SLMS-IG16 Training Needs Analysis

advertisement
SLMS-IG16 Training Needs
Analysis
Document Information
Document Name
Author
Issue Date
Approved By
Next review
SLMS-IG16 Training Needs Analysis
Kristina Drew
02/08/2013
Chair of SLMS IGSG
Three years
Document History
Version
0.1
0.2
0.3
0.4
0.5
Date
21/01/2013
24/01/2013
24/04/2013
10/06/2013
09/07/2013
1.0
1.1
02/08/2013
21/08/2014
2.0
23/09/2014
Summary of change
First draft for discussion
Incorporated feedback from Alice Garrett
Revisions from Shane Murphy
Incorporated revisions from Trevor Peacock
Incorporated roles from IDHS-Roles-Workflow-and-AuthorisationModel-v3
Approved by Chair of SLMS IGSG
Amendments by Kristina Drew to reflect in-house SLMS IG training
provision and simplified training requirements for SLMS job roles
Approved by Chair of SLMS IGSG
Model Guidance for the SLMS Information Governance Training
1. Purpose
The NHS Department of Health has mandated the use of the NHS IG Toolkit (Hosted
Secondary Use Team/Project) (IGTK) for research study compliance. One of the
requirements of the IGTK is that all relevant staff complete their annual mandatory
Information Governance (IG) Training. Additionally, there is a requirement to test and
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 1 of 11 follow up staff understanding of IG responsibilities thus providing assurance that they
are competent when handling sensitive personal data.
IGTK (Hosted Secondary Use Team/Project) identifies holistically the various
requirements and standards for handling sensitive personal data and deals with the
following areas:
• Confidentiality
• Information Security
• Data Quality
• Data Protection, Subject Access
In house introductory information governance training (‘SLMS Introduction to
Information Governance’ training and awareness event (SLMS Intro to IG)) with a
follow-up in house online assessment (‘SLMS Information Governance - Assessment
of Understanding’ (SLMS IG - Assessment of Understanding)) covers the above
areas and ensures a consistent and measurable approach to IG training for those
handling sensitive personal data across the SLMS.
Where an individual is unable to attend an SLMS Intro to IG event, the NHS HSCIC
Information Governance Training Tool (IGTT) will be used as alternative training and
assessment tool.
The SLMS must continue to ensure and demonstrate that information is used legally
and ethically, and prove to be a trustworthy and considerate data custodian when
carrying out the high quality research that the SLMS’s reputation is based upon.
This Guidance ensures that the SLMS:
•
•
•
will be compliant with the IGTK requirements;
that those with access to sensitive personal data can demonstrate through the
SLMS IG - Assessment of Understanding or the IGTT reports the required
level of understanding; and
that those with access to sensitive personal data are provided with training on
internal procedures that support the SLMS Information Governance
Framework.
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 2 of 11 2. Scope
This Guidance applies to all personnel of the SLMS, including contracted, noncontracted, temporary, honorary, secondments, agency, students, volunteers or
locums.
3. Guidance
3.1 Training Needs Analysis
Annual IG Training is a mandated requirement of the IGTK. All the SLMS Line
Managers must ensure that a Training Needs Analysis is completed for relevant staff
to ensure the appropriate IG training is completed:
•
•
•
During staff induction into the SLMS
When a change in role and/or responsibilities occurs
As part of the annual staff performance development review
The Information Governance Lead with the approval of the Information Governance
Steering Group (IGSG) may also request that additional Information Governance
training is undertaken by relevant staff as a result of a security breach or Serious
Untoward Incident (SUI) involving information assets.
SLMS information governance training or relevant NHS IGTT training, and the
frequency that the SLMS personnel are expected to complete them is located at
Appendix 1.
Guidelines on how to access the online NHS IGTT are located at Appendix 3.
3.2 Minimum training requirements
In-house SLMS training has been devised to cover both the requirements of the
IGTK and to inform SLMS personnel of locally-provided information governance
services and solutions.
The IGSG has recommended that as a minimum the following initial training is
mandatory for all the SLMS staff who have access to sensitive personal data:
•
Attendance of ‘SLMS Introduction to Information Governance’ (SLMS Intro to
IG) training and awareness event
Followed by
•
Successful completion of the online ‘SLMS Information Governance Assessment of Understanding’ (SLMS IG - Assessment of Understanding)
(See Appendix 2)
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 3 of 11 Where there is a pressing requirement for IG training and the staff member is unable
to attend an SLMS Intro to IG training event, initial mandatory training may
alternatively be met by completion of the ‘Introduction to Information Governance’
module and assessment within the NHS HSCIC Information Governance Training
Tool (IGTT). (The IGTT uses clinical, rather than research-based examples, so is not
the preferred training tool for the research context in which SLMS operates.)
Once the initial mandatory training has been successfully completed, by way of
Refresher training, the ‘SLMS IG - Assessment of Understanding’ must be retaken
and successfully completed on an annual basis.
Certificates should be retained as an electronic copy as proof of completion of
training.
For those staff undertaking Incident and, or Risk Management and Confidentiality
Audits, guidance will be provided via the SLMS Information Governance Advisory
Service.
3.3 Staff unable to complete on line training/assessment
Line managers must contact the IG Lead where they have staff who do not have
access to a computer/laptop in order to complete their Information Governance
Training. Alternative arrangements will be agreed to ensure that these staff complete
their annual mandatory Information Governance Training.
Staff who do not have access to a computer/laptop and whose role does not include
the use of personal information may, at the discretion of the IG Lead, be excluded
from this Guidance. Other relevant Information Governance Training will be agreed.
Staff who are unable to complete their identified annual mandatory Information
Governance Training for whatever reason must inform their line manager or the IG
Lead as soon as possible.
3.4 Responsibilities
3.4.1 The SLMS Information Governance Training and Awareness Service will:
•
Issue prompts and updates to all staff via email, intranet, team meeting
briefings and newsletters regarding completion of annual mandatory
Information Governance Training as per this Guidance.
•
Monitor staff completion of Information Governance Training.
•
Escalate cases of non-compliance via the IG Lead to the Information
Governance Steering Group (IGSG) and ultimately to the SIRO
•
Issue quarterly reports showing the SLMS progress for Information
Governance Training to IGSG members for discussion at IGSG and other
SLMS meetings. The reports will be statistical only (no personal data) and
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 4 of 11 obtained from the SLMS Information Governance Register and online
Information Governance Training Tool (IGTT).
•
Provide ad hoc reports to Line Managers for monitoring staff performance of
Information Governance Training. The reports will provide detailed information
for Line Managers’ staff and will show completion of IG Training.
3.4.2 Line Managers are responsible for:
•
Completing Training Needs Analysis for all staff as in 3.1 above.
•
Confirming and monitoring that their staff have completed the relevant annual
mandatory Information Governance Training.
•
Agreeing actions and associated timescales with staff that have not
completed their identified training.
3.4.3 Staff are responsible for:
•
Completing identified Information Governance Training within the specified
timescales.
•
Keeping themselves informed and up to date about changes to all corporate
policies and procedural documents.
•
Notifying their Line Manager when they cannot complete the identified
Information Governance Training as soon as possible.
3.5 Implementation and compliance
3.5.1 Information about this Guidance will be disseminated via e-mail, intranet,
website, staff meetings, team meeting briefings and Information Governance or
other UCL newsletters.
3.5.2 All staff as defined in Section 2.0 are obliged to adhere strictly to all the SLMS
policies and a failure to do so may lead to disciplinary action.
3.5.3 Managers must ensure that staff are made aware of this Guidance, understand
the Guidance and adhere to it.
3.5.4 Implementation and compliance with this Guidance will be audited by the
Information Governance Steering Group.
3.5.5 The Department of Heath will review compliance via Information Governance
Toolkit Submissions by the organisation and via audit.
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 5 of 11 Appendix 1
Information Governance Training - Training to be undertaken by staff.
1.
All SLMS personnel who are part of a team who handle sensitive personal
data must attend the SLMS Introduction to Information Governance training
and must successfully complete, within two weeks of the training event, the
online SLMS IG - Assessment of Understanding (See Appendix 2). On
passing the assessment they will be issued with a certificate and their name
added to the SLMS IG Training Register.
(It is recommended that the same training and assessment is undertaken by
those who do not currently handle sensitive personal data.)
2.
Annual Refresher Training: To remain on the SLMS IG Training Register,
personnel are required to re-take and successfully complete the SLMS IG Assessment of Understanding annually thereafter. As part of this process
personnel will be directed to relevant SLMS IG training resources and updates
to IG legislation.
•
Individuals will be contacted by the SLMS Information Governance
Training and Awareness Service one month before their IG training is due
to expire
•
Individuals will then be required to complete SLMS IG - Assessment of
Understanding before expiry of their current IG training
•
Those whose IG training lapses, either by failing the assessment or not
taking the SLMS IG - Assessment of Understanding within the required the
one year period, will be removed from the IG register and given one month
to book onto another ‘SLMS Intro to IG’ training event. The Information
Governance Training and Awareness Service will monitor training
bookings, and will escalate the failure to rebook within one month, via the
IG Lead to the IGSG and ultimately the SIRO.
•
To be reinstated on the SLMS IG register, re-attendance of the ‘SLMS
Intro to IG’ training and passing the SLMS IG - Assessment of
Understanding within two weeks of the training event is required.
3.
The relevant training identified for each job role is mandatory and must be
undertaken within six weeks of being allocated and every year thereafter.
4.
If you are unsure which job role to follow please ask your Line Manager. They
will contact the Information Governance Lead for advice if necessary.
5.
Particular roles are required to attend specialist IG training sessions. These
include:
• SIRO
• IG Lead
• Members of IGSG
• IG Service Owners
• IG Service Operations Managers
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 6 of 11 The SLMS Job
Role
Training to be completed
Personnel who
Mandatory Initial Training
routinely handle
• SLMS Introduction to Information
sensitive
Governance training and awareness event
personal data
• SLMS IG - Assessment of Understanding
as part of a
(‘Pass’ required within 2 weeks of attending
research project
the SLMS Intro to IG event)
(Includes
Alternative Initial Training
Principal
Investigators,
(For those unable unable to attend SLMS
Researchers,
Intro to IG training event)
Research
NHS IG Training Tool ‘Introduction to
Students,
Information Governance’ includes
Project
assessment
Administrators,
IT for SLMS
Mandatory Annual Refresher
Infrastructure
• SLMS IG - Assessment of Understanding
Team)
(‘Pass’ required annually)
• If training lapses, re-do ‘Initial training’
Approx.
Time
1.5h
½h
2h
½h
SLMS mandatory training may be waived where
the individual is able to provide evidence of up-todate IG certification from another recognised
organisation (See Appendix 4)
Principal
Investigators
Mandatory Initial Training
•
As for those who routinely handle sensitive
personal data as part of a research project
(see above)
Mandatory Annual Refresher
•
As for those who routinely handle sensitive
personal data as part of a research project
(see above)
Mandatory Supporting Guides to review
•
•
SLMS-IG04 Data Handling Guidance for
Principal Investigators (URL)
Guide to On-going Management of IG
Toolkit (TBA)
SLMS mandatory training may be waived where
the individual is able to provide evidence of up-toSLMS-­‐IG16 Training Needs Analysis v2.0 Page 7 of 11 1.5h
½h
date IG certification from another recognised
organisation (See Appendix 4)
Mandatory Training
Personnel who
do not currently
• Induction material (TBA)
handle sensitive
personal data
Recommended Training
as part of a
research project
• SLMS Introduction to Information
Governance training and awareness event
• SLMS IG - Assessment of Understanding
(‘Pass’ required within 2 weeks of attending
the SLMS Intro to IG event)
1.5h
½h
Recommended Annual Refresher
•
•
SIRO
SLMS IG - Assessment of Understanding
(‘Pass’ required annually)
If training lapses, re-do ‘Initial training’
½h
Mandatory Training
Specialist SIRO/IG Lead training (e.g. as
provided by Dilys Jones Associates)
IG Lead
½ day
Mandatory Annual Refresher
Specialist SIRO/IG Lead refresher training
(e.g. as provided by Dilys Jones Associates)
TBC
Supporting Guides
•
•
•
IGSG members
Mandatory Training
Specialist IG training (e.g as provided by
Dilys Jones Associates)
IG Service
Service Owners
IG Service
Operations
Managers
SLMS-IG01 IG Steering Group ToR
SLMS-IG02 SIRO Role
SLMS-IG05 IG Lead Role
Mandatory Annual Refresher
Specialist IG refresher training (e.g. as
provided by Dilys Jones Associates)
Supporting Guides
•
SLMS-IG01 IG Steering Group ToR
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 8 of 11 ½ day
TBC
Appendix 2
SLMS Information Governance - Assessment of Understanding
Online application
Moodle
When assessment will be used
1. Initial test following attendance of
‘SLMS Intro to IG’
2. Annual Refresher
Number of questions
15
Randomly generated from a bank of at
least 45 questions
Question types
MCQ
Pass mark
80% (12/15)
Attempts allowed
5 attempts to gain a pass; otherwise reattend SLMS Intro to IG training event
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 9 of 11 Appendix 3
How to complete Information Governance Training using the online NHS
Information Governance Training Tool
A - Users with a password
1) Go to the IG Training Tool
2) If you are already registered login using your email address and password.
3) Click on ‘Your profile’ tab and read through your details to ensure correct, click on
‘Update profile’ bottom right of page to save any changes
4) Click on the ‘Learning Tools’ tab
5) Click on ‘Show all modules’ button
6) Under the ‘Information Governance and IG Management’ section, select the
‘Introduction to Information Governance’ module (Note: There are other introductory
modules for aimed at specific professionals – do not select these!)
7) Complete the ‘Assessment’ questions
8) Save and print off the certificate when you have passed.
B - Staff with no password
1) Go to the IG Training Tool
2) To check if you are already registered, click on ‘Reset my password’
3) Your user name is your email address
4) If you are already registered it will ask you to select a security question and
provide the answer
5) If you successfully answer the question it will allow you to reset your password
6) Login and follow the instructions in ‘A’ above from no. 3.
C - Staff not registered
1) Go to the IG Training Tool
2) Click on ‘Register Now’
3) In the ‘Organisational search’ box start typing ‘University College London’
4) A box will provide with selection to choose from, select ‘University College
London (EE133902)
5) Click ‘Next’ and complete the next few pages with your details and set a password
6) The last screen will inform you have successfully registered
7) An email will be sent to you to confirm your details
8) Login and follow the instructions in ‘A’ above from no. 3.
Please contact the SLMS Information Governance Training and Awareness service
for further assistance (Email: pid.slms@ucl.ac.uk)
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 10 of 11 Appendix 4
Recognised IG training accepted in lieu of SLMS training
1. HSCIC IG Training Tool ‘Introduction to Information Governance’ certificate
issued from another organisation confirming pass mark within the past 12
months
2. Scottish Health Informatics Programme (SHIP) Information Governance
online training course certificate confirming pass mark within validity of the
certification
SLMS-­‐IG16 Training Needs Analysis v2.0 Page 11 of 11 
Download