Skip to main content Skip to footer

Secure Data Environment: What it means for GP practices

What is a Secure Data Environment

A cloud-based platform that allows researchers and analysts to safely access health and care data for a specific project and purpose. Data access is tightly controlled, and record level data cannot be removed from the environment.

The North East and North Cumbria is one of 10 regions to receive funds from NHS England to create a ‘Secure Data Environment’. 

GPs and other data providers such as hospital and mental health trusts are being approached to support sharing data into a regional Secure Data Environment to allow researchers and planners to have safe access to anonymised patient records.

In this video, Dr Mark Dornan explains how the Secure Data Environment can support both patient care and GP services while keeping data safe.

Find out more about the Secure Data Environment and what it means for GP practices

If you have any questions about the programme, please contact the team.

Sharing GP data for research and development

GP practices that choose to share data for research and planning purposes can play a key role in driving medical breakthroughs, without the hassle of reviewing multiple data-sharing requests. By signing up, you will help advance health research, improve understanding of population needs, and support better care for our communities.

Why share data?
GP practices are often asked on a project-by-project basis to share data. By establishing regular data flows to a regional Secure Data Environment, practices can avoid repeated requests. Under a regional agreement, practive data will be securely held alongside other datasets, ensuring it’s only used for research and development purposes.

How it works

  • GP practices will have the opportunity to complete a data-sharing agreement
  • The Data Access Committee and the ICB (Integrated Care Board) will review and approve all project requests, ensuring they meet strict protections and protocols
  • The committee includes GPs, public representatives, and other experts to ensure compliance with the "5 Safes" framework, and whether the project is in the public interest.

This process allows GPs to contribute to research while reducing their workload.

Looking ahead
We are working with trusts and other data providers to make health and care data accessible for research and planning projects. A public information campaign is underway to raise awareness as data sharing expands.

Get involved
If your practice would like to start sharing data with the Secure Data Environment, please contact our team at: nencsde@healthinnovationnenc.org.uk 

Some GP practices currently receive service support costs for research activities such as identifying eligible patients, providing datasets, and inviting patients to participate in studies. These activities are coordinated by the NIHR Clinical Research Network, now known as the Research Delivery Network, or directly by commercial organisations. Many GP practices also participate in the Clinical Practice Research Datalink (CPRD). These initiatives are separate from the work of the Secure Data Environment and will continue as before.

The Secure Data Environment offers an additional benefit by providing researchers with access to data collated from all GP practices, linked with secondary care datasets to deliver a comprehensive, system-wide overview. Achieving this level of integration and scale has historically been very challenging. By streamlining access to linked datasets, the Secure Data Environment will make our region a more attractive hub for research, facilitating greater use of existing data resources.

Importantly, participation in the Secure Data Environment is not expected to result in a decline in income for GP practices.

Flows of data from GP practices will be defined through a data sharing agreement between the North East and North Cumbria Secure Data Environment lead controller (which is the ICB) and each GP practice. Once the data is shared into the Secure Data Environment, it becomes the legal responsibility of the lead controller organisation, not the practice.

Liability for any data breach sits with the organisation(s) responsible for the breach in line with existing data protection legislation. As data controllers, GP practices will enter into data processing agreements with the data processor (Northumbria Healthcare NHS Foundation Trust) to ensure full compliance with data protection laws.

GP practices do not need to manage opt outs - any patients who have already selected the National Data Opt Out will be excluded by the source organisation.

There is a Local Opt Out for the NENC Secure Data Environment which is managed by Northumbria Healthcare NHS Foundation Trust, so practices do not need to administer this. Find out more on the opt out page.

The ICB is leading the programme and in collaboration with Health Innovation North East and North Cumbria, Northumbria Healthcare NHS Foundation Trust and Cumbria, Northumberland, Tyne and Wear NHS Foundation Trust (CNTW) to deliver the service.

By making health and care data more accessible, means that more research can happen. However for this to be done in a secure, robust way with standardised processes across the region to control who accesses the Secure Data Environment.

Accessing health and care data for research can be time-consuming and difficult process. The Goldacre Review and the Data Saves Lives strategy proposed the set up of Secure Data Environments as a more secure and efficient way to access data for research and development.

This is now reflected in NHS England policy. Over the coming years access to NHS data will move exclusively to Secure Data Environments.

This creates a simplified and robust route to access the data for research and development, reducing the burden on all NHS organisations including NHS trusts and GPs. Agreed datasets transfer from organisational IT systems to the Secure Data Environment for the purpose of research and development. Access is only granted for approved projects and accredited researchers through the North East and North Cumbria Data Access Committee.

The Secure Data Environment is up and running. We have data from primary care, ambulance, mental and acute trusts coming in. The range of data is expanding and we are in discussions with other data providers including local authorities.

We will support both research and development uses of data in the Secure Data Environment. We use the Health Research Authority guidance to determine whether projects fit into research or development. The types of projects the Secure Data Environment will use include:

  • AI/algorithm development – testing, training and validation
  • Clinical trial activities – feasibility, recruitment, efficacy through short and long term follow-up
  • Real world studies – safety, effectiveness and cost effectiveness
  • Translational research – academic discovery and implementation of discovery into practice
  • Epidemiological studies – large cohorts for population health research
  • Health systems research – evaluation of systems or processes, including operational and applied research
  • Non-research – service planning, evaluation and improvement

Sharing data is optional.

The central, regional governance structure within the Data Access Committee means that GP practices will no longer need to review and assess individual data projects. There is one central process with GP and patient representation to assess whether projects meet public interest and security standards. This reduces the burden on GP practices and shift Data Controller liability to the Integrate Care Board. 

The North East and North Cumbria Data Access Committee assesses and recommends to the ICB whether to approve or refuse access to research and development projects and users. Our Data Access Committee includes data controller representatives from primary and secondary care, public members and data protection officers and information governance and research ethics specialists.

The process also includes a review by members of the public who assess whether the project is in the public interest.

All projects have to complete an application form to use the Secure Data Environment that will be presented to the Data Access Committee. The application will cover the legal basis for the study, how data will be minimised and what benefit the project will provide.

The Research Management Team will guide projects through the process to ensure they meet the required standards for safety and security. They will check that projects have relevant approvals from the Health Research Authority and Confidentiality Advisory Group where applicable. 

We regularly update our involving people page with our activity. You can see the vital role our public members play, and how we are working with communities across the North East and North Cumbria to understand how they feel about their health and care records being used on the Secure Data Environment.

Find out more.

Under UK General Data Protection Regulation the following provides the legal basis for sharing data into the Secure Data Environment:

  •  Article 6.1 e of UK GDPR (e) Public task: the processing is necessary for you to perform a task in the public interest or for your official functions, and the task or function has a clear basis in law.
  • There is a requirement under the Health and Social Care Act to undertake research (paragraph 13(1) of Schedule 1 of the NHS Act 2006) which was updated in 2022 to include Integrated Care Boards.
  • Article 9.2(j) of UK GDPR enables the processing of special category data where “processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with article 89 (1) based on domestic law which shall be proportionate to the aim pursued, respect the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.”

DPA 2018 enables the processing of special category data under Schedule 1 part 1 section 4

a)    For archiving purposes scientific or historical research purposes or statistical purposes,

b)    is carried out in accordance with article 89 one of the UK GDPR (as supplemented by section 19)

c)     is in the public interest

 

Common Law Duty of Confidentiality:

The ICB has an approved S251 application to set aside Common Law Duty of Confidentiality for the purpose of treating personal confidential data to pseudonymise, link and de-identify it for use in the NENC Secure Data Environment. The S251 also enables the generation of a research database (the NENC Secure Data Environment itself).

 

NENC Secure Data Environment also has separate Research Ethics Committee approval which covers both the use of the data flowing into the Secure Data Environment and the generation of the research database (the Secure Data Environment itself).

 

This means we have in place the legal basis under UK GDPR and Common Law to flow data into the Secure Data Environment.

 

A second S251 application is being developed for non-research purposes and is expected to be submitted by the end of 2024/25.

There remains significant public and professional confusion about the distinction between the Federated Data Platform (FDP) and Secure Data Environments (SDEs). The FDP and SDE are two different products and have different suppliers.

  • The FDP is an operational data platform that enables NHS organisations to link and use data for direct care and service management. Access is role‑based, data remains under NHS control.
  • The SDE is a highly secure environment designed to protect sensitive data while allowing approved users to carry out analysis. Data is accessed within the controlled environment and cannot be freely removed. SDEs are typically used for research, statistics, and evaluation, with strict controls in place to protect privacy and confidentiality. They allow organisations to tightly specify:
    • who can access data
    • exactly which data they can see
    • what analyses can be performed
    • what outputs can be released

Each programme has different legal and governance set up and are only allowed to be used for their specific purpose. SDE does not use Palantir. The North East and North Cumbria SDE platform stays within the NHS and is hosted by Northumbria Healthcare NHS Foundation Trust.

You can find out more about SDEs and the FDP on their respective web pages.

Secure Data Environments brings several opportunities to improve the health and wealth of our region. The Secure Data Environment covers both research and planning use cases which North East and North Cumbria can benefit from.

Research

We experience many of the worst healthcare outcomes, lowest levels of life expectancy, more time in poor health.

Our region features at the bottom of NIHR investment weighted against population need.

The Secure Data Environment will enable MORE research to happen – making the research pie bigger and improving healthcare outcomes for our population.

The Secure Data Environment will not replace patient consented clinical trials and research projects.

By creating a rich research and development data set we will increase our offering to researchers (commercial and non-commercial) and make the region an attractive place to carry out projects.

Our population is attractive to researchers as we have high health needs, with high instances of disease and a static population, although we are less ethnically diverse than other regions.

We also know from published literature that organisations who take part in research often perform better. Their patients benefit from the latest treatments and their staff are upskilled in new ways of working, also helping to make our regional organisations a great place to work.

The Secure Data Environment will enable us to carry out new research and development activities which is currently not possible, or very challenging. The ability to link datasets between primary and secondary care and between organisations for the purposes of research and development, will encourage collaborative working, unique project opportunities and answer important research questions.

These new opportunities will bring additional revenue to our region and participating organisations.

For example, AI projects using datasets to improve diagnostics and workflow improvements –ultimately benefiting patient care.

Service planning and improvement

It can take many years for the benefits of research projects to materialise. A key opportunity the Secure Data Environment presents is near real-time, data driven decisions around service improvement and planning. As we move towards group models of hospital care, and move care into communities, we need to understand these pathways and make the right decisions about how care is provided.

Being able to access data across different organisations will help us to manage demand projection, capability requirements and workforce planning at both trust and regional level. The Secure Data Environment is additionally driving standardisation of data definitions, enabling and ensuring stakeholders are able to speak the same language.

Standardisation of data management

Having a single platform, agreed data definitions, a single access process and a single set of information governance protocols increases the pace and scale under which we can carry out research and planning projects.

Yes, the Secure Data Environment can be accessed by a variety of researchers, including industry/commercial, NHS, academia, charities etc. However, all access requests will be subject to user validation in addition to a comprehensive project approval process. Our Data Access Committee will assess applications on an equal basis. In additional, all applications must pass a ‘public interest’ test with a panel of members of the public.

All applications will be treated the same, following the same governance and processes.

Contact the programme team and we will send you the paperwork.

No, patient information is anonymised or pseudonymised so patients can’t be re-identified and contacted.