CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
Care Quality Commission (CQC) · Agency/Public Body
In term In term in the September 2026 edition: the latest version runs to 12 September 2026.
- Reference
- DARS-NIC-359603-D2Q6M
- Current version
- v15.2
- Term of current version
- 20 June 2025 to 12 September 2026
- Start date
- Before 1 June 2019
- Data controller
- Sole Data Controller
- Commercial purposes
- No
- Sublicensing
- No
- Files released to date
- 1,918
Why the data was released
Objective for processing
Care Quality Commission (CQC) has a long-standing relationship with NHS England to access data that is critical to its regulatory oversight of health and care providers. CQC’s remit is to make sure health and adult social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve.
Access to these data help to ensure CQC can make use of its wide set of powers to protect people who use regulated services from harm and the risk of harm, and to ensure they receive health and social care services of an appropriate standard. These powers also hold registered providers and managers to account for failures in how the service is provided. CQC's enforcement policy sets out CQC's approach to taking action where CQC identify poor care, or where registered providers and managers do not meet the standards required in the regulations.
In CQC's monitoring role, it prioritises the care and welfare of patients. People who use services should experience effective, safe and appropriate care, treatment and support that meets their needs and protects their rights.
CQC uses these data to help determine five core questions about services:
- Are they safe?
- Are they effective?
- Are they caring?
- Are they well-led?
- Are they responsive to people’s needs?
The following NHS England Data will be accessed:
> Hospital Episode Statistics Admitted Patient Care (HES APC)
> HES Outpatients (OP)
> HES Critical Care (CC)
> HES Accident and Emergency (A&E) and Emergency Care Data Set (ECDS)
> Mental Health Services Data Set (MHSDS) and Mental Health and Learning Disabilities Dataset (MHLDDS)
> Community Services Data Set (CSDS)
> Maternity Services Data Set (MSDS)
> Civil Registration of Deaths
CQC use these data to;
(i) populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections)
(ii) to inform judgements about the level of quality in services within CQCs Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation
(iii) support CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act
(iv) Use in thematic reviews and national reporting; for example, the Annual State of Care report and
(v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
The level of data will be:
> Identifiable
Local patient identifier is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. Local patient identifier is used as the Token Person ID is not known to the trust. With this exception, no record level data is released to third parties.
The patient's postcode is used for assigning data to new Local Authority /Integrated Care Systems boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
The Health and Social Care Act 2008 imposes notifications requirements for NHS bodies, which are managed and processed by CQC, which has a duty under the Mental Health Act 1983 (MHA) to monitor how services exercise their powers and discharge their duties when patients are detained in hospital, subject to community treatment orders or guardianship.
Among these are
• Reg 16: Death of a person who uses the service
• Reg 17: Deaths of people detained or liable to be detained under the Mental Health Act
The availability of Date of Death allows CQC to verify whether the team have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
• Reg 18: Other incidents: Admission of a child or young person to an adult psychiatric ward or unit
Date of Birth allows CQC to know whether a child or young person was admitted to an adult ward and produce an indicator. It will also inform analysis of interventions related to age.
CQC's use of identifying data is subject to CQC's statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’) clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions
The Data will be minimised as follows:
> Data required to cover activity within the whole of England.
> The data subjects will cover all individuals who have undergone treatment in these pathways.
> Limited to data between 2014/15 to latest available. Monthly latest available extracts are required to ensure CQC have access to the most up-to-date data for ongoing analyses and oversight. This is particularly important in understanding an organisation's most recent performance. Historic data from 2014/15 is required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
For record-level data, CQC will process these data lawfully under UK GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77.
As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018.
For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under the enactment set out in sections 76 and 77.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS England (previously NHS Digital/Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment has been reviewed and completed by CQC.
Microsoft Limited is a processor acting under the instructions of CQC. Microsoft Limited role is limited to cloud storage (Microsoft Azure).
Data will be accessed by:
• Substantive employees of CQC
• Non-substantive employees (Contractors)
CQC must maintain records in a single location that cover the following details of each individual given access under a contract:
o Their substantive employer;
o Their role in respect of the purpose for the processing specified in the DSA;
o The start date and end date of the duration in which the Data will be accessed by the individual under an honorary contract;
o The necessity for the Data to be accessed by the person(s) holding an honorary contract, instead of a substantive employee of an organisation named as controller or a processor in this DSA;
o Confirmation that an appropriate contract is in place which follows the relevant guidance and is countersigned by the substantive employer of the contract holder.
Processing activities
No data will flow to NHS England for the purposes of this Data Sharing Agreement (DSA).
NHS England will provide the relevant records from the HES, ECDS, Civil Registration of Deaths, Mental health, CSDS and MSDS datasets to CQC.
The Data will contain directly identifying data items including Postcode and Local Patient Identifier which are required for assigning data to new LA/ICS boundaries and for identifying other geography-related data and to identify to a trust examples of their own patients whose care appears problematical.
The Data will not be transferred to any other location.
The Data will be stored on servers at CQC.
CQC stores Data on the Cloud provided by Microsoft Limited.
The Data will be accessed by authorised personnel via remote access.
CQC must confirm and provide evidence upon audit by NHS England that access via any remote device complies with the data security obligations within this DSA and the Data Sharing Framework Contract.
For remote access:
- Remote access will only be from secure locations situated within the territory of use (as further restricted elsewhere within the DSA if so done) stated within this DSA;
- Access controls granting users the minimum level of access required are in place;
- Remote access is only via secure connections (e.g., VPNs or secure protocols) to protect data;
- Multifactor authentication (MFA) is required for remote access;
- Device security, including up-to-date software and operating systems, antivirus software, and enabled firewalls are utilised for the remote access;
- All remote access is undertaken within the scope of the organisation’s DSPT (or other security arrangements as per this DSA) and complies with the organisation’s remote access policy.
The above applies in addition to any condition set out elsewhere within the DSA (e.g. who may carry out processing, and for what purpose).
Remote processing will be from secure locations within England/Wales. The data will not leave England/Wales at any time.
Access is restricted to employees, or contractors of CQC.
All personnel accessing the Data have been appropriately trained in data protection and confidentiality.
The Data will not be linked with any other data.
There will be no requirement and no attempt to reidentify individuals when using the Data, with the sole exception of trusts using Local Patient Identifier to identify patients whose care appears problematic where strictly necessary.
Access to the full, underlying datasets is restricted to a small team of CQC staff; this is the only team that can access the full identifying data. They analyse the data and provide cuts - pseudonymised at both record and provider level - for statistical packages for use in the Data & Insight Unit only by identified staff. These staff request the bespoke breakdowns from the analytical team.
Aggregated data summarised to organisation level is fed into a data warehouse. This is then used to create CQC’s Data & Insight Unit products as well as supporting ad hoc reporting. Where these outputs may contain small numbers suppressed, access to such outputs are only made available to named individuals within the Technology, Data & Insight directorate.
Suppression methodology for datasets within this Data Sharing Agreement:
Where CQC makes any outputs publicly available (e.g. State of Care, thematic reviews), these outputs will adhere to the current NHS England suppression methods required for the specific dataset(s) used in the production of the output.
CQC also produces outputs associated with its regulatory activities which may be shared internally within CQC or externally with specific care providers (predominantly NHS Trusts) or with specific arms-length bodies partnering CQC such as NHS England (e.g. CQC insight products). In such outputs, applying the full rules on small number suppression may undermine the purpose for sharing the outputs.
For example, CQC produces insight reports for each registered care provider. CQC inspectors would need non-rounded figures in order to sensibly discuss them with the providers. If, because of suppression, CQC’s figures differed to those the provider could produce, it would create an issue of confidence in CQC’s numbers.
However, where data is shared with health and care providers, CQC would be sharing their own data with them so there would be no increased risk to confidentiality through the disclosure and the data would be shared under strict controls, with CQC giving a clear direction that the provider should not publish or otherwise onwardly share the data. If, hypothetically, the provider chose to subsequently share/publish the data contrary to CQC’s direction, the individual trust/provider would be making that decision on its own data.
Where insight reports are subsequently shared with other arms-length bodies (e.g. NHS England), CQC would work with these partners bodies to emphasise they must not be published because of NHS England suppression methodologies.
For any data shared with care providers or arms-length bodies, CQC will adhere to the following measures to limit identifiability of individuals in the data:
In place of the different NHS England suppression methodologies for HES and MHSDS/MSDS, CQC under this Data Sharing Agreement will carry out the below process when dealing with publications for circulation internally within CQC or externally with care providers or arms-length bodies partnering CQC:
> Zero allowed, 1-7 suppressed with '*', no rounding of values
> Percentages will be based on raw data; where low number values can be deduced from denominator, percentages will be suppressed.
CQC will stamp these products to signal that they are not for publication/cannot be published.
Expected output
The expected outputs of the processing will be:
> Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape, additional dashboards and early alerts are expected to become available for inspectors.
> Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Telstra - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS England data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
> Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS England's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
> In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
The outputs will not contain NHS England Data and will only contain aggregated information with small numbers suppressed as appropriate in line with the relevant disclosure rules for the dataset(s) from which the information was derived.
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England.
Expected measurable benefits
HES, MHSDS, ECDS and associated data are used to determine key performance indicators in the CQC insight products. Each indicator is categorised in one of the core domains that, in total, provide a view on the quality of the provision of care. CSDS is undergoing internal review and will be used for the same purposes to generate similar outputs; likewise, MSDS, once the extracts are more readily available.
CQC has a suite of insight products which help the planning and review stages of an inspection that seeks to highlight areas of poor care requiring improvement while also seeking to promote good practice. The products use data (HES and/ or MHSDS as appropriate) both to present an overview of the core business of the trust in terms of activity ʹhelping to determine the specialist requirements of the inspection team - while also including specific metrics (e.g. HES re-admissions as descriptive statistics). MSDS, CSDS and ECDS will be used for the same purposes to generate similar outputs.
HES and civil registration mortality data are used in the outliers programme. Outlier events, such as high mortality or readmission rates may be identified either by CQC's own analyses or by those of Telstra. For both, CQC gathers all available information - including HES analyses, where appropriate, and advice from experts - and presents this to an internal review panel. This panel decides whether or not CQC investigate. When CQC decide to proceed, the data is shared with the trust for them to review and comment upon. One of the review actions a trust may carry out is a case note review. On rare occasions the trust is unable to reconcile HES counts with their local systems. In those cases, CQC may share a small number of values for the local patient identifier (lopatid) with the trust so they can identify patient notes to review. The mortality panels meet monthly while the maternity panels meet every two months. Where outlier concerns are identified, the subsequent contact and engagement with trusts have led to implementation of improvements in process that have had a positive impact on patient care. MSDS will be used to as a core input to the maternity panels as well as to the maternity core service within CQC insight.
HES, MHSDS and associated data are used in analyses for thematic reviews and in the development of new CQC insight indicators; for example, in reviewing quality of access to care across different ethnicities. MSDS, CSDS and ECDS will be used for the same purposes to generate similar outputs.
CQC insight and associated dashboards are regularly updated. Outlier analyses are undertaken on a monthly or two-monthly basis. National reporting is a combination of predominantly annual reports as well as topic-specific reports released on a one-off basis.
Where CQC identifies poor care, or where the standards of registration are not being met, CQC can use its enforcement policy as described above. Such action is targeted to drive improvements or, in extreme cases, protect the public from access to poor quality services.
Monitoring of mortality is the only area where CQC has had to make changes in its use of indicators derived from the requested datasets.
Benefits reported so far
The creation of CQC’s new Data & Insight Unit has started to embed and improve on its previous insight programme and associated dashboards. Core data from this data sharing agreement were used in the production of indicators that align to CQC’s key lines of enquiry for a particular sector (e.g., hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used to inform planning regulatory activity (including to inform inspection planning decisions). The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in Insight products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted, and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
CQC has made extensive use of NHS England data within its insight pre-inspection activity within the hospital/ Mental Health sectors. The core NHS Englnad data acts to highlight any particular concerns (or good practice) that would then be followed up between an inspector and a given organisation or used to determine where an inspection might be focused. The reports provide trust-level indicators and national comparisons from the most readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality-of-care provision and examples of good practice that other organisations could adopt. The NHS England data are therefore critical in this process for driving up the quality-of-care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS England featured in the 2020/21 State of Care report. This year, it highlighted the impact of the pandemic as part of its design to provide a high-level commentary on year-on-year changes to care provision within England.
Over 2021/22 CQC issued 100 letters of intent to Hospital services across England where CQC identified poor care or where the standards of registration were not being met. However, these levels were likely to be lower than for other years, as this period covers the pandemic during which CQC reduced the number of inspections to a minimum level across Hospital services.
CQC continues to monitor a suite of indicators covering secondary health acute services.
In addition, CQC has a suite of indicators relating to safety and quality in mental health services for which it uses the Mental health services dataset.
CQC is also developing analytical methodologies to present data at core service level for Mental health services.
Core services are the unit of rating for CQC's assessments of mental health services, and our objective is to present more granular analysis from MHSDS (and other sources) mapped to these services.
Thematic reviews provide in-depth analyses of chosen topics to inform CQC staff, clinicians and the public about that service/area of care while also highlighting areas for improvement/best practice; working with inspector colleagues, themed inspections allow CQC to develop recommendations for making improvements in the delivery of care. These recommendations are then incorporated into future inspections to encourage continual improvement. ‘Restraint, segregation, and seclusion’, ‘Do not attempt CPR decisions’, and ‘Provider collaboration’ are examples of recent thematic data reviews/themed inspections that helped/ are helping to raise specific questions on the monitoring and provision of care in these areas with a focus on future improvement.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS England's HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
Datasets on the current version
Legal basis for provision: Health and Social Care Act 2012 - s261(5)(d)
| Dataset | Type of data | Sensitivity | Frequency | Confidential data |
|---|---|---|---|---|
| Civil Registrations of Death - Secondary Care Cut | Identifiable | Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| Community Services Data Set (CSDS) | Identifiable | Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| Emergency Care Data Set (ECDS) | Identifiable | Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| HES-ID to MPS-ID HES Accident and Emergency | Anonymised - ICO Code Compliant | Non-Sensitive | One-Off | Statutory exemption to flow confidential data without consent |
| HES-ID to MPS-ID HES Admitted Patient Care | Anonymised - ICO Code Compliant | Non-Sensitive | One-Off | Statutory exemption to flow confidential data without consent |
| HES-ID to MPS-ID HES Outpatients | Anonymised - ICO Code Compliant | Non-Sensitive | One-Off | Statutory exemption to flow confidential data without consent |
| HES:Civil Registration (Deaths) bridge | Identifiable | Non-Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| Hospital Episode Statistics Accident and Emergency (HES A and E) | Identifiable | Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| Hospital Episode Statistics Admitted Patient Care (HES APC) | Identifiable | Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| Hospital Episode Statistics Critical Care (HES Critical Care) | Identifiable | Non-Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| Hospital Episode Statistics Outpatients (HES OP) | Identifiable | Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| Maternity Services Data Set (MSDS) v1.5 | Identifiable | Sensitive | One-Off | Statutory exemption to flow confidential data without consent |
| Maternity Services Data Set (MSDS) v2 | Identifiable | Non-Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| Mental Health and Learning Disabilities Data Set (MHLDDS) | Identifiable | Non-Sensitive | One-Off | Statutory exemption to flow confidential data without consent |
| Mental Health Services Data Set (MHSDS) | Identifiable | Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
| Mental Health Services Data Set (MHSDS) v5.0 | Identifiable | Sensitive | Ongoing | Statutory exemption to flow confidential data without consent |
Files released
Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.
Patient opt-outs were not applied to any of the 1,918 files released under this agreement, across every version. About opt-outs
Files released against version 15.2 of this agreement, summarised by dataset.
| Dataset | Files | First released | Last released | Opt-outs applied |
|---|---|---|---|---|
| Maternity Services Data Set (MSDS) v2 | 120 | September 2025 | March 2026 | No |
| Community Services Data Set (CSDS) | 104 | August 2025 | August 2026 | No |
| Civil Registrations of Death - Secondary Care Cut | 14 | August 2025 | August 2026 | No |
| Hospital Episode Statistics Admitted Patient Care (HES APC) | 14 | August 2025 | August 2026 | No |
| Hospital Episode Statistics Critical Care (HES Critical Care) | 14 | August 2025 | August 2026 | No |
| Hospital Episode Statistics Outpatients (HES OP) | 14 | August 2025 | August 2026 | No |
| Emergency Care Data Set (ECDS) | 13 | August 2025 | August 2026 | No |
Version history
The register lists each renewal of this agreement as a separate row. This site has 12 versions — earlier versions existed before this site's records begin.
DARS-NIC-359603-D2Q6M-v15.2 20 June 2025 to 12 September 2026
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 16
- Files released
- 293
Datasets: Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES-ID to MPS-ID HES Accident and Emergency; HES-ID to MPS-ID HES Admitted Patient Care; HES-ID to MPS-ID HES Outpatients; HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Maternity Services Data Set (MSDS) v2; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Services Data Set (MHSDS); Mental Health Services Data Set (MHSDS) v5.0
What changed from DARS-NIC-359603-D2Q6M-v14.6
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2025-06-20 |
Datasets: + MSDS (Maternity Services Data Set) v2.0
Objective for processing
Care Quality Commission (CQC)
is requesting
has a long-standing relationship with NHS England to access
data that is critical to its regulatory oversight of health and care
[15 words unchanged]
with safe, effective, compassionate, high-quality care and CQC encourages them to improve.
[54 paragraphs unchanged]
Unchanged: Processing activities, Expected output, Expected measurable benefits, Benefits reported.
DARS-NIC-359603-D2Q6M-v14.6 13 September 2024 to 12 September 2026
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 15
- Files released
- 135
Datasets: Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES-ID to MPS-ID HES Accident and Emergency; HES-ID to MPS-ID HES Admitted Patient Care; HES-ID to MPS-ID HES Outpatients; HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Services Data Set (MHSDS); Mental Health Services Data Set (MHSDS) v5.0
What changed from DARS-NIC-359603-D2Q6M-v13.6
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2024-09-13 | |
| End date | 2026-09-12 |
Objective for processing
Under this Data Sharing Agreement, the
Care Quality Commission (CQC) is requesting
record-level
data that is critical to its regulatory oversight of health and care
[15 words unchanged]
with safe, effective, compassionate, high-quality care and CQC encourages them to improve.
Its role will be expanded to encompass an assessment of quality for Integrated Care Systems (ICSs) and assurance of Local Authorities – in relation to their respected roles for health and adult social care. Its regulatory model is underpinned by a Data & Insight programme that draws together indicators of quality and risk about services. The data directly influence the risk and benchmarking models used to prioritise regulatory activity and inform its judgements of quality in services. The datasets also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act and to deliver national reports to parliament. Processing these data allow CQC to meet this public benefit.
Access to these data help to ensure CQC can make use of
[69 words unchanged]
providers and managers do not meet the standards required in the regulations.
The level of enforcement is dependent on many factors but start at a requirement notice (stipulating a timeframe within which a given improvement must take place) for a less serious breach up to the possible cancellation of services in extreme cases.
For record-level data, CQC will process these data lawfully under UK GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77. As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018. For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under the enactment set out in sections 76 and 77.
In CQC's monitoring role, it prioritises the care and welfare of patients. People who use services should experience effective, safe and appropriate care, treatment and support that meets their needs and protects their rights.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS England (previously NHS Digital/Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
CQC uses these data to help determine five core questions about services:
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment has been reviewed and completed by CQC.
- Are they safe?
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and the legacy Mental Health and Learning Disabilities Dataset, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Monthly extracts ensure CQC have access to the most up-to-date data for ongoing analyses and oversight - particularly important in understanding an organisation's most recent performance. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
- Are they effective?
CQC use these data (i) to populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections) and to inform judgements about the level of quality in services (ii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iii) towards CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; (iv) in thematic reviews and national reporting; for example, the Annual State of Care report and (v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
- Are they caring?
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: 'postcode' and 'local patient identifier'. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. 'Local patient identifier' is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient's postcode is used for assigning data to new LA/ICS boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
- Are they well-led?
CQC continues to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The latest review again focused on requests submitted to the CQC central analytical team. CQC has confirmed that, in the review period, analyses were still conducted on the postcode and local patient identifier fields. In a previous iteration of this agreement (v10) additional MHSDS fields were included in the application. Future analyses using birth date, death date, and unique restrictive intervention incident ID from the MHSDS data set will support work related to mortality and for monitoring Use Of Force Act 2018. Unique restrictive intervention incident ID has been requested to facilitate monitoring of restrictive interventions. The Mental Health Units (Use of Force) Act 2018 CHAPTER 27 makes provision about the oversight and management of the appropriate use of force in relation to people in mental health units; to make provision about the use of body cameras by police officers in the course of duties in relation to people in mental health units; and for connected purposes. CQC's statutory powers under s9(a) allow it to require information about restrictive interventions for the purposes of investigation of deaths and serious injury.
- Are they responsive to people’s needs?
The following NHS England Data will be accessed:
> Hospital Episode Statistics Admitted Patient Care (HES APC)
> HES Outpatients (OP)
> HES Critical Care (CC)
> HES Accident and Emergency (A&E) and Emergency Care Data Set (ECDS)
> Mental Health Services Data Set (MHSDS) and Mental Health and Learning Disabilities Dataset (MHLDDS)
> Community Services Data Set (CSDS)
> Maternity Services Data Set (MSDS)
> Civil Registration of Deaths
CQC use these data to;
(i) populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections)
(ii) to inform judgements about the level of quality in services within CQCs Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation
(iii) support CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act
(iv) Use in thematic reviews and national reporting; for example, the Annual State of Care report and
(v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
The level of data will be:
> Identifiable
Local patient identifier is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. Local patient identifier is used as the Token Person ID is not known to the trust. With this exception, no record level data is released to third parties.
The patient's postcode is used for assigning data to new Local Authority /Integrated Care Systems boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
[4 paragraphs unchanged]
The availability of Date of Death allows
us
CQC
to verify whether the team have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
[1 paragraph unchanged]
Date of Birth allows
us
CQC
to know whether a child or young person was admitted to an adult ward and produce an indicator. It will also inform analysis of interventions related to age.
CQC's use of identifying data is subject to CQC's statutory Code of
[57 words unchanged]
it is necessary to do so to enable CQC to perform CQC’s
functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
functions
CQC is the sole data controller and also processes the data. Now held on Microsoft Azure’s cloud environment, the NHS England data will only be accessed by CQC substantive employees and non-substantive employees (contractors). Where CQC used non-substantive employees (contractors), CQC would insist on confidentiality clauses within contracts and oblige individuals to complete in-house training on data protection and confidentiality. The local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
The Data will be minimised as follows:
> Data required to cover activity within the whole of England.
> The data subjects will cover all individuals who have undergone treatment in these pathways.
> Limited to data between 2014/15 to latest available. Monthly latest available extracts are required to ensure CQC have access to the most up-to-date data for ongoing analyses and oversight. This is particularly important in understanding an organisation's most recent performance. Historic data from 2014/15 is required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
For record-level data, CQC will process these data lawfully under UK GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77.
As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018.
For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under the enactment set out in sections 76 and 77.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS England (previously NHS Digital/Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment has been reviewed and completed by CQC.
Microsoft Limited is a processor acting under the instructions of CQC. Microsoft Limited role is limited to cloud storage (Microsoft Azure).
Data will be accessed by:
• Substantive employees of CQC
• Non-substantive employees (Contractors)
CQC must maintain records in a single location that cover the following details of each individual given access under a contract:
o Their substantive employer;
o Their role in respect of the purpose for the processing specified in the DSA;
o The start date and end date of the duration in which the Data will be accessed by the individual under an honorary contract;
o The necessity for the Data to be accessed by the person(s) holding an honorary contract, instead of a substantive employee of an organisation named as controller or a processor in this DSA;
o Confirmation that an appropriate contract is in place which follows the relevant guidance and is countersigned by the substantive employer of the contract holder.
Processing activities
There is no associated flow of data into NHS England. The data flow out of NHS England consists of the datasets described above. These datasets include the special category of personal health data (see reference to UK GDPR Article 9(2)(i) above). CQC downloads and manages the NHS England extracts within Microsoft Azure. Encryption and access controls were set out in the technical submission sent to the NHS England security consultant prior to the agreed transfer.
No data will flow to NHS England for the purposes of this Data Sharing Agreement (DSA).
The extracts currently held by CQC (HES, civil registration mortality for HES mortality, MHSDS, CSDS, MSDS, ECDS and associated datasets) include a bridging file between HES and MHSDS to follow treatment along care pathways. The introduction of the Token_Person_ID into the other datasets will allow linkage between the listed NHS England data (and has removed the need for the HES-MHSDS bridging file) to ensure the optimum use of these extracts. The NHS England data will not be linked to any other sources and any proposal to do so would be subject to a further application with NHS England. CQC can confirm that there will be no attempt to re-identify individuals with the sole exception of trusts using Local Patient Identifier to identify patients whose care appears problematic where strictly necessary.
NHS England will provide the relevant records from the HES, ECDS, Civil Registration of Deaths, Mental health, CSDS and MSDS datasets to CQC.
The Data will contain directly identifying data items including Postcode and Local Patient Identifier which are required for assigning data to new LA/ICS boundaries and for identifying other geography-related data and to identify to a trust examples of their own patients whose care appears problematical.
The Data will not be transferred to any other location.
The Data will be stored on servers at CQC.
CQC stores Data on the Cloud provided by Microsoft Limited.
The Data will be accessed by authorised personnel via remote access.
CQC must confirm and provide evidence upon audit by NHS England that access via any remote device complies with the data security obligations within this DSA and the Data Sharing Framework Contract.
For remote access:
- Remote access will only be from secure locations situated within the territory of use (as further restricted elsewhere within the DSA if so done) stated within this DSA;
- Access controls granting users the minimum level of access required are in place;
- Remote access is only via secure connections (e.g., VPNs or secure protocols) to protect data;
- Multifactor authentication (MFA) is required for remote access;
- Device security, including up-to-date software and operating systems, antivirus software, and enabled firewalls are utilised for the remote access;
- All remote access is undertaken within the scope of the organisation’s DSPT (or other security arrangements as per this DSA) and complies with the organisation’s remote access policy.
The above applies in addition to any condition set out elsewhere within the DSA (e.g. who may carry out processing, and for what purpose).
Remote processing will be from secure locations within England/Wales. The data will not leave England/Wales at any time.
Access is restricted to employees, or contractors of CQC.
All personnel accessing the Data have been appropriately trained in data protection and confidentiality.
The Data will not be linked with any other data.
There will be no requirement and no attempt to reidentify individuals when using the Data, with the sole exception of trusts using Local Patient Identifier to identify patients whose care appears problematic where strictly necessary.
[1 paragraph unchanged]
Aggregated data summarised to organisation level is fed into a data warehouse.
[33 words unchanged]
made available to named individuals within the Technology, Data & Insight directorate.
Processing will only be carried out by CQC substantive employees and contractors who have been trained in data protection and confidentiality.
[8 paragraphs unchanged]
>
Zero allowed, 1-7 suppressed with '*', no rounding of values
>
Percentages will be based on raw data; where low number values can be deduced from denominator, percentages will be suppressed.
[1 paragraph unchanged]
There will be no data linkage undertaken with NHS England data provided under this Agreement that is not already noted in the Agreement.
Expected output
On-going produced outputs include:
The expected outputs of the processing will be:
-incorporates data indicators that align to CQC's assessment framework for that sector
> Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape, additional dashboards and early alerts are expected to become available for inspectors.
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
> Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Telstra - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS England data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
-indicates where the risk to the quality of care provided is greatest
> Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS England's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
-monitors change over time for each of the measures
> In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
-points to services where the quality may be improving
The outputs will not contain NHS England Data and will only contain aggregated information with small numbers suppressed as appropriate in line with the relevant disclosure rules for the dataset(s) from which the information was derived.
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England.
This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Over the course of the Covid pandemic lockdown, CQC took the decision that it would desist from on-site inspection unless the matter was a threat to life. The emphasis shifted to monitoring the NHS England data and other sources, including concerns from the public. With excessive mortality rates through Covid, some of the key indicators below were suspended; for example, mortality outliers. The outputs listed below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape over the next twelve months, additional dashboards and early alerts are expected to become available for inspectors.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Telstra - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS England data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS England's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Expected measurable benefits
In CQC's monitoring role, it prioritises the care and welfare of patients. People who use services should experience effective, safe and appropriate care, treatment and support that meets their needs and protects their rights.
CQC uses these data to help determine five core questions about services:
- Are they safe?
- Are they effective?
- Are they caring?
- Are they well-led?
- Are they responsive to people’s needs?
CQC took the decision – over the course of the Covid pandemic lockdown - that it would desist from on-site inspection unless the matter was a threat to life. The emphasis shifted to monitoring the NHS England data and other sources, including concerns from the public. With excessive mortality rates through Covid, some of the key indicators below were suspended; for example, mortality outliers. The benefits listed below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
[7 paragraphs unchanged]
Unchanged: Benefits reported.
Objective for processing
Care Quality Commission (CQC) is requesting data that is critical to its regulatory oversight of health and care providers. CQC’s remit is to make sure health and adult social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve.
Access to these data help to ensure CQC can make use of its wide set of powers to protect people who use regulated services from harm and the risk of harm, and to ensure they receive health and social care services of an appropriate standard. These powers also hold registered providers and managers to account for failures in how the service is provided. CQC's enforcement policy sets out CQC's approach to taking action where CQC identify poor care, or where registered providers and managers do not meet the standards required in the regulations.
In CQC's monitoring role, it prioritises the care and welfare of patients. People who use services should experience effective, safe and appropriate care, treatment and support that meets their needs and protects their rights.
CQC uses these data to help determine five core questions about services:
- Are they safe?
- Are they effective?
- Are they caring?
- Are they well-led?
- Are they responsive to people’s needs?
The following NHS England Data will be accessed:
> Hospital Episode Statistics Admitted Patient Care (HES APC)
> HES Outpatients (OP)
> HES Critical Care (CC)
> HES Accident and Emergency (A&E) and Emergency Care Data Set (ECDS)
> Mental Health Services Data Set (MHSDS) and Mental Health and Learning Disabilities Dataset (MHLDDS)
> Community Services Data Set (CSDS)
> Maternity Services Data Set (MSDS)
> Civil Registration of Deaths
CQC use these data to;
(i) populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections)
(ii) to inform judgements about the level of quality in services within CQCs Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation
(iii) support CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act
(iv) Use in thematic reviews and national reporting; for example, the Annual State of Care report and
(v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
The level of data will be:
> Identifiable
Local patient identifier is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. Local patient identifier is used as the Token Person ID is not known to the trust. With this exception, no record level data is released to third parties.
The patient's postcode is used for assigning data to new Local Authority /Integrated Care Systems boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
The Health and Social Care Act 2008 imposes notifications requirements for NHS bodies, which are managed and processed by CQC, which has a duty under the Mental Health Act 1983 (MHA) to monitor how services exercise their powers and discharge their duties when patients are detained in hospital, subject to community treatment orders or guardianship.
Among these are
• Reg 16: Death of a person who uses the service
• Reg 17: Deaths of people detained or liable to be detained under the Mental Health Act
The availability of Date of Death allows CQC to verify whether the team have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
• Reg 18: Other incidents: Admission of a child or young person to an adult psychiatric ward or unit
Date of Birth allows CQC to know whether a child or young person was admitted to an adult ward and produce an indicator. It will also inform analysis of interventions related to age.
CQC's use of identifying data is subject to CQC's statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’) clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions
The Data will be minimised as follows:
> Data required to cover activity within the whole of England.
> The data subjects will cover all individuals who have undergone treatment in these pathways.
> Limited to data between 2014/15 to latest available. Monthly latest available extracts are required to ensure CQC have access to the most up-to-date data for ongoing analyses and oversight. This is particularly important in understanding an organisation's most recent performance. Historic data from 2014/15 is required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
For record-level data, CQC will process these data lawfully under UK GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77.
As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018.
For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under the enactment set out in sections 76 and 77.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS England (previously NHS Digital/Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment has been reviewed and completed by CQC.
Microsoft Limited is a processor acting under the instructions of CQC. Microsoft Limited role is limited to cloud storage (Microsoft Azure).
Data will be accessed by:
• Substantive employees of CQC
• Non-substantive employees (Contractors)
CQC must maintain records in a single location that cover the following details of each individual given access under a contract:
o Their substantive employer;
o Their role in respect of the purpose for the processing specified in the DSA;
o The start date and end date of the duration in which the Data will be accessed by the individual under an honorary contract;
o The necessity for the Data to be accessed by the person(s) holding an honorary contract, instead of a substantive employee of an organisation named as controller or a processor in this DSA;
o Confirmation that an appropriate contract is in place which follows the relevant guidance and is countersigned by the substantive employer of the contract holder.
Expected output
The expected outputs of the processing will be:
> Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape, additional dashboards and early alerts are expected to become available for inspectors.
> Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Telstra - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS England data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
> Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS England's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
> In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
The outputs will not contain NHS England Data and will only contain aggregated information with small numbers suppressed as appropriate in line with the relevant disclosure rules for the dataset(s) from which the information was derived.
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England.
Benefits reported
The creation of CQC’s new Data & Insight Unit has started to embed and improve on its previous insight programme and associated dashboards. Core data from this data sharing agreement were used in the production of indicators that align to CQC’s key lines of enquiry for a particular sector (e.g., hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used to inform planning regulatory activity (including to inform inspection planning decisions). The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in Insight products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted, and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
CQC has made extensive use of NHS England data within its insight pre-inspection activity within the hospital/ Mental Health sectors. The core NHS Englnad data acts to highlight any particular concerns (or good practice) that would then be followed up between an inspector and a given organisation or used to determine where an inspection might be focused. The reports provide trust-level indicators and national comparisons from the most readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality-of-care provision and examples of good practice that other organisations could adopt. The NHS England data are therefore critical in this process for driving up the quality-of-care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS England featured in the 2020/21 State of Care report. This year, it highlighted the impact of the pandemic as part of its design to provide a high-level commentary on year-on-year changes to care provision within England.
Over 2021/22 CQC issued 100 letters of intent to Hospital services across England where CQC identified poor care or where the standards of registration were not being met. However, these levels were likely to be lower than for other years, as this period covers the pandemic during which CQC reduced the number of inspections to a minimum level across Hospital services.
CQC continues to monitor a suite of indicators covering secondary health acute services.
In addition, CQC has a suite of indicators relating to safety and quality in mental health services for which it uses the Mental health services dataset.
CQC is also developing analytical methodologies to present data at core service level for Mental health services.
Core services are the unit of rating for CQC's assessments of mental health services, and our objective is to present more granular analysis from MHSDS (and other sources) mapped to these services.
Thematic reviews provide in-depth analyses of chosen topics to inform CQC staff, clinicians and the public about that service/area of care while also highlighting areas for improvement/best practice; working with inspector colleagues, themed inspections allow CQC to develop recommendations for making improvements in the delivery of care. These recommendations are then incorporated into future inspections to encourage continual improvement. ‘Restraint, segregation, and seclusion’, ‘Do not attempt CPR decisions’, and ‘Provider collaboration’ are examples of recent thematic data reviews/themed inspections that helped/ are helping to raise specific questions on the monitoring and provision of care in these areas with a focus on future improvement.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS England's HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
DARS-NIC-359603-D2Q6M-v13.6 29 April 2024 to 29 September 2024
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 15
- Files released
- 234
Datasets: Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES-ID to MPS-ID HES Accident and Emergency; HES-ID to MPS-ID HES Admitted Patient Care; HES-ID to MPS-ID HES Outpatients; HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Services Data Set (MHSDS); Mental Health Services Data Set (MHSDS) v5.0
What changed from DARS-NIC-359603-D2Q6M-v12.3
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2024-04-29 |
Datasets: + Mental Health Services Data Set (MHSDS) v5.0
Unchanged: Objective for processing, Processing activities, Expected output, Expected measurable benefits, Benefits reported.
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of health and care providers. CQC’s remit is to make sure health and adult social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. Its role will be expanded to encompass an assessment of quality for Integrated Care Systems (ICSs) and assurance of Local Authorities – in relation to their respected roles for health and adult social care. Its regulatory model is underpinned by a Data & Insight programme that draws together indicators of quality and risk about services. The data directly influence the risk and benchmarking models used to prioritise regulatory activity and inform its judgements of quality in services. The datasets also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act and to deliver national reports to parliament. Processing these data allow CQC to meet this public benefit.
Access to these data help to ensure CQC can make use of its wide set of powers to protect people who use regulated services from harm and the risk of harm, and to ensure they receive health and social care services of an appropriate standard. These powers also hold registered providers and managers to account for failures in how the service is provided. CQC's enforcement policy sets out CQC's approach to taking action where CQC identify poor care, or where registered providers and managers do not meet the standards required in the regulations. The level of enforcement is dependent on many factors but start at a requirement notice (stipulating a timeframe within which a given improvement must take place) for a less serious breach up to the possible cancellation of services in extreme cases.
For record-level data, CQC will process these data lawfully under UK GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77. As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018. For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under the enactment set out in sections 76 and 77.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS England (previously NHS Digital/Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment has been reviewed and completed by CQC.
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and the legacy Mental Health and Learning Disabilities Dataset, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Monthly extracts ensure CQC have access to the most up-to-date data for ongoing analyses and oversight - particularly important in understanding an organisation's most recent performance. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
CQC use these data (i) to populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections) and to inform judgements about the level of quality in services (ii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iii) towards CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; (iv) in thematic reviews and national reporting; for example, the Annual State of Care report and (v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: 'postcode' and 'local patient identifier'. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. 'Local patient identifier' is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient's postcode is used for assigning data to new LA/ICS boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continues to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The latest review again focused on requests submitted to the CQC central analytical team. CQC has confirmed that, in the review period, analyses were still conducted on the postcode and local patient identifier fields. In a previous iteration of this agreement (v10) additional MHSDS fields were included in the application. Future analyses using birth date, death date, and unique restrictive intervention incident ID from the MHSDS data set will support work related to mortality and for monitoring Use Of Force Act 2018. Unique restrictive intervention incident ID has been requested to facilitate monitoring of restrictive interventions. The Mental Health Units (Use of Force) Act 2018 CHAPTER 27 makes provision about the oversight and management of the appropriate use of force in relation to people in mental health units; to make provision about the use of body cameras by police officers in the course of duties in relation to people in mental health units; and for connected purposes. CQC's statutory powers under s9(a) allow it to require information about restrictive interventions for the purposes of investigation of deaths and serious injury.
The Health and Social Care Act 2008 imposes notifications requirements for NHS bodies, which are managed and processed by CQC, which has a duty under the Mental Health Act 1983 (MHA) to monitor how services exercise their powers and discharge their duties when patients are detained in hospital, subject to community treatment orders or guardianship.
Among these are
• Reg 16: Death of a person who uses the service
• Reg 17: Deaths of people detained or liable to be detained under the Mental Health Act
The availability of Date of Death allows us to verify whether the team have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
• Reg 18: Other incidents: Admission of a child or young person to an adult psychiatric ward or unit
Date of Birth allows us to know whether a child or young person was admitted to an adult ward and produce an indicator. It will also inform analysis of interventions related to age.
CQC's use of identifying data is subject to CQC's statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’) clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
CQC is the sole data controller and also processes the data. Now held on Microsoft Azure’s cloud environment, the NHS England data will only be accessed by CQC substantive employees and non-substantive employees (contractors). Where CQC used non-substantive employees (contractors), CQC would insist on confidentiality clauses within contracts and oblige individuals to complete in-house training on data protection and confidentiality. The local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
Expected output
On-going produced outputs include:
-incorporates data indicators that align to CQC's assessment framework for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Over the course of the Covid pandemic lockdown, CQC took the decision that it would desist from on-site inspection unless the matter was a threat to life. The emphasis shifted to monitoring the NHS England data and other sources, including concerns from the public. With excessive mortality rates through Covid, some of the key indicators below were suspended; for example, mortality outliers. The outputs listed below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape over the next twelve months, additional dashboards and early alerts are expected to become available for inspectors.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Telstra - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS England data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS England's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
The creation of CQC’s new Data & Insight Unit has started to embed and improve on its previous insight programme and associated dashboards. Core data from this data sharing agreement were used in the production of indicators that align to CQC’s key lines of enquiry for a particular sector (e.g., hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used to inform planning regulatory activity (including to inform inspection planning decisions). The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in Insight products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted, and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
CQC has made extensive use of NHS England data within its insight pre-inspection activity within the hospital/ Mental Health sectors. The core NHS Englnad data acts to highlight any particular concerns (or good practice) that would then be followed up between an inspector and a given organisation or used to determine where an inspection might be focused. The reports provide trust-level indicators and national comparisons from the most readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality-of-care provision and examples of good practice that other organisations could adopt. The NHS England data are therefore critical in this process for driving up the quality-of-care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS England featured in the 2020/21 State of Care report. This year, it highlighted the impact of the pandemic as part of its design to provide a high-level commentary on year-on-year changes to care provision within England.
Over 2021/22 CQC issued 100 letters of intent to Hospital services across England where CQC identified poor care or where the standards of registration were not being met. However, these levels were likely to be lower than for other years, as this period covers the pandemic during which CQC reduced the number of inspections to a minimum level across Hospital services.
CQC continues to monitor a suite of indicators covering secondary health acute services.
In addition, CQC has a suite of indicators relating to safety and quality in mental health services for which it uses the Mental health services dataset.
CQC is also developing analytical methodologies to present data at core service level for Mental health services.
Core services are the unit of rating for CQC's assessments of mental health services, and our objective is to present more granular analysis from MHSDS (and other sources) mapped to these services.
Thematic reviews provide in-depth analyses of chosen topics to inform CQC staff, clinicians and the public about that service/area of care while also highlighting areas for improvement/best practice; working with inspector colleagues, themed inspections allow CQC to develop recommendations for making improvements in the delivery of care. These recommendations are then incorporated into future inspections to encourage continual improvement. ‘Restraint, segregation, and seclusion’, ‘Do not attempt CPR decisions’, and ‘Provider collaboration’ are examples of recent thematic data reviews/themed inspections that helped/ are helping to raise specific questions on the monitoring and provision of care in these areas with a focus on future improvement.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS England's HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
DARS-NIC-359603-D2Q6M-v12.3 21 February 2024 to 29 September 2024
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 14
- Files released
- 232
Datasets: Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES-ID to MPS-ID HES Accident and Emergency; HES-ID to MPS-ID HES Admitted Patient Care; HES-ID to MPS-ID HES Outpatients; HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Services Data Set (MHSDS)
What changed from DARS-NIC-359603-D2Q6M-v11.8
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2024-02-21 |
Datasets:
− Mental Health Services Data Set (MHSDS) v5.0
Unchanged: Objective for processing, Processing activities, Expected output, Expected measurable benefits, Benefits reported.
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of health and care providers. CQC’s remit is to make sure health and adult social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. Its role will be expanded to encompass an assessment of quality for Integrated Care Systems (ICSs) and assurance of Local Authorities – in relation to their respected roles for health and adult social care. Its regulatory model is underpinned by a Data & Insight programme that draws together indicators of quality and risk about services. The data directly influence the risk and benchmarking models used to prioritise regulatory activity and inform its judgements of quality in services. The datasets also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act and to deliver national reports to parliament. Processing these data allow CQC to meet this public benefit.
Access to these data help to ensure CQC can make use of its wide set of powers to protect people who use regulated services from harm and the risk of harm, and to ensure they receive health and social care services of an appropriate standard. These powers also hold registered providers and managers to account for failures in how the service is provided. CQC's enforcement policy sets out CQC's approach to taking action where CQC identify poor care, or where registered providers and managers do not meet the standards required in the regulations. The level of enforcement is dependent on many factors but start at a requirement notice (stipulating a timeframe within which a given improvement must take place) for a less serious breach up to the possible cancellation of services in extreme cases.
For record-level data, CQC will process these data lawfully under UK GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77. As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018. For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under the enactment set out in sections 76 and 77.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS England (previously NHS Digital/Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment has been reviewed and completed by CQC.
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and the legacy Mental Health and Learning Disabilities Dataset, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Monthly extracts ensure CQC have access to the most up-to-date data for ongoing analyses and oversight - particularly important in understanding an organisation's most recent performance. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
CQC use these data (i) to populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections) and to inform judgements about the level of quality in services (ii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iii) towards CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; (iv) in thematic reviews and national reporting; for example, the Annual State of Care report and (v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: 'postcode' and 'local patient identifier'. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. 'Local patient identifier' is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient's postcode is used for assigning data to new LA/ICS boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continues to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The latest review again focused on requests submitted to the CQC central analytical team. CQC has confirmed that, in the review period, analyses were still conducted on the postcode and local patient identifier fields. In a previous iteration of this agreement (v10) additional MHSDS fields were included in the application. Future analyses using birth date, death date, and unique restrictive intervention incident ID from the MHSDS data set will support work related to mortality and for monitoring Use Of Force Act 2018. Unique restrictive intervention incident ID has been requested to facilitate monitoring of restrictive interventions. The Mental Health Units (Use of Force) Act 2018 CHAPTER 27 makes provision about the oversight and management of the appropriate use of force in relation to people in mental health units; to make provision about the use of body cameras by police officers in the course of duties in relation to people in mental health units; and for connected purposes. CQC's statutory powers under s9(a) allow it to require information about restrictive interventions for the purposes of investigation of deaths and serious injury.
The Health and Social Care Act 2008 imposes notifications requirements for NHS bodies, which are managed and processed by CQC, which has a duty under the Mental Health Act 1983 (MHA) to monitor how services exercise their powers and discharge their duties when patients are detained in hospital, subject to community treatment orders or guardianship.
Among these are
• Reg 16: Death of a person who uses the service
• Reg 17: Deaths of people detained or liable to be detained under the Mental Health Act
The availability of Date of Death allows us to verify whether the team have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
• Reg 18: Other incidents: Admission of a child or young person to an adult psychiatric ward or unit
Date of Birth allows us to know whether a child or young person was admitted to an adult ward and produce an indicator. It will also inform analysis of interventions related to age.
CQC's use of identifying data is subject to CQC's statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’) clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
CQC is the sole data controller and also processes the data. Now held on Microsoft Azure’s cloud environment, the NHS England data will only be accessed by CQC substantive employees and non-substantive employees (contractors). Where CQC used non-substantive employees (contractors), CQC would insist on confidentiality clauses within contracts and oblige individuals to complete in-house training on data protection and confidentiality. The local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
Expected output
On-going produced outputs include:
-incorporates data indicators that align to CQC's assessment framework for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Over the course of the Covid pandemic lockdown, CQC took the decision that it would desist from on-site inspection unless the matter was a threat to life. The emphasis shifted to monitoring the NHS England data and other sources, including concerns from the public. With excessive mortality rates through Covid, some of the key indicators below were suspended; for example, mortality outliers. The outputs listed below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape over the next twelve months, additional dashboards and early alerts are expected to become available for inspectors.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Telstra - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS England data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS England's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
The creation of CQC’s new Data & Insight Unit has started to embed and improve on its previous insight programme and associated dashboards. Core data from this data sharing agreement were used in the production of indicators that align to CQC’s key lines of enquiry for a particular sector (e.g., hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used to inform planning regulatory activity (including to inform inspection planning decisions). The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in Insight products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted, and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
CQC has made extensive use of NHS England data within its insight pre-inspection activity within the hospital/ Mental Health sectors. The core NHS Englnad data acts to highlight any particular concerns (or good practice) that would then be followed up between an inspector and a given organisation or used to determine where an inspection might be focused. The reports provide trust-level indicators and national comparisons from the most readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality-of-care provision and examples of good practice that other organisations could adopt. The NHS England data are therefore critical in this process for driving up the quality-of-care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS England featured in the 2020/21 State of Care report. This year, it highlighted the impact of the pandemic as part of its design to provide a high-level commentary on year-on-year changes to care provision within England.
Over 2021/22 CQC issued 100 letters of intent to Hospital services across England where CQC identified poor care or where the standards of registration were not being met. However, these levels were likely to be lower than for other years, as this period covers the pandemic during which CQC reduced the number of inspections to a minimum level across Hospital services.
CQC continues to monitor a suite of indicators covering secondary health acute services.
In addition, CQC has a suite of indicators relating to safety and quality in mental health services for which it uses the Mental health services dataset.
CQC is also developing analytical methodologies to present data at core service level for Mental health services.
Core services are the unit of rating for CQC's assessments of mental health services, and our objective is to present more granular analysis from MHSDS (and other sources) mapped to these services.
Thematic reviews provide in-depth analyses of chosen topics to inform CQC staff, clinicians and the public about that service/area of care while also highlighting areas for improvement/best practice; working with inspector colleagues, themed inspections allow CQC to develop recommendations for making improvements in the delivery of care. These recommendations are then incorporated into future inspections to encourage continual improvement. ‘Restraint, segregation, and seclusion’, ‘Do not attempt CPR decisions’, and ‘Provider collaboration’ are examples of recent thematic data reviews/themed inspections that helped/ are helping to raise specific questions on the monitoring and provision of care in these areas with a focus on future improvement.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS England's HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
DARS-NIC-359603-D2Q6M-v11.8 30 September 2023 to 29 September 2024
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 15
- Files released
- 28
Datasets: Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES-ID to MPS-ID HES Accident and Emergency; HES-ID to MPS-ID HES Admitted Patient Care; HES-ID to MPS-ID HES Outpatients; HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Services Data Set (MHSDS); Mental Health Services Data Set (MHSDS) v5.0
What changed from DARS-NIC-359603-D2Q6M-v10.2
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2023-09-30 | |
| End date | 2024-09-29 | |
| Civil Registrations of Death - Secondary Care Cut: legal basis | Health and Social Care Act 2012 - s261(5)(d) |
Objective for processing
[2 paragraphs unchanged]
For record-level data, CQC will process these data lawfully under
UK
GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and
[173 words unchanged]
or rule of law, and CQC has a duty of confidentiality under
the
enactment set out in sections 76 and 77.
CQC's statutory powers under s64 of the 2008 Act allow it to
[13 words unchanged]
oversight of health and social care; for example, local authorities and NHS
Digital (Health
England (previously NHS Digital/Health
and Social Care Information Centre). These powers are constrained by the application
[13 words unchanged]
of the use of (potentially) identifying data to meet the necessity test.
As part of the process for weighing up the risk of potential
[12 words unchanged]
benefit of its use for the organisation, a Data Protection Impact Assessment
was finalised on 31 May 2019
has been reviewed
and
subsequently reviewed 04 December 2020. It is currently undergoing review (September 2022).
completed by CQC.
[2 paragraphs unchanged]
The data contain patient identifying details although CQC have worked to reduce
[62 words unchanged]
the former, the patient's postcode is used for assigning data to new
LA/CCG
LA/ICS
boundaries, and for identifying other geography-related data (such as linking with deprivation
[9 words unchanged]
to help monitor for adverse events for people living in care homes).
CQC continues to review its use of identifiers and whether the amount
[30 words unchanged]
analyses were still conducted on the postcode and local patient identifier fields.
This application requests three
In a previous iteration of this agreement (v10)
additional
patient identifying
MHSDS
fields
from MHSDS.
were included in the application.
Future analyses using birth date, death date, and unique restrictive intervention incident
[106 words unchanged]
restrictive interventions for the purposes of investigation of deaths and serious injury.
[4 paragraphs unchanged]
The availability of Date of Death allows us to verify whether
we
the team
have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
[3 paragraphs unchanged]
CQC is the sole data controller and also processes the data. Now held on Microsoft Azure’s cloud environment, the NHS
Digital
England
data will only be accessed by CQC substantive employees and non-substantive employees
[39 words unchanged]
identify patient notes to review, as detailed below in the Benefits section.
Processing activities
There is no associated flow of data into NHS
Digital.
England.
The data flow out of NHS
Digital
England
consists of the datasets described above. These datasets include the special category of personal health data (see reference to
UK
GDPR Article 9(2)(i) above). CQC downloads and manages the NHS
Digital
England
extracts within Microsoft Azure. Encryption and access controls were set out in the technical submission sent to the NHS
Digital
England
security consultant prior to the agreed transfer.
The extracts currently held by CQC (HES, civil registration mortality for HES
[26 words unchanged]
Token_Person_ID into the other datasets will allow linkage between the listed NHS
Digital
England
data (and has removed the need for the HES-MHSDS bridging file) to ensure the optimum use of these extracts. The NHS
Digital
England
data will not be linked to any other sources and any proposal to do so would be subject to a further application with NHS
Digital.
England.
CQC can confirm that there will be no attempt to re-identify individuals
[8 words unchanged]
Patient Identifier to identify patients whose care appears problematic where strictly necessary.
[1 paragraph unchanged]
Aggregated data summarised to organisation level is fed into a data
warehouse (Data Centres listed within this Agreement).
warehouse.
This is then used to create CQC’s Data & Insight Unit products
[42 words unchanged]
employees and contractors who have been trained in data protection and confidentiality.
[1 paragraph unchanged]
Where CQC makes any outputs publicly available (e.g. State of Care, thematic reviews), these outputs will adhere to the current NHS
Digital
England
suppression methods required for the specific dataset(s) used in the production of the output.
[3 paragraphs unchanged]
Where insight reports are subsequently shared with other arms-length bodies (e.g. NHS
[6 words unchanged]
partners bodies to emphasise they must not be published because of NHS
Digital
England
suppression methodologies.
[1 paragraph unchanged]
In place of the different NHS
Digital
England
suppression methodologies for HES and MHSDS/MSDS, CQC under this Data Sharing Agreement
[13 words unchanged]
within CQC or externally with care providers or arms-length bodies partnering CQC:
[3 paragraphs unchanged]
All organisations party to this Agreement must comply with the Data Sharing Framework Contract requirements, including those regarding the use (and purposes of that use) by “Personnel” (as defined within the Data Sharing Framework Contract - i.e. employees, agents and contractors of the Data Recipient who may have access to that data).
There will be no data linkage undertaken with NHS England data provided under this Agreement that is not already noted in the Agreement.
There will be no data linkage undertaken with NHS Digital data provided under this Agreement that is not already noted in the Agreement.
Expected output
[7 paragraphs unchanged]
Over the course of the Covid pandemic lockdown, CQC took the decision
[10 words unchanged]
was a threat to life. The emphasis shifted to monitoring the NHS
Digital
England
data and other sources, including concerns from the public. With excessive mortality
[18 words unchanged]
below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
[1 paragraph unchanged]
Outliers Programme: analysis of certain metrics derived from these data are shared
[54 words unchanged]
procedures on biliary tract' raised in response to an alert raised by
Dr Foster Intelligence Ltd (now known as Telstra)
Telstra
- investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS
Digital
England
data to make a decision on the highlighted risk with reference to
[40 words unchanged]
approach to monitoring mortality will be reviewed over the next 12 months.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS England's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS Digital's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
[1 paragraph unchanged]
Expected measurable benefits
[7 paragraphs unchanged]
CQC took the decision – over the course of the Covid pandemic
[12 words unchanged]
was a threat to life. The emphasis shifted to monitoring the NHS
Digital
England
data and other sources, including concerns from the public. With excessive mortality
[18 words unchanged]
below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
[2 paragraphs unchanged]
HES and civil registration mortality data are used in the outliers programme.
[9 words unchanged]
may be identified either by CQC's own analyses or by those of
Dr Foster Intelligence Ltd (now known as Telstra).
Telstra.
For both, CQC gathers all available information - including HES analyses, where
[153 words unchanged]
panels as well as to the maternity core service within CQC insight.
[1 paragraph unchanged]
Thematic reviews provide in-depth analyses of chosen topics to inform CQC staff, clinicians and the public about that service/area of care while also highlighting areas for improvement/best practice; working with inspector colleagues, themed inspections allow CQC to develop recommendations for making improvements in the delivery of care. These recommendations are then incorporated into future inspections to encourage continual improvement. ‘Restraint, segregation, and seclusion’, ‘Do not attempt CPR decisions’, and ‘Provider collaboration’ are examples of recent thematic data reviews/themed inspections that helped/ are helping to raise specific questions on the monitoring and provision of care in these areas with a focus on future improvement.
[1 paragraph unchanged]
Where CQC identifies poor care, or where the standards of registration are not being met, CQC can use its enforcement policy as
set out in Section 5a objective for processing.
described above.
Such action is targeted to drive improvements or, in extreme cases, protect the public from access to poor quality services.
[1 paragraph unchanged]
With the new v5 data set we anticipate being able to progress this work, and achieving the benefits to our regulatory programmes.
Benefits reported
[2 paragraphs unchanged]
CQC has made extensive use of NHS
Digital
England
data within its insight pre-inspection activity within the hospital/ Mental Health sectors. The core NHS
Digital
Englnad
data acts to highlight any particular concerns (or good practice) that would
[51 words unchanged]
has been necessary, an inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality-of-care provision and examples of good practice that other organisations could adopt. The NHS
Digital
England
data are therefore critical in this process for driving up the quality-of-care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS
Digital
England
featured in the 2020/21 State of Care report. This year, it highlighted
[11 words unchanged]
provide a high-level commentary on year-on-year changes to care provision within England.
[5 paragraphs unchanged]
Thematic reviews provide in-depth analyses of chosen topics to inform CQC staff, clinicians and the public about that service/area of care while also highlighting areas for improvement/best practice; working with inspector colleagues, themed inspections allow CQC to develop recommendations for making improvements in the delivery of care. These recommendations are then incorporated into future inspections to encourage continual improvement. ‘Restraint, segregation, and seclusion’, ‘Do not attempt CPR decisions’, and ‘Provider collaboration’ are examples of recent thematic data reviews/themed inspections that helped/ are helping to raise specific questions on the monitoring and provision of care in these areas with a focus on future improvement.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS England's HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of health and care providers. CQC’s remit is to make sure health and adult social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. Its role will be expanded to encompass an assessment of quality for Integrated Care Systems (ICSs) and assurance of Local Authorities – in relation to their respected roles for health and adult social care. Its regulatory model is underpinned by a Data & Insight programme that draws together indicators of quality and risk about services. The data directly influence the risk and benchmarking models used to prioritise regulatory activity and inform its judgements of quality in services. The datasets also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act and to deliver national reports to parliament. Processing these data allow CQC to meet this public benefit.
Access to these data help to ensure CQC can make use of its wide set of powers to protect people who use regulated services from harm and the risk of harm, and to ensure they receive health and social care services of an appropriate standard. These powers also hold registered providers and managers to account for failures in how the service is provided. CQC's enforcement policy sets out CQC's approach to taking action where CQC identify poor care, or where registered providers and managers do not meet the standards required in the regulations. The level of enforcement is dependent on many factors but start at a requirement notice (stipulating a timeframe within which a given improvement must take place) for a less serious breach up to the possible cancellation of services in extreme cases.
For record-level data, CQC will process these data lawfully under UK GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77. As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018. For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under the enactment set out in sections 76 and 77.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS England (previously NHS Digital/Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment has been reviewed and completed by CQC.
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and the legacy Mental Health and Learning Disabilities Dataset, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Monthly extracts ensure CQC have access to the most up-to-date data for ongoing analyses and oversight - particularly important in understanding an organisation's most recent performance. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
CQC use these data (i) to populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections) and to inform judgements about the level of quality in services (ii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iii) towards CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; (iv) in thematic reviews and national reporting; for example, the Annual State of Care report and (v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: 'postcode' and 'local patient identifier'. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. 'Local patient identifier' is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient's postcode is used for assigning data to new LA/ICS boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continues to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The latest review again focused on requests submitted to the CQC central analytical team. CQC has confirmed that, in the review period, analyses were still conducted on the postcode and local patient identifier fields. In a previous iteration of this agreement (v10) additional MHSDS fields were included in the application. Future analyses using birth date, death date, and unique restrictive intervention incident ID from the MHSDS data set will support work related to mortality and for monitoring Use Of Force Act 2018. Unique restrictive intervention incident ID has been requested to facilitate monitoring of restrictive interventions. The Mental Health Units (Use of Force) Act 2018 CHAPTER 27 makes provision about the oversight and management of the appropriate use of force in relation to people in mental health units; to make provision about the use of body cameras by police officers in the course of duties in relation to people in mental health units; and for connected purposes. CQC's statutory powers under s9(a) allow it to require information about restrictive interventions for the purposes of investigation of deaths and serious injury.
The Health and Social Care Act 2008 imposes notifications requirements for NHS bodies, which are managed and processed by CQC, which has a duty under the Mental Health Act 1983 (MHA) to monitor how services exercise their powers and discharge their duties when patients are detained in hospital, subject to community treatment orders or guardianship.
Among these are
• Reg 16: Death of a person who uses the service
• Reg 17: Deaths of people detained or liable to be detained under the Mental Health Act
The availability of Date of Death allows us to verify whether the team have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
• Reg 18: Other incidents: Admission of a child or young person to an adult psychiatric ward or unit
Date of Birth allows us to know whether a child or young person was admitted to an adult ward and produce an indicator. It will also inform analysis of interventions related to age.
CQC's use of identifying data is subject to CQC's statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’) clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
CQC is the sole data controller and also processes the data. Now held on Microsoft Azure’s cloud environment, the NHS England data will only be accessed by CQC substantive employees and non-substantive employees (contractors). Where CQC used non-substantive employees (contractors), CQC would insist on confidentiality clauses within contracts and oblige individuals to complete in-house training on data protection and confidentiality. The local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
Expected output
On-going produced outputs include:
-incorporates data indicators that align to CQC's assessment framework for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Over the course of the Covid pandemic lockdown, CQC took the decision that it would desist from on-site inspection unless the matter was a threat to life. The emphasis shifted to monitoring the NHS England data and other sources, including concerns from the public. With excessive mortality rates through Covid, some of the key indicators below were suspended; for example, mortality outliers. The outputs listed below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape over the next twelve months, additional dashboards and early alerts are expected to become available for inspectors.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Telstra - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS England data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS England's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
The creation of CQC’s new Data & Insight Unit has started to embed and improve on its previous insight programme and associated dashboards. Core data from this data sharing agreement were used in the production of indicators that align to CQC’s key lines of enquiry for a particular sector (e.g., hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used to inform planning regulatory activity (including to inform inspection planning decisions). The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in Insight products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted, and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
CQC has made extensive use of NHS England data within its insight pre-inspection activity within the hospital/ Mental Health sectors. The core NHS Englnad data acts to highlight any particular concerns (or good practice) that would then be followed up between an inspector and a given organisation or used to determine where an inspection might be focused. The reports provide trust-level indicators and national comparisons from the most readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality-of-care provision and examples of good practice that other organisations could adopt. The NHS England data are therefore critical in this process for driving up the quality-of-care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS England featured in the 2020/21 State of Care report. This year, it highlighted the impact of the pandemic as part of its design to provide a high-level commentary on year-on-year changes to care provision within England.
Over 2021/22 CQC issued 100 letters of intent to Hospital services across England where CQC identified poor care or where the standards of registration were not being met. However, these levels were likely to be lower than for other years, as this period covers the pandemic during which CQC reduced the number of inspections to a minimum level across Hospital services.
CQC continues to monitor a suite of indicators covering secondary health acute services.
In addition, CQC has a suite of indicators relating to safety and quality in mental health services for which it uses the Mental health services dataset.
CQC is also developing analytical methodologies to present data at core service level for Mental health services.
Core services are the unit of rating for CQC's assessments of mental health services, and our objective is to present more granular analysis from MHSDS (and other sources) mapped to these services.
Thematic reviews provide in-depth analyses of chosen topics to inform CQC staff, clinicians and the public about that service/area of care while also highlighting areas for improvement/best practice; working with inspector colleagues, themed inspections allow CQC to develop recommendations for making improvements in the delivery of care. These recommendations are then incorporated into future inspections to encourage continual improvement. ‘Restraint, segregation, and seclusion’, ‘Do not attempt CPR decisions’, and ‘Provider collaboration’ are examples of recent thematic data reviews/themed inspections that helped/ are helping to raise specific questions on the monitoring and provision of care in these areas with a focus on future improvement.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS England's HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
DARS-NIC-359603-D2Q6M-v10.2 12 December 2022 to 29 September 2023
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 15
- Files released
- 275
Datasets: Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES-ID to MPS-ID HES Accident and Emergency; HES-ID to MPS-ID HES Admitted Patient Care; HES-ID to MPS-ID HES Outpatients; HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Services Data Set (MHSDS); Mental Health Services Data Set (MHSDS) v5.0
What changed from DARS-NIC-359603-D2Q6M-v9.8
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2022-12-12 | |
| Civil Registrations of Death - Secondary Care Cut: legal basis | Not stated |
Unchanged: Objective for processing, Processing activities, Expected output, Expected measurable benefits, Benefits reported.
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of health and care providers. CQC’s remit is to make sure health and adult social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. Its role will be expanded to encompass an assessment of quality for Integrated Care Systems (ICSs) and assurance of Local Authorities – in relation to their respected roles for health and adult social care. Its regulatory model is underpinned by a Data & Insight programme that draws together indicators of quality and risk about services. The data directly influence the risk and benchmarking models used to prioritise regulatory activity and inform its judgements of quality in services. The datasets also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act and to deliver national reports to parliament. Processing these data allow CQC to meet this public benefit.
Access to these data help to ensure CQC can make use of its wide set of powers to protect people who use regulated services from harm and the risk of harm, and to ensure they receive health and social care services of an appropriate standard. These powers also hold registered providers and managers to account for failures in how the service is provided. CQC's enforcement policy sets out CQC's approach to taking action where CQC identify poor care, or where registered providers and managers do not meet the standards required in the regulations. The level of enforcement is dependent on many factors but start at a requirement notice (stipulating a timeframe within which a given improvement must take place) for a less serious breach up to the possible cancellation of services in extreme cases.
For record-level data, CQC will process these data lawfully under GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77. As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018. For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under enactment set out in sections 76 and 77.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS Digital (Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment was finalised on 31 May 2019 and subsequently reviewed 04 December 2020. It is currently undergoing review (September 2022).
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and the legacy Mental Health and Learning Disabilities Dataset, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Monthly extracts ensure CQC have access to the most up-to-date data for ongoing analyses and oversight - particularly important in understanding an organisation's most recent performance. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
CQC use these data (i) to populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections) and to inform judgements about the level of quality in services (ii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iii) towards CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; (iv) in thematic reviews and national reporting; for example, the Annual State of Care report and (v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: 'postcode' and 'local patient identifier'. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. 'Local patient identifier' is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient's postcode is used for assigning data to new LA/CCG boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continues to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The latest review again focused on requests submitted to the CQC central analytical team. CQC has confirmed that, in the review period, analyses were still conducted on the postcode and local patient identifier fields. This application requests three additional patient identifying fields from MHSDS. Future analyses using birth date, death date, and unique restrictive intervention incident ID from the MHSDS data set will support work related to mortality and for monitoring Use Of Force Act 2018. Unique restrictive intervention incident ID has been requested to facilitate monitoring of restrictive interventions. The Mental Health Units (Use of Force) Act 2018 CHAPTER 27 makes provision about the oversight and management of the appropriate use of force in relation to people in mental health units; to make provision about the use of body cameras by police officers in the course of duties in relation to people in mental health units; and for connected purposes. CQC's statutory powers under s9(a) allow it to require information about restrictive interventions for the purposes of investigation of deaths and serious injury.
The Health and Social Care Act 2008 imposes notifications requirements for NHS bodies, which are managed and processed by CQC, which has a duty under the Mental Health Act 1983 (MHA) to monitor how services exercise their powers and discharge their duties when patients are detained in hospital, subject to community treatment orders or guardianship.
Among these are
• Reg 16: Death of a person who uses the service
• Reg 17: Deaths of people detained or liable to be detained under the Mental Health Act
The availability of Date of Death allows us to verify whether we have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
• Reg 18: Other incidents: Admission of a child or young person to an adult psychiatric ward or unit
Date of Birth allows us to know whether a child or young person was admitted to an adult ward and produce an indicator. It will also inform analysis of interventions related to age.
CQC's use of identifying data is subject to CQC's statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’) clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
CQC is the sole data controller and also processes the data. Now held on Microsoft Azure’s cloud environment, the NHS Digital data will only be accessed by CQC substantive employees and non-substantive employees (contractors). Where CQC used non-substantive employees (contractors), CQC would insist on confidentiality clauses within contracts and oblige individuals to complete in-house training on data protection and confidentiality. The local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
Expected output
On-going produced outputs include:
-incorporates data indicators that align to CQC's assessment framework for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Over the course of the Covid pandemic lockdown, CQC took the decision that it would desist from on-site inspection unless the matter was a threat to life. The emphasis shifted to monitoring the NHS Digital data and other sources, including concerns from the public. With excessive mortality rates through Covid, some of the key indicators below were suspended; for example, mortality outliers. The outputs listed below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape over the next twelve months, additional dashboards and early alerts are expected to become available for inspectors.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Dr Foster Intelligence Ltd (now known as Telstra) - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS Digital data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS Digital's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
The creation of CQC’s new Data & Insight Unit has started to embed and improve on its previous insight programme and associated dashboards. Core data from this data sharing agreement were used in the production of indicators that align to CQC’s key lines of enquiry for a particular sector (e.g., hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used to inform planning regulatory activity (including to inform inspection planning decisions). The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in Insight products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted, and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
CQC has made extensive use of NHS Digital data within its insight pre-inspection activity within the hospital/ Mental Health sectors. The core NHS Digital data acts to highlight any particular concerns (or good practice) that would then be followed up between an inspector and a given organisation or used to determine where an inspection might be focused. The reports provide trust-level indicators and national comparisons from the most readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality-of-care provision and examples of good practice that other organisations could adopt. The NHS Digital data are therefore critical in this process for driving up the quality-of-care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS Digital featured in the 2020/21 State of Care report. This year, it highlighted the impact of the pandemic as part of its design to provide a high-level commentary on year-on-year changes to care provision within England.
Over 2021/22 CQC issued 100 letters of intent to Hospital services across England where CQC identified poor care or where the standards of registration were not being met. However, these levels were likely to be lower than for other years, as this period covers the pandemic during which CQC reduced the number of inspections to a minimum level across Hospital services.
CQC continues to monitor a suite of indicators covering secondary health acute services.
In addition, CQC has a suite of indicators relating to safety and quality in mental health services for which it uses the Mental health services dataset.
CQC is also developing analytical methodologies to present data at core service level for Mental health services.
Core services are the unit of rating for CQC's assessments of mental health services, and our objective is to present more granular analysis from MHSDS (and other sources) mapped to these services.
DARS-NIC-359603-D2Q6M-v9.8 30 September 2022 to 29 September 2023
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 15
- Files released
- 81
Datasets: Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES-ID to MPS-ID HES Accident and Emergency; HES-ID to MPS-ID HES Admitted Patient Care; HES-ID to MPS-ID HES Outpatients; HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Services Data Set (MHSDS); Mental Health Services Data Set (MHSDS) v5.0
What changed from DARS-NIC-359603-D2Q6M-v8.4
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2022-09-30 | |
| End date | 2023-09-29 |
Datasets:
+ Mental Health Services Data Set (MHSDS) v5.0 · − Civil Registrations of Death
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of
health and
care providers. CQC’s remit is to make sure health and
adult
social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve.
It does that through effective monitoring
Its role will be expanded to encompass an assessment of quality for Integrated Care Systems (ICSs)
and
inspection activity
assurance of Local Authorities – in relation to their respected roles for health and adult social care. Its regulatory model is
underpinned by
an Intelligence insight
a Data & Insight
programme that draws together
indicators of quality and
risk
and bench marking metrics at core service level.
about services.
The data directly influence the risk and benchmarking models
used to prioritise regulatory activity
and
help determine both when inspections take place and where they should focus. They
inform its judgements of quality in services. The datasets
also help with CQC’s statutory responsibility to monitor the use of the Mental Health
Act.
Act and to deliver national reports to parliament. Processing these data allow CQC to meet this public benefit.
For record-level data, CQC will process these data lawfully under GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 (under which CQC was formed). As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) in, ‘processing is necessary for reasons of public interest in the area of public health, such as…ensuring high standards of quality and safety of health care…on the basis of Union or Member State law…’.
Access to these data help to ensure CQC can make use of its wide set of powers to protect people who use regulated services from harm and the risk of harm, and to ensure they receive health and social care services of an appropriate standard. These powers also hold registered providers and managers to account for failures in how the service is provided. CQC's enforcement policy sets out CQC's approach to taking action where CQC identify poor care, or where registered providers and managers do not meet the standards required in the regulations. The level of enforcement is dependent on many factors but start at a requirement notice (stipulating a timeframe within which a given improvement must take place) for a less serious breach up to the possible cancellation of services in extreme cases.
CQC’s statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS Digital (Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test. CQC’s core purpose is to seek to protect the public from poor provision of care, highlight good practice, and publish information (for example, inspection reports and ratings) that allow the public an improved understanding of the quality of provision of care by individual providers. Processing these data allow CQC to meet that public benefit.
For record-level data, CQC will process these data lawfully under GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77. As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018. For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under enactment set out in sections 76 and 77.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment was finalised on 31 May 2019 and subsequently reviewed 04 December 2020.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS Digital (Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and the legacy Mental Health and Learning Disabilities Dataset, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. With the phasing out of the HES mortality file, CQC is now requesting access to the civil registration mortality file as a replacement with the addition of the Token_Person_ID field that will allow linkage between NHS datasets, once this field is embedded in their outputs. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment was finalised on 31 May 2019 and subsequently reviewed 04 December 2020. It is currently undergoing review (September 2022).
CQC use these data (i) to populate indicators within their Intelligent insight products and associated dashboards, which help CQC focus inspections of providers by deciding when, where and what to inspect; (ii) to construct evidence tables / data packs, which bring together information and analysis for each provider and are used for inspection planning; (iii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iv) towards CQC’s statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; and (v) in thematic reviews and national reporting; for example, the Annual State of Care report.
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and the legacy Mental Health and Learning Disabilities Dataset, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Monthly extracts ensure CQC have access to the most up-to-date data for ongoing analyses and oversight - particularly important in understanding an organisation's most recent performance. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
CQC use these data (i) to populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections) and to inform judgements about the level of quality in services (ii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iii) towards CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; (iv) in thematic reviews and national reporting; for example, the Annual State of Care report and (v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
[1 paragraph unchanged]
CQC continues to review its use of identifiers and whether the amount
[24 words unchanged]
confirmed that, in the review period, analyses were still conducted on the
held identifiers. With respect
postcode and local patient identifier fields. This application requests three additional patient identifying fields from MHSDS. Future analyses using birth date, death date, and unique restrictive intervention incident ID from the MHSDS data set will support work related
to
mortality and for monitoring Use Of Force Act 2018. Unique restrictive intervention incident ID has been requested to facilitate monitoring of restrictive interventions. The Mental Health Units (Use of Force) Act 2018 CHAPTER 27 makes provision about
the
period
oversight and management
of
data, it concluded that CQC only needed
the appropriate use of force in relation
to
retain data from 2014/15. Subsequently, all data older than 2014/15 have been deleted from CQC systems. This covers HES, HES-associated data, and all
people in mental health units; to make provision about the use
of
MHMDS. The detail is set out
body cameras by police officers
in the
data destruction form.
course of duties in relation to people in mental health units; and for connected purposes. CQC's statutory powers under s9(a) allow it to require information about restrictive interventions for the purposes of investigation of deaths and serious injury.
CQC’s use of identifying data is subject to CQC’s statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’), clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
The Health and Social Care Act 2008 imposes notifications requirements for NHS bodies, which are managed and processed by CQC, which has a duty under the Mental Health Act 1983 (MHA) to monitor how services exercise their powers and discharge their duties when patients are detained in hospital, subject to community treatment orders or guardianship.
CQC is the sole data controller and also processes the data. Atos was CQC’s ICT service provider and was engaged through the IMS3 framework contract, let by the Department of Health and Social Care. This contract came to an end at the end in March 2020 but was temporarily extended while this Agreement was finalised to permit these data to be stored within the cloud environment of Microsoft Azure. The data were subsequently transferred from Atos to Microsoft Azure. An NHS Digital data destruction form has now been submitted and this version of the agreement removes Atos.
Among these are
Now transferred to Microsoft Azure’s cloud environment, the NHS Digital data will only be accessed by substantive employees of CQC but note that the local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
• Reg 16: Death of a person who uses the service
• Reg 17: Deaths of people detained or liable to be detained under the Mental Health Act
The availability of Date of Death allows us to verify whether we have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
• Reg 18: Other incidents: Admission of a child or young person to an adult psychiatric ward or unit
Date of Birth allows us to know whether a child or young person was admitted to an adult ward and produce an indicator. It will also inform analysis of interventions related to age.
CQC's use of identifying data is subject to CQC's statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’) clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
CQC is the sole data controller and also processes the data. Now held on Microsoft Azure’s cloud environment, the NHS Digital data will only be accessed by CQC substantive employees and non-substantive employees (contractors). Where CQC used non-substantive employees (contractors), CQC would insist on confidentiality clauses within contracts and oblige individuals to complete in-house training on data protection and confidentiality. The local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
Processing activities
There is no associated flow of data into NHS Digital. The data
[17 words unchanged]
of personal health data (see reference to GDPR Article 9(2)(i) above). CQC
currently
downloads and manages the NHS Digital extracts within Microsoft
Azure following transfer of the data from its previous storage managed by Atos (CQC's former ICT provider).
Azure.
Encryption and access controls were set out in the technical submission sent to the NHS Digital security consultant prior to the agreed transfer.
As part of the transfer agreement, the data on the Atos-managed servers have been deleted. Atos decommissioned the storage/ processing areas and an NHS Digital data destruction form was completed. Atos have now been removed from this data sharing agreement.
The extracts currently held by CQC (HES, civil registration mortality for HES
[10 words unchanged]
bridging file between HES and MHSDS to follow treatment along care pathways.
As discussed above, CQC are applying for the civil registration mortality file (with Token_Person_ID) to replace the HES mortality file that is being phased out.
The introduction of the Token_Person_ID into the other datasets will allow linkage between the listed NHS Digital data (and
remove
has removed
the need for the HES-MHSDS bridging file) to ensure the optimum use
[51 words unchanged]
Patient Identifier to identify patients whose care appears problematic where strictly necessary.
Access to the full, underlying datasets is restricted to a small team of CQC
staff (approximately six);
staff;
this is the only team that can access the full identifying data.
[11 words unchanged]
record and provider level - for statistical packages for use in the
Intelligence Directorate
Data & Insight Unit
only by identified staff. These staff request the bespoke breakdowns from the analytical team.
Aggregated data summarised to organisation level is fed into a data warehouse (Data Centres listed within this Agreement). This is then used to create CQC’s
intelligence
Data & Insight Unit
products as well as supporting ad hoc reporting. Where these outputs may
[5 words unchanged]
to such outputs are only made available to named individuals within the
Intelligence and Digital directorates. At this time, processing is
Technology, Data & Insight directorate. Processing will
only
be
carried out by CQC substantive employees
and contractors
who have been trained in data protection and confidentiality.
If CQC were to use non-substantive employees, CQC would insist on confidentiality clauses within contracts and oblige individuals to complete in-house training on data protection and confidentiality.
[2 paragraphs unchanged]
CQC also produces outputs associated with
inspections (e.g. CQC insight products)
its regulatory activities
which may be shared internally within CQC or externally with specific care providers (predominantly NHS Trusts) or with specific arms-length bodies partnering CQC such as NHS England
and NHS Improvement.
(e.g. CQC insight products).
In such outputs, applying the full rules on small number suppression may undermine the purpose for sharing the outputs.
[1 paragraph unchanged]
However, where data is shared with
health and
care providers, CQC would be sharing their own data with them so
[52 words unchanged]
the individual trust/provider would be making that decision on its own data.
Where insight reports are subsequently shared with other arms-length bodies (e.g. NHS
England/NHS Improvement),
England),
CQC would work with these partners bodies to emphasise they must not be published because of NHS Digital suppression methodologies.
[2 paragraphs unchanged]
•
Zero allowed, 1-7 suppressed with
‘*’,
'*',
no rounding of values
•
Percentages will be based on raw data; where low number values can be deduced from denominator, percentages will be
suppressed
suppressed.
[3 paragraphs unchanged]
Data will only be accessed and processed by substantive employees of the Care Quality Commission and will not be accessed or processed by any other third parties not mentioned in this Agreement.
Expected output
On-going produced outputs
include risk-based monitoring through CQC insight:
include:
-incorporates data indicators that align to
CQC’s key lines of enquiry
CQC's assessment framework
for that sector
[4 paragraphs unchanged]
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS
England/ NHS Improvement.
England.
This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Pre-inspection data evidence grids and monitoring dashboards: used by the inspections teams and shared with providers. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes.
Over the course of the Covid pandemic lockdown, CQC took the decision that it would desist from on-site inspection unless the matter was a threat to life. The emphasis shifted to monitoring the NHS Digital data and other sources, including concerns from the public. With excessive mortality rates through Covid, some of the key indicators below were suspended; for example, mortality outliers. The outputs listed below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on ‘Perinatal mortality and neonatal readmissions’ used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Dr Foster Intelligence Ltd - investigated death rates for endoscopic procedures. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape over the next twelve months, additional dashboards and early alerts are expected to become available for inspectors.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2019/20 publication appeared in February 2021.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Dr Foster Intelligence Ltd (now known as Telstra) - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS Digital data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
[1 paragraph unchanged]
In the monitoring of organisations for ongoing compliance against essential quality and safety standards, CQC uses screening techniques in its CQC insight tools, which analyse a wide variety of data sources to highlight possible outlying concerns that trigger actions where concerns are raised. Such screening methods are aided by a more local approach to information gathering and analysis, which is being developed in consultation with appropriate stakeholders. These techniques, currently along with national surveys of patients, help to create a more holistic understanding in informing its work with ongoing compliance, investigations, and thematic reviews.
[1 paragraph unchanged]
Expected measurable benefits
[7 paragraphs unchanged]
HES, MHSDS, EDDS and associated data are used to determine key performance indicators in the CQC insight products. Each indicator is categorised in one of the core domains that, in total, provide a view on the quality of the provision of care. CSDS is undergoing internal review and will be used for the same purposes to generate similar outputs; likewise, MSDS, once the extracts are more readily available.
CQC took the decision – over the course of the Covid pandemic lockdown - that it would desist from on-site inspection unless the matter was a threat to life. The emphasis shifted to monitoring the NHS Digital data and other sources, including concerns from the public. With excessive mortality rates through Covid, some of the key indicators below were suspended; for example, mortality outliers. The benefits listed below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
The pre-inspection data packs/evidence tables help the planning and review stages of an inspection that seeks to highlight areas of poor care requiring improvement while also seeking to promote good practice. Each data pack uses the data (HES and/ or MHSDS as appropriate) both to present an overview of the core business of the trust in terms of activity – helping to determine the specialist requirements of the inspection team - while also including specific metrics (e.g. HES re-admissions as descriptive statistics). MSDS, CSDS and ECDS will be used for the same purposes to generate similar outputs.
HES, MHSDS, ECDS and associated data are used to determine key performance indicators in the CQC insight products. Each indicator is categorised in one of the core domains that, in total, provide a view on the quality of the provision of care. CSDS is undergoing internal review and will be used for the same purposes to generate similar outputs; likewise, MSDS, once the extracts are more readily available.
HES and civil registration mortality data are used in the outliers programme. Outlier events, such as high mortality or readmission rates may be identified either by CQC's own analyses or by those of Dr Foster Intelligence Ltd. For both, CQC gathers all available information - including HES analyses, where appropriate, and advice from experts - and presents this to an internal review panel. This panel decides whether or not CQC investigate. When CQC decide to proceed, the data is shared with the trust for them to review and comment upon. One of the review actions a trust may carry out is a case note review. On rare occasions the trust is unable to reconcile HES counts with their local systems. In those cases, CQC may share a small number of values for the local patient identifier (lopatid) with the trust so they can identify patient notes to review. The mortality panels meet monthly while the maternity panels meet every two months. Where outlier concerns are identified, the subsequent contact and engagement with trusts have led to implementation of improvements in process that have had a positive impact on patient care. MSDS will be used to as a core input to the maternity panels as well as to the maternity core service within CQC insight.
CQC has a suite of insight products which help the planning and review stages of an inspection that seeks to highlight areas of poor care requiring improvement while also seeking to promote good practice. The products use data (HES and/ or MHSDS as appropriate) both to present an overview of the core business of the trust in terms of activity ʹhelping to determine the specialist requirements of the inspection team - while also including specific metrics (e.g. HES re-admissions as descriptive statistics). MSDS, CSDS and ECDS will be used for the same purposes to generate similar outputs.
HES and civil registration mortality data are used in the outliers programme. Outlier events, such as high mortality or readmission rates may be identified either by CQC's own analyses or by those of Dr Foster Intelligence Ltd (now known as Telstra). For both, CQC gathers all available information - including HES analyses, where appropriate, and advice from experts - and presents this to an internal review panel. This panel decides whether or not CQC investigate. When CQC decide to proceed, the data is shared with the trust for them to review and comment upon. One of the review actions a trust may carry out is a case note review. On rare occasions the trust is unable to reconcile HES counts with their local systems. In those cases, CQC may share a small number of values for the local patient identifier (lopatid) with the trust so they can identify patient notes to review. The mortality panels meet monthly while the maternity panels meet every two months. Where outlier concerns are identified, the subsequent contact and engagement with trusts have led to implementation of improvements in process that have had a positive impact on patient care. MSDS will be used to as a core input to the maternity panels as well as to the maternity core service within CQC insight.
[1 paragraph unchanged]
Thematic reviews provide in-depth analyses of chosen topics to inform CQC staff,
[35 words unchanged]
These recommendations are then incorporated into future inspections to encourage continual improvement.
‘End of Life Care’, ‘Safety in hospitals’
‘Restraint, segregation,
and
‘Children
seclusion’, ‘Do not attempt CPR decisions’,
and
Young People's Mental Health’
‘Provider collaboration’
are examples of recent thematic data reviews/themed inspections that helped/ are helping
[8 words unchanged]
provision of care in these areas with a focus on future improvement.
CQC insight and associated dashboards are regularly updated. Outlier analyses are undertaken on a monthly or
bi-monthly
two-monthly
basis.
Data packs/evidence tables are created on an on-going basis for impending inspections.
National reporting is a combination of predominantly annual reports as well as topic-specific reports released on a one-off basis.
Where CQC identifies poor care, or where the standards of registration are not being met, CQC can use its enforcement policy as set out in Section 5a objective for processing. Such action is targeted to drive improvements or, in extreme cases, protect the public from access to poor quality services.
Monitoring of mortality is the only area where CQC has had to make changes in its use of indicators derived from the requested datasets.
With the new v5 data set we anticipate being able to progress this work, and achieving the benefits to our regulatory programmes.
Benefits reported
CQC
The creation of CQC’s new Data & Insight Unit
has
embedded
started to embed and improve on
its
previous
insight programme and
associate dashboards over the last four years.
associated dashboards.
Core data from this data sharing agreement were used in the production of
indictors
indicators
that align to CQC’s key lines of enquiry for a particular sector
[23 words unchanged]
have pointed to services where the quality of care may be improving.
These data are also used
in the
to inform planning
regulatory
activity (including to inform inspection
planning
meetings (RPMs) as well as in the production of pre-inspection data evidence grids and dashboards. These have allowed lead inspectors to decide which core services to inspect.
decisions).
The data have provided the groundwork for inspectors to approach identified areas
[7 words unchanged]
a clear focus during the intensive inspection process. The data used in
these
Insight
products help to derive an ongoing assessment of the quality of core
[27 words unchanged]
of using quality benchmarks to raise standards both within and across organisations.
Side-by-side with this process, CQC’s outliers programme has continued to monitor and review potential outliers of high mortality and readmission rates. CQC received data from Dr Foster Intelligence Ltd that provided an additional route for identification in addition to CQC’s own. Where concerns were identified, these were taken up by the relevant relationship owner in conjunction with appropriate analytical support to understand whether an issue existed and, where this might have been the case, whether the trust were aware of the concern and what remedial action had been put in place. The mortality data are therefore used to provide a fundamental resource in the understanding of the quality of the provision of care and provide a tool to highlight where possible concerns may exist and where further investigation is required.
CQC has made extensive use of NHS Digital data within its insight pre-inspection activity within the hospital/ Mental Health sectors. The core NHS Digital data acts to highlight any particular concerns (or good practice) that would then be followed up between an inspector and a given organisation or used to determine where an inspection might be focused. The reports provide trust-level indicators and national comparisons from the most readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
CQC has made extensive use of NHS Digital data within its insight pre-inspection activity within the hospital/ Mental Health sectors. Over the previous 12 months, the CQC response to Covid has been to focus more heavily on the information it receives in helping determine levels of risk and the development of dashboards. These provide a breakdown of analysis by highlighted service (for example, surgery) and allow the inspection team to determine where to focus the inspection. The reports provide trust-level indicators and national comparisons from the most-readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
[1 paragraph unchanged]
Further reviews of the ratings and analyses of NHS Digital featured in the
2019/20
2020/21
State of Care report. This year, it highlighted the impact of the
[7 words unchanged]
provide a high-level commentary on year-on-year changes to care provision within England.
Over 2021/22 CQC issued 100 letters of intent to Hospital services across England where CQC identified poor care or where the standards of registration were not being met. However, these levels were likely to be lower than for other years, as this period covers the pandemic during which CQC reduced the number of inspections to a minimum level across Hospital services.
CQC continues to monitor a suite of indicators covering secondary health acute services.
In addition, CQC has a suite of indicators relating to safety and quality in mental health services for which it uses the Mental health services dataset.
CQC is also developing analytical methodologies to present data at core service level for Mental health services.
Core services are the unit of rating for CQC's assessments of mental health services, and our objective is to present more granular analysis from MHSDS (and other sources) mapped to these services.
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of health and care providers. CQC’s remit is to make sure health and adult social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. Its role will be expanded to encompass an assessment of quality for Integrated Care Systems (ICSs) and assurance of Local Authorities – in relation to their respected roles for health and adult social care. Its regulatory model is underpinned by a Data & Insight programme that draws together indicators of quality and risk about services. The data directly influence the risk and benchmarking models used to prioritise regulatory activity and inform its judgements of quality in services. The datasets also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act and to deliver national reports to parliament. Processing these data allow CQC to meet this public benefit.
Access to these data help to ensure CQC can make use of its wide set of powers to protect people who use regulated services from harm and the risk of harm, and to ensure they receive health and social care services of an appropriate standard. These powers also hold registered providers and managers to account for failures in how the service is provided. CQC's enforcement policy sets out CQC's approach to taking action where CQC identify poor care, or where registered providers and managers do not meet the standards required in the regulations. The level of enforcement is dependent on many factors but start at a requirement notice (stipulating a timeframe within which a given improvement must take place) for a less serious breach up to the possible cancellation of services in extreme cases.
For record-level data, CQC will process these data lawfully under GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 under which CQC was formed and has a duty of confidentiality under enactment set out in sections 76 and 77. As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) – processing is necessary for reasons of public interest in the area of public health in that CQC’s remit is to make sure that health and adult social care services provide people with safe, effective, compassionate, high-quality care. As per the Information Commissioner’s Officer (ICO) guidance; if an organisation is relying on Article 9(2)(i), they also need to meet the associated condition in UK law, set out in Part 1 of Schedule 1 of the DPA 2018. For Public health, this condition is met if the processing is necessary for reasons of public interest in the area of public health (as illustrated above). This condition is also met if the processing is carried out by another person who in the circumstances owes a duty of confidentiality under an enactment or rule of law, and CQC has a duty of confidentiality under enactment set out in sections 76 and 77.
CQC's statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS Digital (Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment was finalised on 31 May 2019 and subsequently reviewed 04 December 2020. It is currently undergoing review (September 2022).
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and the legacy Mental Health and Learning Disabilities Dataset, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Monthly extracts ensure CQC have access to the most up-to-date data for ongoing analyses and oversight - particularly important in understanding an organisation's most recent performance. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
CQC use these data (i) to populate indicators within their Data & Insight Unit products and associated dashboards, to support prioritisation of regulatory activity (including inspections) and to inform judgements about the level of quality in services (ii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iii) towards CQC's statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; (iv) in thematic reviews and national reporting; for example, the Annual State of Care report and (v) to support the development and implementation of CQC’s new remit to assess ICSs and Local Authorities (with respect to health and care responsibilities).
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: 'postcode' and 'local patient identifier'. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. 'Local patient identifier' is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient's postcode is used for assigning data to new LA/CCG boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continues to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The latest review again focused on requests submitted to the CQC central analytical team. CQC has confirmed that, in the review period, analyses were still conducted on the postcode and local patient identifier fields. This application requests three additional patient identifying fields from MHSDS. Future analyses using birth date, death date, and unique restrictive intervention incident ID from the MHSDS data set will support work related to mortality and for monitoring Use Of Force Act 2018. Unique restrictive intervention incident ID has been requested to facilitate monitoring of restrictive interventions. The Mental Health Units (Use of Force) Act 2018 CHAPTER 27 makes provision about the oversight and management of the appropriate use of force in relation to people in mental health units; to make provision about the use of body cameras by police officers in the course of duties in relation to people in mental health units; and for connected purposes. CQC's statutory powers under s9(a) allow it to require information about restrictive interventions for the purposes of investigation of deaths and serious injury.
The Health and Social Care Act 2008 imposes notifications requirements for NHS bodies, which are managed and processed by CQC, which has a duty under the Mental Health Act 1983 (MHA) to monitor how services exercise their powers and discharge their duties when patients are detained in hospital, subject to community treatment orders or guardianship.
Among these are
• Reg 16: Death of a person who uses the service
• Reg 17: Deaths of people detained or liable to be detained under the Mental Health Act
The availability of Date of Death allows us to verify whether we have received all death notifications from a provider for a period. Indicators will be related to absence of notification, or its completeness.
• Reg 18: Other incidents: Admission of a child or young person to an adult psychiatric ward or unit
Date of Birth allows us to know whether a child or young person was admitted to an adult ward and produce an indicator. It will also inform analysis of interventions related to age.
CQC's use of identifying data is subject to CQC's statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’) clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
CQC is the sole data controller and also processes the data. Now held on Microsoft Azure’s cloud environment, the NHS Digital data will only be accessed by CQC substantive employees and non-substantive employees (contractors). Where CQC used non-substantive employees (contractors), CQC would insist on confidentiality clauses within contracts and oblige individuals to complete in-house training on data protection and confidentiality. The local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
Expected output
On-going produced outputs include:
-incorporates data indicators that align to CQC's assessment framework for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Over the course of the Covid pandemic lockdown, CQC took the decision that it would desist from on-site inspection unless the matter was a threat to life. The emphasis shifted to monitoring the NHS Digital data and other sources, including concerns from the public. With excessive mortality rates through Covid, some of the key indicators below were suspended; for example, mortality outliers. The outputs listed below therefore contain what CQC anticipate (and have experienced) outside of lockdown.
Insight products (which includes a range of dashboards and outputs that support monitoring and judgement), including outputs that are shared with providers. These products use aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes. As the new CQC Data & Insight Unit takes shape over the next twelve months, additional dashboards and early alerts are expected to become available for inspectors.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on 'Perinatal mortality and neonatal readmissions' used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Dr Foster Intelligence Ltd (now known as Telstra) - investigated death rates for endoscopic procedures. On the latter, CQC review their own available NHS Digital data to make a decision on the highlighted risk with reference to local intelligence known about the trust. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. The impact of COVID led to CQC suspending its mortality outlier processes, but its approach to monitoring mortality will be reviewed over the next 12 months.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2020/21 publication appeared in February 2022.
Thematic reviews: used internally to inform CQC’s regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS Digital's HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
The creation of CQC’s new Data & Insight Unit has started to embed and improve on its previous insight programme and associated dashboards. Core data from this data sharing agreement were used in the production of indicators that align to CQC’s key lines of enquiry for a particular sector (e.g., hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used to inform planning regulatory activity (including to inform inspection planning decisions). The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in Insight products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted, and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
CQC has made extensive use of NHS Digital data within its insight pre-inspection activity within the hospital/ Mental Health sectors. The core NHS Digital data acts to highlight any particular concerns (or good practice) that would then be followed up between an inspector and a given organisation or used to determine where an inspection might be focused. The reports provide trust-level indicators and national comparisons from the most readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality-of-care provision and examples of good practice that other organisations could adopt. The NHS Digital data are therefore critical in this process for driving up the quality-of-care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS Digital featured in the 2020/21 State of Care report. This year, it highlighted the impact of the pandemic as part of its design to provide a high-level commentary on year-on-year changes to care provision within England.
Over 2021/22 CQC issued 100 letters of intent to Hospital services across England where CQC identified poor care or where the standards of registration were not being met. However, these levels were likely to be lower than for other years, as this period covers the pandemic during which CQC reduced the number of inspections to a minimum level across Hospital services.
CQC continues to monitor a suite of indicators covering secondary health acute services.
In addition, CQC has a suite of indicators relating to safety and quality in mental health services for which it uses the Mental health services dataset.
CQC is also developing analytical methodologies to present data at core service level for Mental health services.
Core services are the unit of rating for CQC's assessments of mental health services, and our objective is to present more granular analysis from MHSDS (and other sources) mapped to these services.
DARS-NIC-359603-D2Q6M-v8.4 1 June 2021 to 31 May 2022
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 15
- Files released
- 158
Datasets: Civil Registrations of Death; Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES-ID to MPS-ID HES Accident and Emergency; HES-ID to MPS-ID HES Admitted Patient Care; HES-ID to MPS-ID HES Outpatients; HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Services Data Set (MHSDS)
What changed from DARS-NIC-359603-D2Q6M-v7.2
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2021-06-01 | |
| End date | 2022-05-31 |
Datasets:
+ Civil Registrations of Death; + HES-ID to MPS-ID HES Accident and Emergency; + HES-ID to MPS-ID HES Admitted Patient Care; + HES-ID to MPS-ID HES Outpatients · − Bridge file: Hospital Episode Statistics to Mental Health Minimum Data Set; − Mental Health Minimum Data Set (MHMDS)
Objective for processing
[3 paragraphs unchanged]
As part of the process for weighing up the risk of potential
[13 words unchanged]
of its use for the organisation, a Data Protection Impact Assessment was
undertaken and
finalised on 31 May
2019.
2019 and subsequently reviewed 04 December 2020.
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and
the
legacy
datasets,
Mental Health and Learning Disabilities Dataset,
Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files.
With the phasing out of the HES mortality file, CQC is now requesting access to the civil registration mortality file as a replacement with the addition of the Token_Person_ID field that will allow linkage between NHS datasets, once this field is embedded in their outputs.
These data are received at record-level and cover activity within the whole
[29 words unchanged]
and allow CQC to identify trends/ themes in organisations’ provision of care.
To expand on the Mental Health legacy datasets, these include Mental Health & Learning Disabilities Dataset, Mental Health Minimum Dataset, and KP90 Dataset.
CQC use these data (i) to populate indicators within their Intelligent insight products and associated dashboards, which help CQC focus inspections of providers by deciding when, where and what to inspect; (ii) to construct evidence tables / data packs, which bring together information and analysis for each provider and are used for inspection planning; (iii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iv) towards CQC’s statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; and (v) in thematic reviews and national reporting; for example, the Annual State of Care report.
CQC use these data (i) to populate indicators within their Intelligent insight products, which help CQC focus inspections of providers by deciding when, where and what to inspect; (ii) to construct evidence tables / data packs, which bring together information and analysis for each provider and are used for inspection planning; (iii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iv) towards CQC’s statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; and (v) in thematic reviews and national reporting; for example, the Annual State of Care report.
[1 paragraph unchanged]
CQC continues to review its use of identifiers and whether the amount
[41 words unchanged]
the period of data, it concluded that CQC only needed to retain
a rolling period of 5 full FY years (annual refresh or equivalent) plus the current in-year data.
data from 2014/15.
Subsequently, all data older than 2014/15 have been deleted from CQC systems. This covers HES, HES-associated data, and all of MHMDS.
The detail is set out in the data destruction form.
[1 paragraph unchanged]
CQC is the sole data controller and also processes the data. Atos
is
was
CQC’s ICT service provider and was engaged through the IMS3 framework contract, let by the Department of
Health.
Health and Social Care.
This contract
was due to come
came
to an end at the end in March 2020 but was temporarily extended while
CQC requested
this Agreement
permitting
was finalised to permit
these data to be stored within the cloud environment of Microsoft Azure.
Full details have been submitted to, and approved by, NHS Digital’s security consultant. Under this Agreement, the
The
data
will be
were subsequently
transferred from Atos to Microsoft Azure.
Atos will then confirm
An NHS Digital data
destruction
of all copies
form has now been submitted and this version
of the
data previously held on its servers and CQC will request a further amendment to this Data Sharing Agreement to remove Atos as an approved Data Processor.
agreement removes Atos.
Once stored in
Now transferred to
Microsoft Azure’s cloud environment, the
data from
NHS Digital
data
will only be accessed by substantive employees of CQC but note that
[12 words unchanged]
identify patient notes to review, as detailed below in the Benefits section.
Capgemini has been commissioned to transfer the data from the current storage to the Microsoft Azure platform (discussed in separate technical response). Capgemini will have no access to the underlying data and will therefore not be processing the data. There are no other organisations involved in the wider project nor any commissioners involved. NHS Digital has considered the nature of Capgemini's role in moving the data from the old system to the Microsoft Azure platform and is content that Capgemini is not a data processor given that because the data are encrypted Capgemini is unable to access, view, modify the data whilst Capgemini will be transferring the data in this respect without the keys it is not possible for Capgemini to have access to the data to act as a data processor.
Processing activities
There is no associated flow of data into NHS Digital. The data
[19 words unchanged]
health data (see reference to GDPR Article 9(2)(i) above). CQC currently downloads
and manages
the NHS Digital extracts
to its server sited
within
a secure area
Microsoft Azure following transfer
of the
Experian Data Centre held in Nottingham, which conforms to ISO 27001. All
data
stored on this server is
from its previous storage
managed by
Atos, CQC’s
Atos (CQC's former
ICT
provider. Physical
provider). Encryption and
access
is limited to authorised data centre support staff. Any access
controls were set out in the technical submission sent
to the
data centre by other engineers or visitors must be separately booked in advance and authorised by Atos or Experian. All access by this means is supervised whilst on site. Atos has been
NHS Digital security consultant prior to
the
supplier
agreed transfer. As part
of
CQC’s ICT infrastructure. In essence, Atos hires an area within
the transfer agreement,
the data
centres. There is no interaction with Experian
on the Atos-managed servers have been deleted. Atos decommissioned the storage/ processing areas
and
the
an NHS Digital
data
and CQC confirms their involvement as limited to providing ‘bricks and mortar’.
destruction form was completed. Atos have now been removed from this data sharing agreement.
CQC regional offices are connected to the CQC WAN (Wide Area Network) which in turn is connected to the Atos data centres via secure remote access. Atos are responsible for the ICT infrastructure on which the data are held. Atos are not involved in any transformation of the data.
The extracts currently held by CQC (HES, civil registration mortality for HES mortality, MHSDS, CSDS, MSDS, ECDS and associated datasets) include a bridging file between HES and MHSDS to follow treatment along care pathways. As discussed above, CQC are applying for the civil registration mortality file (with Token_Person_ID) to replace the HES mortality file that is being phased out. The introduction of the Token_Person_ID into the other datasets will allow linkage between the listed NHS Digital data (and remove the need for the HES-MHSDS bridging file) to ensure the optimum use of these extracts. The NHS Digital data will not be linked to any other sources and any proposal to do so would be subject to a further application with NHS Digital. CQC can confirm that there will be no attempt to re-identify individuals with the sole exception of trusts using Local Patient Identifier to identify patients whose care appears problematic where strictly necessary.
This Agreement permits the transfer of data from the Experian data centre to the cloud environment of Microsoft Azure (as set out and agreed in CQC's technical response to NHS Digital's cloud-hosting requirements). The contract with Atos is being terminated and CQC will manage its data within Microsoft Azure. Encryption and access controls are set out in the technical submission sent to the NHS Digital security consultant. CQC's contract with Atos and the storage of data within the Experian data centre will continue until data is transferred to Microsoft Azure. The data on the Atos-managed servers will then be deleted. At that point, Atos will cease to have oversight of the ICT arrangements and the servers on which the data currently reside will undergo degaussing. This will ensure any remnants of the data are irretrievably destroyed.
The extracts currently held by CQC (HES, civil registration mortality, MHSDS, CSDS, MSDS, ECDS and associated datasets) include a bridging file between HES and MHSDS to follow treatment along care pathways. The community (CSDS), maternity (MSDS), and emergency care (ECDS) extracts will be supplied with linkage to HES or to MHSDS - once available - to ensure the best use of these extracts. CQC will link NHS Digital data sets. The NHS Digital data will not be linked to any other sources and any proposal to do so would be subject to a further application with NHS Digital. CQC can confirm that there will be no attempt to re-identify individuals with the sole exception of trusts using Local Patient Identifier to identify patients whose care appears problematic where strictly necessary.
[1 paragraph unchanged]
Aggregated data summarised to organisation level is fed into a data warehouse
[31 words unchanged]
to such outputs are only made available to named individuals within the
Strategy and Intelligence,
Intelligence
and Digital directorates. At this time, processing is only carried out by
[27 words unchanged]
and oblige individuals to complete in-house training on data protection and confidentiality.
[14 paragraphs unchanged]
Expected output
[7 paragraphs unchanged]
Pre-inspection data evidence
grids:
grids and monitoring dashboards:
used by the inspections teams and shared with providers. This is aggregate
[42 words unchanged]
and provides high-level information to the inspection team for planning/ review purposes.
[1 paragraph unchanged]
National Reporting: used to support the creation and population of national reports
[45 words unchanged]
MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the
2018/19
2019/20
publication appeared in February
2020.
2021.
[3 paragraphs unchanged]
Expected measurable benefits
[2 paragraphs unchanged]
- Are they
safe
safe?
- Are they
effective
effective?
- Are they
caring
caring?
[2 paragraphs unchanged]
HES,
MHSDS
MHSDS, EDDS
and associated data are used to determine key performance indicators in the
[15 words unchanged]
total, provide a view on the quality of the provision of care.
MSDS,
CSDS
and ECDS have only recently been received and are
is
undergoing internal review
but
and
will be used for the same purposes to generate similar
outputs.
outputs; likewise, MSDS, once the extracts are more readily available.
[4 paragraphs unchanged]
CQC insight
is
and associated dashboards are
regularly updated. Outlier analyses are undertaken on a monthly or bi-monthly basis.
[19 words unchanged]
annual reports as well as topic-specific reports released on a one-off basis.
Benefits reported
CQC has embedded its
new
insight programme
and associate dashboards
over the last
three
four
years. Core data from this data sharing agreement were used in the production of indictors that align to CQC’s key lines of enquiry for a particular sector
(e.g.
(e.g.,
hospitals). The indicators have been used to highlight the greatest risks to
[10 words unchanged]
have pointed to services where the quality of care may be improving.
These data are also used in the regulatory planning meetings (RPMs) as well as in the production of pre-inspection data evidence
grids.
grids and dashboards.
These have allowed lead inspectors to decide which core services to inspect.
[37 words unchanged]
ongoing assessment of the quality of core services. Areas of concern are
highlighted
highlighted,
and remedial action is monitored to follow up improvements. Additionally, areas of
[9 words unchanged]
of using quality benchmarks to raise standards both within and across organisations.
[1 paragraph unchanged]
CQC has made extensive use of NHS Digital data within its insight pre-inspection
reports
activity
within the hospital/
MH
Mental Health
sectors. Over the previous 12 months,
the
CQC
have produced approximately 150
response to Covid has been to focus more heavily on the information it receives in helping determine levels
of
these reports, which
risk and the development of dashboards. These
provide a breakdown of analysis by highlighted service (for example, surgery) and
[26 words unchanged]
allow the inspection team to hone in on particular areas of interest.
An
Where this has been necessary, an
inspection report and associated ratings are then published.
The published reports included recommendations for improving the
quality of care
quality-of-care
provision and examples of good practice that other organisations could adopt. The NHS Digital data are therefore critical in this process for driving up the
quality of care
quality-of-care
provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS Digital featured in the
2017/18
2019/20
State of Care
report that is designed
report. This year, it highlighted the impact of the pandemic as part of its design
to provide a high-level commentary on year-on-year changes to care provision within England.
This year, it highlighted the ‘safety’ domain as a particular concern with the aim of creating debate and policy changes to make long-term improvements in this area.
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of care providers. CQC’s remit is to make sure health and social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. It does that through effective monitoring and inspection activity underpinned by an Intelligence insight programme that draws together risk and bench marking metrics at core service level. The data directly influence the risk and benchmarking models and help determine both when inspections take place and where they should focus. They also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act.
For record-level data, CQC will process these data lawfully under GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 (under which CQC was formed). As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) in, ‘processing is necessary for reasons of public interest in the area of public health, such as…ensuring high standards of quality and safety of health care…on the basis of Union or Member State law…’.
CQC’s statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS Digital (Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test. CQC’s core purpose is to seek to protect the public from poor provision of care, highlight good practice, and publish information (for example, inspection reports and ratings) that allow the public an improved understanding of the quality of provision of care by individual providers. Processing these data allow CQC to meet that public benefit.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment was finalised on 31 May 2019 and subsequently reviewed 04 December 2020.
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and the legacy Mental Health and Learning Disabilities Dataset, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. With the phasing out of the HES mortality file, CQC is now requesting access to the civil registration mortality file as a replacement with the addition of the Token_Person_ID field that will allow linkage between NHS datasets, once this field is embedded in their outputs. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
CQC use these data (i) to populate indicators within their Intelligent insight products and associated dashboards, which help CQC focus inspections of providers by deciding when, where and what to inspect; (ii) to construct evidence tables / data packs, which bring together information and analysis for each provider and are used for inspection planning; (iii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iv) towards CQC’s statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; and (v) in thematic reviews and national reporting; for example, the Annual State of Care report.
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: ‘postcode’ and ‘local patient identifier’. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. ‘Local patient identifier’ is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient’s postcode is used for assigning data to new LA/CCG boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continues to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The latest review again focused on requests submitted to the CQC central analytical team. CQC has confirmed that, in the review period, analyses were still conducted on the held identifiers. With respect to the period of data, it concluded that CQC only needed to retain data from 2014/15. Subsequently, all data older than 2014/15 have been deleted from CQC systems. This covers HES, HES-associated data, and all of MHMDS. The detail is set out in the data destruction form.
CQC’s use of identifying data is subject to CQC’s statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’), clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
CQC is the sole data controller and also processes the data. Atos was CQC’s ICT service provider and was engaged through the IMS3 framework contract, let by the Department of Health and Social Care. This contract came to an end at the end in March 2020 but was temporarily extended while this Agreement was finalised to permit these data to be stored within the cloud environment of Microsoft Azure. The data were subsequently transferred from Atos to Microsoft Azure. An NHS Digital data destruction form has now been submitted and this version of the agreement removes Atos.
Now transferred to Microsoft Azure’s cloud environment, the NHS Digital data will only be accessed by substantive employees of CQC but note that the local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
Expected output
On-going produced outputs include risk-based monitoring through CQC insight:
-incorporates data indicators that align to CQC’s key lines of enquiry for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England/ NHS Improvement. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Pre-inspection data evidence grids and monitoring dashboards: used by the inspections teams and shared with providers. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on ‘Perinatal mortality and neonatal readmissions’ used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Dr Foster Intelligence Ltd - investigated death rates for endoscopic procedures. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2019/20 publication appeared in February 2021.
Thematic reviews: used internally to inform CQC's regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS Digital’s HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In the monitoring of organisations for ongoing compliance against essential quality and safety standards, CQC uses screening techniques in its CQC insight tools, which analyse a wide variety of data sources to highlight possible outlying concerns that trigger actions where concerns are raised. Such screening methods are aided by a more local approach to information gathering and analysis, which is being developed in consultation with appropriate stakeholders. These techniques, currently along with national surveys of patients, help to create a more holistic understanding in informing its work with ongoing compliance, investigations, and thematic reviews.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
CQC has embedded its insight programme and associate dashboards over the last four years. Core data from this data sharing agreement were used in the production of indictors that align to CQC’s key lines of enquiry for a particular sector (e.g., hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used in the regulatory planning meetings (RPMs) as well as in the production of pre-inspection data evidence grids and dashboards. These have allowed lead inspectors to decide which core services to inspect. The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in these products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted, and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
Side-by-side with this process, CQC’s outliers programme has continued to monitor and review potential outliers of high mortality and readmission rates. CQC received data from Dr Foster Intelligence Ltd that provided an additional route for identification in addition to CQC’s own. Where concerns were identified, these were taken up by the relevant relationship owner in conjunction with appropriate analytical support to understand whether an issue existed and, where this might have been the case, whether the trust were aware of the concern and what remedial action had been put in place. The mortality data are therefore used to provide a fundamental resource in the understanding of the quality of the provision of care and provide a tool to highlight where possible concerns may exist and where further investigation is required.
CQC has made extensive use of NHS Digital data within its insight pre-inspection activity within the hospital/ Mental Health sectors. Over the previous 12 months, the CQC response to Covid has been to focus more heavily on the information it receives in helping determine levels of risk and the development of dashboards. These provide a breakdown of analysis by highlighted service (for example, surgery) and allow the inspection team to determine where to focus the inspection. The reports provide trust-level indicators and national comparisons from the most-readily available data and so allow the inspection team to hone in on particular areas of interest. Where this has been necessary, an inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality-of-care provision and examples of good practice that other organisations could adopt. The NHS Digital data are therefore critical in this process for driving up the quality-of-care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS Digital featured in the 2019/20 State of Care report. This year, it highlighted the impact of the pandemic as part of its design to provide a high-level commentary on year-on-year changes to care provision within England.
DARS-NIC-359603-D2Q6M-v7.2 1 May 2020 to 31 May 2021
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 13
- Files released
- 251
Datasets: Bridge file: Hospital Episode Statistics to Mental Health Minimum Data Set; Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Minimum Data Set (MHMDS); Mental Health Services Data Set (MHSDS)
What changed from DARS-NIC-359603-D2Q6M-v6.2
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2020-05-01 | |
| End date | 2021-05-31 | |
| Bridge file: Hospital Episode Statistics to Mental Health Minimum Data Set: common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Civil Registrations of Death - Secondary Care Cut: common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Community Services Data Set (CSDS): common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Emergency Care Data Set (ECDS): common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| HES:Civil Registration (Deaths) bridge: common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Hospital Episode Statistics Accident and Emergency (HES A and E): common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Hospital Episode Statistics Admitted Patient Care (HES APC): common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Hospital Episode Statistics Critical Care (HES Critical Care): common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Hospital Episode Statistics Outpatients (HES OP): common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| MSDS (Maternity Services Data Set) v1.5: common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Mental Health Minimum Data Set (MHMDS): common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Mental Health Services Data Set (MHSDS): common law duty of confidentiality | Statutory exemption to flow confidential data without consent | |
| Mental Health and Learning Disabilities Data Set (MHLDDS): common law duty of confidentiality | Statutory exemption to flow confidential data without consent |
Objective for processing
[3 paragraphs unchanged]
As part of the process for weighing up the risk of potential
[7 words unchanged]
of data against the public benefit of its use for the organisation,
CQC's Caldicott Guardian conducted an internal review and signed it off for the previous iteration of this Data Sharing Agreement to determine the necessity of the data released by NHS Digital under previous iterations of this Agreement and the data (and new datasets) under this Agreement. With the augmentation of additional datasets (as discussed below),
a Data Protection Impact Assessment was undertaken and finalised on 31 May 2019.
CQC currently has receipt/use of
HES (inpatient,
Hospital Episode Statistics (HES) inpatient,
outpatient, critical care, and
A&E), MHSDS (and
A&E, Mental Health Services Data Set (MHSDS) and
legacy
datasets),
datasets, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS),
civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These
[40 words unchanged]
and allow CQC to identify trends/ themes in organisations’ provision of care.
To expand on the Mental Health legacy datasets, these include Mental Health & Learning Disabilities Dataset, Mental Health Minimum Dataset, and KP90 Dataset.
CQC has not held nor processed Learning Disabilities Census data under any of the past iterations of this Agreement.
[1 paragraph unchanged]
Under this Agreement, CQC are also requesting access to:
• the Maternity Services Data Set (MSDS) to improve its ability to report on this sector;
• the Community Services Dataset (CSDS) to develop a community-specific Intelligence insight product) and emergency care;
• the Emergency Care Data Set (ECDS) to provide a parallel feed to HES A&E and create new metrics as this product is rolled out/replaces the HES Accident & Emergency dataset.
[1 paragraph unchanged]
CQC
continue
continues
to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The
latest
review
focuses
again focused
on requests submitted to the CQC central analytical team.
It
CQC has
confirmed that, in the review period, analyses were still conducted on the held
identifiers and over
identifiers. With respect to
the
full
period of
retained HES. For MHMDS, no use had
data, it concluded that CQC only needed to retain a rolling period of 5 full FY years (annual refresh or equivalent) plus the current in-year data. Subsequently, all data older than 2014/15 have
been
made
deleted from CQC systems. This covers HES, HES-associated data, and all
of
2008/09 and 2009/10 data and a decision was taken to delete these years from the system. These years of MHMDS data will be removed from this Data Sharing Agreement in the next iteration, by which time deletion will have taken place.
MHMDS.
[1 paragraph unchanged]
CQC is the sole data controller and also processes the data.
Atos is a data processor for CQC.
Atos is CQC’s ICT service provider and was engaged through the IMS3 framework contract, let by the Department of Health.
The data from NHS Digital will only be processed by substantive employees of CQC and ATOS (note that the local patient identifier may be shared with the originating Trust
This contract was due
to
identify patient notes
come
to
review, as detailed below in the Benefits section). CQC wish to flag that the IMS3 contract will be expiring
an end
at the end
in March 2020 but was temporarily extended while CQC requested this Agreement permitting these data to be stored within the cloud environment of Microsoft Azure. Full details have been submitted to, and approved by, NHS Digital’s security consultant. Under this Agreement, the data will be transferred from Atos to Microsoft Azure. Atos will then confirm destruction of all copies
of the
2019/20 financial year. A new supplier(s) for these services
data previously held on its servers and CQC
will
be agreed over the course of the next 12 months. Any such change will result in an
request a further
amendment
of
to
this Data Sharing Agreement
before the new changes can take effect.
to remove Atos as an approved Data Processor.
There are no other organisations involved in the wider project nor any commissioners involved.
Once stored in Microsoft Azure’s cloud environment, the data from NHS Digital will only be accessed by substantive employees of CQC but note that the local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
Capgemini has been commissioned to transfer the data from the current storage to the Microsoft Azure platform (discussed in separate technical response). Capgemini will have no access to the underlying data and will therefore not be processing the data. There are no other organisations involved in the wider project nor any commissioners involved. NHS Digital has considered the nature of Capgemini's role in moving the data from the old system to the Microsoft Azure platform and is content that Capgemini is not a data processor given that because the data are encrypted Capgemini is unable to access, view, modify the data whilst Capgemini will be transferring the data in this respect without the keys it is not possible for Capgemini to have access to the data to act as a data processor.
Processing activities
There is no associated flow of data into NHS Digital. The data
[17 words unchanged]
of personal health data (see reference to GDPR Article 9(2)(i) above). CQC
download
currently downloads
the NHS Digital extracts to its server sited within a secure area
[57 words unchanged]
or Experian. All access by this means is supervised whilst on site.
ATOS supply
Atos has been the supplier of
CQC’s ICT
infrastructure
infrastructure. In essence, Atos hires an area within the data centres. There is no interaction with Experian
and
are certificated
the data and CQC confirms their involvement as limited
to
ISO 27001.
providing ‘bricks and mortar’.
In essence, Atos hire an area within the data centres. There is no interaction with Experian and the data and CQC confirms their involvement as limited to providing ‘bricks and mortar’.
[1 paragraph unchanged]
The extracts currently held by CQC (HES, civil registration mortality, MHSDS and associated datasets) include a bridging file between HES and MHSDS to follow treatment along care pathways. The additional community (CSDS), maternity (MSDS), and emergency care (ECDS) extracts will be supplied with linkage to HES or to MHSDS to ensure the best use of these extracts. CQC will link all NHS Digital data together (as some datasets do not hold a bridge file). The NHS Digital data will not be linked to any other sources and any proposal to do so would be subject to a further application with NHS Digital. CQC can confirm that there will be no attempt to re-identify individuals with the sole exception of trusts using Local Patient Identifier to identify patients whose care appears problematic where strictly necessary.
This Agreement permits the transfer of data from the Experian data centre to the cloud environment of Microsoft Azure (as set out and agreed in CQC's technical response to NHS Digital's cloud-hosting requirements). The contract with Atos is being terminated and CQC will manage its data within Microsoft Azure. Encryption and access controls are set out in the technical submission sent to the NHS Digital security consultant. CQC's contract with Atos and the storage of data within the Experian data centre will continue until data is transferred to Microsoft Azure. The data on the Atos-managed servers will then be deleted. At that point, Atos will cease to have oversight of the ICT arrangements and the servers on which the data currently reside will undergo degaussing. This will ensure any remnants of the data are irretrievably destroyed.
The extracts currently held by CQC (HES, civil registration mortality, MHSDS, CSDS, MSDS, ECDS and associated datasets) include a bridging file between HES and MHSDS to follow treatment along care pathways. The community (CSDS), maternity (MSDS), and emergency care (ECDS) extracts will be supplied with linkage to HES or to MHSDS - once available - to ensure the best use of these extracts. CQC will link NHS Digital data sets. The NHS Digital data will not be linked to any other sources and any proposal to do so would be subject to a further application with NHS Digital. CQC can confirm that there will be no attempt to re-identify individuals with the sole exception of trusts using Local Patient Identifier to identify patients whose care appears problematic where strictly necessary.
[1 paragraph unchanged]
Aggregated data summarised to organisation level is fed into a data warehouse
[15 words unchanged]
as well as supporting ad hoc reporting. Where these outputs may contain
low numbers,
small numbers suppressed,
access to such outputs are only made available to named individuals within
[24 words unchanged]
data protection and confidentiality. If CQC were to use non-substantive employees, CQC
would
insist on confidentiality clauses within contracts and oblige individuals to complete in-house training on data protection and confidentiality.
[12 paragraphs unchanged]
There will be no data linkage undertaken with NHS Digital data provided under this Agreement that is not already noted in the Agreement.
Data will only be accessed and processed by substantive employees of the Care Quality Commission and will not be accessed or processed by any other third parties not mentioned in this Agreement.
Expected output
[8 paragraphs unchanged]
Outliers
Programme :
Programme:
analysis of certain metrics derived from these data are shared with trusts
[83 words unchanged]
in line with the CQC suppression rules as specified in processing activities.
National Reporting: used to support the creation and population of national reports
[45 words unchanged]
MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the
2017/18
2018/19
publication appeared in February
2019.
2020.
[3 paragraphs unchanged]
Expected measurable benefits
[7 paragraphs unchanged]
HES, MHSDS and associated data are used to determine key performance indicators
[21 words unchanged]
on the quality of the provision of care. MSDS, CSDS and ECDS
have only recently been received and are undergoing internal review but
will be used for the same purposes to generate similar outputs.
[3 paragraphs unchanged]
Thematic reviews provide in-depth analyses of chosen topics to inform CQC staff,
[53 words unchanged]
hospitals’ and ‘Children and Young People's Mental Health’ are examples of recent
and current
thematic data reviews/themed inspections that helped/ are helping to raise specific questions on the monitoring and provision of care in these areas with a focus on future improvement.
[1 paragraph unchanged]
Benefits reported
CQC has
been embedding
embedded
its new insight programme over the last
two
three
years. Core data from this data sharing agreement were used in the
[38 words unchanged]
have pointed to services where the quality of care may be improving.
[5 paragraphs unchanged]
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of care providers. CQC’s remit is to make sure health and social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. It does that through effective monitoring and inspection activity underpinned by an Intelligence insight programme that draws together risk and bench marking metrics at core service level. The data directly influence the risk and benchmarking models and help determine both when inspections take place and where they should focus. They also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act.
For record-level data, CQC will process these data lawfully under GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 (under which CQC was formed). As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) in, ‘processing is necessary for reasons of public interest in the area of public health, such as…ensuring high standards of quality and safety of health care…on the basis of Union or Member State law…’.
CQC’s statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS Digital (Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test. CQC’s core purpose is to seek to protect the public from poor provision of care, highlight good practice, and publish information (for example, inspection reports and ratings) that allow the public an improved understanding of the quality of provision of care by individual providers. Processing these data allow CQC to meet that public benefit.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, a Data Protection Impact Assessment was undertaken and finalised on 31 May 2019.
CQC currently has receipt/use of Hospital Episode Statistics (HES) inpatient, outpatient, critical care, and A&E, Mental Health Services Data Set (MHSDS) and legacy datasets, Community Services Data Set (CSDS), Maternity Services Data Set (MSDS), Emergency Care Data Set (ECDS), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
To expand on the Mental Health legacy datasets, these include Mental Health & Learning Disabilities Dataset, Mental Health Minimum Dataset, and KP90 Dataset.
CQC use these data (i) to populate indicators within their Intelligent insight products, which help CQC focus inspections of providers by deciding when, where and what to inspect; (ii) to construct evidence tables / data packs, which bring together information and analysis for each provider and are used for inspection planning; (iii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iv) towards CQC’s statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; and (v) in thematic reviews and national reporting; for example, the Annual State of Care report.
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: ‘postcode’ and ‘local patient identifier’. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. ‘Local patient identifier’ is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient’s postcode is used for assigning data to new LA/CCG boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continues to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The latest review again focused on requests submitted to the CQC central analytical team. CQC has confirmed that, in the review period, analyses were still conducted on the held identifiers. With respect to the period of data, it concluded that CQC only needed to retain a rolling period of 5 full FY years (annual refresh or equivalent) plus the current in-year data. Subsequently, all data older than 2014/15 have been deleted from CQC systems. This covers HES, HES-associated data, and all of MHMDS.
CQC’s use of identifying data is subject to CQC’s statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’), clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this Agreement meets this requirement.
CQC is the sole data controller and also processes the data. Atos is CQC’s ICT service provider and was engaged through the IMS3 framework contract, let by the Department of Health. This contract was due to come to an end at the end in March 2020 but was temporarily extended while CQC requested this Agreement permitting these data to be stored within the cloud environment of Microsoft Azure. Full details have been submitted to, and approved by, NHS Digital’s security consultant. Under this Agreement, the data will be transferred from Atos to Microsoft Azure. Atos will then confirm destruction of all copies of the data previously held on its servers and CQC will request a further amendment to this Data Sharing Agreement to remove Atos as an approved Data Processor.
Once stored in Microsoft Azure’s cloud environment, the data from NHS Digital will only be accessed by substantive employees of CQC but note that the local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section.
Capgemini has been commissioned to transfer the data from the current storage to the Microsoft Azure platform (discussed in separate technical response). Capgemini will have no access to the underlying data and will therefore not be processing the data. There are no other organisations involved in the wider project nor any commissioners involved. NHS Digital has considered the nature of Capgemini's role in moving the data from the old system to the Microsoft Azure platform and is content that Capgemini is not a data processor given that because the data are encrypted Capgemini is unable to access, view, modify the data whilst Capgemini will be transferring the data in this respect without the keys it is not possible for Capgemini to have access to the data to act as a data processor.
Expected output
On-going produced outputs include risk-based monitoring through CQC insight:
-incorporates data indicators that align to CQC’s key lines of enquiry for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England/ NHS Improvement. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Pre-inspection data evidence grids: used by the inspections teams and shared with providers. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes.
Outliers Programme: analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on ‘Perinatal mortality and neonatal readmissions’ used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Dr Foster Intelligence Ltd - investigated death rates for endoscopic procedures. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2018/19 publication appeared in February 2020.
Thematic reviews: used internally to inform CQC's regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS Digital’s HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In the monitoring of organisations for ongoing compliance against essential quality and safety standards, CQC uses screening techniques in its CQC insight tools, which analyse a wide variety of data sources to highlight possible outlying concerns that trigger actions where concerns are raised. Such screening methods are aided by a more local approach to information gathering and analysis, which is being developed in consultation with appropriate stakeholders. These techniques, currently along with national surveys of patients, help to create a more holistic understanding in informing its work with ongoing compliance, investigations, and thematic reviews.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
CQC has embedded its new insight programme over the last three years. Core data from this data sharing agreement were used in the production of indictors that align to CQC’s key lines of enquiry for a particular sector (e.g. hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used in the regulatory planning meetings (RPMs) as well as in the production of pre-inspection data evidence grids. These have allowed lead inspectors to decide which core services to inspect. The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in these products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
Side-by-side with this process, CQC’s outliers programme has continued to monitor and review potential outliers of high mortality and readmission rates. CQC received data from Dr Foster Intelligence Ltd that provided an additional route for identification in addition to CQC’s own. Where concerns were identified, these were taken up by the relevant relationship owner in conjunction with appropriate analytical support to understand whether an issue existed and, where this might have been the case, whether the trust were aware of the concern and what remedial action had been put in place. The mortality data are therefore used to provide a fundamental resource in the understanding of the quality of the provision of care and provide a tool to highlight where possible concerns may exist and where further investigation is required.
CQC has made extensive use of NHS Digital data within its insight pre-inspection reports within the hospital/ MH sectors. Over the previous 12 months, CQC have produced approximately 150 of these reports, which provide a breakdown of analysis by highlighted service (for example, surgery) and allow the inspection team to determine where to focus the inspection. The reports provide trust-level indicators and national comparisons from the most-readily available data and so allow the inspection team to hone in on particular areas of interest. An inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality of care provision and examples of good practice that other organisations could adopt. The NHS Digital data are therefore critical in this process for driving up the quality of care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS Digital featured in the 2017/18 State of Care report that is designed to provide a high-level commentary on year-on-year changes to care provision within England. This year, it highlighted the ‘safety’ domain as a particular concern with the aim of creating debate and policy changes to make long-term improvements in this area.
DARS-NIC-359603-D2Q6M-v6.2 15 October 2019 to 31 May 2020
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 13
- Files released
- 184
Datasets: Bridge file: Hospital Episode Statistics to Mental Health Minimum Data Set; Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Minimum Data Set (MHMDS); Mental Health Services Data Set (MHSDS)
What changed from DARS-NIC-359603-D2Q6M-v5.3
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2019-10-15 | |
| Bridge file: Hospital Episode Statistics to Mental Health Minimum Data Set: common law duty of confidentiality | Does not include the flow of confidential data | |
| Civil Registrations of Death - Secondary Care Cut: common law duty of confidentiality | Does not include the flow of confidential data | |
| Community Services Data Set (CSDS): common law duty of confidentiality | Does not include the flow of confidential data | |
| Emergency Care Data Set (ECDS): common law duty of confidentiality | Does not include the flow of confidential data | |
| HES:Civil Registration (Deaths) bridge: common law duty of confidentiality | Does not include the flow of confidential data | |
| Hospital Episode Statistics Accident and Emergency (HES A and E): common law duty of confidentiality | Does not include the flow of confidential data | |
| Hospital Episode Statistics Admitted Patient Care (HES APC): common law duty of confidentiality | Does not include the flow of confidential data | |
| Hospital Episode Statistics Critical Care (HES Critical Care): common law duty of confidentiality | Does not include the flow of confidential data | |
| Hospital Episode Statistics Outpatients (HES OP): common law duty of confidentiality | Does not include the flow of confidential data | |
| MSDS (Maternity Services Data Set) v1.5: common law duty of confidentiality | Does not include the flow of confidential data | |
| Mental Health Minimum Data Set (MHMDS): common law duty of confidentiality | Does not include the flow of confidential data | |
| Mental Health Services Data Set (MHSDS): common law duty of confidentiality | Does not include the flow of confidential data | |
| Mental Health and Learning Disabilities Data Set (MHLDDS): common law duty of confidentiality | Does not include the flow of confidential data |
Unchanged: Objective for processing, Processing activities, Expected output, Expected measurable benefits, Benefits reported.
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of care providers. CQC’s remit is to make sure health and social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. It does that through effective monitoring and inspection activity underpinned by an Intelligence insight programme that draws together risk and bench marking metrics at core service level. The data directly influence the risk and benchmarking models and help determine both when inspections take place and where they should focus. They also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act.
For record-level data, CQC will process these data lawfully under GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 (under which CQC was formed). As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) in, ‘processing is necessary for reasons of public interest in the area of public health, such as…ensuring high standards of quality and safety of health care…on the basis of Union or Member State law…’.
CQC’s statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS Digital (Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test. CQC’s core purpose is to seek to protect the public from poor provision of care, highlight good practice, and publish information (for example, inspection reports and ratings) that allow the public an improved understanding of the quality of provision of care by individual providers. Processing these data allow CQC to meet that public benefit.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, CQC's Caldicott Guardian conducted an internal review and signed it off for the previous iteration of this Data Sharing Agreement to determine the necessity of the data released by NHS Digital under previous iterations of this Agreement and the data (and new datasets) under this Agreement. With the augmentation of additional datasets (as discussed below), a Data Protection Impact Assessment was undertaken and finalised on 31 May 2019.
CQC currently has receipt/use of HES (inpatient, outpatient, critical care, and A&E), MHSDS (and legacy datasets), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
To expand on the Mental Health legacy datasets, these include Mental Health & Learning Disabilities Dataset, Mental Health Minimum Dataset, and KP90 Dataset. CQC has not held nor processed Learning Disabilities Census data under any of the past iterations of this Agreement.
CQC use these data (i) to populate indicators within their Intelligent insight products, which help CQC focus inspections of providers by deciding when, where and what to inspect; (ii) to construct evidence tables / data packs, which bring together information and analysis for each provider and are used for inspection planning; (iii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iv) towards CQC’s statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; and (v) in thematic reviews and national reporting; for example, the Annual State of Care report.
Under this Agreement, CQC are also requesting access to:
• the Maternity Services Data Set (MSDS) to improve its ability to report on this sector;
• the Community Services Dataset (CSDS) to develop a community-specific Intelligence insight product) and emergency care;
• the Emergency Care Data Set (ECDS) to provide a parallel feed to HES A&E and create new metrics as this product is rolled out/replaces the HES Accident & Emergency dataset.
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: ‘postcode’ and ‘local patient identifier’. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. ‘Local patient identifier’ is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient’s postcode is used for assigning data to new LA/CCG boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continue to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The review focuses on requests submitted to the CQC central analytical team. It confirmed that, in the review period, analyses were still conducted on the held identifiers and over the full period of retained HES. For MHMDS, no use had been made of 2008/09 and 2009/10 data and a decision was taken to delete these years from the system. These years of MHMDS data will be removed from this Data Sharing Agreement in the next iteration, by which time deletion will have taken place.
CQC’s use of identifying data is subject to CQC’s statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’), clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this agreement meets this requirement.
CQC is the sole data controller and also processes the data. Atos is a data processor for CQC. Atos is CQC’s ICT service provider and was engaged through the IMS3 framework contract, let by the Department of Health. The data from NHS Digital will only be processed by substantive employees of CQC and ATOS (note that the local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section). CQC wish to flag that the IMS3 contract will be expiring at the end of the 2019/20 financial year. A new supplier(s) for these services will be agreed over the course of the next 12 months. Any such change will result in an amendment of this Data Sharing Agreement before the new changes can take effect.
There are no other organisations involved in the wider project nor any commissioners involved.
Expected output
On-going produced outputs include risk-based monitoring through CQC insight:
-incorporates data indicators that align to CQC’s key lines of enquiry for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England/ NHS Improvement. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Pre-inspection data evidence grids: used by the inspections teams and shared with providers. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes.
Outliers Programme : analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on ‘Perinatal mortality and neonatal readmissions’ used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Dr Foster Intelligence Ltd - investigated death rates for endoscopic procedures. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2017/18 publication appeared in February 2019.
Thematic reviews: used internally to inform CQC's regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS Digital’s HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In the monitoring of organisations for ongoing compliance against essential quality and safety standards, CQC uses screening techniques in its CQC insight tools, which analyse a wide variety of data sources to highlight possible outlying concerns that trigger actions where concerns are raised. Such screening methods are aided by a more local approach to information gathering and analysis, which is being developed in consultation with appropriate stakeholders. These techniques, currently along with national surveys of patients, help to create a more holistic understanding in informing its work with ongoing compliance, investigations, and thematic reviews.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
CQC has been embedding its new insight programme over the last two years. Core data from this data sharing agreement were used in the production of indictors that align to CQC’s key lines of enquiry for a particular sector (e.g. hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used in the regulatory planning meetings (RPMs) as well as in the production of pre-inspection data evidence grids. These have allowed lead inspectors to decide which core services to inspect. The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in these products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
Side-by-side with this process, CQC’s outliers programme has continued to monitor and review potential outliers of high mortality and readmission rates. CQC received data from Dr Foster Intelligence Ltd that provided an additional route for identification in addition to CQC’s own. Where concerns were identified, these were taken up by the relevant relationship owner in conjunction with appropriate analytical support to understand whether an issue existed and, where this might have been the case, whether the trust were aware of the concern and what remedial action had been put in place. The mortality data are therefore used to provide a fundamental resource in the understanding of the quality of the provision of care and provide a tool to highlight where possible concerns may exist and where further investigation is required.
CQC has made extensive use of NHS Digital data within its insight pre-inspection reports within the hospital/ MH sectors. Over the previous 12 months, CQC have produced approximately 150 of these reports, which provide a breakdown of analysis by highlighted service (for example, surgery) and allow the inspection team to determine where to focus the inspection. The reports provide trust-level indicators and national comparisons from the most-readily available data and so allow the inspection team to hone in on particular areas of interest. An inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality of care provision and examples of good practice that other organisations could adopt. The NHS Digital data are therefore critical in this process for driving up the quality of care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS Digital featured in the 2017/18 State of Care report that is designed to provide a high-level commentary on year-on-year changes to care provision within England. This year, it highlighted the ‘safety’ domain as a particular concern with the aim of creating debate and policy changes to make long-term improvements in this area.
DARS-NIC-359603-D2Q6M-v5.3 7 August 2019 to 31 May 2020
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 13
- Files released
- 41
Datasets: Bridge file: Hospital Episode Statistics to Mental Health Minimum Data Set; Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Minimum Data Set (MHMDS); Mental Health Services Data Set (MHSDS)
What changed from DARS-NIC-359603-D2Q6M-v4.8
Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.
| Field | Was | Became |
|---|---|---|
| Start date | 2019-08-07 |
Unchanged: Objective for processing, Processing activities, Expected output, Expected measurable benefits, Benefits reported.
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of care providers. CQC’s remit is to make sure health and social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. It does that through effective monitoring and inspection activity underpinned by an Intelligence insight programme that draws together risk and bench marking metrics at core service level. The data directly influence the risk and benchmarking models and help determine both when inspections take place and where they should focus. They also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act.
For record-level data, CQC will process these data lawfully under GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 (under which CQC was formed). As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) in, ‘processing is necessary for reasons of public interest in the area of public health, such as…ensuring high standards of quality and safety of health care…on the basis of Union or Member State law…’.
CQC’s statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS Digital (Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test. CQC’s core purpose is to seek to protect the public from poor provision of care, highlight good practice, and publish information (for example, inspection reports and ratings) that allow the public an improved understanding of the quality of provision of care by individual providers. Processing these data allow CQC to meet that public benefit.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, CQC's Caldicott Guardian conducted an internal review and signed it off for the previous iteration of this Data Sharing Agreement to determine the necessity of the data released by NHS Digital under previous iterations of this Agreement and the data (and new datasets) under this Agreement. With the augmentation of additional datasets (as discussed below), a Data Protection Impact Assessment was undertaken and finalised on 31 May 2019.
CQC currently has receipt/use of HES (inpatient, outpatient, critical care, and A&E), MHSDS (and legacy datasets), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
To expand on the Mental Health legacy datasets, these include Mental Health & Learning Disabilities Dataset, Mental Health Minimum Dataset, and KP90 Dataset. CQC has not held nor processed Learning Disabilities Census data under any of the past iterations of this Agreement.
CQC use these data (i) to populate indicators within their Intelligent insight products, which help CQC focus inspections of providers by deciding when, where and what to inspect; (ii) to construct evidence tables / data packs, which bring together information and analysis for each provider and are used for inspection planning; (iii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iv) towards CQC’s statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; and (v) in thematic reviews and national reporting; for example, the Annual State of Care report.
Under this Agreement, CQC are also requesting access to:
• the Maternity Services Data Set (MSDS) to improve its ability to report on this sector;
• the Community Services Dataset (CSDS) to develop a community-specific Intelligence insight product) and emergency care;
• the Emergency Care Data Set (ECDS) to provide a parallel feed to HES A&E and create new metrics as this product is rolled out/replaces the HES Accident & Emergency dataset.
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: ‘postcode’ and ‘local patient identifier’. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. ‘Local patient identifier’ is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient’s postcode is used for assigning data to new LA/CCG boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continue to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The review focuses on requests submitted to the CQC central analytical team. It confirmed that, in the review period, analyses were still conducted on the held identifiers and over the full period of retained HES. For MHMDS, no use had been made of 2008/09 and 2009/10 data and a decision was taken to delete these years from the system. These years of MHMDS data will be removed from this Data Sharing Agreement in the next iteration, by which time deletion will have taken place.
CQC’s use of identifying data is subject to CQC’s statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’), clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this agreement meets this requirement.
CQC is the sole data controller and also processes the data. Atos is a data processor for CQC. Atos is CQC’s ICT service provider and was engaged through the IMS3 framework contract, let by the Department of Health. The data from NHS Digital will only be processed by substantive employees of CQC and ATOS (note that the local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section). CQC wish to flag that the IMS3 contract will be expiring at the end of the 2019/20 financial year. A new supplier(s) for these services will be agreed over the course of the next 12 months. Any such change will result in an amendment of this Data Sharing Agreement before the new changes can take effect.
There are no other organisations involved in the wider project nor any commissioners involved.
Expected output
On-going produced outputs include risk-based monitoring through CQC insight:
-incorporates data indicators that align to CQC’s key lines of enquiry for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England/ NHS Improvement. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Pre-inspection data evidence grids: used by the inspections teams and shared with providers. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes.
Outliers Programme : analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on ‘Perinatal mortality and neonatal readmissions’ used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Dr Foster Intelligence Ltd - investigated death rates for endoscopic procedures. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2017/18 publication appeared in February 2019.
Thematic reviews: used internally to inform CQC's regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS Digital’s HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In the monitoring of organisations for ongoing compliance against essential quality and safety standards, CQC uses screening techniques in its CQC insight tools, which analyse a wide variety of data sources to highlight possible outlying concerns that trigger actions where concerns are raised. Such screening methods are aided by a more local approach to information gathering and analysis, which is being developed in consultation with appropriate stakeholders. These techniques, currently along with national surveys of patients, help to create a more holistic understanding in informing its work with ongoing compliance, investigations, and thematic reviews.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
CQC has been embedding its new insight programme over the last two years. Core data from this data sharing agreement were used in the production of indictors that align to CQC’s key lines of enquiry for a particular sector (e.g. hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used in the regulatory planning meetings (RPMs) as well as in the production of pre-inspection data evidence grids. These have allowed lead inspectors to decide which core services to inspect. The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in these products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
Side-by-side with this process, CQC’s outliers programme has continued to monitor and review potential outliers of high mortality and readmission rates. CQC received data from Dr Foster Intelligence Ltd that provided an additional route for identification in addition to CQC’s own. Where concerns were identified, these were taken up by the relevant relationship owner in conjunction with appropriate analytical support to understand whether an issue existed and, where this might have been the case, whether the trust were aware of the concern and what remedial action had been put in place. The mortality data are therefore used to provide a fundamental resource in the understanding of the quality of the provision of care and provide a tool to highlight where possible concerns may exist and where further investigation is required.
CQC has made extensive use of NHS Digital data within its insight pre-inspection reports within the hospital/ MH sectors. Over the previous 12 months, CQC have produced approximately 150 of these reports, which provide a breakdown of analysis by highlighted service (for example, surgery) and allow the inspection team to determine where to focus the inspection. The reports provide trust-level indicators and national comparisons from the most-readily available data and so allow the inspection team to hone in on particular areas of interest. An inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality of care provision and examples of good practice that other organisations could adopt. The NHS Digital data are therefore critical in this process for driving up the quality of care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS Digital featured in the 2017/18 State of Care report that is designed to provide a high-level commentary on year-on-year changes to care provision within England. This year, it highlighted the ‘safety’ domain as a particular concern with the aim of creating debate and policy changes to make long-term improvements in this area.
DARS-NIC-359603-D2Q6M-v4.8 1 June 2019 to 31 May 2020
- Title
- CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets
- Commercial
- No
- Sublicensing
- No
- Datasets
- 13
- Files released
- 6
Datasets: Bridge file: Hospital Episode Statistics to Mental Health Minimum Data Set; Civil Registrations of Death - Secondary Care Cut; Community Services Data Set (CSDS); Emergency Care Data Set (ECDS); HES:Civil Registration (Deaths) bridge; Hospital Episode Statistics Accident and Emergency (HES A and E); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Critical Care (HES Critical Care); Hospital Episode Statistics Outpatients (HES OP); Maternity Services Data Set (MSDS) v1.5; Mental Health and Learning Disabilities Data Set (MHLDDS); Mental Health Minimum Data Set (MHMDS); Mental Health Services Data Set (MHSDS)
Objective for processing
Under this Data Sharing Agreement, the Care Quality Commission (CQC) is requesting record-level data that is critical to its regulatory oversight of care providers. CQC’s remit is to make sure health and social care services provide people with safe, effective, compassionate, high-quality care and CQC encourages them to improve. It does that through effective monitoring and inspection activity underpinned by an Intelligence insight programme that draws together risk and bench marking metrics at core service level. The data directly influence the risk and benchmarking models and help determine both when inspections take place and where they should focus. They also help with CQC’s statutory responsibility to monitor the use of the Mental Health Act.
For record-level data, CQC will process these data lawfully under GDPR Article 6(1)(e) with CQC’s statutory powers arising from the Health and Social Care Act 2008 (under which CQC was formed). As the regulator of health and adult social care in England, CQC will process special category data under Article 9(2)(i) in, ‘processing is necessary for reasons of public interest in the area of public health, such as…ensuring high standards of quality and safety of health care…on the basis of Union or Member State law…’.
CQC’s statutory powers under s64 of the 2008 Act allow it to require information from all registered providers as well as key organisations in the oversight of health and social care; for example, local authorities and NHS Digital (Health and Social Care Information Centre). These powers are constrained by the application of CQC’s Code of Practice for Confidential Personal Information that requires all consideration of the use of (potentially) identifying data to meet the necessity test. CQC’s core purpose is to seek to protect the public from poor provision of care, highlight good practice, and publish information (for example, inspection reports and ratings) that allow the public an improved understanding of the quality of provision of care by individual providers. Processing these data allow CQC to meet that public benefit.
As part of the process for weighing up the risk of potential harm to the public by the dissemination of data against the public benefit of its use for the organisation, CQC's Caldicott Guardian conducted an internal review and signed it off for the previous iteration of this Data Sharing Agreement to determine the necessity of the data released by NHS Digital under previous iterations of this Agreement and the data (and new datasets) under this Agreement. With the augmentation of additional datasets (as discussed below), a Data Protection Impact Assessment was undertaken and finalised on 31 May 2019.
CQC currently has receipt/use of HES (inpatient, outpatient, critical care, and A&E), MHSDS (and legacy datasets), civil registration mortality, as well as HES-mortality and HES-MHSDS bridging files. These data are received at record-level and cover activity within the whole of England. The data subjects will cover all individuals who have undergone treatment in these pathways. Multi-year extracts are required to produce time-series analyses. These review change over time and allow CQC to identify trends/ themes in organisations’ provision of care.
To expand on the Mental Health legacy datasets, these include Mental Health & Learning Disabilities Dataset, Mental Health Minimum Dataset, and KP90 Dataset. CQC has not held nor processed Learning Disabilities Census data under any of the past iterations of this Agreement.
CQC use these data (i) to populate indicators within their Intelligent insight products, which help CQC focus inspections of providers by deciding when, where and what to inspect; (ii) to construct evidence tables / data packs, which bring together information and analysis for each provider and are used for inspection planning; (iii) within the applicants Outliers programme to identify when key metrics relating to mortality rates and maternity outcomes reach a level that may warrant further investigation; (iv) towards CQC’s statutory role of monitoring the Mental Health Act and protecting the interests of people whose rights are restricted under the Act; and (v) in thematic reviews and national reporting; for example, the Annual State of Care report.
Under this Agreement, CQC are also requesting access to:
• the Maternity Services Data Set (MSDS) to improve its ability to report on this sector;
• the Community Services Dataset (CSDS) to develop a community-specific Intelligence insight product) and emergency care;
• the Emergency Care Data Set (ECDS) to provide a parallel feed to HES A&E and create new metrics as this product is rolled out/replaces the HES Accident & Emergency dataset.
The data contain patient identifying details although CQC have worked to reduce the number of identifying fields CQC hold to two: ‘postcode’ and ‘local patient identifier’. For the latter, it is occasionally necessary to identify to a trust examples of their own patients whose care appears problematical. ‘Local patient identifier’ is used as the HESID is not known to the trust. With this exception, no record level data is released to third parties. For the former, the patient’s postcode is used for assigning data to new LA/CCG boundaries, and for identifying other geography-related data (such as linking with deprivation tables, calculating distances from the address to the Trust, to help monitor for adverse events for people living in care homes).
CQC continue to review its use of identifiers and whether the amount of retained identifiable data continues to be necessary. The review focuses on requests submitted to the CQC central analytical team. It confirmed that, in the review period, analyses were still conducted on the held identifiers and over the full period of retained HES. For MHMDS, no use had been made of 2008/09 and 2009/10 data and a decision was taken to delete these years from the system. These years of MHMDS data will be removed from this Data Sharing Agreement in the next iteration, by which time deletion will have taken place.
CQC’s use of identifying data is subject to CQC’s statutory Code of Practice on Confidential Personal Information (the code). The purpose of the code is to provide transparency on CQC’s use of information for data subjects and other stakeholders and as a guide for staff on the practices CQC will follow. Practice 1 of the code (‘Obtaining confidential personal information’), clarifies that CQC ‘only obtain confidential personal information where it is necessary to do so to enable CQC to perform CQC’s functions. CQC will obtain only the minimum necessary confidential personal information’. The CQC are satisfied the substance of this agreement meets this requirement.
CQC is the sole data controller and also processes the data. Atos is a data processor for CQC. Atos is CQC’s ICT service provider and was engaged through the IMS3 framework contract, let by the Department of Health. The data from NHS Digital will only be processed by substantive employees of CQC and ATOS (note that the local patient identifier may be shared with the originating Trust to identify patient notes to review, as detailed below in the Benefits section). CQC wish to flag that the IMS3 contract will be expiring at the end of the 2019/20 financial year. A new supplier(s) for these services will be agreed over the course of the next 12 months. Any such change will result in an amendment of this Data Sharing Agreement before the new changes can take effect.
There are no other organisations involved in the wider project nor any commissioners involved.
Expected output
On-going produced outputs include risk-based monitoring through CQC insight:
-incorporates data indicators that align to CQC’s key lines of enquiry for that sector
-brings together information from people who use services, knowledge from CQC’s inspections and data from CQC’s partners
-indicates where the risk to the quality of care provided is greatest
-monitors change over time for each of the measures
-points to services where the quality may be improving
Outputs are produced on an ongoing basis and shared with the specific provider as well as granting access to key arms-length partners; for example, NHS England/ NHS Improvement. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
Pre-inspection data evidence grids: used by the inspections teams and shared with providers. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities. For example, 'Same-day procedure' indicator within HES sets out the proportion of elective admissions where the patient’s primary procedure was on the day of admission and provides high-level information to the inspection team for planning/ review purposes.
Outliers Programme : analysis of certain metrics derived from these data are shared with trusts who have hit a statistical threshold that is regarded as being of concern. A trust receives analysis only of patients admitted at that trust with a comparison to overall national rates. For example, indicators have been generated on ‘Perinatal mortality and neonatal readmissions’ used to monitor the care of new-borns; 'therapeutic endoscopic procedures on biliary tract' raised in response to an alert raised by Dr Foster Intelligence Ltd - investigated death rates for endoscopic procedures. This is aggregate information with small numbers suppressed in line with the CQC suppression rules as specified in processing activities.
National Reporting: used to support the creation and population of national reports providing a qualitative review of health and care supported by aggregated information. The nature of these reports varies year on year depending on CQC's topics of interest. This is aggregate information with small numbers suppressed in line with NHS Digital’s HES Analysis Guide. For example, MHMDS was used within CQC’s annual ‘Monitoring the Mental Health Act’; the 2017/18 publication appeared in February 2019.
Thematic reviews: used internally to inform CQC's regulatory activities. They provide an in-depth review of selected areas of care, for example dementia care. This is aggregate information with small numbers suppressed. This will use both the CQC suppression rules as specified in processing activities as well as NHS Digital’s HES Analysis Guide rules and judgement will be determined by CQC on whether it is felt a slightly nuanced version for circulation internally within CQC or externally to care providers/arms-length bodies partnering CQC would be of more benefit via the CQC rules. A further example being a review of urgent care in which the indicator of ‘death within 30 days of stroke, neck of femur, acute myocardial infarction’ was used from HES. They are shared publicly, however some contribute to CQC’s internal understanding of a subject and are not released publicly.
In the monitoring of organisations for ongoing compliance against essential quality and safety standards, CQC uses screening techniques in its CQC insight tools, which analyse a wide variety of data sources to highlight possible outlying concerns that trigger actions where concerns are raised. Such screening methods are aided by a more local approach to information gathering and analysis, which is being developed in consultation with appropriate stakeholders. These techniques, currently along with national surveys of patients, help to create a more holistic understanding in informing its work with ongoing compliance, investigations, and thematic reviews.
In addition, the data will also be used in the CQC’s remit to investigate serious concerns about the quality of public services. These data will be a vital pillar in both a national system of monitoring registered organisations, and the development and publication of reliable performance indicators.
Benefits reported
CQC has been embedding its new insight programme over the last two years. Core data from this data sharing agreement were used in the production of indictors that align to CQC’s key lines of enquiry for a particular sector (e.g. hospitals). The indicators have been used to highlight the greatest risks to the quality of care and, through monitoring change over time, have pointed to services where the quality of care may be improving.
These data are also used in the regulatory planning meetings (RPMs) as well as in the production of pre-inspection data evidence grids. These have allowed lead inspectors to decide which core services to inspect. The data have provided the groundwork for inspectors to approach identified areas with an appropriate set of questions providing a clear focus during the intensive inspection process. The data used in these products help to derive an ongoing assessment of the quality of core services. Areas of concern are highlighted and remedial action is monitored to follow up improvements. Additionally, areas of good practice are also flagged with the specific aim of using quality benchmarks to raise standards both within and across organisations.
Side-by-side with this process, CQC’s outliers programme has continued to monitor and review potential outliers of high mortality and readmission rates. CQC received data from Dr Foster Intelligence Ltd that provided an additional route for identification in addition to CQC’s own. Where concerns were identified, these were taken up by the relevant relationship owner in conjunction with appropriate analytical support to understand whether an issue existed and, where this might have been the case, whether the trust were aware of the concern and what remedial action had been put in place. The mortality data are therefore used to provide a fundamental resource in the understanding of the quality of the provision of care and provide a tool to highlight where possible concerns may exist and where further investigation is required.
CQC has made extensive use of NHS Digital data within its insight pre-inspection reports within the hospital/ MH sectors. Over the previous 12 months, CQC have produced approximately 150 of these reports, which provide a breakdown of analysis by highlighted service (for example, surgery) and allow the inspection team to determine where to focus the inspection. The reports provide trust-level indicators and national comparisons from the most-readily available data and so allow the inspection team to hone in on particular areas of interest. An inspection report and associated ratings are then published.
The published reports included recommendations for improving the quality of care provision and examples of good practice that other organisations could adopt. The NHS Digital data are therefore critical in this process for driving up the quality of care provision both within each organisation and more widely across England.
Further reviews of the ratings and analyses of NHS Digital featured in the 2017/18 State of Care report that is designed to provide a high-level commentary on year-on-year changes to care provision within England. This year, it highlighted the ‘safety’ domain as a particular concern with the aim of creating debate and policy changes to make long-term improvements in this area.
Register history
When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds, the earliest of which is July 2021.
-
July 2021 —
already listed in the earliest edition this site holds, so it may be older. 5 versions: DARS-NIC-359603-D2Q6M-v4.8, DARS-NIC-359603-D2Q6M-v5.3, DARS-NIC-359603-D2Q6M-v6.2, DARS-NIC-359603-D2Q6M-v7.2, DARS-NIC-359603-D2Q6M-v8.4
-
October 2021
Amended DARS-NIC-359603-D2Q6M-v8.4
- Datasets: + HES-ID to MPS-ID HES Accident and Emergency; + HES-ID to MPS-ID HES Admitted Patient Care; + HES-ID to MPS-ID HES Outpatients
-
December 2022
1 version added: DARS-NIC-359603-D2Q6M-v9.8
-
February 2023
1 version added: DARS-NIC-359603-D2Q6M-v10.2
-
October 2023
1 version added: DARS-NIC-359603-D2Q6M-v11.8Amended DARS-NIC-359603-D2Q6M-v10.2
- Civil Registrations of Death - Secondary Care Cut: legal basis:
Health and Social Care Act 2012 - s261(5)(d)→ Not stated
- Civil Registrations of Death - Secondary Care Cut: legal basis:
-
April 2024
1 version added: DARS-NIC-359603-D2Q6M-v12.3
-
June 2024
1 version added: DARS-NIC-359603-D2Q6M-v13.6
-
October 2024
1 version added: DARS-NIC-359603-D2Q6M-v14.6
-
August 2025
1 version added: DARS-NIC-359603-D2Q6M-v15.2
"Amended in place" means NHS England changed the record without issuing a new version number. The register publishes no changelog for those edits; this site infers them by comparing editions. An edit is attributed to the edition it first appears in, not to the date it was made.
Cite this page
NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-359603-D2Q6M, “CQC agreement for HES, MHSDS, MSDS, CSDS and ECDS and associated datasets”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-359603-d2q6m/ (accessed [date]).
This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.
Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-359603-D2Q6M to see the original rows.