North East Ambulance Service NHS Trust Information Governance Toolkit Assessment 2009/10
Ref: Version: 0001 Status: Final Issue date: Apr 2010
Information Governance Toolkit Assessment
2009/10
Document Profile Box
Document Reference:
Version: Final
Ratified by: Trust Board
Date ratified:
Name of originator/author: Rahima Hoque – Information Governance
Manager
Name of responsible committee/individual: Information Governance Working Group
Document owner: Colin Cessford – Director of Strategy and
TABLE OF CONTENTS
PAGE
1. EXECUTIVE SUMMARY 1
2. ACTIONS REQUESTED 1
3. INFORMATION GOVERNANCE ASSESSMENT SCORES 1
4. CURRENT POSITION 2
5. ACTION PLAN 3
6. INFORMATION GOVERNANCE TOOLKIT V8 4
North East Ambulance Service NHS Trust Information Governance Toolkit Assessment 2009/10
Ref: Version: 0001 Status: Final Issue date: Apr 2010 Page - 1 -
1. Executive Summary
1.1. The Information Governance Toolkit (IGT) report is based on the scores achieved in the fiscal year 2009/10 and the scores have been submitted to Connecting for Health for validation. The attainment levels are shown alongside the 2008/09 score for comparison.
1.2. In this fiscal year 2009/10 the IGT results scored an overall 68% whilst in 2008/09 the overall score was 65%. The Trust has an amber status of achievement.
1.3. The final assessment has been approved via the IGWG and each of the initiative leads with recommendation for sign-off by the Trust Board.
1.4. Sunderland Internal Audit Services have concluded that there is significant assurance that there is a generally sound system of internal control designed to meet the organisation’s objectives and that controls are generally being applied consistently. 5 IGT requirements were audited.
2. Actions Requested
2.1. The NEAS Board is asked to approve the IGT assessment scores and the action plan for 2010/11.
3. Information Governance Assessment Scores
3.1. The table below shows the comparative scores over the last 4 years. The IGT scores are based on RAG principles: RED – AMBER – GREEN.
Initiative 2006/07 Version 4 2007/08 Version 5 2008/09 Version 6 2009/10 Version 7
Clinical Information Assurance 33% 41% 50% 58%
Confidentiality and Data Protection Assurance 62% 79% 87% 75%
Corporate Information Assurance 41% 75% 50% 75%
Information Governance Management 74% 69% 71% 71%
Information Security Assurance 40% 50% 57% 62%
Overall Score 54% 62% 65% 68%
Red 0 – 39%
Amber 40 – 69%
3.2. The individual initiative in the area of Confidentiality and Data Protection has gone down from 87% to 75%. Clinical Information Assurance and Information Security Assurance have risen slightly 50% - 58% and 57% - 62% respectively. There has been a significant increase in Corporate Information Assurance from 50% to 75%. Information Governance Management has maintained the same scores as last year.
3.3. The IGT is also linked to the various assessments which are required to be submitted by the Trust including:
• Care Quality Commission – Core Standards • Auditor’s Local Evaluation
• NHSLA assessments
4. Current Position
4.1. The table below shows the number of requirements at each level against each of the 5 initiative areas.
Initiative / Level 0 1 2 3 Total
Information Governance Management - 3 7 5 15
Confidentiality and Data Protection
Assurance -
1 4 3 8
Information Security Assurance 2 1 9 3 15
Clinical Information Assurance - 2 1 1 4
Corporate Information Assurance - - 3 1 4
Total 2 7 24 13 46
The Informatics Planning Guidance 2010/11 states that level 2 performance must be achieved against all requirements by 31 March 2011.
North East Ambulance Service NHS Trust Information Governance Toolkit Assessment 2009/10
Ref: Version: 0001 Status: Final Issue date: Apr 2010 Page - 3 -
5. Action Plan
The key areas of work for the IGWG for the forthcoming year are:
5.1. Information Governance Management
5.1.1. Requirement 104 - How would you assess your AMT's ability to access expertise across the Information Quality and Records Management Agenda?
Information Quality and Records Management arrangements need to be coordinated by the lead manager/officers but incorporated within broader IG arrangements. The IGWG needs to receive routine reports from the Information Quality and Records Management Functions and sign off the appropriate components of the IG assessment before its submission to the Board. 5.1.2. Requirement 106 - Does the AMT have up to date and tested business continuity plans for all
critical infrastructure components and core information systems?
The SIRO (Senior Information Risk Owner) and IAOs (Information Asset Owners) should ensure ongoing review and testing of Trust business continuity plans for relevance and effectiveness. Training should be provided to all affected staff to ensure that awareness of these plans and competency in the event of their execution can be assured.
5.1.3. Requirement 108: Has the AMT implemented its Information Governance management arrangements to ensure the NHS CFH Statement of Compliance (SoC) is satisfied?
The Trust should implement an independent audit and assurance programme to ensure that it continues to be able to comply with the requirements of its current Statement of Compliance 5.2. Confidentiality and Data Protection Assurance
5.2.1. Requirement 210: Does the AMT ensure that all new processes, software and hardware, comply with confidentiality and data protection requirements?
The AMT should monitor compliance with the guidance by reviewing any new processes that have been introduced. The approval process must be regularly reviewed to ensure that it continues to be followed.
5.3. Information Security Assurance
5.3.1. Requirement 311: Does the AMT ensure that its information systems are capable of the rapid detection, isolation and removal of malicious code and unauthorised mobile code?
The AMT SIRO and IAOs should routinely review all existing Information Assets to ensure that appropriate controls are in place, are up to date and are operating according to the agreed specification. Alerts should be proactively monitored and investigated, and IAOs should continually review implemented controls and procedures in order to provide effective protection of their information assets. Any instances of implemented anti-virus software being tampered with, switched off or bypassed must be considered a serious security incident and be investigated accordingly with appropriate actions taken.
5.3.2. Requirement 312: Does the AMT have in place appropriate procedures for ensuring that the development and introduction of any new Information Systems, or other relevant Information Assets of the AMT are conducted in a secure and structured manner? This requirement includes the development and maintenance of appropriate IG accreditation documentation. The SIRO and IAOs should ensure that all Trust Information Assets implementations follow the agreed project management process. This should ensure that security requirements are well defined, selected, and that information security risks and issues are identified early and addressed routinely within the Trust’s Information Asset lifecycle process. Robust change control processes should be applied.
5.3.3. Requirement 314: Does the AMT have appropriate procedures for ensuring that mobile computing and teleworking are conducted in a secure manner?
The AMT should ensure all relevant staff are effectively informed of the procedures and guidelines and have received appropriate instruction in the use of remote access solutions. The AMT must also ensure that mobile devices and removable media contain adequate information security capability, including reliable data encryption where patient, personal or otherwise confidential information is to be processed.
5.4. Clinical Information Assurance
5.4.1. Requirement 401: Does the AMT have a strategy to ensure the correct NHS Number is recorded for each active patient and ensure that it is used routinely in clinical communications?
The AMT must be able to demonstrate commitment to improving NHS number retrieval to achieve the IQAP standard of 100% coverage for active patient records in the MPI. The AMT must ensure that the NHS number is routinely used in all clinical communications.
5.4.2. Requirement 408: Does the AMT have procedures in place to ensure that when new services are provided, or where changes within the system are made, that these do not adversely impact on information quality?
Compliance with the procedures should be monitored and enforced and any evidence that the procedures have not been followed should be followed up.
6. Information Governance Toolkit V8
6.1. The 2009/10 submission is based on V7 of the toolkit. Version 8 is due to be released in June 2010 which will now require evidence upload to the site as opposed to a tick box exercise. It is anticipated that there will be a reduction in the IGT scores for 2010/11 submission as much of the level 3 criteria has been mapped to level 2 which is the cause in the drop in scores.
North East Ambulance Service NHS Trust Information Governance Toolkit Assessment 2009/10
Ref: Version: 0001 Status: Final Issue date: Apr 2010
Page - 5 - Appendix A – Final submission for Information Governance Toolkit Version 7
No. Standard 08/09
Score
09/10 Score
101 Does the AMT have adequate governance in place to support the current and evolving Information Governance agenda? 3 3
102 How would you assess your AMT's ability to access expertise across the Confidentiality & Data Protection Assurance agenda? 3 3
103 How would you assess your AMT's ability to access expertise across the Information Security agenda? 2 2
104 How would you assess your AMT's ability to access expertise across the Information Quality and Records Management Agenda? 2 1
105 Does the AMT have in place comprehensive IG Policy and associated Strategy and Improvement Plans all signed off by the Board? 3 3 106 Does the AMT have up to date and tested business continuity plans for all critical infrastructure components and core information
systems? 1 1
107 Does the AMT have a comprehensive Board endorsed Information Lifecycle Management Policy and Strategy / implementation plan? 3 3 108 Has the AMT implemented its Information Governance management arrangements to ensure the NHS CFH Statement of Compliance
(SoC) is satisfied? 1 1
109 Does the AMT ensure that staff and those working on behalf of the AMT comply with the terms and conditions set out on the RA01
form? 1 3
110 Does the AMT ensure that it has formal contractual arrangements that include compliance with information governance requirements,
with all contractors and support organisations? 2 2
111 Does the AMT ensure that all individuals carrying out work on behalf of the AMT have employment contracts which require compliance
with information governance standards? 2 2
112 Does the AMT's staff induction procedures effectively raise the awareness of Information Governance? 3 2
North East Ambulance Service NHS Trust
No. Standard 08/09
Score
09/10 Score 120 Does the AMT ensure that its registration authority (RA) managers, agents and sponsors have sufficient knowledge and skills (including
latest software, operational process guidance and its integration into AMT policies and procedures) to discharge its RA responsibilities? 2 2 121
Does the AMT have a Board level Senior Information Risk Owner (SIRO) who takes ownership of the AMT’s information risk policy, acts as advocate for information risk on the board and provides written advice to the accounting officer on the content of their Statement of Internal Control in regard to information risk?
1 2
201 Does the AMT have a confidentiality code of conduct that provides staff with clear guidance on the disclosure of patient personal
information? 3 3
202
Does the AMT ensure that patients are generally asked before their personal information is used in ways that do not directly contribute to, or support the delivery of, their care and that patients' decisions to restrict the disclosure of their personal information are appropriately respected?
3 2
203 Does the AMT ensure that patients are informed about the proposed uses of their personal information and the importance of providing
accurate information to NHS staff? 3 2
204 Does the AMT have effective procedures for ensuring that detailed questions, raised by patients about how their information may be
used, can be answered? 2 2
205 Does the AMT have appropriate procedures for recognising and responding to patient requests for access to their health records? 3 3
206 Has the AMT established appropriate confidentiality audit procedures to monitor access to confidential patient information? 2 2
208 Has the AMT mapped all flows of person identifiable information, assessed risks in line with Department of Health guidelines and put in
place safe haven procedures for all routine flows of person identifiable information to the organisation? 3 3
210 Does the AMT ensure that all new processes, software and hardware, comply with confidentiality and data protection requirements? 2 1 301 Does the AMT have a formal information security risk assessment and management programme that is adequately documented,
implemented and regularly reviewed? 2 2
302 Does the AMT have documented and accessible information security event reporting and management procedures in place that are
explained to all staff? 3 3
303 Has the AMT established business processes that ensure all staff smartcards and access profiles issued are appropriate and satisfy
North East Ambulance Service NHS Trust Information Governance Toolkit Assessment 2009/10
Ref: Version: 0001 Status: Final Issue date: Apr 2010
Page - 7 -
No. Standard 08/09
Score
09/10 Score 305 Does the AMT ensure that operating and application information systems under its control support appropriate access control
functionality? 2 2
306 Are there defined, documented and agreed access rights for all users of AMT based information systems and services? 2 2
307 Has the AMT established a register of all its major information assets and assigned responsibility or ‘ownership’ for each? 2 2
308 Does the AMT ensure that digital information shared with other organisations is secured in transit? 3 2
309 Does the AMT have adequate procedures in place to ensure the availability of information assets, data processing facilities,
communications services and data? 2 2
310 Does the AMT have procedures in place to prevent information processing being interrupted or disrupted through equipment failure,
environmental hazard or human error? 2 2
311 Does the AMT ensure that its information systems are capable of the rapid detection, isolation and removal of malicious code and
unauthorised mobile code? 1 1
312
Does the AMT have in place appropriate procedures for ensuring that the development and introduction of any new Information Systems, or other relevant Information Assets of the AMT are conducted in a secure and structured manner? This requirement includes the development and maintenance of appropriate IG accreditation documentation.
0 0
313 Does the AMT have appropriate procedures in place to ensure that communication networks under the AMT's control operate in a
secure manner? 2 2
314 Does the AMT have appropriate procedures for ensuring that mobile computing and teleworking are conducted in a secure manner? 0 0
315 Does the AMT satisfy its security management requirements to protect the Airwave communications service? 3 3
322 Does the AMT ensure that Registration Authority equipment (hardware and software) and consumables meet current specifications, is
adequately maintained and securely stored? 1 2
401 Does the AMT have a strategy to ensure the correct NHS Number is recorded for each active patient and ensure that it is used routinely
in clinical communications? 1 1
403 Does the AMT have an organisation-wide, multi-professional audit of clinical record keeping standards, including accuracy, for all
North East Ambulance Service NHS Trust
No. Standard 08/09
Score
09/10 Score
405 Does the AMT have robust procedures and processes for monitoring all data collection activities across the AMT? 1 2
408 Does the AMT have procedures in place to ensure that when new services are provided, or where changes within the system are
made, that these do not adversely impact on information quality? 1 1
601 Does the AMT have documented and implemented procedures for the creation and filing of electronic corporate records to enable
efficient retrieval and effective records management? 1 2
602 Does the AMT have documented and implemented procedures for the creation, filing and tracking/tracing of paper corporate records to
enable efficient retrieval and effective records management? 1 2
603 Does the AMT have publicly available, documented and implemented procedures to ensure compliance with the Freedom of
Information Act 2000? 3 3