Information technology (IT) and health

On this page we will help you to identify any new practices in IT and technology that may impact your healthcare.

Page contents

Risk stratification

Risk Stratification is a process that identifies patients who are likely to have poor health and to use several services. It helps the NHS to prioritise their care and to reduce and prevent poor outcomes for those patients. It also helps identify patients who would benefit if their GP was proactive in offering support. Using Risk Stratification, GPs can also assess how suitable available treatments are for their high-risk patients.

More information on risk stratification can be found on the NHS England information governance webpage. You can also download the poster below. Please note this activity has been approved by the Secretary of State, following advice from the Confidentiality Advisory Group.

The poster for Risk Stratification sent to GP surgeries.

What is risk stratification?

We use a system called ‘Eclipse’ to better understand our patients’ health needs. This means we use ‘case finding’ technology to screen our health records and flag how we can plan and organise your healthcare and identify possible risks to your health.

The information attained by using Eclipse is assessed by your care team and decisions are never made by technology alone.

To find out more visit the NHS Cornwall and isles of Scilly website, speak to your GP or at ask reception.

https://cios.icb.nhs.uk/health/primary-care or call 01726 627800.

The QR code linking to Your GP surgery web page.

Privacy notice

Patient data and how we keep it safe

Access to patient data is part of the essential activities of the NHS. It helps with decision-making on service delivery and improvements in healthcare. Section 251 of the NHS Act 2006 allows the use of confidential patient information for defined purposes when it is not possible to use anonymised information and when seeking consent from individuals is not practical. Section 251 will continue to be required until the processes to link data in pseudonymised form are properly developed within the NHS.

  • Anonymised data: information identifying the patient has been removed, so we can’t tell who the data belongs to.
  • Pseudonymised data: most of the identifiable elements are removed or ‘scrambled’. The people who do have a legal right in the NHS to see the identifiable data – the GP or a clinician working in a GP practice – can see the data and know who it belongs to, so that they can offer support to the high-risk patients identified through Risk Stratification.

Authorisation

  • The ICB produces anonymised data from individual identifiable patient records held in a regional data repository which the ICB does not have access to, in order to support Risk Stratification activities.
  • The ICB sometimes collects and uses information about past or present geographical location from patient records held in the same repository. Postcodes are required for ward-level analysis. As there is a potential to identify individual patients using this information, it is regarded as ‘patient-identifiable data’ or PID.
  • The ICB is able to identify, and with appropriate ‘Data Controller’ approval, contact patients to invite them to participate in medical research. The ICB can also use patient data for medical research. However, it very rarely does this, as most medical research is undertaken outside the ICB and by non-ICB staff.
  • The ICB links patient-identifiable information from more than one source, validating the completeness or quality of the information.
  • The ICB has the authority to process certain patient identifiable information (usually NHS number only) for the purpose of auditing, monitoring and analysing patient care or treatment.
  • The ICB has the authority to process patient identifiable information for an authorised user for one or more of the purposes outlined above.

Protection

The ICB protects this information by using security and confidentiality processes recognised by the community (NHS organisations and the public) to be more advanced than other national data collection and aggregation initiatives.

  • The ICB stores and analyses the information in a secure environment.
  • Access to this information is restricted to appropriate members of the ICB.
  • The ICB provides regular (annual) mandatory and specialist Information Governance training to all ICB staff.
  • The ICB ensures the information collected conforms to the strict rules of confidentiality established by Acts of Parliament, including the Data Protection Act, the NHS Act 2006, and Health & Social Care Acts.

Our Data Protection Officer is responsible for monitoring our compliance with data protection requirements. You can contact them with queries or concerns relating to the use of your personal data at ciosicb.pcdt@nhs.net.

Opting out

For more information about how your data is used, or to opt out, please contact your GP surgery or contacting the Integrated Care Board contact email. More information can be found on the ICB website.

Page last reviewed: 23 January 2026

Text Size

Change font

Contrast