Transcription of IG Requirement Assurance Tool (IGT) …
1 Information Governance ToolkitPage 1 of 167 Commercial Third Party | v11IG Requirement Assurance tool (IGT) requirements BookletCommercial Third PartyVersion 11 Information Governance ToolkitPage 2 of 167 Commercial Third Party | v11 ReqNoDescriptionPageInformation Governance Management11-114 Responsibility for Information Governance has been assigned to an appropriatemember, or members, of staff311-115 There is an information governance policy that addresses the overallrequirements of information governance1111-116 All contracts (staff, contractor and third party)
2 Contain clauses that clearlyidentify information governance responsibilities1911-117 All staff members are provided with appropriate training on informationgovernance requirements31 Confidentiality and Data Protection Assurance11-202 Personal information is only used in ways that do not directly contribute to thedelivery of care services where there is a lawful basis to do so and objections tothe disclosure of confidential personal information are appropriately respected3911-206 There are appropriate confidentiality audit procedures to monitor access toconfidential personal information4911-209 All person identifiable data processed outside of the UK complies with the DataProtection Act 1998 and Department of Health guidelines5711-210 All new processes, services, information systems, and other relevantinformation assets are developed and implemented in a secure and structuredmanner, and comply with IG security accreditation.
3 Information quality andconfidentiality and data protection requirements6511-211 All transfers of personal and sensitive information are conducted in a secureand confidential manner79 Information Security Assurance11-305 Operating and application information systems (under the organisation scontrol) support appropriate access control functionality and documented andmanaged access rights are in place for all users of these systems8911-313 Policy and procedures are in place to ensure that Information CommunicationTechnology (ICT) networks operate securely10511-314 Policy and procedures ensure that mobile computing and teleworking aresecure11311-316 There is an information asset register that includes all key information, software,hardware and services12311-317 Unauthorised access to the premises, equipment, records and other assets isprevented12911-319 There are documented plans and procedures to support business continuityin the event of power failures, system failures.
4 Natural disasters and otherdisruptions13711-320 There are documented incident management and reporting procedures14711-323 All information assets that hold, or are, personal data are protected byappropriate organisational and technical measures159 Information Governance ToolkitPage 3 of 167 Commercial Third Party | v11 Requirement No:11-114 Initiative:InformationGovernanceManageme ntOrganisationType:CommercialThird PartyResponsibility for InformationGovernance has been assigned to anappropriate member, or members, DescriptionIt is important that that there is a consistent approach to information handling within theorganisation which is in line with the law, central policy, contractual terms and conditionsand best practice guidance.
5 This requires one or more members of staff to be assignedclear responsibility for driving any required for Information requires that named individuals take responsibility for co-ordinating, publicisingand monitoring standards of information handling within the organisation andfor developing and implementing an IG improvement plan (also known asimplementation or work plan). The Information Governance Lead(s) also need(s) toensure that IG Toolkit assessments are submitted as an IG senior management should consider the responsibilities of an IG Leadand decide whether these can be met by one member of staff or whether theresponsibilities should be shared between a number of staff.
6 For organisations withmultiple premises there may be a need to appoint an overall lead with other staffsupporting at the premises level. Those appointed should have sufficient seniorityand authority to ensure that any necessary changes in information handling withinthe organisation can be implemented and implementation models a contractor is supported by a substantial head office function,a member of head office staff may be appointed to co-ordinateinformation governance across the organisation however there willstill be a need for a local IG lead to co-ordinate local IG activities suchas developing an improvement plan (see paragraph 11)
7 Relevant tothe local circumstances and supporting a monitoring visit from thecommissioning a contractor runs an individual business the IG lead would typicallybe a senior permanent member of the confidentiality is already a key part of the clinical governance requirementsin most contractual frameworks. IG responsibilities can be combined with otherInformation Governance ToolkitPage 4 of 167 Commercial Third Party | v11similar responsibilities, where there is a contractual framework Requirement foran organisation to have an identifiable clinical governance lead, this individual mightalso act as the IG should be written assignment of IG Lead responsibility.
8 This could be throughadding this to staff job descriptions or simply a written note explaining the Training and Support does the IG Lead Require? IG Lead needs to be sufficiently trained to undertake their key should cover data protection, security and confidentiality and Freedomof Information requirements . Training can be undertaken through the on-line NHSI nformation Governance Training IG Training tool comprises a structured e-learning programme withIntroductory, Foundation and Practitioner level modules covering all aspects ofIG. The organisation needs to be registered in the tool before users can set upan account, and ideally an organisation administrator should be nominated andgiven the appropriate permissions to monitor staff training.
9 This can all be arrangedby logging a request with the IG Training tool helpdesk complete the Contact Ussection providing the organisation name, corporate email domain (if one exists) andODS code, (also known as the practice code, the national code, or the pharmacyF code found on the submission document used to send prescriptions to NHSP rescription Services). the organisation is registered, other members of staff will be able to registeron the tool . As part of the user registration process, staff will be asked for theirorganisation's ODS code, so it is important to ensure staff know what the code isbefore they attempt to register.
10 If no corporate email domain exists, staff can stillregister by selecting "no" when asked if they have a work email and following thesteps to create an onscreen IG Lead should also have access to sufficient support to do their job and if s/heis not a health or care professional (eg pharmacist, optician, ophthalmologist, GP,dentist, etc) or a senior manager, they will need access to such a person for supportwith of an Information Governance IG lead is not required to carry out all the work necessary to meet the NHS IGrequirements, but should be able to supervise and direct the work of others wherenecessary.