Information Governance Assurance Manager

Norfolk and Norwich University Hospital

The closing date is 16 May 2025

Job summary

Digital Health provides an expert information technology and telecommunications service covering all aspects of information processing to support operational and performance management and service improvement. The Department provides the Trust with a coherent digital strategy and secure, robust, reliable responsive, cost effective and customer driven digital services and systems. It also identifies opportunities for streamlining business processes and to enable data sharing and collaboration, both internally and externally, by the use or replacement of technology. In addition, it provides tools to enable business units to achieve their goals, facilitating a first-class quality of care to patients.

Now is a really exciting time to join the Norfolk & Norwich University Hospital, as we and the other two acute hospitals in Norfolk and Waveney we are working on our biggest digital programme to date: introducing an Electronic Patient Record (EPR) system. This programme is a key enabler of our transformation strategies for Acute Clinical Services across all sites. This is not simply a digital programme; this is one of the biggest pieces of clinical and operational transformation in the Norfolk and Waveney, set across 3 acute trusts. You will play a part in bringing the EPR to life and beyond, as we learn together about how to use it to its full advantage over the years to come in a safe and secure manner.

Main duties of the job

Act as a specialist on Information Governance (IG) for the Trust to provide an expert specialist advice service, in accordance with frameworks, national & local IG standards, requirements and best practice.

Lead the development and implementation of mechanisms to monitor compliance against national IG standards and the requirements of UK Data Protection laws and other external performance assessments.

Lead regular assessment against the Data Security and Protection Toolkit (DSPT), and other relevant standards. Report on Trust performance against these standards. Create plans to address risks and implement to improve the Trust's DSPT score and reduce the risks that the Trust faces through IG issues.

Investigate serious Incidents/breaches of IG and, when required produce formal reports of findings on reported adverse IG incidents, ensuring that lessons are learnt throughout the organisation, and that the recommendations are audited to ensure continued compliance.

Day to day line management responsibilities for the IG team.

Responsible for ensuring appropriate information sharing agreements and research projects, comply with data protection laws and are established with partner organisations and third parties.

Manage employee subject access requests (SAR's) under data protection laws which involve Trust emails. This includes identifying what information can be disclosed and providing advice to HR in relation to an applicant's personal information held in employment files.

About us

Join us at the Norfolk and Norwich University Hospital and be part of a workforce of over 10,000 staff!

The NNUH is one of the largest NHS trusts in the UK, providing first-class acute care for around one million people, living in Norfolk and surrounding areas. We are a teaching and research hospital, at the forefront of innovation, home to state-of-the-art facilities, such as the Quadram Institute. We are pleased to work closely with the University of East Anglia, providing teaching opportunities for our staff and placement opportunities for their students. We attract some of the best and leading professionals from across the country and are proud that our workforce represents 94 countries from across the world.

We are a friendly, collaborative hospital, working with local services and home to N&N Hospitals Charity

We can offer you the full range of NHS benefits/discounts and in addition:

  • Flexible working hours
  • Fast Track Staff Physiotherapy Service
  • Multi Faith prayer room
  • Discounted gym memberships
  • Excellent pension scheme and annual leave entitlement
  • Wagestream - access up to 40% of your pay as you earn it
  • Free Park & Ride service direct to NNUH site
  • Free 24-hours confidential counselling support
  • On-site Nursery
  • On-site cafes offering staff discounts
  • Support in career development
  • Flexible staff bank
  • Salary Sacrifice schemes including lease cars, Cycle to Work scheme and home electronics

Date posted

02 May 2025

Pay scheme

Agenda for change

Band

Band 8a

Salary

£53,755 to £60,504 a year per annum

Contract

Permanent

Working pattern

Full-time, Flexible working, Home or remote working

Reference number

234-24-C2607

Job locations

20 Rouen Rd

Norwich

NR1 1QQ


Job description

Job responsibilities

The following skills and experience will be required and are essential for the successful candidates:

  • To act as a designated specialist on Information Governance for the Trust to provide an expert specialist advice service, in accordance with regulatory and legislative framework, national and local information governance standards, requirements and best practice.
  • Permitted the freedom to achieve stated objectives in own way, without reference to line manager.
  • Lead in the development and implementation of mechanisms to monitor compliance against national IG standards and the requirements of UK Data Protection laws and other external performance assessments..
  • Ensure that external suppliers, contracted staff and end users are aware of the Information Governance standards and policies in place.
  • Has good understanding and the aptitude to remain up to date with information governance developments. Possesses an in-depth understanding of the information governance framework and standards used by the Trust. Is effective and persuasive in both written and oral communication.
  • To be a member of the Trusts Caldicott and Information Governance Assurance Committee and provide expertise and support for the data protection and confidentiality improvement plans identified through the Data Security and Protection Toolkit (DSPT). To provide this support by making an expert assessment of current data protection and confidentiality and proposing mitigation measures to improve information governance.
  • Lead regular assessment and accreditation of the Trust against information governance baselines contained within the Data Security and Protection Toolkit (DSPT), national Information Governance Assurance Frameworks and other relevant standards. Report to the Head of Information Governance on Trust performance against these standards.

Please refer to the Job Description for the full specification of responsibilities and requirements for this post.

Job description

Job responsibilities

The following skills and experience will be required and are essential for the successful candidates:

  • To act as a designated specialist on Information Governance for the Trust to provide an expert specialist advice service, in accordance with regulatory and legislative framework, national and local information governance standards, requirements and best practice.
  • Permitted the freedom to achieve stated objectives in own way, without reference to line manager.
  • Lead in the development and implementation of mechanisms to monitor compliance against national IG standards and the requirements of UK Data Protection laws and other external performance assessments..
  • Ensure that external suppliers, contracted staff and end users are aware of the Information Governance standards and policies in place.
  • Has good understanding and the aptitude to remain up to date with information governance developments. Possesses an in-depth understanding of the information governance framework and standards used by the Trust. Is effective and persuasive in both written and oral communication.
  • To be a member of the Trusts Caldicott and Information Governance Assurance Committee and provide expertise and support for the data protection and confidentiality improvement plans identified through the Data Security and Protection Toolkit (DSPT). To provide this support by making an expert assessment of current data protection and confidentiality and proposing mitigation measures to improve information governance.
  • Lead regular assessment and accreditation of the Trust against information governance baselines contained within the Data Security and Protection Toolkit (DSPT), national Information Governance Assurance Frameworks and other relevant standards. Report to the Head of Information Governance on Trust performance against these standards.

Please refer to the Job Description for the full specification of responsibilities and requirements for this post.

Person Specification

Qualifications

Essential

  • Educated to masters level in relevant subject or equivalent level qualification or significant experience of working at a similar level in Information Governance.

Experience

Essential

  • Experience of managing Information Governance risk-based improvement programmes within the NHS.
  • Extensive knowledge of data protection processes, including statutory requirements and national policy.
  • Experience of developing Information Governance policies and processes in a complex environment where confidential information is stored.

Skills

Essential

  • Ability to explain complex technical or legal issues to a non-technical audience
  • Ability to prepare and produce concise yet insightful communications for dissemination to senior stakeholders and a broad range of stakeholders as required
  • Demonstrated capabilities to manage own workload and make informed decisions in the absence of required information, working to tight and often changing timescales

Attitude & Aptitude

Essential

  • Demonstrates understanding and commitment to Equality, Diversity and Inclusion
  • Effective role model, demonstrating NNUH's PRIDE values of People focussed, Respect, Integrity, Dedication and Excellence
Person Specification

Qualifications

Essential

  • Educated to masters level in relevant subject or equivalent level qualification or significant experience of working at a similar level in Information Governance.

Experience

Essential

  • Experience of managing Information Governance risk-based improvement programmes within the NHS.
  • Extensive knowledge of data protection processes, including statutory requirements and national policy.
  • Experience of developing Information Governance policies and processes in a complex environment where confidential information is stored.

Skills

Essential

  • Ability to explain complex technical or legal issues to a non-technical audience
  • Ability to prepare and produce concise yet insightful communications for dissemination to senior stakeholders and a broad range of stakeholders as required
  • Demonstrated capabilities to manage own workload and make informed decisions in the absence of required information, working to tight and often changing timescales

Attitude & Aptitude

Essential

  • Demonstrates understanding and commitment to Equality, Diversity and Inclusion
  • Effective role model, demonstrating NNUH's PRIDE values of People focussed, Respect, Integrity, Dedication and Excellence

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Additional information

Disclosure and Barring Service Check

This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.

Certificate of Sponsorship

Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).

From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).

Employer details

Employer name

Norfolk and Norwich University Hospital

Address

20 Rouen Rd

Norwich

NR1 1QQ


Employer's website

https://teamnnuh.co.uk/ (Opens in a new tab)


Employer details

Employer name

Norfolk and Norwich University Hospital

Address

20 Rouen Rd

Norwich

NR1 1QQ


Employer's website

https://teamnnuh.co.uk/ (Opens in a new tab)


For questions about the job, contact:

Head of Information Governance & Cyber Security

Mark Northcott

mark.northcott@nnuh.nhs.uk

Date posted

02 May 2025

Pay scheme

Agenda for change

Band

Band 8a

Salary

£53,755 to £60,504 a year per annum

Contract

Permanent

Working pattern

Full-time, Flexible working, Home or remote working

Reference number

234-24-C2607

Job locations

20 Rouen Rd

Norwich

NR1 1QQ


Supporting documents

Privacy notice

Norfolk and Norwich University Hospital's privacy notice (opens in a new tab)