Privacy Analytics Platform
IQVIA's Privacy Analytics Platform provides Privacy Enhancing Technologies with a range of flexible capabilities, including Data Cataloging/Data Governance Enablement/Anonymisation/Pseudonymisation/Data Linking and Differential Privacy. This solution enables organisations to safely use/share patients personal data, across many modalities (structured, unstructured text, imaging). The platform complies with good governance and UK privacy standards.
Features
- Data Anonymisation
- Data Cataloguing
- Data governance enablement
- Identifiability and Re-identification risk analysis/intelligence
- Privacy assurance reporting
- Data anonymization and treatment automation and scheduling
- Unstructured data(e.g. Text and Images) protection/anonymisation
- Data pseudonymisation/masking/generalisation/suppression/date shifting, other data transformations
- Differential privacy, synthetic dataset creation
- Data linking and matching
Benefits
- Ensure public trust with defensible privacy protection
- Mitigate reputational risk by demonstrating strong privacy safeguards
- Comply with UK GDPR/ICO requirements for data anonymisation / pseudonymisation
- Accelerate safe data access, driving efficiencies with automated privacy
- Enable auditability, privacy, transparency, trust for data flows
- Implement the Five Safes Framework
- Measure, understand, quantify, manage data privacy risks
- Create safe/synthetic datasets for research, R&D/testing, other needs
- Improve the quality, utility, scale of anonymised data
- Safely link and match datasets without revealing patient identities
Pricing
£60,000 a unit a year
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
9 8 2 0 4 1 3 1 5 8 1 9 5 1 5
Contact
    IQVIA LTD.
    
    Bhavin Shindroja
    
    
    Telephone: 0203 075 5019
    
    
    Email: nhssolutions@iqvia.com
    
  
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- 
      - Private cloud
- Hybrid cloud
 
- Service constraints
- No
- System requirements
- Dependant on specific characteristics of Client requirements
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- This will be set out within the agreed SLA with client.
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- The IQVIA Service Team will act as a single point of contact for the client. Itis the mission of the Service Team to provide the client with a great service experience and to resolve any issues or requests in an effective manner and within the agreed timescales. The Service Team have accountability for all the Service Management processes and work across our Delivery Teams to monitor all aspects of the service, manage governance and risk and continually review and recommend improvements. IQVIA provides unlimited support queries relating to any aspect of the solution. Our Service Team will monitor Major Incidents, Incidents, Service Requests and Problem Management resolution timings. In agreement with the client, Severity Levels will be allocated to Incidents, Service Requests and Problem Records. IQVIA will allocate an account manager to the client.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- At contract initiation a member of our team will discuss your requirements and with your input, plan and execute an approach. As part of the approach the appropriate training will be provided to your team(s).
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- This will be dependent on the Client requirements and specific service components and will be discussed at contract start.
- End-of-contract process
- This will be discussed with the client at contract start with the client.
Using the service
- Web browser interface
- Yes
- Supported browsers
- 
      - Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
 
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- 
      Authenticate with the solution
 Read and write meta-data
 Configure and Execute processes
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- There are a number of ways the service can be customised and is specific to the requirements of the client. Please contact us to discuss these options.
Scaling
- Independence of resources
- Each client will have its own deployment. Additionally, auto-scaling can be discussed at contract time.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- 
      - Physical access control, complying with another standard
- Other
 
- Other data at rest protection approach
- IQVIA have implemented a Global Information Assurance Framework to provide information assurance to information assets. It is based on industry standards and regulations including GDPR, HITRUST, the ISO 27000 family, COBIT, HIPAA, HITECH and NIST. All data assets are assessed against an Information Classification Level in order for the appropriate safeguards and controls to be implemented. The control sets cover the following areas: Access Control; HR Security; Compliance; Asset Management; Physical Security; Operational
- Data sanitisation process
- Yes
- Data sanitisation type
- 
      - Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
 
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- The options can be discussed with the client to ensure IQVIA provide this appropriately.
- Data export formats
- CSV
- Data import formats
- 
      - CSV
- Other
 
- Other data import formats
- 
      - Database
- Parquet
 
Data-in-transit protection
- Data protection between buyer and supplier networks
- 
      - Private network or public sector network
- TLS (version 1.2 or above)
- Other
 
- Other protection between networks
- IQVIA have implemented a Global Information Assurance Framework to provide information assurance to information assets. It is based on industry standards and regulations including GDPR, HITRUST, the ISO 27000 family, COBIT, HIPAA, HITECH and NIST. The framework includes the management of Risk, Cryptography, Change, vulnerability and monitoring and these policies and controls apply to the management of the data that is in transit. Data is transferred encrypted typically using N3. Our approach ensures ahigh level of data protection, security and confidentiality in our Products and Service.
- Data protection within supplier network
- 
      - TLS (version 1.2 or above)
- Other
 
- Other protection within supplier network
- IQVIA have implemented a Global Information Assurance Framework to provide information assurance to information assets. It is based on industry standards and regulations including GDPR, HITRUST, the ISO 27000 family, COBIT, HIPAA, HITECH and NIST. The framework includes the management of Risk, Cryptography, Change, vulnerability and monitoring and these policies and controls apply to the management of the data that is in transit. Data is transferred encrypted typically using N3. Our approach ensures ahigh level of data protection, security and confidentiality in our Products and Service.
Availability and resilience
- Guaranteed availability
- SLAs can be discussed at contract time with client
- Approach to resilience
- To be discussed with client on contract start.
- Outage reporting
- Service outages are communicated to internal stakeholders and external key contacts by the IQVIA Service Delivery team in line with ITIL Service Management processes
Identity and authentication
- User authentication needed
- Yes
- User authentication
- 
      - Username or password
- Other
 
- Other user authentication
- Role based access controls and can integrate with common authentication services
- Access restrictions in management interfaces and support channels
- Interfaces and support channels Asset owner and Access Control Register will govern who can access the service in addition to the authentication management access
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI (UKAS accredited certificate)
- ISO/IEC 27001 accreditation date
- 11/04/2023
- What the ISO/IEC 27001 doesn’t cover
- There are no exclusions to the ISO 27001 Statement of Applicability
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
- 
      - HSCIC Information Governance Toolkit (ISMS Certificate)
- ISO 27001 Lead Implementer
- ISO 27001 Auditor
 
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- IQVIA is committed to Information security and we operate under a Corporate Global Information Assurance Framework to ensure the management, controls and protection of our information Assets and those entrusted to us by clients and business partners The Global Information Assurance Framework is based on industry standards and regulations including GDPR, HITRUST, the ISO 27000 family, COBIT, HIPAA, HITECH and NIST. In addition IQVIA also maintains and aligns with a current NHS Digital Information Governance Toolkit with a ‘compliant’ status. IQVIA approach ensures a high level of data protection, security and confidentiality in our Products and Service. IQVIA also comply fully with our obligations under the NHS Digital IG Toolkit and we maintain a ‘compliant’ status. N3 is used for Support and Project work and staff undergo data protection, confidentiality and ISO27001 training so they understand their responsibilities in their role. We also ensure we follow the clients IG policy and data security processes
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
- The IQVIA Service Delivery team follow an Operational Change Management process aligned with ITIL standards
- Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
- The IQVIA Global Information Assurance Framework provides information assurance to information assets. It is based on industry standards and regulations including HITRUST, the ISO 27000 family, COBIT, HIPAA, HITECH and NIST. Vulnerability management process consists of Risk Assessment, Vulnerability test and Penetration test. Findings out of these assessments are prioritised and addressed. Change, Patch and Asset management processes helps in identifying and mitigating the vulnerabilities and the associated risks.
- Protective monitoring type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Protective monitoring approach
- IQVIA Global Information Assurance Framework provides information assurance to information assets. It is based on industry standards and regulations including HITRUST, the ISO 27000 family, COBIT, HIPAA, HITECH and NIST. Protective monitoring process includes review of access and resource requests, system errors, system logs, security threats, weaknesses or vulnerabilities. These events are logged with a service desk and recorded in a service management system. Necessary remediation measures are taken to address the risks.
- Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
- IQVIA has an integrated Incident and Problem Management process aligned with ITIL standards
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
- 
      Social Value - Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
 Fighting climate change At IQVIA we understand our role as an effective steward of the environment, and we take seriously our responsibility. As members of the United Nations Global Compact, IQVIA aligned with four of the UNGC Sustainable Development Goals (SDG) in 2021. IQVIA is committed to the Science Based Target (SBT) initiative, and we have embarked on the process to setan approved SBT to reduce carbon emissions by the end of 2023. Under contract we will fight climate change through:
 • Seeking to deliver additional environmental benefits, including reducing our greenhouse gas emissions, improving air quality, and working with our supply chain to adopt effective practices.
 • Work to influence staff, suppliers, customers and communities to support environmental protection and improvement across the length of the contractsCovid-19 recovery IQVIA understands the impact Covid 19 has had, and through our social value work we are committed to help local communities’ recover from the impact of the pandemic. Whilst most of these activities are addressed through other TOMs, we to further our support we also ensure that we are:
 • Creating employment and re-training opportunities for those left unemployed by COVID-19,
 • Ensuring support for the physical and mental health of employees affected by COVID-19
 • Guaranteeing appropriate workplace conditions that support the COVID-19recovery effort including remote working, and sustainable travel solutions.Tackling economic inequality IQVIA are committed to tackling economic inequality through the creation of new jobs, develop our workforces’ skills, and increasing our supply chain capacity.
 Some of the ways we achieve this through:
 • Creating training opportunities for young people through schools, colleges, work experience and apprenticeships
 • Creating employment opportunities, particularly for those who face barriers to employment
 • Diversifying our supply chain including new businesses and entrepreneurs, start-ups, SMEs and VCSEs.
 • Taking action to identify and manage cyber security risks internally and across our supply chain.Equal opportunity IQVIA are committed to tackling economic inequality through the creation of new jobs, develop our workforces’ skills, and increasing our supply chain capacity.
 Some of the ways we achieve this through:
 • Creating training opportunities for young people through schools, colleges, work experience and apprenticeships
 • Creating employment opportunities, particularly for those who face barriers to employment
 • Diversifying our supply chain including new businesses and entrepreneurs, start-ups, SMEs and VCSEs.
 • Taking action to identify and manage cyber security risks internally and across our supply chain.Wellbeing The wellbeing of staff, suppliers and communities is core IQVIA’s ways of working. Some of the ways we achieve this through:
 • Taking demonstratable action to support health and wellbeing of our workforce, including their physical and mental health
 • We influence staff, suppliers, customers, and communities to focus on their health and wellbeing, including their physical and mental health.
 • We collaborate with our staff, stakeholders and communities in the co-design and delivery of targeted interventions to support strong, integrated communities.
Pricing
- Price
- £60,000 a unit a year
- Discount for educational organisations
- No
- Free trial available
- No