Presentation is loading. Please wait.

Presentation is loading. Please wait.

1 CQC review of data security standards in the NHS Rosie Wood, Strategy Lead Information Governance Alliance Conference 16 March 2016.

Similar presentations


Presentation on theme: "1 CQC review of data security standards in the NHS Rosie Wood, Strategy Lead Information Governance Alliance Conference 16 March 2016."— Presentation transcript:

1 1 CQC review of data security standards in the NHS Rosie Wood, Strategy Lead Information Governance Alliance Conference 16 March 2016

2 CQC purpose and role Our purpose We make sure health and social care services provide people with safe, effective, compassionate, high-quality care and we encourage care services to improve Our role We monitor, inspect and regulate services to make sure they meet fundamental standards of quality and safety and we publish what we find, including performance ratings to help people choose care 2

3 3 New strategy 2016-21 We aim to adapt and improve We want to become a more efficient and effective regulator so that we stay relevant and sustainable for the future We are working in a changing environment The way that services regulated by CQC are used and delivered is changing CQC must deliver its purpose with fewer resources

4 Our approach  NHS trust inspections will be concluded this year  As part of our next strategy, published in May, we will set out how we want to target and tailor our inspections to risk (e.g. look in depth at a core service in a hospital, improvements required)  We’ll also use this to refine what evidence we look at to inform our inspections and identify risks, which will include information governance and data security  The findings by others about very specialist areas, e.g. food and kitchens, theatre practise, etc. are used to indicate levels of risk  Findings on Data Security is one such specialist area we will include more on 4

5 5 ‘People need to have trust in the NHS and have confidence that their personal medical records will be secure and protected at all times’ - David Behan

6 We were asked to make recommendations on:  How current arrangements can be improved  How the new standards can be assured through CQC inspections, NHS commissioning processes, and any other potential mechanisms Data security review 6 The Secretary of State asked CQC to review the effectiveness of current approaches to data security by NHS organisations when handling confidential patient information

7 Purpose To establish if personal health and care information is being used safely and is appropriately protected in the NHS  To inform the National Data Guardian’s development of standards on the protection of personal information, against which NHS organisations will be held to account  To prompt NHS England, technical suppliers, providers and CQC to think about the steps needed to build on current approaches to information security 7

8 Approach Using a combination of methods to collect robust data on a diverse range of providers 18 NHS Trusts, 22 GP practices and 20 dental practices Individual and group interviews with staff - over 200 people Fieldwork started - November Report completed – January 8

9 Assessment framework Our approach looked at three core themes: People How is risk defined and communicated (to staff, contractors, patients & partners). How well is it understood and delivered? Systems How are incidents avoided, identified, reported and responded to? How is mobile/remote working managed? Technology How are networks and ICT equipment designed, configured and managed to deal with threats and vulnerabilities? 9

10 10 We submitted the report to the Secretary of State at the end of January We are currently working with Department of Health and the National Data Guardian on a coordinated approach to publication of our report and that of Dame Fiona Caldicott on data security standards and a new model of consent/opt-out The publication date has yet to be confirmed by DH Meanwhile, we have prepared our policy, are working on the new Key Lines of Enquiry, and support to staff. Where are we now?

11 www.cqc.org.uk enquiries@cqc.org.uk @CareQualityComm Rosie Wood Strategy Lead 11 Thank you 11


Download ppt "1 CQC review of data security standards in the NHS Rosie Wood, Strategy Lead Information Governance Alliance Conference 16 March 2016."

Similar presentations


Ads by Google