Privacy Notice – Invoice Validation

Privacy Notice – Invoice Validation

Purpose and Legal basis for processing

Invoice validation is an important process. It involves using your NHS number to check that we are the CCG that is responsible for paying for your treatment.

There are situations where identifiable patient personal data is required to ensure that the correct service provider is paid.

In such cases, service providers are required to send identifiable patient personal data such as the NHS Number to a Controlled Environment for Finance (CEfF). Midlands and Lancashire Commissioning Support Unit is an accredited Controlled Environment for Finance (CEfF) which enables them to process patient identifiable information on behalf of West Lancashire CCG without consent for the purposes of invoice validation. We will also use your NHS number to check whether your care has been funded through specialist commissioning, which NHS England will pay for. The process makes sure that the organisations providing your care are paid correctly.

NHS England has published guidance on how invoices must be processed and Commissioners have a duty to detect report and investigate any incidents of where a breach of confidentiality has been made.

Under the NHS Act 2006, provision is made for the sharing of patient information that is in the interests of improving patient care or deemed to be in the public interest. This is commonly referred to as a Section 251 exemption that allows the common law duty of confidentiality to be bypassed in order to fulfil a task in the interests of improving patient care or in the public interest. The specific reference for this exemption is: CAG 7-07(a)(b)(c)/2013. As such, our legal basis under GDPR is Article 6(1)(e) ‘…exercise of official authority…’. For special categories (health) data the basis is Article 9(2)(h) ‘…health or social care…’.


Sources of the data

The sources of data are providers who submit invoices to NHS Shared Business Services for payment.

Categories of Personal data

The data required for effective invoice validations can be found in appendix B. of “Who Pays? Information Governance Advice for Invoice Validation” which you can find here:

Recipients of personal data

Midlands and Lancashire Commissioning Support Unit is the only organisation that will have receive personal data relating to invoice validation as an accredited Controlled Environment for Finance.

Last updated on 29 September 2021 at 06:46 by Meg Pugh