Plain-English explanations of the technical terms and legislation used in this document.
- Authentication
- Confirming that a person is who they claim to be before they are allowed access, usually by checking a password and a second proof of identity.
- BYOD (bring-your-own-device)
- The use of a member of staff's own personal computer, tablet or phone for work.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Clear-desk / clear-screen
- The habit of leaving no confidential information visible on a desk or screen when it is left unattended.
- Common law duty of confidentiality
- The long-standing legal duty to keep information someone shares in confidence private and to use it only for the purpose it was given.
- Controller
- The organisation that decides how and why personal data is used and is legally responsible for protecting it.
- Cyber Essentials
- A UK government-backed scheme that sets out basic technical controls an organisation should have in place to guard against common cyber attacks.
- Data Protection Act 2018
- The UK law that sits alongside the UK GDPR and governs how personal information must be handled.
- Data Protection Impact Assessment (DPIA)
- A check done before a new activity to identify and reduce risks to people's personal data.
- Data Protection Officer
- A designated person responsible for advising on and monitoring an organisation's compliance with data-protection law.
- Data Security and Protection Toolkit (DSPT)
- An annual online self-assessment that lets an organisation measure its data-security and information-handling standards against national requirements.
- Encryption
- Scrambling data into a coded form so it cannot be read without the right key, protecting it whether it is being sent ('in transit') or stored ('at rest').
- Full-disk encryption
- Encrypting everything on a device's storage so its contents cannot be read if the device is lost or stolen.
- Hashing
- A one-way method of scrambling a password so the system can check it without ever storing the password itself in readable form.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- The regulations setting out the fundamental standards that providers of regulated care must meet, enforced by the Care Quality Commission.
- Information Commissioner's Office (ICO)
- The UK's independent regulator for data protection and information rights, to which serious data breaches are reported.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Least privilege
- The principle of giving each person access only to the information and functions they need for their role, and no more.
- Multi-factor authentication (MFA)
- A login that requires two or more separate proofs of identity, such as a password plus a one-time code, so a stolen password alone is not enough to get in.
- National Cyber Security Centre (NCSC)
- The UK's national technical authority for cyber security, which publishes guidance to help organisations stay secure.
- Near miss
- An event that could have caused harm but did not, by chance or because it was caught in time.
- Nominated Individual
- The senior person responsible to the regulator for supervising how a service is provided.
- Patching
- Applying the security updates that software makers release to fix newly discovered weaknesses.
- Personal / patient data
- Information that identifies a living person; patient data includes health details and is treated as 'special category' data needing extra protection.
- Phishing
- A trick, usually by email or message, that tries to fool someone into revealing passwords or other sensitive information or into clicking a harmful link.
- Privacy notice
- A document that tells people what personal information an organisation collects about them, why, and how it is used.
- Processor
- An organisation that handles personal data on behalf of the controller, such as a hosting, platform or email provider.
- Ransomware
- Malicious software that locks or encrypts an organisation's data and demands payment to release it.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Regulated activity
- A type of care or treatment the law requires a provider to register with the regulator to deliver.
- Removable media
- Portable storage such as a USB stick, memory card or external drive that can be plugged into a device and carried away.
- Role-based access control (RBAC)
- Granting access according to a person's defined job role, so access changes automatically when they join, change or leave that role.
- Senior Information Risk Owner (SIRO)
- The senior person who holds overall accountability for an organisation's information risk.
- Social engineering
- Manipulating or deceiving people into giving away information or access rather than attacking technology directly.
- Special category data
- Particularly sensitive personal information, such as health data, that data-protection law gives extra protection.
- Standard Operating Procedure (SOP)
- A written, step-by-step procedure setting out how a particular task is to be carried out consistently and safely.
- Subject Access Request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- UK General Data Protection Regulation (UK GDPR)
- The UK's main data-protection law governing how personal information is collected, used and kept secure.
- Virtual private network (VPN)
- An encrypted connection that lets staff reach the clinic's systems securely over the internet.