Overarching Information Governance Policy

Size: px
Start display at page:

Download "Overarching Information Governance Policy"

Transcription

1 Document Information Board Library Reference Document Type Document Subject Original Document Author Reviewed By Review Cycle IM&T_01 Policy Information Information IGMG 3 Years Note: This document is electronically controlled. The master copy is maintained by the author department within the document library on OurSpace. Once printed, this document becomes uncontrolled. Version Tracking Version Date Revision Description Editor Approval Status /12/2004 Version 1 Information /06/2009 Administrative review Information /08/2009 Legal Framework updated Information Approved Approved Draft /11/2009 Standardisation of Archiving of Master Documents /12/2009 Approved by Quality and Healthcare Committee /09/2010 Review for compliance with Information Management Framework /12/2010 Incorporate comments from Executive Management Team Information Company Secretary Information Information Draft Approved Draft Draft /12/2010 Approved by Executive Management Team Information Approved

2 Table of Contents 1. Introduction Purpose Scope Roles and Responsibilities The Chief Executive The Senior Information Risk Owner The Caldicott Guardian The Information The Data Protection Officer The Freedom of Information Lead The Information Security Specialist Line s All staff Management Arrangements Information Management Group (IGMG) Policy Statement Implementation Standards Monitoring and Audit Archiving of Master Documents References Approved 22/12/ of 11

3 1. Introduction 1.1. Avon and Wiltshire Mental Health Partnership NHS Trust (AWP) is bound by the provisions of a considerable number of items of legislation and regulation affecting the stewardship of data and information Information (IG) ensures the Trust s compliance with applicable legislation, the regulatory framework, Common Law, and mandated Best Practice. In short, IG exists to ensure the Integrity, Availability, Confidentiality of the Trust s operational, patient, staff and management information The AWP Overarching Information Policy defines the Trust s mandated base-line strategy for compliance and effective management in each of the following six areas of Information Confidentiality & Data Protection Assurance Information Management Assurance Clinical Information Assurance Information Security Assurance Secondary Use Assurance Corporate Information Assurance 1.4. The overarching and other information governance policies constitute the top level documentation of the Trust s Information Management System (IGMS) Compliance with all Policies, Procedures and Guidelines contained in the IGMS is mandatory for all persons and organisations operating under the auspices of, or delivering a service to the Trust, whether they are staff, students, volunteers, contractors or partner organisations Staff should be aware that IGMS Policies are intended to protect the Trust and staff from adverse outcomes in terms of compliance with the law. Where IGMS policies are breached by staff it may be necessary for managers to consider retraining staff, or following the Trust s Disciplinary Procedures. Staff should also note that legal penalties could also be imposed upon the Trust or its employees for non-compliance with relevant legislation and NHS guidance, and in serious cases individuals may not be immune from prosecution or civil legal action by virtue of their employment within the Trust. 2. Purpose 2.1. To set out the Trust s policy for compliance with specified and applicable national standards of Information, and, Approved 22/12/ of 11

4 2.2. To formally document the key principles which shall be enacted through associated detailed procedures. 3. Scope 3.1. This is a Trust-wide Policy and applies to all Information and Communication Technology (ICT) systems and the data held, processed or transmitted by them, including staff, service user, management, audit and all other types of information used by the Trust This is a Trust-wide Policy and applies to all staff and personnel operating under the auspices of the Trust, including employees, locums, contractors, temporary staff, students, service user representatives, volunteers and partner agency staff Where a third party has an organisational policy that differs from this Policy, a formal agreement as to which policy statement applies shall be outlined and agreed in an appropriate protocol if necessary. In the absence of such an agreement, this Policy shall be deemed to have precedence. 4. Roles and Responsibilities 4.1. The Chief Executive The Chief Executive is responsible for the Trust s compliance with applicable legislation and regulation The Senior Information Risk Owner The Executive Director of Finance and Commerce and Deputy Chief Executive shall be the Trust SIRO and shall represent any relevant information risk issues to the Board The SIRO shall receive specialist information governance advice from Company Secretary and the Information Manger The Board shall receive an annual Information report sponsored by the SIRO Fosters a culture for protecting and using data Provides a focal point for managing information risks and incidents The SIRO works closely with the Caldicott Guardian to jointly deliver their respective roles Is concerned with the management of all information assets Approved 22/12/ of 11

5 4.3. The Caldicott Guardian The Caldicott Guardian role has the key role in ensuring that the Trust can satisfy the highest practical standards for handling patient-identifiable information and acts as the conscience of the organisation The Caldicott Guardian has the strategic role in representing and championing Information requirements and issues in the Board and Executive Management Team, The Caldicott Guardian role is advisory and accountable for that advice The Caldicott Guardian role provides a focal point for patient confidentiality & information sharing issues The Caldicott Guardian role is concerned with the management of patient/service user information The Board will receive an annual report from the Caldicott Guardian in relation to the delivery of the role The Caldicott Guardian works closely with the SIRO to jointly deliver their respective roles The Deputy Caldicott Guardian Through delegation, supports the Caldicott Guardian in the delivery of their roles, including reporting and assurance of delivery in practice Leads the delivery of the Caldicott Guardian advisory role Acts as lead senior manager in relation to the Caldicott Guardian functions, ensuring that they are planned, delivered and reported through the Mental Health Legislation and Safeguarding Management Group The Information Is responsible for the management of the Information Toolkit Action Plan and shall provide specialist advice to the organisation and staff regarding information governance incidents Approved 22/12/ of 11

6 4.6. The Data Protection Officer Shall ensure that the Trust s Data Protection Notification is accurate and up to date on an annual basis and provide specialist data protection advise to the organisation and staff were necessary 4.7. The Freedom of Information Lead Shall ensure that the Trust s Freedom of Information Publication Scheme is accurate and up to date Shall ensure that all requests for information are processed in accordance with the Freedom of Information Act and Trust policy and procedures 4.8. The Information Security Specialist Shall manage the Trust s technical safeguards against the risks of loss, corruption, misuse or unauthorised disclosure of data and protect the systems and infrastructure used to store, process and transmit this information whilst monitoring and improving their usage and effectiveness. re and processes Line s Line s are responsible for ensuring compliance with this policy through appropriate managerial arrangements including supervision, training, performance management and the use of disciplinary procedures where necessary It is the responsibility of Line s to enable their staff to attend suitable information governance training All staff All users of AWP ICT systems are responsible for ensuring that their use of these systems is conducted in compliance with this policy and have a duty to report any instances of non-compliance they witness to their managers Management Arrangements The Head of Information Systems and Technology shall be the Trust lead for the provision of Information advice and is supported the Information who is the Data Protection Officer in the provision of expert advice and guidance on standards and compliance for Information, The Medical Director and Executive Director of Strategy and Business Development is the nominated Trust Data Quality Lead, Approved 22/12/ of 11

7 and is supported in this role by the Deputy Director of Strategy, Performance and Business Development Executive Directors and Strategic Business Unit Directors are responsible for the implementation of the standards of Information specified in the IGMS Information Management Group The Trust shall establish an Information Management Group (IGMG) which shall: provide the Senior Information Risk Owner (SIRO) with advice and guidance on information policy and risk management, ensure the Trust s Information Management System, including its processes, procedures, protocols, training and awareness programmes, is in compliance with applicable Standards, Legislation, Department of Health NHS Directives, and Connecting for Health Guidelines and Policies, monitor the implementation of the Trust s Information Management System (IGMS) and associated Information Action Plans, monitor the Trust s achievement of compliance with the Information Toolkit and associated Key Lines of Enquiry for Care Quality Commission The IGMG reports to Performance EMT and to the Quality & Healthcare Committee for the purposes of reporting and approving Trust documents and policies Mental Health Legislation & Safeguarding Management Group The Trust shall establish a Mental Health Legislation and Safeguarding Management Group which shall: provide the Caldicott Guardian with advice and guidance on policy and management of patient/service user information ensure the Trust s Caldicott Guardian and information systems, including processes, procedures, protocols, training and awareness programmes, is in compliance with applicable Standards, Legislation, Department of Health NHS Directives in the management of patient/service user information., Approved 22/12/ of 11

8 monitor the delivery of the Caldicott Guardian advisory function and Caldicott Guardian Action Plans, monitor the Trust s achievement of compliance with the relevant sections of the Information Toolkit and the relevant Care Quality Commission Quality Essential Standards of Quality and Safety reports to Performance EMT and to the Quality & Healthcare Committee for the purposes of reporting and approving relevant Trust documents and policies. 5. Policy Statement 5.1. The Trust shall implement Information systems, measures and provisions to ensure the integrity of information and systems in compliance with the national standards defined in the Connecting for Health Information Toolkit The Trust shall aim to demonstrate compliance with key Information standards through achievement of at least level 2 performance and shall provide an action plan to progress beyond this minimum where this has been achieved This shall include a suite of policies, procedures, protocols and management responsibilities which constitute the Trust s Information Management System (IGMS) The key Information Policies forming the procedural element of the IGMS are: 6. Implementation Data Protection Policy Freedom of Information Policy Information Security Policy Records Management Policy Health and Social Care Records Policy Information Sharing Agreements Acceptable Use Policy 6.1. A policy alert will be issued using the Trust s standard policy alert system Approved 22/12/ of 11

9 6.2. Implementation of the policy in practice will be conducted by managers with responsibility for ensuring compliance Compliance with this policy will be monitored and assessed as described in section The Policy will be made available on the Trust Intranet. 7. Standards 7.1. This policy will be assessed against the Information Toolkit standards 8. Monitoring and Audit 8.1. The Information Security Specialist is responsible for monitoring that the requirements of this policy have been met Compliance with this policy will be monitored and measured by: 8.3. An annual assurance report to the Information Management Group The Trust s arrangements for auditing records will be evaluated annually against various external standards to include the annual Information Toolkit, Care Quality Commission and National Health Service Litigation Authority (NHSLA) Risk Management Standards The annual assurance report will specifically provide information, critique and evaluate: compliance with the IGMS 8.6. Any issues arising from auditing this policy will be added to the directorate risk register and lead to the creation of an action plan, the implementation of which will be monitored by the Information Management Group Any issues arising from the audit and monitoring that will aid and inform wider learning will be communicated via the Trust s programme of thematic reviews and Head of Professions. 9. Archiving of Master Documents 9.1. This policy document form part of a formal Trust record, and is to be managed in accordance with the Trust s records management policies and retention and disposal schedules. Users must familiarise themselves with the national standards defined by the Department of Health in the Records Management: NHS Code of Practice. The Code can be read online by clicking on this link which opens the Department of Health website in a web browser window (use ctrl + left-click) Approved 22/12/ of 11

10 9.2. The Board Policy Document Library on OurSpace is the only recognised repository for master versions of policy documents. Copies of this document must therefore not be stored elsewhere on the system, e.g. in workgroups The OurSpace document library system shall provide records management functionality to allow for the retrieval of previous versions of policy documents for audit purposes. 10. References Access to Health Records Act 1990 (where not superseded by the Data Protection Act 1998) Computer Misuse Act Copyright, Designs and Patents Act 1988 (as amended by the Copyright (Computer Programs) Regulations Crime & Disorder Act Criminal Justice & Court Services Act 2000 (where Multi Agency Public Protection Panels & Information exchange is set out) Data Protection Act Electronic Communications Act Freedom of Information Act Lawful Business Practice Regulations Regulation of Investigatory Powers Act 2000The Directive on Privacy and Electronic Communications (2002/58/EC) A full list of legislation can be reviewed within the NHS Information Guidance on Legal and Professional Obligations at the following link: PolicyAndGuidance/DH_ Additionally, the NHS has mandated a number of relevant regulations including: BS10012:2009 Data Protection: Specification for a Personal Information Management System Confidentiality: NHS Code of Practice Connecting for Health s Information Toolkit Approved 22/12/ of 11

11 Data Quality Assurance to include NHS Data Dictionary, Hospital Episode Statistics (HES) and Mental Health Minimum Data Set (MHMDS) Information Security Management: NHS Code of Practice NHS Records Management: Code of Practice The Caldicott Report The Caldicott Guardian Manual The Care Record Guarantee The International Standards Organisation Standard for Information Security Management, Approved 22/12/ of 11

Records management policy. Document author Assured by Review cycle. Audit and Risk Committee. 1. Introduction Purpose or aim Scope...

Records management policy. Document author Assured by Review cycle. Audit and Risk Committee. 1. Introduction Purpose or aim Scope... Records management policy Board library reference Document author Assured by Review cycle P017 Head of Compliance Audit and Risk Committee 3 Years This document is version controlled. The master copy is

More information

INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION

INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION INFORMATION GOVERNANCE STRATEGY AND STRATEGIC VISION Policy approved by: Joint Audit and Governance Committee Date: December 2016 Next Review Date: October 2018 Version: 2.0 Information Governance Strategy

More information

IGPr002 - Information Governance Management Framework

IGPr002 - Information Governance Management Framework IGPr002 - Information Governance Management Framework Page 1 of 10 Table of Contents Information Governance Management Framework... 1 Why we need this Framework... 3 What the Framework is trying to do...

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Date completed: February 2016 Responsible Director: Approved by/ date: Director of Compliance Review date: October 2017 Amended: Author: Ben Westmancott Information Governance

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Policy Number IG001 Target Audience CCG/ GMSS Staff Approving Committee CCG Chief Officer Date Approved February 2018 Last Review Date February 2018 Next Review Date February

More information

Information governance strategy

Information governance strategy Information governance strategy January 2018 Version 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment V 1.0 Trevor Duplessis 22/01/18 Due for review Dec

More information

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN INFORMATION GOVERNANCE STRATEGY & IMPLEMENTATION PLAN 2015-2018 Disclaimer The latest version of this document is located on PTHB intranet. Please check the review date and if there are any doubts contact

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Page 1 of 13 INFORMATION GOVERNANCE POLICY EXECUTIVE SUMMARY Key Messages Principles of Information Governance Openness Confidentiality and Legal Compliance Information Security

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

IG01 Information Governance Management Framework

IG01 Information Governance Management Framework IG01 Information Governance Management Framework 1 INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG01 Document Purpose: The document compliments all other Information

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

Information Governance Strategy and Management Framework

Information Governance Strategy and Management Framework Information Governance Strategy and Management Framework Summary: This strategy sets out the framework, structure, system and accountabilities for Information Governance Management within NHS Eastbourne,

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Applicable to All employees Version1.0 Last Updated March 2014 CONFIDENTIAL Page 2 of 6 Contents 1. Objectives 3 2. Scope 3 3. Principles 3 4. Information Governance Policy

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Unique Reference / Version Primary Intranet Location Information Management & Governance Secondary Intranet Location Policy Name Information Governance Policy Version Number

More information

Information Sharing Policy

Information Sharing Policy Information Sharing Policy DOCUMENT CONTROL: Version: 1 Ratified by: Risk Management Sub Group Date ratified: 19 December 2012 Name of originator/author: Information Governance Manager Name of responsible

More information

Information Governance Strategic Management Framework

Information Governance Strategic Management Framework Information Governance Strategic Management Framework 2016-2018 Susan Meakin Information Governance Manager June 2016 Information Governance DOCUMENT CONTROL: Version: 2 Ratified by: Health Informatics

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Putting Barnsley People First Information Governance Policy and Management Framework Version: 2.0 Approved By: Governing Body Date Approved: February 2014 Name of originator / author: Richard Walker Name

More information

Information Governance Management Framework

Information Governance Management Framework Information Governance Management Framework November 2014 Author: Responsibility: Lynda Harris, Head of Information Governance All Staff Effective Date: November 2014 Review Date: November 2015 Reviewing/Endorsing

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Including the Information Governance Strategy Framework and associated Information Governance Procedures Last Review Date June 2017 Approving Body Audit Committee Date of

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK NHS South West Lincolnshire Clinical Commissioning Group (CCG) INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History: Document Reference: Document Purpose: IG01 Date Ratified: January 2015 Ratified

More information

Information Governance Clauses Clinical and Non Clinical Contracts

Information Governance Clauses Clinical and Non Clinical Contracts Information Governance Clauses Clinical and Non Clinical Contracts Policy Number Target Audience Approving Committee Date Approved Last Review Date Next Review Date Policy Author Version Number IG014 All

More information

Information Governance Management Framework

Information Governance Management Framework Management Framework Summary: This document sets out the framework, structure, system and accountabilities for Management within West Kent CCG Clinical Commissioning Group. APPROVED BY: Chief Finance Officer

More information

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead DATA QUALITY POLICY Version: 1.2 Approved by: Date approved: 02 February 2016 Name of Originator/Author: Name of Responsible Committee/Individual: Information Governance, Records Management and Caldicott

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG33 Document Purpose: The document complements all other Information Governance policies and sets out the management arrangements

More information

Information Governance Assurance Framework

Information Governance Assurance Framework Document Reference POL008 Document Status Approved Version: V4.0 DOCUMENT CHANGE HISTORY Initiated by Date Author IG Toolkit Requirements November 2010 IG Manager Version Date Comments (i.e. viewed, or

More information

Information Security Policy

Information Security Policy Information Security Policy Issue sheet Document reference Document location Title Author Issued to Reason issued NHSBSARM001 NHS Business Services Authority Information Security policy Head of Security

More information

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY Version Control Version: 2.0 dated 17 July 2015 DATE VERSION CONTROL 04/06/2013 1.0 First draft of new policy

More information

NHS DIGITAL Records and Document Management Policy

NHS DIGITAL Records and Document Management Policy Status Document Record ID Key Version Director Responsible for this policy Final v2.0 Version Date 10/04/2018 Catherine O Keeffe, Director of Information Governance, Burden and Audit Person to contact

More information

Job Description. Operations Manager. Scheduled Care. Band 8A. Centre Manager. Centre Manager

Job Description. Operations Manager. Scheduled Care. Band 8A. Centre Manager. Centre Manager Job Description Job Title: Clinical Group Base Band: Reports To: Accountable To: Key Working Relationships: Operations Manager Scheduled Care The Shrewsbury and Telford Hospital NHS Trust Band 8A Centre

More information

Date: INFORMATION GOVERNANCE POLICY

Date: INFORMATION GOVERNANCE POLICY Date: INFORMATION GOVERNANCE POLICY Information Governance Policy IGPOL/01 Information Systems Corporate Services Division March 2017 1 Revision History Version Date Author(s) Comments 0.1 12/12/2012 Helen

More information

INFORMATION GOVERNANCE ASSURANCE FRAMEWORK

INFORMATION GOVERNANCE ASSURANCE FRAMEWORK INFORMATION GOVERNANCE ASSURANCE FRAMEWORK Summary This document sets out an overarching framework for the strategic Information Governance agenda in the Business Services Organisation. In particular,

More information

Privacy Impact Assessment Policy and Procedure

Privacy Impact Assessment Policy and Procedure Privacy Impact Assessment Policy and Procedure This document outlines the Trust s approach and methodology for conducting Privacy Impact Assessments in line with the Information Risk Policy Key Words:

More information

This Policy supersedes the following Policy, which must now be destroyed:

This Policy supersedes the following Policy, which must now be destroyed: Document Title Reference Number Lead Officer Author(s) (name and designation) Ratified by Forensic Readiness Policy NTW(O)56 Lisa Quinn, Executive Director of Commissioning and Quality Assurance Angela

More information

This Policy supersedes the following Policy, which must now be destroyed:

This Policy supersedes the following Policy, which must now be destroyed: Document Title Reference Number Lead Officer Author(s) (name and designation) Ratified by Forensic Readiness Policy NTW(O)56 Lisa Quinn Executive Director of Performance and Assurance Sue Proud Information

More information

INFORMATION GOVERNANCE POLICY AND FRAMEWORK

INFORMATION GOVERNANCE POLICY AND FRAMEWORK INFORMATION GOVERNANCE POLICY AND FRAMEWORK Policy approved by: Audit and Governance Committees Date: 9 th October 2017 Next Review Date: September 2018 Version: 4.0 Information Governance Policy & Framework

More information

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00

Human Resources. Data Protection Policy IMS HRD 012. Version: 1.00 Human Resources Data Protection Policy IMS HRD 012 Version: 1.00 Disclaimer While we do our best to ensure that the information contained in this document is accurate and up to date when it was printed

More information

INFORMATION GOVERNANCE STRATEGY

INFORMATION GOVERNANCE STRATEGY INFORMATION GOVERNANCE STRATEGY Document Number 2009/49/V2 Document Title Information Governance Strategy Author Phil Cottis Author s Job Title Information Governance & RA Manager Department IM&T Ratifying

More information

NHS Sunderland Clinical Commissioning Group. Information Governance Strategy 2016/17

NHS Sunderland Clinical Commissioning Group. Information Governance Strategy 2016/17 NHS Sunderland Clinical Commissioning Group Information Governance Strategy 2016/17 Document Status Equality Impact Assessment Document Ratified/Approved By Final No impact Executive Committee Governing

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY Version: 1.4 Approved by: Date approved: 19 January 2017 Name of Originator/Author: Name of Responsible Committee/Individual: Date issued: Information

More information

Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective:

Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective: Data Protection Act Policy Statement Status/Version: 0.1 Review Information Classification: Unclassified Effective: 1 Policy Statement Objective 1.1 It is the policy of Penderels Trust to demonstrate compliance

More information

TRUST GOVERNANCE POLICY (formerly referenced as the CMFT Governance Strategy) - UPDATED NOVEMBER

TRUST GOVERNANCE POLICY (formerly referenced as the CMFT Governance Strategy) - UPDATED NOVEMBER Review Circulation Application Ratification Originator or modifier Supersedes Title CENTRAL MANCHESTER UNIVERSITY HOSPITALS NHS FOUNDATION TRUST TRUST GOVERNANCE POLICY (formerly referenced as the CMFT

More information

TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients

TECHNICAL RELEASE TECH 05/14BL. Data Protection Handling information provided by clients TECHNICAL RELEASE TECH 05/14BL Data Protection Handling information provided by clients ABOUT ICAEW ICAEW is a world leading professional membership organisation that promotes, develops and supports over

More information

INFORMATION GOVERNANCE STRATEGY. Documentation control

INFORMATION GOVERNANCE STRATEGY. Documentation control INFORMATION GOVERNANCE STRATEGY Documentation control Reference Date Approved Approving Body Version Supersedes Consultation Undertaken Target Audience Supporting procedures GG/INF/01 TRUST BOARD Information

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Owner Author Information Team Information Governance Manager Reviewed by Approved by and date Council/Committee/EMT Board - Date approved Effective from 24 April 2017 Review

More information

Information Security Risk Management Programme and Strategy

Information Security Risk Management Programme and Strategy Information Security Risk Management Programme and Strategy Table of Contents 1. Introduction... 3 2. Purpose... 3 3. Definitions... 3 4. Roles and Responsibilities... 4 4.1. Accountable Officer... 4 4.2.

More information

Information Governance Management Framework 2016/17

Information Governance Management Framework 2016/17 Information Governance Management Framework 2016/17 Reference: IG12 Compliance with all CCG policies, procedures, protocols, guidelines, guidance and standards is a condition of employment. Breach of policy

More information

Information Governance Management Framework 2017/18 Reference: IG12

Information Governance Management Framework 2017/18 Reference: IG12 Information Governance Management Framework 2017/18 Reference: IG12 Compliance with all CCG policies, procedures, protocols, guidelines, guidance and standards is a condition of employment. Breach of policy

More information

Induction Policy. Document author Assured by Review cycle. 1. Introduction Policy Statement Purpose or Aim Scope...

Induction Policy. Document author Assured by Review cycle. 1. Introduction Policy Statement Purpose or Aim Scope... Induction Policy Board library reference Document author Assured by Review cycle P091 Head of Learning and Development Quality and Standards Committee 3 Year This document is version controlled. The master

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY CONSULTATION AND RATIFICATION SCHEDULE Document Name: Governance Policy Policy Number/Version: 2.0 Name of originator/author: Midlands & Lancashire CSU Governance Team Ratified

More information

RISK MANAGEMENT STRATEGY

RISK MANAGEMENT STRATEGY Agenda Item No: 15 RISK MANAGEMENT STRATEGY PURPOSE: The Risk Management Strategy has been updated to reflect the revised approach to the Corporate Risk Register and Board Assurance Framework and to reflect

More information

Controlled Document Number: Version Number: 7 Controlled Document Sponsor: Controlled Document Lead:

Controlled Document Number: Version Number: 7 Controlled Document Sponsor: Controlled Document Lead: Policy for the Development and Management of Controlled Documents CONTROLLED DOCUMENT CATEGORY: CLASSIFICATION: PURPOSE: Controlled Document Number: Version Number: 7 Controlled Document Sponsor: Controlled

More information

Information Governance Management Framework Version 6 December 2017

Information Governance Management Framework Version 6 December 2017 Information Governance Management Framework Version 6 December 2017 Page 1 of 8 Introduction Robust information governance requires clear and effective management and accountability structures, governance

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Review date November 2016 Version No. V07 Internal Ref: NELC 16.60.01 Humber Information Sharing Charter This Charter may be an uncontrolled copy, please check the source of this document

More information

Records Management Policy

Records Management Policy Records Management Policy November 2013 Page 1 of 12 Policy Title: Records Management Policy Reference Number: CORP 08/003 Original Implementation Date: June 2011 Reviewed: November 2013 Next Review Date:

More information

PROCEDURE (Essex) / Linked SOP (Kent) Information Sharing Agreements. Number: W 1014 Date Published: 23 June 2017

PROCEDURE (Essex) / Linked SOP (Kent) Information Sharing Agreements. Number: W 1014 Date Published: 23 June 2017 1.0 Summary of Changes 1.1 The following minor changes have been made to this procedure/sop on 23 June 2017: Paragraph 3.3.7 link created to Privacy Impact Assessment; Paragraph 3.4 Legal Services replaced

More information

Data Quality Policy

Data Quality Policy Cambridgeshire and Peterborough Clinical Commissioning Group (CCG) Data Quality Policy 2017-2019 Ratification Process Lead Author(s): Reviewed / Developed by: Approved by: Ratified by: Associate Director

More information

Information Governance and Records Management Policy March 2014

Information Governance and Records Management Policy March 2014 Information Governance and Records Management Policy March 2014 Approving authority: Secretary s Board Consultation via: Secretary's Board Information Governance and Security Group Approval date: 4 March

More information

Information Governance Policy

Information Governance Policy Author Darren Rigg Head of Information Governance Corporate Lead Bryan Machin Executive Director of Finance and Resources Document Version 1 Date ratified by Quality Committee 24 th October 2014 Date issued

More information

Information Asset Management Policy

Information Asset Management Policy Information Asset Management Policy 1.0 Purpose 1.1 The purpose of this policy is to outline the management of the Fund s information asset register and the actions that will be taken to provide sufficient

More information

Information Management Policy CCMT Sponsor Director of Information Department/Area Joint Information Management Unit

Information Management Policy CCMT Sponsor Director of Information Department/Area Joint Information Management Unit Policy Title Information Management Policy CCMT Sponsor Director of Information Department/Area Joint Information Management Unit CONTENTS: (All Force policies should incorporate the following) 1.0 Rationale

More information

Recruitment, Selection and Appointment

Recruitment, Selection and Appointment Recruitment, Selection and Appointment Who Should Read This Policy Target Audience Managers Version 2.0 November 2016 Ref. Contents Page 1.0 Introduction 4 2.0 Purpose 4 3.0 Objectives 4 4.0 Process 5

More information

Records Management Plan

Records Management Plan Records Management Plan October 2014 1 2 Document control Title The Scottish Funding Council Records Management Plan Prepared by Information Management and Security Officer Approved internally by Martin

More information

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk Title Description of document The sets out the process by which the Trust identifies, manages, reduces and mitigates risks to achieving the organisational objectives. It sets out the framework required

More information

Policy for the Development, Approval, Management and Dissemination of Trust Controlled Documents

Policy for the Development, Approval, Management and Dissemination of Trust Controlled Documents J Policy for the Development, Approval, Management and Dissemination of Trust Controlled Documents Reference Number Version Status Executive Lead(s) Name and Job Title Author(s) Name and Job Title 55 6

More information

Information Governance Strategic Management Framework (Including Policy and Strategy)

Information Governance Strategic Management Framework (Including Policy and Strategy) Information Governance Strategic Management Framework (Including Policy and Strategy) This document sets out the framework that brings together all the requirements, standards and best practice that apply

More information

DATA QUALITY POLICY Review Date: CONTENT

DATA QUALITY POLICY Review Date: CONTENT Title: Date Approved: Approved by: DATA QUALITY POLICY Review Date: Policy Ref: Issue: Jan 2010 Sherwood Forest Hospitals Oct 2011 Information Governance Group Division/Department: Policy Category: ISP_03

More information

Directorate of Strategy & Planning DATA QUALITY POLICY

Directorate of Strategy & Planning DATA QUALITY POLICY Directorate of Strategy & Planning DATA QUALITY POLICY Reference: FPP003 Version: 1.6 This version issued: 24/06/14 Result of last review: Minor changes Date approved by owner (if applicable): N/A Date

More information

Records Management Policy

Records Management Policy Records Management Policy Responsible Officer Author Business Planning & Resources Director Corporate Office Date effective from December 1999 Date last amended December 2015 Review date October 2018 1

More information

THE IPSWICH HOSPITAL NHS TRUST. Divisional Board. TERMS OF REFERENCE Version 1.0

THE IPSWICH HOSPITAL NHS TRUST. Divisional Board. TERMS OF REFERENCE Version 1.0 THE IPSWICH HOSPITAL NHS TRUST Divisional Board TERMS OF REFERENCE Version 1.0 Purpose: For use by: This document is compliant with /supports compliance with: This document supersedes: Approved by: To

More information

HEALTH AND SAFETY STRATEGY

HEALTH AND SAFETY STRATEGY HEALTH AND SAFETY STRATEGY 2016-2019 Version: 1.0 Ratified by: Integrated Governance Committee Date ratified: 30 September 2015 Title of originator/author: Title of responsible committee/group: Head of

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY 1. CONSULTATION AND RATIFICATION SCHEDULE 1.2. Document Name: Governance Policy 1.4. Policy Number/Version: V4.0 1.6. Name of originator/author: Midlands & Lancashire CSU

More information

JOB DESCRIPTION. To be responsible for supervising the day to day operations of the cross site Café Bistro outlets.

JOB DESCRIPTION. To be responsible for supervising the day to day operations of the cross site Café Bistro outlets. JOB DESCRIPTION 1. POST TITLE: Senior Barista 2. BASE: Princess Royal Hospital 3. DEPARTMENT: Facilities Catering Services 4. MANAGER RESPONSIBLE TO: Catering Manager 5. HOURS: As Per Contract 6. POST

More information

Freedom of Information/Environmental Information Regulations Policy and Procedure

Freedom of Information/Environmental Information Regulations Policy and Procedure Policy Number: 8.3 Version number: 01 Date of issue: Date Archived: Reason for policy: (Redraft/new) New policy to ensure compliance with current legislation Authorised by: On Behalf of Management (Signature)

More information

Organisational Change Policy P078. Version Date Revision Description Editor Status

Organisational Change Policy P078. Version Date Revision Description Editor Status Document Information Board Library Reference Document Author Assured By Review Cycle P078 Head of HR Employment Strategy and Engagement Committee 3 Years Note: This document is electronically controlled.

More information

Findings from ICO audits of 16 local authorities

Findings from ICO audits of 16 local authorities Data protection Findings from ICO audits of 16 local authorities January to December 2013 Introduction This report is based on ICO audits of 16 local authorities between January and December 2013. This

More information

Author s job title Head of Clinical Coding and Data Quality Directorate IM&T

Author s job title Head of Clinical Coding and Data Quality Directorate IM&T Document Control Title Data Quality Policy Author Author s job title Head of Clinical Coding and Data Quality Directorate IM&T Department Clinical Coding Version Date Issued Status Comment / Changes /

More information

The UK legislation is wholly retrospective and applies to all information held by public authorities regardless of its date.

The UK legislation is wholly retrospective and applies to all information held by public authorities regardless of its date. FREEDOM OF INFORMATION POLICY INTRODUCTION The Freedom of Information (FOI) Act was passed in 2000 and replaces the Open Government Code of Practice that has been in place since 1994. The Act gives the

More information

Information Assets: Security and Risk Management Policy. Choice, Responsiveness, Integration & Shared Care

Information Assets: Security and Risk Management Policy. Choice, Responsiveness, Integration & Shared Care s: Security and Risk Management Policy Choice, Responsiveness, Integration & Shared Care Worcestershire Mental Health Partnership NHS Trust Reader Box Document Type: Document Purpose: Unique identifier:

More information

Documented and publicly available procedures are in place to ensure compliance with the Freedom of Information Act 2000

Documented and publicly available procedures are in place to ensure compliance with the Freedom of Information Act 2000 Documented and publicly available procedures are in place to ensure compliance with the Freedom of Information Act 2000 Guidance Compliance with the Freedom of Information Act 2000 Introduction 1. The

More information

Risk Management Strategy, Policy and Guidance

Risk Management Strategy, Policy and Guidance Risk Management Strategy, Policy and Guidance 11.0 Risk Management EQUALITY IMPACT The Trust strives to ensure equality of opportunity for all both as a major employer and as a provider of health care.

More information

Anti-Fraud, Bribery and Corruption Policy. Document author Assured by Review cycle. Audit and Risk Committee. 1. Executive summary...

Anti-Fraud, Bribery and Corruption Policy. Document author Assured by Review cycle. Audit and Risk Committee. 1. Executive summary... Anti-Fraud, Bribery and Corruption Policy Board library reference Document author Assured by Review cycle P115 Counter Fraud Specialist Audit and Risk Committee 3 years This document is version controlled.

More information

AUDIT COMMITTEE. Terms of Reference

AUDIT COMMITTEE. Terms of Reference AUDIT COMMITTEE Terms of Reference These Terms of Reference are used as evidence for: Care Quality Commission Regulation: Other (please specify): 1. Accountability Regulation 17 Good Governance 1.1 The

More information

For: Information Assurance Discussion and input Decision/approval. Ellen Bull, Deputy Director of Quality Author Contact Details: 3531

For: Information Assurance Discussion and input Decision/approval. Ellen Bull, Deputy Director of Quality Author Contact Details: 3531 Trust Board Item: 15 Date: 07/02/2018 Purpose of the Report: Enclosure: K To request ratification from the Trust Board of Directors on the. which was discussed, refined and approved at the Risk Management

More information

at work Health and safety p o l i c y d o c u m e n t

at work Health and safety p o l i c y d o c u m e n t Employees & visitors Safety Champion Supporting teams Roles & responsibilities Health and safety at work p o l i c y d o c u m e n t The Health and Safety at Work Policy provides a framework to ensure

More information

Honorary Contracts Procedure

Honorary Contracts Procedure Honorary Contracts Procedure Version: 3.0 Bodies consulted: Approved by: Joint Staff Consultative Committee & WMT Executive Management Team Date Approved: 03 October 2017 Lead Manager: Responsible Director:

More information

POLICY ON MANAGING POLICIES, PROCEDURES AND GUIDANCE DOCUMENTS

POLICY ON MANAGING POLICIES, PROCEDURES AND GUIDANCE DOCUMENTS POLICY ON MANAGING POLICIES, PROCEDURES AND GUIDANCE DOCUMENTS Version: 6 Date Ratified: February 2017 Review Date: February 2020 Applies to: Senior Managers and staff who produce procedural documents.

More information

Policies, Procedures, Guidelines and Protocols. Document Details

Policies, Procedures, Guidelines and Protocols. Document Details Policies, Procedures, Guidelines and Protocols Document Details Title Security Management Strategy Trust Ref No 2038-38676 Local Ref (optional) Main points the document The Strategy intends to reinforce

More information

Policy Document Control Page

Policy Document Control Page Title: Records Management Policy Version: 9 Reference Number: CO20 Policy Document Control Page Keywords Records, management, record keeping, audit, transportation, HR, personnel, health records, child

More information

Date of review: Policy Category:

Date of review: Policy Category: Title: Disciplinary Policy Date Approved by: Approved: February JSPF 2015 March 2015 OD and Workforce Committee October 2016 JSPF Division/Department: Date of review: November 2018 Policy Category: Policy

More information

JOB DESCRIPTION OPHTHALMOLOGY OUTPATIENTS DEPARTMENT

JOB DESCRIPTION OPHTHALMOLOGY OUTPATIENTS DEPARTMENT JOB DESCRIPTION OPHTHALMOLOGY OUTPATIENTS DEPARTMENT Job Title: Housekeeper Grade: Band 1 Responsible to: Accountable to: Job Overview The postholder will provide non-clinical support to the department

More information

Job Description Support Clerical Assistant. Essential: Administrative Experience Experience:

Job Description Support Clerical Assistant. Essential: Administrative Experience Experience: Job Description Support Clerical Assistant Post Title: Support Clerical Assistant Grade: Band 2 Managerially accountable to: Responsible to: Professional Guidance: Key relationships: Medical Secretaries

More information

Records Management Policy

Records Management Policy Records Management Policy Page 1 of 7 Document Control Document name Author Department Policy Nicki Hargreaves (Lead Officer) Good Practice Document status V1.0 Approval Information Governance Steering

More information

Policy:E7. Escalation Policy N/A. Appended below at Appendix B. Version: E7/01

Policy:E7. Escalation Policy N/A. Appended below at Appendix B. Version: E7/01 Policy:E7 Escalation Policy Version: E7/01 Ratified by: Trust Management Team Date ratified: 11 th September 2013 Title of Author: Board Secretary & Head of Governance Title of responsible Director Medical

More information

Lisa Quinn Executive Director of Performance and Assurance. Lead Officer

Lisa Quinn Executive Director of Performance and Assurance. Lead Officer Document Title Reference Number Lead Officer Author(s) (name and designation) Ratified by Data Quality Policy NTW(O)26 Lisa Quinn Executive Director of Performance and Assurance Jennifer Illingworth Deputy

More information

Suspension, Exclusion or Transfer Policy

Suspension, Exclusion or Transfer Policy Suspension, Exclusion or Transfer Policy Solent NHS Trust Policies can only be considered to be valid and up-to-date if viewed on the intranet. Please visit the intranet for the latest version. Purpose

More information

Emergency Preparedness, Resilience & Response (EPRR) Policy

Emergency Preparedness, Resilience & Response (EPRR) Policy A member of: Association of UK University Hospitals Emergency Preparedness, Resilience & Response (EPRR) Policy POLICY NUMBER TP/CO/092 POLICY VERSION V.1 RATIFYING COMMITTEE Clinical Practice Forum,DATE

More information

GENERAL DATA PROTECTION REGULATION

GENERAL DATA PROTECTION REGULATION GENERAL DATA PROTECTION REGULATION (GDPR) What is General Data Protection Regulation (GDPR) What this means for GP Practices Replaces the Data Protection Act 1998 (DPA) Designed to match data privacy laws

More information

GOVERNANCE STRATEGY October 2013

GOVERNANCE STRATEGY October 2013 GOVERNANCE STRATEGY October 2013 1. Introduction 1.1. The Central Manchester University Hospitals NHS Foundation Trust believes that the role of the governing body is pivotal to the success of the Trust.

More information

RISK MANAGEMENT COMMITTEE TERMS OF REFERENCE

RISK MANAGEMENT COMMITTEE TERMS OF REFERENCE RISK MANAGEMENT COMMITTEE TERMS OF REFERENCE Terms of Reference Agreed by the Committee Signed by the Chair on Behalf of the Committee Print Signature Date 16 th December 2011 Review Date December 2012

More information