NMH

NMH Annual Report 2020

Issue link: http://digitaleditions.uberflip.com/i/1388210

Contents of this Issue

Navigation

Page 182 of 255

181 Administration NMH Annual Rep t | 2020 Penny Mitchell, Midwife. Compliance For the National Maternity Hospital, being a Section 38 hospital, the regulatory environment has increased over the last few years. Annual compliance reporting is required both to our main funder, the HSE, as well as to the Charities Regulator among other authorities. Governance issues are essential elements for the Executive Committee (Board) of the Hospital. Together with staff members the sub-committees are following compliance issues closely and reporting on a regular basis to the Executive Committee making sure that we are compliant with all relevant regulations. The governance arrangements, including Board arrangements and responsibilities, are in compliance with the HSE Code of Governance and the Core Standards for Governance. In addition all the members of the Executive Committee have participated in refresher seminars on governance issues. In an Annual Compliance Statement, we furnish our compliance status to the HSE in areas such as governance, finance, procurement, risk management, taxation and remuneration. Since October, we also have to report to the Charities Regulator our compliance with the Charities Governance Code. Data Protection The Data Protection department is responsible for implementing and maintaining a Data Protection Management System (DPMS) with a framework for ensuring that the Hospital meets its obligations under the General Data Protection Regulation (GDPR) and all associated legislation. We have a Data Protection Management System in place that is in compliance with GDPR and our staff are 'data privacy/GDPR' aware with knowledge and understanding of how it affects their day-to-day role as well as the need to ensure that data protection is considered in all our planning. Subject Access Request (SAR) An individual has the right to access any electronic or manual information that the NMH holds about them. The hospital will provide them with a copy of their personal data held by the hospital on request free of charge within 30 days from the date the request is made. A system is in place to ensure that all SARs are actioned, quality checked and sent out within the 30 days' period allowed by the law. There has been a significant increase in the number of SARs received over the last two years with over 50% of requests Compliance & Data Protection coming from solicitors on behalf of their clients. Less than 50% of requests are now coming directly from data subjects or their relatives. Training Staff training is a crucial part of protecting data privacy and is required under Article 39 of the GDPR. Data protection training is part of the mandatory training for all staff, this is in addition to data protection training for all incoming staff during induction. Staff are also encouraged to take the HSELand online training provided by the HSE. The data protection mandatory training, data protection induction training and the online data protection training on HSELand are all measures put in place to help us comply with the law. Breaches Most of the data breaches are as a result of increased awareness of what constitutes data breaches and the various data protection courses available to staff. NMH staff are more than aware of the need for transparency and the need to ensure due process in reporting and in dealing with data breaches. There is an internal on-line system to report data breaches to make it easy and transparent.

Articles in this issue

view archives of NMH - NMH Annual Report 2020