To ask the Scottish Executive what safeguards there will be in the NHS national database of patient details to ensure appropriate patient confidentiality.
National electronic databasescontaining patient details are protected by a range of safeguards to ensure appropriatepatient confidentiality. Staff access is governed by their contractual duty of confidentiality,backed by training and a specific protocol for each database which sets out appropriateuse. There are in addition a range of technical security safeguards. These includeuse of the secure intra-NHS telecommunications system, firewalls, encryption, individualuser passwords and audit log of all accesses.
Planning work and early implementationis underway towards the Electronic Health Record, an outcome of Delivering forHealth, which is expected to be fully deployed by 2010. Early components of the Electronic Health Record, such as the Emergency Care Summary are protected bythe full range of security measures outlined above and future versions of the ElectronicHealth Record will be similarly protected. Information on the Emergency Care Summarydatabase can only be accessed on a genuine “need to know” basis. This requires thatthose who use a patient’s information:
Are who they claim to be throughauthorisation identity checks
Have a legitimate care relationshipwith the patient
Only see information their roleallows
An audit trail record is keptof everyone who views a patient’s Emergency Care Summary record.