Dear NHS England,

Recommendation 1 of the Information Governance review (Caldicott 2) requested the Department of Health & the NHS Commissioning Board to drive a clear plan f or implementation of the recommendation (to make audit trails available).

Please provide a copy of the plan,or if not available yet of any minutes referring to progress on development (or abandonment) of such a plan.

Yours faithfully,

Alan Bunn

FOI England (NHS ENGLAND), NHS England

Dear Mr Bunn,

Thank you for your Freedom of Information (FOI) request, dated 21 April 2016.

Please be assured that your request is being dealt with under the terms of the Freedom of Information Act 2000 and will be answered within twenty working days.

If you have any queries about this request or wish to contact us again, please email [NHS England request email] and the message will be forwarded appropriately. Please remember to quote the above reference number in any future communications.

Please do not reply to this email. This message has been sent from a central mailbox. To communicate with NHS England regarding Freedom of Information (FOI) requests, enquiries or complaints we ask these are sent directly to NHS England’s customer contact centre. This is to ensure all communications are progressed correctly. Their postal address, telephone number and email details are as follows:- PO Box 16738, Redditch, B97 9PT; 0300 3 11 22 33, [NHS England request email] .

Yours sincerely,

Freedom of Information
Corporate Communications Team
Transformation and Corporate Operations Directorate

NHS England
PO Box 16738
REDDITCH
B97 9PT

Tel: 0300 311 22 33
Email: [NHS England request email]

show quoted sections

FOI England (NHS ENGLAND), NHS England

Dear Mr Bunn,

 

Re:      Freedom of Information request (Our Ref – FOI: 010561)

 

Thank you for your Freedom of Information (FOI) request dated 21 April
2016.

 

Your exact request was:

 

“Recommendation 1 of the Information Governance review (Caldicott 2)
requested the Department of Health & the NHS Commissioning Board to drive
a clear plan f or implementation of the recommendation (to make audit
trails available).

 

Please provide a copy of the plan, or if not available yet of any minutes
referring to progress on development (or abandonment) of such a plan.”

 

NHS England holds some information relevant to your request.

 

We have liaised with the relevant departments within NHS England and are
in a position to provide the following.

 

There is no plan or minutes relating to this recommendation.  However, NHS
England has ensured that several mechanisms are in place including the
Information Governance Toolkit ([1]https://www.igt.hscic.gov.uk/) and the
Serious Incidents Requiring Investigation process
([2]https://www.igt.hscic.gov.uk/KnowledgeBa...)
 to meet the commitments made as described on page 48 of the Information:
To Share or not to Share Government Response to the Caldicott Review
paper.  

Access to audit trails is promoted through different routes (see below).
 To ensure patients are aware, regardless of whether they request it or
not, of improper access to their data the Serious Incidents Requiring
Investigation (SIRI) process is initiated when a breach is identified
which ensures that the patient is notified of the issue and given details
of what has occurred.  Improper access is defined as an incident which
breaches the Data Protection Act (DPA) for that patient.  The SIRI
incident process also ensures that the Department of Health and
Information Commissioners Office is notified of the breach and can take
further action, if appropriate.

Patient led access to their own audit data is driven through the IG
Toolkit (version 13) - it requires health bodies to ensure they follow
certain the requirements including those set out below:

·         Patients, service users and the public understand how personal
information is used and shared for both direct and non-direct care, and
are fully informed of their rights in relation to such use

 

·         There are appropriate procedures for recognising and responding
to individuals’ requests for access to their personal data

·         Staff access to confidential personal information is monitored
and audited. Where care records are held electronically, audit trail
details about access to a record can be made available to the individual
concerned on request

This ensures that patients are aware of their rights as regards their
data, that there is a process in place for patients to gain their data and
that patients right to request their audit data is recognised. 
Organisational responses to the IG Toolkit are monitored by the Health and
Social care Information Centre (HSCIC) (www.hscic.gov.uk) who can take
control action as appropriate. Most GP practices have systems that can
offer this functionality (although not all will currently have this
ability enabled).

Copyright: NHS England operates under the terms of the open government
licence. Please see the NHS England Terms and conditions on the following
link [3]http://www.england.nhs.uk/terms-and-cond...

We hope this information is helpful. However, if you are dissatisfied, you
have the right to ask for an internal review by writing to us, within two
months of the date of this letter, to:

 

NHS England

PO Box 16738

REDDITCH

B97 9PT

 

Email: [4][NHS England request email]

 

Please quote the reference number FOI: 010561 in any future
communications.

 

If you are not content with the outcome of the internal review, you have
the right to apply directly to the Information Commissioner for a
decision. The Information Commissioner’s Office (ICO) can be contacted at:

 

The Information Commissioner’s Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

 

Telephone: 0303 123 1113

Email: [5][email address]  

Website: [6]www.ico.gov.uk

 

Please note there is no charge for making an appeal.

 

Please be aware that in line with the Information Commissioner’s directive
on the disclosure of information under the FOI Act, your request will be
anonymised and published on our website as part of our disclosure log.

 

Please do not reply to this email. This message has been sent from a
central mailbox. To communicate with NHS England regarding Freedom of
Information (FOI) requests, enquiries or complaints we ask these are sent
directly to NHS England’s customer contact centre. This is to ensure all
communications are progressed correctly. Their postal address, telephone
number and email details are as follows:- PO Box 16738, Redditch, B97 9PT;
0300 3 11 22 33, [7][NHS England request email].

 

 

Yours sincerely,

 

 

Freedom of Information

Corporate Communications Team

Transformation and Corporate Operations Directorate

 

NHS England

PO Box 16738

REDDITCH

B97 9PT

 

Tel: 0300 311 22 33

Email: [8][NHS England request email]

 

show quoted sections

References

Visible links
1. https://www.igt.hscic.gov.uk/
2. https://www.igt.hscic.gov.uk/KnowledgeBa...
3. http://www.england.nhs.uk/terms-and-cond...
4. mailto:[NHS England request email]
5. mailto:[email address]
6. http://www.ico.gov.uk/
7. mailto:[NHS England request email]
8. mailto:[NHS England request email]

Looking for an EU Authority?

You can request documents directly from EU Institutions at our sister site AskTheEU.org . Find out more .

AskTheEU.org