Skip to main content

Post audit review: Newcastle University, Newcastle 85+ Study

This report provides the formal closure of the data sharing audit at Newcastle University, Newcastle 85+ Study in September 2019.

Audit summary

This report provides the formal closure of the data sharing audit of the Newcastle 85+ Study being conducted at the Campus for Ageing and Vitality, Newcastle University (NU) on 4 and 5 September 2019 against the requirements of both:

  • the data sharing framework contract (DSFC) CON-318044-Z5W4J
  • the data sharing agreement (DSA) NIC-148471-FR43L-v1.19 

This DSA covers the provision of the following datasets:

Dataset Classification of data Dataset period
Medical Research Information Service (MRIS) – Flagging Current Status Report Identifiable, Sensitive

2006/18

MRIS – Cohort Event Notification Report

Identifiable, Sensitive

2006/18

MRIS – Cause of Death Report Identifiable, Sensitive

2006/18

MRIS – Members and Postings Report Identifiable, Sensitive

Latest available release

MRIS – Cohort Event Notification Period Identifiable, Sensitive Latest available release

 

The Controller is NU.

Further guidance on the terms used in this post audit review report can be found in version 3 of the NHS Digital Data Sharing Audit Guide.

Post audit review

This post audit review comprised a desk-based assessment of the action plan and supporting evidence supplied by NU between August 2020 and March 2021.

Post audit review outcome

Based on the evidence provided by NU, the Audit Team has closed all the findings. Therefore, no further action is required by the Audit Team and NU.

Updated risk statement

Based on the results of the post audit review the risk statement has been reassessed against the options of Critical - High - Medium – Low.

Original risk statement: Low

Current risk statement: Low


Data recipient’s acceptance statement

NU has reviewed this report and confirmed that it is accurate.


Status

The following table identifies the 7 agreement nonconformities, 3 organisation nonconformities and 3 opportunities for improvement raised as part of the original audit. 

Ref Finding Link to area Update Designation Status
1 At the time of the audit the previous Principal Investigator (PI)/Information Asset Owner (IAO), along with other historical system administration accounts, still had access to the folders containing data supplied by NHS Digital.  
A full review of access to this folder needs to be carried out to ensure access is restricted to only the roles declared in the DSA. This regular review should be documented to provide evidence it has been carried out.
Access control A full review of access to folders where the MRIS data resides has been undertaken. Historical accounts have been removed and only appropriate study specific users can now gain access.  Reviews of access are undertaken regularly during data guardian meetings, evidence of which was supplied to the Audit Team. Agreement nonconformity Closed
2 The Network Attached Storage (NAS), used to store the data supplied by NHS Digital, is not encrypted as stated in the DSA. Access control References to encryption have been removed from the updated DSA (v3.2), but comment that NHS Digital data is stored on a secure area network with restricted access continues to be stated. Agreement nonconformity Closed
3 The location of the primary datacentre, where data supplied by NHS Digital is stored and backed up, is not declared within the DSA. This is a commercial datacentre although the hardware is owned by the University. Information transfer

The location of the primary datacentre has been included in subsequent versions of the DSA (v2.2 and v3.2).

Agreement nonconformity Closed
4 Data is being processed at a location not stated within the DSA. While this location is part of the NU estate, it is in a different postcode area. Information transfer

The additional location has been included in subsequent versions of the DSA.

Agreement nonconformity Closed
5

The DSFC requires all users with access to NHS Digital data to complete suitable training on an annual basis. The Audit Team noted that not all staff had completed the data protection training in the last 12 months.

Operational management

Evidence was supplied to the Audit Team illustrating that all study members with access to the folders holding NHS Digital data, had completed suitable data protection training in the previous 12 months period.

Agreement nonconformity Closed
6

The Data Privacy Impact Assessment (DPIA) for the study was not available at the time of the onsite visit. It was reported by NU that a draft version had been created, but University staff were unable to access it during the visit.

Operational management

An approved version of the DPIA was provided to the Audit Team.  

Agreement nonconformity Closed
7 The Privacy Notice (PN) does not meet the requirements of General Data Protection Regulation (GDPR) and needs further review and update to ensure that all criteria required are fully completed and accurate. Operational management A revised PN, which complies with the requirements of GDPR, has been published on the NU website. Agreement nonconformity Closed
8 The cover page information as well as some of the contents of several University policies and process documents are out of date and need to be updated to reflect current practice and versions.  Operational management All documents highlighted as part of the original report have now undergone either a documented review or formal update to reflect changes to content and practice.  Revised copies of these documents were supplied to the Audit Team. Organisation nonconformity Closed
9 Validation testing of required security controls is not in place. Access control NU confirmed that NHS Digital data is held on an internal system which is subject to regular testing.  Advice around subsequent actions for any vulnerabilities identified as part of these regular checks was provided to NU separately by the Audit Team. Organisation nonconformity Closed
10 The encryption algorithm observed on some client devices used to access data supplied by NHS Digital was different to that specified in the Information Security Policy v3.0. Access control Following a review of the Information Security Policy v3.0, a revised updated v4.0 now reflects more accurately the encryption levels required for client devices across the NU estate. Organisation nonconformity Closed
11 NU should consider keeping evidence such as screenshots or log files to provide an audit trail for data destroyed electronically. Data destruction Certificates of destruction, as provided to NHS Digital, are now retained routinely as part of the project file records. An example of one of these certificates was provided to the Audit Team. Opportunity for improvement Closed
12 Whenever data supplied by NHS Digital is being processed using a third-party application, NU should be aware that if that application experiences an unexpected shutdown, then it could create temporary files. NU should therefore assess any risks arising from this situation and take appropriate action. Data destruction NU has made an assessment of this potential outcome. Whilst NU accept in some circumstances this may happen, it is mitigated by other controls such as disk encryption and restrictive access controls on any devices used to access the data. Opportunity for improvement Closed
13 When sending end user IT equipment away to a third-party disposal contractor for destruction, NU should maintain an itemised list of the sent assets, including serial numbers of hard disk drives, even where disk encryption mitigates any potential risk.
NU should also request a detailed data destruction certificate from the third-party disposal contractor against which the sent assets can be reconciled by NU, in order to ensure all IT end user equipment sent has been destroyed and accounted for.
Data destruction NU provided a representative itemised list of equipment recently sent for destruction to the third-party disposal contractor, as no actual project specific equipment was due for destruction during the course of this follow up. As the evidence provided showed that items were identified by weight and quantity, the Audit Team suggested that more granular detail, for example, serial number of hard disk drives, be included on future submissions. Opportunity for improvement Closed

 


Disclaimer

NHS Digital takes all reasonable care to ensure that this audit report is fair and accurate but cannot accept any liability to any person or organisation, including any third party, for any loss or damage suffered or costs incurred by it arising out of, or in connection with, the use of this report, however such loss or damage is caused. NHS Digital cannot accept liability for loss occasioned to any person or organisation, including any third party, acting or refraining from acting as a result of any information contained in this report.

Last edited: 20 May 2021 4:52 pm