(Opinion Article) Pathway to Privacy: Time to Take Ownership of Re-building Trust with Patients

FairWarningBy Tim Dunn, General Manager, FairWarning.
The government has finally published its long-awaited response to the Caldicott2 review of information sharing in the NHS - and, as many of us had hoped, has accepted all of its recommendations. It's a landmark moment that could see the NHS turn an important corner and stride progressively towards building transformational models of care.

After years of analysis and consultation about the merits of electronic healthcare, the time for debate is over.

There are key elements within Caldicott2 I believe will be essential in assuring the confidence and trust of patients and healthcare professionals, they include: the duty of candor and notification of data breaches, how they happened and what remediation steps are being taken; a patient's right to know of "everyone and anyone" who has accessed their record; a robust audit and enforcement framework agreed between the Information Commissioners Office (ICO) and Care Quality Commission (CQC) and electronic health records (HER) vendors supporting audit and logs on access activity.

The Government response reaffirms the belief that better information sharing can help the NHS meet many of its strategic goals, and lead to more effective and efficient healthcare services, enhanced care pathways and improved patient outcomes. But a critical success factor for sharing health information will be ensuring that it is done in such a way that it reassures patients that their privacy will be protected.

The Caldicott2 recommendation that patients should have availability to 'details on everyone and anyone who has accessed their record', along with the requirement 'to notify patients when their records have been breached', represents a huge step towards transparent healthcare. But to deliver it, the NHS needs to foster a culture of collective responsibility for patient privacy, and drive accountability across local organisations.

At a local level, ownership for driving change and leading NHS organisations towards secure electronic healthcare largely rests with a triumvirate of key stakeholders; CEOs, Senior Information Risk Officers (SIRO) and Caldicott Guardians.

Responsibilities
As trusts grapple with strategic challenges to ensure they are financially robust and competitive within the new commissioning environment, hospitals are increasingly recognising the role that digital healthcare can play in meeting their objectives. As a result, the development of EHR systems, in line with the government timetable for electronic patient records, has become a major priority. Although the CEO is ultimately accountable for data control on behalf of a trust, responsibility for overall ownership of the organisation's Information Risk Policy is delegated to the SIRO.

SIROs have been in existence within trusts for a number of years, but the significance of the role has been reinforced by the Department of Health (DH) response to Caldicott2. The function, performed in addition to individuals' existing NHS roles, is defined as an Executive Director or Senior Management Board member who is formally responsible for the organisation's standards of practice for information governance.

The SIRO acts as the Board's 'champion' for information risk, advising the CEO on the organisation's information governance strategy and capabilities. As a prominent board member, the SIRO is naturally familiar with a trust's wider strategic goals. But the challenge is to understand how those goals may be impacted by information risks and how, in turn, those risks should be managed.

The SIRO's key purpose is to lead and implement Information Governance risk assessment and management processes, and provide assurance to the CEO and board of the effectiveness of the trust's information risk management. It is a significant responsibility and, since trusts commonly have high volumes of information assets, is not something that can be managed alone. The SIRO must work collaboratively with internal and external stakeholders to reinforce a culture of privacy and drive accountability and responsibility across an NHS organisation.

Alongside SIROs, Caldicott Guardians are also growing in influence. Originally introduced to provide trust boards with advice on how patient information should be shared - acting as the 'conscience of the organisation' - the Caldicott Guardian’s role is now being extended to take a greater lead on information governance, Its primary purposes are to ensure information governance is effective and to provide oversight of information sharing amongst clinicians.

But distinct from SIROs - whose remit is to look at risks across all information systems - Caldicott Guardians are solely focused on patient identifiable information. Their rationale is to safeguard and govern uses of patient information within a trust, as well as data flows to other NHS and non-NHS organisations.

In this context, there is now the opportunity and indeed the expectation that Caldicott Guardians will take ownership of the implementation of Caldicott2 for their organisation and, as a fellow board member, they must work closely with the SIRO to ensure a trust's information risk strategy protects patient confidentiality.

Where next?
So armed with a robust framework to underpin the secure and effective implementation of information sharing, how can NHS organisations make the move from ideology to delivery? Trusts that make the greatest strides towards protecting patient confidentiality will be those where the SIRO and the Caldicott Guardian work closely together.

Best practice examples show that the most proactive trusts have embraced the need to ensure organisation-wide understanding of the importance of data sharing and patient confidentiality - and, championed by both SIROs and Caldicott Guardians, have facilitated sustained engagement with Information Asset Owners and trust staff to develop a culture of privacy.

The effective use of technology has also proved a critical success factor. The requirement to report privacy breaches has placed SIROs under increased pressure to ensure trusts are maintaining the highest standards of information governance - indeed DH training for SIROs states that any privacy breach could be a 'career-ending event'. But innovative solutions are there to support them.

Technology is readily available that can provide increased transparency regarding who is accessing patient records and enable trusts to monitor access proactively. In fact, the government's response to Caldicott2 highlighted the effective use of privacy breach detection tools (or patient privacy monitoring solutions as they are often called) in NHS Scotland as a good example of best practice.

Use of such technology can significantly help SIROs underpin their responsibilities for information assurance and, in the process, facilitate the optimal use of patient data to support the strategic goals outlined by the CEO and board. Patient privacy monitoring solutions provide SIROs with greater assurance that data access is appropriate and can protect a trust’s reputation by mitigating the risk of confidentiality breaches. Furthermore, the use of technology can help trusts reinforce a culture of privacy.

Caldicott2 represents a significant milestone in the UK's ambitions to harness the power of information. To seize the opportunity, SIROs should redouble their efforts to drive collective responsibility across the organisation, and set up an appropriate information risk framework that focuses the trust on the importance of data transparency. And, as an increasing number of UK trusts are beginning to do, they should consider putting in place the appropriate technology that underpins the Caldicott2 recommendations.

The secure, timely and effective sharing of patient information can transform healthcare services in the UK. But it will only succeed if patients' personal data is treated with propriety and respect. As Jeremy Hunt said in his endorsement of the Caldicott2 recommendations, "the prize for achieving this is very great indeed."

About FairWarning, Inc.
FairWarning empowering care providers to grow their reputation for protecting confidentiality, scale their digital health initiatives and comply with complex privacy laws. By partnering with FairWarning, care providers are able to direct their focus on delivering the best patient outcomes possible while receiving expert, sustainable and affordable privacy and compliance solutions. Customers consider FairWarning such as ARRA HITECH privacy and meaningful use criteria, HIPAA, UK and EU Data Protection, and Canadian provincial healthcare privacy law.

Most Popular Now

SPARK TSL Acquires Sentean Group

SPARK TSL is acquiring Sentean Group, a Dutch company with a complementary background in hospital entertainment and communication, and bringing its Fusion Bedside platform for clinical and patient apps to...

ChatGPT Extracts Data for Ischaemic Stro…

In an ischaemic stroke, an artery in the brain is blocked by blood clots and the brain cells can no longer be supplied with blood as a result. Doctors must...

Herefordshire and Worcestershire Health …

Herefordshire and Worcestershire Health and Care NHS Trust has successfully implemented Alcidion's Miya Precision platform to streamline bed management workflow across seven community hospitals in Worcestershire. The trust delivers community...

A Shortcut for Drug Discovery

For most human proteins, there are no small molecules known to bind them chemically (so called "ligands"). Ligands frequently represent important starting points for drug development but this knowledge gap...

New Horizon Europe Funding Boosts Europe…

The European Commission has announced the launch of new Horizon Europe calls, with a substantial funding pool of over €112 million. These calls are aimed primarily at pioneering projects in...

Cleveland Clinic Study Finds AI can Deve…

Cleveland Clinic researchers developed an artficial intelligence (AI) model that can determine the best combination and timeline to use when prescribing drugs to treat a bacterial infection, based solely on...

New AI-Technology Estimates Brain Age Us…

As people age, their brains do, too. But if a brain ages prematurely, there is potential for age-related diseases such as mild-cognitive impairment, dementia, or Parkinson's disease. If "brain age...

Radboud University Medical Center and Ph…

Royal Philips (NYSE: PHG, AEX: PHIA), a global leader in health technology, and Radboud University Medical Center have signed a hospital-wide, long-term strategic partnership that delivers the latest patient monitoring...

With Huge Patient Dataset, AI Accurately…

Scientists have designed a new artificial intelligence (AI) model that emulates randomized clinical trials at determining the treatment options most effective at preventing stroke in people with heart disease. The model...

GPT-4, Google Gemini Fall Short in Breas…

Use of publicly available large language models (LLMs) resulted in changes in breast imaging reports classification that could have a negative effect on patient management, according to a new international...

ChatGPT fails at heart risk assessment

Despite ChatGPT's reported ability to pass medical exams, new research indicates it would be unwise to rely on it for some health assessments, such as whether a patient with chest...

Study Shows ChatGPT Failed when Challeng…

With artificial intelligence (AI) poised to become a fundamental part of clinical research and decision making, many still question the accuracy of ChatGPT, a sophisticated AI language model, to support...