Government data security consultation

The Government has been conducting a data security review, run by Dame Fiona Caldicott, the National Data Guardian for Health and Care. A report has now been produced with ten proposed standards:

  1. All staff ensure that personal confidential data is handled, stored and transmitted securely, whether in electronic or paper form. Personal confidential data is only shared for lawful and appropriate purposes.
  2. All staff understand their responsibilities under the National Data Guardian’s Data Security Standards including their obligation to handle information responsibly and their personal accountability for deliberate or avoidable breaches.
  3. All staff complete appropriate annual data security training and pass a mandatory test, provided through the revised Information Governance Toolkit.
  4. Personal confidential data is only accessible to staff who need it for their current role and access is removed as soon as it is no longer required. All access to personal confidential data on IT systems can be attributed to individuals.
  5. Processes are reviewed at least annually to identify and improve processes which have caused breaches or near misses, or which force staff to use workarounds which compromise data security.
  6. Cyber-attacks against services are identified and resisted and CareCERT security advice is responded to. Action is taken immediately following a data breach or a near miss, with a report made to senior management within 12 hours of detection.
  7. A continuity plan is in place to respond to threats to data security, including significant data breaches or near misses, and it is tested once a year as a minimum, with a report to senior management.
  8. No unsupported operating systems, software or internet browsers are used within the IT estate.
  9. A strategy is in place for protecting IT systems from cyber threats which is based on a proven cyber security framework such as Cyber Essentials. This is reviewed at least annually.
  10. Suppliers are held accountable via contracts for protecting the personal confidential data they process and meeting the National Data Guardian’s Data Security Standard.

The Government are seeking feedback on the proposed ten standards via an online survey, which is open until 7 September 2016.

Last updated : 19 Jul 2016

 

BMA seek feedback on NHSPS leases without service charges (18 Dec 2018)

The BMA would like to speak to practices in in NHS Property Services premises who have: Written leases without service charge provisions where no payments have historically been made...
Read more »

NHS England and CCGs investigating half-day closing sub-contracting arrangements (18 Dec 2018)

NHS England and various London CCGs have been carrying out analysis of practices’ opening hours based on the information provided in their E-Declarations. Some commissioners have identified practices who have...
Read more »

General Practice Indicators module on the NHS England primary care website updated. (17 Dec 2018)

NHS England have recently updated eight indicators in the General Practice Indicators module on www.primarycare.nhs.uk. The eight indicators which have been updated relate to: Cervical screening to 2017/18...
Read more »

ICO fines for practices who do not pay their registration fees (17 Dec 2018)

From 25 May 2018, the Data Protection (Charges and Information) Regulations 2018 required every organisation or sole trader who processes personal information to pay a data protection fee to the...
Read more »

Tips of the month December 2018 (17 Dec 2018)

We provide weekly tips based on common queries which come through to us from London GPs and practice teams. These are shared via social media and collated for...
Read more »

Practice Managers Conference 2018 summary (17 Dec 2018)

The Practice Managers Conference was attended by dozens of delegates from across the Londonwide area. Delegates said they enjoyed the day, particularly the opportunity to meet other PMs and learn...
Read more »

The Data Security and Protection Toolkit (DSPT) – submission deadline 31 March 2019. (17 Dec 2018)

The Data Security and Protection Toolkit (DSPT) replaced the Information Governance toolkit from April 2018. The DSPT is an online self-assessment toolkit that has to be used by all organisations...
Read more »

Thank you for responding to our workforce survey (13 Dec 2018)

Thank you to everyone who took the time to complete our workforce survey, which closed last week.  The data gathered from previous workforce surveys has been used in a number...
Read more »

Motions sought for national LMC conference (07 Dec 2018)

We are seeking draft motions for the UK LMC conference before Christmas, so we have time to submit them in early January. If you are an LMC member please speak...
Read more »
Next Page »
« Previous Page