FOI/2026/27/26

Read more about this page below

Your Request & Our Response:

 

Inappropriate Access & Disclosure of Personal Data – Learning and Prevention (UK NHS Trusts)

 

1.      This FOI forms part of an apprenticeship project focused on understanding how NHS Trusts manage incidents of inappropriate access to, or disclosure of, personal data, and how learning is used to reduce recurrence and strengthen information governance controls.This request is made under the Freedom of Information Act 2000. No personal or identifiable information is requested. Aggregated or approximate information is acceptable where exact figures are not held.

 

2.      Please provide the name of your NHS Trust.

 Central London Community Healthcare NHS Trust

 

3.      What type of NHS Trust do you work for?

  1. Acute Trust
  2. Mental Health Trust
  3. Ambulance Services Trust
  4. Community Health and Mental Health Trust
  5. Specialist Trust

Central London Community Healthcare NHS Trust is a Community Trust.

 

4.      Please provide copies of, or links to, the Trust’s current policies or procedures relating to:

  1. Inappropriate access to records
  2. Inappropriate disclosure of personal data
  3. Staff access auditing and monitoring

Please find attached:

  1. Acceptable IT Use Policy Acceptable-IT-Use-Policy-v5.4-Final (3).pdf
  2. Clinical Record Keeping Policy and Protocol  Clinical-Record-Keeping-Policy-and-Protocol_PRG-queries_VN (2).pdf
  3. Confidentiality Code of Conduct Confidentiality-Code-of-Conduct-Policy-v6.4-Final (4).pdf

 

5.      Does the Trust undertake trend analysis or thematic review of inappropriate access or disclosure incidents?

       If yes, please confirm how frequently:

  1. Monthly
  2. Quarterly
  3. Annually

All information Governance incidents are reviewed and reported on a bi-monthly basis.

 

6.      Does the Trust routinely carry out system access audits following allegations of inappropriate access?

      If yes, please confirm which systems are subject to audit and how often (e.g. EPR or clinical systems).

Yes, the Trust carries out access audit following allegations of inappropriate access. The system audit is random across all clinical systems.

 

7.      Does the Trust have a policy for the management of Allegations Against People in a Position of Trust (for example, PIPOT, LADO, SAMA, or equivalent)?

      If yes, please provide copies of, or links to, this policy.

Please find attached Managing-Safeguarding-Allegations-Made-Against-CLCH-Staff-LADO-and-PiPoT-Policy-Links-removed-9-Dec-25.pdf

 

8.      Are you able to provide aggregated data relating to inappropriate access or disclosure incidents, and how many were reported to the Information Commissioner’s Office (ICO)?

      Approximate figures are acceptable where exact figures are not held.

 

Year (April–March)

No. of Incidents Recorded No. Reported to ICO

2023–2024 107  3

2024–2025 153 3

2025–2026 137 0

 

9.      Please confirm whether staff receive mandatory training covering:

  1. Appropriate access to records
  2. Confidentiality and data protection obligations

The above are addressed during staff induction sessions. The clinical Record Keeping training which includes the two aspects above is mandatory for all clinical staff.  

 

10.  Does the Trust provide additional targeted training or communications in response to increases in inappropriate access or disclosure incidents? If yes, please describe or provide examples.

]Reminders are sent Trust wide via the Communications Team.

 

11.  Please confirm whether learning from inappropriate access or disclosure incidents is:

  1. Shared with the services or teams involved
  2. Used to inform policy updates, training, or system controls

Yes, learning is shared with the services and incidents are used to inform Trust policies, training or system controls.

 

12.     What actions has the Trust taken to address inappropriate access or disclosure, and which measures have been effective or ineffective?

Actions has been taken on a case-by-case basis, including application of HR processes. The Trust is unable to comment on which measures have been effective as the incident criteria are depended on each case and therefore are vary.   

 

Accessibility tools