|
FOI Request 974 - Patient Record Access |
|
Written by FOI Lead
|
| Case Number |
974 |
| Request Date |
22/01/2009 |
|
Details of the Request
- Date of the last audit or investigation undertaken by or for the trust on the appropriateness of patient record access and an indication of the frequency of such audits.
- Number of instances in last 2 years when patient's record inappropriately accessed by 5 separate staff members.
- A description of the circumstances surrounding and nature of each instance of inappropriate access.
- Details of any disciplinary (formal or otherwise) or remedial action relating to the inappropriate access.
|
|
| Completion Date |
08/07/2009 |
|
Details of the Response
Thank you for your recent request to Ashford and St. Peter’s Hospitals NHS Trust regarding access to patients’ records. Please accept our apologies for the delay in responding.
The most recent audit covering IT system user access was undertaken in January-February 2009 as part of the Trust’s internal audit programme. Access to information systems is restricted to authorised users who have a business need either to operate or manage the information system or to directly access the information being processed. Information security breaches are recorded in line with the Trust’s Reporting and Management of Incidents Policy. All incidents are thoroughly investigated and disciplinary action instigated in line with the Trust’s Disciplinary Policy where appropriate.
During the last 2 years, there has been one incident reported relating to inappropriate access to a patient’s results. This matter is currently under investigation.
We would like to assure you that information security is extremely important and viewed with the utmost seriousness by the Trust. A comprehensive Information Governance presentation is given as part of the Trust’s corporate induction covering the following areas:
- Confidentiality: NHS Code of Practice
- Information Security
- Caldicott Principles
- Data Protection Act
- Freedom of Information Act
Information security is also covered during all training sessions on patient information systems.
|
|
|
|
Last Updated ( Tuesday, 27 September 2011 09:54 )
|