Friday, 9 December 2011

Protecting patient data - essential for you...and your organisation


With changes planned to the way in which health care commissioning is undertaken and with an increasing diversity of health care providers, the Department of Health (DoH) have signalled the intention that the NHS and the Information Commissioning Office (ICO) will work together to ensure delivery of good information governance.

The ICO is clear that health care staff should be more aware of data security, particularly as it is central to what they do. They report a disconnect between the awareness of staff to protect the patient information that is entrusted to them and the number of breaches that occur. An example of such a disconnect is illustrated by the Dartford and Gravesham trust which inadvertently destroyed 10 000 health care records which had been stored in a destruction room because the archive room had been full. Acton was taken against the trust.

According to the ICO, human error is not an excuse for the loss of data. It is a systemic problem. Too often people rely on technical solutions for their data security. It is much more, extending to the organisations themselves, how they operate, and the standards they set.

The IG toolkit is acknowledged as the bench mark standard for assuring good information and data security management. The Information Governance Board - which is set to become part of the Care Quality Commission (CQC) in 2013 under proposals in the health and social care bill - acknowledges that people have difficulties with some of the complexities of the tool kit and it was working on transitional guidance to help healthcare professionals with the changes to the NHS.

With the ICO now able to impose penalties of up to £500 000 for serious breaches of the Data Protection Act and against a background of more than 800 reported data breaches over 3 years attributable to nhs staff - 1 in 8 breaches reported by health care service organisations resulted in staff dismissals - then it is worth making sure that you have robust data security systems built around a sound information governance structure in place.

And so if you need support with your information governance framework? Speak to one of WWR's IG experts today.

The importance of Data Sharing codes of practice


Whilst data sharing contributes effectively to providing efficient services to both private and public sector users it is not appropriate for companies and public bodies to do this without due attention to the need of the public right to remain in control of who is using their information and for what purpose the information is being used. As a consequence of this public right and in order to help businesses and public bodies share people’s personal information the Information Commissioner’s Office (ICO) have provided a code of conduct that includes good practice on how best to achieve this.

Data sharing, in terms of the ICO’s code of conduct, refers to the disclosure of personal data between or within organisations. This should be carried out with due regard to the Data Protection Act and other considerations such as statutory prohibitions on sharing or a duty of confidence. In circumstances where a duty of confidence applies or is expected - for example medical or banking information - then legal advice will need to be taken. Examples of the sharing of personal data includes;

· a GP sending information about a patient to a local hospital

· a local authority disclosing personal information about its employees to an anti – fraud body

· a retailer providing customer details to a payment processing company

It is important to note that there are differences in the rules that apply to the sharing of data in public sector organisations – which have common law powers to share information – and private organisations which must comply fully with the data protection principles and any specific legal constraints. However, in genera,l these are found not to be too restrictive.

Regardless of whether the sharing of personal data is relevant to a public or private organisation it is important to have strong governance rules which are fully transparent and understood by all parties. A key governance control in achieving this is the data sharing agreement (some times referred to as a data sharing protocol). This sets out a common set of rules binding all the organisations involved in the data sharing agreement and should typically address issues such as :

· purpose of the data sharing initiative

· the organisations that will be involved in the data sharing

· the data items to be shared

· the basis of sharing

· information governance compliance

With the changes to the commissioning of health care provision and the increase in complexity and diversity of health care providers then the need to share personal data between and within the commissioning and provider communities will undoubtedly offer significant challenges. Essential to meeting these challenges is the existence of good information governance framework.

If you need support in achieving this then speak to one of the WWRL information governance experts today.

The Care Quality Commission - is it as bad as it seems?

Does the Care Quality Commission (CQC) deserve all its recent criticisms? Does it actually perform against its own regulatory targets? Well, not according to the National Audit Office (NAO) which asserts that “there is a gap between what the public and providers expect of the CQC and what it can achieve as a regulator”.

Whilst a value for money debate, linked to under spends against a reduced budget target ensues, can the CQC claim any successes? It certainly has had an uphill struggle bringing together 3 existing regulators and implementing a new regulatory approach which for the first time integrates health and social care services. However as the CQC points out it has over 700 inspectors actively speaking to patients and staff and observing care. When necessary it forces providers to take action if they are not meeting essential standards of quality and care whilst registering over 40, 000 provider locations against tight timescales.

In evidencing its improving performance the CQC points out that “In October alone, we conducted more than 1,400 unannounced inspections. In the last three months we have recruited and trained over 100 additional inspectors. Our national report on our Dignity and Nutrition inspection programme – looking at the care older people receive in 100 acute hospitals – was published in October. The response it received from the public and the NHS demonstrates just how effective our regulatory system can be”

Further evidence of the CQC’s influence in improving standards of care can be seen in its report against a dental practice not meeting essential standards of care - the first dental provider to have been identified as such following the recent introduction of this group of providers to fall under the CQC regulatory system. Similarly, the investigations into the Barking, Havering and Redbridge hospital has identified serious failings across the organisation, whilst the CQCs second report into the use of the Mental Health Act has found that care for people treated under the Act needs to improve further.

With further inspections and unplanned visits throughout 2012 planned the CQC recognises that whilst everything may have not gone smoothly , lessons have been learned and changes made following the inevitable reviews. This has led it to assert that ‘we are now firmly on the right track and making rapid progress’

As its Chief Executive says, the CQC “are absolutely dedicated to protecting those who use health and social care services” – 2012 may well be the year when the CQC gains some yearned for credit and positive acknowledgment.

CQC could improve in it's delivery of value for money services


Care Quality Commission could improve in it’s delivery of value for money services -the National Audit Committee makes recommendations on how the CQC can improve it’s performance

The work of the Care Quality Commission (CQC) has been the subject of considerable public interest during recent months triggered by a number of high profile incidents including;

· a BBC Panorama programme in May 2011 which exposed abuse of patients in a residential hospital looking after people with learning disabilities

· the closure in July 2011 of Southern Cross, the largest care provider in the UK

· the examination of the commissioners role in the Mid Staffordshire NHS Trust which is currently subject to a public enquiry

· the Commissions reports published in October 2011 on dignity and nutrition in NHS hospitals and its investigation in to the Barking, Havering and Redbridge NHS trust

Against this backdrop of public interest the National Audit Office (NAO) undertook to examine how the CQC has used its resources in carrying out its quality and safety assurance work.

Whilst recognising that the difficulties face by the CQC in bringing together the work of three organisations in to in a new model of regulating health and adult social care the NAO noted that the public expectations of the CQC are high and whilst its responsibilities are clearly defined they have not always been effectively communicated. This has led the head of the NAO to observe that “There is a gap between what the public and providers expect of the Care Quality Commission and what it can achieve as a regulator. The Commission and the Department of Health should make clear what successful regulation of this critical sector would look like."

The NAO noted that the ultimate measure of the CQCs value for money is the impact of its regulation on the quality of safety of care. In the absence of measures of impact the CQC assessed value for money in terms of delivery against what the CQC set out to deliver in terms of quality and safety assurance and concluded that, in the majority of cases, the CQC did not meet its deadlines. The NAO also commented that the responsibility for funding the CQCs regulatory activities is falling increasingly on the providers of the service rather than by the Department of ealth Health, with TH

Health and that it is moving towards full cost recovery.

To it’s credit the CQC has welcomed and acknowledged the findings and comments of the NAO’s examination and reaffirmed it’s dedication to protecting those who use the health and social care services. In so doing it will continue to take steps to improve its performance including those recommendations of the NAO findings which include;

· making clear what success looks like in terms of measurable outcomes

· addressing shortcomings in its performance management arrangements

· drawing on previous registrations to develop detailed plans for registering GP practices

· better support and inform its compliance inspectors to help them make sound and consistent judgements

· review the effectiveness of its whistle blowing arrangements

· assess the viability and resource impact of extending the its role

Words Worth Reading Ltd can help take the hassle out of your CQC registration and compliance?