Community Pharmacy Summary Care Record (SCR) Privacy Officer End-user.

Slides:



Advertisements
Similar presentations
AmeriCorps is introducing a new online payment system for the processing of AmeriCorps forms
Advertisements

Shared Space Admin Demo March Admin demo introduces - Adding users Moderating users Moderating resources Adding communities and sub groups.
Introduction to the Summary Care Record (SCR) GP Module SCR Concept Training GP Module Self Run v
GP2GP Electronic health record transfer 1. What is GP2GP? GP2GP is a software application that can be used to transfer a patient’s electronic health record.
Document management Rev. Description Author Date 0.0 First draft
Welcome to Online HRS All your Human Resources needs in one easy to follow database system.
Module 4: System Maintenance Intuit Financial Services University Internet Banking Certification Training.
EMIS Web Sorting out RBAC.
1 Welcome To Siebel Training Welcome To Siebel Training.
The PestLens web system:
Maintaining and Updating Windows Server 2008
Mental Health Survey 2015: Webinar 14 th January 2015.
School of Public Health MyAurion - Approve a Timekeeper Form Tutorial & Teaching Support Staff.
Electronically approve and create Suppliers in Oracle Financials using a combination of APEX and Oracle Workflow. NZOUG Conference 2010 Brad Sayer Team.
Implementation of Security and Confidentiality in GP Practices.
Cross Vendor Exchange Testing and Certification Plans April 18, 2013.
On the sites Two websites that provide learning materials and information Enabling Organisations to meet.
Microsoft - Partner Confidential Information PIN number and PIN Ordering February 2012.
Cross Vendor Exchange Testing and Certification Plans April 18, 2013 Meaningful Use Stage 2 Exchange Summit Avinash Shanbhag, ONC.
VHC SP Application - Overview VHC Service Provider Application Training WELCOME.
Standard Operating Procedures Joe Wherton Queen Mary University of London
Parent Guide for staying connected. To Begin using Skyward Family Access you will need:  A computer connected to the internet  A web browser (Windows.
Lead Management Tool Partner User Guide March 15, 2013
Introduction to the First of Type Process. 2 Agenda Introduction to the meeting First of Type Site – What it means? Responsibilities of CFH in FOT process.
Shib-Grid Integrated Authorization (Shintau) George Inman (University of Kent) TF-EMC2 Meeting Prague, 5 th September 2007.
Introduction to the Summary Care Record (SCR)
This PowerPoint has been produced for the public and is made available for non-commercial use (e.g. toolbox meetings,
Training Role Module 8 – User Admin Ver. 10 Oct 2009.
A Sense of Connection Managed Knowledge Networks and You Dr Ann Wales NHS Education for Scotland.
SOCPA Connect Plus Patient Portal. Intro to the Follow My Health Patient Portal.
1 Fertility Scout: User Guide Version 1.0 Purpose: To provide a visual guide of The AFP’s Clinical Finder and Referral Tool.
Get Involved Group Records Sharing to Support High Quality Care Becky Gayler Clinical Informatics Project Manager 17 th September 2014.
Intern Placement Tracking (IPT) Tutorial for Field Instructors Baccalaureate Social Work Program Office of Field Education Assistant Dean of Field Instruction:
Request TEASE Access: SPP 13 or SPP 14 Steps to request access to State Performance Plan SPP 13 or SPP 14 through TEASE ( Texas Education Agency Secure.
STEPS TO REQUEST ACCESS TO SPP 11 AND 12 THROUGH TEASE ( TEXAS EDUCATION AGENCY SECURE ENVIRONMENT) 1 TEASE.
CHMRAT Roll Out th February 2013 Practice Support and Development Officer GNC.
A user guide to accessing, reviewing and contributing to the Online Registry System.
UNCLASSIFIED – For Official Use Only 1 Contract Load Notification “Fly-in” Action ( Continue to Page Down/Click on each page…) Electronic Document Access.
Objectives  Legislation:  Understand that implementation of legislation will impact on procedures within an organisation.  Describe.
Rachel Habergham EPS Programme Head Electronic Prescription Service Moving to Release 2 Michelle Greatrex Senior Implementation Manager Health and Social.
Self Service Admin. Self Service as the name suggests may remind you of food services provided by some big names in the market. So also, Self Service.
V April 2016 Training guide 2 NOTE: All screen shots from Communicare indicate PCEHR. Any reference to the PCEHR or the My Health Record within this.
FHA Training Module 1 This document reflects current policy related to this topic. Its content is approved for use in all external and internal FHA-related.
Collecting Copyright Transfers and Disclosures via Editorial Manager™ -- Editorial Office Guide 2015.
Documentation Requirements for Hospital Accreditation -By Global Manager Group.
Session 3 -2 Session 3 FAA Access to CPS Online – Designed for Efficiency.
Maintaining and Updating Windows Server 2008 Lesson 8.
The research ethics review process Hazel Abbott, Chair University Research Ethics Committee.
7 Day Self Assessment Tool (7 Day SAT) March 2016 Survey - User Guide v4 (March 2016)
Microsoft Customer 2 Partner Connector Quick Reference Guide
Response to an Emergency Training for 211 Staff in Ontario Updated September
On the sites Two websites that provide learning materials and information Enabling organisations to meet.
Communicare Presentation v March 2016 NOTE: All screen shots from Communicare indicate PCEHR. Any reference to the PCEHR or the My Health Record.
REDCap General Overview
Project Management: Messages
Software Application Overview
Accessing the Enterprise reporting service (ers) application
Shared Space Admin Demo
Briefing Session Guide
Information Governance
Click on My Team to open your My Team page.
Information for Patients Please return to reception
GDPR (General Data Protection Regulation)
Getting Started with UCSF Chatter
Confidentiality Policy
This presentation document has been prepared by Vault Intelligence Limited (“Vault") and is intended for off line demonstration, presentation and educational.
Let’s talk EPS “Developing the best way forward for practices and pharmacy to maximise EPS”
Lincolnshire Care Portal David Smith MSc, MBCS CITP (STP Lead Officer for ICT) Liz Jones (STP Project Manager for ICT) Care Portal Youtube.
National data opt-out - Preparing for implementation
For Service Coordinators
Presentation transcript:

Community Pharmacy Summary Care Record (SCR) Privacy Officer End-user

This Privacy Officer module: Is designed for all staff with the responsibility of monitoring alerts and auditing viewing activity in community pharmacy Summarises how to monitor alerts and audit viewing activity Suggests some best practice to help Introduction

Creation of an SCR: Patient can opt out or in at any time as often as they like Viewing SCRs: The patient asked permission to view before health professional can access their SCR Emergency Access is available to some users if permission cannot be obtained e.g. the patient is unconscious or confused Alerts can be generated when SCR is used A Privacy Officer needs to monitor these alerts Consent and Patient Choice Recap

The Privacy Officer role can be: Specifically for the purpose of SCR; or Incorporated into the existing IG function of an organisation The Privacy Officer should: Receive alert notifications Investigate alerts e.g. matching a self claimed LR alert to the local record of patient care (PMR) or identifying unusual patterns of Accesses Escalate inappropriate accesses Ensure local IG processes incorporate SCR viewing activity e.g. Information Governance Policy, Confidentiality Policy Privacy Officer Role and Responsibilities

Alerts will be generated when a pharmacy staff member views an SCR and that action needs to be verified and/or investigated Alerts will identify the patient whose record has been viewed, the user that has viewed the record and the site the access occurred The following actions will generate an alert:  Use of clinician self claimed LR  Use of Emergency Access Alert Generation

When an alert is generated, a notification will be created and sent to the person responsible for monitoring the alerts These notifications can be switched off and reports should be run instead on a regular basis for monitoring and investigation The tool for monitoring and managing alerts is called the Alert Viewer Each organisation must ensure that they have a nominated responsible officer (normally the Privacy Officer), with the correct RBAC on their smartcard, to access this tool and manage the alert process Monitoring Alerts

Subject: Alert Notification urn:nhs:names:services:lrs: Create LR (Self Claimed) alert on 19-Jun :33:20 by This will be the site code Alert Id: 7E07F1A7-A924-4FF1-B8A9-D44FFA4FCB72 This message is sent automatically based on information held on the Spine. To stop receiving alerts, please contact your local Spine administrator. Please do not reply to this . Alert Notification Text

Notification in Alert Viewer alerts can only be received be s with the following @police.uk

Alert Types All of the alert types will need to be managed but some are more common than others How they will be managed will be decided by the local organisations IG policies and procedures

Regular locums should have the sites ODS code assigned to their smartcard Irregular Locums will have a generic code on their smartcard (FFFFF) What ever type of access they perform they (irregulars) should record the site ODS code into the comments box This can then be cross checked with that days staff logs Locum Accesses

Comments Box

Some privacy officers will be responsible for multiple sites Within the alert viewer there is a facility to search for different ODS codes that are allocated to that Privacy Officer Multiple Sites

Investigating Alerts IG alerts can be viewed using the Alert Viewer which enables: The recording and storage of IG alerts with the capability to search, view and close alerts The generation of IG alert notifications Alert Viewer is accessed using the Spine Portal or directly from the desktop Access is granted as part of the Privacy Officer RBAC role

Organisations are responsible for auditing accesses to their records and for providing responses to queries from patients requesting details of who has accessed their record Required by Care Record Guarantee Reconciling accesses

Business processes are needed for the Privacy Officer to define how to investigate alerts The following activities need to included in these processes: –Receiving notifications or running reports –Investigating alerts e.g. matching a self claimed LR alert to the local record or identifying unusual patterns of accesses –Escalating inappropriate accesses to relevant parties –Closing and updating the alert status Example Business Processes for POs

Example Business Process

Suggested SOP No. pharmacies the PO is responsible for which will be audited each period? All50%10%5% Frequency of review?WeeklyMonthlyQuarterly Time period reviewed?Every weekRandom monthsRandom weeks Random days Number of alerts/accesses checked against pharmacy records for the given time period reviewed? All50%Random sample None Source information for reconciling access from pharmacy? Entry on PMRSigned consent formEitherN/A Regular use of suspicious behaviour reports: time access made, no. accesses per patient/user? 6 monthlyQuarterlyMonthly

Demonstrations are available for the following: Alert Tools Demonstration Search, Update & Close Subject Access Request SCR Access Report

NHS organisations are responsible for auditing accesses to their records and for providing responses to queries from patients requesting details of who has accessed their record Required by Care Record Guarantee In order to run audit reports for SCR viewing activity, Privacy Officers can use: –The Spine Reporting Service (SRS) if the viewing system was SCRa (accessed via the Spine Portal) –Reports on the host system if the viewing system was an integrated solution e.g. Adastra or Ascribe Symphony Auditing SCR Activities

A subject access request (SAR) as defined by the Data Protection Act 1988, is when a patient wishes to know who has looked at their information in that organisation. Not many patients make a SAR. Very Rare. Normally these are received via the organisations Caldicott Guardian or IG manager In the event that the PO can see multiple sites information should only be provided on the organisation/sites that the PO is responsible for Audit Reports - Subject Access Requests (SAR)

When the viewing system is SCRa, various reports are available including: Users that have accessed a specific record Records accessed by a specific user Transaction detail report SCR Access Report Access is granted as part of the Privacy Officer RBAC role Audit Reports - Other types

Privacy Officer S8002 : G8003 : R0001 Admin and Clerical : Admin and Clerical : Privacy Officer Activities : B Receive Self Claimed LR Alerts B Receive Legal Override and Emergency View Alerts B0018 – Receive Seal alerts Privacy Officer RBAC Role

SCR IG Pages Alert Viewer user guide Authentication and Role Based Access Control y/raoverview Additional Information

Connect with us Web: Prezi: User Demo Sign up to the SCR bulletin: