Information Governance in Healthcare Education: A Practical Guide

Illustration of GDPR and HIPAA compliance for healthcare video data

A 2024 nationwide survey checked every acute NHS trust and board in England and Wales. Only 22 of 140 routinely recorded surgical procedures. Governance policies for that recording existed in fewer than half. GDPR and HIPAA compliance did not close that gap. Information governance is the discipline that does. It decides what data an institution captures, who can use it, how long it stays, and when the institution deletes it. This guide explains what information governance means in healthcare education, how it differs from data protection and security, and how to build a program around it.

What Is Information Governance in Healthcare?

Most institutions that record clinical assessments already have a GDPR policy and a HIPAA policy. Almost none have decided who owns the recording once both boxes are checked. Almost none have set how long it should exist, or who confirms its deletion. That ownership question, not the legal minimum, is what information governance actually answers.

The American Health Information Management Association defines the discipline this way: the overall administration, through clearly defined procedures and plans, that assures the availability, integrity, security, and usability of an organization’s data. A 2024 scoping review traced the concept back to the NHS’s Caldicott Principles in the late 1990s. Healthcare later formalized it through the Information Governance Principles for Healthcare framework, published by AHIMA in 2014. The review, covering 37 studies, groups health information governance into six components: goals, applications, principles, structural elements, roles and responsibilities, and processes. Ghaffari Heshajin and colleagues conducted this review.

Information Governance vs. Data Protection vs. Data Security

Information governance is the umbrella discipline. Data protection and data security sit underneath it. They are compliance requirements, not replacements for governance itself.

GDPR and HIPAA set legal minimums for protecting personal and health data. GDPR Article 9 restricts the processing of health data. The HIPAA Privacy Rule governs how US entities use and disclose protected health information. Neither rule tells an institution what to record, who should review it, or when to delete it. Information governance answers those questions.

The same scoping review lists data security and legal compliance as two goals of health information governance among several. Other goals include equitable access to healthcare information and dependable services. Compliance answers whether an institution followed the law. Governance answers whether its data practices actually work for patients, students, and staff. Videolab’s HIPAA FAQ covers the compliance layer in more detail.

The Healthcare Data Lifecycle: Capture, Process, Use, Store, Dispose

Every recording moves through five stages. An OSCE station follows this path. So does a simulation debrief. Each stage carries its own governance decision.

AHIMA describes a five-part data lifecycle. Capture means recording data in health information systems. Process covers the actions that turn a recording into something usable, such as tagging or transcription. Use means access, sharing, and analysis. Store means maintaining and archiving the file. Dispose means destroying it on a retention schedule.

Apply this to a recorded OSCE station. Capture means deciding what the camera frames and what audio it collects. Process means deciding who tags the recording against a rubric. Use means deciding which examiners or moderators can open the file. Store means deciding where it lives and for how long. Dispose means deciding when it gets deleted, and confirming that deletion actually happens.

Institutions often treat these five stages as one storage decision. They then lose track of the later stages first. Retention limits and deletion are consistently the weakest part of recorded assessment governance. The initial capture is rarely the problem.

Governance Roles: Who Owns Information Governance?

Information governance needs a named owner at each level. A policy document alone will not do the job. AHIMA describes a hierarchy running from a Chief Data Officer, through a Data Governance Office, down to data trustees and data stewards. Stewards sit closest to the daily recording and review work.

Data stewards define what a rubric term means. They approve how data gets used. They monitor quality at the point where staff capture and review recordings. A deployment spanning multiple simulation centers needs this stewardship kept close to the people who understand the assessment. Central IT and legal review can then handle the regulatory layer, often through a Data Protection Officer or equivalent.

Why Information Governance Gaps Are Common in Healthcare Education

Most institutions that record clinical training assume their GDPR or HIPAA compliance already covers governance. A 2024 nationwide Freedom of Information request tested that assumption across every acute NHS trust and board in England and Wales.

Yiu and colleagues found that only 22 of 140 responding trusts routinely recorded surgical procedures. That is 15.7 percent. Among those that did, governance policies covering recording, use, and storage existed in only 59 of 140 trusts. That is 42.1 percent. Just over a third had limited how long surgical video could be stored. Fifteen of 140 reported no storage limit at all. The authors call this significant heterogeneity in surgical video recording practices. Governance, consent, and storage policies varied widely, even among institutions that recorded routinely.

Recording more is not the fix either. A University of Manchester study reviewed the literature on video-marked OSCEs. The researchers also surveyed assessment leads at 31 UK medical schools and postgraduate institutions. Video marking tended to produce lower scores than live marking. Hogley and colleagues concluded that video recording does not currently support student appeals in the literature. Most institutions running high-stakes OSCEs agree. The researchers recommended examiner training, clear marking descriptors, and enough OSCE stations for reliable analysis instead.

Both findings point to the same gap. Recording infrastructure is not governance. More recording without a clear access, retention, and review policy creates risk. It does not reduce it.

Regulatory Frameworks Under Information Governance: GDPR, HIPAA, and NIS2

GDPR, HIPAA, and NIS2 set the legal floor an information governance program has to clear. Each one covers a different piece of the picture.

In the European Union, GDPR Article 9 treats health data as a special category requiring explicit safeguards. Article 32 sets security-of-processing requirements. Article 35 defines when an institution needs a Data Protection Impact Assessment. Videolab’s guide to GDPR compliant video recording covers these requirements for healthcare education specifically.

In the United States, the HIPAA Privacy Rule governs how entities use and disclose protected health information. The Security Rule requires safeguards for electronic protected health information. The Breach Notification Rule sets the timeline for reporting a breach. Videolab’s comparison of GDPR and HIPAA goes through these obligations in more depth.

Institutions operating in the EU also need to account for the NIS2 Directive. It extends cybersecurity resilience requirements to healthcare providers as essential entities. None of these frameworks, alone or together, specifies what to record, who reviews it, or when to delete it. Building the information governance program around them is the actual job.

Building an Information Governance Program for Healthcare Education

A working information governance program starts with a charter, not a checklist. AHIMA recommends defining the program’s scope and decision-making authority first. Add a small set of guiding principles before writing any procedure. Data is a strategic asset carrying both value and risk. Data-related decisions should sit at the lowest reasonable level. Not all data warrants the same protection, and protected health information needs the highest scrutiny.

For a healthcare education program, that means naming who decides what gets recorded. It means naming who can review a recording, how long it stays, and who confirms its deletion. Do this before the first camera turns on. Assign these decisions by role, not by individual. That keeps the program running when staff change.

Videolab supports this structure directly rather than leaving it to policy documents alone. Role-based access controls limit who can open a recording to the assigned examiners, supervisors, or moderators. Retention settings enforce deletion on a schedule instead of relying on manual follow-through. None of this replaces the governance decisions above. It gives an institution a way to enforce them consistently once it makes those decisions.

Share the Post:
Scroll to Top