Gloucestershire Health and Care- NHS Trust logo
with you, for you
Corporate Governance > Governance and oversight of Information Tools

Freedom of Information request Governance and oversight of Information Tools

Response published: 10 July 2026

FOI Request

Dear FOI Team, I am conducting independent research into the governance of information tools used within clinical or operational services across NHS provider Trusts. I am a former Deputy Director of Data Engineering at NHS England and the founder of Bartlett Data Ltd, an independent NHS data consultancy. "For the purposes of this request, 'locally developed or maintained information tools used within clinical or operational services' means any spreadsheet, database, document, shared drive folder, whiteboard, paper-based tracker, printed patient list, or other digital or non-digital tool that contains patient-identifiable or service-level information and is created or maintained by clinical or operational staff outside the Trust's formally managed IT systems and record-keeping processes (such as the EPR, PAS, or other centrally supported applications). It does not need to contain patient identifiable data to be included, it just needs to be in use within clinical or operational services. I request the following information. If any individual question would exceed the cost limit under Section 12 of the Freedom of Information Act, please answer the remaining questions and advise which question(s) could not be answered within the limit and why. If any information requested is not held, please confirm that it is not held. 1) Has the Trust completed an audit or survey of locally developed or maintained information tools used within clinical or operational services in the last three years? If so, please provide the date of the most recent audit and a summary of its scope and principal findings. If no such audit has been completed, please confirm this. 2) Does the Trust's Board Assurance Framework or Corporate Risk Register currently include a risk entry relating to the use of clinical or operational information held outside the Trust's formally managed IT systems? If so, please provide the risk detail in full. If no such risk entry exists, please confirm this. 3) How many incidents (e.g. Serious Incidents, Patient Safety Incidents, data breaches, or formal complaints) in the last three years had a root cause or contributing factor related to the accuracy, availability, security, or governance of information held outside the Trust's formally managed IT systems? If the Trust does not categorise or record incidents in a way that would allow this question to be answered without a manual review of individual records, just confirm this rather than attempting the search. 4) Which role(s) within the Trust has designated responsibility for the oversight and governance of information tools used within clinical or operational services that sit outside the Trust's formally managed IT systems? Please provide the job title and directorate. If no role has designated responsibility, please confirm this. If disclosing the job title would identify a specific individual, please provide the directorate and pay band instead. 5) Has the Trust issued a current policy or guidance to staff regarding the creation, use, and governance of locally developed information tools used within clinical or operational services as defined above? If so, please provide a copy or a link to the published version. If no such policy exists, please confirm this. Thank you for your assistance with this request. Please contact me at tom@bartlettdata.co.uk if any clarification is needed. Yours faithfully,

FOI Response

Freedom of Information Request – Ref: FOI 181-2026

Thank you for your recent Freedom of Information request. Please find our response below.

You asked:

1) Has the Trust completed an audit or survey of locally developed or maintained information tools used within clinical or operational services in the last three years? If so, please provide the date of the most recent audit and a summary of its scope and principal findings. If no such audit has been completed, please confirm this.

Our response:

No such audit has been completed.

You asked:

2) Does the Trust’s Board Assurance Framework or Corporate Risk Register currently include a risk entry relating to the use of clinical or operational information held outside the Trust’s formally managed IT systems? If so, please provide the risk detail in full. If no such risk entry exists, please confirm this.

Our response:

No such entry exists.

You asked:

3) How many incidents (e.g. Serious Incidents, Patient Safety Incidents, data breaches, or formal complaints) in the last three years had a root cause or contributing factor related to the accuracy, availability, security, or governance of information held outside the Trust’s formally managed IT systems? If the Trust does not categorise or record incidents in a way that would allow this question to be answered without a manual review of individual records, just confirm this rather than attempting the search.

Our response:

The Trust does not hold data in a way that would allow this question to be answered.

You asked:

4) Which role(s) within the Trust has designated responsibility for the oversight and governance of information tools used within clinical or operational services that sit outside the Trust’s formally managed IT systems? Please provide the job title and directorate. If no role has designated responsibility, please confirm this. If disclosing the job title would identify a specific individual, please provide the directorate and pay band instead.

Our response:

The Trust has three roles that have oversight and governance responsibilities that, though not specifically cover this area, have portfolios that would encompass this. They are the Trust’s Senior Information Risk Owner, the Caldicott Guardian and the Chief Clinical Information Officer.

You asked:

5) Has the Trust issued a current policy or guidance to staff regarding the creation, use, and governance of locally developed information tools used within clinical or operational services as defined above? If so, please provide a copy or a link to the published version. If no such policy exists, please confirm this.

Our response

The Trust does not have such a policy or guidance.

Next steps:

Should you have any queries in relation to our response, please do not hesitate to contact us. If you are unhappy with the response you have received in relation to your request and wish to ask us to review our response, you should write to:

Louise Moss
Head of Legal Services / Associate Director of Corporate Governance
c/o Gloucestershire Health and Care NHS Foundation Trust
Edward Jenner Court
1010 Pioneer Avenue
Gloucester Business Park
Brockworth, GL3 4AW
E-mail: louise.moss@ghc.nhs.uk

If you are not content with the outcome of any review, you may apply directly to the Information Commissioner’s Office (ICO) for further advice/guidance. Generally, the ICO will not consider your case unless you have exhausted your enquiries with the Trust which should include considering the use of the Trust’s formal complaints procedure. The ICO can be contacted at: The Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.