How to Complete Your Annual Information Governance Refresher Online

Annual information governance training helps hospital staff protect confidential information, use digital systems appropriately and recognise risks before they become incidents. For learners and staff using the Gloucestershire Hospitals NHS Foundation Trust eLearning portal, the refresher is generally completed online through the local learning environment and recorded against the relevant training requirement.

Australian readers may be accessing the portal while working with an NHS-linked programme, studying remotely or comparing UK practice with local requirements. The basic process is familiar: sign in, locate the assigned module, complete the learning and assessment, then check that the completion record has been saved.

Stage What to do Evidence to retain
Sign in Use the account and access route provided by your organisation Successful login or dashboard view
Find the module Search for the annual information governance refresher Module title and due date
Study the content Read each topic and complete required activities Progress status
Take the assessment Answer the knowledge check honestly and review any feedback Pass result or completion screen
Confirm the record Check that the course shows as complete Certificate, transcript or screenshot

Access the right learning portal

Start with the official Gloucestershire Hospitals NHS Foundation Trust eLearning portal address supplied by your employer, placement coordinator or course administrator. Avoid using a search result that looks similar but is not an approved NHS website, particularly when signing in with a work username or handling personal information.

Some users may need an NHS or Trust account, while learners may receive separate credentials or an invitation link. Enter your details carefully, and do not share passwords by email, text message or workplace chat. If multifactor authentication is enabled, use the approved method rather than forwarding a verification code to another person.

The portal is designed around Gloucestershire Hospitals staff and learners, so Australian users should distinguish between access instructions and local policy. A NSW Health, Queensland Health or Victorian public health employee may have a separate training system for mandatory education, even if the subject matter is similar.

Prepare before you sign in

Use a supported browser on a trusted device, preferably a managed work computer or an approved laptop. A stable connection is important because a module may contain interactive pages, audio, video or a timed knowledge check. If you are working from Australia, remember that Gloucestershire and Melbourne or Sydney operate in different time zones, especially when daylight saving changes.

Set aside enough uninterrupted time to read the material rather than clicking rapidly through screens. Close unrelated clinical systems and remove patient identifiers from your desk, notes and browser tabs. Training should be completed in a private setting, not on a shared computer in a hospital foyer, public library or busy café.

Have your staff or learner identification details available, but do not copy real patient information into a quiz, free-text box or support request. The same care applies when working with Australian records. Information in My Health Record, local electronic medical records and hospital referral systems must be accessed only for a legitimate work or care purpose.

Complete the learning activities

After signing in, open the assigned learning area and search for the annual information governance refresher online. The title may vary slightly, so look for terms such as information governance, confidentiality, data protection, cyber security, records management or mandatory refresher training. Check the due date and whether the module is marked as annual, recurring or assigned.

Work through every required screen and activity. Common topics include the lawful handling of personal data, secure disposal, clean-desk practice, strong passwords, phishing, access permissions, incident reporting and the safe use of email. Clinical staff should also consider how information moves between bedside documentation, pathology, imaging, discharge summaries and external services.

Governance principles apply across borders, but legal frameworks differ. In Australia, the Privacy Act and Australian Privacy Principles are important for many organisations, while state and territory health services may impose additional rules. Do not assume that completing a UK module replaces training required by an Australian employer or regulator.

Complete the assessment carefully

The final knowledge check may use multiple-choice questions, scenarios or a pass threshold. Read each question fully, especially where the options distinguish between a permitted use, an inappropriate disclosure and a reportable incident. If you answer incorrectly, use the explanation to understand the policy rather than simply repeating an option.

A realistic scenario might involve receiving a suspicious attachment, finding printed clinical notes in a public area or being asked to disclose information to a relative. The safest response is usually to verify identity and authority, limit access to what is necessary, and report uncertainty through the approved channel.

Information governance also supports clinical learning and research. When reviewing specialist material, such as discussion of atrial fibrillation triggers, use only authorised sources and never upload identifiable patient details to an external website or research forum. Educational interest does not create permission to disclose confidential information.

Apply the principles in Australian practice

The refresher is most useful when connected to everyday work. In an Australian hospital, that may mean checking a patient’s identity before opening a record, using secure messaging approved by the service, and confirming that a family member has the right authority before discussing care. Casual phrases such as “Can you just send me the notes?” should prompt a verification check, not an automatic reply.

Be particularly careful with Aboriginal and Torres Strait Islander health information. Cultural safety and community expectations matter alongside privacy law, and information may carry collective, family or community significance. Follow the policies of the health service and the relevant local data governance arrangements rather than relying on assumptions based on personal familiarity.

Remote work creates further risks. A staff member in Perth, Adelaide or regional New South Wales may be completing training outside ordinary UK office hours, but support, access permissions and incident reporting still need to follow the organisation’s documented process. Use an approved virtual private network or secure connection where required, and avoid downloading course material to an unmanaged personal device.

Check completion and keep a clear record

When the module ends, look for a completion message, pass result, certificate or updated transcript. Some portals record progress automatically; others require the learner to select a final button or return to the dashboard. Refresh the page and check that the status has changed from assigned or in progress to complete.

Save the available evidence according to workplace policy. A certificate, confirmation email or screenshot can help if a manager later asks about mandatory training, but do not store it in a folder containing patient records. If the course remains incomplete after you have finished it, record the date and module name before contacting the eLearning Helpdesk by the published phone number or email address.

If you cannot sign in, report an expired account, missing assignment or technical error with enough detail for support staff to investigate. Include your learner or staff ID through a secure channel, the browser and device used, and the exact error message without including confidential clinical information. The essential point to remember is that completion means more than passing a quiz: it means knowing how to protect information, use access responsibly and report a concern promptly.