Step 3 Information Governance
IG is an essential component of PHM because it requires the collation, linkage and analysis of data from a large variety of clinical and non-clinical sources, all of which needs to be protected through robust governance processes
Moreover, these data will be drawn from a range of local authorities, health and care organisations, which creates a further degree of complexity from an IG perspective. The key is to engage with IG professionals early enough in the process to ensure that privacy is designed into the whole process right from the start. By doing so, IG can become a facilitator of population health management rather than a blocker.
- Identify a data governance lead who will work closely with the BU and PHM lead
- Develop data sharing agreements with different provider units
- Create and manage a cluster level data repository with access rights
Key IG preparations for the Cluster are:
- Identify a data governance lead who will work closely with the BU and PHM lead
- Develop data sharing agreements with different provider units
- Create and manage a cluster level data repository with access rights
Due to the nature of PHM information collection from across the system it may be used for both primary and secondary uses. Person identifiable information for direct care activities can be shared between providers however this is not the case for information to inform commissioning where data must be de- personalised.
Throughout the PHM process the roles and responsibilities of the data controller and processors must continue to be clearly defined to ensure accountability of data. In addition to obtaining patient consent to use data organisations must allow patients the option of removing their permission if they no longer allow their data to be shared.
Key questions to answer
- 1. Who will be the data processor and who will be the data controller?
- 2. What will be the role of SeHE, NHIC, national data observatory etc?
- 3. How will you set up disease registries and how will you control access to it?
- 4. What are the identified priorities of the system?
- 5. What are the questions that we are seeking to answer?
- 6. Are there anonymous data-sets that could be used to answer those
- 7. Questions?
- 8. What data-sets need to be linked?
- 9. Could people be identified through linking those data-sets?
- 10. What is the legal purpose for linking those data-sets?
- 11. Who has the statutory authority?
- 12. Thinking about data protection 'by design' and 'by default’, i.e. need to
- 13. Integrate data protection into processing activities and business practices from design stage and through the lifecycle