This story was first published in digitalhealth.net
In the depth of The Times dated 16 June 2008, a short item described that a package containing computer disks sent by post from a North London NHS Hospital was missing. The disks contained personal details of about 18,000 NHS staff. The hospital apologised and a member of staff was suspended.
Breaches of information security within the public sector have recently become a major problem. In the NHS, other examples include clinical information sent by internal mail not placed in sealed envelopes and not properly addressed, thereby leading to loss or damage. Extant Notes stored for years in boxes in basements and attics without being checked for loss or damage, at risk from fire, rodent and water damage and an electrical and spacial cost. Misdirected e-mails and overheard conversations. The extensive use of laptops and memory sticks and the spread of e-mail and texting leading to a massive explosion of uncontrolled information.
Most breaches can be laid at the lack of clearly understood security classifications, the reckless failure to apply protective measures and failures to clearly identify information that needs protecting. Breaches are also more easily achieved where protection of information procedures is weak and the counter-measures are complex.
What is information?
Information is the soul of the organisation. Without it, businesses cannot function, armies cannot fight, governments cannot govern and clinicians cannot diagnose. But what is information?
Information is defined in the Oxford English Dictionary as ‘what is told; knowledge; items of knowledge’. There are essentially two types. Implicit Information relies upon the direct communication between the minimum of two human beings and/or animals that both understand, to a greater or lesser degree, for instance the dog and his master. The development of the telephone and the electronic basic unit of information (the ‘bit’) have seen the spread of Explicit Information, which relies upon a third party to deliver information. Less secure, it can be damaging if the third party is either unpredictable or unreliable or a mistake is made in transmission. It can also be intercepted.
Irrespective of the systems used, the protection of information revolves around three basic principles:
Information can be further broken down into:
Most government departments have clearly defined classifications that grades information – Top Secret, Secret, Confidential and Restricted – into damage compromise could affect national security. They can be further broken down into levels of privacy, such as Top Secret – Intelligence and Restricted – Medical. Access is strictly authorised through levels of vetting matched to appointments.
On paper, classifications are marked top and bottom of documents and inserted into different coloured folders, thereby clearly defining the value of the information. Specific rules govern storage, transmission, auditing and disposal and where there are breaches, security investigations are generated, usually by security practitioners. A contemporary issue in this 21st Century is that since huge amounts of information is held electronically on memory sticks, laptops and disks on which it is very difficult to mark classifications. Encryption helps but even that can be breached.
Patient confidentiality
Information is also power. Frequent is the cry ‘patient confidentiality’. But what does this mean? In common with priests, doctors are ethically bound not to volunteer information on patients gained in a professional capacity without the consent of the patient, except in very exceptional circumstances, for instance a person posing a significant menace to society.
British legislation is reluctant to create a general right to privacy, even under Common Law or within the Human Rights Act 1998. The Data Protection Act 1998 is often quoted as a reason for not sharing information, even within organisations. Complex because it is rarely simple to interpret, organisations and individuals are now fearful of sharing information, which can impact on the manner in which business is conducted.
Although the Data Protection Act does not mention privacy, theoritically it gives individuals the ability to control information about themselves that could be imported into the public arena. The protection of domestic information, such as statements, old address books and personal letters is the responsibility of the individual and thus the drive to shred information against theft from dustbins, which is commonly known as garbology.
Health records
The Data Protection (Subject Access Modification) (Health) Order 2000 (SI 20000/413) exempts health records from general right of access where such access would be ‘likely to cause serious harm to the physical or mental health or condition of the data subject or any other person’. The principal reason for clinical confidentiality in Common Law is not to protect individual right to privacy but to ensure that individuals are not reluctant to share personal information about their physical and mental health.
Where a patient requests access to their notes and the person controlling the records is, for instance, an administrator there is an obligation to consult the person most recently responsible for the clinical care of a patient, usually a doctor, before releasing the records. This is particularly relevant in psychiatric settings where the honest sharing of information is critical in developing care plans. While clinicians have a general duty to act in the patient’s best interests, which could mean denying a patient access to information where, in the opinion of the clinician, it is in the patient’s best interests to deny, patients need to be confident that the disclosure of clinical information will not result in embarrassment or loss of reputation. This is a powerful concept and poorly managed information can affect individual and corporate reputations.
Under Section 4 of The Access to Medical Reports Act 1988, individuals have the right to see medical reports prepared for insurance and employment purposes before it is supplied to the insurer/employer. A doctor should not forward reports until individuals have had opportunity to see it and request any amendments. But under Section 7, access to reports can be refused where, in the doctors’ opinion, disclosures would cause serious harm to the subject or others.
The Access to Health Records Act 1990 giving patients a statutory right to see manual medical records not previously covered by the Data Protection Act has largely been repealed with the right to records now governed by the Data Protection Act 1998. Section 3(f) of the Act gives third parties rights of access to the medical records of a deceased patient.
In conclusion, information has immense value, is powerful and must be protected. As NHS Trusts move into the competitive world of self-financing Foundation businesses, it is inevitable that strategic planning, financial spreadsheets, business plans and funded research and development will be at risk. It is therefore time that the NHS develops clearly understood and easily applied information protection measures. Security investigators should challenge loopholes and breaches. Information is a powerful and critical resource that needs protecting.
This story was first published in digitalhealth.net
UK Building Regulations highlight toxic gas and smoke from layers of paint built up over multiple redecorations as a major cause of permanent ill health or death in a building fire.
Their concern rose with discovery the flame retardant paints most widely used paint along escape routes have been ones which to this day counter-productively use emission of heavy toxic gas to smother flames which rapidly spread along walls if layers of paint delaminate in a fire.
Northwich’s Victoria Infirmary (VIN) Community Diagnostic Centre (CDC) has enabled more patients
Adveco, the commercial hot water specialist, announces the launch of live metering of domestic ho
Sarah Greenslade, public affairs and communications officer at the British Parking Association looks at some of the problems and innovations in healthcare parking
It’s easy to assume that the comms team is there to handle press enquiries and the occasional social media storm – but the reality is that strategic communications can make a measurable impact across the entire organisation, from operational to financial, when done properly