Information Sharing and Data Governance With ICBs in Mental Health Services

As Integrated Care Boards (ICBs), NHS Trusts, local authorities and community providers work more closely together, effective information sharing has become fundamental to safe, coordinated mental health care. Commissioners increasingly expect providers to demonstrate mature information governance arrangements that enable timely decision-making while protecting confidentiality, maintaining public trust and complying with legal requirements. Strong data governance is now recognised as both a clinical safety issue and a key indicator of organisational maturity.

This article forms part of the Mental Health Services Knowledge Hub and should be read alongside Working with ICBs, NHS Trusts & System Partners, Quality, Safety & Governance, Digital & Remote Support and Mental Health Risk & Safeguarding.

Commissioners increasingly distinguish between providers that simply exchange information and those that demonstrate secure, well-governed information sharing that actively improves safety, continuity of care and system performance.

Why information sharing is fundamental to integrated care

Effective community mental health services depend upon professionals having timely access to accurate information. Poor communication between organisations can delay interventions, duplicate assessments and increase clinical risk.

Commissioners therefore expect information sharing arrangements that support:

  • Safe clinical decision-making.
  • Effective safeguarding.
  • Continuity across care pathways.
  • Reduced duplication.
  • Timely risk escalation.
  • Improved multidisciplinary working.
  • Better service user experience.
  • System-wide quality improvement.

Information governance should enable integrated care while maintaining appropriate confidentiality and public confidence.

Legal and regulatory responsibilities

Integrated working does not reduce individual organisational responsibility for protecting personal information. Every provider remains accountable for ensuring that information is shared lawfully, proportionately and securely.

Providers should demonstrate compliance through:

  • Clear lawful processing arrangements.
  • Appropriate consent processes where required.
  • Transparency with people using services.
  • Data protection policies.
  • Information governance training.
  • Routine compliance monitoring.

Commissioners expect providers to demonstrate confidence in applying legal requirements rather than treating information governance as a barrier to partnership working.

Operational example 1: improving information sharing during crisis escalation

A community provider identifies increasing suicide risk during routine support. The individual is also receiving input from an NHS Trust and primary care. Rather than relying on fragmented communication, the provider follows the agreed information-sharing protocol.

The response includes:

  • Immediate sharing of updated risk information.
  • Secure communication with partner organisations.
  • Documented clinical rationale.
  • Confirmation of receipt by receiving teams.
  • Updated safety planning.
  • Review through the multidisciplinary team.

This coordinated approach enables timely intervention while maintaining appropriate governance and accountability.

Information sharing agreements that support partnership working

Formal information-sharing agreements provide clarity regarding responsibilities, expectations and governance across organisational boundaries. Commissioners increasingly expect these arrangements to be documented, regularly reviewed and understood by frontline staff.

Effective agreements commonly define:

  • Information to be shared.
  • Purpose of sharing.
  • Authorised users.
  • Security requirements.
  • Retention arrangements.
  • Escalation following breaches.

Clear agreements reduce uncertainty and support consistent practice across integrated services.

Managing operational information flows

Information governance should support routine clinical delivery rather than creating unnecessary administrative burden. Providers should be able to demonstrate how information moves safely throughout the person's pathway.

Routine information flows often include:

  • Referrals.
  • Triage outcomes.
  • Risk assessments.
  • MDT decisions.
  • Safeguarding updates.
  • Discharge and transition summaries.

Efficient information flow strengthens continuity of care while reducing avoidable delays and duplication.

Operational example 2: improving interoperability across partner organisations

A provider identifies that frontline staff are duplicating assessments because information from partner organisations is not consistently available at the point of care. Although temporary workarounds exist, commissioners highlight the operational inefficiency during contract review.

The partnership responds by:

  • Reviewing current information flows.
  • Standardising referral information.
  • Improving secure digital access arrangements.
  • Clarifying data ownership.
  • Reducing duplicate documentation.
  • Monitoring improvements through joint governance meetings.

These changes reduce administrative burden while improving continuity, clinical decision-making and service user experience.

Digital systems and interoperability

Commissioners increasingly expect providers to move beyond isolated digital systems towards greater interoperability across health and social care organisations. While complete integration may not always be immediately achievable, providers should demonstrate a clear direction of travel.

Good practice includes:

  • Secure electronic care records.
  • Role-based system access.
  • Encrypted communication platforms.
  • Standardised data formats.
  • Interoperability improvement plans.
  • Routine testing of system resilience.

Providers should be able to explain how digital infrastructure supports integrated care while maintaining robust security and governance.

Managing information governance risks

Strong providers recognise that effective information sharing requires continuous oversight. Commissioners increasingly expect information governance to be actively monitored rather than assumed.

Governance arrangements typically include:

  • Routine information governance audits.
  • Monitoring of access logs.
  • Investigation of incidents and near misses.
  • Cyber security assurance.
  • Staff competency reviews.
  • Board reporting of significant information risks.

This proactive approach helps identify weaknesses before they affect service users or partnership working.

Operational example 3: learning from an information governance incident

A delayed safeguarding referral is traced to inconsistent communication between partner organisations rather than individual staff performance. The provider works collaboratively with system partners to strengthen information governance arrangements.

Actions include:

  • Reviewing communication protocols.
  • Clarifying escalation responsibilities.
  • Introducing additional staff training.
  • Updating information-sharing agreements.
  • Auditing future safeguarding communications.
  • Reporting learning through joint governance forums.

Commissioners value this transparent approach because it demonstrates organisational learning, system collaboration and continuous improvement.

Commissioner expectations

Commissioners increasingly expect providers working with ICBs and NHS Trusts to demonstrate:

  • Robust information governance.
  • Secure digital systems.
  • Clear information-sharing agreements.
  • Lawful and proportionate data sharing.
  • Strong cyber security arrangements.
  • Routine governance and audit.
  • Effective interoperability planning.
  • Continuous improvement through learning.

Common pitfalls to avoid

  • Allowing information governance to become a barrier to safe care.
  • Relying on informal communication.
  • Unclear responsibilities for information sharing.
  • Poor interoperability planning.
  • Weak cyber security controls.
  • Limited staff understanding of governance requirements.
  • Failure to audit information-sharing practice.
  • Not learning from governance incidents.

How to evidence this in tenders and commissioner reviews

Strong tender responses explain how information governance supports safe integrated mental health care through formal information-sharing agreements, secure digital systems, lawful processing arrangements, interoperability planning, staff training, cyber security, routine audit and continuous improvement. Providers should include practical examples where effective information sharing improved safeguarding, reduced duplication, supported multidisciplinary working or strengthened continuity of care across partner organisations.

Commissioners gain confidence when providers demonstrate that information governance actively enables safe integrated working rather than simply ensuring legal compliance.

Conclusion

Information sharing is fundamental to modern integrated mental health services. Safe, lawful and well-governed communication enables professionals to make better decisions, coordinate care more effectively and respond rapidly to changing levels of risk.

Providers that combine robust information governance, secure digital infrastructure, effective partnership arrangements and continuous organisational learning are better placed to support integrated care systems, strengthen commissioner confidence and deliver consistently high-quality mental health services.