Government data security consultation

The Government has been conducting a data security review, run by Dame Fiona Caldicott, the National Data Guardian for Health and Care. A report has now been produced with ten proposed standards:

  1. All staff ensure that personal confidential data is handled, stored and transmitted securely, whether in electronic or paper form. Personal confidential data is only shared for lawful and appropriate purposes.
  2. All staff understand their responsibilities under the National Data Guardian’s Data Security Standards including their obligation to handle information responsibly and their personal accountability for deliberate or avoidable breaches.
  3. All staff complete appropriate annual data security training and pass a mandatory test, provided through the revised Information Governance Toolkit.
  4. Personal confidential data is only accessible to staff who need it for their current role and access is removed as soon as it is no longer required. All access to personal confidential data on IT systems can be attributed to individuals.
  5. Processes are reviewed at least annually to identify and improve processes which have caused breaches or near misses, or which force staff to use workarounds which compromise data security.
  6. Cyber-attacks against services are identified and resisted and CareCERT security advice is responded to. Action is taken immediately following a data breach or a near miss, with a report made to senior management within 12 hours of detection.
  7. A continuity plan is in place to respond to threats to data security, including significant data breaches or near misses, and it is tested once a year as a minimum, with a report to senior management.
  8. No unsupported operating systems, software or internet browsers are used within the IT estate.
  9. A strategy is in place for protecting IT systems from cyber threats which is based on a proven cyber security framework such as Cyber Essentials. This is reviewed at least annually.
  10. Suppliers are held accountable via contracts for protecting the personal confidential data they process and meeting the National Data Guardian’s Data Security Standard.

The Government are seeking feedback on the proposed ten standards via an online survey, which is open until 7 September 2016.

Last updated : 19 Jul 2016

 

GPC regional election nominations 2017 (22 Feb 2017)

Nominations are open for the round of GPC regional elections to cover terms from 2017-20, in London two seats are up for election: Hillingdon, Brent, Harrow, Ealing, Hammersmith and...
Read more »

NHS England guidance on managing conflicts of interest (22 Feb 2017)

NHS England has just published new guidance on managing conflicts of interest which comes into effect from 1 June 2017. The guidance aims to: Introduce common principles and rules...
Read more »

Submission to new All Party Parliamentary Group Primary Care and Public Health Inquiry (22 Feb 2017)

Londonwide LMCs has been invited to submit evidence to the All Party Parliamentary Group on Primary Care and Public Health's new inquiry into managing demand in primary care. As we...
Read more »

Workforce Survey - latest results (22 Feb 2017)

Thank you for supporting our November 2016 Workforce Survey. We had a fantastic response from 552 unique practices across the 1295 practices we represent in the Capital. That is the...
Read more »

London Ambulance Service Research Project (21 Feb 2017)

The London Ambulance Service (LAS) is running a research project linking ambulance data to emergency department data, enabling them to look at a patient record from their 999 call to...
Read more »

Prospective Employers requests to see copies of appraisal summaries (21 Feb 2017)

It has been reported to us that some prospective employers have been asking candidates to share their appraisal summary. Our view, which is supported by colleagues on the GPC, is...
Read more »

2017/18 GP contract (20 Feb 2017)

The key elements of the new contract agreement are as follows, full details can be found on the BMA website: Direct Enhanced Services The Avoiding Unplanned Admissions (AUA) DES...
Read more »

Guest blog - life as a refugee doctor in the UK (20 Feb 2017)

This month our guest blog comes from Dr Helal Attayee, who arrived in the UK as a refugee and has gone through the process of getting the necessary qualifications to...
Read more »

The NHS winter crisis and the Prime Minister’s run-in with GPs (26 Jan 2017)

The NHS winter crisis and the Prime Minister’s run-in with GPs The weekend of 14 January saw general practice and Theresa May come to blows over claims about the impact...
Read more »
Next Page »
« Previous Page