Information governance

Information governance

We use information about you to help us plan, buy and deliver healthcare services effectively, efficiently and safely.

Everyone working for the NHS has a legal duty to keep that information confidential, safe and secure. To ensure that happens, NHS Devon works to an information governance framework, including:

If you have any questions about how we use your information, please contact us.

National data protection legislation and guidelines

Our information governance framework follows these national rules and guidelines:

The Caldicott Guardian and principles

NHS Devon’s Caldicott Guardian is the chief medical officer, Peter Collins. He is responsible for protecting the confidentiality of patient and service user information, whilst enabling appropriate information sharing in accordance with the Caldicott principles.

  1. Justify the purpose(s) – Every proposed use or transfer of personal confidential data within or from an organisation should be clearly defined, scrutinised and documented, with continuing uses regularly reviewed, by an appropriate guardian.
  2. Don’t use personal confidential data unless it is absolutely necessary – Personal confidential data should not be included unless it is essential for the specified purpose(s) of that flow. The need for patients to be identified should be considered at each stage of satisfying the purpose(s).
  3. Use the minimum necessary personal confidential data – Where use of personal confidential data is considered to be essential, the inclusion of each individual item of data should be considered and justified so that the minimum amount of personal confidential data transferred or accessible as is necessary for a given function to be carried out.
  4. Access to personal confidential data should be on a strict need-to-know basis – Only those individuals who need access to personal confidential data should have access to it, and they should only have access to the data items that they need to see. This may mean introducing access controls or splitting data flows where one data flow is used for several purposes.
  5. Everyone with access to personal confidential data should be aware of their responsibilities – Action should be taken to ensure that those handling personal confidential data – both clinical and non-clinical staff – are made fully aware of their responsibilities and obligations to respect patient confidentiality.
  6. Comply with the law – Every use of personal confidential data must be lawful. Someone in each organisation handling personal confidential data should be responsible for ensuring that the organisation complies with legal requirements.
  7. The duty to share information can be as important as the duty to protect patient confidentiality – Health and social care professionals should have the confidence to share information in the best interests of their patients within the framework set out by these principles. They should be supported by the policies of their employers, regulators and professional bodies.
  8. Inform patients and service users about how their confidential information is used – A range of steps should be taken to ensure no surprises for patients and service users, so they can have clear expectations about how and why their confidential information is used, and what choices they have about this. These steps will vary depending on the use: as a minimum, this should include providing accessible, relevant and appropriate information – in some cases, greater engagement will be required.

Privacy notice

Our privacy notice provides a summary of how we use your information. This includes what information we collect and hold about you, what we do with it, how we will look after it and who we may share it with. It covers information we collect directly from you or receive from other individuals or organisations.

Access to health records

Under the Access to Health Records Act and the Data Protection Act, individuals have a right to request access to information NHS Devon holds about them, or another person acting on their behalf. This is sometimes known as a Subject Access Request (SAR).

Requests can be made to: d-icb.DataProtection@nhs.net

When making a request, please include the following details:

  • Your name, address and postcode
  • Any relevant case reference numbers
  • The type of information or documents you want to look at, including any relevant dates
  • Any preferences you have for the way you would like receive the information (for example, hard copy, large print or by email)
  • At least two forms of ID: Passport, Driving Licence or Birth Certificate (if requesting records on behalf of someone else, evidence of a Court of Protection order (Enduring Power of Attorney) or Lasting Power of Attorney must be provided).

NHS Devon will respond to your request in line with the General Data Protection Regulation.

Access to a child’s records

If the child is under 16, and the organisation agrees that disclosure would not be detrimental to the individual’s physical and/or mental wellbeing, access may be granted to a parent or guardian.

Dependant on the age and/or understanding of the child, they may be asked whether they agree to the release of their records.

If deemed in the best interest of the child, access may be granted by the health professional in charge of the clinical care.

Access to a deceased person’s records

Access will usually be granted where the request comes from a personal representative of the deceased who holds a role set out in law. This is usually the person who holds the probate documentation (such as the Grant of Probate or Letters of Administration) or is named as executor in the deceased’s will.

If you are not the personal representative of the deceased but you have a claim arising out of the death of the deceased, you may have the right to see the health records of the deceased where they are relevant to your claim. However, because the duty of confidentiality extends after someone has died, we will not always grant access. We will need to take into account, for example, any wishes the individual expressed before they died.

Further information

For more information, contact: d-icb.DataProtection@nhs.net