Record Keeping Policy

Scope

BS Care record keeping policy sets out the values, principles and policies underpinning BS Care’s approach to record keeping, data protection and access to records, which are kept in the service user’s home.

Policy Statement
BS Care believes that all records required for the protection of service users, and for the effective and efficient running of the organisation, should be maintained accurately and be up to date; that service users should have access to their records and information about them; and that all individual records and organisation records should be kept in a confidential and secure fashion.

This policy is intended to set out the values, principles and methods underpinning this organisation’s approach to record keeping, data protection and access to records.

It is written in line with:
Regulation 9: Person-centred Care, which requires care providers to consider fully the rights, wishes and preferences of the people receiving their services
Regulation 17: Good Governance of the Health and Social Care Act 2008 (Regulated Activities 2014), which requires care providers to have secure record-keeping systems with policies on authorised access and sharing.

SERVICE USER RECORDS
1. With the service user’s consent, care or support workers should record, in records kept inthe homes of service users, the time and date of every visit to the home, the service provided and any significant occurrence.
2. where appropriate, records should include:
a) Assistance with medication – including time and dosage
b) Financial transactions undertaken on behalf of the service user
c) Details of any changes in the service user’s or carer’s circumstances, health, physical condition or care needs
d) Any accident, however minor, to the service user and/or care or support worker
e) Any other untoward incidents
f) Any other information that would assist the next health or social care worker to ensure consistency in the provision of care

3. All records required for the protection of service users and for the effective and efficient running of the organisation should be maintained in an up to date and accurate fashion by all staff.

4. Service users should have access to their records and information about them held by the organisation; they should also be given opportunities to help maintain their personal records.
5. Individual records and organisations records should be kept in a secure fashion, should be up to date and in good order; and should be constructed, maintained and used in accordance with the Data Protection Act 1998, GDPR and other statutory requirements.
6. Records should be kept in the home for one month, or until the service is concluded, after which time they should be transferred, with the permission of the service user, to the service provider or other suitable body (eg local authority or health trust, or other purchaser of the service), for safe keeping. Some personal data is retained to assist in the running of the business and some is retained for statutory purposes. All service user records are kept for three years after the conclusion of the service for these purposes, after which they are destroyed.
7. Wherever practical or reasonable, fill in all care records and service user notes in thepresence of and with the co-operation of the service user concerned.
8. Ensure that all care records and notes, including Service User Plans, are signed and dated.
9. Ensure that all files or written information of a confidential nature are stored in a securemanner wherever possible.
10. Consent is collected for data acquired through care plans and risk assessments to allow us to lawfully process the data for the following reasons.
• Maintaining and updating rotas
• Updating service user records to ensure accuracy
• Analytical and compliance Purposes
• Invoicing purposes.

EMPLOYMENT RECORDS
These may include the following:
• Applications for vacancies and CV’s
• Interview records
• References
• Medical reports
• Offers of employment
• Statutory statements of terms and conditions
• Disciplinary and grievance records
• Performance appraisals and similar reviews
• Notes of informal meetings and interviews
• Allowances and expenses
• Training details
• Salary, additional payments and bonuses etc
• Work permits
• Related correspondence
• Attendance records

Which are all kept for 3 years after the conclusion of the employees contract. This data is retained for employment purposes to assist in the running of the business and / or to enable people to be paid. Some personal data is held for statutory purposes.
Consent is collected for collecting and processing this data at the time of application.
This data isprocessed for the following purposes:
• Employment decision making
• Maintaining and updating rotas
• Making necessary adjustments to the working environment or role
• Payroll purposes
• Analytical and compliance purposes.
BS Care believes that access to information and security and privacy of data is an absolute right of every staff member and service user and that service users are entitled to see a copy of all personal information held about them and to correct any error or omission in it or have data deleted if they so wish. Staff and service users have the right to withdraw their consent for us to store and process their data.
The care workers assisting our service user have access to both the information passed to them when they start to work with that service user and the knowledge which accumulates in the course of providing care.
1. Service Users and employees have the right to be supplied with a copy of their personal data BS Care retains. All requests are to be made to the Registered Manager who is the “Data Protection Co-ordinator”. In his/her absence the Registered Person is to be contacted.
2. When requesting to view personal data, Service Users and employees are required to complete the relevant form. All requests for copies of personal data will be provided free of charge.
3. An authorised representative may be allowed to view the data provided the Registered Manager or Registered Person is satisfied that permission has been given.
4. If any part of the information requested was shared with us by Derbyshire County Council, then prior to release of the information, BS Care will seek consent for the information to be released by Derbyshire County Council.
5. Service users and employees may request the transfer of their personal information to another organisation or company.
6. BS Care will respond to any request for personal data within ten days.
7. Copies of personal data will be provided in an accessible format, either physically or electronically.
8. Service Users and employees are requested to inform BS Care of any changes in their circumstances that could affect the accuracy of the data.
9. Every effort will be made to resolve any disagreement between BS Care and the data subject, but in situations where the matter cannot be resolved, the following procedures are to be followed:
10. Service Users are requested to use BS Care’s formal complaints procedure.

11. Employees are requested to use BS Care’s formal grievance procedure.
They have a duty of confidentiality to:
a) Treat all personal information with respect and in the best interests of the person to whom it relates
b) Share with their manager, when appropriate, information given to them in confidence
c) Share confidential information when appropriate only with colleagues with whom they are sharing the task of providing care
d) Pass and receive confidential information to and from colleagues on occasions only when they have to be replaced because of sickness, holidays or other reasons, in a responsible and respectful manner
e) Only pass confidential information to other social and healthcare agencies with the agreement of the service user, with the permission of their manager, or in emergencies when it is clear that it is in the interests of the service user or is urgently required for the protection of the service user or another person
f) Refer to confidential information in training or group supervision sessions with respect and caution and preferably in ways which conceal the identity of the service user to which it relates
g) Never gossip about a service user or staff member to pass information to any other individual other than for professional reasons
h) Maintain records for the protection of service users and staff for the effective and efficient running of the organisation and keep them up to date and accurate
i) Allow service users and staff access to their records and information about them held by the organisation
j) Keep individual records and organisational records in a secure fashion and should be constructed, maintained and used in accordance with the Data Protection Act 1998, the GDPR and other statutory requirements.
k) Wherever practical or reasonable, fill in all care records service user notes in the presence of and with the co-operation of the service user concerned
l) Ensure that all care records and service users’ notes, including Service User Plans, are signed and dated
m) Ensure that all files or written information of a confidential nature are stored in a secure manner in a locked room and are only accessed by staff who have a need and a right to access them.
n) Ensure that all files or written information of a confidential nature are not left out where they can be read by unauthorised staff or others
o) Check regularly on the accuracy of data being entered into computers
p) Always use the passwords provided to access the computer system and not abuse them by passing them on to people who should not have them
q) Use computer screen blanking to ensure that personal data is not left on screen when not in use

MANAGERIAL AND ADMINISTRATIVE RESPONSIBILITIES
Confidential information must occasionally be seen by staff other than the care workers providing direct care. It if therefore the responsibility of managers to ensure that information is stored and handled in ways that limit access to those who have a need to
know, and to provide the following arrangements in particular:
1. To provide lockable filing cabinets to hold service user’s records and ensure that records are kept secure at all times
2. To arrange for information held in computers to be accessed only by appropriate personnel
3. to locate office machinery and provide shielding so that screens displaying personal data are hidden from general view
4. To monitor the record keeping and confidentiality of data through supervisions and direct observations in the homes of the service users
5. Records must be clear and contain sufficient detail to audit the care service provided
6. Records must be stored for the required time as listed:
• Risk assessments – until a new one replaces the last one
• Purchasing medical equipment – 18 months
• General policies – 3 years
• Incidents, events or occurrences – 3 years
• Use of restraint – 3 years
• Detention – 3 years
• Maintenance of premises – 3 years
• Maintenance of equipment – 3 years
• Electrical testing – 3 years
• Fire safety – 3 years
• Water safety – 3 years
• Money or valuables deposited for safe keeping – 3 years
• Staff employment – 3 years
• Duty rotas – 4 years
• Purchasing of medical equipment – 11 years
• Final annual accounts – 30 years
7. Records will be disposed of safely by shredding or burning.

DATA BREACHES

BS Care take data breaches very seriously. To detect data breaches, certain systems have been put in place.
On staff mobile phones, the phone will alert staff members if someone has tried to log in from a different device. The phones will also lock if the passcode is entered incorrectly a number of times. This will alert the staff member that there has been an attempted or successful breach.
Rooms where data is stored are regularly checked for anything out of the ordinary and for any evidence of tampering or forcing of locks.

Staff members are expected to report detections of data breaches to the Registered Manager, immediately.
An investigation will be started by the Registered Manager to the extent of the data breach and any relevant people, such as the police, outside bodies and the subjects of the data matter will be informed.
All staff members will be subject to training on data protection and procedures during their induction period. Any updates will be carried out as necessary.

Record-keeping
With the service user’s consent, records should include:
• Assistance with medication, including time and dosage.
• Financial transactions undertaken on behalf of the service user.
• Details of any changes in the service user’s or carer’s circumstances, health, physical condition, or care needs.
• Any accident, however minor, to the service user and/or care or support worker.
• Any other untoward incidents.
• Any other information that would assist the next health or social care worker to ensure consistency in the provision of care.
All records required for the protection of service users and for the effective and efficient running of the organisation should be maintained in an up-to-date and accurate fashion by all staff.
Service users have access to their records and information about them held by the organisation; they are also given opportunities to help maintain their personal records at initial assessment, reviews and other occasions.
Individual records and organisation records are kept in a secure fashion; are up to date and in good order; and are constructed, maintained and used in accordance with data protection legislation and other statutory requirements:
• Ensure that all files or written information of a confidential nature are stored in a secure manner in a locked filing cabinet and are only accessed by staff who have a need and a right to access them.
• Ensure that all files or written information of a confidential nature are not left in a place where they can be read by unauthorised staff or others.
• Check regularly on the accuracy of data being entered into computers.
• Always use the passwords provided to access the computer system and not abuse them by passing them on to people who should not have them.
• Use computer screen blanking to ensure that personal data is not left on screen when not in use, e.g.:
o All essential records and data relating to service users.
o All essential records and personnel data.
o Interview/recruitment records (records of interviews of applicants for posts who are subsequently employed for three years, and six months for applicants for posts who are not subsequently employed).
o All paperwork and computer records relating to complaints.

o All paperwork and computer records relating to accounts and financial transactions.
Storage and Disposal of Records
Wherever they are relevant to the service, the following records are kept and for the periods of time stated:
• Risk assessments: retain the last risk assessment until a new one replaces it.
• Purchasing, excluding medical devices and medical equipment: 18 months.
• General operating policies and procedures: retain the current version and previous version for three years.
• Any incidents, events or occurrences that require notification to the Care Quality Commission (CQC): three years.
• Use of restraint or the deprivation of liberty: three years.
• Detention: three years.
• Maintenance of the premises: three years.
• Maintenance of equipment: three years.
• Electrical testing: three years.
• Fire safety: three years.
• Water safety: three years.
• Medical gas safety, storage and transport: three years.
• Money or valuables deposited for safe keeping: three years.
• Staff employment: three years following date of last entry.
• Duty rosters: four years after the year to which they relate.
• Purchasing of medical devices and medical equipment: 11 years.
• Final annual accounts: 30 years.
• Social care records for adults are kept or disposed of in accordance with data protection legislation and three years from last date of entry.
• The social care records for children are kept or disposed of in accordance with data protection legislation and 80 years from last date of entry.
Records Management Code of Practice for Health and Social Care 2016 

This Code of Practice is for best pratice and the storage and disposal times are different than above. Appendix 3 of the code contains the detailed retention schedules. It sets out how long records should be retained, either due to their ongoing administrative value or because of statutory requirement.

Archiving Records and Documents
Archived paper records are kept securely in [secured file drawers and cabinets].
Electronic documents are archived on [protected and secure desktops and systems].
The information is backed up on [protected and secure hard drives]

Destruction of Confidential Records

It is the responsibility of all staff to ensure information they are handling is destroyed effectively, securely and in accordance with this policy and procedure.

All manual records that have reached their destruction date should be destroyed using one of the following methods:
• Internal shredding: crosscut shredder. Paper records are destroyed using a shredding device designed to crosscut material to ensure shredding cannot be reconstructed. Staff shredding their own records are responsible for ensuring records are destroyed adequately and in such a way that protects the security of the information contained within them.
• Use of external confidential waste disposal company. The confidential waste disposal company will supply waste disposal containers or bags that are stored until the required amount of waste meets the criteria agreed by the waste disposal company.
• IT equipment/electronic media. All queries regarding the destruction of IT equipment and electronic media must be referred to the IT Department or the organisation’s IT Consultants.

Related Policies
• Accessible Information and Communication
• Access to Records and Files
• Adult Safeguarding
• Confidentiality
• Consent
• Cyber Security
• Data Protection Legislative Framework (GDPR)
• Service users Records
Related Guidance
Data Protection Legislation:
https://ico.org.uk/for-organisations/guide-to-the-general-data-protection-regulation-gdpr/

Freedom of Information Act 2000:

https://ico.org.uk/for-organisations/guide-to-freedom-of-information/what-is-the-foi-act/

NHS Digital: A Guide to Sonfidentiality in Health and Social Care

https://digital.nhs.uk/data-and-information/looking-after-information/data-security-and-information-governance/codes-of-practice-for-handling-information-in-health-and-care/a-guide-to-confidentiality-in-health-and-social-care

Royal College of Nursing: Confidentiality:
https://www.rcn.org.uk/get-help/rcn-advice/confidentiality
Records Management Code of Practice for Health and Social Care 2016:

https://digital.nhs.uk/data-and-information/looking-after-information/data-security-and-information-governance/codes-of-practice-for-handling-information-in-health-and-care/records-management-code-of-practice-for-health-and-social-care-2016

A Data Protection Code of Practice for Surveillance Cameras and Personal Information:

https://ico.org.uk/media/1542/cctv-code-of-practice.pdf

Training
All staff, during induction, are made aware of the organisation’s policies and procedures, all of which are used for training updates. All policies and procedures are reviewed and amended where necessary, and staff are made aware of any changes. Observations are
undertaken to check skills and competencies. Various methods of training are used, including one to one, online, workbook, group meetings, and individual supervisions.
External courses are sourced as required. Inappropriate breach of the rules of confidentiality relating to record keeping will be treated as a disciplinary matter. Training will be through Inductions and qualifications in National Occupational Standards for all staff. All staff will be required to attend updates for this training.

 

Signed:_____ BA _____________ 

Date: ______1st June 2022____________ 

Policy review date: _____30th Jan 2023______________