Executive Summary
A fair processing strategy is needed to support Chester le Street Health Limited in meeting the legal requirement for fair processing of personal and confidential information by organisations involved in commissioning and providing care in an extremely complex organisational and operational environment.
The use of patients’ data is a vital part of the delivery of care and commissioning process. Providing information to the public is integral to the provision of care and the commissioning cycle. It is also an important part of the overall engagement with a health economy of a commissioner as part of their public participation and involvement.
The strategy is also needed to ensure that both the company and staff are clear about their legal and professional obligations.
Background
This document sets out the Chester le Street Health Limited Fair Processing Strategy for direct and indirect care uses of personal and confidential data.
Scope
Fair Processing describes the circumstances and communication for patients and the public required when personal and confidential data derived from the provision of health and social care services is used, linked and shared across the health economy. This may be direct or indirect care uses. [1]
This strategy is relevant for all those with responsibility for use of patient data and information governance in health and social care organisations. It is important that a consistent approach to fair processing is adopted to provide the necessary assurance to both the public and to bodies disclosing such data to others.
The scope of the Fair Processing Strategy covers
The document also sets out the means of communicating the Strategy and its supporting material.
Context
Intended end state on processing patient data for indirect uses
The intended end-state of how the restructured NHS will process patient data following the 2012 Health and Social Care Act and the outcome of the Caldicott Review [2] is based on
Therefore data may be legitimately obtained and held for a range of purposes and in a variety of forms. The Data Protection Act requires the holders of the data to be clear to relevant data subjects how their data will be used.
Use of personal data
NHS and social care organisations utilise personal data in various aspects of their operations. It is a requirement of the Data Protection Act 1998 [3] that such data is processed on a fair basis and that data subjects are duly informed about such uses. It is necessary therefore to provide ‘privacy notices’ to deliver explanations to individuals when information is collected about them – in effect stating ‘how we use your data’. Thus, fair processing describes best practice communications to ensure that patients know how these organisations are using their data and to ensure data from these organisations can be legally processed by fulfilling their fair processing obligations.
The use of personal data in health and social care can be grouped in two main ways:
Direct Care
The primary use is for provision of direct care and care services. Data are collected from patients and shared between regulated professionals (whether in the same or different organisations) to enable the provision of care. Relevant data are stored and processed in computer systems within care providers, such as general practices and hospitals and within community services.
The sharing of data between regulated professionals and their organisations is implicit in the process of provision of care. Fair processing requires that such sharing is explicit to the patient and is understood by the patient. This is especially so when there are changes to the delivery of services, for example where services are to be outsourced to a new provider, the use of independent sector providers or for potential sharing with social care for integrated care.
Where such changes are to be made, there is a need to update fair processing leaflets and to actively communicate these proposed changes well in advance of implementation. Information about how to raise concerns will also be required and consideration given to patient objections.
Indirect Care
The second use is for indirect care purposes, which is to support
Relevant data are derived from the data collected in the provision of direct care. Such data are stored and processed within commissioning organisations, such as CCGs and NHS England, and any contracted data processing organisations.
Fair Processing Strategy
Overview
The Fair Processing Strategy is intended to enable, through a variety of communications channels and mechanisms,
Information should be made available to patients and service users initially giving basic privacy information at a high level, with directions or links to more detailed information for those that wish to follow this up. The more detailed information will also need to cover the specific uses referred to in the last bullet point above. The specific uses relate to the various major domains, such as research, commissioning and risk stratification, for which additional detail about the use and management of relevant data will need to be provided.
Privacy Notices
The ICO’s Privacy Notice Code of Practice [4]states that privacy notices
“should tell people who you are, what you are going to do with their information and who it will be shared with”.
It can also tell people more than this. For example, it might provide information about people’s rights of access to their data or local arrangements for keeping their data secure. A privacy notice should be genuinely informative making an organisation more transparent about how they are using data.
It is necessary for organisations to provide and draw patients and service user’s attention to their privacy notices.
Communications mechanisms
The privacy notices and other communications that support a Fair Processing Strategy have a number of difference audiences including patients, service users, carers, clinicians, professional staff and the public.
Implementation of the communication elements may require some or all of the following (depending on local discussion/agreement)
The detailed information for patients and public needs to include
Topics on which specific Fair Processing statements will be required include
Annex 1 - The Fair Processing Strategy – uses of data (taken from the NHSE Fair Processing Strategy)
Overview
Rationale and benefits
The reasons health and social care organisations, both locally and nationally, need to use data about the services provided to patients and service users and their outcomes include
Examples of benefits arising include:
These are the sorts of reasons and benefits that should be included in general and specific privacy notices.
Sharing and linking data
NHS patients and social care service users may receive care and treatments from a number of different places such as their GP, hospital or community service. It is necessary to link this information together to provide the full picture needed to support the activities listed above. In effect, sharing information enables the NHS to improve its understanding of the most important health needs and the quality of the treatment and care provided.
Protecting data
Information about individual people, such as their postcode and NHS number, rather than their name, are used to link their records, in a secure system. This enables the identities of individuals to be protected. Information, which does not reveal who the individuals are, can then be used by others, such as those planning NHS services and approved researchers to support the provision of care.
The Data Protection Act requires that health and social care organisations only share the minimum amount of information they need to understand what is happening and how to improve services.
The NHS may release information to approved researchers and some third party organisations, where this is allowed, under the strict rules in place to protect individual’s privacy. The NHS and social care organisations are required to use information in line with the law, national guidance and best practice and will never identify a particular person in any published reports.
Individual Choice
The NHS has committed to provide the right for individuals to prevent confidential information from being shared or used for any purpose other than supporting the provision of direct care, except in special circumstances. If an individual does not want information to be shared outside their GP practice, this can be added to their medical record. This will prevent their confidential information being used other than where necessary by law, (for example, if there is a public health emergency).
It will also be possible to restrict the use of information held by other places where care is provided, such as hospitals and community services. Again, this can be achieved through the individual’s GP.
It is important to note that this is different to sharing decisions made, for example in relation to sharing medical record information in support of treatment.
The choice not to share information for indirect care purposes will not affect the care provided.
Specific uses of data - commissioning
There are a range of functions in the commissioning role that leads to a variety of uses of information about individuals. These different purposes will lead to the need to identify these purposes and uses in relevant privacy notices. An overview is given below.
For commissioning services that pertain to direct care or commissioned as individual packages of care (this includes Specialist Commissioning, Prisons, Military, Long Term Conditions and Requests for Individual Funding) – the NHS already has a set process for fair processing notices, generic patient leaflet and standard wording for the consent form.
For commissioning purposes there is a need to explain to patients how their data will be used to support health care management and administration, and how they can object (dissent). To support this, there is the need to cover each of the scenarios where use of person level data occurs, namely
[1] The Caldicott Review 2013 defined indirect care as ‘activities that contribute to the overall provision of services to a population as a whole or a group of patients with a particular condition, but which fall outside the scope of direct care. It covers health services management, preventative medicine, and medical research. Examples of activities would be risk prediction and stratification, service evaluation, needs assessment, financial audit.’
[2] see https://www.gov.uk/government/publications/the-information-governance-review
[3] see http://www.legislation.gov.uk/ukpga/1998/29/contents
[4] see http://www.ico.org.uk/for_organisations/data_protection/topic_guides/privacy_notices