Standard operating procedure

Data Security & Access Control Procedure

The day-to-day procedure by which [Organisation Name], an online clinic whose clinicians often work remotely, keeps patient information secure - applying role-based access on the least-privilege principle, strong authentication including multi-factor authentication, device and platform security, and safe home and remote-working practices - so that the right people, and only the right people, can reach patient data.

For Telehealth & Online ClinicRef BS-TEL-SOP-008See a sample (PDF) →
£39.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This standard operating procedure is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Definitions and abbreviations
  • 4. Responsibilities
  • 5. Procedure
  • 6. Home and remote working
  • 7. Records
  • 8. Related documents
  • 9. Review and version control
  • 10. Disclaimer

Legislation & standards it maps to

  • UK General Data Protection Regulation (UK GDPR), in particular Article 5(1)(f) (the security principle) and Article 32 (security of processing)
  • Data Protection Act 2018
  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, Regulation 17 (Good governance)
  • Data Security and Protection Toolkit (DSPT), where applicable to the service
  • National Cyber Security Centre (NCSC) guidance, including the Cyber Essentials scheme
  • Common law duty of confidentiality

Who it applies to

All clinical, administrative, management, technical and support staff at [Organisation Name], including employed, bank, locum, agency, contractor and volunteer staff, who access, hold, process, transfer or administer patient or other confidential information on any system or device, whether working from the clinic's premises or from home or another remote location.

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Authentication
Confirming that a person is who they claim to be before they are allowed access, usually by checking a password and a second proof of identity.
BYOD (bring-your-own-device)
The use of a member of staff's own personal computer, tablet or phone for work.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Clear-desk / clear-screen
The habit of leaving no confidential information visible on a desk or screen when it is left unattended.
Common law duty of confidentiality
The long-standing legal duty to keep information someone shares in confidence private and to use it only for the purpose it was given.
Controller
The organisation that decides how and why personal data is used and is legally responsible for protecting it.
Cyber Essentials
A UK government-backed scheme that sets out basic technical controls an organisation should have in place to guard against common cyber attacks.
Data Protection Act 2018
The UK law that sits alongside the UK GDPR and governs how personal information must be handled.
Data Protection Impact Assessment (DPIA)
A check done before a new activity to identify and reduce risks to people's personal data.
Data Protection Officer
A designated person responsible for advising on and monitoring an organisation's compliance with data-protection law.
Data Security and Protection Toolkit (DSPT)
An annual online self-assessment that lets an organisation measure its data-security and information-handling standards against national requirements.
Encryption
Scrambling data into a coded form so it cannot be read without the right key, protecting it whether it is being sent ('in transit') or stored ('at rest').
Full-disk encryption
Encrypting everything on a device's storage so its contents cannot be read if the device is lost or stolen.
Hashing
A one-way method of scrambling a password so the system can check it without ever storing the password itself in readable form.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting out the fundamental standards that providers of regulated care must meet, enforced by the Care Quality Commission.
Information Commissioner's Office (ICO)
The UK's independent regulator for data protection and information rights, to which serious data breaches are reported.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Least privilege
The principle of giving each person access only to the information and functions they need for their role, and no more.
Multi-factor authentication (MFA)
A login that requires two or more separate proofs of identity, such as a password plus a one-time code, so a stolen password alone is not enough to get in.
National Cyber Security Centre (NCSC)
The UK's national technical authority for cyber security, which publishes guidance to help organisations stay secure.
Near miss
An event that could have caused harm but did not, by chance or because it was caught in time.
Nominated Individual
The senior person responsible to the regulator for supervising how a service is provided.
Patching
Applying the security updates that software makers release to fix newly discovered weaknesses.
Personal / patient data
Information that identifies a living person; patient data includes health details and is treated as 'special category' data needing extra protection.
Phishing
A trick, usually by email or message, that tries to fool someone into revealing passwords or other sensitive information or into clicking a harmful link.
Privacy notice
A document that tells people what personal information an organisation collects about them, why, and how it is used.
Processor
An organisation that handles personal data on behalf of the controller, such as a hosting, platform or email provider.
Ransomware
Malicious software that locks or encrypts an organisation's data and demands payment to release it.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Regulated activity
A type of care or treatment the law requires a provider to register with the regulator to deliver.
Removable media
Portable storage such as a USB stick, memory card or external drive that can be plugged into a device and carried away.
Role-based access control (RBAC)
Granting access according to a person's defined job role, so access changes automatically when they join, change or leave that role.
Senior Information Risk Owner (SIRO)
The senior person who holds overall accountability for an organisation's information risk.
Social engineering
Manipulating or deceiving people into giving away information or access rather than attacking technology directly.
Special category data
Particularly sensitive personal information, such as health data, that data-protection law gives extra protection.
Standard Operating Procedure (SOP)
A written, step-by-step procedure setting out how a particular task is to be carried out consistently and safely.
Subject Access Request (SAR)
A person's legal right to ask for a copy of the personal information an organisation holds about them.
UK General Data Protection Regulation (UK GDPR)
The UK's main data-protection law governing how personal information is collected, used and kept secure.
Virtual private network (VPN)
An encrypted connection that lets staff reach the clinic's systems securely over the internet.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyTelehealth Consent Policy£54.99
PolicyCybersecurity Policy£54.99
PolicyRemote Assessment Policy£54.99
PolicyData Protection Policy£54.99

Need the whole set?

Buy the full Telehealth & Online Clinic pack and save versus buying documents individually.

View the Telehealth & Online Clinic pack