NMH

NMH Annual Report 2024

Issue link: http://digitaleditions.uberflip.com/i/1535709

Contents of this Issue

Navigation

Page 194 of 275

193 NMH | 2024 193 Administration Compliance The National Maternity Hospital is a Section 38 hospital and therefore the regulatory environment is complex. Annual compliance reporting is required both to our main funder, the HSE, as well as to the Charities Regulator among other authorities. Compliance and governance are essential elements of the dealings of the Executive Committee (The Board) of the Hospital. Together with staff members, the sub-committees are following compliance and governance issues closely and reporting on a regular basis to the Executive Committee making sure that we are compliant with all relevant rules and regulations. For the fourth year, we reported our compliance in relation to the Charities Regulator's Code of Governance. In addition, corporate governance procedures, including Board arrangements and responsibilities, are mapped against the Code of Practice for the Governance of State Bodies and the HSE Code of Governance. Members of the Board are invited annually to participate in refresher seminars on corporate governance issues. A report of the external review of governance procedures was published during the year. In an Annual Compliance Statement, we furnish our compliance status to the HSE in areas such as governance, finance, procurement, risk management, taxation and remuneration. We also report our compliance with the provisions of the Service Level Agreement with the HSE (an extensive document covering services of the Hospital contracted to the HSE). Data Protection The Data Protection Officer (DPO) is responsible for implementing and maintaining a Data Protection Management System with a framework for ensuring that the Hospital meets its obligations under the General Data Protection Regulation (GDPR) and associated national legislation. We have Compliance & Data Protection a Data Protection Management System in place that is in compliance with GDPR and our staff are 'data privacy/GDPR' aware with knowledge and understanding of how it affects their day-to-day role as well as the need to ensure that data protection is considered in all our planning. A big project started with the aim of reducing our off-site storage of reports from hospital departments. In relation to this we have also reviewed our retention policy and created a more robust process for sending material off-site. This project will also make us fully compliant with data protection legislation. Starting from scratch a few years ago, our register of data protection contracts and agreements have been established and is now covering all known ones. In addition, a third-party vendor contract register has been put in place to give us full overview of our renewal dates and procurement needs. Policies, Guidelines and Forms are constantly being reviewed and updated. Patient chart requests An individual has the right to access any electronic or manual information that the Hospital holds about them. The Hospital will provide them with a copy of their personal data held by the Hospital on request free of charge within 30 days from the date the request is made. A system is in place to ensure that all requests are actioned, quality checked and sent out within the 30 days' period allowed by the law. The number of requests have been steady over recent years. During the year we responded to more than 1,100 requests, the majority being from patients requesting information directly. We continued our project (From Request to Report) to provide all records digitally to requesters which is a safer and more cost-effective way of handling the requests. The shift to digital has been very well received by patients/ clients. Training Staff training is a crucial part of protecting data privacy and is required under GDPR. Data protection training is mandatory for all staff bi-annually, in addition to data protection training for all incoming staff. The data protection training is done in person or online. In addition, awareness-raising of data protection is an integral part of the induction scheme. We regularly send out notes to staff on specific topics to constantly maintain and improve awareness on data protection and confidentiality matters. Breaches Most of the internal data breaches reported are as a result of increased awareness of what constitutes data breaches and the various data protection courses available to staff. NMH staff are well aware of the need for transparency and the need to ensure due process in reporting and in dealing with data breaches. There is an internal on-line system to report data breaches to make it easy and transparent. Last year we had 32 reported data breaches in the Hospital, which is a drop from previous year by 10 breaches. Significant breaches are reported to the Data Protection Commission and reviewed and if need be, internal practices are improved to minimise future breaches. Carl Alfvag, Compliance and Operations Manager / Data Protection Officer.

Articles in this issue

view archives of NMH - NMH Annual Report 2024