Skip to main content
Beta version A NHS service powered by standards. Feedback opens in a new window will help us improve.

Core Information Standard: Reports

9 Residual Hazard Risk Assessment (page 38 of 18) in Clinical Safety Case Report (chapter 3 of 5) within Core Information Standard: Reports

The updated hazard log consists of 37 hazards. Six new hazards were identified in the Digital Social Care information consultation. Additional elements were added to existing hazards, during this consultation as well. The majority of which did not alter the risk of the hazard. Where the initial risk was raised following the Digital Social Care Information consultation, the hazard is discussed below. A further additional hazard was added on review of the changes to the sex and gender data items and one hazard was modified.

There are 15 hazards with an initial risk of 3 or more. After controls and mitigations there remain six hazards with a residual risk of 3, which is undesirable. Hazard 16 was originally rated at level 4 but was subsequently reviewed following changes to the sex and gender data items and was assessed at level 3, mitigated to level 2. Also hazard 30 (level 3), which has been raised by the inclusion of social care data and can only be mitigated further at implementation.

All the residual risks in the Hazard log will be transferred to those incorporating the CIS and associated products into an EHR. Action should be seriously considered for all level 3 risks. Consideration should also be given to further reducing those at level 2 where it is possible to do so. The residual risks at level 3 are as follows:

Risk Level 3

Hazard 8: The context or provenance of the information is lost, unknown or misunderstood

It is recognised that the Core Information Standard is a set of sections under which information is displayed, but that this view does not allow all the useful context and provenance of the information to be seen. Examples may include:

  • This Core Information Standard model shows data from all sources under defined sections. The elements of the items under each section do not take into account the full amount of contextual data available. Contextual data may be used to view a data item as part of a problem or part of an encounter for example and can therefore help to understand the provenance and context in which it was entered.
  • Losing the link to a source document. For example; Elements from the PRSB eDischarge or local authority assessment.
  • Summary separated under different sections in the CIS and links to whole document lost.
  • Inability to distinguish clinical information shared by care home or local authority with that entered by clinicians
  • Healthcare provider is unsure of the provenance of the CPR decision information and is thus unable to be sure of actions to take regarding CPR.
  • It is unclear whether clinical information was derived from a professional source e.g. consultant physician or from a patient history
  • Clinician unclear about the purpose of About Me (NB: The About Me section has been updated in the latest version of the CIS as part of the PRSB Digital Social Care Information project)

The mitigation for this is the development of other views of the information being made available to the end user, ensuring that the context and provenance of the data is retained. As well as ensuring users of systems understand the source of the data and the importance of context to support judging the validity of an entry - especially understanding the structure and purpose of the About Me section.

Hazard 11: Significant problems, diagnoses, conditions or procedures are not visible to healthcare user

The sections containing Problems, Diagnoses, Conditions and Procedures is recognised to be an issue because of the semantics of language between different professional groups (i.e What is regarded as a problem) and the structure of the data held in different clinical systems. In addition, there is a risk of an overload of data obscuring the information required. It is well known that GP problem lists are often extensive and are not curated.

Hazard 24: Failure to adopt CIS

The development of the standard needs to be supported in adoption by promotion by NHS Digital, NHS England, PRSB and stakeholder organisations who have provided endorsement for the standard, including bodies representing local authorities and care homes. The heterogeneity in the data items recorded by different local authorities and care homes will increase this risk as certain centres may consider the scope of the standards as limited or difficult to implement. Failure to adopt it risks multiple different models being adopted, resulting in lack of interoperability and lack of user familiarity. Leading to loss of benefit and potential patient harm.

Hazard 25: CIS used out of scope

The clinical safety case is based on the CIS being used in scope. Failure to stick to the scope defined and use it for purposes beyond its intended purpose would pose a risk to patient safety. It should be implemented following the implementation guidelines.

It should be noted that it has been assessed as a “Read only” record system. A read only shared record system can only reflect information supplied by other systems and should not be regarded as the single source of truth.

Hazard 30: Patient data error in interconnecting systems (Out of scope for Middleware Manufacturer noted here for Health Organisation only)

The addition of data from Local Authorities has increased this risk to a level 3 and it remains at this level of residual risk.

Identifying demographics information should be obtained from established sources such as the Patient Administration System [PAS] or national Patient Demographic Service [PDS]) – however, it is recognised that data may be missing, incorrect, incomplete, out of date or corrupt; creating a clinical safety risk. Examples of possible causes may include:

  • Failure to identify duplicates of patients in local master patient Index.
  • Missing, incorrect, incomplete, out of date or corrupt local data resulting in inability to identify patient or misidentification.
  • Inconsistency of patient record identifiers between interconnecting systems.
  • Data incorrectly entered into national records e.g. PDS multiple active (non end-dated) address records exist.
  • Data does not match demographics. NB Systems completed manually.

In addition, Local Authorities have identified significant issues in NHS number tracing and this may cause any of the above. NB: The use of NHS number or equivalent is a legal requirement for local authorities unless they are unable to reasonably comply – The Health and Social Care (Safety and Quality Act) 2015. Mitigations are required at the implementation stage.

Hazard 31: Data in legal section misunderstood or missing.

This hazard was introduced because of the introduction of legal data from local authorities, although it applies to all data in the legal section. The data may refer to the presence of a legal document such as an advance directive, but the actual document may not be accessible. The record might be out of date or misinterpreted. As this is a UK wide standard there was concern that there are differences in the legal requirements across the different UK countries.

This can be mitigated by ensuring that the original documents are accessible, and this is made clear in the implementation guidance. We are aware that work is going on nationally to create a single repository for documents. Training users to understand what is in this section and how it should be interpreted is also important.

Risk Level 2

The Hazards 2 and 3 described below are where initial risk has increased to level three following the Digital Social Care Information Consultation, but controls and mitigations have reduced the residual risk to level 2.

Hazard 2: Data missing/ incomplete data

This risk increased because of the addition of Local Authority data. It is important to ensure the design of shared care record system can handle the local authority data model (out of scope) - (LA information).

Hazard 3: Incorrect data or data is misinterpreted, or data is represented incorrectly.

The inclusion of data from Local authorities and in the About Me section has increased this risk. It is mitigated by ensuring that users understand the issues around different semantic use of terms in different environments and are clear about the provenance and context of data being displayed.

Hazards 33 and 34 are new and were identified following the Digital Social Care Information consultation and a review of the existing safety case for the CIS. They have an initial risk of three but are mitigated to two.

Hazard 33: Inappropriate role-based access control (RBAC) implementation

Either an appropriate end-user does not see information that they need to see, or an end-user has access to information that they should not see due to inappropriately allocated RBAC.

The initial design of the Care Homes View of the CIS included two different RBAC view proposals one for clinical care staff and one for others. These were both filtered views of the data. Following consultation these have been removed from the standard. PRSB recommends that all data must be viewable for appropriate users and should not be filtered unnecessarily, as this may lead to data not being visible. It was noted that Care homes very often do not have clinically qualified staff.

More generally this hazard increases with the rise in the number of organisations having access to the CIS data. This can be mitigated by ensuring that those administering RBAC privileges have adequate training and local policy is well communicated. As well as ensuring that there is adequate granularity in the RBAC roles. It is recognised that with the rising complexity of the data from multiple sources, the functionality of RBAC is increasingly challenged in managing confidentiality.

Hazard 34: The care home view of the CIS record does not include some important information

The initial design of the Care Homes View of the CIS included two different RBAC view proposals, which were both filtered views of the data. Following consultation these have been removed from the standard. Therefore, this hazard has been controlled.

Hazard 37: Hazard 37 was added following changes to the sex and gender data items to capture the risk of patients being called or not called for sex specific screening if the sex at birth is absent or incorrect. This was assessed at level 3 but with mitigation, adoption of the standard, reduced to level 2.

Page last updated: 28 July 2026