Government data security consultation

The Government has been conducting a data security review, run by Dame Fiona Caldicott, the National Data Guardian for Health and Care. A report has now been produced with ten proposed standards:

  1. All staff ensure that personal confidential data is handled, stored and transmitted securely, whether in electronic or paper form. Personal confidential data is only shared for lawful and appropriate purposes.
  2. All staff understand their responsibilities under the National Data Guardian’s Data Security Standards including their obligation to handle information responsibly and their personal accountability for deliberate or avoidable breaches.
  3. All staff complete appropriate annual data security training and pass a mandatory test, provided through the revised Information Governance Toolkit.
  4. Personal confidential data is only accessible to staff who need it for their current role and access is removed as soon as it is no longer required. All access to personal confidential data on IT systems can be attributed to individuals.
  5. Processes are reviewed at least annually to identify and improve processes which have caused breaches or near misses, or which force staff to use workarounds which compromise data security.
  6. Cyber-attacks against services are identified and resisted and CareCERT security advice is responded to. Action is taken immediately following a data breach or a near miss, with a report made to senior management within 12 hours of detection.
  7. A continuity plan is in place to respond to threats to data security, including significant data breaches or near misses, and it is tested once a year as a minimum, with a report to senior management.
  8. No unsupported operating systems, software or internet browsers are used within the IT estate.
  9. A strategy is in place for protecting IT systems from cyber threats which is based on a proven cyber security framework such as Cyber Essentials. This is reviewed at least annually.
  10. Suppliers are held accountable via contracts for protecting the personal confidential data they process and meeting the National Data Guardian’s Data Security Standard.

The Government are seeking feedback on the proposed ten standards via an online survey, which is open until 7 September 2016.

Last updated : 19 Jul 2016

 

End of Coronavirus Act death certification and registration changes (23 Mar 2022)

The arrangements for death certification and registration introduced by the Coronavirus Act (2020) expire on 24 March 2022. The relevant guidance can be found on the Government website, the key...
Read more »

Registered nursing associate blended learning programme launched (22 Mar 2022)

This blended learning programme has been developed by experienced primary care nurses and it is specifically designed for registered nursing associates (RNAs) new to working within the general practice setting....
Read more »

Briefing on GP Contract 2022/23 - message from Dr Michelle Drage (10 Mar 2022)

Thursday 10 March 2022 Dear Colleagues, Briefing on GP Contract 2022/23 As you will now be aware, despite lengthy negotiation no agreement was reached on changes to...
Read more »

Wellbeing webinars - spring 2022 (24 Feb 2022)

The webinars aim to support the emotional and psychological health of staff by supporting you in finding your own strategies, tools, and coping mechanisms. These 40-minute interactive webinars are packed...
Read more »

Tips of the month February 2022 (23 Feb 2022)

We provide tips based on common queries which come through to us from London GPs and practice teams. These are shared via social media and collated for this...
Read more »

How do treatment delays impact patients and general practice? (23 Feb 2022)

Our new animation explains how the treatment backlog in the NHS affects patients and exacerbates capacity problems in general practice. London practices are welcome to share it in on social media...
Read more »

Patients to view record entries from July 2022 onwards (23 Feb 2022)

Update: this requirement was initially intended to go live on 1 April 2022, but is now postponed until July. From July 2022, patients with an existing online account will automatically be...
Read more »

UCLH positive response to reducing inappropriate transfers of activity (22 Feb 2022)

Leaders from University College London Hospitals Foundation Trust have written to consultants and GPs following representation from LMCs. Their letter includes this advice: "Please actively have conversations with patients in...
Read more »
Next Page »