SlideShare una empresa de Scribd logo
1 de 29
Governance and Data
            Protection in the Health
            Sector


          Billy Hawkes
          Data Protection Commissioner


Health Informatics Workshop
Dublin, 16 November 2011
Presentation Outline
• What Should Be
• What Is
• What Can Be?
The Governance Challenge
• What does an Organisation in the Health
  Sector need to do to be considered a
  good “corporate citizen” in its treatment of
  personal data?
• How would it demonstrate this
  accountability in practice:
   To its Customers/Clients?
   To a Regulator?
Accountability: Essential Elements
  1. Organisation commitment to accountability
     and adoption of internal policies consistent
     with external criteria.
  2. Mechanisms to put privacy policies into
     effect, including tools, training and
     education.
  3. Systems for internal, ongoing oversight and
     assurance reviews and external verification.
  4. Transparency and mechanisms for individual
     participation.
  5. Means for remediation and external
     enforcement.
       http://www.huntonfiles.com/files/webupload/
       CIPL_Galway_Accountability_Paper.pdf
Demonstrating Accountability
• Policies
• Executive oversight
• Staffing and delegation
• Education and awareness
• Ongoing risk assessment and mitigation
• Program risk assessment oversight and
  validation
• Event management and complaint handling
• Internal enforcement
• Redress
Data Protection – a
Fundamental Human Right
• Implicit Right to Personal Privacy under Irish
  Constitution – Article 40.3.1
• Explicit Right to Personal Privacy under Article
  8 of 1950 European Convention for the
  Protection of Human Rights & Fundamental
  Freedoms [ECHR]
     ECHR now indirectly part of Irish law due to ECHR
      Act 2003
• Explicit Right to Data Protection under EU
  Treaties – Lisbon Treaty and EU Charter
EU Charter of Fundamental
Rights: Article 8
• Protection of personal data
• 1. Everyone has the right to the protection of
  personal data concerning him or her.
  2. Such data must be processed fairly for specified
  purposes and on the basis of the consent of the
  person concerned or some other legitimate basis laid
  down by law. Everyone has the right of access to
  data which has been collected concerning him or
  her, and the right to have it rectified.
  3. Compliance with these rules shall be subject to
  control by an independent authority.
EU & Irish Legislation
• Data Protection Directive   • Data Protection Acts
  95/46/EC
      Being updated            1988 & 2003

• Electronic Privacy
  Directive 2002/58/EC        • EC Electronic Privacy
  (as amended by                Regulations 2011 (SI
  2006/24/EC +                  336/2011)
  2009/136/EC)
Data Protection & Health
Data
• Data on physical or mental health or
  condition or sexual life are
  ‘sensitive personal data’ with
  special protection
• Complements ethical duty of medical
  confidentiality
Eurobarometer Survey
(2011): Privacy most
important in relation to:
1. Medical Records       6. Social Welfare History
2. Financial History     7. Telephone / Internet
3. Credit Card Details      Records

4. PPS Number            8. Personal Emails
                         9. CV Details
5. Garda Record
                         10. Personal Telephone
                             Number
Presentation Outline
• What Should Be
• What Is
• What Can Be?
Health Sector Audits: 2007-1010
 •   Large Public Hospital
 •   Large Voluntary Hospital
 •   5 GP/General Clinics
 •   Health Insurer
 •   Nursing Home Repayment Scheme
 •   Pharmacy
 •   Out-of-hours Facility
Large Voluntary Hospital
Audit
• “good organisational awareness of data
  protection principles”
• “good technical security measures were in
  place”
• Main concern: physical security
     Access to Chart Room
• Positive response to specific recommendations
Large Public Hospital Audit (1)
• “Data protection, from a governance perspective,
  is falling well short of what would be expected
  in an organisation collecting and processing vast
  amounts of sensitive personal data”
• “Critically, it is unclear where responsibility lies for
  the practical application of data protection policies and
  procedures on a day to day basis …In order to correct
  the many data protection concerns which have been
  highlighted in the report, this issue of responsibility
  must first be addressed.”
• “Having regard to the primary goal of the audit “to
  establish whether care was delivered in a manner that
  gave due respect to the legitimate privacy
  expectations of patients”, the issues raised in this
  audit are of such a scale that this Office is not in a
  position at present to indicate that this is the
  case.”
Large Public Hospital Audit (2)
• “In terms of security alone, the inspection
  Team encountered numerous breaches of the
  Data Protection Acts during the course of the
  audit, including:
     Files left in public / unsecure areas
     Inoperative security mechanisms on file storage
      areas
     Patient data stored in corridors
     Medical data sent by unsecure email
     USB ports not locked down
     Lack of system access controls
     Lack of physical access controls to sensitive areas”
GP Clinics
• “good awareness of data protection principles
  generally”.
• “one area requiring attention is the location
  and storage of the physical patient files”
• IT Security
• Extent of access to medical records by non-
  medical personnel
• Data Retention
Follow-up: GPs
• “A Working Group was established in early
  2010 following the discussions between the
  Office of the Data Protection Commissioner
  and the ICGP in response to the findings of the
  Office of the Data Protection Commissioner
  following audits it carried out on a number of
  GP practices”
     Foreword to A Guide to Data Protection Legislation
      for Irish General Practice, April 2011
• Guide, Templates @:
  http://www.icgp.ie/go/in_the_practice/informat
  ion_technology/data_protection
Follow-up: Hospitals/General
• Input to HIQA work on Standards for Health
 Information Governance
      http://www.hiqa.ie/standards/health-information-
      standards
   What   you should know about Information
      Governance & Self-Assessment Tool(October 11)
• Input to Health Information Bill
Presentation Outline
• What Should Be
• What Is
• What Can Be?
Good Practice: General
• Transparent and Balanced approach to
  collecting and using patient data
• Patients should know what you are doing
  with their personal data
• Consult DPC and other guidance
  (www.dataprotection.ie; www.hiqa.ie)
Good Practice: Audit
• Do we know what types of personal data we hold?
      Electronically (also CCTV images)
      Paper
• Can we justify:
      Why we collect it?
      What it is used for?
      Length of time we hold it?
      Who has access to it?
      Who it is disclosed to?
• Use HIQA Information Governance Self-Assessment Tool
Good Practice: Access &
Correction Requests
• Can we :
   Provide a description of the personal data
    we hold on an individual patient within a
    max. of 20 days?
   Provide copy of this data within a max. of 40
    Days?
   Correct or erase data within 40 days?
Good Practice: Security
 • Access Controls
    Electronic   patient systems secure
    Paper Files
    Audit Trails
 • Vulnerabilities
    Portable   Devices
Good Practice - Need to
Know Access
• Must be able to stand over all access to personal data
  as justifiable within an organisation
      Balance between needed access and data protection
• ECHR Judgment of 17 July 2008 - CASE OF I v.
  FINLAND (Application no. 20511/03) – obligation to be
  able to stand over all access to health data on a need
  to know basis
• Access to sensitive personal data must be even more
  restricted. Locked cabinets for manual data etc
• Different medical teams/different users – different
  access
Good Practice: Disposal
•   Do not retain patient records for any longer
    than can be objectively justified: clear policy
•   Comply with legal retention obligations
•   Orderly and secure disposal of old records
Good Practice : People
•   Does everyone handling personal data know
    their responsibilities under Data Protection
    Law? Is this routinely included in
    training/induction?
•   Are procedures for handling personal data
    properly documented?
•   Are DP compliance responsibilities clearly
    allocated?
Good Practice: If things go
wrong …
• Have a clear plan – what will you do if
  there is a security breach?
• Notify DPC and patients
   DPC   Code of Practice and Guidance
• Tell patients how you intend to remedy
  any damage done to their interests
Good Practice - Research
• Anticipate how you intend to use patient data,
  fully inform patient and get written consent
  or
• Anonymise the data effectively (DP
  legislation only applies to data attributable to
  an identifiable person) before using for
  research – still best to tell the patient
• Consult DPC Guidelines
      Data Protection Guidelines on Research in the
       Health Sector
        • http://www.dataprotection.ie/documents/guidance/Health_
         research.pdf
Thank You
Further Guidance

• www.dataprotection.ie

• Data Protection Commissioner, Canal House,
  Station Road, Portarlington, Co Laois
  Tel. 1890-252231 (Lo-call), 057-8684800

Más contenido relacionado

La actualidad más candente

Big Data and Smart Healthcare
Big Data and Smart Healthcare Big Data and Smart Healthcare
Big Data and Smart Healthcare Sujan Perera
 
Reviewing the Healthcare Analytics Adoption Model: A Roadmap and Recipe for A...
Reviewing the Healthcare Analytics Adoption Model: A Roadmap and Recipe for A...Reviewing the Healthcare Analytics Adoption Model: A Roadmap and Recipe for A...
Reviewing the Healthcare Analytics Adoption Model: A Roadmap and Recipe for A...Health Catalyst
 
The Data Operating System: Changing the Digital Trajectory of Healthcare
The Data Operating System: Changing the Digital Trajectory of HealthcareThe Data Operating System: Changing the Digital Trajectory of Healthcare
The Data Operating System: Changing the Digital Trajectory of HealthcareDale Sanders
 
Csc8710 001 winter2014-mohammed_shahnawazali-ff2687_presentation_final
Csc8710 001 winter2014-mohammed_shahnawazali-ff2687_presentation_finalCsc8710 001 winter2014-mohammed_shahnawazali-ff2687_presentation_final
Csc8710 001 winter2014-mohammed_shahnawazali-ff2687_presentation_finalff2687
 
Big implications of Big Data in healthcare
Big implications of Big Data in healthcareBig implications of Big Data in healthcare
Big implications of Big Data in healthcareGuires
 
Why Payers, Providers and Life Science/Pharma Must Join Forces to Achieve Tru...
Why Payers, Providers and Life Science/Pharma Must Join Forces to Achieve Tru...Why Payers, Providers and Life Science/Pharma Must Join Forces to Achieve Tru...
Why Payers, Providers and Life Science/Pharma Must Join Forces to Achieve Tru...Health Catalyst
 
Data-Driven Healthcare for Manufacturers
Data-Driven Healthcare for Manufacturers Data-Driven Healthcare for Manufacturers
Data-Driven Healthcare for Manufacturers Amit Mishra
 
Demystifying Healthcare Data Governance
Demystifying Healthcare Data GovernanceDemystifying Healthcare Data Governance
Demystifying Healthcare Data GovernanceHealth Catalyst
 
Getting to the Wrong Answer Faster with Your Analytics: Shifting to a Better ...
Getting to the Wrong Answer Faster with Your Analytics: Shifting to a Better ...Getting to the Wrong Answer Faster with Your Analytics: Shifting to a Better ...
Getting to the Wrong Answer Faster with Your Analytics: Shifting to a Better ...Health Catalyst
 
Using Analytics to Increase Cash Flow
Using Analytics to Increase Cash FlowUsing Analytics to Increase Cash Flow
Using Analytics to Increase Cash FlowHealth Catalyst
 
A Reference Architecture for Digital Health: The Health Catalyst Data Operati...
A Reference Architecture for Digital Health: The Health Catalyst Data Operati...A Reference Architecture for Digital Health: The Health Catalyst Data Operati...
A Reference Architecture for Digital Health: The Health Catalyst Data Operati...Health Catalyst
 
Big Data in Medicine
Big Data in MedicineBig Data in Medicine
Big Data in MedicineNasir Arafat
 
DAMA Webinar - Big and Little Data Quality
DAMA Webinar - Big and Little Data QualityDAMA Webinar - Big and Little Data Quality
DAMA Webinar - Big and Little Data QualityDATAVERSITY
 
Optimize Your Healthcare Data Quality Investment: Three Ways to Accelerate Ti...
Optimize Your Healthcare Data Quality Investment: Three Ways to Accelerate Ti...Optimize Your Healthcare Data Quality Investment: Three Ways to Accelerate Ti...
Optimize Your Healthcare Data Quality Investment: Three Ways to Accelerate Ti...Health Catalyst
 
Chronic care management_success_story1.3
Chronic care management_success_story1.3Chronic care management_success_story1.3
Chronic care management_success_story1.3Faichi Solutions
 
Healthcare 2.0: The Age of Analytics
Healthcare 2.0: The Age of AnalyticsHealthcare 2.0: The Age of Analytics
Healthcare 2.0: The Age of AnalyticsDale Sanders
 
Big data in healthcare
Big data in healthcareBig data in healthcare
Big data in healthcareDeZyre
 
Microsoft: A Waking Giant In Healthcare Analytics and Big Data
Microsoft: A Waking Giant In Healthcare Analytics and Big DataMicrosoft: A Waking Giant In Healthcare Analytics and Big Data
Microsoft: A Waking Giant In Healthcare Analytics and Big DataHealth Catalyst
 
IRJET- Integration of Big Data Analytics in Healthcare Systems
IRJET- Integration of Big Data Analytics in Healthcare SystemsIRJET- Integration of Big Data Analytics in Healthcare Systems
IRJET- Integration of Big Data Analytics in Healthcare SystemsIRJET Journal
 
The future of healthcare and big data
The future of healthcare and big dataThe future of healthcare and big data
The future of healthcare and big dataCharles Barnett
 

La actualidad más candente (20)

Big Data and Smart Healthcare
Big Data and Smart Healthcare Big Data and Smart Healthcare
Big Data and Smart Healthcare
 
Reviewing the Healthcare Analytics Adoption Model: A Roadmap and Recipe for A...
Reviewing the Healthcare Analytics Adoption Model: A Roadmap and Recipe for A...Reviewing the Healthcare Analytics Adoption Model: A Roadmap and Recipe for A...
Reviewing the Healthcare Analytics Adoption Model: A Roadmap and Recipe for A...
 
The Data Operating System: Changing the Digital Trajectory of Healthcare
The Data Operating System: Changing the Digital Trajectory of HealthcareThe Data Operating System: Changing the Digital Trajectory of Healthcare
The Data Operating System: Changing the Digital Trajectory of Healthcare
 
Csc8710 001 winter2014-mohammed_shahnawazali-ff2687_presentation_final
Csc8710 001 winter2014-mohammed_shahnawazali-ff2687_presentation_finalCsc8710 001 winter2014-mohammed_shahnawazali-ff2687_presentation_final
Csc8710 001 winter2014-mohammed_shahnawazali-ff2687_presentation_final
 
Big implications of Big Data in healthcare
Big implications of Big Data in healthcareBig implications of Big Data in healthcare
Big implications of Big Data in healthcare
 
Why Payers, Providers and Life Science/Pharma Must Join Forces to Achieve Tru...
Why Payers, Providers and Life Science/Pharma Must Join Forces to Achieve Tru...Why Payers, Providers and Life Science/Pharma Must Join Forces to Achieve Tru...
Why Payers, Providers and Life Science/Pharma Must Join Forces to Achieve Tru...
 
Data-Driven Healthcare for Manufacturers
Data-Driven Healthcare for Manufacturers Data-Driven Healthcare for Manufacturers
Data-Driven Healthcare for Manufacturers
 
Demystifying Healthcare Data Governance
Demystifying Healthcare Data GovernanceDemystifying Healthcare Data Governance
Demystifying Healthcare Data Governance
 
Getting to the Wrong Answer Faster with Your Analytics: Shifting to a Better ...
Getting to the Wrong Answer Faster with Your Analytics: Shifting to a Better ...Getting to the Wrong Answer Faster with Your Analytics: Shifting to a Better ...
Getting to the Wrong Answer Faster with Your Analytics: Shifting to a Better ...
 
Using Analytics to Increase Cash Flow
Using Analytics to Increase Cash FlowUsing Analytics to Increase Cash Flow
Using Analytics to Increase Cash Flow
 
A Reference Architecture for Digital Health: The Health Catalyst Data Operati...
A Reference Architecture for Digital Health: The Health Catalyst Data Operati...A Reference Architecture for Digital Health: The Health Catalyst Data Operati...
A Reference Architecture for Digital Health: The Health Catalyst Data Operati...
 
Big Data in Medicine
Big Data in MedicineBig Data in Medicine
Big Data in Medicine
 
DAMA Webinar - Big and Little Data Quality
DAMA Webinar - Big and Little Data QualityDAMA Webinar - Big and Little Data Quality
DAMA Webinar - Big and Little Data Quality
 
Optimize Your Healthcare Data Quality Investment: Three Ways to Accelerate Ti...
Optimize Your Healthcare Data Quality Investment: Three Ways to Accelerate Ti...Optimize Your Healthcare Data Quality Investment: Three Ways to Accelerate Ti...
Optimize Your Healthcare Data Quality Investment: Three Ways to Accelerate Ti...
 
Chronic care management_success_story1.3
Chronic care management_success_story1.3Chronic care management_success_story1.3
Chronic care management_success_story1.3
 
Healthcare 2.0: The Age of Analytics
Healthcare 2.0: The Age of AnalyticsHealthcare 2.0: The Age of Analytics
Healthcare 2.0: The Age of Analytics
 
Big data in healthcare
Big data in healthcareBig data in healthcare
Big data in healthcare
 
Microsoft: A Waking Giant In Healthcare Analytics and Big Data
Microsoft: A Waking Giant In Healthcare Analytics and Big DataMicrosoft: A Waking Giant In Healthcare Analytics and Big Data
Microsoft: A Waking Giant In Healthcare Analytics and Big Data
 
IRJET- Integration of Big Data Analytics in Healthcare Systems
IRJET- Integration of Big Data Analytics in Healthcare SystemsIRJET- Integration of Big Data Analytics in Healthcare Systems
IRJET- Integration of Big Data Analytics in Healthcare Systems
 
The future of healthcare and big data
The future of healthcare and big dataThe future of healthcare and big data
The future of healthcare and big data
 

Similar a Governance And Data Protection In The Health Sector - Billy Hawkes

Annual environment and health conference 2018 fionnuala donohue hse epa data ...
Annual environment and health conference 2018 fionnuala donohue hse epa data ...Annual environment and health conference 2018 fionnuala donohue hse epa data ...
Annual environment and health conference 2018 fionnuala donohue hse epa data ...Environmental Protection Agency, Ireland
 
Information governance
Information governanceInformation governance
Information governanceGerardo Medina
 
Anne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for ResearchersAnne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for Researcherskclcompbio
 
Health Data Sharing Scene Setting
Health Data Sharing Scene Setting Health Data Sharing Scene Setting
Health Data Sharing Scene Setting ipposi
 
HISI conference 2016 - Derick Mitchell - November 16th 2016
HISI conference 2016 - Derick Mitchell - November 16th 2016HISI conference 2016 - Derick Mitchell - November 16th 2016
HISI conference 2016 - Derick Mitchell - November 16th 2016ipposi
 
Things you need to know about info governance to sell healthtech products int...
Things you need to know about info governance to sell healthtech products int...Things you need to know about info governance to sell healthtech products int...
Things you need to know about info governance to sell healthtech products int...3GDR
 
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...Health IT Conference – iHT2
 
NCVHS Privacy and Security Update
NCVHS Privacy and Security Update NCVHS Privacy and Security Update
NCVHS Privacy and Security Update Brian Ahier
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture ECMDLearning
 
Ann Cavoukian Presentation
Ann Cavoukian PresentationAnn Cavoukian Presentation
Ann Cavoukian PresentationCityAge
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterBrowne Jacobson LLP
 
In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017
In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017
In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017ipposi
 
Information governance considerations in developing healthcare applications
Information governance considerations in developing healthcare applicationsInformation governance considerations in developing healthcare applications
Information governance considerations in developing healthcare applicationsHANDI HEALTH
 

Similar a Governance And Data Protection In The Health Sector - Billy Hawkes (20)

Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 
Annual environment and health conference 2018 fionnuala donohue hse epa data ...
Annual environment and health conference 2018 fionnuala donohue hse epa data ...Annual environment and health conference 2018 fionnuala donohue hse epa data ...
Annual environment and health conference 2018 fionnuala donohue hse epa data ...
 
Information governance
Information governanceInformation governance
Information governance
 
Anne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for ResearchersAnne Cameron - An Introduction to the Data Protection Act for Researchers
Anne Cameron - An Introduction to the Data Protection Act for Researchers
 
Health Data Sharing Scene Setting
Health Data Sharing Scene Setting Health Data Sharing Scene Setting
Health Data Sharing Scene Setting
 
HISI conference 2016 - Derick Mitchell - November 16th 2016
HISI conference 2016 - Derick Mitchell - November 16th 2016HISI conference 2016 - Derick Mitchell - November 16th 2016
HISI conference 2016 - Derick Mitchell - November 16th 2016
 
Protection of patient data in EU vs. US
Protection of patient data in EU vs. USProtection of patient data in EU vs. US
Protection of patient data in EU vs. US
 
Things you need to know about info governance to sell healthtech products int...
Things you need to know about info governance to sell healthtech products int...Things you need to know about info governance to sell healthtech products int...
Things you need to know about info governance to sell healthtech products int...
 
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
Keynote Presentation "Building a Culture of Privacy and Security into Your Or...
 
The Health Information Governance Framework
The Health Information Governance FrameworkThe Health Information Governance Framework
The Health Information Governance Framework
 
HSCIC's Professor Martin Severs previewing the HSCIC's forthcoming 'New Code ...
HSCIC's Professor Martin Severs previewing the HSCIC's forthcoming 'New Code ...HSCIC's Professor Martin Severs previewing the HSCIC's forthcoming 'New Code ...
HSCIC's Professor Martin Severs previewing the HSCIC's forthcoming 'New Code ...
 
NCVHS Privacy and Security Update
NCVHS Privacy and Security Update NCVHS Privacy and Security Update
NCVHS Privacy and Security Update
 
EHR - A Consumer Perspective
EHR - A Consumer PerspectiveEHR - A Consumer Perspective
EHR - A Consumer Perspective
 
Health data - Is it safe?
Health data - Is it safe?Health data - Is it safe?
Health data - Is it safe?
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture E
 
Ann Cavoukian Presentation
Ann Cavoukian PresentationAnn Cavoukian Presentation
Ann Cavoukian Presentation
 
Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Hipaa and social media using new
Hipaa and social media using newHipaa and social media using new
Hipaa and social media using new
 
In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017
In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017
In Electronic Health Records We Trust - IPPOSI Outcome Report - March 2017
 
Information governance considerations in developing healthcare applications
Information governance considerations in developing healthcare applicationsInformation governance considerations in developing healthcare applications
Information governance considerations in developing healthcare applications
 

Más de healthcareisi

Gerard Hurl - Industry Presentation 26-04-12
Gerard Hurl - Industry Presentation 26-04-12Gerard Hurl - Industry Presentation 26-04-12
Gerard Hurl - Industry Presentation 26-04-12healthcareisi
 
Using Technology To Help People - Ilana Rozannes
Using Technology To Help People - Ilana RozannesUsing Technology To Help People - Ilana Rozannes
Using Technology To Help People - Ilana Rozanneshealthcareisi
 
The Electronic Medical Record - David Beausang
The Electronic Medical Record - David BeausangThe Electronic Medical Record - David Beausang
The Electronic Medical Record - David Beausanghealthcareisi
 
The Effects Of Ischemia On The Estimation Accuracy Of A Reduced Lead System ...
The  Effects Of Ischemia On The Estimation Accuracy Of A Reduced Lead System ...The  Effects Of Ischemia On The Estimation Accuracy Of A Reduced Lead System ...
The Effects Of Ischemia On The Estimation Accuracy Of A Reduced Lead System ...healthcareisi
 
Telehealth In Southampton - C Webb
Telehealth In Southampton - C WebbTelehealth In Southampton - C Webb
Telehealth In Southampton - C Webbhealthcareisi
 
Stroke Teleconsultation - Paul McCullagh
Stroke Teleconsultation - Paul McCullaghStroke Teleconsultation - Paul McCullagh
Stroke Teleconsultation - Paul McCullaghhealthcareisi
 
Software As Device - Frank Maxwell
Software As Device - Frank MaxwellSoftware As Device - Frank Maxwell
Software As Device - Frank Maxwellhealthcareisi
 
Real Life In Real Time - Shimmer Research
Real Life In Real Time - Shimmer ResearchReal Life In Real Time - Shimmer Research
Real Life In Real Time - Shimmer Researchhealthcareisi
 
Recommendations For Unique Health Identifiers - Tracy O'Carroll
Recommendations For Unique Health Identifiers - Tracy O'CarrollRecommendations For Unique Health Identifiers - Tracy O'Carroll
Recommendations For Unique Health Identifiers - Tracy O'Carrollhealthcareisi
 
Recognising Human Factors In Evaluating User Interfaces In Healthcare - Bridg...
Recognising Human Factors In Evaluating User Interfaces In Healthcare - Bridg...Recognising Human Factors In Evaluating User Interfaces In Healthcare - Bridg...
Recognising Human Factors In Evaluating User Interfaces In Healthcare - Bridg...healthcareisi
 
Raising The Level Of ICT Knowledge and Skills In The HSC - Paul Comac
Raising The Level Of ICT Knowledge and Skills In The HSC - Paul ComacRaising The Level Of ICT Knowledge and Skills In The HSC - Paul Comac
Raising The Level Of ICT Knowledge and Skills In The HSC - Paul Comachealthcareisi
 
Progress With Professionalism - Jean Roberts
Progress With Professionalism - Jean RobertsProgress With Professionalism - Jean Roberts
Progress With Professionalism - Jean Robertshealthcareisi
 
Professional Development Of Health Informatics In Northern Ireland - Paul Mc ...
Professional Development Of Health Informatics In Northern Ireland - Paul Mc ...Professional Development Of Health Informatics In Northern Ireland - Paul Mc ...
Professional Development Of Health Informatics In Northern Ireland - Paul Mc ...healthcareisi
 
Patient Journey Record(pajr) - Jing Su
Patient Journey Record(pajr) - Jing SuPatient Journey Record(pajr) - Jing Su
Patient Journey Record(pajr) - Jing Suhealthcareisi
 
Nursing Clinical Informatics - Suzanne Brown
Nursing Clinical Informatics - Suzanne BrownNursing Clinical Informatics - Suzanne Brown
Nursing Clinical Informatics - Suzanne Brownhealthcareisi
 
NI Electronic Care Record - Des O'Loan
NI Electronic Care Record - Des O'LoanNI Electronic Care Record - Des O'Loan
NI Electronic Care Record - Des O'Loanhealthcareisi
 
NHS Scotland Ehealth Strategy - Alan Hyslop
NHS Scotland Ehealth Strategy - Alan HyslopNHS Scotland Ehealth Strategy - Alan Hyslop
NHS Scotland Ehealth Strategy - Alan Hyslophealthcareisi
 
Multidisciplinary Team Experience In The Incorporation Of Pacs And Realtime E...
Multidisciplinary Team Experience In The Incorporation Of Pacs And Realtime E...Multidisciplinary Team Experience In The Incorporation Of Pacs And Realtime E...
Multidisciplinary Team Experience In The Incorporation Of Pacs And Realtime E...healthcareisi
 
Medical Clinic - Daragh O Brien
Medical Clinic - Daragh O BrienMedical Clinic - Daragh O Brien
Medical Clinic - Daragh O Brienhealthcareisi
 
Making Sense Of Ubiquitous Health Information A Cross Generational Study - Ka...
Making Sense Of Ubiquitous Health Information A Cross Generational Study - Ka...Making Sense Of Ubiquitous Health Information A Cross Generational Study - Ka...
Making Sense Of Ubiquitous Health Information A Cross Generational Study - Ka...healthcareisi
 

Más de healthcareisi (20)

Gerard Hurl - Industry Presentation 26-04-12
Gerard Hurl - Industry Presentation 26-04-12Gerard Hurl - Industry Presentation 26-04-12
Gerard Hurl - Industry Presentation 26-04-12
 
Using Technology To Help People - Ilana Rozannes
Using Technology To Help People - Ilana RozannesUsing Technology To Help People - Ilana Rozannes
Using Technology To Help People - Ilana Rozannes
 
The Electronic Medical Record - David Beausang
The Electronic Medical Record - David BeausangThe Electronic Medical Record - David Beausang
The Electronic Medical Record - David Beausang
 
The Effects Of Ischemia On The Estimation Accuracy Of A Reduced Lead System ...
The  Effects Of Ischemia On The Estimation Accuracy Of A Reduced Lead System ...The  Effects Of Ischemia On The Estimation Accuracy Of A Reduced Lead System ...
The Effects Of Ischemia On The Estimation Accuracy Of A Reduced Lead System ...
 
Telehealth In Southampton - C Webb
Telehealth In Southampton - C WebbTelehealth In Southampton - C Webb
Telehealth In Southampton - C Webb
 
Stroke Teleconsultation - Paul McCullagh
Stroke Teleconsultation - Paul McCullaghStroke Teleconsultation - Paul McCullagh
Stroke Teleconsultation - Paul McCullagh
 
Software As Device - Frank Maxwell
Software As Device - Frank MaxwellSoftware As Device - Frank Maxwell
Software As Device - Frank Maxwell
 
Real Life In Real Time - Shimmer Research
Real Life In Real Time - Shimmer ResearchReal Life In Real Time - Shimmer Research
Real Life In Real Time - Shimmer Research
 
Recommendations For Unique Health Identifiers - Tracy O'Carroll
Recommendations For Unique Health Identifiers - Tracy O'CarrollRecommendations For Unique Health Identifiers - Tracy O'Carroll
Recommendations For Unique Health Identifiers - Tracy O'Carroll
 
Recognising Human Factors In Evaluating User Interfaces In Healthcare - Bridg...
Recognising Human Factors In Evaluating User Interfaces In Healthcare - Bridg...Recognising Human Factors In Evaluating User Interfaces In Healthcare - Bridg...
Recognising Human Factors In Evaluating User Interfaces In Healthcare - Bridg...
 
Raising The Level Of ICT Knowledge and Skills In The HSC - Paul Comac
Raising The Level Of ICT Knowledge and Skills In The HSC - Paul ComacRaising The Level Of ICT Knowledge and Skills In The HSC - Paul Comac
Raising The Level Of ICT Knowledge and Skills In The HSC - Paul Comac
 
Progress With Professionalism - Jean Roberts
Progress With Professionalism - Jean RobertsProgress With Professionalism - Jean Roberts
Progress With Professionalism - Jean Roberts
 
Professional Development Of Health Informatics In Northern Ireland - Paul Mc ...
Professional Development Of Health Informatics In Northern Ireland - Paul Mc ...Professional Development Of Health Informatics In Northern Ireland - Paul Mc ...
Professional Development Of Health Informatics In Northern Ireland - Paul Mc ...
 
Patient Journey Record(pajr) - Jing Su
Patient Journey Record(pajr) - Jing SuPatient Journey Record(pajr) - Jing Su
Patient Journey Record(pajr) - Jing Su
 
Nursing Clinical Informatics - Suzanne Brown
Nursing Clinical Informatics - Suzanne BrownNursing Clinical Informatics - Suzanne Brown
Nursing Clinical Informatics - Suzanne Brown
 
NI Electronic Care Record - Des O'Loan
NI Electronic Care Record - Des O'LoanNI Electronic Care Record - Des O'Loan
NI Electronic Care Record - Des O'Loan
 
NHS Scotland Ehealth Strategy - Alan Hyslop
NHS Scotland Ehealth Strategy - Alan HyslopNHS Scotland Ehealth Strategy - Alan Hyslop
NHS Scotland Ehealth Strategy - Alan Hyslop
 
Multidisciplinary Team Experience In The Incorporation Of Pacs And Realtime E...
Multidisciplinary Team Experience In The Incorporation Of Pacs And Realtime E...Multidisciplinary Team Experience In The Incorporation Of Pacs And Realtime E...
Multidisciplinary Team Experience In The Incorporation Of Pacs And Realtime E...
 
Medical Clinic - Daragh O Brien
Medical Clinic - Daragh O BrienMedical Clinic - Daragh O Brien
Medical Clinic - Daragh O Brien
 
Making Sense Of Ubiquitous Health Information A Cross Generational Study - Ka...
Making Sense Of Ubiquitous Health Information A Cross Generational Study - Ka...Making Sense Of Ubiquitous Health Information A Cross Generational Study - Ka...
Making Sense Of Ubiquitous Health Information A Cross Generational Study - Ka...
 

Último

Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Neo4j
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024BookNet Canada
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 

Último (20)

Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 

Governance And Data Protection In The Health Sector - Billy Hawkes

  • 1. Governance and Data Protection in the Health Sector Billy Hawkes Data Protection Commissioner Health Informatics Workshop Dublin, 16 November 2011
  • 2. Presentation Outline • What Should Be • What Is • What Can Be?
  • 3. The Governance Challenge • What does an Organisation in the Health Sector need to do to be considered a good “corporate citizen” in its treatment of personal data? • How would it demonstrate this accountability in practice:  To its Customers/Clients?  To a Regulator?
  • 4. Accountability: Essential Elements 1. Organisation commitment to accountability and adoption of internal policies consistent with external criteria. 2. Mechanisms to put privacy policies into effect, including tools, training and education. 3. Systems for internal, ongoing oversight and assurance reviews and external verification. 4. Transparency and mechanisms for individual participation. 5. Means for remediation and external enforcement. http://www.huntonfiles.com/files/webupload/ CIPL_Galway_Accountability_Paper.pdf
  • 5. Demonstrating Accountability • Policies • Executive oversight • Staffing and delegation • Education and awareness • Ongoing risk assessment and mitigation • Program risk assessment oversight and validation • Event management and complaint handling • Internal enforcement • Redress
  • 6. Data Protection – a Fundamental Human Right • Implicit Right to Personal Privacy under Irish Constitution – Article 40.3.1 • Explicit Right to Personal Privacy under Article 8 of 1950 European Convention for the Protection of Human Rights & Fundamental Freedoms [ECHR]  ECHR now indirectly part of Irish law due to ECHR Act 2003 • Explicit Right to Data Protection under EU Treaties – Lisbon Treaty and EU Charter
  • 7. EU Charter of Fundamental Rights: Article 8 • Protection of personal data • 1. Everyone has the right to the protection of personal data concerning him or her. 2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified. 3. Compliance with these rules shall be subject to control by an independent authority.
  • 8. EU & Irish Legislation • Data Protection Directive • Data Protection Acts 95/46/EC  Being updated 1988 & 2003 • Electronic Privacy Directive 2002/58/EC • EC Electronic Privacy (as amended by Regulations 2011 (SI 2006/24/EC + 336/2011) 2009/136/EC)
  • 9. Data Protection & Health Data • Data on physical or mental health or condition or sexual life are ‘sensitive personal data’ with special protection • Complements ethical duty of medical confidentiality
  • 10. Eurobarometer Survey (2011): Privacy most important in relation to: 1. Medical Records 6. Social Welfare History 2. Financial History 7. Telephone / Internet 3. Credit Card Details Records 4. PPS Number 8. Personal Emails 9. CV Details 5. Garda Record 10. Personal Telephone Number
  • 11. Presentation Outline • What Should Be • What Is • What Can Be?
  • 12. Health Sector Audits: 2007-1010 • Large Public Hospital • Large Voluntary Hospital • 5 GP/General Clinics • Health Insurer • Nursing Home Repayment Scheme • Pharmacy • Out-of-hours Facility
  • 13. Large Voluntary Hospital Audit • “good organisational awareness of data protection principles” • “good technical security measures were in place” • Main concern: physical security  Access to Chart Room • Positive response to specific recommendations
  • 14. Large Public Hospital Audit (1) • “Data protection, from a governance perspective, is falling well short of what would be expected in an organisation collecting and processing vast amounts of sensitive personal data” • “Critically, it is unclear where responsibility lies for the practical application of data protection policies and procedures on a day to day basis …In order to correct the many data protection concerns which have been highlighted in the report, this issue of responsibility must first be addressed.” • “Having regard to the primary goal of the audit “to establish whether care was delivered in a manner that gave due respect to the legitimate privacy expectations of patients”, the issues raised in this audit are of such a scale that this Office is not in a position at present to indicate that this is the case.”
  • 15. Large Public Hospital Audit (2) • “In terms of security alone, the inspection Team encountered numerous breaches of the Data Protection Acts during the course of the audit, including:  Files left in public / unsecure areas  Inoperative security mechanisms on file storage areas  Patient data stored in corridors  Medical data sent by unsecure email  USB ports not locked down  Lack of system access controls  Lack of physical access controls to sensitive areas”
  • 16. GP Clinics • “good awareness of data protection principles generally”. • “one area requiring attention is the location and storage of the physical patient files” • IT Security • Extent of access to medical records by non- medical personnel • Data Retention
  • 17. Follow-up: GPs • “A Working Group was established in early 2010 following the discussions between the Office of the Data Protection Commissioner and the ICGP in response to the findings of the Office of the Data Protection Commissioner following audits it carried out on a number of GP practices”  Foreword to A Guide to Data Protection Legislation for Irish General Practice, April 2011 • Guide, Templates @: http://www.icgp.ie/go/in_the_practice/informat ion_technology/data_protection
  • 18. Follow-up: Hospitals/General • Input to HIQA work on Standards for Health Information Governance  http://www.hiqa.ie/standards/health-information- standards  What you should know about Information Governance & Self-Assessment Tool(October 11) • Input to Health Information Bill
  • 19. Presentation Outline • What Should Be • What Is • What Can Be?
  • 20. Good Practice: General • Transparent and Balanced approach to collecting and using patient data • Patients should know what you are doing with their personal data • Consult DPC and other guidance (www.dataprotection.ie; www.hiqa.ie)
  • 21. Good Practice: Audit • Do we know what types of personal data we hold?  Electronically (also CCTV images)  Paper • Can we justify:  Why we collect it?  What it is used for?  Length of time we hold it?  Who has access to it?  Who it is disclosed to? • Use HIQA Information Governance Self-Assessment Tool
  • 22. Good Practice: Access & Correction Requests • Can we :  Provide a description of the personal data we hold on an individual patient within a max. of 20 days?  Provide copy of this data within a max. of 40 Days?  Correct or erase data within 40 days?
  • 23. Good Practice: Security • Access Controls  Electronic patient systems secure  Paper Files  Audit Trails • Vulnerabilities  Portable Devices
  • 24. Good Practice - Need to Know Access • Must be able to stand over all access to personal data as justifiable within an organisation  Balance between needed access and data protection • ECHR Judgment of 17 July 2008 - CASE OF I v. FINLAND (Application no. 20511/03) – obligation to be able to stand over all access to health data on a need to know basis • Access to sensitive personal data must be even more restricted. Locked cabinets for manual data etc • Different medical teams/different users – different access
  • 25. Good Practice: Disposal • Do not retain patient records for any longer than can be objectively justified: clear policy • Comply with legal retention obligations • Orderly and secure disposal of old records
  • 26. Good Practice : People • Does everyone handling personal data know their responsibilities under Data Protection Law? Is this routinely included in training/induction? • Are procedures for handling personal data properly documented? • Are DP compliance responsibilities clearly allocated?
  • 27. Good Practice: If things go wrong … • Have a clear plan – what will you do if there is a security breach? • Notify DPC and patients  DPC Code of Practice and Guidance • Tell patients how you intend to remedy any damage done to their interests
  • 28. Good Practice - Research • Anticipate how you intend to use patient data, fully inform patient and get written consent or • Anonymise the data effectively (DP legislation only applies to data attributable to an identifiable person) before using for research – still best to tell the patient • Consult DPC Guidelines  Data Protection Guidelines on Research in the Health Sector • http://www.dataprotection.ie/documents/guidance/Health_ research.pdf
  • 29. Thank You Further Guidance • www.dataprotection.ie • Data Protection Commissioner, Canal House, Station Road, Portarlington, Co Laois Tel. 1890-252231 (Lo-call), 057-8684800