If identifiable NHS data are used in your research, you must take care to follow your NHS Trust’s information governance policies and procedures, especially those concerned with ICT security and information risk.
If you do not have, and cannot obtain, research subjects’ consent to use their data in your research, you will need to apply for permission to acquire the data via section 251 of the NHS Act 2006.
Identifiable data held by NHS Trusts may not be:
- held outside Trust systems without the written approval of your Trust’s Information Governance Manager and / or Caldicott Guardian
- copied to portable devices, unless approved or supplied by the Trust’s IM&T / information governance function, using approved encryption software and devices
- stored on PC hard drives (the ‘C’ drive) and shared drives (the 'S' drive)
- transmitted by email except within nhsmail
- stored with ‘cloud’ providers
See additional guidance for Information Governance for obtaining Health & Social Care (HSCIC) data.