23.08.2015 Views

April 1st 2009 to March 31st 2010

The Annual Report and Accounts April 1st 2009 to March 31st 2010

The Annual Report and Accounts April 1st 2009 to March 31st 2010

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Information GovernanceComplianceInformation Governance allows organisationsand individuals <strong>to</strong> ensure that personalinformation is handled legally, securely,efficiently and effectively, in order <strong>to</strong> deliverthe best possible care. It additionally enablesorganisations <strong>to</strong> put in place procedures andprocesses for their corporate information thatsupport the efficient location and retrieval ofcorporate records where and when needed, inparticular <strong>to</strong> meet requests for information andassist compliance with Corporate Governancestandards.The Information Governance Committeeidentifies and manages information risks,which reports <strong>to</strong> the Healthcare GovernanceCommittee. The Deputy Chief Executive, who isalso the nominated Board Lead for InformationGovernance Risk and the Senior InformationRisk Owner for the Trust, chairs the InformationGovernance Committee.Compliance with Information Governancestandards is moni<strong>to</strong>red using the InformationGovernance Toolkit and during <strong>2009</strong>-10 theTrust achieved a rating of 87% compliance.In addition <strong>to</strong> the Toolkit the Trust is required<strong>to</strong> assess and report information risks anddata losses. During <strong>2009</strong>/10 the Trust has beenworking <strong>to</strong> improve incident reporting andawareness of information security issues. Anumber of methods have been used includingan ongoing information flow mappingexercise supported by ward and departmentalinformation security and confidentiality reviews.System Administra<strong>to</strong>rs have been undertakinginformation risks assessments for individual coresystems <strong>to</strong> identify and manage informationrisks.During the financial year <strong>2009</strong>-<strong>2010</strong> the Trusthad 28 information security related incidentsreported all of which were rated at a level 0.Whilst the severity rating of these incidentswas rated at 0 all were thoroughly investigatedand reported upon. Note: Information Securityincidents are rated on a scale from 0-5, incidentsclassified as a severity rating of 3-5 are reportedas a serious un<strong>to</strong>ward incident and reported <strong>to</strong>Moni<strong>to</strong>r and the Information Commissioner.The table below provides a summary.Table 1: Summary Of Other Personal Data Related Incidents In <strong>2009</strong>-10Category Nature of Incident TotalILoss of inadequately protected electronic equipment, devices or paperdocuments from secured NHS premises.0IILoss of inadequately protected electronic equipment, devices or paperdocuments from outside secured NHS premises0IIIInsecure disposal or inadequately protected electronic equipment, devicesor paper documents7IV Unauthorised disclosure 2V Other 19Annual Report and Accounts <strong>April</strong> <strong>1st</strong> <strong>2009</strong> <strong>to</strong> <strong>March</strong> 3<strong>1st</strong> <strong>2010</strong> 43

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!