Between
(1) Supply Chain Coordination Limited (SCCL)
Wellington House, 133-155 Waterloo Road, London SE1 8UG
and
(2) NHS Counter Fraud Authority (NHSCFA)
7th Floor HM Government Hub, 10 South Colonnade, Canary Wharf, London E14 4PU
(collectively “the Parties”, henceforth).
Purpose and aims
1. This Agreement describes the collective roles of Supply Chain Coordination Limited (“SCCL” henceforth) and the NHS Counter Fraud Authority (“NHSCFA” henceforth) and outlines the basis of cooperation and collaboration between the Parties. It sets down the principles underpinning the interaction between the Parties and provides guidance on the exchange of information between them.
2. This Agreement applies to England and is intended to provide a framework to assist the joint working of the Parties to ensure maximum effectiveness by driving savings through preventing and detecting fraud and identifying and enacting additional efficiencies and savings. More specifically it concerns the undertaking of data sharing exercise between the parties, and includes practical arrangements in support of this that are designed to ensure the relationship is effective and that, together, the Parties meet their aims and objectives, particularly when there are overlapping interests and responsibilities.
3. Although the Parties agree to adhere to the contents of this Agreement, it is not intended to be a legally binding document. The Agreement does not override each Party’s statutory responsibilities or functions, nor does it infringe the autonomy and accountability of either Party or their governing bodies.
4. The Parties agree to abide by the Data Sharing Code of Practice #footnote-1[1] produced by the Information Commissioners Office and recognise their respective responsibilities as public bodies under the UK General Data Protection Regulation (GDPR), Data Protection Act 2018 and the Freedom of Information Act 2000.
5. The aims of this Agreement are to facilitate this data sharing, with the wider objectives that:
- prevent and reduce fraud and corruption within the NHS through proactive fraud detection;
- identify opportunities for efficiency through related savings and loss prevention;
- maintain patient safety and confidence in the healthcare profession;
- support the sharing of information, intelligence, expertise and experience;
- define the circumstances in which the two organisations will act independently.
6. The term “information” is used in this Agreement by NHSCFA to refer to any and all information or data used for NHS business purposes, including commercial, business, personal and sensitive information or data. The medium in which information or data may be displayed, presented, shared, disclosed or processed, may be in the form of hard-copy or electronic data, records or documents.
7. To facilitate the sharing of information, both Parties will follow due processes as they are defined in the Agreement.
Remit of the Parties
Supply Chain Coordination Limited
8. SCCL is responsible for sourcing, delivering, and supplying a wide range of healthcare products, services, and food to NHS trusts and healthcare organisations across England and Wales. Its goal is to streamline procurement, reduce costs, and ensure consistent quality and availability of essential supplies, ultimately supporting better patient care.
9. Supply Chain Coordination Limited (SCCL) is the management function behind the NHS supply chain. It provides oversight and operational leadership, ensuring that the supply chain model delivers value and efficiency. SCCL is the legal entity through which the NHS supply chain operates, transacts with suppliers, and engages with NHS customers. Although it is owned by NHS England, SCCL operates as a separate organisation.
10. SCCL operates as a central procurement and logistics service for the NHS in England. It sources, delivers, and manages a wide range of medical and non-medical products, ensuring consistent supply and cost efficiency. SCCL acts as the contracting authority and strategic manager of the supply chain. This structure allows NHS organisations to focus on patient care while benefiting from national economies of scale, improved product quality, and streamlined procurement processes that support the wider goals of the NHS and public health.
NHS Counter Fraud Authority
11. NHSCFA is an independent Special Health Authority established in November 2017. NHSCFA leads on work to identify and tackle crime across the NHS. Its purpose is to safeguard NHS resources so that the NHS is better equipped to care for the nation’s health, providing support, guidance and direction to the NHS. This work enables effective prevention, detection and enforcement action to take place against fraud and fraudulent activity. NHSCFA also collects, collates and analyses information that holds intelligence value, which in turn broadens the understanding of fraud risks in the NHS.
12. NHSCFA has duties and enforcement powers under the NHS Act 2006, the Health and Social Care Act 2012, and the NHSCFA (Establishment, Constitution and Staff and other Transfer Provisions) Order 2017, issued by the Secretary of State for Health. NHSCFA is responsible for:
- leading on work to protect NHS staff, patients and resources from fraud, bribery and corruption, undertake measurement of key areas of fraud risk and the scale and extent of fraud in the NHS;
- educating and informing those who work for, who are contracted to, or who use the NHS about fraud in the health service and how to tackle it;
- preventing and deterring fraud in the NHS by reducing it and removing opportunities for it to occur or to re-occur; and
- holding to account those who have committed fraud against the NHS by detecting and prosecuting offenders and seeking redress where viable.
Information sharing
13. SCCL and NHSCFA intend that their working relationship will be characterised by the development of this Agreement, through which the Parties can:
- Undertake joint data analytics and fraud measurement activities within this exercise, using data for the purposes of reducing fraud and corruption through proactive fraud detection;
- Share information, intelligence, expertise and experience, as necessary, to apply domain expertise drawn from knowledge of fraud, data analytics and NHS practice to derive findings that support counter fraud and loss prevention;
- Make joint decisions concerning findings that disrupt and prevent fraud and drive further efficiencies and savings;
- Address overlaps and gaps in the regulatory framework and, where necessary, derive improved policy and practice to mitigate any recognised fraud risks;
- Cooperate openly and transparently with the other Party;
- Respect each Party’s independent status; and
- Use resources effectively and efficiently.
Information sharing
14. This Agreement specifically supports the creation of joint exercises undertaken by the Parties in support of the above. SCCL holds and uses sensitive information about organisations and individuals in order to perform its core functions. It allows that such information is, on occasion, shared between the Parties, particularly where this serves the public interest and/or the prevention or detection of crime. The Parties recognise that this exchange of information needs to be carried out responsibly and within the guidelines set out in this Agreement.
15. Simultaneously, as part of the NHSCFA Strategy, NHSCFA actively seeks to use powers enacted through data sharing laws, supported by its defined remit, to access and utilise enriched data sources that can be used to detect fraud through outlier detection and to measure the scale and extent of fraud risks and other types of loss. NHSCFA has had notable success by applying a range of data sources to their in-house analytical capability and fraud-specific domain expertise and, bolstered by the above SCCL data and their own domain expertise, this can produce outcomes that meet the joint objectives of preventing fraud and other types of loss.
16. This capability is able to apply a robust data science framework and under a range of data matching, rule based and analytical approaches to find outliers that can indicate fraudulent activity and estimations of fraud loss. More recently, NHSCFA has been able to invest heavily in machine learning and advanced analytics for counter fraud detection, a specific programme of work to enhance proactive counter fraud detection through advanced data analytics. This will necessitate access and use of dynamic datasets of data to allow the appropriate data science framework for machine learning models to take place.
17. By combining domain (subject) specialist, analytical expertise, and technology on a national and local level, this combined approach will increase fraud, error and loss detection and provide the opportunities for fraud prevention loss reduction as part of a wider activities drawn from the findings of the shard data, through which the Parties can intervene quickly to reduce the impact and loss from fraud. The exercise also benefits from a range of NHSCFA use cases that characterize the unique risks associated with staff fraud, supported by a problem centric approach and operational support.
18. As identified above, the requirements for data will sit across a range of potential datasets and corresponding software. It is important to note that the data requirements within each will be clarified and refined following engagement, in support of minimisation and proportionality and in alignment with the Caldicott Principles. Because the exercise concerns a range of substantiated fraud types, this is deliberately broad.
19. The Parties confirm that the agreement does not concern access to, or sharing of, personally identifiable data and that this is not within scope. As such, a full Data Protection Impact Assessment (“DPIA”) has not been determined as necessary. This clause may be revisited in the future should the intended joint work be extended, and this Information Sharing Agreement (and an aligned produced DPIA and jointly approved) be developed to record the identification of any risks associated with these types of data, and their continued management and mitigation over the course of the collaboration.
20. The Parties are subject to the duty of confidentiality owed to those who provide them with confidential information and the confidentiality and security of this information will be respected. It is understood by the Parties that statutory and other constraints on the exchange of information will be fully respected, including the requirements of the UK GDPR, the Data Protection Act 2018, the Freedom of Information Act 2000 and the Human Rights Act 1998.
21. Where it supports the effective delivery of their respective roles and responsibilities, and the aims of this Agreement, the Parties agree:
- to develop mechanisms to systematically and routinely share the types and categories of data (metadata) that they collect and hold relevant to this exercise; and
- to work towards systematically and routinely sharing identifiable data within those categories for the purposes of this exercise.
Intelligence
22. The Parties acknowledge that intelligence can be received by way of information that goes above and beyond the activities of this exercise and can include complaints, professional whistleblowing, concerns raised by members of the public, referrals and findings drawn from other public bodies (including overseas regulators or investigatory bodies), or by information received from other sources (e.g. from press monitoring or during the course of routine inspections) or findings drawn as part of collaborative, or even entirely sperate, activities between NHSCFA and SCCL.
23. Throughout the full extent of this planned work, if either Party receives intelligence which, regardless of relevance to the exercise that concerns the primary information sharing (as outlined above) indicates the following:
- a significant risk to the health and wellbeing of the public;
- a significant risk of fraudulent activity against the NHS; and/or
- that a coordinated multi-agency response is needed;
this information will be shared in confidence with the contact specified below within the other Party at the earliest possible opportunity.
24. NHSCFA has a responsibility to protect NHS staff, patients and resources from fraud, bribery, and corruption by way of effective prevention, detection and enforcement action against fraudsters and fraudulent activity. SCCL is similarly responsible for ensuring that procurement delivers the best possible financial outcomes for the NHSs by negotiating competitive contracts, driving efficiencies in purchasing, and reducing duplication. To facilitate this work, it is important that intelligence held by either party is shared on a timely basis.
Investigation
25. In circumstances where any individual outlier can be utilised for further action then the information would be diverted to a ‘business as usual’ process for national or local investigation which would undertake its own specific data share, as needed. Where SCCL becomes aware of allegations against people abusing the NHS, NHSCFA will be informed (if it is not clear that they are already aware) if there are clear allegations of fraud, corruption, or bribery.
26. In cases where there are other allegations of dishonesty or criminality, SCCL, as part of the case management process, will disclose relevant information and documentation to NHSCFA where such allegations are relevant to NHSCFA’s core functions. However, whether such disclosure takes place will depend on the circumstances of the case and the seriousness of the allegations and will be aligned with the usual rules for case management within the remit of the NHSCFA, as per the Secretary of State for Health’s Directions, and the role of the participating NHS bodies as the organisation(s) managing the investigation.
27. In cases where SCCL is in doubt as to whether a case should be disclosed to NHSCFA, they will liaise with the point of contact specified below in order to discuss the matter. Any discussions at this stage will be anonymised. SCCL will be able to rely on the fact that if the specified NHSCFA contact indicates that they wish to receive wider disclosure, this will be on the basis that it is essential for NHSCFA’s core purpose or is in the public interest.
28. On a broader national picture, if NHSCFA is aware that during or following an investigation, evidence exists that persons of relevance to SCCL have been involved in fraud, corruption or bribery, the relevant organisation(s) will be informed of such matter and can consider whether any further investigation needs to be carried out.
29. In cases where NHSCFA staff are in doubt as to whether a case should be disclosed to SCCL, they will liaise with the point of contact specified below in order to discuss the matter. Any discussions at this stage will be anonymised. NHSCFA will be able to rely on the fact that if SCCL indicates that they wish to receive full disclosure, this will be on the basis that it is essential for its core purpose or is in the public interest.
30. In cases where an investigation has concluded that there was no fraudulent activity, but indicates there may be concerns about the activities of persons of relevance, the information will be passed to the SCCL to enable a decision to be taken on the seriousness of the allegations and their relevance to its core functions.
31. When information is disclosed there will be a discussion in advance about the timing of any action that may be considered appropriate, including disclosure of the case to any third parties and/or the individual involved. Any relevant participating NHS bodies will consider any request to delay action which may compromise any current NHSCFA investigation. However, NHSCFA recognises that action may need to be taken where it is in the public interest to do so.
32. There may be occasions when the Parties need to undertake concurrent investigations. When this occurs both Parties will take steps to ensure that they do not undermine the progress and/or success of each other’s investigation. This may include allowing criminal investigations to take place as a priority. There may, however, be occasions when SCCL will need to act swiftly to take steps to protect public safety and would do so with due regard for other known ongoing investigations.
33. Where either Party intends to undertake an investigation over and above any activity derived as a result of this data share, yet with the knowledge that this concerns the same individuals, the contact in the other Party specified below should be alerted, in confidence, at the earliest possible opportunity.
34. Outcomes arising from any relevant investigations actioned by either Party will be shared with the contact specified below at the earliest possible opportunity.
35. Where joint or parallel investigations are required, preliminary discussions should resolve any potential areas of conflict or overlap, arising from each Party’s respective powers.
Enforcement
36. Where NHSCFA has taken or intends to take enforcement action or the participating NHS bodies intends to take action, the outcome of which is relevant to the other Party, details will be shared at the earliest possible opportunity with the single point of contact (outlined below) or the relevant authorised officer in Appendix A.
Communication
37. Areas of communication between the Parties include, but are not limited to:
-
sharing of analysis, findings and support of domain expertise and experience
Meetings between the participating NHS bodies and NHS Counter Fraud Authority to facilitate the sharing of data, the development of effective analytical methodologies and the validation of findings. These meetings may involve discussion about particular cases (anonymised if appropriate) and the two Parties may be able to share information about activity and outcomes alongside the approaches to investigations which have been successful in particular circumstances or about useful contacts within other organisations. -
discussions about strategy/policy
Regular meetings between the Parties will provide an opportunity to discuss strategic/policy developments which may impact on each other’s work. Whilst it is not possible to predict all future developments which may be of mutual interest, it is clear that when either Party is reviewing disclosure policies, for example, discussion will be valuable. -
discussions about individuals
Where it is clear, as a result of the planned exercise and subsequent work or any wider activity, where there is an overlap that extends to suspicions or allegations that persons of relevance, working in or for the NHS, has acted dishonestly or fraudulently and one or both Parties are investigating the individuals in question. Where this kind of issue arises, it is essential that knowledge and information is shared at an early stage between the Parties in order to allow both to carry out their core functions. -
sharing experiences of investigations or trends
From the many cases that the Parties handle, as well as their knowledge of practice (both fraudulent and otherwise) common themes frequently arise. Working collaboratively and sharing this information will enable trends and weaknesses to be quickly identified. Opportunities to deal with the cause of the problems can be discussed and wherever possible fed into policy discussions to work towards changes in practice to prevent further opportunities for fraud, corruption, theft and other dishonesty. -
sharing views and information about how improved performance might be encouraged
By sharing this information, appropriate strategies for disseminating information on best practice can be identified and implemented. -
publicising joint working commitments
Making known, at every available opportunity through all viable mediums, the Parties’ commitment to working together and sharing information about potential media interest, or when the media have actively shown an interest, on an issue of relevance to both organisations. Thereby, supporting an anti-crime culture within the wider health service, including where possible promotion of the NHS Fraud and Corruption Reporting Line.
38. The working relationship between the Parties will be characterised by regular ongoing contact and the open exchange of information and intelligence, through both formal and informal meetings at all levels, including senior levels.
39. Disclosures from either Party to the other will be regularly monitored to ensure that arrangements are working effectively. To facilitate the sharing of information and intelligence, both Parties will follow due processes as they are defined in this Agreement.
Liaison and dispute resolution
40. The effectiveness of the working relationship between SCCL and NHSCFA will be ensured through regular contact, both formally and informally, at all levels up to and including senior management of the respective Parties.
41. Any dispute between the Parties will normally be resolved at an operational level. If this is not possible, it may be referred to a Senior Manager on behalf of each Party who will try to resolve the issues within 14 days of the matter being referred to them.
42. Unresolved disputes may be referred upwards through those responsible for operating this Agreement, up to and including the Chief Executive Officer or Managing Director (or equivalent) of each Party, who will be jointly responsible for ensuring a mutually satisfactory resolution.
43. The Parties agree to report immediately instances of breaches of any of the terms of this Agreement especially of the confidentiality obligations and to raise an appropriate security incident should such a breach occur.
Point of contact
44. The Parties agree to, when possible, share information and intelligence using a single point of contact (SPOC). The single point of contact will be responsible for sending and receiving shared information, and will act as facilitator for enquiries (however, this person may not necessarily be the end user or processor of the information).
45. The Parties acknowledge that points of contact within the Parties may differ over time due to the nature of investigative activities and the appropriateness of Party involvement. The Parties may nominate an appropriate alternative point of contact for day-to-day communication and/or joint-working in the event of an NHSCFA investigation taking place which involves a specialised area of business, specialist knowledge or a particular expertise. The nominated person(s) will therefore act as single point of contact for investigation purposes. A single point of contact who understands criminal investigation procedures and what is required to a criminal standard is essential to enable investigators to exchange crucial information in a timely manner, to prevent contradictory information being exchanged, and to ensure delays are minimised.
Supply Chain Coordination Limited
46. The single point of contact for SCCL, who will have responsibility for nominating an appropriate alternative point of contact for day-to-day communication and/or joint-working in the event of an NHSCFA investigation, will be:
NHS Counter Fraud Authority
47. The single point of contact for NHSCFA, who will have responsibility for nominating an appropriate alternative point of contact for day-to-day communication and/or joint-working in the event of an NHSCFA investigation, will be:
Data control
48. Under the UK GDPR, controller means any ‘natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.’ All data controllers are required to comply with the UK GDPR whenever they process personal data. At all times, when providing data to partners, the partner responsible for delivering a service will be considered the “data controller”.
49. Where two or more controllers jointly determine the purposes and means of processing, they are joint controllers, and they shall in a transparent manner determine their respective responsibilities for compliance with their obligations under the UK GDPR. For the purpose of this Agreement the Parties will be considered independent data controllers in respect of the information they hold.
Types of data
50. The UK GDPR essentially defines the following classes of information relevant to this Agreement; ‘personal data’, ‘special category data’ and ‘personal data relating to criminal convictions and offences’.
51. The Caldicott Information Governance Review 2013, commissioned by the Department of Health and Social Care, introduced the term ‘personal confidential data’ across the healthcare system to widen the interpretation of ‘personal data’ and ‘sensitive data’ for patient identifiable information:
Personal data
Personal data are defined as “…any information relating to an identified or identifiable natural person; an identifiable natural person (data subject) is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.’
The obtaining, handling, use and disclosure of personal data is principally governed by the UK GDPR, Data Protection Act 2018, Article 8 of the Human Rights Act 1998, and the common law duty of confidentiality.
The law imposes obligations and restrictions on the way personal data is processed (in this context processing means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction,) and the data subject has the right to know who holds their data and how such data are or will be processed, including how such data are to be shared.
Special Category Data
Certain types of data are referred to as “special categories of personal data’ or ‘sensitive personal data”. These are data which relate to the data subject’s:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade union membership;
- genetic data;
- biometric data;
- health;
- sexual life.
Additional and more stringent obligations and restrictions apply whenever sensitive personal data is processed.
Data Relating to Criminal Convictions and Offences
There are separate safeguards for personal data relating to criminal convictions and offences, set out in Article 10 of the UK GDPR and Part 3 of the Data Protection Act 2018. To process personal data regarding convictions or offences there must be a lawful basis under UK GDPR Article 6 and legal/official authority under UK GDPR Article 10 and Part 3 of the Data Protection Act 2018.
Personal Confidential Data
In 2013 the Department of Health published the Caldicott Information Governance Review, which was an independent review of how information about patients is shared across the health and care system. The review introduced the term ‘personal confidential data’ to describe ‘personal’ and ‘sensitive’ information about identified or identifiable patients, which should be kept private or secret. The Caldicott Information Governance Review can be found at:
52. The Parties agree and acknowledge that they will collect and store information in support of the exercise and that they share information in order to assist with the exercise, as well as in performance of their statutory functions, in the format and manner described within this document. However, for the purposes of this agreement the items outlined in paragraph 51 are not in scope, having not been deemed necessary for the purposes of meeting the joint objectives of each party in this context.
53. When the giving Party discloses information to the receiving Party, that information shall be disclosed for the purposes of the prevention, detection, investigation and prosecution of fraud or any other unlawful activity affecting the NHS, as set out in the NHS Counter Fraud Authority (Establishment, Constitution and Staff and Other Transfer Provisions) Order 2017, which can be found at:
http://www.legislation.gov.uk/uksi/2017/958/contents/made
54. Where the giving Party shares information with the receiving Party, it must be in alignment with the principles and objectives outlined in this agreement. The Parties may share any wider information or data that is related to the exercise, so long as it is not personally identifiable or otherwise sensitive, in any manner it considers appropriate, although the receiving Party may from time to time make recommendations to the giving Party as to the most practicable means by which information may be shared.
55. If the Parties wish to share bulk data electronically, it will only be in a mutually compatible IT format and shared via the secure method agreed by both parties in advance.
56. In relation to the sharing of information, the Parties shall take all measures necessary to ensure their respective compliance with all relevant legislation, including, but not limited to, regulations or restrictions regarding disclosure of information to third parties. The Parties will be responsible for processing information in accordance with all applicable data privacy and related regulations (Article 5 of the UK GDPR).
Information sharing protocol
57. Information disclosed by the Parties will comply with the Government Security Classification System. In this regard, each piece of information will be assigned a level of protection for its processing. All material with a protective marking will be, where possible, marked at the top and bottom and page numbered, and will have a distribution list. Any documents without protective marking will be treated as “Official (official sensitive)”. Further information regarding the Government Security Classification System is available in the HM Government Security Policy Framework, which can be found at:
Government Security Classifications Policy Quick Read (HTML) - GOV.UK (www.gov.uk)
58. The levels of classification assigned by the Parties to information shared shall be “Official (official sensitive)” or “Secret” depending on the content. In the context of this exercise, it is envisaged in all but the most extenuating circumstances that “official” / “official – sensitive” will be appropriate.
Official
Most information will fall under the “Official” classification but may need to be further marked to indicate that extra care should be taken when handling the information. If that is the case the marking “Official – Sensitive” should be used. This will be applicable if compromise or loss of the information could have damaging consequences for an individual.
Secret
Very sensitive information that justifies heightened protective measures to defend against determined and highly capable threats should be marked as “Secret”. For example, where compromise could seriously damage the investigation of very serious organised crime. The threat profile for “Secret” anticipates the need to defend against a higher level of capability than would be typical for the “Official” level. This includes sophisticated, well-resourced and determined threats, such as highly capable serious organised crime groups.
59. The Parties agree that, in relation to information contained in material which is marked as “Official” or “Secret”, that it will not:
- disclose, release, communicate, or otherwise make available, the information to any other individual, organisation or third party not directly connected with the work involved without prior agreement and approval of the giving Party, except in the form of non-disclosive statistical data, anonymised data or conclusions;
- use the information for any commercial, industrial or other purpose; or
- copy, adapt, duplicate or otherwise reproduce the information save as provided in this Agreement.
60. If there is a need for the Parties to disclose or supply information to other law enforcement agencies, government departments and agencies, or any specified external body for the purposes of data matching and other anti-crime techniques, full records will be kept of when and what information is disclosed or supplied to external bodies.
Lawful basis for sharing
61. In writing this Agreement due attention has been made to the views of the Parties where possible, and all guidance has been written to ensure that the disclosure, access, storage and processing of shared information is accurate, necessary, secure, legal and ethical, taking into account relevant legislation and approved guidance where applicable, including:
- NHS Act 2006
- UK General Data Protection Regulation
- Human Rights Act 1998
- Data Protection Act 2018
- Freedom of Information Act 2000
- Equality Act 2010
- Access to Health Records Act 1990
- Computer Misuse Act 1990
- Confidentiality: NHS Code of Practice
- Common Law Duty of Confidentiality
NHS Counter Fraud Authority
62. The Secretary of State for Health has responsibility to make arrangements for healthcare provision nationally and to comply with legislation. The Secretary of State for Health, acting through NHSCFA, has a responsibility to ensure healthcare provision is protected from fraud and other unlawful activities. It is therefore appropriate that information relating to the administration of NHS business may be used for these purposes provided that the requirements of law and policy are satisfied.
63. This activity is consistent with the NHSCFA’s role, as outlined by the Secretary of State for Health Directions, which identifies that NHSCFA is directed to obtain, monitor, collate and analyse such data held by the Department of Health and Social Care, NHS bodies, or other bodies or persons or local authorities as NHSCFA may lawfully acquire and as it may consider appropriate for the purposes of identifying trends and anomalies which may be indicative of fraud, corruption or other unlawful activity.
64. Information shared between the Parties will only be used for the purpose(s) specified in this Agreement and its use by NHSCFA will comply with the NHSCFA information security policy and operating procedures.
65. Part 10 of the NHS Act 2006 makes provision for the protection of the NHS from fraud and other unlawful activities. The NHS Act 2006 confers powers upon NHSCFA, as the statutory body responsible for tackling crime across the NHS, to require the production of information or data from an NHS contractor (defined as any person or organisation providing services of any description under arrangements made with an NHS body) in connection with the exercise of the Secretary of State for Health’s counter fraud functions.
66. Data sharing for this exercise, undertaken by NHSCFA, is carried out under Article 6, paragraph (e), Article 9 part (2) paragraphs (f) and/or (g) and Article 10 of the UK GDPR.
Lawful basis for sharing of partner organisation
67. Information or data shared between SCCL and NHSCFA may be used by the Parties for criminal prosecution purposes if the information or data demonstrates evidence of fraud or other unlawful activities against the NHS and/or the information forms a material part of an investigation.
Access and individual’s rights
Freedom of information
68. The Parties are subject to the Freedom of Information Act 2000. The principles of the Freedom of Information Act 2000 apply and nothing provided in this Agreement is confidential to the Parties to this Agreement. Information relating to NHS business processed by the Parties is essentially public sector information; therefore this information may be subject to Freedom of Information enquiries but only by going through the Parties own Freedom of Information process. It is up to the recipient Party to disclose information, or to authorise the disclosure of information, under the terms of the Freedom of Information Act 2000.
69. Under the Freedom of Information Act 2000, individuals can make a request to the Parties for information to be disclosed. This is called a Freedom of Information Request. Requests must be put in writing to the recipient Party following their official Freedom of Information Request process. Requests will be considered by the Party’s Information Governance representative and a decision will be made as to the legality and appropriateness of information disclosure.
Data subjects’ rights
70. The Parties are subject to the UK GDPR and the Data Protection Act 2018. Under the UK GDPR and the Data Protection Act 2018, data subjects can ask to see the information that is held on computer and in some paper records about them. This is called a Subject Access Request. If data subjects wish to know what information is held about them, or have inaccurate information rectified or deleted, requests must be submitted to the recipient Party following their official Subject Access Request process. Requests will be considered by the Party’s Information Governance representative and a decision will be made as to the legality and appropriateness of information disclosure, information rectification or information deletion.
Complaints regarding data
71. Complaints from data subjects about personal or sensitive information held by the Parties must be made in writing to the person or organisation holding the information, detailing the reasons for the complaint. Complaints must be put in writing to the relevant person or organisation following their official complaints process.
Security of information
72. Both Parties are registered with the Information Commissioner’s Office on the Data Protection Register. Registration entry can be found at:
http://www.ico.org.uk/esdwebpages/search
Supply Chain Coordination Limited (SCCL) Registration number: ZA795361
NHS Counter Fraud Authority (NHSCFA) Registration number: ZA290744
73. Regardless of the type of information being accessed, processed and stored, security is considered of paramount importance. All information held by the Parties are held on secure servers, with access restricted to internal use by appropriately authorised members of staff. As data controllers for the information they collect, the Parties are expected to treat all information in accordance with the UK GDPR and the Data Protection Act 2018, and ensure that security is in place sufficient to protect the information from unauthorised access. This includes physical security, such as adhering to organisational clear desk policies and adequate protection for premises when unattended, to IT related security such as passwords, secure IDs and secure servers.
74. It is understood that the Parties may have differing security needs, however it is important that all reasonable steps are made to ensure information is kept private and confidential at all times. Each Party is expected to comply with their own Information Security Policy and operating procedures and to make staff aware of their obligations in this respect. As administrators of NHS business, the Parties are also expected to comply with the standard requirements in the NHS Code of Practice for Information Security Management and the NHS Information Governance Guidance on Legal and Professional Obligations, which can be found at:
75. Each Party’s responsible officer will ensure that their staff know, understand and guarantee to maintain the confidentiality and security of the information and will ensure that anyone involved with the processing of the information is aware of the penalties of wrongful disclosure.
76. Due to the sensitive nature of operational work carried out by the Parties, much of the information held by the Parties is of a sensitive nature and classified under the UK Government Security Classification Scheme as “Official’ or ‘Official Sensitive’. All information shall be managed and handled in accordance with UK Gov. policy and guidance available here - https://www.gov.uk/government/publications/government-security-classifications.
77. The Parties must take appropriate technical and organisational measures against unauthorised or unlawful accessing and/or processing of information and against accidental loss or destruction of, or damage to, information. This will include:
- appropriate technological security measures, having regard to the state of technology available and the cost of implementing such technology, and the nature of the information being protected;
- secure physical storage and management of non-electronic information;
- password protected computer systems;
- ensuring information is only held for as long as is necessary, in line with records retention policies and data protection obligations; and
- appropriate security on external routes into the organisation, for example internet firewalls and secure dial-in facilities.
78. Each Party is responsible for its own compliance with security in respect of the UK GDPR and Data Protection Act 2018, irrespective of the specific terms of this Agreement.
79. The physical and technical security of the information shall be maintained at all times. No disclosable information shall be transmitted unless by encrypted means. If data transfer is required using physical digital media, e.g. USB stick/DVD, the data will be encrypted to approved standards and dispatched by Royal Mail Special Delivery service or by courier.
80. Access to the information will be restricted to those staff with a warranted business case. Access to information will be via restricted-access password protection and be capable of audit. The means of access to the information (such as passwords) will be kept secure.
81. The preferred method of information transfer for general enquiries, general communications and small data attachments (for example MS Office or PDF files notpdf54 exceeding 15MB) will be via email, secured additionally to standard TLS encryption where appropriate. Large volume information sharing (such as downloads of complete datasets where size exceeds 15MB) will be by secure encrypted file transfer.
82. Laptops used to access information must be encrypted and secured to an HM Government approved or recognised level, commensurate with the level of the protective marking of the information involved as will any network they are connected to.
83. The Parties may be required to provide copies of any audits conducted during the period of the Agreement, including any audit arrangements or implementation plans.
Retention of information
84. Information shall be stored in accordance with the Parties’ records retention policy and disposal schedule.
85. In the absence of a records retention policy and/or disposal schedule, or a statutory retention period, the information shall not be retained for longer than is necessary to fulfil the specified purpose or purposes.
Breach and dispute procedures
86. The Parties agree to report immediately instances of breaches to any of the terms of this Agreement and to raise an appropriate security incident.
87. Any disputes arising between the giving and receiving Parties will be resolved initially between the principles of this Agreement. Otherwise, outstanding issues will be referred to an executive group established on behalf of each party.
Duration and review
88. This Agreement shall commence on the date of its signature by the Parties and will remain in effect for a term of one year unless it is terminated, re-negotiated or superseded by a revised document.
89. At the end of one year, or as otherwise agreed, following the commencement of the Agreement, the Agreement will be formally reviewed by the Parties, and will be reviewed again no less frequently than on each anniversary of its signing. Each annual review will:
- report on actions arising from the operation of this Agreement within the preceding 12 months;
- consider whether the Agreement is still useful and fit for purpose, and make amendments where necessary;
- refresh operational protocols where necessary;
- identify areas for future development of the working arrangements; and
- ensure the contact information for each organisation is accurate and up to date.
90. Following each annual review, the Agreement shall automatically renew for a further period of one year, unless terminated or re-negotiated by either Party.
91. Either Party may terminate or re-negotiate this Agreement at any time upon giving the other Party one month’s notice in writing of its intention to do so.
92. This Agreement is not legally binding and is not intended to create legal relationships between the Parties.