(1 month, 2 weeks ago)
Public Bill Committees
Sojan Joseph
Q
Dr Byrne: Those things are very important, yes. There are some technical solutions. Again, the SPR is an opportunity to look at that across the system, because systems vary greatly in the sophistication of their audit function, for example. Even when there is an audit function, if someone has legitimate access through their role as a doctor or a nurse, it can be difficult to know whether their access in any particular case is legitimate. These are not common occurrences, but it is extremely distressing for patients if their confidentiality is breached for any reason.
It is not simply a matter of technical controls. We need to look at how we build stronger, more effective deterrents across the system by having effective sanctions when incidents do occur. I am keen to look at that and delighted that the Department of Health and Social Care and NHS England are, I think, very interested in having that conversation with me. At the moment, it certainly seems that there is a variable response across the system to inappropriate access.
Looking ahead to the SPR, we need to look at that make improvements, so that the public can have faith that, given the harm that it can cause them, it will be taken very seriously if anyone does access their records inappropriately. There are technical, cultural and system aspects to think about here. The SPR is definitely an opportunity to do that, and I am very keen to work with other stakeholders on that.
Peter Prinsley
Q
Dr Byrne: It is an interesting idea, but I am not sure. I heard your question earlier about data controllership specifically in this regard. You will not necessarily like my answer. There are two ways of answering the question; perhaps straightforwardly, legally, but also clinically. I will start with the legal answer, which in some ways is easier. Data controllership in data protection law is a very technical term; it is determined by who is making the decisions about processing the means of the data. An organisation running and controlling an electronic patient record would be the data controller. Obviously, this is ultimately a question for the regulator and the Information Commissioner’s Office to determine, but that would be the legal position, nevertheless.
Clinically, we have to come back to thinking about what a patient record is for. Primarily, it is to provide good care in the context of the clinician-patient relationship. If you prioritise the needs of either side of that relationship, I think it is problematic; the needs of one must not outweigh the needs of the other.
The clinical record is there to enable clinicians to record what someone is presenting with, the difficulties they are having, what investigations are appropriate, the findings and what the plan is. It needs to be there for that tool to work. To take you on a slight thought experiment, if it was entirely held within a patient’s control—however loosely we use that term, legally or otherwise—and we could all amend, correct, change or add our diagnoses, findings and treatments, that might be clinically problematic. That may not be the answer you want, but it is the straight answer, if I am honest, from both a clinical and legal perspective.