Government data security consultation

The Government has been conducting a data security review, run by Dame Fiona Caldicott, the National Data Guardian for Health and Care. A report has now been produced with ten proposed standards:

  1. All staff ensure that personal confidential data is handled, stored and transmitted securely, whether in electronic or paper form. Personal confidential data is only shared for lawful and appropriate purposes.
  2. All staff understand their responsibilities under the National Data Guardian’s Data Security Standards including their obligation to handle information responsibly and their personal accountability for deliberate or avoidable breaches.
  3. All staff complete appropriate annual data security training and pass a mandatory test, provided through the revised Information Governance Toolkit.
  4. Personal confidential data is only accessible to staff who need it for their current role and access is removed as soon as it is no longer required. All access to personal confidential data on IT systems can be attributed to individuals.
  5. Processes are reviewed at least annually to identify and improve processes which have caused breaches or near misses, or which force staff to use workarounds which compromise data security.
  6. Cyber-attacks against services are identified and resisted and CareCERT security advice is responded to. Action is taken immediately following a data breach or a near miss, with a report made to senior management within 12 hours of detection.
  7. A continuity plan is in place to respond to threats to data security, including significant data breaches or near misses, and it is tested once a year as a minimum, with a report to senior management.
  8. No unsupported operating systems, software or internet browsers are used within the IT estate.
  9. A strategy is in place for protecting IT systems from cyber threats which is based on a proven cyber security framework such as Cyber Essentials. This is reviewed at least annually.
  10. Suppliers are held accountable via contracts for protecting the personal confidential data they process and meeting the National Data Guardian’s Data Security Standard.

The Government are seeking feedback on the proposed ten standards via an online survey, which is open until 7 September 2016.

Last updated : 19 Jul 2016

 

I want great care IT system (11 Nov 2015)

The new Co-ordinate My Care (CMC) IT system will launch on 24 November. There are important steps for GPs to take, particularly those who have not seen the pre-launch communications...
Read more »

Speaker's Corner - moustache aficionado Dr Tony Grewal looks at men’s health issues for "Movember" (11 Nov 2015)

This month moustache aficionado Dr Tony Grewal looks at men’s health issues for "Movember", Londonwide LMCs staff raised over £100 for the Movember charity. Tony writes: November is the month when...
Read more »

November 2015 newsletter now available (11 Nov 2015)

Londonwide LMCs Newsletter
Read more »

Update on successful resolution of first Christmas 2013 breach case (10 Nov 2015)

The legal challenge brought against breach notices issued by NHSE to practices who closed their doors on Christmas Eve or New Year’s Eve in 2013 has ended in a successful...
Read more »

Keeping on top of bureaucracy in your practice (09 Nov 2015)

Jeremy Hunt recently announced plans to cut bureaucracy in the health service, including ending the practice of hospitals referring patients who miss appointments back to GPs and consolidating the...
Read more »

Appeal: support the homeless this winter (09 Nov 2015)

Londonwide LMCs’ communications team recently met with Dr Paul O’Reilly and Practice Manager Tanya O’Brien of the Doctor Hickey Surgery in Westminster. Both spoke powerfully about the vulnerable groups...
Read more »

Provider development event round-up (06 Nov 2015)

Londonwide LMCs, in collaboration with Healthy London Partnership co-hosted an event on 4th November at the Kia Oval attended by over 100 representatives from emerging GP Provider Groups, CCGS and...
Read more »

Female Genital Mutilation Datasets briefing note (04 Nov 2015)

Practices are now legally required to report Female Genital Mutilation (FGM) to Health and Social Care Information Centre (HSCIC). The purpose of the data collection is to improve the NHS...
Read more »

PMS contract review update (03 Nov 2015)

This briefing is for information only for GMS practices This update follows our recent PMS briefing: in areas where CCGs have already moved to Level 3 co-commissioning, (fully delegated responsibilities)...
Read more »

Darzi report one year on - 'Primary care stretched to breaking point and still waiting for resources' (21 Oct 2015)

Dr Michelle Drage comments on the implementation of the Better Health for London (Darzi) report, to coincide with the one-year anniversary of its publication and the London: One Year On...
Read more »
Next Page »
« Previous Page