Part of A guide to confidentiality in health and social care: Treating confidential information with respect
Rule 5: Organisations should put policies, procedures and systems in place to ensure the confidentiality rules are followed
Organisations should ensure that they have the appropriate organisational and technical systems security, policies, processes and staff training and education to ensure that
confidential information is held and shared securely39 and appropriately, as set out in this guide. Every organisation should:
A. Appoint a senior individual responsible for ensuring the confidentiality rules are followed
An identified senior individual within each health and social care organisation should be appointed as being responsible for ensuring the organisation continues to meet its requirements as set out in this guide. This individual will be responsible for ensuring the organisation complies with the law in relation to confidentiality. This should be the Caldicott Guardian40 or other senior member of staff responsible for information risk. The guide will be an evolving document and organisations should review their compliance and update their policies and procedures in line with any changes to the guide, at least annually.
B. Complete an Information Governance Toolkit Assessment (IGT)
The IGT defines and draws together many of the information governance requirements that apply in different circumstances. One way to demonstrate that appropriate policies, procedures and systems are in place is for organisations to comply with relevant IGT requirements41. Examples of key requirements include:
⦁ access should be limited to those authorised, with a need to know
⦁ confidential information should be held and distributed securely
⦁ some confidential information should not be retained indefinitely and should be securely disposed of at the appropriate time42
⦁ staff should be trained and educated appropriately to discharge relevant duties
D. Encourage people to report concerns that the confidentiality rules have not been followed
Organisations should have processes in place to encourage people to report concerns that the confidentiality rules are not being followed. If they feel their concerns about confidentiality and safe and effective sharing of information have not been appropriately dealt with by the organisation they should have easy access to the organisation’s whistle- blowing procedure.
Staff need to know that they can safely share information with a particular body. Therefore, they must be informed of serious concerns so they know when they should assess the risk and perhaps not share information with a particular organisation.
Last edited: 9 February 2022 9:26 am