Plain-English explanations of the technical terms and legislation used in this document.
- Air-gapped backup
- A backup copy kept physically or logically disconnected from the network so attackers cannot reach or encrypt it.
- Application programming interface (API)
- A standard connection that lets two software systems exchange data automatically, such as a clinic system and a pathology service.
- Bring Your Own Device (BYOD)
- An arrangement allowing staff to use their own personal phones, tablets or laptops for work, under agreed security rules.
- Business continuity and disaster recovery plan
- A written plan setting out how the service keeps running and recovers its systems and data after a major disruption or outage.
- Caldicott Guardian
- The senior person responsible for protecting the confidentiality of people's health and care information.
- Caldicott Principles
- A set of guiding rules for handling confidential patient information lawfully, safely and only when justified.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Center for Internet Security (CIS) benchmark
- A recognised set of secure configuration settings used to harden computer systems and cloud services against attack.
- Computer Misuse Act 1990
- The United Kingdom law that makes unauthorised access to, or interference with, computer systems and data a criminal offence.
- Confidentiality: Code of Practice for Health and Social Care
- Official guidance on how staff should protect and lawfully share confidential patient and service-user information.
- Cyber Essentials / Cyber Essentials Plus
- A government-backed certification scheme showing an organisation has basic cyber-security controls in place; the 'Plus' level is independently tested.
- Cyber resilience
- An organisation's ability to prevent, withstand and recover quickly from cyber incidents while keeping services running.
- Cyber Security Incident Response Plan (CSIRP)
- A documented plan setting out who does what, and in what order, when a cyber incident occurs.
- Data processing agreement (DPA)
- A written contract, required by data-protection law, setting out how a supplier must handle personal data on the organisation's behalf.
- Data processor
- A third party that processes personal data on the organisation's behalf under a written contract.
- Data Protection Act 2018
- The United Kingdom law that sits alongside the UK GDPR and governs how personal information must be handled.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Protection Officer (DPO)
- The person responsible for advising on and monitoring an organisation's compliance with data-protection law.
- Data residency
- The country or region in which data is physically stored, which matters for legal protection of personal information.
- Data Security and Protection Toolkit (DSPT)
- An annual online self-assessment that organisations handling health and care data complete to show they meet required data-security standards.
- Decommissioned hardware
- Devices being retired from use, which must have their data securely wiped or destroyed before disposal.
- DKIM (DomainKeys Identified Mail)
- An email security method that adds a digital signature so recipients can confirm a message genuinely came from your domain.
- DMARC (Domain-based Message Authentication, Reporting and Conformance)
- An email security policy that tells receiving systems how to handle messages that fail anti-spoofing checks, reducing impersonation.
- Duty of candour
- The legal duty to be open and honest with a person and their family when something goes wrong with their care.
- Electronic patient record (EPR)
- The digital system holding a patient's clinical notes, history and treatment information.
- Encryption at rest
- Scrambling stored data so it cannot be read if a device or database is stolen or accessed without authorisation.
- Encryption in transit
- Scrambling data while it travels across a network so it cannot be intercepted and read.
- Endpoint
- Any device, such as a laptop, phone or tablet, that connects to organisational systems or processes patient data.
- European Economic Area (EEA)
- The European Union countries plus Iceland, Liechtenstein and Norway, treated together for data-transfer and trade purposes.
- Full-disk encryption (BitLocker / FileVault)
- A feature that encrypts everything on a device's drive so the data is unreadable without the correct credentials; BitLocker is the Windows tool and FileVault the Apple tool.
- Immutable backup
- A backup copy that cannot be altered or deleted for a set period, protecting it from ransomware and tampering.
- Information Commissioner's Office (ICO)
- The United Kingdom's independent regulator for data protection and information rights.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- International Data Transfer Agreement / United Kingdom Addendum
- Standard legal contracts that allow personal data to be sent outside the United Kingdom with proper safeguards.
- ISO 27001
- An internationally recognised standard for managing information security within an organisation.
- Just culture
- A workplace approach that encourages honest reporting of errors and incidents to learn from them, rather than to assign blame.
- Least privilege
- The security principle of giving each person only the minimum access they need to do their job.
- Managed service provider (MSP)
- An outside company contracted to run and support an organisation's information technology and security.
- Mobile Device Management (MDM)
- Software that lets an organisation enforce security settings on, and remotely control or wipe, mobile devices that access its data.
- Multi-factor authentication (MFA)
- Confirming identity using two or more independent checks, such as a password plus a code sent to a phone.
- National Cyber Security Centre (NCSC)
- The United Kingdom's national authority that provides cyber-security guidance and support to organisations.
- National Data Guardian's 10 Data Security Standards
- Ten standards covering people, processes and technology that health and care organisations should meet to keep data safe.
- Near miss
- An event that could have caused harm but did not, by chance or because it was caught in time.
- Network and Information Systems Regulations 2018 (NIS Regulations)
- United Kingdom law setting security and incident-reporting duties for operators of certain essential and digital services.
- Penetration test
- An authorised simulated cyber attack used to find and fix weaknesses before a real attacker can exploit them.
- Personal data breach
- A security failure that leads to personal data being lost, destroyed, altered, or disclosed to or accessed by the wrong people.
- Phishing (and smishing)
- A fraudulent message, by email (phishing) or text (smishing), designed to trick someone into revealing data, credentials or money.
- Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
- United Kingdom rules governing electronic marketing, cookies and the security of electronic communications.
- Privileged / administrator account
- A high-level account with extra powers to change systems and settings, requiring stronger controls than ordinary accounts.
- Ransomware
- Malicious software that locks or encrypts data and demands a payment to release it.
- Records Management Code of Practice
- National guidance on how long health and care records should be kept and how they should be stored and disposed of.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Risk appetite
- The level of risk an organisation is willing to accept in pursuit of its objectives.
- Risk assessment
- A structured check identifying what could cause harm and what is being done to prevent it.
- Role-based access control (RBAC)
- Granting system access according to a person's job role, so they see only what that role needs.
- Senior Information Risk Owner (SIRO)
- The senior person accountable for managing information risk across the organisation.
- Service level agreement (SLA)
- A contractual commitment defining the standard of service a supplier must provide, such as guaranteed system uptime.
- SOC 2
- An independent audit report showing that a service provider manages data securely against recognised trust criteria.
- Software-as-a-service (SaaS)
- Software hosted online by a provider and accessed over the internet rather than installed on local computers.
- Special category data
- Sensitive personal information, including health data, that data-protection law gives extra protection.
- SPF (Sender Policy Framework)
- An email security method that lists which servers are allowed to send mail for your domain, helping block forgery.
- Sub-processor
- A further supplier that a data processor uses to help process personal data on the organisation's behalf.
- Transport Layer Security (TLS)
- A widely used technology that encrypts data sent over the internet, including secure websites and clinical traffic.
- UK adequacy regulations
- Decisions confirming that a country offers data protection strong enough to allow personal data to be sent there from the United Kingdom.
- UK General Data Protection Regulation (UK GDPR)
- The United Kingdom's main data-protection law governing how personal information is collected and used.
- Virtual private network (VPN)
- A secure, encrypted connection that lets staff access work systems safely over the internet.
- Vulnerability scan
- An automated check that searches systems for known security weaknesses so they can be fixed.
- Zero-trust gateway
- A security model that verifies every user and device on each access attempt, trusting nothing by default.