DATA PROTECTION ISSUES Dr Julian Brown. Diabetes Manager – Caldicott 1  Justify the Purpose  Developed for three reasons:  My Diabetes Patients were.

Slides:



Advertisements
Similar presentations
Information Governance, Love it or Hate it!
Advertisements

Organisation Of Data (1) Database Theory
Introduction to Information Governance (IG)
Information Governance Peter McKenzie Information Governance Manager NHS Tayside
Information Governance – Who Cares? Alistair Stewart Information Governance Co-ordinator.
Quick Guide to Undertaking an Information Governance Compliant Clinical Audit Project Wendy Harrison and Heather Sharp NHS Bradford and Airedale.
Sharing information to improve patient care in West Sussex Adrian Woolley Head of Strategic IT NHS Coastal West Sussex CCG NHS Crawley CCG NHS Horsham.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
NAU HIPAA Awareness Training
Confidentiality & Records Management. What is Information Governance? What is Records Management?
Patients Association – Our Strategy Rosalynd JowettTrustee The Patients Association.
Revised Caldicott Manual- Practice Managers Groups Revised Caldicott Manual – November 2008.
GP Information Hub in Trafford Briefing for GPs January 2009.
Data Linkage Service Garry Coleman, Health and Social Care Information Centre.
Warrington CCG Population Health Jason DaCosta - Warrington CCG.
Medical Reports Dr. Nasser Al - Jarallah.
Property of Common Sense Privacy - all rights reserved THE DATA PROTECTION ACT 1998 A QUESTION OF PRINCIPLES Sheelagh F M.
Moving Forwards with HealthSpace Gillian Braunold Clinical Director Summary Care Record & HealthSpace.
Mental Health Survey 2015: Webinar 14 th January 2015.
DATA PROTECTION AND PATIENT CONFIDENTIALITY IN RESEARCH Nic Drew Data Protection Manager University Hospital of Wales   
Glucose Monitoring Ceri Jones March Benefits of Glucose Monitoring   Improve glycaemic control?   Empowerment  Hypoglycaemia?  Intercurrent.
Audit of Practice Around Record Keeping and Partner Notification Maeve Cross & Martin Murchie.
Practical Information Management
Your GP record and working together Dr Duncan Gooch and Tom Atack.
Implementation of Security and Confidentiality in GP Practices.
Health & Social Care Apprenticeships & Diploma
Business Continuity and Pandemic Flu Planning
Scottish Health Informatics Programme (SHIP)
Care.data: listening to you Robin Burgess Regional Head of Intelligence
Patient Group Meeting 3 September WORDS OF WISDOM TELL ME – I WILL FORGET SHOW ME – I WILL REMEMBER INVOLVE ME – I WILL UNDERSTAND.
Falkland Surgery Data Sharing 16 th July 2013.
Emergency Care Summary SCIMP Conference - Dunblane 7 th November 2007.
GEOG3025 Confidentiality and social implications.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Dr. Ihab Nada DOE, MSKMC.  The information a patient reveals to a health care provider is private and has limits on how and when it can be disclosed.
Copyright © 2009 by The McGraw-Hill Companies, Inc. All Rights Reserved. McGraw-Hill Chapter 6 The Privacy and Security of Electronic Health Information.
The NHS Summary Care Record Supporting person centred coordinated care Sep 2015 v0.11.
Care.data: listening to you Andrew Chronias Regional Head of Intelligence NHS England (South)
FGM – THE ENHANCED DATASET DR EMMA TUKMACHI LEAD GP FOR SAFEGUARDING CHILDREN IN TOWER HAMLETS.
ICT in Healthcare. Electronic prescription service GPs and nurses can send electronic prescriptions to a dispenser (pharmacy) of the patients choice.
CALDICOTT PRESENTATION. History Caldicott report published in 1997 and implemented in 1999 Inquiry chaired by Dame Fiona Caldicott.
Your health record How the local NHS uses and protects the information held about you Other ways that your records may be used Your local NHS services.
Access to data for local authority public health AGW Public Health Network Training Event: Public Health Data, Information and Intelligence 11 th November.
PO :Physical Therapy Administration. Learning Objectives The physical therapy technician will participate as a member of the physical therapy administration.
This leaflet explains the purpose of Berkshire West Connected Care and how it works. It also gives information to help you decide whether you want to opt.
STRICTLY CONFIDENTIAL © Telehealth Solutions Dr Julian Neal Senior Partner Portsdown Group Practice Telehealth: The Future for Primary (and all) Healthcare.
By Dr Rukhsana Hussain 2011 Confidentiality GMC guidance.
Computer Laws Data Protection Act 1998 Computer Misuse Act 1990.
INFORMATION GOVERNANCE AND CONFIDENTIALITY Information Governance Facilitator.
Sometimes you have to be the worst to become the best?  2006: My Region was highlighted as having significantly high admissions for diabetes.  Our performance.
Dr Michelle Webb Renal Consultant, Associate Medical Director Patient Safety, East Kent Hospitals University NHS Foundation Trust and Co-lead for Sepsis.
Online Data Storage Companies MY Docs Online. Comparison Name Personal Edition Enterprise Edition Transcription Edition Price $9.95 monthly rate $4.99.
Amber: patient’s needs changing/condition deteriorating Social situation has potential to breakdown Discharged from alternative care within 2 weeks Patient.
HOW AN INTELLIGENT DEVICE CAN CUT THE MUSTARD Dr Julian Brown.
Information Governance A refresher for all staff who have previously gone through the full course.
Adastra v3 Reporting & National Quality Requirements
Data Protection and Confidentiality
Safeguarding Update for Pharmacists
General Data Protection Regulation
Information for Patients Please return to reception
Barts Health Trust 2WW Colorectal Workshop Dr Angela Wong,
Recording Clinical Data
How we use Your Health Records
D3 Confidentiality.
care.data: listening to you
Recording Clinical Data
Recording Clinical Data
HIPAA Overview.
Empowering Members to Know Your Health & Own Your Health.
Driving when you have Diabetes
Presentation transcript:

DATA PROTECTION ISSUES Dr Julian Brown

Diabetes Manager – Caldicott 1  Justify the Purpose  Developed for three reasons:  My Diabetes Patients were not getting the information they needed to optimise their care.  Integrated Care was not happening in my PCT  Patients at risk were not being picked up in both my surgery and in my PCT (I have been Prescribing Lead since 2006)  Diabetes Manager will improve Patient Care, Reduce waiting times, Improve Education, Empower the Patients and Save Lives.

Diabetes Manager – Caldicott 2  Don’t Use Patient Identifiable Data Unless Absolutely Necessary.  Every Other Patient Summary Records Uses PID  This is not acceptable for any cloud based technology.  It is not necessary.  No Patients Names, Addresses, Telephone Numbers, NHS numbers are stored on our Remote Server. NHSpatient.org was Carefully Created to allow maximal integration of care whilst protecting the privacy of the Patient.

Diabetes Manager – Caldicott 3  Use the minimum necessary patient-identifiable information.  No Name, DOB, Address, Telephone Number, , Hospital Number  After Discussion with GPs, Diabetes Consultants, Diabetes Nurses and Patients:  All conditions Read Codes  All medications  All Blood Results  Patient’s Treatment Plan  Risk Alerts  Users with Access to the Patients Record

Specific Concern  I don’t think you can justify extracting someones HIV status/sexual history etc (for a DM project) “because we might use it for other CDM in the future.”  Diabetes affects or is affected by most conditions.

SPC sheets Kaletra (lopinavir)  Special Warning – “Hyperglycaemia”  “New onset diabetes mellitus, hyperglycaemia or exacerbation of existing diabetes mellitus has been reported in patients receiving protease inhibitors. In some of these the hyperglycaemia was severe and in some cases also associated with ketoacidosis. Many patients had confounding medical conditions some of which required therapy with agents that have been associated with the development of diabetes mellitus or hyperglycaemia.”  Blood Glucose Elevation reported as common

SPC Norvir (ritonavir)  Special Warning  Diabetes mellitus and hyperglycaemia: New onset diabetes mellitus, hyperglycaemia or exacerbation of existing diabetes mellitus has been reported in patients receiving protease inhibitors. In some of these the hyperglycaemia was severe and in some cases also associated with ketoacidosis. Many patients had confounding medical conditions, some of which required therapy with agents that have been associated with the development of diabetes mellitus or hyperglycaemia

SPC Atripla (efavirenz,emtricitabine,tenofovir)  Boxed Special Warning  “Lactic acidosis, usually associated with hepatic steatosis, has been reported with the use of nucleoside analogues. Early symptoms (symptomatic hyperlactataemia) include benign digestive symptoms (nausea, vomiting and abdominal pain), non-specific malaise, loss of appetite, weight loss, respiratory symptoms (rapid and/or deep breathing) or neurological symptoms (including motor weakness). Lactic acidosis has a high mortality and may be associated with pancreatitis, liver failure or renal failure. Lactic acidosis generally occurred after a few or several months of treatment.”  Common SE “Hyperglycaemia”  Interacts with Statins

Diabetes Manager – Caldicott 4  Access to PID should be on a strict need to know basis.  Only those that need it.  Only have access to the information they need.  PID!  Access Controls  2 factor authentication  Data Splitting  Read Code Filtering  Complete log file of who accessed who at what time.

Diabetes Manager – Caldicott 5 Everyone with Access to PID should Be aware of their responsibilities:  Within Our Organisation.  Within the Hosting Company.  Within Your Organisation.  Only Steven and James have access to the database which contains no PID.  Your Data will be stored a maximum security UK server. (the bunker.net) with full ISO27001 governance.

Diabetes Manager – Caldicott 6  Understand & Comply With the Law  Diabetes Manager, Eclipse Solutions and NHSpatient.org all comply with the Date Protection Act, NHS regulations and the NHS confidentiality code of practice.  Many alternative programs do not

Extra Issues - 1  Patients that Have signed out of the NHS Spine will not have any data extractions.  There is an ability for these patients to sign back in using a specified read code.

Data Should be Hosted Securely  ISO27001  24 hour security  Nuclear Bunker  NHS Approved  Proven Track Record  Stand Alone Server  content/uploads/2013/02/casestudyCimarFINAL.pdf

Should Be Excellent Disaster Recovery  SAN Hard Drives  Industrial Level Servers  Onsite Back up  24 hour support  Continual Automated Tracking

Clear Data Protection Statements  We look after your Patient’s data securely and reliably.  Your GPs have complete governance over who has access to data relating to their patients.  Phase 2 will allow patients to control this.  No data is passed onto third parties without permission.  Currently most GP systems already do this.

Projects with Third Parties  NHS England – David Cousins, David Garrett and Professor Tony Avery (Patient Safety Project)  Cambridge Cancer Research Network.  Imperial College Global Research Unit (Sir Tom Hughes-Hallett)  Opt in only

Projects with Pharmaceuticals  Essential for the future of R&D  Anonymised Data Only.  Can create significant revenue for the Practices and the CCG.  Similar Principles to Dispensing.  Opt in only.  The aim is to have IT creating revenue for your organisation whilst improving patient care not utilising it.

Data Integration  It is essential that any IT databases utilised by the NHS can be used by standard equipment and integrate with secondary databases.  Diabetes Manager links with:  Prescribing Data  Referral / Admission Data  Blood Glucose Meters  BP machines.

Data Integration needs to be Accurate  Link through Patient Card  N3 Server integration  Links hospital number and nhspatient.org number  Allows secure mapping in restricted environment.  Allows removal of PID from admissions data whilst maintaining audit.  Needs Secondary Consent