Invoice validation

Confidentiality Advisory Group (CAG) approval to s251 support for invoice validation data processing (CAG 7-07(a-c)/2013)

NHS England has received approval of their amendment application Under regulation 5 of the Health Service (Control of Patient Information) Regulations 2002 (section 251 support) to extend support for the processing of confidential data for Invoice Validation.

This support is extended for 24 months until the end of September 2027 and allows Integrated Care Boards (ICBs) and NHSE Commissioning Support Units (CSUs) to process personal confidential data which are required for invoice validation purposes, subject to a set of conditions.

It is envisaged that the Control of Patient Information Regulations 2002 will be amended to allow the validation of invoices, which is critical to support NHS services, without separate CAG approval prior to the next renewal date.

Secretary of State for Health and Social Care support decision

  1. The Secretary of State for Health and Social Care, having considered the advice from the Confidentiality Advisory Group as set out below, has determined the following:

The amendment to extend the duration of support for two years until 30 September 2027 is conditionally supported, subject to resolving the security assurances set out in this letter within three months, and continued adherence to the existing specific and standard conditions of support.

Amendment request

In this amendment, the applicants requested an extension to the duration of support to continue the legal basis permitting integrated care boards (ICBs) and commissioning support units (CSUs) to process confidential patient information under Regulation 5 of the Health Service (Control of Patient Information) Regulations 2002 for invoice validation purposes. Support is currently in place until 30 September 2025 and the applicants sought to extend this by a further 24 months until 30 September 2027.

As responsible data controllers, ICBs continue to be responsible for undertaking a review of their processing activities and updating their own privacy notices in order to ensure transparency around their data processing activities related to invoice validation.

Updated controlled environments for finance register

NHS England has updated the Controlled environment for finance (CEfF) register to reflect recent organisational changes and any notified amendments from ICBs/NHS England CSUs.

Organisations should email: england.pttigadvice@nhs.net to notify of any changes to information in the register.

Organisation privacy notices

ICBs are responsible for their invoice validation processing activities and therefore have their own privacy information about how your data is used.