Plain-English explanations of the technical terms and legislation used in this document.
- Advanced Encryption Standard (AES)
- A widely used method of scrambling stored data so it cannot be read by anyone without the correct key.
- Application programming interface (API)
- A set of rules that lets two different computer systems exchange data with each other automatically.
- Artificial intelligence (AI)
- Computer software that performs tasks normally needing human judgement, such as sorting patients by symptoms.
- Asynchronous consultation
- A consultation where the patient and clinician communicate at different times, such as by secure message or questionnaire, rather than live.
- Blood-borne virus (BBV)
- An infection such as hepatitis B, hepatitis C or HIV that can be passed on through blood.
- British Sign Language (BSL)
- A visual language using hand shapes, facial expressions and gestures, used by many deaf people in the United Kingdom.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Clinical safety case
- A documented argument, with supporting evidence, that a health information technology system is acceptably safe to use.
- Computer Misuse Act 1990
- The law that makes unauthorised access to computer systems and data a criminal offence.
- Contemporaneous record
- A record written at the time of, or very soon after, the event it describes, so it is accurate and reliable.
- Controlled drug
- A medicine whose supply, storage and records are tightly restricted by law because of its potential for misuse.
- Cyber Assessment Framework
- A National Cyber Security Centre tool used to judge how well an organisation manages cyber security risks to essential services.
- Data Processing Agreement (DPA)
- A contract setting out how a supplier must handle and protect personal data it processes on an organisation's behalf.
- Data Protection Act 2018
- The United Kingdom's main data-protection law, which sits alongside the UK General Data Protection Regulation.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Protection Officer (DPO)
- The person responsible for advising on and monitoring an organisation's compliance with data-protection law.
- DCB0129 / DCB0160
- Clinical risk management standards setting out how the manufacturers and users of health information technology must manage clinical safety.
- Decontamination
- The combined process of cleaning, disinfecting and, where needed, sterilising equipment so it is safe to reuse.
- Did not attend (DNA)
- A record that a patient missed a booked appointment without cancelling it beforehand.
- Electronic patient record (EPR)
- The digital record holding a patient's clinical history, consultations, test results and treatment.
- Electronic Prescription Service (EPS)
- A system that sends prescriptions electronically from a prescriber to a pharmacy, instead of on paper.
- Endpoint detection and response (EDR)
- Security software that watches computers and devices for signs of attack and helps respond to threats quickly.
- Equality Act 2010
- The law protecting people from discrimination based on characteristics such as age, disability, sex or race.
- Failover
- Automatically switching to a backup system when the main one fails, so the service keeps running.
- FIDO2
- A modern login standard, often using a security key or device, that strongly resists phishing and stolen-password attacks.
- Formulary
- An approved list of medicines that clinicians in a service are permitted to prescribe.
- Fundamental standards
- The minimum standards of safety and quality below which care must never fall.
- General Medical Council (GMC)
- The body that registers and regulates doctors in the United Kingdom.
- General Pharmaceutical Council (GPhC)
- The body that registers and regulates pharmacists and pharmacies in Great Britain.
- Health and Safety at Work etc. Act 1974
- The main law placing a duty on employers to protect the health and safety of staff and others affected by their work.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- The regulations setting out the fundamental standards that all registered care providers in England must meet.
- Human Medicines Regulations 2012
- The law governing how medicines are licensed, prescribed, supplied and advertised in the United Kingdom.
- Immutable backup
- A backup copy of data that cannot be altered or deleted once written, protecting it from ransomware and tampering.
- Information Commissioner's Office (ICO)
- The United Kingdom's independent regulator for data protection and information rights.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Information technology (IT)
- The computers, networks, software and systems an organisation uses to store and process information.
- ISO/IEC 27001
- An internationally recognised standard for managing the security of information within an organisation.
- Liveness check
- A test confirming that a person verifying their identity online is real and present, not a photo or recording.
- Multi-factor authentication (MFA)
- A login method requiring two or more proofs of identity, such as a password plus a code, for extra security.
- National Cyber Security Centre (NCSC)
- The United Kingdom government body that provides advice and support on protecting against cyber threats.
- Near miss
- An event that could have caused harm but did not, by chance or because it was caught in time.
- Network and Information Systems Regulations 2018
- The law requiring operators of essential and digital services to manage the security and resilience of their networks.
- Nominated Individual
- The senior person responsible to the regulator for supervising how a service is provided.
- Notifiable event
- An incident a provider is legally required to report to the regulator, such as a death or serious injury.
- Penetration test
- An authorised simulated cyber attack used to find security weaknesses before real attackers do.
- Personal protective equipment (PPE)
- Items such as gloves, aprons and masks worn to protect against harm or infection.
- Phishing
- A scam where attackers trick people into revealing passwords or data, usually through fake emails or messages.
- Prescription-only medicine (POM)
- A medicine that may lawfully be supplied only on the instruction of an appropriate prescriber.
- Protected characteristics
- The personal features, such as age, disability, sex and race, that the Equality Act 2010 protects from discrimination.
- Ransomware
- Malicious software that locks or encrypts an organisation's data until a ransom is paid.
- Reasonable adjustments
- Changes a service makes so that disabled people can use it as easily as everyone else.
- Recovery Point Objective (RPO)
- The maximum amount of data, measured in time, an organisation is prepared to lose in an incident.
- Recovery Time Objective (RTO)
- The target time within which a service must be restored after a disruption.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Regulated activity
- A type of care or treatment the law requires a provider to register with the regulator to deliver.
- Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (RIDDOR)
- The law requiring certain workplace injuries, diseases and dangerous events to be reported to the Health and Safety Executive.
- Risk assessment
- A structured check identifying what could cause harm and what is being done to prevent it.
- Role-based access control
- Limiting what each user can see or do in a system according to their job role.
- Safeguarding
- Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
- Safety-netting
- Giving patients clear advice on what to watch for and what to do if their condition changes or worsens.
- Security information and event management (SIEM)
- Software that collects and analyses security data from across an organisation to detect and alert on threats.
- Service Level Agreement (SLA)
- A contract setting out the level of service, such as uptime, a supplier promises to deliver.
- Single assessment framework
- The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
- So far as is reasonably practicable
- Doing what is sensible and proportionate to reduce a risk, weighing the effort and cost against the level of harm prevented.
- Special category data
- Sensitive personal information, including health data, that data-protection law gives extra protection.
- Standard operating procedure (SOP)
- A written step-by-step instruction setting out how a particular task must be carried out consistently and safely.
- Sub-processor
- A further supplier that a main supplier brings in to help process personal data on an organisation's behalf.
- Transport Layer Security (TLS)
- A standard that encrypts data as it travels over the internet so it cannot be read or altered in transit.
- Triage
- Sorting patients by the urgency and nature of their needs so they receive the right care in the right order.
- UK General Data Protection Regulation (UK GDPR)
- The United Kingdom's main data-protection law governing how personal information is collected and used.
- Web Content Accessibility Guidelines (WCAG)
- An international standard setting out how to make websites and apps usable by people with disabilities.