INFORMATION GOVERNANCE

Slides:



Advertisements
Similar presentations
Information Governance, Love it or Hate it!
Advertisements

Records Management and the NHS Code of Practice (Foundation) Information Governance Policy Team NHS Connecting for Health.
The Data Quality Team Information Governance Ext 8168 The Importance Of Data Quality High Data Quality is Important to: * Improve Patient Care * Reduce.
Information Governance – Who Cares? Alistair Stewart Information Governance Co-ordinator.
And the finer details of patient privacy TCH Confidential Understanding HIPAA.
Data Protection Information Management / Jody McKenzie.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
NAU HIPAA Awareness Training
Confidentiality & Records Management. What is Information Governance? What is Records Management?
How to Find Your Way Around… SEPT - MANDATORY TRAINING 1. You can play the PowerPoint, and find the Test here EXAMPLE COURSE.
Standards of Integrity and Conduct A code of conduct issued by the State Services Commissioner.
Information Governance
1.  Incident reports should be written only when you are sure that a persons rights have been violated. True False  Full names of consumers should never.
HIPAA Basic Training for Privacy and Information Security Vanderbilt University Medical Center VUMC HIPAA Website: HIPAA Basic.
Audit of Practice Around Record Keeping and Partner Notification Maeve Cross & Martin Murchie.
SECURITY: Personal Health Information Protection Act, 2004 this 5 min. course covers: changing landscape of electronic health records security threats.
Practical Information Management
Information Governance Sylvia Reynolds Senior Resources Officer / Information Governance Manager.
UNIVERSITY OF ALABAMA V HIPAA Privacy and Security Training For Employees Compliance is Everyone’s Job 1 INTERNAL USE ONLY Abbreviated Training.
Safeguarding Vulnerable Adults Level One Mandatory Update.
Child Protection Level Recognising potential indicators of child maltreatment Recognising the potential impact of a parent/carers physical and.
Medical Informatics Patient Administration System.
Female Genital Mutilation
‘A Healthier Dorset’ Safeguarding Children Primary Care Update September 22 nd 2011 Safeguarding Children: the role of Dentists.
Child Protection Level To increase participants awareness of the key aspects of child maltreatment. To feel more confident in where to go and.
Local Government Reform and Compliance with the DPA Ken Macdonald Assistant Commissioner (Scotland & Northern Ireland) Information Commissioner’s Office.
Legal aspects of Health Data protection Solvita Olsena Medical Law Institute Ltd.
CALDICOTT PRESENTATION. History Caldicott report published in 1997 and implemented in 1999 Inquiry chaired by Dame Fiona Caldicott.
Your health record How the local NHS uses and protects the information held about you Other ways that your records may be used Your local NHS services.
12/12/2015 Data Protection Act /12/2015 The DP Act A law that protects personal privacy and upholds individual’s rights Anyone who handles personal.
Data Practices in Minnesota December Outline for this presentation Minnesota data practices laws Classification of government data Government entity.
Introduction to Information Governance (IG) Mark Scallan – Head of IG/Data Protection Officer Angela Kaye – IG Officer.
Standard Circular 57 The purpose of this circular is to clearly set out the responsibility of educational establishments and services in the matter of.
? Moral principles of right and wrong Used by individuals/organisations To guide behaviour.
Safeguarding Adults Care Act 2014.
Information Security January What is Information Security?  Information Security is about the physical security of our equipment and networks as.
1 Information Governance (For Dental Practices) Norman Pottinger Information Governance Manager NHS Suffolk.
FGM Mandatory reporting Debbie Raymond December 2015.
To Learn & Develop Christine Johnson Lead Nurse Safeguarding (named nurse) - STFT Health Visitors Roles and Responsibilities in Domestic Abuse.
Quality Assurance Lincolnshire County Council Provider Forum Handout 2010.
Introduction to Data Protection Plan »Brief Introduction to Data Protection  Example  Principles  P3, 4, 7  Sensitive Data  Conditions for Processing.
Information Governance A refresher for all staff who have previously gone through the full course.
Consent, Capacity and Confidentiality
Data Protection and Confidentiality
And the finer details of patient privacy
The Safeguarding Adult’s Course Level Two
Data Protection Session
Child protection.
HIPAA Basic Training for Privacy and Information Security
Data Protection Scenarios
Incident Reporting Webinar Begins at 12.30
INFORMATION GOVERNANCE
MyHR and Data Protection
Records management and data security
Ranch meeting Thursday 17th November 2016
How to Find Your Way Around…
Safeguarding Update for Pharmacists
Move this to online module slides 11-56
Information for Patients Please return to reception
How we use Your Health Records
D3 Confidentiality.
Consent A brief to the Patients.
Understanding Data Protection
How to find your way around …
How to find your way around …
Move this to online module slides 11-56
Handling information 14 Standard.
GDPR Information and Consent
Privacy and Security Basics Training
Presentation transcript:

INFORMATION GOVERNANCE Awareness for Acute Services Staff

WHAT IS INFORMATION GOVERNANCE? Caldicott Confidentiality Data Protection Data Quality Freedom of Information Information Security Records Management

OBJECTIVES Refresher on data protection and confidentiality Legal obligations Keeping information safe Reporting Breaches NHSGG&C policies and procedures

WHAT IS DATA PROTECTION? “DATA PROTECTION IS CONCERNED WITH THE SAFEGUARDING / PROTECTING OF PERSONAL IDENTIFIABLE DATA, WHETHER IT RELATES TO PATIENTS, STAFF OR OTHERS”

RESPONSIBILITY FOR DATA PROTECTION The Information Commissioner’s Office is responsible for ensuring organisations comply with the Act. They can: Impose monetary fines of up to £500,000 Audit health boards – inspect and confiscate files Interview staff Prosecute and/or fine individuals Impose other sanctions

8 PRINCIPLES

Principle 6: What Can People Access? Health / Occupational Records Personnel File Payroll Information Complaint / Grievance Files Datix Reports Emails Witness Statements

QUIZ Your Aunt phones and asks if you can check when her appointment is due. You check Trak and tell her. Is this appropriate? You are worried about a recent hospital appointment you attended and when you are back at work you have a look at Clinical Portal to Portal to check your information. Is this appropriate? Can you use unencrypted USB memory sticks within the Health Board?

WHO IS RESPONSIBLE? Everyone! Legal Obligation Terms of Employment NHS Scotland Code of Practice Policies and Procedures

HOW DO BREACHES HAPPEN? Faxing/Emailing information to the wrong recipient Theft/Loss of files, notes or papers Theft/Loss of IT equipment Posting information about patients on social networking sites Inappropriate access to information (eg. your own, family etc)

BREACHES The Individual The Organisation The staff member responsible A breach of confidentiality can have serious consequences for: The Individual The Organisation The staff member responsible

INFORMATION COMMISSIONER Over 50 organisations have been fined between £1,000 - £325,000 Ministry of Justice fined £180,000 Crown Prosecution Service fined £200,000 Glasgow City Council fined 150,000 Belfast Health & Social Care Trust fined £225,000 Pharmacist fined for unlawfully accessing family, colleagues and friends health records. Dismissed from her post Total money received in penalties over 5.5 million

NHSGGC Breaches Two letters to GP sent to one of the patients with same surname as GP Two referrals from another HB sent to one of the patients in error – contained sensitive clinical history Letter to GP re patient and fertility treatment sent to Dentist in error Doctor left patient files at bus stop – handed into RAH by member of the public Nurse left 15 patient files in car boot over weekend – car stolen and files never retrieved Patient letters found in hospital grounds from burst bag

SCENARIO In the course of your working duty, you see someone who is known to you attending an outpatient clinic. You then go home and discuss this with family/friends. Have you breached your duty of confidence?

Further guidance available in Data Breach Policy REPORTING BREACHES All ACTUAL, SUSPECTED or POTENTIAL breaches should be reported using the Datix system as soon as possible. This should be done as soon as the breach occurs Inform your line manager If IT equipment is missing/stolen – report to Police and IT Service Desk If appropriate, also inform the Information Governance Department Further guidance available in Data Breach Policy

POLICIES AND GUIDELINES Search for Information Governance Framework on Staff Net

CONTACT DETAILS Simone Rattray, Data Protection Advisor Email: simone.rattray@ggc.scot.nhs.uk Tel: 0141 355 2059 Isobel Brown, Information Governance Manager Email: Isobel.Brown@ggc.scot.nhs.uk Tel: 0141 355 2020 Or: dataprotection@ggc.scot.nhs.uk