442 – Caldicott Guardians for pharmacies

2021-09-26 13:39:25

Last December, we reported that pharmacies may be required to appoint Caldicott Guardians this year. 

The National Data Guardian has used her statutory powers to publish new guidance on the appointment, role and responsibilities of Caldicott Guardians https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/1013756/Caldicott_Guardian_guidance_v1.0_27.08.21.pdf

The guidance recommends the appointment of a Caldicott Guardian not just by public bodies exercising functions relating to the health service, adult social care or adult carer support in England, but also by other persons or organisations providing services as part of the publicly funded health service. This recommendation would plainly extend to pharmacies (and dispensing doctors) that provide NHS services.

The role of Caldicott Guardians is to assist with processing of confidential data of patients and service users of publicly funded services. The role may overlap with that of Data Protection Officer (DPO) and the same person could carry out the same roles as long as no conflict of interest arises.  The Caldicott Guardian need not be an employee, but could be provided by another organisation and/or could be shared with other providers of healthcare services.

According to the guidance, the Caldicott Guardian should “play a key role in helping to ensure that their organisation(s) satisfy the highest ethical and legal standards for processing patient and service user confidential information. Their main concern is confidential information relating to patients, service users and their care. However, in some circumstances the Caldicott Guardian’s judgment may also be needed in relation to the use of information about other individuals, such as staff or relatives of service users.” The guidance stipulates that Caldicott Guardians must be afforded the freedom to exercise their judgment and advise or decide in the best interests of patients and service users.

Day-to-day activities of a Caldicott Guardian will vary according to organisation type and size. They may include:

  • advising on disclosures of confidential information, in particular whether they can be made in line with the common law duty of confidentiality
  • involvement with patients’ or service users’ complaints
  • reviewing and advising on data protection impact assessments, data sharing agreements, and instructions to data processors (although noting also the specific role that the organisation’s DPO may also have in relation to these issues
  • involvement in audit reporting or recommendations
  • involvement in data breach investigations (again noting the potentially overlapping role of the DPO).

 

Leave a Comment

Scroll to Top