Information – friend or foe?

In the depth of The Times dated 16 June 2008, a short item described that a package containing computer disks sent by post from a North London NHS Hospital was missing. The disks contained personal details of about 18,000 NHS staff. The hospital apologised and a member of staff was suspended.
    
Breaches of information security within the public sector have recently become a major problem. In the NHS, other examples include clinical information sent by internal mail not placed in sealed envelopes and not properly addressed, thereby leading to loss or damage. Extant Notes stored for years in boxes in basements and attics without being checked for loss or damage, at risk from fire, rodent and water damage and an electrical and spacial cost. Misdirected e-mails and overheard conversations. The extensive use of laptops and memory sticks and the spread of e-mail and texting leading to a massive explosion of uncontrolled information.
    
Most breaches can be laid at the lack of clearly understood security classifications, the reckless failure to apply protective measures and failures to clearly identify information that needs protecting. Breaches are also more easily achieved where protection of information procedures is weak and the counter-measures are complex.

What is information?
Information is the soul of the organisation. Without it, businesses cannot function, armies cannot fight, governments cannot govern and clinicians cannot diagnose. But what is information?
    
Information is defined in the Oxford English Dictionary as ‘what is told; knowledge; items of knowledge’. There are essentially two types. Implicit Information relies upon the direct communication between the minimum of two human beings and/or animals that both understand, to a greater or lesser degree, for instance the dog and his master. The development of the telephone and the electronic basic unit of information (the ‘bit’) have seen the spread of Explicit Information, which relies upon a third party to deliver information. Less secure, it can be damaging if the third party is either unpredictable or unreliable or a mistake is made in transmission. It can also be intercepted.
    
Irrespective of the systems used, the protection of information revolves around three basic principles:

  • Need to Know permits individuals and groups access to sufficient information to enable them to carry out their assignments effectively and efficiently. Not everyone needs to know everything. Position in the organisational pecking order does not give an automatic right need to know.
  • Need to Hold allows individuals and groups to retain sufficient information essential for their work but no more than is necessary. Information of no further value should be destroyed. 
  • Need to Take means that only those who need to remove information from an organisation should be permitted to do so. It implies that the receiver will safeguard the information under controlled conditions.

Information can be further broken down into:

  • Short term in which the information has a short value.
  • Long term in which it is difficult to quantify the duration of retention.

Most government departments have clearly defined classifications that grades information – Top Secret, Secret, Confidential and Restricted – into damage compromise could affect national security. They can be further broken down into levels of privacy, such as Top Secret – Intelligence and Restricted – Medical. Access is strictly authorised through levels of vetting matched to appointments.
    
On paper, classifications are marked top and bottom of documents and inserted into different coloured folders, thereby clearly defining the value of the information. Specific rules govern storage, transmission, auditing and disposal and where there are breaches, security investigations are generated, usually by security practitioners. A contemporary issue in this 21st Century is that since huge amounts of information is held electronically on memory sticks, laptops and disks on which it is very difficult to mark classifications. Encryption helps but even that can be breached.  

Patient confidentiality

Information is also power. Frequent is the cry ‘patient confidentiality’. But what does this mean? In common with priests, doctors are ethically bound not to volunteer information on patients gained in a professional capacity without the consent of the patient, except in very exceptional circumstances, for instance a person posing a significant menace to society.

British legislation is reluctant to create a general right to privacy, even under Common Law or within the Human Rights Act 1998. The Data Protection Act 1998 is often quoted as a reason for not sharing information, even within organisations. Complex because it is rarely simple to interpret, organisations and individuals are now fearful of sharing information, which can impact on the manner in which business is conducted.
    
Although the Data Protection Act does not mention privacy, theoritically it gives individuals the ability to control information about themselves that could be imported into the public arena. The protection of domestic information, such as statements, old address books and personal letters is the responsibility of the individual and thus the drive to shred information against theft from dustbins, which is commonly known as garbology.

Health records
The Data Protection (Subject Access Modification) (Health) Order 2000 (SI 20000/413) exempts health records from general right of access where such access would be ‘likely to cause serious harm to the physical or mental health or condition of the data subject or any other person’. The principal reason for clinical confidentiality in Common Law is not to protect individual right to privacy but to ensure that individuals are not reluctant to share personal information about their physical and mental health.
    
Where a patient requests access to their notes and the person controlling the records is, for instance, an administrator­­ there is an obligation to consult the person most recently responsible for the clinical care of a patient, usually a doctor, before releasing the records. This is particularly relevant in psychiatric settings where the honest sharing of information is critical in developing care plans. While clinicians have a general duty to act in the patient’s best interests, which could mean denying a patient access to information where, in the opinion of the clinician, it is in the patient’s best interests to deny, patients need to be confident that the disclosure of clinical information will not result in embarrassment or loss of reputation. This is a powerful concept and poorly managed information can affect individual and corporate reputations.
    
Under Section 4 of The Access to Medical Reports Act 1988, individuals have the right to see medical reports prepared for insurance and employment purposes before it is supplied to the insurer/employer. A doctor should not forward reports until individuals have had opportunity to see it and request any amendments. But under Section 7, access to reports can be refused where, in the doctors’ opinion, disclosures would cause serious harm to the subject or others.
    
The Access to Health Records Act 1990 giving patients a statutory right to see manual medical records not previously covered by the Data Protection Act has largely been repealed with the right to records now governed by the Data Protection Act 1998. Section 3(f) of the Act gives third parties rights of access to the medical records of a deceased patient.
    
In conclusion, information has immense value, is powerful and must be protected. As NHS Trusts move into the competitive world of self-financing Foundation businesses, it is inevitable that strategic planning, financial spreadsheets, business plans and funded research and development will be at risk. It is therefore time that the NHS develops clearly understood and easily applied information protection measures. Security investigators should challenge loopholes and breaches. Information is a powerful and critical resource that needs protecting.

Event Diary

This story was first published in digitalhealth.net

Supplier Profiles

CDC success at Victoria Infirmary, Northwich creates ideal model for future patient pathway reforms

Northwich’s Victoria Infirmary (VIN) Community Diagnostic Centre (CDC) has enabled more patients

Gain valuable insight with Adveco for gas to electric decarbonisation projects

Adveco, the commercial hot water specialist, announces the launch of live metering of domestic ho