Risk assessment

Digital Access Risk Assessment

Identifying and controlling risks arising from digital access to remote consultation, prescribing and clinical services in an online/virtual clinic

For Telehealth & Online ClinicRef BS-TEL-RA-001See a sample (PDF) →
£44.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This risk assessment is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Scope and purpose
  • 2. Legal and regulatory framework
  • 3. Risk assessment methodology
  • 4. Hazards, controls and risk rating
  • 5. Action plan
  • 6. Monitoring and review
  • 7. Disclaimer

Legislation & standards it maps to

  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (Regulations 9 to 20A)
  • Care Quality Commission (Registration) Regulations 2009
  • Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR)
  • Network and Information Systems Regulations 2018
  • Computer Misuse Act 1990
  • Human Medicines Regulations 2012 (as amended)
  • Equality Act 2010
  • Health and Safety at Work etc. Act 1974 and the Management of Health and Safety at Work Regulations 1999

Who it applies to

All clinical, administrative and technical staff, registered managers, IT and information governance leads, and third-party platform suppliers involved in the delivery of remote consultations, online prescribing, digital triage and patient-facing portal services at [Organisation Name].

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Advanced Encryption Standard (AES)
A widely used method of scrambling stored data so it cannot be read by anyone without the correct key.
Application programming interface (API)
A set of rules that lets two different computer systems exchange data with each other automatically.
Artificial intelligence (AI)
Computer software that performs tasks normally needing human judgement, such as sorting patients by symptoms.
Asynchronous consultation
A consultation where the patient and clinician communicate at different times, such as by secure message or questionnaire, rather than live.
Blood-borne virus (BBV)
An infection such as hepatitis B, hepatitis C or HIV that can be passed on through blood.
British Sign Language (BSL)
A visual language using hand shapes, facial expressions and gestures, used by many deaf people in the United Kingdom.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Clinical safety case
A documented argument, with supporting evidence, that a health information technology system is acceptably safe to use.
Computer Misuse Act 1990
The law that makes unauthorised access to computer systems and data a criminal offence.
Contemporaneous record
A record written at the time of, or very soon after, the event it describes, so it is accurate and reliable.
Controlled drug
A medicine whose supply, storage and records are tightly restricted by law because of its potential for misuse.
Cyber Assessment Framework
A National Cyber Security Centre tool used to judge how well an organisation manages cyber security risks to essential services.
Data Processing Agreement (DPA)
A contract setting out how a supplier must handle and protect personal data it processes on an organisation's behalf.
Data Protection Act 2018
The United Kingdom's main data-protection law, which sits alongside the UK General Data Protection Regulation.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data Protection Officer (DPO)
The person responsible for advising on and monitoring an organisation's compliance with data-protection law.
DCB0129 / DCB0160
Clinical risk management standards setting out how the manufacturers and users of health information technology must manage clinical safety.
Decontamination
The combined process of cleaning, disinfecting and, where needed, sterilising equipment so it is safe to reuse.
Did not attend (DNA)
A record that a patient missed a booked appointment without cancelling it beforehand.
Electronic patient record (EPR)
The digital record holding a patient's clinical history, consultations, test results and treatment.
Electronic Prescription Service (EPS)
A system that sends prescriptions electronically from a prescriber to a pharmacy, instead of on paper.
Endpoint detection and response (EDR)
Security software that watches computers and devices for signs of attack and helps respond to threats quickly.
Equality Act 2010
The law protecting people from discrimination based on characteristics such as age, disability, sex or race.
Failover
Automatically switching to a backup system when the main one fails, so the service keeps running.
FIDO2
A modern login standard, often using a security key or device, that strongly resists phishing and stolen-password attacks.
Formulary
An approved list of medicines that clinicians in a service are permitted to prescribe.
Fundamental standards
The minimum standards of safety and quality below which care must never fall.
General Medical Council (GMC)
The body that registers and regulates doctors in the United Kingdom.
General Pharmaceutical Council (GPhC)
The body that registers and regulates pharmacists and pharmacies in Great Britain.
Health and Safety at Work etc. Act 1974
The main law placing a duty on employers to protect the health and safety of staff and others affected by their work.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting out the fundamental standards that all registered care providers in England must meet.
Human Medicines Regulations 2012
The law governing how medicines are licensed, prescribed, supplied and advertised in the United Kingdom.
Immutable backup
A backup copy of data that cannot be altered or deleted once written, protecting it from ransomware and tampering.
Information Commissioner's Office (ICO)
The United Kingdom's independent regulator for data protection and information rights.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Information technology (IT)
The computers, networks, software and systems an organisation uses to store and process information.
ISO/IEC 27001
An internationally recognised standard for managing the security of information within an organisation.
Liveness check
A test confirming that a person verifying their identity online is real and present, not a photo or recording.
Multi-factor authentication (MFA)
A login method requiring two or more proofs of identity, such as a password plus a code, for extra security.
National Cyber Security Centre (NCSC)
The United Kingdom government body that provides advice and support on protecting against cyber threats.
Near miss
An event that could have caused harm but did not, by chance or because it was caught in time.
Network and Information Systems Regulations 2018
The law requiring operators of essential and digital services to manage the security and resilience of their networks.
Nominated Individual
The senior person responsible to the regulator for supervising how a service is provided.
Notifiable event
An incident a provider is legally required to report to the regulator, such as a death or serious injury.
Penetration test
An authorised simulated cyber attack used to find security weaknesses before real attackers do.
Personal protective equipment (PPE)
Items such as gloves, aprons and masks worn to protect against harm or infection.
Phishing
A scam where attackers trick people into revealing passwords or data, usually through fake emails or messages.
Prescription-only medicine (POM)
A medicine that may lawfully be supplied only on the instruction of an appropriate prescriber.
Protected characteristics
The personal features, such as age, disability, sex and race, that the Equality Act 2010 protects from discrimination.
Ransomware
Malicious software that locks or encrypts an organisation's data until a ransom is paid.
Reasonable adjustments
Changes a service makes so that disabled people can use it as easily as everyone else.
Recovery Point Objective (RPO)
The maximum amount of data, measured in time, an organisation is prepared to lose in an incident.
Recovery Time Objective (RTO)
The target time within which a service must be restored after a disruption.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Regulated activity
A type of care or treatment the law requires a provider to register with the regulator to deliver.
Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (RIDDOR)
The law requiring certain workplace injuries, diseases and dangerous events to be reported to the Health and Safety Executive.
Risk assessment
A structured check identifying what could cause harm and what is being done to prevent it.
Role-based access control
Limiting what each user can see or do in a system according to their job role.
Safeguarding
Protecting people's health, wellbeing and rights and keeping them safe from abuse, harm or neglect.
Safety-netting
Giving patients clear advice on what to watch for and what to do if their condition changes or worsens.
Security information and event management (SIEM)
Software that collects and analyses security data from across an organisation to detect and alert on threats.
Service Level Agreement (SLA)
A contract setting out the level of service, such as uptime, a supplier promises to deliver.
Single assessment framework
The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
So far as is reasonably practicable
Doing what is sensible and proportionate to reduce a risk, weighing the effort and cost against the level of harm prevented.
Special category data
Sensitive personal information, including health data, that data-protection law gives extra protection.
Standard operating procedure (SOP)
A written step-by-step instruction setting out how a particular task must be carried out consistently and safely.
Sub-processor
A further supplier that a main supplier brings in to help process personal data on an organisation's behalf.
Transport Layer Security (TLS)
A standard that encrypts data as it travels over the internet so it cannot be read or altered in transit.
Triage
Sorting patients by the urgency and nature of their needs so they receive the right care in the right order.
UK General Data Protection Regulation (UK GDPR)
The United Kingdom's main data-protection law governing how personal information is collected and used.
Web Content Accessibility Guidelines (WCAG)
An international standard setting out how to make websites and apps usable by people with disabilities.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyTelehealth Consent Policy£54.99
PolicyCybersecurity Policy£54.99
PolicyRemote Assessment Policy£54.99
PolicyData Protection Policy£54.99

Need the whole set?

Buy the full Telehealth & Online Clinic pack and save versus buying documents individually.

View the Telehealth & Online Clinic pack