Information Governance and Environmental Impact Policies
Total Page:16
File Type:pdf, Size:1020Kb
Request title: Information Governance and Environmental Impact Policies Reference Number: F2344 Date of Response: 03/01/2020 Further to your Freedom of Information Act request, please find the Trust’s response, in blue bold text below: Request and Royal Devon and Exeter NHS Foundation Trust Response Dear Royal Devon and Exeter NHS Foundation Trust, 1) Please can you send me a copy of the current subject access request acknowledgment AND response letter that you use. Please find attached a copy of an acknowledgment letter (document 1) and response letter (document 2). 2) a copy of the last 5 dpias completed. Section 21(1) of the Freedom of Information Act 2000 provides that information which is reasonably accessible to members of the public otherwise than under section 1 is exempt information. This is an absolute exemption. The Trust publishes basic details of completed DPIAs at https://www.rdehospital.nhs.uk/trust/information- governance/accessing-information/freedom-of-information/data-protection- impact-assessments.html 3) a copy of any internal mandatory information governance training that you give to staff which was written in the last 2 years including presentation slides and videos and any other media Please see attached (document 3 and 4). 4) a copy of any instructions given to staff members to reduce data security breaches, for example double checking work which was written in the last 5 years. To undertake this piece of work would take in excess of the appropriate limit set by the Freedom of Information Act 2000 (section 12 (1)) and defined in the Freedom of Information and Data Protection (Appropriate Limit and Fees) Regulations 2004. The appropriate limit of £450 represents the estimated cost of one person spending two and a half days in determining whether the Trust holds the information, and locating, retrieving and extracting the information. Consequently, the Trust is not obliged by the Freedom of Information Act 2000 to retrieve the above information. This is an absolute exemption. Under Section 16 of the FOI Act we have a duty to provide advice and assistance, therefore please find attached staff guidance created to reduce data security breaches as an example of instructions given to staff in the last five years. 5) a list of any policies implemented in the last 2 years within the organisation to help reduce the environmental impact that the organisation has? Please see attached (document 5 and 6). Royal Devon & Exeter 0 Hospital Wonford 0 Area Q1, Room C 0 Barrack Road 0 Exeter 0 EX2 5DW Information Governance Team IM&T 16 December 2019 Our Ref: 0 Your Ref: Re: 0 Dear 0 Thank you for your request for access to personal data. We have received everything that we require from you and will now proceed with processing your request. To confirm, the start date of your request is: 00 January 1900 In accordance with Article 12 of the General Data Protection Regulation, we are required to respond to your request within one month, however this can be extended by two further months when necessary. To enable us to respond to everyone as quickly as possible, we respectfully ask that you do not contact us about the progress of your application within the first month. Yours Sincerely Information Governance Team Royal Devon & Exeter 0 Hospital Wonford 0 Area Q1, Room C 0 Barrack Road 0 Exeter 0 EX2 5DW Information Governance Team IM&T 16 December 2019 Our Ref: 0 Your Ref: Re: 0 Dear 0 Further to your request for access to the personal data of the above individual, I am pleased to be able to offer you the Trust’s response, enclosed. In order to locate the information you requested, I undertook the following searches: • • If you are in any way dissatisfied with how your request has been handled or responded to, please outline your concerns in writing to [email protected] or to: Information Governance Team Area Q1, Room C Royal Devon & Exeter Hospital Barrack Road Exeter EX2 5DW I hope that this information is of assistance to you. Yours Sincerely Information Governance Team Data Security Protection Training v2.2 2. Untitled Scene 2.1 Untitled Slide 2.2 MODULE DURATION Published by Articulate® Storyline www.articulate.com 2.3 SPECIAL INSTRUCTION Guidance (Slide Layer) 2.4 MENU Published by Articulate® Storyline www.articulate.com 2.5 DATA SECURITY AND PROTECTION 2.6 NHS IG OPERATING FRAMEWORK Published by Articulate® Storyline www.articulate.com 2.7 KEY AREAS 2.8 CONFIDENTIALITY Published by Articulate® Storyline www.articulate.com 2.9 EU LAW - GENERAL DATA PROTECTION LEGISLATION 2016 2.10 UK LAW - THE DATA PROTECTION ACT Published by Articulate® Storyline www.articulate.com 2.11 PERSONAL INFORMATION 2.12 SPECIAL CATEGORY DATA Published by Articulate® Storyline www.articulate.com 2.13 CONFIDENTIAL INFORMATION 2.14 DISCLOSING INFORMATION Published by Articulate® Storyline www.articulate.com 2.15 INDIVIDUAL’S RIGHTS 2.16 SUBJECT ACCESS REQUESTS Published by Articulate® Storyline www.articulate.com 2.17 CALDICOTT GUARDIAN 2.18 CALDICOTT PRINCIPLES Published by Articulate® Storyline www.articulate.com 2.19 NDG DATA SECURITY STANDARDS 2.20 10 DATA SECURITY STANDARDS Published by Articulate® Storyline www.articulate.com 2.21 INFORMATION ASSET OWNERS 2.22 UK LAW - THE FREEDOM OF INFORMATION ACT Published by Articulate® Storyline www.articulate.com 2.23 THE INFORMATION COMMISSIONER'S OFFICE 2.24 RECORDS MANAGEMENT Published by Articulate® Storyline www.articulate.com Records Man (Slide Layer) Public Records (Slide Layer) Published by Articulate® Storyline www.articulate.com Personal Information (Slide Layer) 2.25 INFORMATION QUALITY Published by Articulate® Storyline www.articulate.com 2.26 INFORMATION QUALITY High (Slide Layer) Published by Articulate® Storyline www.articulate.com Poor (Slide Layer) 2.27 INFORMATION ASSURANCE Published by Articulate® Storyline www.articulate.com 2.28 INFORMATION SECURITY IS EVERYONE'S RESPONSIBILITY 2.29 TOP TIPS FOR CYBER SECURITY Published by Articulate® Storyline www.articulate.com 2.30 TOPS TIPS FOR CYBER SECURITY 2.31 REPORTING INCIDENTS AND SECURITY WEAKNESSES Published by Articulate® Storyline www.articulate.com 2.32 DATA SECURITY RISKS - SCENARIO The Situation (Slide Layer) Published by Articulate® Storyline www.articulate.com The Organisation's reaction (Slide Layer) Consequences (Slide Layer) Published by Articulate® Storyline www.articulate.com Actions (Slide Layer) 2.33 EMAIL BREACH- SCENARIO Published by Articulate® Storyline www.articulate.com The Situation (Slide Layer) The Organisation's reaction (Slide Layer) Published by Articulate® Storyline www.articulate.com Consequences (Slide Layer) Actions P1 (Slide Layer) Published by Articulate® Storyline www.articulate.com Actions P2 (Slide Layer) 2.34 SECURITY MEASURES Published by Articulate® Storyline www.articulate.com Transportation (Slide Layer) Telephone (Slide Layer) Published by Articulate® Storyline www.articulate.com Fax (Slide Layer) Post (Slide Layer) Published by Articulate® Storyline www.articulate.com Email (Slide Layer) Eavesdropping (Slide Layer) Published by Articulate® Storyline www.articulate.com Incidents (Slide Layer) Encryption (Slide Layer) Published by Articulate® Storyline www.articulate.com 2.35 MANAGING INFORMATION RISKS Published by Articulate® Storyline www.articulate.com Follow the 10 Commandments to avoid Information Security breaches 1. Avoid gossip and use of inappropriate venues for discussion of patient care/confidential information. 2. Do not look up or handle your own or family/friend(s) information (either electronic or paper) – you do not need to know this information in order to do your job. All systems are audited. 3. Check identity before giving out details and only provide information if the person asking has a right to know. If in doubt pass to a senior member of staff or refer to the Information Governance Team. Information Governance Follow the 10 Commandments to avoid Information Security breaches 4. Do not save information on your desktop – use the Trust’s Network Drive. 5. Anonymise information wherever possible before sending electronically and follow the Trust’s Faxing / Email procedures. 6. Do not share passwords or leave yourself logged on, always remember you are personally responsible for any unauthorised access to systems. 7. Only use USB sticks ordered through the Trust (they are encrypted.) Information Governance Follow the 10 Commandments to avoid Information Security breaches 8. Confidential / personally identifiable information must be destroyed securely and should be placed in white confidential waste bags which should be stored securely. Blue Bins (CWO) are now placed at Trust exits. 9. Close doors, lock cabinets and don’t let people tail gate behind you into secure areas. All staff should wear their ID badge at all times. Do not be afraid to ask someone before allowing entry. 10. When leaving your desk please ensure that you LOCK your computer and do not leave documents unattended on your desk!!!!!!!!! Information Governance SUSTAINABLE DEVELOPMENT MANAGEMENT PLAN 2019/2020 Foreword Sustainability is no longer the preserve of niche organisations; some of the largest and most profitable businesses in the world have identified that sustainable business practice is common sense and integral to their ongoing success. All organisations are required to make changes to ensure the well- being of society, to maintain and improve the quality of our environment and to be financially stable. Social, environmental and economic sustainability are concepts which are well understood; there is clear evidence available as to the benefits of sustainable practices a mature body of guidance available on how to make the NHS more sustainable and firm scientific evidence of the risks present if it does not change. In addition to this, the recent protests seen across various schools and within city centres show that there is now a strong social movement behind tackling climate change that the government and public sector must respond to. As a public sector healthcare provider, the RD&E has a conspicuous obligation to society to deliver its services in a fair and sustainable way.