Policy

Cybersecurity Policy

Information security, data protection and cyber resilience for online and virtual clinical services

For Telehealth & Online ClinicRef BS-TEL-POL-002See a sample (PDF) →
£54.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This policy is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Policy statement
  • 4. Definitions
  • 5. Governance and risk management
  • 6. Technical and organisational controls
  • 7. Third-party and supply-chain security
  • 8. Incident detection, response and reporting
  • 9. Roles and responsibilities
  • 10. Training and awareness
  • 11. Records, monitoring and audit
  • 12. Related documents
  • 13. Version control and review
  • Appendix A: New supplier / platform security assurance checklist
  • Appendix B: Cyber incident triage and reporting record
  • Disclaimer

Legislation & standards it maps to

  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - Regulation 17 (Good governance) and Regulation 12 (Safe care and treatment)
  • UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
  • Network and Information Systems Regulations 2018 (the NIS Regulations)
  • Computer Misuse Act 1990
  • Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
  • The Data Security and Protection Toolkit (DSPT) and the National Data Guardian's 10 Data Security Standards
  • Cyber Essentials and Cyber Essentials Plus (the National Cyber Security Centre scheme)
  • The Caldicott Principles and the Confidentiality: Code of Practice for Health and Social Care

Who it applies to

All directors, employees, registered clinicians, locums, bank staff, administrative personnel, IT contractors and third-party suppliers of [Organisation Name] who access, process or manage organisational systems, clinical information or patient data.

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Air-gapped backup
A backup copy kept physically or logically disconnected from the network so attackers cannot reach or encrypt it.
Application programming interface (API)
A standard connection that lets two software systems exchange data automatically, such as a clinic system and a pathology service.
Bring Your Own Device (BYOD)
An arrangement allowing staff to use their own personal phones, tablets or laptops for work, under agreed security rules.
Business continuity and disaster recovery plan
A written plan setting out how the service keeps running and recovers its systems and data after a major disruption or outage.
Caldicott Guardian
The senior person responsible for protecting the confidentiality of people's health and care information.
Caldicott Principles
A set of guiding rules for handling confidential patient information lawfully, safely and only when justified.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Center for Internet Security (CIS) benchmark
A recognised set of secure configuration settings used to harden computer systems and cloud services against attack.
Computer Misuse Act 1990
The United Kingdom law that makes unauthorised access to, or interference with, computer systems and data a criminal offence.
Confidentiality: Code of Practice for Health and Social Care
Official guidance on how staff should protect and lawfully share confidential patient and service-user information.
Cyber Essentials / Cyber Essentials Plus
A government-backed certification scheme showing an organisation has basic cyber-security controls in place; the 'Plus' level is independently tested.
Cyber resilience
An organisation's ability to prevent, withstand and recover quickly from cyber incidents while keeping services running.
Cyber Security Incident Response Plan (CSIRP)
A documented plan setting out who does what, and in what order, when a cyber incident occurs.
Data processing agreement (DPA)
A written contract, required by data-protection law, setting out how a supplier must handle personal data on the organisation's behalf.
Data processor
A third party that processes personal data on the organisation's behalf under a written contract.
Data Protection Act 2018
The United Kingdom law that sits alongside the UK GDPR and governs how personal information must be handled.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data Protection Officer (DPO)
The person responsible for advising on and monitoring an organisation's compliance with data-protection law.
Data residency
The country or region in which data is physically stored, which matters for legal protection of personal information.
Data Security and Protection Toolkit (DSPT)
An annual online self-assessment that organisations handling health and care data complete to show they meet required data-security standards.
Decommissioned hardware
Devices being retired from use, which must have their data securely wiped or destroyed before disposal.
DKIM (DomainKeys Identified Mail)
An email security method that adds a digital signature so recipients can confirm a message genuinely came from your domain.
DMARC (Domain-based Message Authentication, Reporting and Conformance)
An email security policy that tells receiving systems how to handle messages that fail anti-spoofing checks, reducing impersonation.
Duty of candour
The legal duty to be open and honest with a person and their family when something goes wrong with their care.
Electronic patient record (EPR)
The digital system holding a patient's clinical notes, history and treatment information.
Encryption at rest
Scrambling stored data so it cannot be read if a device or database is stolen or accessed without authorisation.
Encryption in transit
Scrambling data while it travels across a network so it cannot be intercepted and read.
Endpoint
Any device, such as a laptop, phone or tablet, that connects to organisational systems or processes patient data.
European Economic Area (EEA)
The European Union countries plus Iceland, Liechtenstein and Norway, treated together for data-transfer and trade purposes.
Full-disk encryption (BitLocker / FileVault)
A feature that encrypts everything on a device's drive so the data is unreadable without the correct credentials; BitLocker is the Windows tool and FileVault the Apple tool.
Immutable backup
A backup copy that cannot be altered or deleted for a set period, protecting it from ransomware and tampering.
Information Commissioner's Office (ICO)
The United Kingdom's independent regulator for data protection and information rights.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
International Data Transfer Agreement / United Kingdom Addendum
Standard legal contracts that allow personal data to be sent outside the United Kingdom with proper safeguards.
ISO 27001
An internationally recognised standard for managing information security within an organisation.
Just culture
A workplace approach that encourages honest reporting of errors and incidents to learn from them, rather than to assign blame.
Least privilege
The security principle of giving each person only the minimum access they need to do their job.
Managed service provider (MSP)
An outside company contracted to run and support an organisation's information technology and security.
Mobile Device Management (MDM)
Software that lets an organisation enforce security settings on, and remotely control or wipe, mobile devices that access its data.
Multi-factor authentication (MFA)
Confirming identity using two or more independent checks, such as a password plus a code sent to a phone.
National Cyber Security Centre (NCSC)
The United Kingdom's national authority that provides cyber-security guidance and support to organisations.
National Data Guardian's 10 Data Security Standards
Ten standards covering people, processes and technology that health and care organisations should meet to keep data safe.
Near miss
An event that could have caused harm but did not, by chance or because it was caught in time.
Network and Information Systems Regulations 2018 (NIS Regulations)
United Kingdom law setting security and incident-reporting duties for operators of certain essential and digital services.
Penetration test
An authorised simulated cyber attack used to find and fix weaknesses before a real attacker can exploit them.
Personal data breach
A security failure that leads to personal data being lost, destroyed, altered, or disclosed to or accessed by the wrong people.
Phishing (and smishing)
A fraudulent message, by email (phishing) or text (smishing), designed to trick someone into revealing data, credentials or money.
Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)
United Kingdom rules governing electronic marketing, cookies and the security of electronic communications.
Privileged / administrator account
A high-level account with extra powers to change systems and settings, requiring stronger controls than ordinary accounts.
Ransomware
Malicious software that locks or encrypts data and demands a payment to release it.
Records Management Code of Practice
National guidance on how long health and care records should be kept and how they should be stored and disposed of.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Risk appetite
The level of risk an organisation is willing to accept in pursuit of its objectives.
Risk assessment
A structured check identifying what could cause harm and what is being done to prevent it.
Role-based access control (RBAC)
Granting system access according to a person's job role, so they see only what that role needs.
Senior Information Risk Owner (SIRO)
The senior person accountable for managing information risk across the organisation.
Service level agreement (SLA)
A contractual commitment defining the standard of service a supplier must provide, such as guaranteed system uptime.
SOC 2
An independent audit report showing that a service provider manages data securely against recognised trust criteria.
Software-as-a-service (SaaS)
Software hosted online by a provider and accessed over the internet rather than installed on local computers.
Special category data
Sensitive personal information, including health data, that data-protection law gives extra protection.
SPF (Sender Policy Framework)
An email security method that lists which servers are allowed to send mail for your domain, helping block forgery.
Sub-processor
A further supplier that a data processor uses to help process personal data on the organisation's behalf.
Transport Layer Security (TLS)
A widely used technology that encrypts data sent over the internet, including secure websites and clinical traffic.
UK adequacy regulations
Decisions confirming that a country offers data protection strong enough to allow personal data to be sent there from the United Kingdom.
UK General Data Protection Regulation (UK GDPR)
The United Kingdom's main data-protection law governing how personal information is collected and used.
Virtual private network (VPN)
A secure, encrypted connection that lets staff access work systems safely over the internet.
Vulnerability scan
An automated check that searches systems for known security weaknesses so they can be fixed.
Zero-trust gateway
A security model that verifies every user and device on each access attempt, trusting nothing by default.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyTelehealth Consent Policy£54.99
PolicyRemote Assessment Policy£54.99
PolicyData Protection Policy£54.99
PolicyEmergency Response Policy£54.99

Need the whole set?

Buy the full Telehealth & Online Clinic pack and save versus buying documents individually.

View the Telehealth & Online Clinic pack