Research paper
The Impact of the new European General Data Protection Regulation (GDPR) on the Information Governance Toolkit in Health and Social care with special
reference to Primary care in England
Ignatius Ndumbe Shu Northumbria University, London Campus
London, UK [email protected]
Hamid Jahankhani Northumbria University, London Campus
London, UK [email protected]
Abstract - The desire for eHealth systems (technology) is ever growing as public institutions (governments), healthcare providers, and its users (patients) see the gains that could possibly arise from having systems like databases of patient health information in a single place which will facilitate the way healthcare can be access by patients and their caregivers. The aim of this paper is to provide a supportive environment for the health and social care workplace with special reference in the Primary Care sector in England on the impact and changes to the information governance toolkit (IGTK) as a result of the new European General Data Protection Regulation (GDPR) which will be implemented in full from May 2018 as agreed by the UK Government thereby replacing the UK Data Protection Act of 1998. These challenges will also include the implementation of the National Data Guardian (NDG) review of data security and opt-outs amongst others.
Keywords-Information Governance, National Health, GDPR
I. INTRODUCTION
The National Health Service UK (NHS England) and other Health care systems everywhere are struggling. In England, Ageing population, many with complicated health issues, high cost, effective, novel technology and relentless demand from internet savvy patients are creating a perfect storm. So the system has to strive to meet up with it demand by innovating new ways and techniques. Currently the support is by only three ways that is by cash, tax or insurance. In 1948 NHS England became the cornerstone of the health service in UK. However, now the system is struggling to keep to demand with one of the setback being the lack of modernisation through the use of more smart technologies in delivery of it services.
Historically, the health and social care system were not set up in a way that supports collaboration across services. Patients have to tell their story multiple times, with staff from various organisations delivering different elements of their care.
Individual organizations have had different priorities and separate ring-fenced budgets. This doesn’t lend itself to health and social care services working as a unit, giving a seamless care experience for patients. At its worst, it has led to unhelpful competition and fragmentation, as each organisation works towards different priorities. This can be seen in the government latest plan, “Sustainability and Transformation Plan (STP)” [1] which is aimed to bridge the fragmentation and create more collaboration.
The push for services to be situated in primary care is part of this, dissolving boundaries between general practice,
outpatient services, community services, mental health and social care.
Many general practices (GP) already operating at the limit of their resources and are facing increasing financial and human pressures, needing to provide more responsive, flexible and accessible services to patients. GPs have to respond to a growing population with more complex needs, increasing prevalence of long term conditions and an inequality in distribution of the workforce.
Whilst overall satisfaction with services remains generally high, a slower growth in general practice workforce, coupled with ever increasing demands on patient’s access, primary care services have a more critical role to play than ever before.
Patients see tremendous value in e-Health like patient online where patient will have access to their summary care record (SCR), e-referrals, and online consultation - video technology.
It has been more difficult for patient to attend an appointment due to the necessity to travel, work commitments or childcare, based on their conditions and health needs. Patients will now have the option to visit their GP virtually negating the need to travel and providing additional flexibility to do so. Though telephone consultation such as NHS England 111 and Out of Hours (OOHs) have been in existence for some time, both GPs and patient see benefit of being able to see one another in real time via online video consultations thanks to cloud computing in e-Health. However, this technology is not provided by the current primary care clinical systems in use in general practice.
There are many options for categorising e-Health technologies. This can be on the basis of the type of technology or can be based on who the targeted users are. There is no one categorisation that is perfect and always applicable mainly because of the continuously evolving possibilities of technology. However, e-Health can be identified in three major domains that is; Self-care & prevention, support care and societal health which falls under the primary care in general practice.
II. IMPACT OF CLOUD COMPUTING ON E-HEALTH
Cloud computing being the essential term used to describe computer power of the web for storing and processing information rather than local computer has been one of the most important changes over the past couple of years in the healthcare sector in general and particularly to the GP Practices. This has evolved from marketing hype to serious alternative to classical information computing, [2].
2017 Cybersecurity and Cyberforensics Conference
978-1-5386-2143-1/17 $31.00 © 2017 IEEE DOI 10.1109/CCC.2017.16
31
This is currently benefiting the health care sector in the following ways:
1. Electronic Records; e-records is one of the most instrumental gains of cloud computing in healthcare sector, because of this, it is much easier to store, share, use patient records and medical images. Due to this all general practice, healthcare providers now in England are running on one of the approved clinical systems supported by cloud computing (Emis, Tpp-SytmOne, Adastra and Orio) as SaaS – web-based. The new approach has greatly improved access, increase storage capabilities and boost security of patient confidential data.
2. Streamlined Collaboration: Over the last two years since the approval of cloud computing in general practice in UK many General Practitioners (GPs) and care givers from other sectors has found benefit of integration and collaboration in delivery care to collaborate as a team for example via mobile devices, video conferencing and application built specifically for healthcare organisations; with cloud system speeds up and allows better communication with other healthcare providers and at a distance.
3. Saving On Data Storage; In healthcare data is collected every time a patient visit their GP, this data is collected because it will help the GP to be able to make more intelligent and informed decisions about the patient health in the future. This process turns to create big data which become an overwhelming challenge for many healthcare providers, but with the cloud computing, it allows providers to save money by minimising in-house storage needs. More importantly the information needed or patient records also become accessible from various locations, and even if something happens on-site, the data is still preserved.
4. High-Powered Analytics: Analytics is crucial in decision making and tracking. With cloud computing, tracking and computing data in real-time provides providers a rich data for diagnosis, medical research, and referral generation, trend-spotting and for more personalised care.
5. Advanced Clinical Research; The cloud enables a lot of high-powered data solutions to superpower the research process. Big data used to be far too comprehensive for smaller computers to handle, but through the advanced computing power of the cloud, using these giant data sets for progress becomes a reality. It thus becomes easier and costlier to develop new drugs, and it especially presents interesting possibilities in DNA sequencing.
6. Telemedicine Capabilities: Due to cloud computing, both low and higher-tech devices, and mobile technology, providing health care from a distance has become a reality. Examples include consultations, tele-surgeries, and monitoring patients without having them come in.
Despite the benefits of cloud computing for the
developing of healthcare it is also considered as one of the most of information management systems of which the nature of processing information in health care need to assess and treat specific risks. Therefore, it is advisable to look at some of the risks of cloud computing in E-health through ISO2700 family. This will help e-Health implementation using cloud computing to focus on the most important Information Security Management Systems
(ISMS) process to establish and operate at an appropriate level of maturity considering limited resources.
III. SECURITY MANAGEMENT IN CLOUD COMPUTING
Security is one of the most argued-about issues in the cloud computing field and the cornerstone of cloud adoption; several enterprises and particularly health care look at cloud computing warily due to projected security risks and security issues have prevented businesses from fully accepting cloud platforms.
Managing security across health care and maintaining patient confidentiality and privacy is one of the many problems that health care organizations must solve in order to accomplish their missions.
An organization’s security strategy and goals must be framed in the context of risk. So the specific risks according to cloud computing need to be assessed and treated in the risk management process. Specific security and privacy risks regarding cloud computing in general practice healthcare, arise from the following:
� Availability: as most of the general practice would be and are currently using e-health cloud services, so to work continuously and effectively, services and data should be available all the time without performance degradation of which is not always the case.
� Reliability: using cloud computing for such a sensitive field requires reliability for the provided services.
� Data management: a good database management is required for handling such diversified data.
� Scalability: e-health cloud would be having hundreds of health care providers with millions of patients.
� Flexibility: different health care providers might be having different requirements.
� Interoperability: as there are multiple cloud service providers, services of e-health cloud for a client could be provided by different service providers; therefore, they all should work on same framework.
� Security: as many service providers could provide the e-health cloud services, and it would be used by many health care providers, therefore their security risk would be very high. When a single health care provider is using its own IT infrastructure then it will not be problem of security as it could monitor its network effectively but on a shared network various authentication methods and access controls would be required.
� Privacy: amongst all the issues of e-health cloud, the most important one is privacy.
� Organizational change: if e-health cloud is used in a health care organization, then many changes would be done like new policies, procedures, and workflows as well changes in the process of how documentation is done.
� Data ownership: in health care sector still there is no clear guideline for ownership of patient’s record.
32
� Privacy, trust, and liability issues: as cloud is on Internet, there is a risk of data leakage, private data exposure, and data loss which could result in loss of reputation of health care provider as well as patient’s trust.
� Usability and end user’s experiences: e-health cloud success lies in the fact that it is adopted by patients, health care professionals, management, and insurance companies. Those risks and their consequences need to be analysed in depth and considered while planning for the usage of cloud services for health care, defining necessary security measures, and using cloud services.
Those risks and their consequences need to be analysed
in depth and considered while planning for the usage of cloud services for health care, thereby defining necessary security measures, and using cloud services. For this a detailed individual risk assessment needs to be performed.
IV.THREAT TO DATA SECURITY
The General Practice needs to collect personal information about patients to provide its services. This information includes name, address, email address, date of birth, private and confidential information, sensitive information. In addition, they may occasionally be required to collect and use certain types of personal information to comply with the requirement of the law. No matter how it is collected, recorded and used for example on a computer, or other digital media, on hardcopy, paper or images, including CCTV, this personal information must be dealt with properly to ensure compliance with the Data Protection Act 1998 (DPA 1998).
The lawful and proper treatment of personal information by general practices is extremely important to the success of business and in order to maintain the confidence to service users or patients.
In UK, GPs fully supports and comply with the eight principles of the Act which are summarised as follows:
1. Personal data shall be processed fairly and lawfully. 2. Personal data shall be obtained or processed for
specific lawful purposes. 3. Personal data must be adequate, relevant and not
excessive. 4. Personal data must be accurate and kept up to date. 5. Personal data shall not be kept for longer than
necessary 6. Personal data shall be processed in accordance with
rights of the data subjects. 7. Personal data must be kept secure 8. Personal data shall not be transferred outside the
European Economic Area (EEA) unless there is adequate protection.
Rodrigues et al, (2013) identified three major threats to security, that is tampering with data (Integrity), loss of data(availability), and unauthorized access to data (confidentiality). With these three under consideration the risk of data security will be minimized, [3].
Furthermore, on threat to data security can be classified into two types, organisational threats and systemic threat as discussed by (Appari and Johnson 2010), [4].
Organisation threats, when users of a system abused their power by access records that they don’t have the legal
rights to do so, and Systemic threats are the misuse of information by people who legitimately have access to it, such as information being disclosed to an entity who does not have the right to receive it.
V.DEMOGRAPHIC THREAT
In a study by Wilkowska and Ziefle (2012), through a mixed focus group the main concern highlighted was confidentiality. This is important when doctors and patient’s confidential communications are concerned. Patients perceive the collecting and sharing of health information via eHealth systems as being connected to disease and therefore stigmatised, as opposed to other kinds of data which are more benign [5].
Also, as the general practice holds the responsibility to “The aging of the population” health care must make sure that security concerns are addressed and that patients feel comfortable with the E Health systems that their caretakers are using. Therefore, the findings of Wilkowska and Ziefle (2012) are highly significant for the development and functioning of an E Health system.
The worst possible scenario would be for patients to avoid doctors because they are afraid of their information not being secure. Therefore, addressing security issues and perceived security risks is important not only for peace of mind but also for actual public health.
VI. INFORMAION GOVERNANCE FRAMEWORK
It is a legal requirement for all health and social services to have in place an efficient and effective arrangement to govern information. These requirements are set out in the Information Governance Standards Framework.
Primary care providers are the data controllers for the personal and confidential data that they hold. They therefore have a legal responsibility to comply with the information governance requirements associated with this designation.
To ensure meeting their obligations in relation to information governance, NHS England considers that primary care providers must have access to the range of core support services. Therefore, it is important to make sure that these services comply with the new European GDPR legislation.
The following sets out the support that is required by primary care providers in relation to Information Governance.
� Core Element 1- Information Governance (IG) policy support - This should be in place for the production and maintenance of local IG policies and procedures. Provision of advice and support to GP practices on the approval, ratification and adoption of IG policies by their organisations. These policies need to include: confidentiality; consent procedures for the use of personal confidential information; data controllership responsibilities and data protection requirements; human rights requirements in relation to privacy; information security (physical security of paper records, smartcards and access controls for information systems,
33
managing mobile computing risks); incident management and reporting; staff training; and needs assessments. Example- Provision of template policies and procedures that can be tailored by the practice to meet local circumstances. Best practice advice and guidance incorporated into approved local policy. Proposed Providers- Policy templates may be provided nationally (e.g., by the Information Governance Alliance) but will need to be tailored locally by an IG support service.
� Core Element 2 - IG Consultancy and Support - There should be a provision of advice and support by telephone and/or email on IG issues, including existing operational processes and new business initiatives. Provision of advice and guidance around access and laws (including access to legal advice). Provision of guidance on implementing the recommendations of the Information Governance Review (“Caldicott2”). Example - Allocation of a set amount of time per practice per month for IG advice. Telephone and email support to IG Leads and Caldicott Lead or Caldicott Guardian in primary care providers. The services required to support the minimum compliance level. Proposed Providers - Local primary care IG support service with referral to the Information Governance Alliance where the enquiry relates to a general rather than a specific issue
� Core Element 3 – IG Training - Training in relation to IG, including the development and provision of training materials to support IG as required, and the delivery of ad hoc IG training that is not covered by the mandatory online IG training module. Examples - Online and face-to-face IG, updates/refresher courses, monitoring of the mandatory online IG training module, advice on the provision of staff and IG handbooks. Proposed Providers - Local primary care IG Support Service, Health and Social Care Information Centre, Information Governance Alliance (national template to be adapted for local requirements by the local GP IG support service).
� Core Element 4 - IG Toolkit (IGT) Compliance Support - Provide update reports on benchmarking against IGT requirements. Provide advice and guidance on how to complete the IGT. Examples - Provide advice on the collation and uploading of evidence required for the IGT. Proposed Providers - Local primary care IG support service, service IGT support team in the Health and Social Care Information Centre.
� Core Element 5 - Incident management and investigations - Provision of advice and/or support to practices on the investigation of possible information security
breaches and incidents. Advising on incident assessment and reporting via the SIRI reporting tool within the IG Toolkit to NHS England (dependent upon severity of incident). Advice on post-incident reviews and actions for customer implementation. Examples - Advice and guidance to practices on how to investigate, manage, report, and review incidents. Advice and support to providers to manage the reporting of the incident and advice on remedies. Proposed Providers - Local IG support service based on national guidance
In December 2015, a new set of legislations designed to
reform the legal framework for ensuring the rights of EU citizens to a private life was completed. This was ratified in the EU parliament on the 14th of April 2016 and is now Law. Member states will then have a 2-year implementation period. Enforcement will commence by May 2018. When the GDPR takes effect it will replace the Data Protection Directives of 1995. Perhaps confusingly, there is a new directive as well as a new regulation; it will apply to police procedures, which will continue to vary from Member state to member state.
The European Data Protection Directive of 1995 (Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data) set the fundamental rights of individuals, notably the right to privacy and accuracy of their personal data held and processed by others there by maintain information security. This was implemented in the UK via the DPA of 1998 and the IGT was one of the means to attain this objective. The IG toolkit is a tool issued by the Department of Health in the UK, whereby organisations assess themselves against IG legislation, guidance, policies and standards, to ensure that they are compliant with the law and can offer assurance as to the management, confidentiality and security of the information they are responsible for, 80% of which was centred on BS ISO/IEC 27001 and the DPA 1998. This assessment is meant to be completed every financially year by all health and social care organisation in England.
Due to the high increase in data driven decisions in Health and Social care, we must find a way in managing (usability) of this volume of data than ever before while maintaining the privacy and security of patients and the business. By processing and presenting data effectively, organisations will then be able to communicate better with stakeholders, increase transparency and ensure their data has maximum impact.
The way we create, use, share, store and discard information has greatly change over the years and this has been a problem in the health and social care sector and particularly to the Caldicott Guardian who is their responsibility to maintain patient/client confidentiality and decide on their information sharing.
It has never been more important to ensure that the ‘right information is in the right place at the right time’. This includes information sharing with a wide range of business partners; and third parties such as the police and solicitors. As the General Data Protection Regulation
34
(GDPR) guidance is being rolled out, there is much within it which is essential for organisations to consider with their Caldicott Guardians and a good place to start is by restructuring or redesigning of the IGT.
It has become increasingly important to be able to carry out audit of the Information Governance Toolkit (IGTK), preferably independently of those who are implementing it in organisations. The Information Commissioner Office and others have identified that self – assessment is inaccurate. This is because the process is considered as a tick box exercise by some organisation without fulfilling its objectives.
Apart of the Information governance framework, a Privacy Impact Assessment (PIA) is very important to be carried out in primary care and most importantly because patient personal and confidential record is involved. The PIA identifies and assesses privacy implications where information (data) about individuals is collected, stored, transferred, shared, and managed. It should be processed rather than output orientated. The purpose is to have the potential to detect and mitigate information risks, as well as to modify plans accordingly.
A PIA should be completed when the following activities occur:
Developing or procuring any new programme, policy, procedure, service, technology or system that handles or collects information relating to individuals.
Developing revisions to an existing programme, policy, procedure, service, technology or system which significantly change how information is managed.
The PIA should be created around the 8 principles of the data protection act (DPA 1998). Any privacy issues which have been identified during the PIA process (for example: no legal basis for collecting and using the information; lack of security of the information in transit, etc.) should be documented in the risk register. This risk register will enable the team to analyse the risks in terms of impact and likelihood and document required action(s) and outcomes.
Note that where it is proposed that a privacy risk is to be ‘accepted’, approval for such acceptance should be sought from the Caldicott Guardian where patient data is concerned and the SIRO for all information risks.
VII. THE GENERAL DATA PROTECTION REGULATION
(GDPR)
The General Data Protection Regulation (GDPR), [6], is designed to enable individuals to better control their personal data. It is hoped that these modernised and unified rules will allow businesses to make the most of the opportunities of the Digital Single Market by reducing regulation and benefiting from reinforced consumer trust.
Areas to look for the implementation of the GDPR should be as follows;
Incidents: The GDPR will now make it a legal duty to
report any incidents to the ICO within 72 hours. This legislates similarly to current working arrangements of contacting the ICO in a similar time period.
The potential financial penalties could be significantly higher for incidents where the regulations were not adhered to. Article 83 states the general conditions for imposing administrative fines. Paragraphs 4 and 5 state the limits of administrative fines that potentially can be issued (this is
dependent on member state approval of what the maximum fine will be). The maximum fines for failing to comply with the regulations could potentially be 20 million Euros or 4 % or of the total worldwide annual turnover of the preceding financial year.
Fair Processing and legal basis for processing data:
Data subjects must have fair processing information made available to them “at the time when personal data are obtained” (Article 13). Further to this, it must also include the following on top of what is currently provided by NHS England:
“the contact details of the data protection officer” “the right to lodge a complaint with a supervisory
authority” “the existence of automated decision-making, including
profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject”
Data subjects have the right to know what safeguards are in place for any personal data that is transferred to a “third country or an international organisation” (i.e. outside the UK). The applicable safeguards that can be used in international transfers are stated within Article 46.
Recital 47 states; in reference to the legitimate interests of a controller as legal basis for processing a data subjects personal data “Given that it is for the legislator to provide by law for the legal basis for public authorities to process personal data, that legal basis should not apply to the processing by public authorities in the performance of their tasks”. This in effect means that processing personal data using legitimate interests as a basis is no longer an option for NHS England and primary care in particular. This could have severe adverse consequences for functions undertaken by the primary care commissioners.
Data Protection Impact Assessments (Article 35):
Privacy Impact Assessments (PIAs) within the Act are named ‘data protection impact assessments’ (DPIAs).
There are limited differences to the two, except; that the appointed Data Protection Officer’s (DPO) advice must be sought (currently SIRO); and, ‘where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing’. Currently patient reps are required sit on Procurement Panels and provide input, but this is not replicated widely across all new processes that currently would require a PIA to be undertaken, or in future a DPIA.
Recital 84 states; “Where a data-protection impact assessment indicates that processing operations involve a high risk which the controller cannot mitigate by appropriate measures in terms of available technology and costs of implementation, a consultation of the supervisory authority should take place prior to the processing”. In essence this means that under New Processes Procedure, any PIA that is undertaken by health and social care organisations in general and primary care in particular, and the mitigations do not reduce the risk to a satisfactory level, BUT, the SIRO (or other senior level approval) accepts the risks involved, the ICO SHOULD be consulted before the project, procurement, change to service etc. that would
35
bring about the risk can bring about new or changed data flows.
Article 25 states that data protection must not only be by default but must be by design (Privacy by design). Essentially primary care organisations carries out similar activities through it’s PIA templates and New Process Procedure mainly under principles 3 and 5 of the Data Protection Act, however Article 25 and ‘Privacy by design’ will at some point need to be certified and whether their current PIA templates and New Processes Procedure will be sufficient to meet any proposed certification will need to be reviewed once this becomes clearer.
Data Protection Officer Role: According to Article 37
paragraph 1; the organisations must appoint a Data Protection Officer (DPO)
The details of the appointed DPO must be published and submitted to the ICO (similar to the register of Caldicott Guardians)
In some regards the DPO role has general similarities to the SIRO role. For example, all PIA’s will need to have consultation with the DPO (our current sign-off mechanism for PIA’s covers this).
However, article 38 states ‘Data subjects may contact the data protection officer with regard to all issues related to processing of their personal data’. It is unclear from this whether tasks such as subject access requests can be delegated, As the ICO would be the supervisory body in this respect, advice should be sought from them.
Similarly, guidance issued by the Working Party (EU joint committee of Member States’ Supervisory Authorities [ICOs]) about the role of DPO are not clear. Guidance states that the “The personal availability of a DPO is essential to ensure that data subjects will be able to contact the DPO” in relation to Article 38 paragraph 4, in regards to “to all issues related to processing of their personal data and to the exercise of their rights under this Regulation”. The level of expertise, skill, knowledge etc. stated in Articles 37-39 and Recital 97 that are relevant to the role, and given that the DPO must be available to communicate directly with data subjects and the Supervisory Board.
Subject Access: Article 12 paragraph 3; states that
SAR’s (as stated under article 13) need to be complied with ‘without undue delay’ and within a month of receipt of the request (does not state whether this is 31 days, or from the date of one month to the other, e.g. the 15th of Jan to the 15th of Feb)
Article 12 paragraph 5; states that there shall be no charge issued to the requestor in complying with their SAR, unless requests from a data subject are ‘manifestly unfounded or excessive, in particular because of their repetitive character’. If a request is denied on these grounds an unspecified fee may be charged (in relation to the administrative cost of dealing with the request) or the request may be denied but the controller (Primary care organisation) must demonstrate that the request was excessive or manifestly unfounded.
The processes for providing the information to the applicant remains the same
The controller maintains the ability where they process a large quantity of information on a data subject to ask the
data subject to specify the information or processing activities to which the request relates.
The fact that there can now be no charge for the first Subject Access Request made by a data subject has potential large financial implications for primary care organisations already struggling financially.
Processing Activities: Article 30 states that Data
Controllers ‘shall maintain a record of processing activities under its responsibility’. The organisations currently undertakes similar programmes of activity through Toolkit requirements where all data sharing agreements and contracts in theory are recorded and logged, however, in reality this is not done comprehensively and in a consolidated repository or format.
Strategic work to undertake in partner with other
organisations and potential future work: Article 40 paragraph 1; states that the drawing up of codes of conduct in keeping with the regulation should be encouraged. Paragraph 2 states that ‘bodies representing categories of controllers or processors’ (NHS England for the wider health system) should help prepare the codes of conduct. The DSPU team are in discussions with the IGA to have relevant work on this undertaken.
In relation to the above, Article 41 states that compliance with the code of conduct must be undertaken by an appropriate body which has an appropriate level of expertise (expertise in this case is decided by the regulatory body – the ICO). Assuming that changes made to the IG Toolkit will encompass changes needed to comply with GDPR then this should act as a good mechanism with which to monitor compliance with any code of conduct.
Article 42 states that it shall be encouraged that data protection certification mechanisms for the purpose of demonstrating compliance with the GDPR are created and complied with. It is unknown currently what form any certification will take, however, the task of deciding competency for a certification body shall lie with the supervisory authority (The ICO). As Primary care organisations represents categories of controllers, if a system of certification is brought in, it is likely that we would need to demonstrate good example by meeting any such certification and so a necessary programme of work may be needed to do so. Current resources or costs associated with this are currently unknown.
Other Considerations: Current legislation maintains
that only the Data Controller for information may be liable for non-compliance with the Data Protection Act. Article 82 paragraph 2 states; “A processor shall be liable for the damage caused by processing only where it has not complied with obligations of this Regulation specifically directed to processors or
where it has acted outside or contrary to lawful
instructions of the controller” – in effect stating that a processor is now equally liable, or entirely liable if, as stated in paragraph 3 the controller “proves that it is not in any way responsible for the event giving rise to the damage”.
In these such circumstances, paragraph 4 states that either the controller or the processor will be held
36
responsible for paying the entire fine, but paragraph 5 gives recourse whereby “controller or processor shall be entitled to claim back from the other controllers or processors involved in the same processing that part of the compensation corresponding to their part of responsibility for the damage”
Given some NHS England commissions other organisations to process large volumes of confidential data on it’s behalf, this may be an opportunity to share potential risks around this processing, and also give reason to seek appropriate assurances from processors that they are working towards compliance with the new GDPR regulations in relation to the contracts held for services with them.
Recital 27 states; “This Regulation does not apply to the personal data of deceased persons” and that “Member States may provide for rules regarding the processing of personal data of deceased persons”, thus meaning that current NHS ENGLANDE AHRA processes/business arrangements still apply.
As part of the IG operating Model and NHS England’s wider assurance role within the healthcare sector, work will need to be undertaken to review how the operating model will fit into GDPR assurance of both directly commissioned healthcare services and non-directly commissioned healthcare services. It seems unrealistic given the nature of some of the new requirements that the GDPR will bring about, that many smaller scale healthcare providing organisations will be able to meet these requirements acting alone, or without significant advice, support and guidance. There are currently mechanisms and provisions in place that can be used to ensure appropriate guidance and assurance of the wider healthcare system in compliance with the GDPR is relatively simply managed (e.g. the IG Toolkit, GPIG contracts, potential future certification models, the potential sharing of DPO’s across organisations), however it is currently unknown as to how much responsibility NHS England should be taking on for the provision of external organisations and for the wider healthcare sectors compliance with what will be state law, and therefore a duty for organisations to comply with in any case.
VIII. CONCLUSIONS
This paper has provided some information for areas in which the General Data Protection Regulations will and have the most effect on current Primary care sector in the NHS England operations and activities. This is not an exhaustive list, there are several other areas in which NHS England Primary care sector will need to be aware and work towards. Considering that the primary care sector in England is commissioned by NHS England there are some areas that cross over between strategic information governance work (undertaken by the Data Sharing and Privacy Team) and operational information governance work (undertaken by the Operational Information Governance team). Diligence and care must be taken to ensure that within these ‘overlapping’ areas and issues are not missed as it may be assumed that one or other of the IG teams will be responsible for, or have picked up on this work which will affect primary care.
REFRENCES [1] Sustainability and transformation plans (2015), https://www.kingsfund.org.uk/topics/integrated-care/sustainability- transformation-plans-explained#what-are-stps, cited on 18-Nov-2017.
[2] Griebel, L., Hans-Ulrich Prokosch, H. U., Köpcke, F., Toddenroth, D., Christoph, J., Leb, I., Engel, I. and Sedlmayr, M., (2015) A scoping review of cloud computing in healthcare, https://www.ncbi.nlm.nih.gov/pmc/articles/PMC4372226/, Cited on 10- Dec.-2017
[3] Rodrigues, J. J., De la Torre, I., Fernández, G., and López- Coronado M., (2013), “Analysis of the security and privacy requirements of cloud-based Electronic Health Records Systems,” Journal of Medical Internet Research, vol. 15, no. 8, 2013.
[4] Ajit, A., and Johnson, M. E., (2010), "Information security and privacy in healthcare: Current state of research." International Journal of Internet and Enterprise Management 6, no. 4, PP 279-314.
[5] Wilkowska, W., Ziefle, M., (2012), “Privacy and data security in E-health: Requirements from the user’s perspective”, Health Informatics Journal, 18(3) 191-201
[6] EU General Data Protection Regulation, (2017), https://www.eugdpr.org/, cited on 12- Dec.- 2017
37
<< /ASCII85EncodePages false /AllowTransparency false /AutoPositionEPSFiles false /AutoRotatePages /None /Binding /Left /CalGrayProfile (None) /CalRGBProfile (None) /CalCMYKProfile (None) /sRGBProfile (sRGB IEC61966-2.1) /CannotEmbedFontPolicy /Error /CompatibilityLevel 1.6 /CompressObjects /Off /CompressPages true /ConvertImagesToIndexed true /PassThroughJPEGImages true /CreateJobTicket false /DefaultRenderingIntent /Default /DetectBlends true /DetectCurves 0.1000 /ColorConversionStrategy /LeaveColorUnchanged /DoThumbnails true /EmbedAllFonts true /EmbedOpenType false /ParseICCProfilesInComments true /EmbedJobOptions true /DSCReportingLevel 0 /EmitDSCWarnings false /EndPage -1 /ImageMemory 1048576 /LockDistillerParams true /MaxSubsetPct 100 /Optimize true /OPM 0 /ParseDSCComments false /ParseDSCCommentsForDocInfo false /PreserveCopyPage true /PreserveDICMYKValues true /PreserveEPSInfo false /PreserveFlatness true /PreserveHalftoneInfo true /PreserveOPIComments false /PreserveOverprintSettings true /StartPage 1 /SubsetFonts true /TransferFunctionInfo /Remove /UCRandBGInfo /Preserve /UsePrologue false /ColorSettingsFile () /AlwaysEmbed [ true ] /NeverEmbed [ true ] /AntiAliasColorImages false /CropColorImages true /ColorImageMinResolution 36 /ColorImageMinResolutionPolicy /Warning /DownsampleColorImages true /ColorImageDownsampleType /Bicubic /ColorImageResolution 300 /ColorImageDepth -1 /ColorImageMinDownsampleDepth 1 /ColorImageDownsampleThreshold 2.00333 /EncodeColorImages true /ColorImageFilter /DCTEncode /AutoFilterColorImages false /ColorImageAutoFilterStrategy /JPEG /ColorACSImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /ColorImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /JPEG2000ColorACSImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /JPEG2000ColorImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /AntiAliasGrayImages false /CropGrayImages true /GrayImageMinResolution 36 /GrayImageMinResolutionPolicy /Warning /DownsampleGrayImages true /GrayImageDownsampleType /Bicubic /GrayImageResolution 300 /GrayImageDepth -1 /GrayImageMinDownsampleDepth 2 /GrayImageDownsampleThreshold 2.00333 /EncodeGrayImages true /GrayImageFilter /DCTEncode /AutoFilterGrayImages false /GrayImageAutoFilterStrategy /JPEG /GrayACSImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /GrayImageDict << /QFactor 0.76 /HSamples [2 1 1 2] /VSamples [2 1 1 2] >> /JPEG2000GrayACSImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /JPEG2000GrayImageDict << /TileWidth 256 /TileHeight 256 /Quality 15 >> /AntiAliasMonoImages false /CropMonoImages true /MonoImageMinResolution 36 /MonoImageMinResolutionPolicy /Warning /DownsampleMonoImages true /MonoImageDownsampleType /Bicubic /MonoImageResolution 600 /MonoImageDepth -1 /MonoImageDownsampleThreshold 1.00167 /EncodeMonoImages true /MonoImageFilter /CCITTFaxEncode /MonoImageDict << /K -1 >> /AllowPSXObjects false /CheckCompliance [ /None ] /PDFX1aCheck false /PDFX3Check false /PDFXCompliantPDFOnly false /PDFXNoTrimBoxError true /PDFXTrimBoxToMediaBoxOffset [ 0.00000 0.00000 0.00000 0.00000 ] /PDFXSetBleedBoxToMediaBox true /PDFXBleedBoxToTrimBoxOffset [ 0.00000 0.00000 0.00000 0.00000 ] /PDFXOutputIntentProfile (None) /PDFXOutputConditionIdentifier () /PDFXOutputCondition () /PDFXRegistryName (http://www.color.org) /PDFXTrapped /False /CreateJDFFile false /Description << /JPN <FEFF3053306e8a2d5b9a306f300130d330b830cd30b9658766f8306e8868793a304a3088307353705237306b90693057305f00200050004400460020658766f830924f5c62103059308b3068304d306b4f7f75283057307e305930023053306e8a2d5b9a30674f5c62103057305f00200050004400460020658766f8306f0020004100630072006f0062006100740020304a30883073002000520065006100640065007200200035002e003000204ee5964d30678868793a3067304d307e30593002> /DEU <FEFF00560065007200770065006e00640065006e0020005300690065002000640069006500730065002000450069006e007300740065006c006c0075006e00670065006e0020007a0075006d002000450072007300740065006c006c0065006e00200076006f006e0020005000440046002d0044006f006b0075006d0065006e00740065006e002c00200075006d002000650069006e00650020007a0075007600650072006c00e40073007300690067006500200041006e007a006500690067006500200075006e00640020004100750073006700610062006500200076006f006e00200047006500730063006800e40066007400730064006f006b0075006d0065006e00740065006e0020007a0075002000650072007a00690065006c0065006e002e00200044006900650020005000440046002d0044006f006b0075006d0065006e007400650020006b00f6006e006e0065006e0020006d006900740020004100630072006f0062006100740020006f0064006500720020006d00690074002000640065006d002000520065006100640065007200200035002e003000200075006e00640020006800f600680065007200200067006500f600660066006e00650074002000770065007200640065006e002e> /FRA <FEFF004f007000740069006f006e00730020007000650072006d0065007400740061006e007400200064006500200063007200e900650072002000640065007300200064006f00630075006d0065006e007400730020005000440046002000700072006f00660065007300730069006f006e006e0065006c007300200066006900610062006c0065007300200070006f007500720020006c0061002000760069007300750061006c00690073006100740069006f006e0020006500740020006c00270069006d007000720065007300730069006f006e002e00200049006c002000650073007400200070006f0073007300690062006c0065002000640027006f00750076007200690072002000630065007300200064006f00630075006d0065006e007400730020005000440046002000640061006e00730020004100630072006f0062006100740020006500740020005200650061006400650072002c002000760065007200730069006f006e002000200035002e00300020006f007500200075006c007400e9007200690065007500720065002e> /PTB <FEFF005500740069006c0069007a006500200065007300740061007300200063006f006e00660069006700750072006100e700f5006500730020007000610072006100200063007200690061007200200064006f00630075006d0065006e0074006f0073002000500044004600200063006f006d00200075006d0061002000760069007300750061006c0069007a006100e700e3006f0020006500200069006d0070007200650073007300e3006f00200061006400650071007500610064006100730020007000610072006100200064006f00630075006d0065006e0074006f007300200063006f006d0065007200630069006100690073002e0020004f007300200064006f00630075006d0065006e0074006f0073002000500044004600200070006f00640065006d0020007300650072002000610062006500720074006f007300200063006f006d0020006f0020004100630072006f006200610074002c002000520065006100640065007200200035002e00300020006500200070006f00730074006500720069006f0072002e> /DAN <FEFF004200720075006700200064006900730073006500200069006e0064007300740069006c006c0069006e006700650072002000740069006c0020006100740020006f0070007200650074007400650020005000440046002d0064006f006b0075006d0065006e007400650072002c0020006400650072002000650072002000650067006e006500640065002000740069006c0020007000e5006c006900640065006c006900670020007600690073006e0069006e00670020006f00670020007500640073006b007200690076006e0069006e006700200061006600200066006f0072007200650074006e0069006e006700730064006f006b0075006d0065006e007400650072002e0020005000440046002d0064006f006b0075006d0065006e007400650072006e00650020006b0061006e002000e50062006e006500730020006d006500640020004100630072006f0062006100740020006f0067002000520065006100640065007200200035002e00300020006f00670020006e0079006500720065002e> /NLD <FEFF004700650062007200750069006b002000640065007a006500200069006e007300740065006c006c0069006e00670065006e0020006f006d0020005000440046002d0064006f00630075006d0065006e00740065006e0020007400650020006d0061006b0065006e00200064006900650020006700650073006300680069006b00740020007a0069006a006e0020006f006d0020007a0061006b0065006c0069006a006b006500200064006f00630075006d0065006e00740065006e00200062006500740072006f0075007700620061006100720020007700650065007200200074006500200067006500760065006e00200065006e0020006100660020007400650020006400720075006b006b0065006e002e0020004400650020005000440046002d0064006f00630075006d0065006e00740065006e0020006b0075006e006e0065006e00200077006f007200640065006e002000670065006f00700065006e00640020006d006500740020004100630072006f00620061007400200065006e002000520065006100640065007200200035002e003000200065006e00200068006f006700650072002e> /ESP <FEFF0055007300650020006500730074006100730020006f007000630069006f006e006500730020007000610072006100200063007200650061007200200064006f00630075006d0065006e0074006f0073002000500044004600200071007500650020007000650072006d006900740061006e002000760069007300750061006c0069007a006100720020006500200069006d007000720069006d0069007200200063006f007200720065006300740061006d0065006e0074006500200064006f00630075006d0065006e0074006f007300200065006d00700072006500730061007200690061006c00650073002e0020004c006f007300200064006f00630075006d0065006e0074006f00730020005000440046002000730065002000700075006500640065006e00200061006200720069007200200063006f006e0020004100630072006f00620061007400200079002000520065006100640065007200200035002e003000200079002000760065007200730069006f006e0065007300200070006f00730074006500720069006f007200650073002e> /SUO <FEFF004e00e4006900640065006e002000610073006500740075007300740065006e0020006100760075006c006c006100200076006f006900740020006c0075006f006400610020006a0061002000740075006c006f00730074006100610020005000440046002d0061007300690061006b00690072006a006f006a0061002c0020006a006f006900640065006e0020006500730069006b0061007400730065006c00750020006e00e400790074007400e400e40020006c0075006f00740065007400740061007600610073007400690020006c006f00700070007500740075006c006f006b00730065006e002e0020005000440046002d0061007300690061006b00690072006a0061007400200076006f0069006400610061006e0020006100760061007400610020004100630072006f006200610074002d0020006a0061002000520065006100640065007200200035002e00300020002d006f0068006a0065006c006d0061006c006c0061002000740061006900200075007500640065006d006d0061006c006c0061002000760065007200730069006f006c006c0061002e> /ITA <FEFF00550073006100720065002000710075006500730074006500200069006d0070006f007300740061007a0069006f006e00690020007000650072002000630072006500610072006500200064006f00630075006d0065006e007400690020005000440046002000610064006100740074006900200070006500720020006c00610020007300740061006d00700061002000650020006c0061002000760069007300750061006c0069007a007a0061007a0069006f006e006500200064006900200064006f00630075006d0065006e0074006900200061007a00690065006e00640061006c0069002e0020004900200064006f00630075006d0065006e00740069002000500044004600200070006f00730073006f006e006f0020006500730073006500720065002000610070006500720074006900200063006f006e0020004100630072006f00620061007400200065002000520065006100640065007200200035002e003000200065002000760065007200730069006f006e006900200073007500630063006500730073006900760065002e> /NOR <FEFF004200720075006b00200064006900730073006500200069006e006e007300740069006c006c0069006e00670065006e0065002000740069006c002000e50020006f00700070007200650074007400650020005000440046002d0064006f006b0075006d0065006e00740065007200200073006f006d002000700061007300730065007200200066006f00720020007000e5006c006900740065006c006900670020007600690073006e0069006e00670020006f00670020007500740073006b007200690066007400200061007600200066006f0072007200650074006e0069006e006700730064006f006b0075006d0065006e007400650072002e0020005000440046002d0064006f006b0075006d0065006e00740065006e00650020006b0061006e002000e50070006e006500730020006d006500640020004100630072006f0062006100740020006f0067002000520065006100640065007200200035002e00300020006f0067002000730065006e006500720065002e> /SVE <FEFF0041006e007600e4006e00640020006400650020006800e4007200200069006e0073007400e4006c006c006e0069006e006700610072006e00610020006e00e40072002000640075002000760069006c006c00200073006b0061007000610020005000440046002d0064006f006b0075006d0065006e007400200073006f006d00200070006100730073006100720020006600f600720020007000e5006c00690074006c006900670020007600690073006e0069006e00670020006f006300680020007500740073006b0072006900660074002000610076002000610066006600e4007200730064006f006b0075006d0065006e0074002e0020005000440046002d0064006f006b0075006d0065006e00740065006e0020006b0061006e002000f600700070006e006100730020006d006500640020004100630072006f0062006100740020006f00630068002000520065006100640065007200200035002e003000200065006c006c00650072002000730065006e006100720065002e> /ENU (Use these settings with Distiller 7.0 or equivalent to create PDF documents suitable for IEEE Xplore. Created 29 November 2005. ****Preliminary version. NOT FOR GENERAL RELEASE***) >> >> setdistillerparams << /HWResolution [600 600] /PageSize [612.000 792.000] >> setpagedevice