Government data security consultation

The Government has been conducting a data security review, run by Dame Fiona Caldicott, the National Data Guardian for Health and Care. A report has now been produced with ten proposed standards:

  1. All staff ensure that personal confidential data is handled, stored and transmitted securely, whether in electronic or paper form. Personal confidential data is only shared for lawful and appropriate purposes.
  2. All staff understand their responsibilities under the National Data Guardian’s Data Security Standards including their obligation to handle information responsibly and their personal accountability for deliberate or avoidable breaches.
  3. All staff complete appropriate annual data security training and pass a mandatory test, provided through the revised Information Governance Toolkit.
  4. Personal confidential data is only accessible to staff who need it for their current role and access is removed as soon as it is no longer required. All access to personal confidential data on IT systems can be attributed to individuals.
  5. Processes are reviewed at least annually to identify and improve processes which have caused breaches or near misses, or which force staff to use workarounds which compromise data security.
  6. Cyber-attacks against services are identified and resisted and CareCERT security advice is responded to. Action is taken immediately following a data breach or a near miss, with a report made to senior management within 12 hours of detection.
  7. A continuity plan is in place to respond to threats to data security, including significant data breaches or near misses, and it is tested once a year as a minimum, with a report to senior management.
  8. No unsupported operating systems, software or internet browsers are used within the IT estate.
  9. A strategy is in place for protecting IT systems from cyber threats which is based on a proven cyber security framework such as Cyber Essentials. This is reviewed at least annually.
  10. Suppliers are held accountable via contracts for protecting the personal confidential data they process and meeting the National Data Guardian’s Data Security Standard.

The Government are seeking feedback on the proposed ten standards via an online survey, which is open until 7 September 2016.

Last updated : 19 Jul 2016

 

‘Innovative and interesting’ HCA course now incorporates the 15 Care Certificate Standards (21 Nov 2017)

“I would recommend it to other HCAs, a very good course”. “The trainers were excellent”. “Facilitators have a good knowledge of their subjects and they explained clearly”. These are just...
Read more »

London Health and Care Devolution Memorandum of Understanding signed (21 Nov 2017)

The London Health and Care Devolution Memorandum of Understanding (MoU) was signed last week by London, national partners and central government. We currently have some high-level details which we can...
Read more »

BMA referral to a specialist patient leaflet (17 Nov 2017)

The BMA has launched a new leaflet which is designed to provide patients with information on what to expect when referred to a specialist. The leaflet can be downloaded...
Read more »

Practice managers please respond to records update email (17 Nov 2017)

In the next few weeks, we will be sending an email to all practice managers asking them to confirm the GPs who are working at their practice, please look out...
Read more »

Request for hospitals to issue fit notes gets results (17 Nov 2017)

Our recent letters to hospital trusts asking them to issue fit notes to patients rather than referring them back to GPs has had a positive response from Imperial College Healthcare...
Read more »

Londonwide LMCs motions at England LMC Representative Conference (17 Nov 2017)

The first Conference of England LMCs took place on 10 November in London. The full list of motions, including which parts were carried can be downloaded here. A summary...
Read more »

Chairs and vice chairs look at cross-LMC working (25 Oct 2017)

Last week’s meeting of Londonwide LMCs’ leaders looked at cross-LMC working, to make sure we are ready to represent members as the NHS brings in new organisations as part of...
Read more »

Participant practices wanted for unique stress and workload study (25 Oct 2017)

Update February 2018: The Primary Care Barometer is now up and running! As of December 2017 practice managers across London have had the exciting opportunity to participate in a novel survey...
Read more »

GPC guidance on requirements for PREVENT training (23 Oct 2017)

Section 26 of the Counter-Terrorism and Security Act 2015 (the Act) places a duty on certain bodies (“specified authorities” listed in Schedule 6 to the Act), in the exercise of...
Read more »
Next Page »
« Previous Page