DSfC - NHS Gloucestershire CCG - Comm
NHS Gloucestershire ICB · Sub ICB Location
Listed under NHS Gloucestershire Integrated Care Board.
Expired The latest version ended on 15 January 2023. The September 2026 register still lists the agreement, but its term has passed.
- Reference
- DARS-NIC-343042-X5T7Y
- Latest version
- v0.4
- Term of latest version
- 16 January 2020 to 15 January 2023
- Start date
- 16 January 2020
- Data controller
- Sole Data Controller
- Commercial purposes
- No
- Sublicensing
- No
- Files released to date
- 0
Why the data was released
Objective for processing
Commissioning
To use pseudonymised data to provide intelligence to support the commissioning of health services. The data (containing both clinical and financial information) is analysed so that health care provision can be planned to support the needs of the population within the CCG area.
The CCGs commission services from a range of providers covering a wide array of services. Each of the data flow categories requested supports the commissioned activity of one or more providers.
The following pseudonymised datasets are required to provide intelligence to support commissioning of health services:
- Local Provider Flows
o Acute
o Ambulance
o Community
o Demand for Service
o Diagnostic Service
o Emergency Care
o Experience, Quality and Outcomes
o Mental Health
o Other Not Elsewhere Classified
o Population Data
o Primary Care Services
o Public Health Screening
The pseudonymised data is required to for the following purposes:
- Population health management:
- Understanding the interdependency of care services
- Targeting care more effectively
- Using value as the redesign principle
- Data Quality and Validation - allowing data quality checks on the submitted data
- Thoroughly investigating the needs of the population, to ensure the right services are available for individuals when and where they need them
- Understanding cohorts of residents who are at risk of becoming users of some of the more expensive services, to better understand and manage those needs
- Monitoring population health and care interactions to understand where people may slip through the net, or where the provision of care may be being duplicated
- Modelling activity across all data sets to understand how services interact with each other, and to understand how changes in one service may affect flows through another
- Service redesign
- Health Needs Assessment - Identification of underlying disease prevalence within the local population
- Patient stratification and predictive modelling - to highlight patients at risk of requiring hospital admission and other avoidable factors such as risk of falls, computed using algorithms executed against linked de-identified data, and identification of future service delivery models
The pseudonymised data is required to ensure that analysis of health care provision can be completed to support the needs of the health profile of the population within the CCG area based on the full analysis of multiple pseudonymised datasets.
Processing for commissioning will be conducted by South, Central and West Commissioning Support Unit and Optum Health Solutions
This application allows the linkage of these data sets to the National datasets (Pseudonymised SUS+, Mental Health data (MHSDS, MHMDS, MHLDDS), Maternity data (MSDS), Improving Access to Psychological Therapies data (IAPT), Child and Young People’s Health data (CYPHS), Community Services Data Set (CSDS), Diagnostic Imaging data (DIDS), National Cancer Waiting Times Monitoring Data Set (CWT), Civil Registries Data (CRD) (Births and Deaths), National Diabetes Audit (NDA) and Patient Reported Outcome Measures (PROMs)) the CCG receives on DARS-NIC-343158-Z2L4D. The same pseudo code will be applied by the DSCRO in order to enable this linkage.
Processing activities
PROCESSING CONDITIONS:
Data must only be used for the purposes stipulated within this Data Sharing Agreement. Any additional disclosure /
publication will require further approval from NHS Digital.
Data Processors must only act upon specific instructions from the Data Controller.
Data can only be stored at the addresses listed under storage addresses.
All access to data is managed under Role-Based Access Controls. Users can only access data authorised by their role and the tasks that they are required to undertake.
Patient level data will only be linked to datatsets specifically detailed within this Data Sharing Agreement and those listed in DARS agreement DARS-NIC-343158-Z2L4D
Data released will only be shared with those parties listed and will only be used for the purposes laid out in the application/agreement.
NHS Digital reminds all organisations party to this agreement of the need to comply with the Data Sharing Framework Contract requirements, including those regarding the use (and purposes of that use) by "Personnel" (as defined within the Data Sharing Framework Contract ie: employees, agents and contractors of the Data Recipient who may have access to that data)
ONWARD SHARING:
Patient level data will not be shared outside of the CCG unless it is for the purpose of Direct Care, where it may be shared only with those health professionals who have a legitimate relationship with the patient and a legitimate reason to access the data.Aggregated reports only with small number suppression can be shared externally as set out within NHS Digital guidance applicable to each data set.
SEGREGATION:
Where the Data Processor and/or the Data Controller hold both identifiable and pseudonymised data, the data will be held separately so data cannot be linked.
Where the Data Processor and/or the Data Controller hold identifiable data with opt outs applied and identifiable data with opt outs not applied, the data will be held separately so data cannot be linked.
All access to data is auditable by NHS Digital.
DATA MINIMISATION:
Data Minimisation in relation to the data sets listed within the application are listed below. This also includes the purpose
on which they would be applied -
For the purpose of Commissioning:
- Patients who are normally registered and/or resident within the NHS Gloucestershire CCG region (including historical
activity where the patient was previously registered or resident in another commissioner).
and/or
- Patients treated by a provider where NHS Gloucestershire CCG is the host/co-ordinating commissioner and/or has the primary responsibility for the provider services in the local health economy - this is only for commissioning and relates to both national and local flows.
and/or
- Activity identified by the provider and recorded as such within national systems (such as SUS+) as for the attention of Gloucestershire CCG - this is only for commissioning and relates to both national and local flows.
University Hospitals Bristol NHS Foundation Trust do not access data held under this agreement as they only supply the building. Therefore, any access to the data held under this agreement would be considered a breach of the agreement. This includes granting of access to the database[s] containing the data.
Black Box Software
- The Black Box is a software process with very limited access, restricted to only those who administer it.
- It is a set of logic that is hidden from users. It generates a re-pseudonymised output from the data that users enter.
- The purpose of the Black Box is to map the data such that the resulting pseudonymisation is the same as that used at the DSCRO.
- The Black Box works by calling upon a mapping table from the DSCRO and re-pseudonymising by switching the
pseudonym. No data is persisted in the Black Box.
The Black Box is held within a private part of South Central and West Commissioning Support Unit secure network and physically located at the storage address within the DARS application/agreement with the same underlying security controls.
DATA LINKAGE
This DARS application is linked in association with the DARS application NIC-343158-Z2L4D and therefore the same pseudo key to be applied to all data releases in both applications
The Data Services for Commissioners Regional Office (DSCRO) obtains the following data sets:
1. Local Provider Flows (received directly from providers)
a. Acute
b. Ambulance
c. Community
d. Demand for Service
e. Diagnostic Service
f. Emergency Care
g. Experience, Quality and Outcomes
h. Mental Health
i. Other Not Elsewhere Classified
j. Population Data
k. Primary Care Services
l. Public Health Screening
Data quality management and pseudonymisation is completed within the DSCRO and is then disseminated as follows:
Data Processor - South, Central and West Commissioning Support Unit
1. Local Provider data only is held until points 2-8 are completed.
2. South, Central and West Commissioning Support Unit receives GP data (See GP Data section below for how this is received)
3. South, Central and West Commissioning Support Unit also receive a flow of social care data. (See Social Care Data section below for how this is received)
4. Once the pseudonymised GP data and social care data is received, South, Central and West Commissioning Support Unit make a request to the DSCRO.
5. The DSCRO check the dates of the key generation.
6. The DSCRO then send a mapping table to South, Central and West Commissioning Support Unit
7. South, Central and West Commissioning Support Unit then overwrite the organisation specific keys with the DSCRO key.
8. The mapping table is then deleted.
9. The DSCRO pass the local provider data securely to South, Central and West Commissioning Support Unit for the addition of derived fields.
10. South, Central and West Commissioning Support Unit then pass the data to the CCG.
11. GP and Social care data is then linked to the data sets listed within point 9. Data is also linked with Pseudonymised SUS+, Mental Health data (MHSDS, MHMDS, MHLDDS), Maternity data (MSDS), Improving Access to Psychological Therapies data (IAPT), Child and Young People’s Health data (CYPHS), Community Services Data Set (CSDS), Diagnostic Imaging data (DIDS), National Cancer Waiting Times Monitoring Data Set (CWT), Civil Registries Data (CRD) (Births and Deaths), National Diabetes Audit (NDA) and Patient Reported Outcome Measures (PROMs) received on application DARS-NIC-343158-Z2L4D
12. The CCG analyse the data to:
a. See patient journeys for pathways or service design, re-design and de-commissioning.
b. Check recorded activity against contracts or invoices and facilitate discussions with providers.
c. Undertake population health management
d. Undertake data quality and validation checks
e. Thoroughly investigate the needs of the population
f. Understand cohorts of residents who are at risk
g. Conduct Health Needs Assessments
13. The CCG pass Pseudonymised SUS, Local Provider Data, GP Primary Care data and Social Care data to Data Processor 4
- Optum Health Solutions (UK) Ltd.
14. Optum Health Solutions (UK) Ltd analyse the data and pass the data to the CCG.
15. Aggregation of required data for CCG management use will be completed by South, Central and West Commissioning
Support Unit as instructed by the CCG.
16. Patient level data will not be shared outside of the CCG and will only be shared within the CCG on a need to know basis, as per the purposes stipulated within the Data Sharing Agreement. External aggregated reports only with small number suppression can be shared as set out within NHS Digital guidance applicable to each data set.
GP DATA
GP Data is received as follows
- Identifiable GP data is submitted to South Central and West Commissioning Support Unit.
- The identifiable data lands in a ring-fenced area for GP data only.
- The GP data is pseudonymised using a pseudonymisation tool, different to that used by the DSCRO.
- There is a Data Processing Agreement in place between the GP and South Central and West Commissioning Support Unit. A specific named individual within South Central and West Commissioning Support Unit acts on behalf of the GP.
- This individual has access to a black box. The pseudonymised data is passed through the black box process where the pseudonymisation is mapped to the pseudonymisation used by the DSCRO.
- Once mapped, the data is passed into South Central and West Commissioning Support, but before South Central and West Commissioning Support Unit will receive the data from the ring-fenced area, they require confirmation that the identifiable data has been deleted.
- South Central and West Commissioning Support Unit are then sent the pseudonymised GP data with the pseudo
algorithm specific to them.
SOCIAL CARE DATA
Social Care data is received in one of the following 2 ways:
- Pseudonymised:
- Social Care data is pseudonymised within the provider using a pseudonymisation tool, different to that used by the DSCRO. The provider requests a pseudonymisation key from the DSCRO. The key can only be used once. The key is specific to the Local Authority and to that specific date.
- The pseudonymised data lands in a ring-fenced area for social care data only within South Central and West
Commissioning Support Unit.
- There is a Data Processing Agreement in place between the Provider and South Central and West Commissioning Support Unit. A specific named individual within South Central and West Commissioning Support Unit acts on behalf of the Provider.
- This individual has access to a black box. The pseudonymised data is passed through the black box process where the pseudonymisation is mapped to the pseudonymisation used by the DSCRO.
- The data is then passed into the non-ring fenced area with the pseudo algorithm specific to them.
- Identifiable:
- Identifiable social care data is submitted to South Central and West Commissioning Support Unit.
- The identifiable data lands in a ring-fenced area for social care data only within South Central and West Commissioning Support Unit.
- The social care data is pseudonymised using a pseudonymisation tool, different to that used by the DSCRO.
- There is a Data Processing Agreement in place between the Local Authority and South Central and West Commissioning Support Unit. A specific named individual within South Central and West Commissioning Support Unit acts on behalf of the provider.
- This individual has access to a black box. The pseudonymised data is passed through the black box process where the pseudonymisation is mapped to the pseudonymisation used by the DSCRO.
- Once mapped, the data is passed into South Central and West Commissioning Support, but before South Central and West Commissioning Support Unit will receive the data from the ring-fenced area, they require confirmation that the identifiable data has been deleted.
- South Central and West Commissioning Support Unit are then sent the pseudonymised social care data with the pseudo algorithm specific to them.
Commissioning - Data Processor: Optum Health Solutions (UK) Ltd
1. Local Provider Data, GP Primary Care data and Social Care data is securely transferred from Gloucestershire CCG to Optum Health Solutions (UK) Ltd. The data is decoupled from the other national datasets and sent as individual data flows
2. Optum Health Solutions (UK) Ltd provide analysis to:
- Whole population segmentation to assess population health needs
- Prospective risk scoring for individuals to indicate the likelihood of future adverse events
- Predictive modelling to determine individuals at risk and an understanding of the drivers of risk
- Longitudinal analysis of intersegmental drift identifying individuals who move between complexity classifications and the drivers of these transitions
- The production of individual-level theographs to identify gaps in care
3. Allowed linkage is between the datasets contained within point (1) above and pseudonymised SUS+ data received from application DARS-NIC-343158-Z2L4D. GP and Social Care datasets are needed for the processing carried out by Optum to enhance the population health analytics beyond SUS and LPF's which contain only secondary care activity
4. Optum Health Solutions (UK) Ltd then pass the processed, pseudonymised and linked data to the CCG.
5. Aggregated of required data for CCG management use will be completed by Optum Health Solutions (UK) Ltd or the CCG as instructed by the CCG.
6. Patient level data will not be shared outside of the CCG and will only be shared within the CCG on a need to know basis, as per the purposes stipulated within the Data Sharing Agreement. External aggregated reports only with small number suppression can be shared as set out within NHS Digital guidance applicable to each data set.
7. Optum Health Solutions (UK) Ltd will only be in receipt of data and only be permitted to act as Data Processors for the period specified in the contract with NHS Gloucestershire CCG
Expected output
COMMISSIONING
1. Commissioner reporting:
a. Summary by provider view - plan & actuals year to date (YTD).
b. Summary by Patient Outcome Data (POD) view - plan & actuals YTD.
c. Summary by provider view - activity & finance variance by POD.
d. Planned care by provider view - activity & finance plan & actuals YTD.
e. Planned care by POD view - activity plan & actuals YTD.
f. Provider reporting.
g. Statutory returns.
h. Statutory returns - monthly activity return.
i. Statutory returns - quarterly activity return.
j. Delayed discharges.
k. Quality & performance referral to treatment reporting.
2. Readmissions analysis.
3. Production of aggregate reports for CCG Business Intelligence.
4. Production of project / programme level dashboards.
5. Monitoring of acute / community / mental health quality matrix.
6. Clinical coding reviews / audits.
7. Budget reporting down to individual GP Practice level.
8. GP Practice level dashboard reports include high flyers.
9. Comparators of CCG performance with similar CCGs as set out by a specific range of care quality and performance measures detailed activity and cost reports
10. Data Quality and Validation measures allowing data quality checks on the submitted data
11. Contract Management and Modelling
12. Patient Stratification, such as:
- Patients at highest risk of admission
- Most expensive patients (top 15%)
- Frail and elderly
- Patients that are currently in hospital
- Patients with most referrals to secondary care
- Patients with most emergency activity
- Patients with most expensive prescriptions
- Patients recently moving from one care setting to another
i. Discharged from hospital
ii. Discharged from community
13. Validation for payment approval, ability to validate that claims are not being made after an individual has died, like Oxygen services.
14. Validation of programs implemented to improve patient pathway e.g. High users unable to validate if the process to help patients find the best support are working or did the patient die.
15. Clinical - understand reasons why patients are dying, what additional support services can be put in to support.
16. Understanding where patient are dying e.g. are patients dying at hospitals due to hospices closing due to Local
authorities withdrawing support, or is there a problem at a particular trust.
17. Removal of patients from Risk Stratification reports.
18. Re births provide a one stop shop of information, Births are recorded in multiple sources covering hospital and home births, a chance to overlook activity.
Expected measurable benefits
COMMISSIONING
1. Supporting Quality Innovation Productivity and Prevention (QIPP) to review demand management, integrated
care and pathways.
a. Analysis to support full business cases.
b. Develop business models.
c. Monitor In year projects.
2. Supporting Joint Strategic Needs Assessment (JSNA) for specific disease types.
3. Health economic modelling using:
a. Analysis on provider performance against 18 weeks wait targets.
b. Learning from and predicting likely patient pathways for certain conditions, in order to influence early
interventions and other treatments for patients.
c. Analysis of outcome measures for differential treatments, accounting for the full patient pathway.
d. Analysis to understand emergency care and linking A&E and Emergency Urgent Care Flows (EUCC).
4. Commissioning cycle support for grouping and re-costing previous activity.
5. Enables monitoring of:
a. CCG outcome indicators.
b. Financial and Non-financial validation of activity.
c. Successful delivery of integrated care within the CCG.
d. Checking frequent or multiple attendances to improve early intervention and avoid admissions.
e. Case management.
f. Care service planning.
g. Commissioning and performance management.
h. List size verification by GP practices.
i. Understanding the care of patients in nursing homes.
6. Feedback to NHS service providers on data quality at an aggregate and individual record level only on data
initially provided by the service providers.
7. Improved planning by better understanding patient flows through the healthcare system, thus allowing
commissioners to design appropriate pathways to improve patient flow and allowing commissioners to identify
priorities and identify plans to address these.
8. Improved quality of services through reduced emergency readmission's, especially avoidable emergency
admissions. This is achieved through mapping of frequent users of emergency services and early intervention of
appropriate care.
9. Improved access to services by identifying which services may be in demand but have poor access, and from this
identify areas where improvement is required.
10. Potentially reduced premature mortality by more targeted intervention in primary care, which supports the
commissioner to meets its requirement to reduce premature mortality in line with the CCG Outcome Framework.
11. Better understanding of the health of and the variations in health outcomes within the population to help
understand local population characteristics.
12. Better understanding of contract requirements, contract execution, and required services for management of
existing contracts, and to assist with identification and planning of future contracts
13. Insights into patient outcomes, and identification of the possible efficacy of outcomes-based contracting
opportunities.
14. Providing greater understanding of the underlying courses and look to commission improved supportive
networks, this would be ongoing work which would be continually assessed.
15. Insight to understand the numerous factors that play a role in the outcome for both datasets. The linkage will
allow the reporting both prior to, during and after the activity, to provide greater assurance on predictive
outcomes and delivery of best practice.
16. Provision of indicators of health problems, and patterns of risk within the commissioning region.
17. Support of bench-marking for evaluating progress in future years.
Benefits reported so far
Yielded Benefits is not a requirement for new applications.
Datasets on the latest version
Legal basis for provision: Health and Social Care Act 2012 – s261(2)(b)(ii)
| Dataset | Type of data | Sensitivity | Frequency | Confidential data |
|---|---|---|---|---|
| Acute-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Ambulance-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Community-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Demand for Service-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Diagnostic Services-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Emergency Care-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Experience, Quality and Outcomes-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Mental Health-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Other Not Elsewhere Classified (NEC)-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Population Data-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Primary Care Services-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
| Public Health and Screening Services-Local Provider Flows | Anonymised - ICO Code Compliant | Sensitive | Frequent Adhoc Flow | Does not include the flow of confidential data |
Files released
Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.
No files recorded as released under this agreement.
Version history
The register lists each renewal of this agreement as a separate row. This site has 1 version.
DARS-NIC-343042-X5T7Y-v0.4 16 January 2020 to 15 January 2023
- Title
- DSfC - NHS Gloucestershire CCG - Comm
- Commercial
- No
- Sublicensing
- No
- Datasets
- 12
- Files released
- 0
Datasets: Acute-Local Provider Flows; Ambulance-Local Provider Flows; Community-Local Provider Flows; Demand for Service-Local Provider Flows; Diagnostic Services-Local Provider Flows; Emergency Care-Local Provider Flows; Experience, Quality and Outcomes-Local Provider Flows; Mental Health-Local Provider Flows; Other Not Elsewhere Classified (NEC)-Local Provider Flows; Population Data-Local Provider Flows; Primary Care Services-Local Provider Flows; Public Health and Screening Services-Local Provider Flows
Register history
When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds, the earliest of which is July 2021.
-
July 2021 —
already listed in the earliest edition this site holds, so it may be older. 1 version: DARS-NIC-343042-X5T7Y-v0.4
-
October 2022
Succeeded Applicant organisation: NHS Gloucestershire CCG succeeded by NHS Gloucestershire ICB from 1 July 2022, according to NHS ODS. Not counted as a change.Succeeded Data controllers: NHS Gloucestershire CCG succeeded by NHS Gloucestershire ICB from 1 July 2022, according to NHS ODS. Not counted as a change.
-
December 2022
Register-wide edit DARS-NIC-343042-X5T7Y-v0.4 — Datasets: legal basis: “
s261(1) and” taken out. Made to 639 agreements in this edition, so it is reported once, on the changes page, and not counted as an amendment of this agreement. -
March 2023
Amended DARS-NIC-343042-X5T7Y-v0.4
- Processing activities:
reworded
Show the change
[109 paragraphs unchanged] - Longitudinal analysis of intersegmental drift
identifyingidentifying individuals who move between complexity classifications and the drivers of these transitions [6 paragraphs unchanged] - Expected measurable benefits:
reworded
Show the change
[24 paragraphs unchanged] 6. Feedback to NHS service providers on data quality at an aggregate and individual record level
onlyonly on data [24 paragraphs unchanged]
- Processing activities:
reworded
"Amended in place" means NHS England changed the record without issuing a new version number. The register publishes no changelog for those edits; this site infers them by comparing editions. An edit is attributed to the edition it first appears in, not to the date it was made.
Cite this page
NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-343042-X5T7Y, “DSfC - NHS Gloucestershire CCG - Comm”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-343042-x5t7y/ (accessed [date]).
This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.
Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-343042-X5T7Y to see the original rows.