Confidentiality and Data Protection Assurance

13-211

Attainment: Level 3 (Previous 2)

There is a need to ensure that all transfers of personal and sensitive information (correspondence, faxes, email, telephone messages, transfer of patient records and other communications containing personal or sensitive information) are conducted in a secure and confidential manner. This is to ensure that information is not disclosed inappropriately, either by accident or design, whilst it is being transferred or communicated to, within or outside of the organisation.

Levek 1.

All areas from which personal and sensitive information is transferred and received have been identified. A procedure is in place to ensure security and confidentiality is maintained.

a. All areas from which personal and sensitive information is sent or received have been identified.

List of the relevant Areas

b.

There is a documented procedure for the secure transfer and receipt of personal and sensitive information.

Staff document

c.

The procedure has been approved by senior management

Meeting approving document

Level 2.

All staff members have been informed about the procedure on secure transfer and receipt of personal and sensitive information and of the need to comply with it.

a.

The procedure has been made accessible to staff in an appropriate location.

Public document

b.

All staff members have been informed of the procedure and in particular of their own responsibilities for compliance.

Training records

c.

All new staff, temporary and contract staff members are made aware of the procedure and in particular of their own responsibilities for compliance.

Induction materials

Level 3.

Staff compliance with the procedure is monitored. The procedure is reviewed and evaluated on at least an annual basis.

a.

Providing staff with guidance materials and briefings does not provide sufficient assurance that the guidance has been understood and is being followed, therefore compliance spot checks and routine monitoring are conducted.

Latest Information Governance Review meeting

b. (Not relevant to OHC at this stage)