Information Governance and Data Sharing in NHS-Commissioned Services

Information governance is no longer a back-office compliance function. Within NHS-commissioned services it has become a core component of safe care delivery, integrated working, patient trust, organisational resilience and commissioner assurance. As health and social care systems become increasingly connected, providers are expected not only to protect information but also to share it appropriately, lawfully and effectively across organisational boundaries.

For many providers, the challenge is no longer simply maintaining GDPR compliance. Commissioners, Integrated Care Systems (ICSs), NHS partners and regulators increasingly want evidence that information governance supports operational decision-making, care coordination, safeguarding, risk management and service continuity.

This article forms part of the NHS & Integrated Community Services Knowledge Hub and links closely with NHS Digital, Data & Interoperability, Risk Management & Compliance, Regulation & Oversight, Quality, Safety & Governance and Working With ICBs & System Partners.

Why Information Governance Matters More Than Ever

NHS pathways increasingly depend upon multiple organisations working together around a shared understanding of an individual's needs, risks and outcomes. Community providers, acute trusts, mental health services, primary care, local authorities, voluntary sector organisations and specialist services may all contribute to a single care pathway.

None of this can function effectively without trusted information sharing.

When information governance is weak, consequences can include:

  • Delayed hospital discharge
  • Repeated assessments and duplication
  • Missed safeguarding risks
  • Medication errors
  • Poor continuity of care
  • Breakdowns in multidisciplinary working
  • Increased complaints and incidents
  • Loss of commissioner confidence

Conversely, strong information governance enables timely decision-making, safer transitions, improved patient experience and more effective use of system resources.

The Shift From Information Protection to Information Enablement

Historically, some organisations viewed information governance primarily as a process of preventing inappropriate information sharing. While protecting confidentiality remains essential, modern NHS systems increasingly recognise that inappropriate non-sharing can be just as harmful as inappropriate sharing.

Commissioners increasingly expect providers to demonstrate that information governance supports:

  • Safe care coordination
  • Integrated pathway delivery
  • Population health approaches
  • Risk management
  • Safeguarding partnerships
  • Quality improvement
  • System-wide decision-making

The question is no longer simply "Can we share this information?" but "How can we share it lawfully, proportionately and effectively to improve outcomes?"

What Commissioners Expect Providers to Understand

Commissioners increasingly expect operational leaders to demonstrate practical understanding rather than relying solely on generic policies.

Providers should be able to explain:

  • Lawful bases for processing information
  • Consent requirements and limitations
  • Public task and vital interest considerations
  • Data minimisation principles
  • Role-based access controls
  • Information sharing agreements
  • Subject access request processes
  • Incident reporting requirements
  • Partner responsibilities within integrated pathways

Inspectors and commissioners increasingly test whether these principles are understood operationally by managers and frontline staff rather than simply existing within policies.

Information Governance Across Integrated Care Systems

Integrated Care Systems rely upon organisations sharing information quickly and safely.

Common examples include:

  • Hospital discharge pathways
  • Urgent community response services
  • Virtual ward models
  • Intermediate care services
  • Mental health crisis pathways
  • Safeguarding investigations
  • Learning disability and autism services
  • Complex case management
  • End-of-life care coordination

In each scenario, delayed or incomplete information can directly affect outcomes.

Commissioners increasingly assess whether providers can operate effectively within wider system information-sharing arrangements rather than focusing solely on their own internal processes.

Operational Example 1: Hospital Discharge Information Sharing

Context: A community provider receives a discharge referral from an acute trust for an individual requiring ongoing support at home.

Risk: Medication changes, mobility risks and equipment requirements are not communicated consistently across systems.

Information governance response: The provider establishes agreed referral standards, mandatory information fields and secure transfer mechanisms with hospital partners.

Outcome: Staff receive complete discharge information before commencing support, reducing delays, duplication and avoidable risks.

Role-Based Access and Data Minimisation

One of the most important principles within modern information governance is ensuring that people have access to the information they need—but only the information they need.

Commissioners increasingly expect providers to demonstrate:

  • Clear user permissions
  • Access controls linked to role requirements
  • Regular user audits
  • Prompt removal of leavers
  • Review of privileged access accounts
  • Monitoring of unusual access activity

Effective access management reduces risk while maintaining operational efficiency.

Consent, Transparency and Trust

Information governance is ultimately about trust.

People receiving services increasingly expect organisations to explain:

  • What information is collected
  • Why it is collected
  • Who it may be shared with
  • How long it is retained
  • How concerns can be raised
  • How rights can be exercised

Commissioners increasingly view transparency as both a legal requirement and an indicator of organisational culture.

Information Governance and Safeguarding

Safeguarding situations often test organisational understanding of information sharing.

Providers must balance confidentiality with protection responsibilities.

Strong safeguarding information governance includes:

  • Clear escalation routes
  • Multi-agency information-sharing protocols
  • Timely documentation
  • Accurate recording of decisions
  • Clear rationale for information sharing
  • Appropriate partner engagement

Commissioners expect safeguarding information-sharing decisions to be both defensible and timely.

Managing Subject Access Requests and Individual Rights

Providers increasingly receive requests relating to:

  • Subject access requests
  • Correction requests
  • Data portability requests
  • Complaints regarding data use
  • Consent withdrawal requests

Strong providers maintain clear processes, defined responsibilities and appropriate oversight mechanisms to ensure statutory requirements are met consistently.

Information Governance Leadership and Accountability

Commissioners increasingly look beyond policies to examine governance arrangements.

They expect to see:

  • Named information governance leads
  • Board-level accountability
  • Regular reporting structures
  • Information governance risk registers
  • Audit programmes
  • Incident review processes
  • Action tracking and improvement plans

Information governance should be visible within wider governance frameworks rather than operating separately.

Operational Example 2: Multi-Agency Safeguarding Coordination

Context: A safeguarding concern requires involvement from social care, healthcare providers, police and community services.

Risk: Delayed information sharing prevents agencies from understanding the full level of risk.

Information governance response: Information-sharing responsibilities are clarified, decisions are documented, and secure communication routes are used.

Outcome: Agencies develop a shared understanding of risk and coordinate protective actions more effectively.

Learning From Information Governance Incidents

Even strong organisations experience incidents.

Commissioners are often more interested in organisational learning than perfection.

Effective incident management includes:

  • Rapid identification
  • Containment actions
  • Investigation
  • Root cause analysis
  • Staff learning
  • Policy review
  • Governance oversight
  • Monitoring of corrective actions

Providers that demonstrate learning and improvement often generate greater commissioner confidence than organisations that treat incidents as isolated events.

Digital Transformation and Information Governance

As providers adopt digital care planning, interoperability platforms, remote monitoring systems, artificial intelligence tools and integrated records, information governance becomes increasingly important.

Future-focused providers are already considering:

  • Interoperability governance
  • AI assurance frameworks
  • Data ethics
  • Cyber resilience
  • Cross-system data sharing
  • Population health analytics
  • Digital consent models
  • Emerging regulatory expectations

Commissioners increasingly assess whether providers are prepared for future digital requirements rather than simply meeting current standards.

Operational Example 3: Digital Care Coordination Across Multiple Providers

Context: Several organisations support an individual with complex needs across health and social care.

Risk: Inconsistent information updates create confusion regarding responsibilities and risk management.

Information governance response: Shared information standards, access controls and agreed update protocols are implemented.

Outcome: MDT communication improves, duplication reduces and care coordination becomes more reliable.

What Good Looks Like to Commissioners

High-performing providers can demonstrate:

  • Confident and lawful information sharing
  • Clear governance structures
  • Strong operational understanding
  • Robust access controls
  • Effective staff training
  • Integrated partnership working
  • Routine audit and assurance activity
  • Learning from incidents
  • Future digital readiness

Most importantly, they can show that information governance actively supports safer, more effective care rather than acting as an administrative exercise.

Conclusion

Information governance has become a critical component of NHS-commissioned service delivery. Strong governance protects confidentiality, supports integrated care, enables effective partnerships and strengthens commissioner confidence.

The most mature providers understand that information governance is not simply about compliance. It is about creating the conditions that allow people, services and systems to work together safely, efficiently and transparently. As NHS pathways become increasingly integrated and digitally enabled, organisations that embed information governance into everyday operational practice will be best placed to demonstrate quality, resilience and long-term system value.