Privacy & Filtering Controls
iPCV supports a number of privacy, governance and filtering controls designed to ensure that data is made available in line with applicable data sharing agreements, customer configurations and governance requirements.
The controls applied to your iPCV environment determine:
- Which patients are included
- Which records are available
- Which coded events are visible
- Whether patient records are pseudonymised
These controls may affect record counts within reports and extracts, and the data available to downstream analytics and reporting solutions. Understanding these controls is important when validating record counts, comparing results between organisations and designing analytical processes.
How Privacy & Filtering Controls Work
Section titled “How Privacy & Filtering Controls Work”Privacy and filtering controls are applied during data processing and determine which records are ultimately made available within iPCV to individual customers. As a result:
- Different customers may receive different data volumes.
- Record counts can vary depending on the configuration applied.
- The same analytical query may return different results across environments where different filtering configurations have been implemented.
Privacy controls should therefore always be considered when comparing datasets or investigating differences in reporting outputs.
Types of Privacy & Filtering Controls
Section titled “Types of Privacy & Filtering Controls”Depending on your organisation’s configuration, iPCV may include one or more of the following controls.
Patient-Level Filtering
Section titled “Patient-Level Filtering”Patient-level filtering determines whether data relating to a patient should be included within the dataset. These controls are applied before records become available within iPCV and affect all related data associated with the patient. They may exclude specific patient records from the available dataset and therefore impact both patient-level and activity-level record counts.
National Data Opt-Out
Section titled “National Data Opt-Out”The National Data Opt-Out Programme (NDOP) allows patients in England to choose whether their confidential patient information can be used for purposes beyond their individual care. Patients record their NDOP preferences with NHS Digital, who then provide the list of patients who are opted in for data sharing.
Local Opt-Out Controls
Section titled “Local Opt-Out Controls”Local data sharing opt-out indicators are recorded locally at the organisation level. There are four sets of codes that organisations can use to record patient preferences for different data uses. Each consists of a pair of codes — one for consent and one for dissent.
| Data Sharing Control | Opt-in code | Opt-out code |
|---|---|---|
| Secondary use of general practitioner patient identifiable data (Type 1 opt-out) | 9Nu1 | 9Nu0 |
| Upload to local shared electronic record | 93c0 | 93c1 |
| Disclosure of personal confidential data by Health and Social Care Information Centre (Type 2 opt-out — superseded by NDOP but may still be present) | 9Nu5 | 9Nu4 |
| Electronic record sharing | 9Nd7 | 9Nd1 |
The date of the most recently recorded code in each pair determines the patient’s status. One or more of the above controls can be applied to a customer’s iPCV dataset.
Dissent must be explicit — if no dissent code is recorded against a patient, they are treated as consented for data sharing.
Patient Registration Filtering
Section titled “Patient Registration Filtering”Patients can be filtered based on the type of patient registration or other patient characteristics, including:
- Registered patients
- Regular patients
- Active patients
- Dummy patients
- Deceased patients
- Patients who have left the organisation
Sensitive Patient Filtering
Section titled “Sensitive Patient Filtering”Patients whose records are marked as sensitive by NHS National Patient Demographics Service (PDS) may be filtered. Examples of patients in this category include:
- Adopted patients
- Gender reassignment patients
- Prisoners
- Mental health patients
- Other vulnerable patients
Confidential Patient Filtering
Section titled “Confidential Patient Filtering”Patients whose whole records are marked as confidential by the organisation (that is, patients that have a confidentiality policy applied to their entire record) may be filtered. Customers who are filtering out sensitive patients usually also choose to filter out confidential patients.
Record-Level Filtering
Section titled “Record-Level Filtering”Sensitive Code Filtering
Section titled “Sensitive Code Filtering”iPCV includes support for filtering clinical events associated with designated sensitive SNOMED concepts. Examples may include categories of information identified as sensitive under applicable governance requirements.
For more information, see the Sensitive SNOMED Code data model documentation.
Confidentiality Controls
Section titled “Confidentiality Controls”Certain clinical events may have a confidentiality policy applied to restrict who can see them within an organisation. If confidential events are excluded, only those specific events are hidden — the rest of the patient’s record remains visible. Customers who are filtering out sensitive records usually also choose to filter out confidential records.
Patient De-identification
Section titled “Patient De-identification”Determines how patient identifiable information is represented within the data. The available options depend on the agreed implementation and data sharing arrangements for the customer, but usually involve securely hashing patient identifiers and removing any free text columns.
Understanding the Impact on Record Counts
Section titled “Understanding the Impact on Record Counts”Privacy and filtering controls are among the most common reasons for differences in record counts between different reporting platforms, reporting periods, and source systems and iPCV. Variations may occur because:
- Patients have exercised opt-out preferences.
- Sensitive records have been excluded.
- Different filtering configurations have been applied.
- Governance rules have changed over time.
When investigating record count differences, filtering and privacy controls should always be reviewed alongside data freshness considerations.
Configuration Options
Section titled “Configuration Options”The exact controls applied to your environment depend on your organisation’s agreed iPCV configuration and data sharing requirements. This configuration is set during initial customer onboarding, so it is important to ensure that your requested configuration meets your requirements.
How Can I Find My Configuration?
Section titled “How Can I Find My Configuration?”If you are unsure which configuration has been applied:
- Review the implementation documentation provided during onboarding.
- Consult your organisation’s data sharing agreement.
- Contact your Explorer support representative.
Best Practices
Section titled “Best Practices”Understand your configuration
Section titled “Understand your configuration”Ensure data consumers understand which privacy and filtering controls are applied to the environment before interpreting record counts and analytical results.
Consider filtering when investigating differences
Section titled “Consider filtering when investigating differences”If record counts differ from expectations, review applicable filtering controls before assuming data quality issues exist.
Document assumptions
Section titled “Document assumptions”Where reporting outputs are shared externally, consider documenting any filtering controls that may affect interpretation of results.
Validate comparisons carefully
Section titled “Validate comparisons carefully”Comparisons between customers, environments or reporting platforms should take privacy and filtering differences into account.
Frequently Asked Questions
Section titled “Frequently Asked Questions”Why do my counts differ from source systems?
Section titled “Why do my counts differ from source systems?”Source systems may contain records that are excluded from iPCV due to configured privacy, governance or filtering controls.
Why are some clinical records missing?
Section titled “Why are some clinical records missing?”Records may be excluded because of patient-level filtering, National Data Opt-Out controls, local opt-out controls, sensitive patient filtering, sensitive code filtering, or confidentiality controls. The exact behaviour depends on the configuration applied to your environment.
Does every customer receive the same data?
Section titled “Does every customer receive the same data?”No. The data available within iPCV is determined by the configuration and governance controls agreed for each customer.
How do I know which filtering options are enabled in my environment?
Section titled “How do I know which filtering options are enabled in my environment?”Refer to your implementation documentation or organisational data sharing agreement for details of the controls that have been applied.
What is the difference between confidential and sensitive?
Section titled “What is the difference between confidential and sensitive?”- Confidential is a marking applied to a patient’s whole record, or to an individual event, by the organisation. The application of confidential policies can therefore vary between organisations.
- Sensitive is externally defined and applied across all organisations — via PDS for patients and SNOMED concepts for events.