Plain-English explanations of the technical terms and legislation used in this document.
- Alternative Provider Medical Services (APMS) contract
- A flexible contract under which an organisation other than a traditional GP partnership provides primary medical services.
- As low as reasonably practicable
- Reducing a risk to the lowest level that is sensible once the effort and cost of further action are weighed against the benefit.
- Caldicott Guardian
- The senior person responsible for protecting the confidentiality of people's health and care information.
- Caldicott Principles
- A set of eight principles that guide how health and care organisations should handle confidential patient information.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Common law duty of confidentiality
- A long-standing legal duty, developed by the courts, to keep information given in confidence private and use it only for proper purposes.
- Computer Misuse Act 1990
- The law that makes it a criminal offence to access or interfere with computer systems or data without authorisation.
- Contemporaneous record
- A record made at the time of, or very soon after, the event it describes, so it is accurate and reliable.
- Data (Use and Access) Act 2025
- A recent law that updates and amends the UK's data protection and data-sharing rules.
- Data controller
- The organisation that decides why and how personal data is collected and used, and is legally responsible for it.
- Data processor
- An organisation that handles personal data on behalf of, and on the instructions of, the data controller.
- Data Protection Act 2018
- The UK law that sits alongside the UK GDPR and sets additional national data-protection rules.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Protection Officer (DPO)
- The person who advises an organisation on its data-protection duties and monitors that it follows the rules.
- Data Security and Protection Toolkit (DSPT)
- An annual online self-assessment that health and care organisations complete to show they handle data safely and meet the required standards.
- Data subject
- The living individual whom a particular piece of personal data is about.
- DCB0160
- The national clinical risk management standard that health organisations follow when deploying and using clinical software safely.
- Electronic Prescription Service (EPS)
- The system that lets prescriptions be sent electronically from a prescriber to a pharmacy.
- Electronic Referral Service
- The national system used to refer patients electronically from primary care to other services.
- General Medical Services (GMS) contract
- A nationally agreed contract under which many GP practices provide primary medical services.
- Health and Social Care (Safety and Quality) Act 2015
- The law that, among other things, places a duty on health and care bodies to share information for an individual's direct care.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- The regulations setting out the fundamental standards that providers of regulated health and care must meet.
- Information Commissioner's Office (ICO)
- The UK regulator that upholds information rights and enforces data-protection law.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Integrated Care Board (ICB)
- The statutory body responsible for planning and arranging health services for a local area.
- Lawful basis
- One of the specific reasons set out in data-protection law that an organisation must have before it can use personal data.
- Lloyd George envelope
- The traditional paper folder historically used to hold a patient's primary care medical records.
- Malware
- Harmful software, such as viruses, designed to damage, disrupt or gain unauthorised access to computer systems.
- Multi-factor authentication
- A security method that requires two or more separate proofs of identity before access is granted.
- Near miss
- An event that could have caused harm but did not, by chance or because it was caught in time.
- Network and Information Systems Regulations 2018
- The law requiring operators of important digital and network services to keep those systems secure and to report serious incidents.
- Notifiable event
- An incident a provider is legally required to report to a regulator, such as a serious data breach.
- Personal data
- Any information relating to an identified or identifiable living person.
- Personal Medical Services (PMS) contract
- A locally agreed alternative to the standard GP contract for providing primary medical services.
- Phishing
- A scam in which fraudulent messages trick people into revealing passwords or other sensitive information.
- Primary medical services
- The everyday medical care provided by a GP practice as a patient's first point of contact with healthcare.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- The rules governing electronic marketing, cookies and the security of electronic communications.
- Privacy notice
- A statement telling people how an organisation collects, uses and protects their personal information.
- Proxy access
- Permission for someone, such as a parent or carer, to access another person's online medical records on their behalf.
- Ransomware
- Malicious software that locks or encrypts data and demands payment to restore access.
- Record of Processing Activities (ROPA)
- A written record of how and why an organisation processes personal data, required by data-protection law.
- Records Management Code of Practice
- National guidance on how health and care records should be kept, stored and disposed of, including how long to retain them.
- Redaction
- Removing or blacking out information from a document so that it cannot be read before the document is shared.
- Regulated activity
- A type of care or treatment the law requires a provider to register with the regulator to deliver.
- Residual risk
- The level of risk that remains after existing controls are taking effect.
- Risk assessment
- A structured check identifying what could cause harm and what is being done to prevent it.
- Role-based access
- Restricting what each user can see or do in a system according to their job role.
- Safe haven
- An agreed secure location and procedure for receiving and handling confidential information.
- Safeguarding
- Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
- Senior Information Risk Owner (SIRO)
- The senior person who takes overall ownership of an organisation's information risk.
- Single assessment framework
- The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
- Smartcard
- A secure card used with a personal passcode to log in to clinical systems and prove the user's identity.
- Social engineering
- Manipulating people into giving away confidential information or access, rather than attacking technology directly.
- Special category data
- Particularly sensitive personal data, such as health information, that the law gives extra protection.
- Subject Access Request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- UK General Data Protection Regulation (UK GDPR)
- The UK's main data-protection law governing how personal information is collected and used.