal and External Relationships (See key relationships above) Management of People Responsible for the line management of Cluster IG officer, see organisation chart
Flexibility This job description is intended to provide a broad outline of the main responsibilities only. The post holder is required to be flexible in developing their role in agreement with the Head of IG. In addition, they may be required by to carry out any other duty commensurate with role and expertise. Performance Management All employees have a responsibility to participate in regular appraisal with their manager and to identify performance standards of the post. As part of the appraisal process every employee is responsible for participating in identifying their own training and development needs to meet their KSF outline. Health and Safety Employees must be aware of the responsibilities place on them under Health and Safety at Work Act 1974, and take reasonable care for the health and safety of themselves and of other people who may be affected by their acts or omissions at work. Equality and Diversity The Cluster is committed to building an environment where the diversity of its employees is valued, respected and seen as an asset to enabling delivery of the best possible healthcare services to our communities. It is unlawful to discriminate directly or indirectly in recruitment or employment because of any of the nine protected characteristics contained in the Equality Act 2010. These are age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation. Failure to comply with organisational policies on equality and diversity may result in disciplinary action Infection Prevention and Control The Cluster is committed to reducing Healthcare Associated Infection. All employees are expected to abide by Infection Prevention and Control policies relevant to their area of work, and undertake the necessary level of training. This will be appraised through the KSF review process or other relevant professional review process. Smoking The Cluster actively discourages smoking, and all employees are expected to observe the No Smoking policy; smoking is not permitted on its premises or grounds. Mobility Whilst the post holder will be based at one of the buildings within the Cluster area, you will be expected to travel within that area. All employees may be required to work at an alternative location within the Cluster to meet the needs of the service.
Confidentiality Your attention is drawn to the confidential nature of information collected within the National Health Service. The unauthorised use or disclosures of patient or other personal information is regarded as gross misconduct and will be subject to disciplinary procedures, and could result in a prosecution for an offence or action for civil damages under the Data Protection Act 1998. Safeguarding It is the responsibility of every member of staff to safeguard and protect vulnerable adults, children and young people from abuse. All staff are expected to undertake mandatory training relevant to the role. All staff should familiarise themselves with organisational safeguarding policies. Postholder Signature: Date:
CSS PERSON SPECIFICATION Post Information Governance Manager Grade 8a Example key areas Job requirements How identified Qualifications/Training Level of education; Professional qualifications; Vocational training; Post basic qualifications; Training and learning programmes/courses Essential Educated to degree level or have the relevant professional experience Committed to ongoing specialist training to support job role and develop self Positive attitude towards learning and development of self and others through continuing professional development A/C/I Records Management qualification or relevant professional experience Experience Length and type of experience Level at which Data Protection qualification or relevant professional experience Desirable Specialist qualifications in ICT and/or Information Governance Essential Substantial practical/ operational experience in developing and implementing information governance strategies, policies and management procedures A/I
experience gained Experience of writing organisation wide strategies, policies, procedures and training material Skills/Knowledge Range and level of skills Depth and extent of knowledge Experience of writing and presenting reports to senior management Extensive knowledge of the legislative requirements of the Data Protection Act and other information law how to apply them to the Cluster Experience in the investigation and management of incidents and root cause analysis Experience in information risk assessment and management Desirable Experience and understanding of complex information governance issues Experience of planning and implementing organisational culture change to support the Information Governance agenda.essential Extensive knowledge of the NHS Information Governance agenda and Information Governance toolkit Knowledge of current issues in information governance in a healthcare setting A/I Thorough understanding of NHS and statutory policies and regulations including Data Protection Act, Freedom of Information Act, Caldicott and IG related NHS Codes of Practice. Desirable
Personal Qualities Other Job Requirements Broad ICT knowledge and an understanding of computer and confidentiality related legislation and professional standards Knowledge of the ISO27001 information security standard and its application within the Cluster Excellent verbal and written communication skills, and the ability to communicate effectively at all levels Interpersonal skills, to lead, influence and motivate staff at all levels Strong analytical skills- ability to identify problems and develop solutions Attention to detail combined with the ability to think laterally and problem solve, pre-empting and dealing with situations to prevent any adverse issues for the Cluster. Confident, enthusiastic and self motivated, able to work independently and as part of a team Able to work under pressure and manage priorities and workload appropriately Ability to work to specified and often demanding timescales A/I/R