IntroductionThe National Data Opt-Out Service Programme has been established to ensure that a mechanism is developed and available for Health and Social Care organisations to use that will enable a Patient’s preference to be honoured accordingly, e.g. if a Patient’s preference is to opt-out then their data is to be withheld from being shared from appropriate disclosures – this is known as the ‘Upholding’ of an opt-out. Compliance, and Assurance and TestingAt a high-level, Compliance, Assurance and Testing of the National Data Opt-Out will align with the following steps: The NDOP Service Onboarding Team will provide Suppliers with the necessary information and materials to enable them to determine the feasibility of developing a technical product. This can be done with a combination of face to face and online sessions and by self-serving content from the Internet The NDOP Service Onboarding Process flow is available
Suppliers are prioritised for go live by approved process employed by the NDOP Service Onboarding Team The NDOP Service Onboarding Lead will manage access to Path to live (PTL) environments Whilst connected to the INT environment, the Supplier will be expected to execute their own tests. The testing may be used as evidence to support the mitigation of risks identified in the Risk Log. Alternatively, SA may request tailored evidence in order to support their assurance activities
In parallel the ‘Supplier & Product information’ SCAL tab and Connecting Systems Risk Log will be completed by the Supplier. If the Supplier has an existing SCAL then this would be sent to them to ensure the details are correct. The NDOP conformance tab would be inserted to the existing SCAL SCAL completion and sign-off: In parallel with development and testing / technical conformance the Supplier will provide Supplier & Product information and all Service-specific sections in the SCAL The contents of the SCAL (as provided by the Supplier) will be reviewed by the Authority stakeholders (co-ordinated by the Onboarding Lead) and any exceptions that are flagged e.g., ambiguous or incomplete Supplier responses to any requirements or questions, will be annotated and returned to the Supplier to resolve
Once the SCAL is signed off by the NDOP Service Onboarding Lead, the Supplier will be sent the legal document (Connection Agreement) for signature. This always involves the Supplier commitment to sharing the EUO AUP with all EUOs The Supplier is now ready for a live deployment to a limited number of sites (known as First of Type), which will be managed by the NDOP Service Onboarding Lead with Live Services (for ‘release management’), an exception to this is GPIT NMEs, see note below The Deployment Verification Criteria (DVC) for NDOP is: Stable running for a minimum of 14 days At least 1 report applying NDOP has been produced during DVP
Upon agreement that DVC has been met, the Supplier is then permitted to move to full rollout Note: New Market Entrants Foundation Suppliers will not be able to move to live service until the full foundation Solution has been assured. This will be managed by the Suppliers assigned GPITF delivery lead. For further information or to onboard to National Data Opt Out, please contact liveservices.operations@nhs.net At a high-level, Compliance, Assurance and Testing of the National Data Opt-Out will align with the following steps:
A GP System Supplier will provide NHS Digital Solution Assurance with their full list of data extractions/ data disseminations impacted for NDOP, for reference.
A GP System Supplier will provide NHS Digital Solution Assurance with their detailed user stories and their associated acceptance criteria, for each NDOP requirements in scope, for reference and any feedback.
A GP System Supplier will provide NHS Digital Solution Assurance with their test cases against each of their user stories and the pass/fail test results against each test case. Evidence of associated test criteria for supplier test cases may be additionally requested by NHS Digital Solution Assurance.
A GP System Supplier Testing to include but not limited to:
Retrieval and upholding of Patient National Data Opt-Out preference for a single Patient data dissemination(s)
Retrieval and upholding of Patient National Data Opt-Out preference for multiple Patients data dissemination(s)
Patient changes their National Data Opt-Out choice and its’ effect on data dissemination(s) from the GP System
Testing that any Type 1 opt-out preferences recorded in the GP system for Patients, continue to be respected
Testing that the GP system is able to report with the required report data attributes on whether Patient data was included or removed from a dataset along with the reason for inclusion/exclusion
Audit logging for retrieval of Patient’s National Data Opt-Out preference
NHS Digital Solutions Assurance to sample a set of Supplier test cases for witness testing in a witness test session lasting not exceeding more than one day
FOT (First of Type) DevMAC to be awarded to the GP System Supplier at the end of the successful assurance
FRA (Full Rollout Approval) DevMAC post successful FOT
RequirementsNational Data Opt-Out applies to all in-scope data from GP systems including any exports, extracts, releases, disseminations and disclosures from GP systems as defined by National Data Opt-Outs Operational Policy. Supplier Solutions need to retrieve the National Data Opt-Out Status before using or disclosing data, which can be done over Message Exchange for Social Care and Health (MESH). Technical information below describes, how to access and use MESH to check for national data opt-outs: Check for National Data Opt-outs Service DCB3058 Compliance with National Data Opt-Outs contains Outs contains further information on the Standard and information on the legal, strategic and policy context behind the requirements. The final set of National Data Opt-Out requirements, v2.0 published April 2019, can be accessed below: View file |
---|
name | NDOP GP IT Change requirements v2.0 29Apr2019.docx |
---|
|
|