Information governance policy and framework
Document control
- Policy owner: Narissa Leyland, Head of information governance and data protection officer
- Corporate lead: Executive director of finance and resources
- Document version: V3
- Document status: Approved
- Date approved by Clinical and Corporate Policies Group (CCPG): 5 November 2018
- Date ratified by SMT: 28 November 2018
- Date issued: 3 November 2018
- Next review date: 28 November 2021
- Policy number: PL301
Executive summary
The NHS is in a state of considerable change, with new legislation and guiding frameworks being implemented in 2018. To ensure this is undertaken effectively for all patients and staff, the trust is implementing this policy, based on Department of Health (DH) guidelines and Data Protection (DP)-related law.
From 25 May 2018 the main piece of legislation is the EU General Data Protection Regulation (GDPR). This has been complemented with domestic legislation, which is the Data Protection Act 2018 (DPA).
This policy sets out the strategic IG agenda for Leeds Community Healthcare Trust. It relies strongly on a risk-based approach to the identification of information assets (IA) and ownership of such IAs by information asset owners (IAO) through a robust information management (IM) programme.
Equality analysis
Leeds Community Healthcare NHS Trust’s vision is to provide the best possible care to every community. In support of the vision, with due regard to the Equality Act 2010 General Duty aims, Equality Analysis has been undertaken on this policy and any outcomes have been considered in the development of this policy.
Table of content
- Introduction
- Definitions
- Aims and objectives
- Responsibilities
- Overarching legislation and principles
- Effective information governance management
- Monitoring compliance and effectiveness
- Training needs
- Approval and ratification process
- Review arrangement
- Associated documents
- References
- Appendices
1. Introduction
Information is a vital asset clinically and for the efficient management of services, resources and performance. It is therefore important that an appropriately robust policy framework is in place. Information governance (IG) stipulates the way in which information, particularly in an NHS environment, how personal confidential data (PCD) should be handled. IG also enables the trust to ensure that all confidential information is dealt with legally, securely and efficiently, in order to deliver the best possible care to its patients.
2. Definitions
Personal confidential data is:
- Personal information about identifiable individuals, which should be kept private.
- The data protection (DP) legislation definition of personal and special categories of data, adapted to include those who have passed away (see next two paragraphs for definitions).
- Information ‘given in confidence’ and ‘that which is owed a duty of confidence’.
Under the new DP legislation personal data is defined as:
“Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”
And special categories of personal data is defined as:
“Racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.”
3. Aims and objectives
To ensure good practice across the trust there are robust IG processes in place to support the successful local implementation of national legislation and guidance:
- An annual IG audit
- Oversight by the healthcare regulator, the Care Quality Commission (CQC)
- A mandatory training and awareness programme
- A staff Confidentiality Code of Conduct, distributed to all staff
- A robust plan to communicate Confidentiality and DP to Data Subjects
- An information asset management (IAM) and business continuity (BC) programme
- An information risk management (IRM) programme
- Data protection impact assessments (DPIA) for new projects and proposals
- Robust information security (IS), cyber security and user access controls
- Safe Haven processes to ensure data is safely transmitted and received
- Systematic records management processes
- Robust IG clauses in third party contracts
- Clarity on the legalities of processing data and the use of consent
- Robust information sharing processes
- Assurance on the transfer of PCD (Personal Confidential Data) outside the UK
- Data quality assurance
- Subject access requests (SAR), allowing subjects to view and check their information
- Clarity on the disclosure of information to the police
- Robust processes for the reporting and analysis of information-related incidents
4. Responsibilities
All staff employed by Leeds Community Healthcare NHS Trust must work in concordance with the Leeds Safeguarding Multi-agency Policies and Procedures and local guidelines in relation to any safeguarding concerns they have for service users and the public with who they are in contact.
Everyone within the trust has a level of IG responsibility:
The trust board: The Board is ultimately responsible for ensuring the IG function is addressed.
Chief executive: The individual with overall accountability for IG within the trust is the accountable officer, the chief executive. The role provides assurance, through a statement of internal controls, that all risks to the organisation, including those relating to information, are effectively managed and mitigated.
Senior information risk owner: The (SIRO) is the director of finance and resources with overall responsibility for the organisation’s information risk management. The SIRO also leads and implements the IG risk assessment and advises the board on the effectiveness of information risk management (IRM) across the organisation.
Caldicott Guardian: The Caldicott Guardian is the medical director, this is an advisory role and has responsibility for protecting the confidentiality of patient information and ensuring it is shared appropriately and securely. The Caldicott Guardian is supported by the trust’s IG team.
Head of information governance and data protection officer: The head of information governance and data protection officer has the leadership function for IG, maintaining the confidence of patients, staff and the public, through advice and guidance on the creation of robust and effective mechanisms and assurance processes to protect and
appropriately handle PCD. This includes ensuring that the trust is fully compliant with all IG-related legislation and that the trust meets statutory and mandatory obligations for IG through development of strategy and implementation of IG policies and procedures.
Information security manager: A role held by the head of information technology, it provides advice on all aspects of information security (IS). Their assessment of IS risks, threats and advice on controls contributes significantly to the effectiveness of the trust’s information security. The role holder is required to hold a formal IS qualification.
Information asset owners (IAOs): The SIRO is supported by IAOs. The role of an IAO is to understand what information is held, how it is used, who has access and why for information systems under their responsibility. Consequently they can understand and address risks to the IAs they own and to provide assurance to the SIRO on their security and use, including the creation of System Level Security Policies. The IG Team support the IAOs in fulfilling their role.
Information governance group (IGG): IGG has representatives from across the trust and is responsible for overseeing the implementation of the information governance policy and framework also the annual IG assessment. The group also reviews and approves IG-related documentation. The group reports to the Audit Committee and through that to the trust board. IGG has a key function to monitor and review IG incident trends and guide overarching remedial action to those trends.
Directors, managers and supervisors: All managers have a responsibility to promote this policy and enable good IG practice within their areas. They must promote that national and local IG standards are upheld within their department and advising all staff of their IS, confidentiality and data quality responsibilities and supporting planned evaluation and audit of IG tasks, and implementing necessary actions. They also have a responsibility to liaise with the IG team where necessary regarding issue and/or incidents of concern.
All staff: Staff have responsibility to abide by their legal, professional ethical and contractual responsibilities for IG related issues, regardless of their position, and whether directly employed or not. They must also comply with the most up-to-date version of this policy and other trust IG policies and procedures, and undertake annual IG
mandatory training.
5. Overarching legislation and principles
A range of components fall under IG as it overlaps clinical governance and is a subset of corporate governance. The National Data Guardian Review on Data Security, Consent and Opt-outs outlines the National Data Security Standards, which the trust must adopt. Local implementation of the National Data Security Standards is supported by compliance with the data security and protection toolkit (DSPT), which replaces the IG toolkit in April 2018.
In its management of PCD, the trust complies with Data Protection Act 2018 and Caldicott Principles. Under the new law, PCD must be processed in line with six principles:
- Fairly, lawfully and transparently
- For specified purposes
- Using the minimum amount necessary
- Accurately
- For only as long as it is needed
- Securely
Individuals (Data Subjects) also have rights under the new legislation to:
- Information about how their information is being processed. The trust addresses this by ensuring a layered approach to informing data subjects how their information is used, including posters, pamphlets and service-level leaflets.
- Access to their personal information
- Rectification when information is wrong. Any request for rectification will be assessed on a case by case basis using the precedent of the trust’s developing experience of the new legislation, along with relevant case law.
- Be forgotten, when it is appropriate. In healthcare, information needs to be retained for care and medicolegal purposes, rendering this right largely exempt. Any request to be forgotten will be assessed on a case by case basis using the precedent of the trust’s developing experience of the new legislation, along with relevant case law.
- Restrict processing. Data subjects may request that the trust hold only sufficient personal data about them, but not process it any further. Any request for restriction of processing will be assessed on a case by case basis using the precedent of the trust’s developing experience of the new legislation, along with relevant case law.
- Data portability. This allows data subjects to obtain and reuse their information across different services. In healthcare there are not expected to be many requests, as much information is available as a SAR. Any request for portability of data will be assessed on a case by case basis using the precedent of the trust’s developing experience of the new legislation, along with relevant case law.
- Object to processing. This allows the data subject to object if they do not believe the use of their information is legitimate. Any request to object will be assessed on a case by case basis using the precedent of the Trust’s developing
experience of the new legislation, along with relevant case law. - Appropriate decision-making. The trust is required to demonstrate that it has a lawful basis to carry out profiling and (or) automated decision-making. This is undertaken by an annual organisation-wide assessment, led by the IG team.
All requests from Data Subjects to exercise their rights must normally be responded to within 1 month (30 days) unless there are extenuating circumstances, in which case there are some rights to extension under the legislation.
In the NHS, the Caldicott Principles are equally as important; when using PCD:
- Justify the purpose(s)
- Don’t use it unless it is absolutely necessary
- Use the minimum necessary
- Access should be on a strict need to know basis
- Everyone with access to it should be aware of their responsibilities
- Comply with the law
- The duty to share information can be as important as the duty to protect patient confidentiality.
6. Effective information governance management
To ensure good practice across the trust there are robust IG processes in place:
Annual information governance audit
From April 2018 the trust’s IG compliance will be measured via an annual self assessment process of compliance against standards set out in the data security and protection toolkit (DSPT). The trust will utilise the tool to assess its IG practice in broadly the same manner as its IG toolkit (IGT), DSPT predecessor, to assess its compliance against national security standards.
Care Quality Commission oversight
CQC, as outlined in Safe Data, Safe Care (2016),5 have powers to inspect the trust’s IG as part of its inspection process. To this end the trust must ensure that robust IG practices are in place. CQC specifically requires that Medical Records are
accurate, fit for purpose, held securely and confidentially.
Mandatory training and awareness
Fundamental to the success of delivering a robust IG agenda across the trust is the development of an IG-aware culture. Training is provided to all staff to promote this ethos. In practical terms, since IGT v13, this means 95% of all staff must be adequately trained.
In addition to formal IG training, a layered approach to awareness is employed, acknowledging a broader understanding of training to encapsulate raising awareness.
Some roles, such as SIRO, Caldicott Guardian, and IAOs are required to undertake regular training to remain current in their role. All decisions on the need for training will be documented in a training needs analysis, which must be ratified by the Information Governance Group (IGG).
Confidentiality Code of Conduct
All staff must be aware of their individual responsibilities for the maintenance of confidentiality, data protection, information security management and data quality.
They are given the tools for this through attending annual mandatory IG training, and all staff receiving a Confidentiality Code of Conduct. All new staff are issued the latter during the trust corporate induction, and all staff are annually directed to it via the information governance staff handbook.
It is made clear in both of these documents that failure to maintain confidentiality may lead to disciplinary action, including dismissal.
Data protection and information security
The IG team jointly maintain an improvement plan with the IT team. This includes actions to ensure that patients and the public are adequately informed about confidentiality and the way their information is used and shared, their rights as Data
Subjects, in particular how they may access their Personal Data and how they may exercise those rights.
Information risk management (IRM)
The trust is committed to making the best use of the information it holds to provide efficient healthcare and services to its patients and the local health economy, while ensuring that adequate safeguards are in place to keep information secure and to protect data subjects’ right to privacy.
The trust recognises that information handling represents a significant corporate risk in that failures to protect information properly or use it appropriately can have a damaging impact on its reputation. Furthermore, failure to protect information adequately can attract the attention of the Information Commissioner’s Office (ICO), which regulates DP and has access to a range of sanctions including significant fines.
IRM complements the Trust’s risk management approach. As part of this, information risks are clearly recognised and the appropriate controls implemented through a Board-approved risk management policy and procedure.
Information risk is intrinsic in all administrative and business activities and all staff must continuously manage it. The trust recognises that the aim of IRM is not to eliminate risk, but to provide the structural means to manage it, by balancing its treatments with anticipated benefits that maybe derived.
The trust acknowledges that IRM is an essential element of broader IG and IS arrangements and is an integral part of good management practice, it should not be seen as an additional requirement.
Records management
The trust is committed to a systematic and planned approach to the management of records within the organisation, from their creation to their ultimate disposal. The trust ensures it controls the quality and quantity of the information that it generates, can maintain that information in an effective manner, and can dispose of the information efficiently and securely when it is no longer required.
Medical records are managed in accordance with the Records Management Code of Practice for Health and Social Care, as set out in the trust’s records management policy and managed by the IG team. To ensure that the trust maintains the highest standards in the quality of its medical records an annual audit of clinical records is undertaken.
Information governance, information security and cyber security incidents
The IG Team must be informed immediately of all IG, IS and Cyber Security incidents. These include, but are not limited to, NHS Digital’s classifications:
- Lost in transit
- Lost or stolen hardware
- Lost or stolen paperwork
- Disclosed in error
- Uploaded to website in error
- Non-secure disposal: Hardware
- Non-secure disposal: Paperwork
- Technical security failing (including, hacking)
- Unauthorised access or disclosure
IG incident reporting is undertaken on the trust’s Datix incident reporting application.
On receiving notification of a potential data security and protection incidents, the IG team must inform the DPO, SIRO, Caldicott Guardian, a senior manager within the respective directorate as soon as practicably possible to seek advice and guidance, as appropriate.
The decision to report externally to the ICO is made in line with NHS Digital’s Guide to the notification of data security and protection incidents, with the ultimate decision being the DPO’s with advice of colleagues in the previous paragraph.
Any reports are made by the IG team, having taken advice from the DPO, SIRO, Caldicott Guardian and (or) a senior manager within the respective department.
7. Monitoring compliance and effectiveness
| Minimum requirement to be monitored and audited | Process for monitoring and audit | Lead for the monitoring and audit process | Frequency of monitoring and auditing | Lead for reviewing results | Lead for developing and reviewing action plan | Lead for monitoring action plan |
|---|---|---|---|---|---|---|
| Compliance with the data security and protection toolkit | Reporting to the IG group | Head of information governance and data protection officer | Quarterly | Director of finance and resources | Head of information governance and data protection officer | IG group |
| Annual information governance audit | Reporting to the audit committee | Head of information governance and data protection officer | Annually | Director of finance and resources | Head of information governance and data protection officer | IG group |
8. Training needs
All staff must adhere to the IG training requirements set out in the trust’s mandatory and statutory training policy.
9. Approval and ratification process
The policy has been approved by the IG group, audit committee and ratified by SMT on behalf of the board.
10. Dissemination and implementation
Dissemination of this policy will be via the clinical and corporate policy group and workforce policies to services and made available to staff via the IG intranet page.
11. Review arrangements
This policy will be reviewed in three years by the author or sooner if there is a local or national requirement then ratified by the audit committee.
12. Associated documents
Key IG policies
The policies and procedures in place to support the IG framework are:
- Confidentiality Code of Conduct
- Records management policy
- FOI procedure
- Data protection policy
- Information rights and subject access request procedure
- Information handling policy
- Network security policy
13. References
- General Data Protection Regulation
- Data Protection Act (2018)
- Access to Health Records Act (1990)
- Computer Misuse Act (1990)
- Environmental Information Regulations (2004)
- Freedom of Information Act (2000)
- Health and Social Care Act (2012)
- Health and Social Care (Safety and Quality) Act (2015)
- Human Rights Act (1998)
- Privacy and Electronic Communications Regulations (2003)
- A Manual for Caldicott Guardians (2017)
- Common Law Duty of Confidentiality
- Care Quality Commission, Safe Data, Safe Care (2016)
- Department of Health, Confidentiality: NHS Code of Practice (2003)
- Information Governance Alliance, Records Management Code of Practice for Health and Social Care (2016)
- Department of Health, Information Security Management Code of Practice (2007)
- Department of Health, Information: To Share or Not to Share (2013) (Caldicott 2)
- Department of Health, Report on the Review of Patient-Identifiable Information (1997) (The Caldicott Report)
- National Data Guardian for Health and Care, Review of Data Security, Consent and Opt-Outs (2016)
- NHS Digital, Code of Practice on Confidential Information (2014)