Data Protection Act 1998

Prevents unauthorised or inappropriate use of ‘personal data’ held electronically or manually. Individuals (‘data subjects’) are allowed access to information held about them and given redress if the Act is contravened. Organisations (‘data controllers’), unless exempt, must notify the Information Commissioner of the data held and how it is used. They must follow eight data protection principles. Certain breaches amount to criminal offences and in some instances data subjects have the right to damages. Insurresponses arise under public liability, legal expenses, directors’ and officers, and professional indemnity policies (www.dataprotection.gov.uk). ance

Data resource manager

Individual who uses computer-based health record systems, databases, and clinical data repositories to make sure the facility’s information systems are suitable for those that provide and manage patient services and that the organization’s data resources are secure, accessible, accurate, and reliable.

Data security

Electronic protection of computer-based information from unauthorized alteration or intentional or accidental destruction. Also, it is the process of controlling access and maintaining confidentiality when entering, storing, processing, and communicating information.

Data segment

Under HIPAA, a set of data elements of which there are two types, information segments or control segments. An information segment is used to convey information on the provider, payer, or services rendered. A control segment carries information necessary to the transmission and reception of a transaction.

Data use agreement

Legal binding agreement that the Centers for Medicare and Medicaid Services (CMS) requires to obtain identifiable data. It also delineates the confidentiality requirements of the Privacy Act of 1974 security safeguards and CMS’s data use policy and procedures.