Can a PCT take action against a pharmacy contractor who does not achieve Level 2 compliance by the 31st March 2011?
Compliance with the NHS Information Governance Requirements is not yet a specific contractual requirement; however there are provisions in the Terms of Service relating to pharmacy compliance with the Data Protection Act 1995 and the NHS Code of Practice on Confidentiality. The Information Commissioner’s Office (ICO) enforces and oversees the Data Protection Act. In April 2010, the ICO was given new powers to fine organisations up to £500,000 as a penalty for serious breaches of the Data Protection Act. When serving monetary penalties, the Information Commissioner will carefully consider the circumstances, including the seriousness of the data breach; the likelihood of substantial damage and distress to individuals; whether the breach was deliberate or negligent and what reasonable steps the organisation has taken to prevent breaches. The ICO has published guidance on what they consider to be ‘reasonable steps’. This includes things like putting in place appropriate policies and proced