Information Governance Peter Mc Kenzie Information Governance Manager

  • Slides: 12
Download presentation
Information Governance Peter Mc. Kenzie Information Governance Manager NHS Tayside informationgovernance. tayside@nhs. net

Information Governance Peter Mc. Kenzie Information Governance Manager NHS Tayside informationgovernance. tayside@nhs. net

Caldicott Approval The Caldicott Guardian has a responsibility to review and monitor all flows

Caldicott Approval The Caldicott Guardian has a responsibility to review and monitor all flows of information in NHS Tayside and all transfers of data outside of the organisation. Approval must be sought when creating an information sharing protocol to share patient identifiable information (PII) with another organisation proposals for research projects that will use PII collecting PII for the purposes of creating a new database

Caldicott Coverage Out of Hours and Direct Calls Inpatient Lab. Services Out Patients Pharmacy

Caldicott Coverage Out of Hours and Direct Calls Inpatient Lab. Services Out Patients Pharmacy Online Services Boards Visited at home Dentist A&E Walk-in centre GP/practice nurse Health Care Guides

Caldicott Approval – to cover… research where data is used for any living patient

Caldicott Approval – to cover… research where data is used for any living patient (this also includes images, videos, charts etc). all use of NHS patient data even if you consider the data being held to be non-identifiable data. it is the responsibility of the Caldicott Guardian to review the use of all data and determine if it is appropriately anonymised to ensure that this it nonidentifiable. if identifiable data is to be used then you must be able to justify the requirement for use of this data. all databases created for the purposes of research to hold patient identifiable data must also be registered for data protection purposes

Caldicott Principles Justify the purpose for using person identifiable information (PII) Only use PII

Caldicott Principles Justify the purpose for using person identifiable information (PII) Only use PII when absolutely necessary Use only the minimum PII required Access is on a strict “need to know” basis Everyone must be aware of their responsibilities You must comply with the law

DP 1 Fair & Lawful DP 2 Specific Purposes DP 3 Adequate, Relevant and

DP 1 Fair & Lawful DP 2 Specific Purposes DP 3 Adequate, Relevant and Not Excessive DP 4 Accurate DP 5 Retention DP 6 Individual' s Rights DP 7 Held & Used Securely Caldicott Principles and Data Protection C 1 Justify the Purpose C 2 Necessary DP 8 Safe Non. EEA Transfers C 3 Minimum C 4 “Need to Know” C 5 Responsib ilities C 6 Comply with Law

Caldicott Requirements The Caldicott Guardian has to ensure that proposals comply with Caldicott Principles

Caldicott Requirements The Caldicott Guardian has to ensure that proposals comply with Caldicott Principles and that the technical and operational arrangements that are proposed will safeguard the information to be provided: the justification for using PII? – linkage, other data sets what that data is? – data items physical or electronic where you will get the data from? – collected, manually or electronically extracted is data to be collected from more than one source?

Caldicott Requirements how you will get that data? – encrypted transfer, email who will

Caldicott Requirements how you will get that data? – encrypted transfer, email who will provide you with the data? – an authorised administrator, self, colleague, service who will have access to the data? – co-users, data entry, processors how you intend to protect the data given to you? – anonymisation, encryption, retention if individuals are to be contacted who will do that and how will that be done? – GP, responsible medical officer, researcher

Caldicott Arrangements - HIC NHS Tayside Systems Central Vision TOPAS Mi. Di. S NHS

Caldicott Arrangements - HIC NHS Tayside Systems Central Vision TOPAS Mi. Di. S NHS Generic Caldicott Approval Request for Anonymous Data Health Informatics Centre Researcher Request for Identifiable Data If the study is limited to: a) using electronic data already held within, or accessed via HIC and will be undertaken using anonymised data or b) also includes data collected directly from a patient who has explicitly consented to its use for this research and it is anonymously linked to other electronic data held within, or accessed via, HIC …the study will not require explicit Caldicott Guardian approval. The researcher will have no access to any identifiable data. Caldicott Approval Researcher Any request for identifiable data will require specific Caldicott approval.

Caldicott Arrangements - Clinical Systems Live NHS Tayside System e. g. Central Vision Where

Caldicott Arrangements - Clinical Systems Live NHS Tayside System e. g. Central Vision Where a study relies on electronic data already held in an NHS Tayside clinical information system then Caldicott Guardian approval is required. System Administrator Access to systems requires the identification of the person accessing data to be recorded by means of a transaction log. Such logs are essential evidence of legitimate (in this case approved) access and form part of the person’s personal data. These records will be disclosed as part of any subject access request and any investigation of activity around patient’s records. Request for Identifiable or Anonymous Data Caldicott Approval Researcher The researcher will normally have no access to any identifiable data unless specific approval has been given.

Caldicott Approval is concerned with: controlling access to patient identifiable information ensuring that adequate

Caldicott Approval is concerned with: controlling access to patient identifiable information ensuring that adequate operational data handling arrangements are in place that clearly establish responsibilities ensuring that adequate technical data handling arrangements are in place to safeguard the data maintaining the trust and reassurance of patients in our handling of their personal data

Information Governance Peter Mc. Kenzie Information Governance Manager NHS Tayside informationgovernance. tayside@nhs. net

Information Governance Peter Mc. Kenzie Information Governance Manager NHS Tayside informationgovernance. tayside@nhs. net