Caldicott Report
   HOME

TheInfoList



OR:

The Caldicott Committee's ''Report on the Review of Patient-Identifiable Information'', usually referred to as the Caldicott Report was a review commissioned in 1997 by the
Chief Medical Officer Chief medical officer (CMO) is the title used in many countries for the senior government official designated head of medical services, sometimes at the national level. The post is held by a physician who serves to advise and lead a team of medical ...
of
England England is a country that is part of the United Kingdom. It shares land borders with Wales to its west and Scotland to its north. The Irish Sea lies northwest and the Celtic Sea to the southwest. It is separated from continental Europe b ...
due to increasing worries concerning the use of patient information in the
National Health Service The National Health Service (NHS) is the umbrella term for the publicly funded healthcare systems of the United Kingdom (UK). Since 1948, they have been funded out of general taxation. There are three systems which are referred to using the " ...
(NHS) in
England and Wales England and Wales () is one of the three legal jurisdictions of the United Kingdom. It covers the constituent countries England and Wales and was formed by the Laws in Wales Acts 1535 and 1542. The substantive law of the jurisdiction is Eng ...
and the need to avoid the undermining of confidentiality because of the development of
information technology Information technology (IT) is the use of computers to create, process, store, retrieve, and exchange all kinds of data . and information. IT forms part of information and communications technology (ICT). An information technology system (I ...
in the NHS, and its ability to propagate information concerning patients in a rapid and extensive way. A committee was established under the chairmanship of Dame
Fiona Caldicott Dame Fiona Caldicott, ( Soesan; 12 January 1941 – 15 February 2021) was a British psychiatrist and psychotherapist who also served as Principal (college), Principal of Somerville College, Oxford She was the National Data Guardian for Health a ...
, Principal of
Somerville College, Oxford Somerville College, a constituent college of the University of Oxford in England, was founded in 1879 as Somerville Hall, one of its first two women's colleges. Among its alumnae have been Margaret Thatcher, Indira Gandhi, Dorothy Hodgkin, Ir ...
, and previously President of the
Royal College of Psychiatrists The Royal College of Psychiatrists is the main professional organisation of psychiatrists in the United Kingdom, and is responsible for representing psychiatrists, for psychiatric research and for providing public information about mental health ...
. Its findings were published in December 1997. The Caldicott Report highlighted six key principles, and made 16 specific recommendations. In 2012 Dame Fiona produced a follow-up report which made 26 further recommendations including the addition of a seventh principle which is included in the list below. In 2016 a further follow-up report was produced following controversy over the
care.data care.data was a programme announced by the then Health and Social Care Information Centre in spring 2013. It aimed to extract data from GP surgeries into a central database through the General Practice Extraction Service (GPES). Members of the E ...
initiative from
HSCIC NHS Digital is the trading name of the Health and Social Care Information Centre, which is the national provider of information, data and IT systems for commissioners, analysts and clinicians in health and social care in England, particularly th ...
.


Caldicott principles

#Justify the purpose(s)
Every single proposed use or transfer of patient identifiable information within or from an organisation should be clearly defined and scrutinised, with continuing uses regularly reviewed, by an appropriate guardian. #Don't use patient identifiable information unless it is necessary
Patient identifiable information items should not be included unless it is essential for the specified purpose(s) of that flow. The need for patients to be identified should be considered at each stage of satisfying the purpose(s). #Use the minimum necessary patient-identifiable information
Where use of patient identifiable information is considered to be essential, the inclusion of each individual item of information should be considered and justified so that the minimum amount of identifiable information is transferred or accessible as is necessary for a given function to be carried out. #Access to patient identifiable information should be on a strict need-to-know basis
Only those individuals who need access to patient identifiable information should have access to it, and they should only have access to the information items that they need to see. This may mean introducing access controls or splitting information flows where one information flow is used for several purposes. #Everyone with access to patient identifiable information should be aware of their responsibilities
Action should be taken to ensure that those handling patient identifiable information - both clinical and non-clinical staff - are made fully aware of their responsibilities and obligations to respect patient confidentiality. #Understand and comply with the law
Every use of patient identifiable information must be lawful. Someone in each organisation handling patient information should be responsible for ensuring that the organisation complies with legal requirements. #The duty to share information can be as important as the duty to protect patient confidentiality
Professionals should in the patient's interest share information within this framework. Official policies should support them doing so. These principles have been subsumed into the NHS confidentiality code of practice.


Summary of recommendations in original report

#Every dataflow, current or proposed, should be tested against basic principles of good practice. Continuing flows should be re-tested regularly. #A programme of work should be established to reinforce awareness of
confidentiality Confidentiality involves a set of rules or a promise usually executed through confidentiality agreements that limits the access or places restrictions on certain types of information. Legal confidentiality By law, lawyers are often required ...
and
information security Information security, sometimes shortened to InfoSec, is the practice of protecting information by mitigating information risks. It is part of information risk management. It typically involves preventing or reducing the probability of unauthorize ...
requirements amongst all staff within the
NHS The National Health Service (NHS) is the umbrella term for the publicly funded healthcare systems of the United Kingdom (UK). Since 1948, they have been funded out of general taxation. There are three systems which are referred to using the " ...
. #A senior person, preferably a health professional, should be nominated in each health organisation to act as a guardian, responsible for safeguarding the confidentiality of patient information. #Clear guidance should be provided for those individuals/bodies responsible for approving uses of patient-identifiable information. #Protocols should be developed to protect the exchange of patient-identifiable information between NHS and non-NHS bodies. #The identity of those responsible for monitoring the sharing and transfer of information within agreed local protocols should be clearly communicated. #An accreditation system which recognises those organisations following good practice with respect to confidentiality should be considered. #The NHS number should replace other identifiers wherever practicable, taking account of the consequences of errors and particular requirements for other specific identifiers. #Strict protocols should define who is authorised to gain access to patient identity where the NHS number or other coded identifier is used. #Where particularly sensitive information is transferred,
privacy Privacy (, ) is the ability of an individual or group to seclude themselves or information about themselves, and thereby express themselves selectively. The domain of privacy partially overlaps with security, which can include the concepts of a ...
enhancing technologies (e.g.
encrypting In cryptography, encryption is the process of encoding information. This process converts the original representation of the information, known as plaintext, into an alternative form known as ciphertext. Ideally, only authorized parties can deci ...
identifiers or "patient identifying information") must be explored. #Those involved in developing health
information systems An information system (IS) is a formal, sociotechnical, organizational system designed to collect, process, information storage, store, and information distribution, distribute information. From a sociotechnical perspective, information systems a ...
should ensure that best practice principles are incorporated during the design stage. #Where practicable, the internal structure and administration of databases holding patient-identifiable information should reflect the principles developed in this report. #The
NHS number NHS numbers are the unique numbers allocated in a shared numbering scheme to registered users of the three public health services in England, Wales and the Isle of Man. It is the key to the identification of patients, especially in delivering safe ...
should replace the patient's name on Items of Service Claims made by General Practitioners as soon as practically possible. #The design of new systems for the transfer of prescription data should incorporate the principles developed in this report. #Future negotiations on pay and conditions for General Practitioners should, where possible, avoid systems of payment which require patient identifying details to be transmitted. #Consideration should be given to procedures for General Practice claims and payments which do not require patient-identifying information to be transferred, which can then be piloted.


References

{{reflist


See also

*
Caldicott guardian The Caldicott Committee's December 1997 ''Report on the Review of Patient-Identifiable Information'', usually referred to as the Caldicott Report (named after its author Dame Fiona Caldicott), identified weaknesses in the way parts of NHS handled ...

UK Caldicott Guardian Council (UKCGC)
National Health Service