Information Governance: The Refresher Module (Revision and Update)

Size: px
Start display at page:

Download "Information Governance: The Refresher Module (Revision and Update)"

Transcription

1 Information Governance: The Refresher Module (Revision and Update) Introduction This is a printable copy of the Training Tracker e-learning refresher module on Information Governance. This is aimed at all staff who have completed one of the modules listed below: Information Governance - The Beginner s Guide. Introduction to Information Governance. Introduction to IG for General Practice. Information Governance for NHS CFH Staff. Information Governance for Pharmacy Staff. Information Governance for Dental Practices. Information Governance for Medical Secretaries. If you have not completed one of these modules you should do so and leave this refresher module for the following year. The refresher module should be completed every year to keep you updated with Information Governance best practice and to satisfy any requirements to undertake mandatory IG training annually. The purpose of the refresher module is to: update you on changes that have taken place since the original modules were created revise some key learning points from the original modules Indicate any topics which you need to fully review again (by completing whichever of the original modules mentioned above is appropriate for you). Navigation point The material in the course covers a number of important points. As you go through the course the topic heading will tell you whether it is revision or an update. 1

2 The areas covered are:. NHS IG Standards Confidentiality Care Record Guarantees and the NHS Constitution UK Law Data Protection Act 1998 UK Law Freedom of Information Act 2000 Records Management and Quality Records Security NHS IG Standards (Revision) After serious losses of personal information, including the loss in 2007 of computer disks containing the names, addresses and bank details of 25 million child benefit claimants, the Government conducted a Data Handling Review (June 2008). This sets out mandatory measures for public bodies on protecting personal data such as staff training and committed the Government to publicly reporting progress on putting these measures into place. In the next section we ll look at the progress of this review. NHS IG Standards (Update) The first progress report of the UK Government s Data Handling Review was published in January 2010 and noted the NHS progress in improving the following standards of information handling: Performance management to push improvements. Contracts with organisations being renegotiated to make sure confidentiality and security protections are in place. Older computer systems being replaced with modern systems that have state of the art security. Nearly one million encryption licences were in use under a nationally negotiated contract. Encryption had been mandated for all patient data held on portable devices (e.g. memory sticks, laptops). Online training was available to over one million staff (e.g. this module). 2

3 The information governance framework and guidance had been further developed so that NHS organisations were clear about expected standards. The NHS Operating Framework (Update) The Department of Health (DH) published an Operating Framework which set out objectives for the NHS. 2010/11 key themes included: Organisations must meet all Information Governance requirements set out by DH by 31st March 2011 (the level of compliance is then reported to DH and Care Quality Commission) Ensuring that all staff receive annual basic IG training (through the online NHS IG Training Tool) Reporting on the management of information risks Publishing security breaches in annual reports. A link to further reading is available in Read more about it at the end of this workbook. Confidentiality (Revision) It is important to understand what is meant by confidential information. Personal Information Information about an individual is personal information when it enables an individual to be identified. It is non-personal when it doesn t. This isn t always straightforward, e.g. a person s name and address are clearly personal information when presented together, but an unusual surname may itself enable someone to be identified. This is an important distinction in law. Sensitive Personal Information Personal information is legally classed as sensitive when it makes reference to particular matters of an identifiable person, such as his / her health, ethnicity, religion, criminal record or sexual life. These are also listed in the Data Protection Act

4 Other details, e.g. a person s bank account details, DNA or finger prints are not listed in the Data Protection Act 1998 but are still regarded as sensitive because of the damage and distress that could be caused if they were not properly protected. The rules set out in the Data Protection Act only apply to information about living individuals not the deceased. This differs to the common law duty of confidentiality which continues after the death of the patient. Confidential Information Health and Staff Information Personal and sensitive personal information is classed as confidential if it was provided in circumstances where an individual could reasonably expect that it would be held in confidence, e.g. a healthcare professional and patient. This applies to staff working on behalf of the health professional such as pharmacy / dental and eye care staff. Confidentiality is accepted to extend after the death of the patient. Personal or Sensitive Personal CAN be Confidential Information Whether it is confidential or not depends on the circumstances under which it was provided. If it is: private information about a person and given to someone who has a duty of confidence and expected to be used in confidence then it is confidential. 4

5 Confidentiality Disclosing information (Revision) Confidential information should not normally be used (which includes sharing and disclosing) unless one of the following criteria are met. 1. The person has given consent for the disclosure. For patients: Consent may be implied for care purposes and related purposes that support or check the quality of care provided. For other purposes consent should be specifically sought. 2. There is a legal basis which permits or requires disclosure of confidential information. 3. There are exceptional circumstances (e.g. investigation or prevention of serious crime) where the overriding public interest outweighs the duty of confidentiality. Confidentiality Patient Welfare (Revision) The duty of confidence does not prevent adequate welfare arrangements being made with, for example, a patient s partner, carer, friend or support agency, as long as the patient is happy for this to happen. It is sensible to check with the patient if there is any doubt what the patient s expectations and wishes are. Detailed guidance is available Confidentiality: NHS Code of Practice. This can be found in the Read more about it section on the menu. Confidentiality Caldicott Guardian/IG Lead (Revision) In 1997 a review was carried out into the use of patient identifiable information in the NHS. This was carried out because there were concerns about how patient information was being handled and transferred. Dame Fiona Caldicott chaired the Caldicott Review. The report set out principles and recommendations for the security of patient information. An important recommendation was that a senior clinician should be nominated in each NHS Trust to act as the Trust s conscience for the uses of patient identifiable information. These senior clinicians are known as Caldicott Guardians. 5

6 In independent contractor organisations such as General Practice, Pharmacy, Dental Practice and Eye Care Services a person, normally the practice manager, will act as the Information Governance Lead and coordinate Information Governance issues including the Caldicott principles and recommendations. Confidentiality Six Caldicott Principles (Revision) The six Caldicott principles published in the report support the confidentiality and security controls on using patient information. The principles should be used whenever a use of confidential information is being considered and in particular when there is an intention to transfer confidential information to another organisation: 1. Justify the purpose for using confidential information. 2. Only use it when absolutely necessary. 3. Use the minimum required. 4. Access should be on a strict need-to-know basis. 5. Everyone must understand their responsibilities. 6. Everyone must understand and comply with the law. If you do not know who the Caldicott Guardian or Information Governance Lead is in your organisation, then you should find out. Detailed guidance about Caldicott Guardians is available in Read more about it. Confidentiality NHS Care Record Guarantee (Revision) The National Information Governance Board is a statutory body which champions the confidentiality and security of health and social care services records, especially records containing clinical and care information. The Board published the NHS Care Record Guarantee in The Guarantee sets out rules that govern how patient information is used in the NHS. This includes: people s access to their own records controls; monitoring and policing staff access to patient files 6

7 options that patients have to limit access access in an emergency what happens when someone cannot make decisions for themselves. Confidentiality Care Record Guarantees (Update) The Guarantees set out rules governing how patient and service user information can be used. NHS Care Record Guarantee An annual review of the NHS Care Record Guarantee for England is carried out by the National Information Governance Board. Everyone who works for the NHS or for organisations delivering services under contract to the NHS has to comply with this guarantee as far as they possibly can. A link to further reading is available in Read more about it at the end of this workbook. Social Care Record Guarantee for England In addition to the NHS Guarantee, in 2009 the National Information Governance Board published the Social Care Record Guarantee for England. The Guarantee explains to service users how the information they provide to social care staff is used and what control they can have over this. It complements the NHS Care Record Guarantee for England. A link to further reading is available in Read more about it at the end of this workbook. Confidentiality The NHS Constitution (Update) The NHS Constitution was first published on 21 January 2009 and was updated after public consultation in March It describes the principles of the NHS in England and the rights and responsibilities of patients, public and staff. 7

8 One such right is that patients can expect the NHS to keep their confidential information safe and secure. All NHS bodies and private and third sector providers supplying NHS services are required by law to take account of the NHS Constitution in their decisions and actions. The NHS Constitution will be renewed every ten years. A link to further reading is available in Read more about it at the end of this workbook. A new training module for medical students and junior doctors is being developed for release soon. It will cover the secure handling of confidential information. UK Law The Data Protection Act 1998 (Revision) UK law in the form of the Data Protection Act 1998 governs how organisations may use personal information (about living people), including how they acquire, store, share or dispose of it. The Information Commissioners Office (ICO) is the UK s independent regulator set up to uphold the public s information rights by promoting data privacy for individuals (and openness by public bodies). The ICO investigates complaints made by the public and provides guidance for the public and organisations. Under the Act, organisations that process personal information must notify the ICO (unless they are exempt). The organisations details are entered on a public register (available on the internet). Failure to notify is a criminal offence. UK Law The Data Protection Act 1998 (Update) There have been some recent changes to enforcement of the Act and public awareness of the Act is growing. 8

9 Strengthening the ICO Powers In April 2010, the ICO was given new powers. It can now fine organisations (including Government Departments) and individuals 500,000 for serious data security breaches such as deliberately or recklessly breaking the data protection principles. The new powers also permit the ICO to carry out spot checks on the data protection practices of Government departments without their permission and without prior notice. Changes to the Notification Fee From 1st October 2009 a two-tiered fee structure was introduced. The fee for any organisation with fewer than 250 staff remains at 35. A higher fee of 500 is payable by large organisations. All organisations must notify the Information Commissioner when they propose to process personal data. The ICO Annual Report The annual report for 2009/2010 included survey findings about data protection which showed: Public awareness. Individuals awareness of the right to see information held about them is at its highest level ever. 91% of people are now aware of this right. Complaints - Health Sector. Of the total complaints received by the ICO on Data Protection matters, the Health sector comprised only 7%. Common Complaint: The most common complaints made to the ICO were from people having problems getting copies of information about them from organisations (these are called Subject Access Requests). A link to the ICO website is available at the end of this document. Additional Guidance. Guidance for Access to Health Records Requests was published on 19th February This assists NHS organisations in England, through the process of dealing with an access request in accordance with the UK Law (common law duty of confidence, Data Protection Act 1998 and the Access to Health Records Act 1990). 9

10 A link to the guidance is available in Read more about it at the end of this workbook. UK Law The Freedom of Information Act 2000 (Revision) Public Authorities (including NHS Trusts, Local Authorities, Dentists, Doctors, Eye Care Services and Pharmacists), are subject to the legal obligations of the Freedom of Information (FOI) Act Public Authorities have only 20 working days to respond to written information requests. This is the limit set out by law. Speak to your Line Manager if you are unsure about your organisation s procedure for dealing with FOI requests. The Information Commissioners Office (ICO) is the independent regulator (for FOI in England and Wales) set up to uphold people s information rights by promoting openness for public bodies (and data privacy for individuals). The ICO investigates complaints made by the public and provides guidance for the public and organisations. The Read All About It section contains a link to the Information Commissioner s Office which publishes public guidance on how the Act works. What can be asked for using the FOI Act? (Revision) People have a right to ask for any information at all - but some information might be withheld to protect various interests which are allowed for by the Act (such as confidential health and social care case notes). If this is the case, the public authority must tell the person who requested the information why it has been withheld. If a person asks for information about him/herself, then the request will be handled under the Data Protection Act instead of the Freedom of Information Act - because the Data Protection Act governs the disclosure of personal Information. 10

11 FOI Act The ICO Annual Report (Update) The ICO s Annual Report for 2009/2010 included survey findings about the Freedom of Information Act which showed: Awareness: People s awareness of the Freedom of Information right to request information rose from 75% in 2008 to 85% in This is shown in the bar chart. Reasons for complaints: The sector generating most complaints from the public to the ICO is Local Government. The Health sector comprised only 7% of complaints while Private Companies comprised 1% (but the Act only applies to a very small number of private companies). Records Management and Information Quality (Revision) Public bodies, including the NHS, are subject to legislation covering subjects such as: Personal Information. The Data Protection Act 1998 which sets outs legal obligations for using personal information such as making sure it is accurate, kept for no longer than is necessary and only the information needed for the intended legal purpose is obtained. Public Records. The Public Records Act 1958 which set out a process of preserving public records and giving a public right of access to these records after 50 years (later reduced to 30 then to 20 years). The Freedom of Information Act (covered earlier in this module) replaced those parts of the Public Records Act relating to accessing all records (both current and archived). 11

12 Records Management (Revision) There are also codes of practice supporting these Acts which have been produced by the Department of Health (DH). In 2005 the DH published Records Management: NHS Code of Practice. If you need to find out guidelines on the length of time to keep documents relating to NHS patients and NHS organisations, then this is where you will find them. The Code applies to NHS records (hard copy and electronic). The Read more about it section contains a link to the Records Management: NHS Code of Practice. Information Quality (Revision) It may seem obvious that information and records must be accurate but it's not just accuracy that matters. Right information, Right place, Right time Accuracy is just one quality that we expect in records. But other qualities are also needed for the information to be useful, e.g. it would be pointless having information which was 100% accurate but wasn t available in time for it to be used. Information is used to make decisions throughout the health sector each day in all sorts of situations. Sometimes this information needs to be extremely high quality, such as quick and accurate test results to help decide a patient s urgent condition and treatment. Other information may be less urgent or the level of accuracy may be less vital, such as an annual national comparison of flu injections for forward planning. Whatever the situation, the right information should be in the right place at the right time - and that needs to be achieved every time. Poor quality information Poor quality information is bad for patient care, bad for funding and bad for reputation, e.g. 12 Incomplete, inadequately analysed data can lead to serious failures in service. Poor demographic data results in duplicate and confused entries on patient record systems. Confused patient identity numbers can lead to the wrong patient being treated.

13 Inadequate records lead to poorly planned care. Poor data results in poor commissioning, monitoring, planning and financing of services. High quality information The NHS takes Information Quality very seriously because the consequences can be vital to patient outcomes or, in the case of planning, result in too much or not enough service provision. High quality means: C omplete A ccurate R elevant A ccessible T imely A link to the Records Management: NHS Code of Practice is available in Read more about it at the end of this workbook. Records and Information NHS Quality, Innovation, Productivity and Prevention (Update) Investment in the NHS in England in 2010/11 is planned at 102 billion. Roughly 1 of every 13 produced by the UK economy is spent on healthcare a level that matches most other European countries. Quality information is needed to support the NHS Quality, Innovation, Productivity and Prevention Programme. To meet the increasing demands of an ageing population and increasing costs, the NHS needs to concentrate on improving productivity and eliminating waste while focusing relentlessly on clinical quality and patient safety. So whenever we record information we need to make sure it is of sufficient quality for the primary purpose, e.g. patient care. If it will also be used in an anonymous form for planning then it must also be of sufficient quality for that too. 13

14 Records and Information Additional guidance (Update) A Clinicians' Guide to Record Standards. The Royal College of Physicians (in partnership with NHS Connecting for Health) has developed standards for hospital patient records, approved by the Academy of Medical Royal Colleges. The new standards (accompanied by a two-part clinicians' guide) will improve patient safety by standardising the information held on patients throughout their stay in hospital, reducing the likelihood of mistakes and missing information at admission, handover and discharge. The standards are available from the Royal College of Physicians website in Read more about it at the end of this workbook. Security (Revision) Security supports the ability of the organisation to provide a reliable service. Security Measures Security measures protect business assets (staff, buildings, equipment and information) against dangers (such as physical attacks, floods and fires, theft or failure of equipment). If the level of danger is not acceptable to the organisation, then measures need to be put in place to reduce the danger - or reduce the impact that it would cause to the organisation. The measures can be grouped into three types: Physical Measures. People Measures. Electronic Measures Key Principle A key principle is to overlap security measures whenever possible to avoid situations where only one measure protects against the danger. 14

15 Overlapping is good practice as it avoids total reliance upon a single measure that may fail, e.g. an outside security door (a physical measure) may be left open by staff, but security staff carrying out routine checks (a people measure) at the end of the day discover the open door and secure it before anything is stolen. The open door needs to be reported as a security incident or it may happen again, and next time the security staff may not notice it. Organisational Responsibility The security measures in your work area are part of the overall plan to ensure adequate security is in place. Your organisation may spend lots of money ensuring computers can be locked by pressing a few buttons on the keyboard and that a password is needed to log back in, but these measures have no effect if passwords are written down and left in the desk drawer, or an encrypted memory stick holding sensitive information has the password taped to the stick. Security Is Everyone s Responsibility Security is not the sole responsibility of a duty manager, security staff or a cleaner who may be left to lock up on his/her own. Employees are each responsible for their own actions, complying with the security measures put in place by their employer and failure to do so can lead to disciplinary measures and legal action. We all need to make sure that we take security seriously, such as making sure: we discuss confidential information out of earshot of others if we need to send or take confidential information to another place then we do so securely we consider the security risks in our work area and what measures are in place or could be in place to reduce those risks. Reporting Incidents and Security Weaknesses An important element of security is the reporting of incidents and weaknesses. We all can and must report problems that we see. You are the expert in your work area in noticing potential problems, such as doors or windows that don t lock properly or confidential waste put in office waste baskets instead of being properly disposed of. We all have an obligation to act responsibly and know what our local policy is and the procedures for reporting. Early intervention will help minimise impacts and ensure corrective actions are taken swiftly. Managing Information Risks In large organisations like an NHS Trust, each important information system that organisations rely upon is 'owned' by a senior manager called an 'Information Asset Owner'. The system (or asset) may be a computer system, 15

16 an MRI scanner or even an operating theatre. The asset owner is responsible for making sure the asset is protected against threats. Asset owners report to a Board level member (known as the Senior Information Risk Owner) who has been appointed in each Trust to be accountable, lead and co-ordinate management of 'Information Risks'. Issues of concern should be reported to ensure that these individuals are made aware of possible weaknesses and do something about it. A link to the NHS Information Risk Management web pages is available in Read more about it at the end of this workbook. Security Data Security Breaches (Update) On 28 May 2010, the UK Information Commissioner s Office published details of the 1007 data security breaches since late Can you guess which category was the major cause of breaches? Information disclosed in error Lost data/hardware Information lost in transit Stolen data or hardware A technical or procedural failure Breach arising from non-secure disposal The highest number of breaches involves stolen equipment, for example, laptops and memory sticks. Another common reason is where information has been disclosed in error, which often happens when automated machinery is incorrectly used and letters are sent to the wrong addresses. Stolen data/hardware, Lost data/hardware and Disclosed in error feature highly across several sectors including the private sector, local government, the NHS and other public sector bodies. 16

17 Security NHS Data Security Breaches (Update) Of the 1007 security breaches reported to the ICO, 305 were reported by NHS organisations. The NHS is the UK s largest employer with over 1 million staff. NHS rules require that all serious breaches must be reported to the ICO (other sectors do not). The actual number of breaches for other sectors may be significantly higher than those actually reported. You can see that: the stolen data/hardware column shows 116 breaches. the lost data/hardware column, shows 87 breaches. Together the loss and theft of data/hardware accounted for 203 breaches, which is 67% of the NHS total security breaches since Security Everyone s Responsibility (Update) All employees have a duty to maintain confidentiality and security. Basic measures we can take to reduce breaches are: Encryption - Ensure patient and other sensitive data is encrypted if held on portable computing devices such as laptops or memory sticks (this is a mandatory NHS measure). Secure passwords - Use the security measures that are in place to protect information such as encrypted memory sticks, your computer login and PIN numbers for door locks avoid using passwords which are easily guessed or known to others Reporting incidents and security weaknesses - Every organisation needs to be aware of and learn from incidents so that steps can be taken to prevent them happening again. The same applies to reporting security weaknesses. We do not need to wait until an incident happens. Early reporting can avoid the incident happening in the first place. 17

18 Eavesdropping - Be careful that your conversations are not overheard by people who do not need to know. Check Automated Mailing - Ensure that mail merge and automated mailing machinery is used correctly and quality controls identify problems before letters are sent out. - Ensure you know who you are sending information to before you press send. Check the address if you are unsure. Mail - Ensure you are using the most up to date and confirmed address details. Fax - Confirm the number and that someone is there to receive the fax before pressing send. Telephone Security - Confirm the identity of the caller and justify the need to disclose confidential information to them before doing so. Training. Make sure that you and your colleagues are aware of information governance. Always consider the dangers in your work area, what measures are in place or should be in place to reduce those dangers. Security Additional Training The NHS has its own online training which is available to over one million NHS staff at no cost to individuals or their organisations. If your colleagues are not aware let them know! There is more training and guidance available for you. It covers a number of issues. 18

19 Business Continuity Management (BCM).This is a foundation level module designed to provide staff awareness of business continuity, focussing on ways to address the continuity of information assets as a core component of an organisation s overall approach to business. You can link to the IG Training Tool website from the Read more about it section but you should register first to be able to log on to view this module. If you are already logged on you just need to return to the learning tool page. Information Security Management Robust information security management arrangements are needed for the protection of patient records and information services generally. This new foundation module is aimed at newly appointed staff and those needing to know a little more about the role of ISM. You can link to the IG Training Tool website from the Read more about it section but you should register first to be able to log on to view this module. If you are already logged on you just need to return to the learning tool page. Secure Handling of Confidential Information A new module covering this topic is in development, suitable for Medical Students and Junior Doctors (due for release in 2011). You can link to the IG Training Tool website from the Read more about it section but you should register first to be able to log on to view this module. If you are already logged on you just need to return to the learning tool page. Short Message Service (SMS) & Texting Guidance was published in May 2010 and provides NHS organisations with a general awareness of the associated risks of Short Message Service (SMS) and texting that could affect the effectiveness of local services. You can find a link to this guidance from the Read more about it section. Maintenance and Secure Disposal of Digital Printers, Copiers and Multifunction Devices Guidance was published in July 2010 to provide NHS organisations with a general awareness of the associated risks for maintenance and disposal of digital printers, copiers and multifunction devices. You can find a link to this guidance from the Read more about it section. NHS Information Governance: Guidance on Blogging and Social Networking Guidance was published in December You can find a link to this guidance from the Read more about it below. 19

20 Summary Information Governance Standards The Data Handling Review set out measures across Government to improve protection of personal information. The NHS Operating Framework demonstrates the NHS s commitment to improving awareness and best practice around information governance. The measures include improving security of information by strengthening the management framework, using encryption to protect data and making training mandatory for all NHS staff. The NHS Operating Framework demonstrates the NHS s commitment to improving awareness and best practice around information governance. The measures include: 20 improving security of information by strengthening management framework using encryption to protect data making training mandatory for all NHS staff. Confidentiality The NHS deals with vast amounts of confidential information which needs to be protected but easily available to authorized staff. Balancing security and availability is difficult but can be made easier if all staff understand what information is confidential and how it must be handled in care settings. 'Confidential' information is defined in law, NHS regulations and professional ethics. The Caldicott Review sets out 6 principles for the use of patient identifiable information. The NHS Care Record Guarantee sets out rules that govern how patient information is used. The NHS Constitution records that patients have the right to expect the NHS to keep their confidential information safe and secure. Balancing security and availability is difficult but can be made easier if all staff understand what information is confidential and how it must be handled in care settings. UK Law - The Data Protection Act 1998 The Information Commissioner is the regulator charged with making sure that personal information is used lawfully. From April 2010, the Information Commissioner s Office has powers to fine individuals and organisations up to 500,000 for serious breaches of data protection. The Commissioner s annual report shows the health sector is responsible for about 7% of complaints it receives. These complaints include difficulties

21 in getting copies of health records, inaccurate information and improperly disclosing information. UK Law - The Freedom of Information Act 2000 The health sector is subject to the legal obligations of the Freedom of Information Act 2000 which applies to all Public Authorities. This law gives people the right to ask NHS organisations for any information at all and any request must be responded to in 20 working days. Public awareness of this right has now reached 85% of the population, so requests for information are likely to continue increasing. NHS organisations must have processes in place to deal with requests within the legal time limits. Records Management and Quality Records Decisions affecting care must be based on high quality information. This applies to the direct care of patients as well as information used to support service management and planning. Information has enormous value in care but only if it has the right qualities, The Right information in the Right place at the Right time. High quality information is: C omplete A ccurate R elevant A ccessible T imely Security Security measures protect business assets from dangers such as assaults against staff and theft of equipment. A key practice is to mix and overlap the types of measures: Physical measures People measures Electronic measures Security is everyone s responsibility. We all have a part to play in maintaining good security and reporting incidents and weaknesses. Lost and stolen computers are the major causes of security breaches in the NHS. Encryption prevents compromise of confidential information as long as the password to the encryption is kept safe. 21

22 Read More About It Press Ctrl & Click the following links for more information: Revision to the NHS Operating Framework for 2010/11 The NHS Constitution for England NHS Care Records Guarantee Social Care Record Guarantee for England Confidentiality: NHS Code of Practice NHS Caldicott Guardians Guidance for Access to Health Records Requests Data Protection Act 1998 Information Commissioner s Office Freedom of Information Act The Records Management NHS Code of Practice Royal College of Physicians (RCP) Information Security Management: NHS Code of Practice NHS Information Risk Management NHS Connecting for Health Information Governance Website Short Message Service (SMS) and Texting Maintenance and Secure disposal of Digital Printers, Copiers and Multi Function Devices NHS Information Governance: Guidance on blogging and social networks. 22

Working with Information Governance INFORMATION GOVERNANCE REFRESHER TRAINING WORK BOOK

Working with Information Governance INFORMATION GOVERNANCE REFRESHER TRAINING WORK BOOK Working with Information Governance INFORMATION GOVERNANCE REFRESHER TRAINING WORK BOOK Name: Date:.. Training Material & Assessment. Accreditation for Completed Assessments Included 1 IG Refresher Training

More information

How we use your information. Information for patients and service users

How we use your information. Information for patients and service users How we use your information Information for patients and service users What we record about you Pennine Care NHS Foundation Trust provides mental health and community health services to people living in

More information

QUICK REFERENCE TO CALDICOTT & THE DATA PROTECTION ACT 1998 PRINCIPLES

QUICK REFERENCE TO CALDICOTT & THE DATA PROTECTION ACT 1998 PRINCIPLES QUICK REFERENCE TO CALDICOTT & THE DATA PROTECTION ACT 1998 PRINCIPLES What is Caldicott? The term Caldicott refers to a review commissioned by the Chief Medical Officer. A review committee, under the

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Document Number 2010/35/V1 Document Title Data Protection Policy Author Nic McCullagh Author s Job Title Information Governance Manager Department IM&T Ratifying Committee Capacity

More information

Standard Operating Procedures (SOP) Research and Development Office

Standard Operating Procedures (SOP) Research and Development Office Standard Operating Procedures (SOP) Research and Development Office Title of SOP: Principles of Data Collection and Storage SOP Number: 8 Supercedes: 1.0 Effective date: August 2013 Review date: August

More information

Fair Processing Notice or Privacy Notice

Fair Processing Notice or Privacy Notice Fair Processing Notice or Privacy Notice What is a Fair Processing or Privacy notice? A privacy notice is an oral or written statement that individuals are given when information is collected about them.

More information

STEP BY STEP SCHOOL. Data Protection Policy and Privacy Notice

STEP BY STEP SCHOOL. Data Protection Policy and Privacy Notice Data Protection Policy and Privacy Notice 1 Contents 1. Aims... 3 2. Legislation and guidance... 3 3. Definitions... 3 4. The data controller... 4 5. Data protection principles... 4 6. Roles and responsibilities...

More information

High level guidance to support a shared view of quality in general practice

High level guidance to support a shared view of quality in general practice Regulation of General Practice Programme Board High level guidance to support a shared view of quality in general practice March 2018 Publications Gateway Reference: 07811 This document was produced with

More information

Registration under the Care Standards Act Guide to the application process for Private Dentists

Registration under the Care Standards Act Guide to the application process for Private Dentists Registration under the Care Standards Act 2000 Guide to the application process for Private Dentists March 2013 Completing the Application Form The type of dentistry services you provide, will determine

More information

Diploma Unit 9 Unit code: HSC 028 Technical Certificate Unit 9 Unit code: Y/602/3118. Unit Information

Diploma Unit 9 Unit code: HSC 028 Technical Certificate Unit 9 Unit code: Y/602/3118. Unit Information Health & Social NVQ Level 2 Diploma Unit 9 Unit code: HSC 028 Technical Certificate Unit 9 Unit code: Y/602/3118 Unit Information Handle Information in Health and Social Care Setting & Understand how to

More information

I SBN Crown copyright Astron B31267

I SBN Crown copyright Astron B31267 I SBN 0-7559- 0875-9 Crown copyright 2003 Astron B31267 9 780755 908752 w w w. s c o t l a n d. g o v. u k NHS Code of Practice on Protecting Patient Confidentiality 1 INTRODUCTION 1.1 Accurate and secure

More information

DOCUMENT CONTROL Title: Use of Mobile Phones and Tablets (by services users & visitors in clinical areas) Policy. Version: Reference Number: CL062

DOCUMENT CONTROL Title: Use of Mobile Phones and Tablets (by services users & visitors in clinical areas) Policy. Version: Reference Number: CL062 DOCUMENT CONTROL Title: Version: Reference Number: Use of Mobile Phones and Tablets (by services users & visitors in clinical areas) Policy 5 CL062 Scope: This Policy applies all employees of the Trust,

More information

Principles of Data Sharing for GPs and LMCs

Principles of Data Sharing for GPs and LMCs Principles of Data Sharing for GPs and LMCs August 2013 www.lmc.org.uk This advice is based on careful examination of the relevant legislation and guidance but it does not constitute a formal legal opinion.

More information

Advanced HIPAA Communications and University Relations

Advanced HIPAA Communications and University Relations Advanced HIPAA Communications and University Relations accepts no liability of any use reliance placed on it, as it is warranty, express, or implied, or completeness of 1 the HIPAA Health Insurance Portability

More information

JOB DESCRIPTION. Service Manager AMH Inpatient Services. Enhanced CRB with Both Barred List Check

JOB DESCRIPTION. Service Manager AMH Inpatient Services. Enhanced CRB with Both Barred List Check JOB DESCRIPTION JOB TITLE: BAND: HOURS AND: DURATION Service Manager AMH Inpatient Services Agenda for Change Band 8B As specified in the job advertisement and the Contract of Employment AGENDA FOR CHANGE

More information

CLINICAL SERVICES POLICY & PROCEDURE (CSPP No. 25) Clinical Photography Policy in the Pre-Hospital Setting. January 2017

CLINICAL SERVICES POLICY & PROCEDURE (CSPP No. 25) Clinical Photography Policy in the Pre-Hospital Setting. January 2017 CLINICAL SERVICES POLICY & PROCEDURE (CSPP No. 25) Clinical Photography Policy in the Pre-Hospital Setting January 2017 DOCUMENT INFORMATION Author: Mark Ainsworth-Smith Consultant in Pre-hospital Care

More information

Personal Identifiable Information Policy

Personal Identifiable Information Policy Personal Identifiable Information Policy Page 1 of 24 Document Management Title of document Type of document Description IG2 Personal Identifiable Information Policy Policy This Policy supports the Information

More information

OUTPATIENT SERVICES CONTRACT 2018

OUTPATIENT SERVICES CONTRACT 2018 1308 23 rd Street S Fargo, ND 58103 Phone: 701-297-7540 Fax: 701-297-6439 OUTPATIENT SERVICES CONTRACT 2018 Welcome to Benson Psychological Services, PC. This document contains important information about

More information

Compliance with Personal Health Information Protection Act

Compliance with Personal Health Information Protection Act Compliance with Personal Health Information Protection Act Ontario s Personal Health Information & Protection Act (PHIPA) governs the collection, use and disclosure of personal health information by midwives

More information

DATA PROTECTION ACT (1998) SUBJECT ACCESS REQUEST PROCEDURE

DATA PROTECTION ACT (1998) SUBJECT ACCESS REQUEST PROCEDURE DATA PROTECTION ACT (1998) SUBJECT ACCESS REQUEST PROCEDURE Date effective from: 1 st September 2014 Review date: 1 st September 2017 Version number: 4.0 See Document Summary Sheet for full details Date

More information

JOB DESCRIPTION. As specified in the job advertisement and the Contract of. Lead Practice Teacher & Clinical Team Leader

JOB DESCRIPTION. As specified in the job advertisement and the Contract of. Lead Practice Teacher & Clinical Team Leader JOB DESCRIPTION JOB TITLE: Student Health Visitor BAND: Agenda for Change Band 5 HOURS AND: DURATION As specified in the job advertisement and the Contract of Employment AGENDA FOR CHANGE (reference No)

More information

White Rose Surgery. How we collect, look after and use your data.

White Rose Surgery. How we collect, look after and use your data. White Rose Surgery How we collect, look after and use your data. This notice explains how The White Rose Surgery will collect, look after, use or otherwise process your personal data. Personal data is

More information

Visiting Celebrities, VIPs and other Official Visitors

Visiting Celebrities, VIPs and other Official Visitors Visiting Celebrities, VIPs and other Official Visitors Who Should Read This Policy Target Audience Healthcare Professionals Executive Team Version 1.0 May 2016 Ref. Contents Page 1.0 Introduction 4 2.0

More information

Occupational Health Privacy Notice

Occupational Health Privacy Notice In addition Occupational Health Privacy Notice This Privacy Notice explains what personal information we collect from you, how we store this personal information, how long we retain it and with whom and

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Version Number 5 Version Date March 2017 Policy Owner Chief Information Officer Author Information Governance Manager First approval or date July 2013 last reviewed Staff/Groups

More information

What to do When Faced With a Privacy Breach: Guidelines for the Health Sector. ANN CAVOUKIAN, Ph.D. COMMISSIONER

What to do When Faced With a Privacy Breach: Guidelines for the Health Sector. ANN CAVOUKIAN, Ph.D. COMMISSIONER What to do When Faced With a Privacy Breach: Guidelines for the Health Sector ANN CAVOUKIAN, Ph.D. COMMISSIONER INFORMATION AND PRIVACY COMMISSIONER OF ONTARIO Table of Contents What is a privacy breach?...1

More information

THE PRIVACY ACT AND THE AUSTRALIAN PRIVACY PRINCIPLES FREQUENTLY ASKED QUESTIONS

THE PRIVACY ACT AND THE AUSTRALIAN PRIVACY PRINCIPLES FREQUENTLY ASKED QUESTIONS THE PRIVACY ACT AND THE AUSTRALIAN PRIVACY PRINCIPLES FREQUENTLY ASKED QUESTIONS CONTENTS How is Privacy governed in Australia?... 3 Does the Privacy Act apply to me?... 3 I have been told that my State/Territory

More information

EAST CALDER & RATHO MEDICAL PRACTICE YOUR INFORMATION

EAST CALDER & RATHO MEDICAL PRACTICE YOUR INFORMATION EAST CALDER & RATHO MEDICAL PRACTICE YOUR INFORMATION East Calder & Ratho Medical Practice aims to ensure the highest standard of medical care for our patients. To do this we keep records about you, your

More information

PRIVACY BREACH MANAGEMENT POLICY

PRIVACY BREACH MANAGEMENT POLICY \(.kon Education Education PRIVACY BREACH MANAGEMENT POLICY Effective Date: September 1, 2016 GENERAL INFORMATION Under the Access to Information and Protection of Privacy Act (A TIPP Act) public bodies

More information

Frequently Asked Questions (FAQs) About Sharing Information for Patients

Frequently Asked Questions (FAQs) About Sharing Information for Patients Frequently Asked Questions (FAQs) About Sharing Information for Patients Introduction The FAQs answer frequently asked questions on how organisations working for the NHS share medical records to support

More information

GPs as data controllers under the General Data Protection Regulation

GPs as data controllers under the General Data Protection Regulation GPs as data controllers under the General Data Protection Regulation The GDPR is an EU Regulation which will be directly applicable in the UK on 25 May 2018. It should be read alongside the forthcoming

More information

Precedence Privacy Policy

Precedence Privacy Policy Precedence Privacy Policy This Policy describes how Precedence Health Care Pty Ltd (Precedence), and any company which it owns or controls, manages personal information for which it is responsible, specifically

More information

NHS CHOICES COMPLAINTS POLICY

NHS CHOICES COMPLAINTS POLICY NHS CHOICES COMPLAINTS POLICY 1 TABLE OF CONTENTS: INTRODUCTION... 5 DEFINITIONS... 5 Complaint... 5 Concerns and enquiries (Incidents)... 5 Unreasonable or Persistent Complainant... 5 APPLICATIONS...

More information

SPONSORSHIP AND JOINT WORKING WITH THE PHARMACEUTICAL INDUSTRY

SPONSORSHIP AND JOINT WORKING WITH THE PHARMACEUTICAL INDUSTRY SPONSORSHIP AND JOINT WORKING WITH THE PHARMACEUTICAL INDUSTRY 1 SUMMARY This document sets out Haringey Clinical Commissioning Group policy and advice to employees on sponsorship and joint working with

More information

Inspection of residential family centres

Inspection of residential family centres Inspection of residential family centres Framework for inspection from April 2013 This document sets out the framework and guidance for the inspection of residential family centres from April 2013. It

More information

Access to Records Procedure under Data Protection Act 1998 Access to Health Records Act 1990

Access to Records Procedure under Data Protection Act 1998 Access to Health Records Act 1990 Access to Records Procedure under Data Protection Act 1998 Access to Health Records Act 1990 Procedure approved by: Executive Group Date: 14 November 2014 Next Review Date: September 2016 Version: 1.0

More information

Little Swans Day Nursery Whistle Blowing Policy and Procedures May 2014

Little Swans Day Nursery Whistle Blowing Policy and Procedures May 2014 Little Swans Day Nursery Whistle Blowing Policy and Procedures May 2014 Whistle Blowing Procedure Reviewed by Miss Tranter, Nursery Manager and Designated Person for Safeguarding What is Whistle Blowing?

More information

Casual Worker Agreement Form. This agreement is between: Casual Worker (name): The Royal Liverpool & Broadgreen University Hospitals NHS Trust

Casual Worker Agreement Form. This agreement is between: Casual Worker (name): The Royal Liverpool & Broadgreen University Hospitals NHS Trust Casual Worker Agreement Form This agreement is between: Casual Worker (name): Organisation: The Royal Liverpool & Broadgreen University Hospitals NHS Trust Terms of Agreement START DATE: JOB TITLE: Registered/Unregistered

More information

Privacy Toolkit for Social Workers and Social Service Workers Guide to the Personal Health Information Protection Act, 2004 (PHIPA)

Privacy Toolkit for Social Workers and Social Service Workers Guide to the Personal Health Information Protection Act, 2004 (PHIPA) Social Workers and Social Service Workers Guide to the Personal Health Information Protection Act, 2004 (PHIPA) COPYRIGHT 2005 BY ONTARIO COLLEGE OF SOCIAL WORKERS AND SOCIAL SERVICE WORKERS ALL RIGHTS

More information

Privacy Policy - Australian Privacy Principles (APPs)

Privacy Policy - Australian Privacy Principles (APPs) Policy New England North West Health Ltd (Trading as HealthWISE New England North West) will be referred to as HealthWISE for the purposes of this document. HealthWISE recognises that Information Privacy

More information

Peterborough Office. Select Support Partnerships Ltd. Overall rating for this service. Inspection report. Ratings. Requires Improvement

Peterborough Office. Select Support Partnerships Ltd. Overall rating for this service. Inspection report. Ratings. Requires Improvement Select Support Partnerships Ltd Peterborough Office Inspection report Workspace House 28/29 Maxwell Road Peterborough Cambridgeshire PE2 7JE Tel: 01733396160 Date of inspection visit: 14 June 2017 19 June

More information

NOT PROTECTIVELY MARKED

NOT PROTECTIVELY MARKED POLICY / PROCEDURE Security Classification Disclosable under Freedom of Information Act 2000 NOT PROTECTIVELY MARKED Yes POLICY TITLE Welfare Services REFERENCE NUMBER A114 Version 1.1 POLICY OWNERSHIP

More information

PERSONALLY IDENTIFIABLE INFORMATON (PII)

PERSONALLY IDENTIFIABLE INFORMATON (PII) PERSONALLY IDENTIFIABLE INFORMATON (PII) 1 PII - REFERENCES DOD 5400.11-R, DoD Privacy Act Program, May 07 OSD Memo, Subj: Safeguarding Against and Responding to the Breach of Personally Identifiable Information,

More information

Application for Recognition or Expansion of Recognition

Application for Recognition or Expansion of Recognition Application for Recognition or Expansion of Recognition Notes for applicants All Applicants Should Read This Section This form is for applicants who are: o applying to become a recognised awarding organisation

More information

AN OVERVIEW OF FIPPA for FACULTY, INSTRUCTORS & ADMINISTRATORS. Information and tips on how to keep you FIPPA FRIENDLY

AN OVERVIEW OF FIPPA for FACULTY, INSTRUCTORS & ADMINISTRATORS. Information and tips on how to keep you FIPPA FRIENDLY AN OVERVIEW OF FIPPA for FACULTY, INSTRUCTORS & ADMINISTRATORS Information and tips on how to keep you FIPPA FRIENDLY Privacy Legislation Ontario universities were made subject to provincial Freedom of

More information

A protocol for using electronic notes in psychological therapies (talking treatments)

A protocol for using electronic notes in psychological therapies (talking treatments) Sheffield Health and Social Care NHS Foundation Trust Psychological Therapies Governance Committee A protocol for using electronic notes in psychological therapies (talking treatments) Review version June

More information

MCCP Online Orientation

MCCP Online Orientation 1 Objectives At the conclusion of this presentation, students will be able to: Discuss application of HIPAA to student s role. Describe the federal requirements of the HIPAA/HITECH regulations that protect

More information

ACCESS TO HEALTH RECORDS POLICY & PROCEDURE

ACCESS TO HEALTH RECORDS POLICY & PROCEDURE ACCESS TO HEALTH RECORDS POLICY & PROCEDURE Document Number 2009/45 Version 3 Document Title Access to Health Records Policy & Procedure Author Karl Perryman Author s Job Title Head of Legal Services Department

More information

Standards of Practice for Optometrists and Dispensing Opticians

Standards of Practice for Optometrists and Dispensing Opticians Standards of Practice for Optometrists and Dispensing Opticians effective from April 2016 Standards of Practice for Optometrists and Dispensing Opticians Standards of Practice Our Standards of Practice

More information

The NHS Constitution

The NHS Constitution 2 The NHS Constitution The NHS belongs to the people. It is there to improve our health and wellbeing, supporting us to keep mentally and physically well, to get better when we are ill and, when we cannot

More information

IVAN FRANKO HOME Пансіон Ім. Івана Франка

IVAN FRANKO HOME Пансіон Ім. Івана Франка THE IVAN FRANKO HOME S COMMITMENT TO PRIVACY PRIVACY STATEMENT The Ivan Franko Home respects this privacy of our residents, employees, Directors, volunteers and donors. We are committed to ensuring that

More information

Sample. Information Governance. Copyright Notice. This booklet remains the intellectual property of Redcrier Publications L td

Sample. Information Governance. Copyright Notice. This booklet remains the intellectual property of Redcrier Publications L td First name: Surname: Company: Date: Information Governance Please complete the above, in the blocks provided, as clearly as possible. Completing the details in full will ensure that your certificate bears

More information

Performance and Quality Committee

Performance and Quality Committee Title: NHS Continuing Health Care Choice Policy (addendum to Cornwall Wide Patient Choice, Equity and Fair Access Policy) Developed by: Document type: Policy library: NHS Kernow Policy Policies Sub Section:

More information

NHS Constitution The NHS belongs to the people. This Constitution principles values rights pledges responsibilities

NHS Constitution The NHS belongs to the people. This Constitution principles values rights pledges responsibilities for England 8 March 2012 2 NHS Constitution The NHS belongs to the people. It is there to improve our health and well-being, supporting us to keep mentally and physically well, to get better when we are

More information

Research Code of Practice

Research Code of Practice National Foundation for Educational Research Research Code of Practice Why have a Code of Practice? A wide range of individuals and organisations contribute to the work carried out by the National Foundation

More information

Inspections of children s homes

Inspections of children s homes Inspections of children s homes Framework for inspection This document sets out the framework and guidance for the inspections of children s homes. It should be read alongside the evaluation schedule for

More information

Implementation of the right to access services within maximum waiting times

Implementation of the right to access services within maximum waiting times Implementation of the right to access services within maximum waiting times Guidance for strategic health authorities, primary care trusts and providers DH INFORMATION READER BOX Policy HR / Workforce

More information

JOB DESCRIPTION FOR THE POST OF Support, Time and Recovery Worker COMMUNITY ADULT MENTAL HEALTH

JOB DESCRIPTION FOR THE POST OF Support, Time and Recovery Worker COMMUNITY ADULT MENTAL HEALTH JOB DESCRIPTION FOR THE POST OF Support, Time and Recovery Worker COMMUNITY ADULT MENTAL HEALTH TITLE: AGENDA FOR CHANGE PAY BAND: DIVISION ACCOUNTABLE TO: REPORTS TO: RESPONSIBLE FOR: Support, Time and

More information

Consultation on developing our approach to regulating registered pharmacies

Consultation on developing our approach to regulating registered pharmacies Consultation on developing our approach to regulating registered pharmacies May 2018 The text of this document (but not the logo and branding) may be reproduced free of charge in any format or medium,

More information

DUTIES OF A CUSTODIAN

DUTIES OF A CUSTODIAN DUTIES OF A CUSTODIAN SUMMARY OF CUSTODIAN DUTIES UNDER THE PERSONAL HEALTH INFORMATION ACT Custodians have legislated duties as outlined in the Act. A custodian is required to: 1. prepare and make readily

More information

Fair Processing Strategy

Fair Processing Strategy Fair Processing Strategy March 2014 Fair Processing Strategy v8 2014.03.25 Page 1 of 15 NHS England INFORMATION READER BOX Directorate Medical Operations Patients and Information Nursing Policy Commissioning

More information

Privacy health check: Diagnosing for law reform

Privacy health check: Diagnosing for law reform Privacy health check: Diagnosing for law reform PMAANZ Conference 10 September 2016 Daimhin Warner Director (Auckland), Simply Privacy Ltd Law reform is coming: Time to get your house in order What is

More information

ACCESS TO HEALTH RECORDS POLICY & PROCEDURE

ACCESS TO HEALTH RECORDS POLICY & PROCEDURE ACCESS TO HEALTH RECORDS POLICY & PROCEDURE Primary Intranet Location Version Number Next Review Year Next Review Month Legal Services V3 2018 January Current Author Author s Job Title Department Approved

More information

The Care Act - Independent Advocacy Policy Guidance

The Care Act - Independent Advocacy Policy Guidance The Care Act - Independent Advocacy Policy Guidance Defining the Independent Advocacy Offer Version 1 Document to be refreshed July 2015 1. Introduction The Care Act 2014 requires that local authorities

More information

Leadership and management for all doctors

Leadership and management for all doctors Leadership and management for all doctors The duties of a doctor registered with the General Medical Council Patients must be able to trust doctors with their lives and health. To justify that trust you

More information

Privacy and Security Training for Connecting Ontario. PACE Cardiology April, 2017

Privacy and Security Training for Connecting Ontario. PACE Cardiology April, 2017 Privacy and Security Training for Connecting Ontario PACE Cardiology April, 2017 Session Goals By the end of this session you will: Review key elements of privacy protection Know your privacy obligations

More information

FACULTY OF DENTISTRY, THE UNIVERSITY OF HONG KONG THE PRINCE PHILIP DENTAL HOSPITAL

FACULTY OF DENTISTRY, THE UNIVERSITY OF HONG KONG THE PRINCE PHILIP DENTAL HOSPITAL FACULTY OF DENTISTRY, THE UNIVERSITY OF HONG KONG THE PRINCE PHILIP DENTAL HOSPITAL Rules Governing Treatment of Patients and Handling of Patient Information (Applicable to Staff and Students of both the

More information

Updated FY15 Dignity Health General Compliance Education for Staff Module 2

Updated FY15 Dignity Health General Compliance Education for Staff Module 2 Updated FY15 Dignity Health General Compliance Education for Staff Module 2 This course will provide you with important information about the laws and regulations that affect the healthcare industry, our

More information

THE CODE. Professional standards of conduct, ethics and performance for pharmacists in Northern Ireland. Effective from 1 March 2016

THE CODE. Professional standards of conduct, ethics and performance for pharmacists in Northern Ireland. Effective from 1 March 2016 THE CODE Professional standards of conduct, ethics and performance for pharmacists in Northern Ireland Effective from 1 March 2016 PRINCIPLE 1: ALWAYS PUT THE PATIENT FIRST PRINCIPLE 2: PROVIDE A SAFE

More information

Standards of conduct, ethics and performance

Standards of conduct, ethics and performance Standards of conduct, ethics and performance September 2010 The General Pharmaceutical Council is the regulator for pharmacists, pharmacy technicians and registered pharmacy premises in England, Scotland

More information

Technology Standards of Practice

Technology Standards of Practice 2016 Technology Standards of Practice Used with permission from the Association of Social Work Boards (2016) Table of Contents Technology Standards of Practice 2 Definitions 2 Section 1 Practitioner Competence

More information

Policy No. AD I1 ** Information from collection to retention shall be managed according to relevant legislation.

Policy No. AD I1 ** Information from collection to retention shall be managed according to relevant legislation. Community Living and Respite Services Inc. (CLRS) Policy No. AD I1 ** Issue No. 6 Issue Date: May 2005, August 2009February 2011Renamed Previously Information Privacy Policy. Revised Date February 2011,

More information

Sample Privacy Impact Assessment Report Project: Outsourcing clinical audit to an external company in St. Anywhere s hospital

Sample Privacy Impact Assessment Report Project: Outsourcing clinical audit to an external company in St. Anywhere s hospital Sample Privacy Impact Assessment Report Project: Outsourcing clinical audit to an external company in St. Anywhere s hospital October 2010 2 Please Note: The purpose of this document is to demonstrate

More information

Reservation of Powers to the Board & Delegation of Powers

Reservation of Powers to the Board & Delegation of Powers Reservation of Powers to the Board & Delegation of Powers Status: Draft Next Review Date: March 2014 Page 1 of 102 Reservation of Powers to the Board & Delegation of Powers Issue Date: 5 April 2013 Document

More information

SM-PGN 01- Security Management Practice Guidance Note Closed Circuit Television (CCTV)-V03

SM-PGN 01- Security Management Practice Guidance Note Closed Circuit Television (CCTV)-V03 Security Management Practice Guidance Note Closed Circuit Television (CCTV)-V03 Date Issued Issue 7 Sep 17 Issue 8 Dec 17 Issue 9 Mar 18 Planned Review September- 2018 SM-PGN 01- Part of NTW(O)21 Security

More information

Healthcare Identifiers Service Information Guide

Healthcare Identifiers Service Information Guide Healthcare Identifiers Service Information Guide Introduction and overview Audience This information guide is intended for all individual healthcare providers and organisations seeking to participate in

More information

Welsh Government Response to the Report of the National Assembly for Wales Public Accounts Committee Report on Unscheduled Care: Committee Report

Welsh Government Response to the Report of the National Assembly for Wales Public Accounts Committee Report on Unscheduled Care: Committee Report Welsh Government Response to the Report of the National Assembly for Wales Public Accounts Committee Report on Unscheduled Care: Committee Report We welcome the findings of the report and offer the following

More information

Board Report In Public Meeting Title of Paper Information Governance Annual Report inc. Caldicott Guardian Annual Activity/Assurance Reports Author(s)

Board Report In Public Meeting Title of Paper Information Governance Annual Report inc. Caldicott Guardian Annual Activity/Assurance Reports Author(s) Item 18.1 Board Report In Public Meeting Title of Paper Information Governance Annual Report inc. Caldicott Guardian Annual Activity/Assurance Reports Author(s) Sadie Bell, Head of Information Governance

More information

Your NHS number and how we use your information in the NHS

Your NHS number and how we use your information in the NHS Your NHS number and how we use your information in the NHS Write your NHS number here: Take this with you whenever you see a doctor or other healthcare worker Keep your NHS number safe Leaflet for people

More information

NOTICE OF PRIVACY PRACTICES

NOTICE OF PRIVACY PRACTICES NOTICE OF PRIVACY PRACTICES Effective Date: 2013 Wisconsin Dental Association (800) 243-4675 THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS

More information

PRIVACY BREACH MANAGEMENT GUIDELINES. Ministry of Justice Access and Privacy Branch

PRIVACY BREACH MANAGEMENT GUIDELINES. Ministry of Justice Access and Privacy Branch Ministry of Justice Access and Privacy Branch December 2015 Table of Contents December 2015 What is a privacy breach? 3 Preventing privacy breaches 3 Responding to privacy breaches 4 Step 1 Contain the

More information

Student Privacy Notice

Student Privacy Notice Student Privacy Notice Queen s University Belfast collects, holds and processes personal information or data relating to its students. We need to do this in order for the University to carry out its functions

More information

GRANTfinder Special Feature

GRANTfinder Special Feature GRANTfinder Special Feature Successfully Securing Grant Funding: A Beginner s Guide Article submitted by Robert Kelk, Information Researcher Introduction Even in times of economic austerity, funding bodies

More information

Social care guideline Published: 14 March 2014 nice.org.uk/guidance/sc1

Social care guideline Published: 14 March 2014 nice.org.uk/guidance/sc1 Managing medicines in care homes Social care guideline Published: 14 March 2014 nice.org.uk/guidance/sc1 NICE 2018. All rights reserved. Subject to Notice of rights (https://www.nice.org.uk/terms-and-conditions#notice-ofrights).

More information

Delivering Local Health Care

Delivering Local Health Care Delivering Local Health Care Accelerating the pace of change Contents Joint foreword by the Minister for Health and Social Services and the Deputy Minister for Children and Social Services Foreword by

More information

STAFF CODE OF CONDUCT

STAFF CODE OF CONDUCT Fierté Multi Academy Trust Staff Code of Conduct 2017-2018 At the heart of our Trust are both the UNICEF Rights Respecting values and articles and Learning Behaviours. Through these, we aim to put children

More information

Information Privacy and Security

Information Privacy and Security Information Privacy and Security 2015 Purpose of HIPAA HIPAA stands for the Health Insurance Portability and Accountability Act. Its purpose is to establish nationwide protection of patient confidentiality,

More information

A Deep Dive into the Privacy Landscape

A Deep Dive into the Privacy Landscape A Deep Dive into the Privacy Landscape David Goodis Assistant Commissioner Information and Privacy Commissioner of Ontario Canadian Institute Advertising & Marketing Law January 22, 2018 Who is the Information

More information

JOB DESCRIPTION DIRECTOR OF SCREENING. Author: Dr Quentin Sandifer, Executive Director of Public Health Services and Medical Director

JOB DESCRIPTION DIRECTOR OF SCREENING. Author: Dr Quentin Sandifer, Executive Director of Public Health Services and Medical Director JOB DESCRIPTION DIRECTOR OF SCREENING Author: Dr Quentin Sandifer, Executive Director of Public Health Services and Medical Director Date: 1 November 2017 Version: 0d Purpose and Summary of Document: This

More information

Information for registrants. How to renew your registration

Information for registrants. How to renew your registration Information for registrants How to renew your registration Contents Introduction 1 Renewing your registration with the HCPC 2 Paying your registration renewal fee 12 What happens if 13 Contact us 15 Keeping

More information

Responsible to: Operational Manager(s) Head of Biomedical Scientist Accountable to: Head of Biomedical Scientist

Responsible to: Operational Manager(s) Head of Biomedical Scientist Accountable to: Head of Biomedical Scientist Job Description Post: Medical Laboratory Assistant Band AFC Band 3 Directorate Of Laboratory Medicine Department: Laboratory Medicine Responsible to: Operational Manager(s) Head of Biomedical Scientist

More information

The CARE CERTIFICATE. Duty of Care. What you need to know. Standard THE CARE CERTIFICATE WORKBOOK

The CARE CERTIFICATE. Duty of Care. What you need to know. Standard THE CARE CERTIFICATE WORKBOOK The CARE CERTIFICATE Duty of Care What you need to know Standard THE CARE CERTIFICATE WORKBOOK Duty of care You have a duty of care to all those receiving care and support in your workplace. This means

More information

Getting Ready for Ontario s Privacy Legislation GUIDE. Privacy Requirements and Policies for Health Practitioners

Getting Ready for Ontario s Privacy Legislation GUIDE. Privacy Requirements and Policies for Health Practitioners Getting Ready for Ontario s Privacy Legislation GUIDE Privacy Requirements and Policies for Health Practitioners PUBLISHED BY THE COLLEGE OF DENTAL HYGIENISTS OF ONTARIO SEPTEMBER 2004 2 This booklet is

More information

Data Protection Privacy Notice

Data Protection Privacy Notice Data Protection Privacy Notice Introduction This document explains why information is collected about you by the UK Renal Registry (UKRR) and how your information may be used this is called a Fair Processing

More information

IT ALL STARTS WITH YOU

IT ALL STARTS WITH YOU Email: jo.curtis@nhs.net IT ALL STARTS WITH YOU Tell us about your experience Help us improve NHS services This guide takes you through the different ways you can tell the NHS about your experiences, so

More information

Parkbury House Surgery

Parkbury House Surgery Parkbury House Surgery Complaint Policy and Procedures St Peters Street, St Albans, Hertfordshire, AL1 3HD Tel: 01727 851589 Fax: 01727 854372 parkburyhouse.info@nhs.net; www.parkburyhouse.nhs.uk Version

More information

JOB DESCRIPTION. Building Services Manager

JOB DESCRIPTION. Building Services Manager JOB DESCRIPTION JOB TITLE: LOCATION: DEPARTMENT: RESPONSIBLE TO: ACCOUNTABLE TO: Hospital Porter Highgate Hospital Hotel Services Senior Hospital Porter Building Services Manager 1. JOB PURPOSE: The Hospital

More information

CODE OF CONDUCT CODE OF ACCOUNTABILITY IN THE NHS

CODE OF CONDUCT CODE OF ACCOUNTABILITY IN THE NHS CODE OF CONDUCT CODE OF ACCOUNTABILITY IN THE NHS CODE OF CONDUCT Public Service Values General Principles Openness and Public Responsibilities Public Service Values in Management Public Business and Private

More information

Good Practice Guidance : Safe management of controlled drugs in Care Homes

Good Practice Guidance : Safe management of controlled drugs in Care Homes Good Practice Guidance : Safe management of controlled drugs in Care Homes Date produced: April 2015; Date for Review: April 2017 Good Practice Guidance documents are believed to accurately reflect the

More information

Implied Consent Model and Permission to View

Implied Consent Model and Permission to View NHS CRS - Summary Care Record, Implied consent model and Permission to view Programme NPFIT Document Record ID Key Sub-Prog / Project Summary Care Record NPFIT-SCR-SCRDOCS-0025.02 Prog. Director James

More information