- Purposes and Aims
- Information Sharing
- Data Items
- Legal Basis for Sharing
- Access and Individual’s Rights
- Security of Information
- Information Governance
- Health and Care Professions Council
Park House, 184-186 Kennington Park Road, London, SE11 4BU; and
- NHS Counter Fraud Authority
Fourth Floor, Skipton House, 80 London Road, London, SE1 6LH; and
- NHS Counter Fraud Services (NHS Wales)
First Floor Block B, Mamhilad House, Mamhilad Park Estate, Pontypool, NP4 0YP
- Department of Health & Social Care Anti-Fraud Unit
Skipton House, 80 London Road, London, SE1 6LH
being collectively “the Parties”.
Purpose and Aims
This agreement describes the roles of the Health and Care Professions Council (HCPC) and NHS Counter Fraud Authority (NHSCFA) and the Department of Health and Social Care Anti-Fraud Unit (DHSC AFU) and outlines the basis of cooperation and collaboration between the Parties. It sets down the principles underpinning the interaction between the Parties and provides guidance on the exchange of information between them.
This agreement applies to England and Wales and is intended to provide a framework to assist the joint working of the Parties to ensure maximum effectiveness and efficiency when carrying out investigations. The agreement includes practical arrangements designed to ensure the relationship is effective and that together the Parties meet their aims and objectives, particularly when there are overlapping interests and responsibilities.
Although the Parties agree to adhere to the contents of this agreement, it is not intended to be a legally binding document. The agreement does not override the Parties’ statutory responsibilities or functions, nor does it infringe the autonomy and accountability of the Parties or their governing bodies.
The Parties agree to abide by the Data Sharing Code of Practice produced by the Information Commissioners Office, and recognise their respective responsibilities as public bodies under the General Data Protection Regulation 2016, Data Protection Act 2018 and the Freedom of Information Act 2000.
The aims of this agreement are to:
- reduce fraud and corruption within the health and care professions to a minimum;
- maintain service user safety and confidence in the health and care professions;
- support the sharing of information, intelligence, expertise and experience;
- contribute to improving the regulatory oversight of the health and care professions; and
- define the circumstances in which the organisations will act independently.
The term “information” is used in this agreement by NHSCFA to refer to any and all information or data used for healthcare business purposes, including commercial, business, personal and sensitive information or data. The medium in which information or data may be displayed, presented, shared, disclosed or processed, may be in the form of hard-copy or electronic data, records or documents.
To facilitate the sharing of information, the Parties will follow due processes as they are defined in the agreement.
Remit of the Health and Care Professions Council
The HCPC is the independent statutory regulator of the 15 professions set out below. The HCPC’s main objective in exercising its functions is to safeguard the health and well-being of persons using or needing the services of its registrants.
The responsibilities and functions of the HCPC are set out in the Health Professions Order 2001 (The Order). The Order protects one or more designated titles set out below for each of the relevant professions, and anyone using one of those titles must be registered with the HCPC. Misuse of a title is a criminal offence.
|Chiropodist / podiatrist||
|Hearing aid dispenser||
|Operating department practitioner||
|Prosthetist / Orthotist||
|Speech and language therapist||
Under The Order the principal functions of the HCPC are to establish standards of education, training, conduct and performance of members of the relevant professions and to ensure the maintenance of those standards. It does this by:
- setting standards, including Standards of Proficiency, Standards of Conduct, Performance and Ethics and Standards of Education and Training;
- approving education programmes and qualifications which meets its standards,
- maintaining a register of appropriately qualified professionals; and
- investigating and adjudicating concerns about fitness to practise.
Remit of the NHS Counter Fraud Authority
NHSCFA is an independent Special Health Authority established in November 2017. NHSCFA leads on work to identify and tackle fraud across the NHS. Its purpose is to safeguard NHS resources so that the NHS is better equipped to care for the nation’s health, providing support, guidance and direction to the NHS. This work enables effective prevention, detection and enforcement action to take place against fraud and fraudulent activity. NHSCFA also collects, collates and analyses information that holds intelligence value, which in turn broadens the understanding of fraud risks in the NHS
NHSCFA has duties and enforcement powers under the NHS Act 2006, the Health and Social Care Act 2012, and the NHSCFA (Establishment, Constitution and Staff and other Transfer Provisions) Order 2017, issued by the Secretary of State for Health. NHSCFA is responsible for:
- leading on work to protect NHS staff, patients and resources from fraud, bribery and corruption, educating and informing those who work for, who are contracted to, or who use the NHS about fraud in the health service and how to tackle it;
- preventing and deterring fraud in the NHS by reducing it and removing opportunities for it to occur or to re-occur; and
- holding to account those who have committed fraud against the NHS by detecting and prosecuting offenders and seeking redress where viable.
Remit of Department of Health and Social Care Anti -Fraud Unit
The Department of Health and Social Care Anti-Fraud Unit (DHSC AFU) was established in November 2014 to tackle fraud against the Department and its Arm’s Length Bodies (ALBs) . DHSC AFU investigates allegations of fraud and corruption which do not affect or relate to the health service or cases which are either of very significant ministerial, government or public interest, or require action to be taken in the name of the Secretary of State, or carry a risk of significant reputational damage to the Department or its ALBs.
DHSC AFU is the sponsor within the Department for NHSCFA. Joint working between DHSC AFU and NHSCFA may be used to enable a joined up/multidisciplinary approach to cases involving new types of fraud or new fraud trends.
DHSC AFU has a comprehensive fraud investigation capability. Investigators complete accredited professional training in criminal investigation and procedure, which is comparable with Police training.
The HCPC’s role in regulating health and care professionals means that its processes are distinct from those of the NHS or the Department of Health and Social Care.
The HCPC is committed to working collaboratively with NHSCFA, the NHS as a whole, DHSC AFU and others, to ensure that service users’ and the public’s safety is upheld. This agreement is intended to ensure that effective channels of communication are maintained between the Parties.
NHSCFA and DHSC AFU are committed to reducing fraud and, corruption within the NHS to a minimum and to put in place arrangements to hold fraud and, corruption at a minimum level permanently. Working in collaboration with the HCPC will ensure patients and public are protected and allegations of suspected fraud and, corruption, which are received by the HCPC, can be passed to NHSCFA or DHSC AFU for investigation. Such information is vital for NHSCFA or DHSC AFU to ensure that systems and procedures can be assessed for their ability to prevent, reduce, detect or measure fraud and, corruption within the NHS in England and Wales.
The Parties intend that their working relationship will be characterised by the development of this agreement, through which they can:
- reduce fraud and corruption within the health profession to a minimum;
- make decisions that promote patient and public safety;
- share information, intelligence, expertise and experience;
- address overlaps and gaps in the regulatory framework;
- cooperate openly and transparently with the other Party;
- respect each Party’s independent status; and
- use resources effectively and efficiently.
The Parties hold and use sensitive information about organisations and individuals in order to perform their core functions. It is important that such information is on occasion shared between the Parties. The Parties recognise that this exchange of information needs to be carried out responsibly and within the guidelines set out in this agreement.
The Parties are committed to the principle of using information more effectively as a means to reducing the burden of administration and regulation.
The HCPC routinely publishes information about the sanctions it has imposed when registrants are not fit to practise.
Where it supports the effective delivery of their respective roles and responsibilities, and the aims of this agreement, the Parties agree:
- to develop mechanisms to systematically and routinely share the types and categories of data (metadata) that they collect and hold; and
- to work towards systematically and routinely sharing identifiable data within those categories.
The Parties acknowledge that intelligence can be received by way of complaints, professional whistleblowing, concerns raised by members of the public, referrals from other public bodies (including overseas regulators or investigatory bodies), or by information received from other sources (e.g. from press monitoring or during the course of routine inspections to registered healthcare premises).
If a Party receives intelligence which:
- indicates a significant risk to the health and wellbeing of the public, particularly in relation to the conduct of a HCPC registrant or suitability of learning environment for students of any professions regulated by HCPC;
- indicates a significant risk of fraudulent activity against the health service; and/or,/li>
- requires a coordinated multi-agency response;
this information will be shared in confidence with the contact specified below within the other Party at the earliest possible opportunity.
NHSCFA has a responsibility to protect NHS staff, patients and resources from fraud, bribery, and corruption by way of effective prevention, detection and enforcement action against fraudsters and fraudulent activity. To facilitate this work, it is important that intelligence held by HCPC relating to HCPC registrant’s fitness to practise is shared with NHSCFA or DHSC AFU in a timely manner.
The HCPC is responsible for regulating health and care professionals which includes taking action when allegations are received which question a registrant’s fitness to practise or concerns about approved education programmes and how education providers meet our standards. This can include allegations relating to fraudulent activity. To facilitate this work, it is important that intelligence held by NHSCFA or DHSC AFU relating to investigations into health and care professionals is shared with the HCPC in a timely manner.
Where the HCPC becomes aware of allegations relating to fraud or corruption against a registrant working in or for the NHS in England or Wales (or indeed, where there are misdirected allegations against other NHS staff) the matter, unless it is clear that NHSCFA is already aware of it, will be reported to NHSCFA as soon as possible in order to ensure it is investigated appropriately and to maximise the chances of financial recovery. Similarly, where the HCPC becomes aware of allegations relating to fraud or corruption against a registrant working in or for the Department of Health or its ALBs (or indeed, where there are misdirected allegations against other DH or ALB staff) the matter, will be reported to DHSC AFU as soon as possible in order to ensure it is investigated appropriately and to maximise the chances of financial recovery.
Reports to NHSCFA can be made via the freephone NHS Fraud and Corruption Reporting hotline on 0800 028 4060 or by completing an online form at www.reportnhsfraud.nhs.uk. The latter method is encouraged as this will enable the HCPC, as a health and care regulatory body, to create an online account for reporting allegations of fraud or corruption in the NHS. By having an account, the HCPC will be able to report matters quickly and more efficiently as and when they arise, and will be able to monitor progress of reports made.
In cases where there are other allegations of dishonesty or criminality, the HCPC will disclose relevant information and documentation to NHSCFA or DHSC AFU where such allegations are relevant to the core functions of NHSCFA or DHSC AFU as appropriate. However, whether such disclosure takes place will depend on the circumstances of the case and the seriousness of the allegations.
In cases where the HCPC is in doubt as to whether a case should be disclosed to NHSCFA or DHSC AFU, they will make contact with the relevant point of contact specified below in order to discuss the matter. Any discussions at this stage will be anonymised. The HCPC will be able to rely on the fact that if the specified NHSCFA or DHSC AFU contact indicates that they wish to receive full disclosure, this will be on the basis that it is essential for that Party’s core purpose or is in the public interest.
Where NHSCFA or DHSC AFU is aware that during or following an investigation, evidence exists that a HCPC registrant, or an healthcare organisation which provides learning environments for students related to HCPC regulated professions has been involved in fraud or corruption the HCPC will be informed of such matters. The HCPC will then consider whether the concerns meet its threshold for allegations for investigation under its fitness to practise process. For concerns about learning environments, the HCPC will consider referrals according to its process for investigations of approved programmes
In cases where NHSCFA or DHSC AFU is in doubt as to whether a case should be disclosed to the HCPC, they will make contact with the point of contact specified below in order to discuss the matter. Any discussions at this stage will be anonymised. NHSCFA and DHSC AFU will be able to rely on the fact that if the specified HCPC contact indicates that they wish to receive full disclosure, this will be on the basis that that is essential for the HCPC’s core purpose or is in the public interest.
Where a case has resulted in a criminal prosecution, NHSCFA or DHSC AFU will share details of the case with the HCPC. That information will already be in the public domain and consent to disclose that information will not be required.
In cases where an investigation has concluded that there was no criminal activity, but indicates there may be concerns about the activities of a HCPC registrant the information will be passed to the HCPC to enable it to decide whether the concerns meet its threshold for allegations for investigation under its fitness to practise process. The HCPC will share that information with the HCPC registrant and their representatives and other third parties involved in the case (where appropriate) and through the provision of that information to the HCPC, NHSCFA or DHSC AFU is consenting to the disclosure of that information.
When information is disclosed to the HCPC there will be a discussion in advance about the timing of any action that the HCPC may consider appropriate, including disclosure of the case to the HCPC registrant and employer involved. The HCPC will consider any request to delay action which may compromise any current NHSCFA or DHSC AFU investigation. However, NHSCFA and DHSC AFU recognise that action may need to be taken by the HCPC where it is in the public interest to do so.
In cases where NHSCFA or DHSC AFU becomes aware of allegations or evidence that an individual may be posing as a HCPC registrant, either through a stolen identity, fraudulently acquired registration or through falsified qualifications, NHSCFA or DHSC AFU will immediately contact the HCPC via the point of contact specified below. NHSCFA or DHSC AFU will provide all available information that might suggest that an individual is posing as a HCPC registrant. In these cases, the primary concern for all Parties will be service user safety. The HCPC will take whatever action is appropriate in the interests of protecting service users.
There may be occasions when the Parties need to undertake concurrent investigations. When this occurs the Parties will take steps to ensure that they do not undermine the progress and/or success of each other’s investigation. This may include allowing criminal investigations to take place as a priority. There may, however, be occasions when the HCPC will need to act swiftly to take steps to protect public safety and would do so with due regard for other known ongoing investigations.
Where any Party intends to undertake a concurrent investigation the contacts in the other Parties specified below should be alerted, in confidence, at the earliest possible opportunity.
Outcomes arising from any relevant investigations actioned by any Party will be shared with the contacts specified below at the earliest possible opportunity.
Where joint or parallel investigations are required, preliminary discussions should resolve any potential areas of conflict or overlap, arising from the Parties’ respective powers.
Where NHSCFA or DHSC AFU have taken or intend to take enforcement action or HCPC intends to take action, the outcome of which is relevant to the other Party, details will be shared at the earliest possible opportunity with the single point of contact or the relevant authorised officer in Appendix 1, specified below.
Areas of communication between the Parties include, but are not limited to:
- sharing of expertise and experience
- discussions about strategy/policy
- discussions about individual registrants
- discussions about suitability of learning environments
- sharing experiences of investigations or trends
- sharing views and information about how improved performance might be encouraged
- publicising joint working commitments
Meetings as and when required between managers within the Fitness to Practise and Registration Depts of the HCPC and counterparts within NHSCFA and DHSC AFU to facilitate the development of effective investigative methodologies. These meetings may involve discussion about particular cases (anonymised if appropriate) and the Parties may be able to share information about approaches to investigations which have been successful in particular circumstances or about useful contacts within other organisations.
Meetings as required between the Parties will provide an opportunity to discuss strategic/policy developments which may impact on each other’s work. Whilst it is not possible to predict all future developments which may be of mutual interest, it is clear that when any Party is reviewing disclosure policies, for example, discussion will be valuable.
Whilst the Parties have very distinct roles, it is clear that there is an overlap where there are allegations that a registrant working in or for the NHS or DHSC or an ALB has acted dishonestly or fraudulently and one or other of the Parties are investigating the individuals in question. Where this kind of issue arises, it is essential that knowledge and information is shared at an early stage between the Parties in order to allow both to carry out their core functions
Referring a concern to the HCPC may be appropriate where investigation of fraud or dishonesty within a healthcare organisation calls into question its suitability as a safe learning environment for students or any of the professions regulated by the HCPC.
From the many cases that the Parties handle, common themes frequently arise. Working collaboratively and sharing this information will enable trends and weaknesses to be quickly identified. Opportunities to deal with the cause of the problems can be discussed and wherever possible fed into policy discussions to work towards changes in practice to prevent further opportunities for fraud, corruption, and other dishonesty.
By sharing this information, appropriate strategies for disseminating information on best practice can be identified and implemented.
Making known, at every available opportunity through all viable mediums, the Parties’ commitment to working together and sharing information about potential media interest, or when the media have actively shown an interest, on an issue of relevance to the organisations. Thereby, supporting an anti-fraud culture within the health profession industry and the wider health service, including where possible promotion of the NHS Fraud and Corruption Reporting Line.
Liaison and dispute resolution
The effectiveness of the working relationship between the Parties will be ensured through regular contact, both formally and informally, at all levels up to and including senior management of the respective Parties.
Any dispute between the Parties will normally be resolved at an operational level. If this is not possible, it may be referred to a Senior Manager on behalf of each Party who will try to resolve the issues within 14 days of the matter being referred to them.
Unresolved disputes may be referred upwards through those responsible for operating this agreement , up to and including the Chief Executive Officer or Managing Director (or equivalent) of each Party, who will be jointly responsible for ensuring a mutually satisfactory resolution.
The Parties agree to report immediately instances of breaches of any of the terms of this agreement especially of the confidentiality obligations and to raise an appropriate security incident should such a breach occur.
Point of contact
The Parties agree to, when possible, share information and intelligence using a single point of contact (SPOC). The single point of contact will be responsible for sending and receiving shared information, and will act as facilitator for enquiries (however, this person may not necessarily be the end user or processor of the information).
The Parties acknowledge that points of contact within the Parties may differ over time due to the nature of investigative activities and the appropriateness of Party involvement. The Parties may nominate an appropriate alternative point of contact for day-to-day communication and/or joint-working in the event of an NHSCFA investigation taking place which involves a specialised area of business, specialist knowledge or a particular expertise. The nominated person(s) will therefore act as single point of contact for investigation purposes. A single point of contact who understands criminal investigation procedures and what is required to a criminal standard is essential to enable investigators to exchange crucial information in a timely manner, to prevent contradictory information being exchanged, and to ensure delays are minimised.
The single point of contact for the HCPC (who will have responsibility for nominating an appropriate alternative point of contact for day-to-day communication and/or joint-working in the event of an NHSCFA investigation) will be:
The single point of contact for NHSCFA (who will have responsibility for nominating an appropriate alternative point of contact for day-to-day communication and/or joint-working in the event of an NHSCFA investigation) will be:
The single point of contact for DHSC AFU (who will have responsibility for nominating an appropriate alternative point of contact for day-to-day communication and/or joint-working in the event of an investigation) will be:
Types of data
The General Data Protection Regulation 2016 essentially defines the following classes of information relevant to this agreement; ‘personal data’, ‘special categories’ and ‘personal data relating to criminal convictions and offences’.
The Caldicott Information Governance Review 2013, commissioned by the Department of Health, introduced the term ‘personal confidential data’ across the healthcare system to widen the interpretation of ‘personal data’ and ‘sensitive data’ for patient identifiable information.
Personal data are defined as “…any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.”
The obtaining, handling, use and disclosure of personal data is principally governed by the General Data Protection Regulation 2016, Data Protection Act 2018, Article 8 of the Human Rights Act 1998, and the common law duty of confidentiality.
The law imposes obligations and restrictions on the way personal data is processed (in this context processing means any operation or set of operations which is performed on personal data , whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction,) and the data subject has the right to know who holds their data and how such data are or will be processed, including how such data are to be shared.
Special Category Data
Certain types of data are referred to as “special categories of personal data’. These are data which relate to the data subject’s:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade union membership;
- genetic Data;
- biometric data (used for identification purposes) ;
- sexual life
- sexual orientation
Additional and more stringent obligations and restrictions apply whenever sensitive personal data is processed.
Data Relating to Criminal Convictions and Offences
Processing of personal data relating to criminal convictions and offences or related security measures is carried out under Article 6 and Article 10 of the GDPR and under Part 3 and Schedule 2 of the Data Protection Act 2018.
Personal confidential data
In 2013 the Department of Health published the Caldicott Information Governance Review, which was an independent review of how information about patients is shared across the health and care system. The review introduced the term ‘personal confidential data’ to describe ‘personal’ and ‘sensitive’ information about identified or identifiable patients, which should be kept private or secret.
Under the General Data Protection Regulation 2016, controller means any ‘natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.’ All data controllers are required to comply with the General Data Protection Regulation 2016 whenever they process personal data. At all times, when providing data to partners, the partner responsible for delivering a service will be considered the “data controller”.
Where two or more controllers jointly determine the purposes and means of processing they are joint controllers and they shall in a transparent manner determine their respective responsibilities for compliance with their obligations under the Regulation. For the purpose of this agreement the Parties will be considered joint data controllers.
Legal Basis for Sharing
In writing this Agreement due attention has been paid to the views of the Parties where possible, and all guidance has been written to ensure that the disclosure, access, storage and processing of shared information is accurate, necessary, secure, legal and ethical, taking into account relevant legislation and approved guidance where applicable, including:
- NHS Act 2006;
- General Data Protection Regulation 2016
- Human Rights Act 1998;
- Freedom of Information Act 2000;
- Data Protection Act 2018;
- Equality Act 2010;
- Access to Health Records Act 1990;
- Computer Misuse Act 1990;
- Confidentiality: NHS Code of Practice;
- Common Law Duty of Confidentiality.
The Secretary of State for Health has responsibility to make arrangements for healthcare provision nationally and to comply with legislation. The Secretary of State for Health, acting through NHSCFA, has a responsibility to ensure healthcare provision is protected from fraud and other unlawful activities. It is therefore appropriate that information relating to the administration of NHS business may be used for these purposes provided that the requirements of law and policy are satisfied.
Information shared between the Parties will only be used for the purpose(s) specified in this Agreement and its use by NHSCFA will comply with the NHSCFA information security policy and operating procedures.
Part 10 of the NHS Act 2006 makes provision for the protection of the NHS from fraud and other unlawful activities. The NHS Act 2006 confers powers upon NHSCFA, as the statutory body responsible for tackling crime across the NHS, to require the production of information or data from an NHS contractor (defined as any person or organisation providing services of any description under arrangements made with an NHS body) in connection with the exercise of the Secretary of State for Health’s counter fraud functions.
Operational work undertaken by NHSCFA is carried out under Article 6, para (e), Article 9(2) paras (f) and/or (g) and Article 10 of the General Data Protection Regulation 2016 and Part 3 and Schedule 2 Part 1 of the Data Protection Act 2018, for the prevention and detection of crime; under Part 10 of the NHS Act 2006, for the protection of the NHS from fraud and other unlawful activities; and in accordance with the powers contained in part 4 of the NHS Counter Fraud Authority (Establishment, Constitution, and Staff and other Transfer Provisions) 2017 and such directions as the Secretary of State for Health may give. These can be found at:
NHS Act 2006, Part 10:
General Data Protection Regulation 2016
Data Protection Act 2018, Part 3:
Secretary of State for Health’s counter fraud functions:
Information or data shared between HCPC, NHSCFA and DHSC AFU may be used by the Parties for criminal prosecution purposes if the information or data demonstrates evidence of fraud or other unlawful activities against the NHS and/or the information forms a material part of an investigation.
Access and Individual’s Rights
Freedom of Information
The Parties are subject to the Freedom of Information Act 2000. The principles of the Freedom of Information Act 2000 apply and nothing provided in this Agreement is confidential to the Parties to this Agreement. Information relating to NHS business processed by the Parties is essentially public sector information; therefore this information may be subject to Freedom of Information enquiries but only by going through the Parties own Freedom of Information process. It is up to the recipient Party to disclose information, or to authorise the disclosure of information, under the terms of the Freedom of Information Act 2000. Public sector information which is subject to the provisions of the Freedom of Information Act 2000 cannot be accessed under Freedom of Information processes by going directly to a third party data processor.
Under the Freedom of Information Act 2000, individuals can make a request to the Parties for information to be disclosed. This is called a Freedom of Information Request. Requests must be put in writing to the recipient Party following their official Freedom of Information Request process. Requests will be considered by the Party’s Information Governance representative and a decision will be made as to the legality and appropriateness of information disclosure.
Subject Access Requests
The Parties are subject to the General Data Protection Regulation 2016 and the Data Protection Act 2018. Under the General Data Protection Regulation 2016 and the Data Protection Act 2018, data subjects can ask to see the information that is held on computer and in some paper records about them. This is called a Subject Access Request. If data subjects wish to know what information is held about them, requests must be submitted to the recipient Party following their official Subject Access Request process. Requests will be considered by the Party’s Information Governance representative and a decision will be made as to the legality and appropriateness of information disclosure.
Complaints regarding data
Complaints from data subjects about personal or sensitive information held by the Parties must be made in writing to the person or organisation holding the information, detailing the reasons for the complaint. Complaints must be put in writing to the relevant person or organisation following their official complaints process.
Security of information
HCPC, NHSCFA and DHSC are registered with the Information Commissioner’s Office on the Data Protection Register.
Regardless of the type of information being accessed, processed and stored, security is considered of paramount importance. All information held by the Parties is held on secure servers, with access restricted to internal use by appropriately authorised members of staff. As data controllers for the information they collect, the Parties are expected to treat all information in accordance with the General Data Protection Regulation 2016 and the Data Protection Act 2018, and ensure that security is in place sufficient to protect the information from unauthorised access. This includes physical security, such as adhering to organisational clear desk policies and adequate protection for premises when unattended, to IT related security such as passwords, secure IDs and secure servers.
It is understood that the Parties may have differing security needs, however it is important that all reasonable steps are made to ensure information is kept private and confidential at all times. Each Party is expected to comply with their own Information Security Policy and operating procedures and to make staff aware of their obligations in this respect. As administrators of NHS business, the Parties are also expected to comply with the standard requirements in the NHS Code of Practice for Information Security Management and the NHS Information Governance Guidance on Legal and Professional Obligations, which can be found at:
Each Party’s responsible officer will ensure that their staff know, understand and guarantee to maintain the confidentiality and security of the information and will ensure that anyone involved with the processing of the information is aware of the penalties of wrongful disclosure.
Due to the sensitive nature of operational work carried out by NHSCFA and DHSC AFU, much of the information held is classified by the Government Security Classification System as “Official’ or ‘Official Sensitive’. Very sensitive information that justifies heightened protective measures to defend against determined and highly capable threats should be marked as ‘Secret’. NHSCFA and DHSC AFU therefore use the Public Services Network (PSN) in its operations and in so doing complies with the standard requirements in the code of conduct for Government Connect.
The levels of classification assigned by the HCPC to information shared are “Unrestricted”, “Restricted”, “Confidential” and “Highly Confidential” depending on the content as per its policy.
The Parties must take appropriate technical and organisational measures against unauthorised or unlawful accessing and/or processing of information and against accidental loss or destruction of, or damage to, information. This will include:
- appropriate technological security measures, having regard to the state of technology available and the cost of implementing such technology, and the nature of the information being protected;
- secure physical storage and management of non-electronic information;
- password protected computer systems;
- ensuring information is only held for as long as is necessary, in line with data protection obligations; and
- appropriate security on external routes into the organisation, for example internet firewalls and secure dial-in facilities
Each Party is responsible for its own compliance with security in respect of the General Data Protection Regulation 2016 and Data Protection Act 2018, irrespective of the specific terms of this Agreement.
The physical and technical security of the information will be maintained at all times. No disclosable information will be sent by fax or email (unless vis PSN or NHS.net networks) and, if posted, will be encrypted to approved standards to protect the information and dispatched by Royal Mail Special Delivery service or by courier.
Access to the information will be restricted to those staff with a warranted business case. Access to information will be via restricted-access password protection and be capable of audit. The means of access to the information (such as passwords) will be kept secure.
The preferred method of information transfer for general enquiries, general communications and small data attachments (for example MS or PDF files not exceeding 15MB) will be by email (via PSN). NHSCFA uses Egress Switch to send data securely using the ‘official (official-sensitive) marking under the Government Classification Scheme.
The preferred method of information transfer for large volume information sharing (such as downloads of complete datasets where size exceeds 15MB), will be by saving the information to a removable media device (for example, a USB stick, pen drive or CD) and dispatching the device to the receiving Party, either by Royal Mail Special Delivery service or by courier. The removable media device must be encrypted to approved standards to protect the information and the information itself must be password protected. Decryption processes and passwords will be disclosed separately upon receipt of the removable media device and the information it contains. The Parties may agree on alternative methods of transfer of documents as appropriate, for example by Egress.
Laptops used to access information must be encrypted and secured to an HM Government approved or recognised level, commensurate with the level of the protective marking of the information involved as will any network they are connected to.
The Parties may be required to provide copies of any audits conducted during the period of the Agreement, including any audit arrangements or implementation plans.
Retention of information
Information shall be stored in accordance with the Parties’ records retention and disposal schedule. In the absence of a records retention and disposal schedule, or a statutory retention period, the information shall not be retained for longer than is necessary to fulfil the specified purpose or purposes.
Breach and Dispute Procedures
The Parties agree to report immediately instances of breaches to any of the terms of this Agreement and to raise an appropriate security incident. Any disputes arising between the giving and receiving Parties will be resolved initially between the principles of this Agreement. Otherwise, outstanding issues will be referred to an executive group established on behalf of each party.
The parties will maintain their own individual information sharing log in respect of the agreement.
The log will contain:
- A record of information disclosed between the parties under the terms of this agreement;
- The decision of justification to disclose or not to disclose;
- An access list recording the authorising officer’s decision on where data is agreed for disclosure or non-disclosure;
- Records of meetings between the parties;
- A record of any review of the agreement.
Duration and review
This agreement shall commence on the date of its signature by the Parties and will remain in effect for a term of one year, or as otherwise agreed, unless it is terminated, re-negotiated or superseded by a revised document.
At the end of one year, or as otherwise agreed, following the commencement of the agreement, the agreement will be formally reviewed by the Parties, and will be reviewed again as agreed. Each review will:
- report on actions arising from the operation of this agreement within the preceding agreed period;
- consider whether the agreement is still useful and fit for purpose, and make amendments where necessary;
- refresh operational protocols where necessary;
- identify areas for future development of the working arrangements; and
- ensure the contact information for each organisation is accurate and up to date.
Following each review, the agreement shall automatically renew for a further period of one year, or as otherwise agreed, unless terminated or re-negotiated by either Party.
Either Party may terminate or re-negotiate this agreement at any time upon giving the other Party one month’s notice in writing of its intention to do so.
This agreement is not legally binding and is not intended to create legal relationships between the Parties.