Risk assessment

Information Governance Risk Assessment

Confidentiality, integrity and availability of personal and special category data across clinical and corporate systems

For Private Healthcare ClinicRef BS-PH-RA-006See a sample (PDF) →
£44.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This risk assessment is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Scope and purpose
  • 2. Legal and regulatory framework
  • 3. Risk assessment methodology
  • 4. Hazards, controls and risk rating
  • 5. Action plan
  • 6. Monitoring and review
  • 7. Disclaimer

Legislation & standards it maps to

  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - in particular Regulation 12 (Safe care and treatment), Regulation 17 (Good governance) and Regulation 20 (Duty of candour)
  • UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
  • Data (Use and Access) Act 2025
  • Network and Information Systems Regulations 2018
  • Common law duty of confidentiality and the Caldicott Principles (8 principles, 2020)
  • Data Security and Protection Toolkit and the National Cyber Security Centre's Cyber Essentials scheme
  • Privacy and Electronic Communications (EC Directive) Regulations 2003
  • Care Quality Commission single assessment framework - the Safe, Effective, Caring, Responsive and Well-led key questions

Who it applies to

All staff, contractors, locums, agency workers, volunteers and third-party data processors of [Organisation Name] who access, process, store or transmit personal, special category or confidential business data

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Article 28 data processing agreement
A written contract required by data protection law that sets out how a supplier may handle personal data on the organisation's behalf.
Audit trail (audit log)
An automatic record of who accessed or changed information and when, used to detect and investigate misuse.
Best interests
A decision made for someone who cannot decide for themselves, choosing the option that is best for them.
Caldicott Guardian
The senior person responsible for protecting the confidentiality of people's health and care information.
Caldicott Principles
A set of principles that govern how patient-identifiable information should be handled, used and shared safely and lawfully.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Common law duty of confidentiality
The long-standing legal duty not to disclose information given in confidence, such as patient information, without consent or another legal basis.
Controller
The organisation that decides how and why personal data is processed, and which is legally responsible for it.
Cyber Essentials / Cyber Essentials Plus
A government-backed certification scheme showing an organisation has basic cyber security controls in place; the Plus level adds an independent technical check.
Data (Use and Access) Act 2025
A law that updates the UK's data protection and data-sharing rules, including for health and adult social care.
Data Protection Act 2018
The UK law that sits alongside the UK General Data Protection Regulation and governs how personal data is used.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data Protection Officer (DPO)
The person who advises an organisation on data protection law and monitors its compliance.
Data Security and Protection Toolkit (DSPT)
An annual online self-assessment that lets a health or care provider show it meets the national data security and protection standards.
Data subject
The living individual that a piece of personal data is about, such as a patient or employee.
Disclosure and Barring Service (DBS) check
A criminal-records check showing whether a person is suitable to work with patients or vulnerable people.
Duty of candour
The legal duty to be open and honest with a person and their family when something goes wrong with their care.
Electronic patient record (EPR)
A patient's clinical record held in a computer system rather than on paper.
Encryption
Scrambling data so it can only be read by someone with the correct key, protecting it if a device is lost or stolen.
Exfiltration
The unauthorised copying or removal of data from an organisation's systems, often by an attacker.
Fundamental standards
The minimum standards of safety and quality below which care must never fall.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting out the fundamental standards that providers of regulated care must meet, enforced by the Care Quality Commission.
Health Research Authority (HRA)
The body that protects and promotes the interests of patients and the public in health and social care research.
Information Commissioner's Office (ICO)
The UK's independent regulator for data protection and information rights.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Lawful basis
One of the legally recognised reasons that allows an organisation to use personal data.
Mobile device management (MDM)
Software that lets an organisation secure, control and, if needed, remotely wipe phones, tablets and laptops.
Multi-factor authentication (MFA)
A login that requires two or more proofs of identity, such as a password plus a code, to make accounts harder to compromise.
National Cyber Security Centre (NCSC)
The UK government organisation that provides advice and support on protecting against cyber threats.
National Data Guardian
The independent adviser who champions the safe and confidential use of people's health and care data.
Near miss
An event that could have caused harm but did not, by chance or because it was caught in time.
Network and Information Systems Regulations 2018
The law requiring operators of certain essential and digital services to keep their networks and information systems secure.
Nominated Individual
The senior person responsible to the regulator for supervising how a service is provided.
Notifiable event
An incident a provider is legally required to report to the regulator, such as a death or serious injury.
Personal data
Any information that identifies, or can identify, a living individual.
Phishing
A scam, usually by email, that tricks people into revealing passwords or clicking harmful links.
Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
The rules that govern electronic marketing, cookies and the security of phone, text and email communications.
Ransomware
Malicious software that locks or encrypts an organisation's data until a ransom is paid.
Recovery point objective (RPO)
The maximum amount of recent data an organisation can afford to lose in an incident, which sets how often backups are needed.
Recovery time objective (RTO)
The target time within which a system or service must be restored after a failure or outage.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Regulated activity
A type of care or treatment the law requires a provider to register with the regulator to deliver.
Research Ethics Committee (REC)
A panel that reviews health research proposals to protect the rights, safety and wellbeing of participants.
Residual risk
The level of risk that remains once the existing controls have been taken into account.
Risk assessment
A structured check identifying what could cause harm and what is being done to prevent it.
Role-based access control
Limiting access to information and systems according to a person's job role, so they see only what they need.
Safeguarding
Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
Senior Information Risk Owner (SIRO)
The senior person, usually a board member, who owns and is accountable for the organisation's information risk.
Service level agreement (SLA)
A contract that defines the level of service a supplier must provide, such as system availability or how quickly faults are fixed.
Single assessment framework
The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
Special category data
Sensitive personal data, such as health information, that the law gives extra protection.
Spine
The national database and messaging system that links health and care IT systems across England.
Statement of Purpose
A required document describing who a service is, what it does and where, shared with the regulator.
Sub-processor
A second supplier that a data processor uses to help deliver its service and which also handles personal data.
Subject Access Request (SAR)
A person's legal right to ask for a copy of the personal information an organisation holds about them.
UK General Data Protection Regulation (UK GDPR)
The UK's main data-protection law governing how personal information is collected and used.
Uninterruptible power supply (UPS)
A battery-backed power source that keeps key equipment running for a short time during a power cut.
Whistleblowing (speaking up)
Raising a concern about wrongdoing, risk or malpractice at work, protected by law.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyBusiness Continuity Policy£54.99
PolicyClinical Governance Policy£54.99
PolicyComplaints Handling Policy£54.99
PolicyConsent to Treatment Policy£54.99

Need the whole set?

Buy the full Private Healthcare Clinic pack and save versus buying documents individually.

View the Private Healthcare Clinic pack