Transcription of NHS England report template - data icon
1 NHS England and NHS Improvement Confidentiality Policy OFFICIAL Document Owner: Head of Corporate Information Governance Prepared by: Corporate Information Governance First Published: Document number: Approval date: 23/9/19 Version number: Status: Approved Next review date: September 2022 Page 2 NHS England and NHS Improvement INFORMATION READER BOX Directorate Medical Operations and Information Specialised Commissioning Nursing Trans. & Corp. Dev. Strategy & Innovation Finance Publications Gateway Reference: Document Purpose Policy Document Name Confidentiality Policy Author Corporate Information Governance Publication Date September 2019 Target Audience All NHS England and NHS Improvement Employees Description Policy and high-level procedures for Confidentiality Cross Reference N/A Superseded Docs (if applicable) Confidentiality Policy Action Required To note Timing / Deadlines (if applicable) N/A Contact Details for further information Carol Mitchell Head of Corporate Information Governance Quarry House Leeds LS2 7UE Document Status This is a controlled document.
2 Whilst this document may be printed, the electronic version posted on the intranet is the controlled copy. Any printed copies of this document are not controlled. As a controlled document, this document should not be saved onto local or network drives but should always be accessed from the intranet. OFFICIAL Document Owner: Head of Corporate Information Governance Prepared by: Corporate Information Governance First Published: Document number: Approval date: 23/9/19 Version number: Status: Approved Next review date: September 2022 Page 3 Confidentiality Policy Version number: Updated: September 2019 Prepared by: Corporate Information Governance Classification: OFFICIAL This information can be made available in alternative formats, such as easy read or large print, and may be available in alternative languages, upon request.
3 Please contact OFFICIAL Document Owner: Head of Corporate Information Governance Prepared by: Corporate Information Governance First Published: Document number: Approval date: 23/9/19 Version number: Status: Approved Next review date: September 2022 Page 4 Contents Contents .. 4 1 Introduction .. 5 2 Scope .. 6 3 Roles and Responsibilities .. 6 The Chief Executive .. 6 The Caldicott Guardian .. 6 Senior Information Risk Owner .. 7 Data Protection Officer (DPO) .. 7 The National Information Governance Steering 7 Director with responsibility for 7 Senior Managers .. 7 Head of Corporate Information Governance .. 7 All staff .. 7 4 Corporate Level Procedures .. 8 Principles .. 8 Disclosing Personal/Confidential Information.
4 9 Working Away from the Office Environment .. 11 Carelessness .. 12 Abuse of 12 Confidentiality Audits .. 13 5 Distribution and Implementation .. 13 Distribution Plan .. 13 Training Plan .. 13 6 Monitoring .. 13 7 Equality Impact Assessment .. 13 8 Associated Documents .. 14 Appendix A: Confidentiality Do s and Don 15 Appendix B: Summary of Legal and NHS Mandated Frameworks .. 17 Appendix C: Reporting of Policy Breaches .. 20 Appendix D: Definitions .. 22 Version control tracker .. 23 OFFICIAL Document Owner: Head of Corporate Information Governance Prepared by: Corporate Information Governance First Published: Document number: Approval date: 23/9/19 Version number: Status: Approved Next review date: September 2022 Page 5 1 Introduction The purpose of this Confidentiality Policy is to lay down the principles that must be observed by all who work within NHS England and NHS Improvement and have access to person-identifiable information or confidential information (see appendix D).
5 All staff need to be aware of their responsibilities for safeguarding confidentiality and preserving information security. All employees working in the NHS are bound by a legal duty of confidence to protect personal information they may come into contact with during the course of their work. This is not just a requirement of their contractual responsibilities but also a requirement within the common law duty of confidence and data protection legislation the European General Data Protection Regulation (GDPR) and Data Protection Act 2018 (DPA2018) which implements the GDPR in the UK. Confidentiality is also a requirement within the NHS Care Record Guarantee, produced to assure patients regarding the use of their information. NHS England and NHS Improvement are cooperating to establish a joint enterprise.
6 This mirrors the focus of the NHS Long Term Plan on how we will deliver integrated care to patients at the local level, how we set the whole of the NHS up to do that and how it will benefit patients and communities. To ensure that we comply with our data protection obligations the three statutory organisations (NHS England and NHS Improvement which comprises Monitor and TDA) have entered into a Joint Controller and Information Sharing Framework Agreement. This sets out our joint data protection responsibilities and the measures that we have put in place to ensure that we comply. The Information Sharing Policy sets our framework for processing personal data in support of joint working with reference to this agreement. It is important that NHS England and NHS Improvement protect and safeguard person-identifiable and confidential business information that it gathers, creates processes and discloses, in order to comply with the law, relevant NHS mandatory requirements and to provide assurance to patients and the public.
7 This policy sets out the requirements placed on all staff when sharing information within the NHS and between NHS and non-NHS organisations. Person-identifiable information is anything that contains the means to identify a person, name, address, postcode, date of birth, NHS number and must not be stored on removable media unless it is encrypted as per current NHS Encryption Guidance or a business case has been approved by the Transformation & Corporate Development Directorate s Information Governance Team. Confidential information within the NHS is commonly thought of as health information; however, it can also include information that is private and not public knowledge or information that an individual would not expect to be shared.
8 It can take many forms including patient level health information, employee records, OFFICIAL Document Owner: Head of Corporate Information Governance Prepared by: Corporate Information Governance First Published: Document number: Approval date: 23/9/19 Version number: Status: Approved Next review date: September 2022 Page 6 occupational health records, etc. It also includes NHS England and NHS Improvement confidential business information. Information can relate to patients and staff (including temporary staff), however stored. Information may be held on paper, CD/DVD, USB sticks, computer file or printout, laptops, palmtops, mobile phones, digital cameras or even heard by word of mouth. A summary of Confidentiality Do s and Don ts can be found at Appendix A.
9 The Legal and NHS Mandated Framework for confidentiality which forms the key guiding principles of this policy can be found in Appendix B. How to report a breach of this policy and what should be reported can be found in Appendix C. Definitions of confidential information can be found in Appendix D. 2 Scope All our staff and of hosted organisations, without exception, are within the scope of this policy, including and without limitation: Central and Regional Teams; All Commissioning Support Units; NHS Interim and Management Support (NHS IMAS); NHS Sustainable Development Unit; Strategic Clinical Networks; Clinical Senates; and Healthcare Safety Investigation Branch (HSIB) 3 Roles and Responsibilities The Chief Executive The Chief Executive has overall responsibility for strategic and operational management, including ensuring that NHS England and NHS Improvement policies comply with all legal, statutory and good practice guidance requirements.
10 The Caldicott Guardian A senior person responsible for protecting the confidentiality of patient and service user information and enabling appropriate information sharing by providing advice to professionals and staff. OFFICIAL Document Owner: Head of Corporate Information Governance Prepared by: Corporate Information Governance First Published: Document number: Approval date: 23/9/19 Version number: Status: Approved Next review date: September 2022 Page 7 Senior Information Risk Owner Sign off and take accountability for risk-based decisions and reviews in regards to the use, disclosure or processing of confidential data in regard to the operating functions of NHS England and NHS Improvement. The SIRO (or their deputy) chairs the National IG Steering Group (see ).