Standard operating procedure

Cyber Incident Response Procedure

How [Organisation Name] recognises, contains, reports and recovers from cyber incidents and personal data breaches affecting its online clinic, and meets its statutory duties to the Information Commissioner's Office and to affected patients

For Telehealth & Online ClinicRef BS-TEL-SOP-009See a sample (PDF) →
£39.99
One-off purchase · no VAT · instant download
  • Instant download after checkout
  • Editable Microsoft Word (.docx)
  • Mapped to the CQC standards
  • Optional 3-monthly updates

What's inside

This standard operating procedure is fully drafted and structured, ready to brand and complete for your service. It covers:

  • 1. Purpose
  • 2. Scope
  • 3. Definitions and abbreviations
  • 4. Responsibilities
  • 5. Preparedness
  • 6. Procedure
  • 7. Notification and reporting
  • 8. Records
  • 9. Post-incident review, learning and staff awareness
  • 10. Related documents
  • 11. Review and version control
  • 12. Disclaimer

Legislation & standards it maps to

  • UK General Data Protection Regulation (UK GDPR) - Article 33 (notification of a personal data breach to the supervisory authority) and Article 34 (communication of a personal data breach to the data subject)
  • Data Protection Act 2018
  • Information Commissioner's Office (ICO) guidance on personal data breaches and the duty to report
  • Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 - Regulation 17 (Good governance)
  • Data Security and Protection Toolkit (where the service handles patient data, or connects to national systems, covered by the Toolkit)
  • National Cyber Security Centre (NCSC) guidance, including its small organisations and incident management guidance
  • Care Quality Commission (CQC) single assessment framework

Who it applies to

All clinicians, prescribers, customer service and administrative staff, technical and information governance staff, contractors and any data processors acting for [Organisation Name], together with the registered manager, the data protection lead and the senior information risk owner or [Insert Job Title], who use, support or hold patient information or the systems on which the service depends

Glossary

Plain-English explanations of the technical terms and legislation used in this document.

Action Fraud
The United Kingdom's national reporting centre for fraud and cyber crime, run with the police.
Care Quality Commission (CQC)
The independent regulator of health and social care services in England.
Containment
Action taken to stop a cyber incident spreading or causing further harm, such as isolating an affected device or account.
Controlled drug
A medicine whose supply, storage and records are tightly restricted by law because of its potential for misuse.
Cyber incident
Any event that harms, or could harm, the security of an organisation's information or the systems that hold it.
Data processor
An organisation that handles personal data on behalf of, and on the instructions of, the service that decides how the data is used.
Data Protection Act 2018
The United Kingdom law that sits alongside the UK GDPR and governs how personal information is handled.
Data protection lead
The person responsible for advising on and overseeing the organisation's handling of personal data and its breach duties.
Data Security and Protection Toolkit (DSP Toolkit)
An online self-assessment and incident-reporting tool for organisations that handle certain patient data or connect to national health systems.
Denial-of-service attack
An attack that floods a system or website with traffic so that it becomes slow or unavailable to genuine users.
Encryption
Scrambling data so that it can only be read by someone who holds the correct key, protecting it if it is lost or stolen.
Exfiltration
The unauthorised copying or transfer of data out of an organisation's systems.
Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
The regulations setting the fundamental standards that registered health and care providers must meet.
Information Commissioner's Office (ICO)
The United Kingdom's independent regulator for data protection and information rights, to which serious data breaches are reported.
Information governance
The framework for handling people's personal and health information legally, securely and appropriately.
Malware
Malicious software designed to damage, disrupt or gain unauthorised access to a computer system.
National Cyber Security Centre (NCSC)
The United Kingdom's technical authority for cyber security, which provides guidance and support during incidents.
Near miss
An event that could have caused harm but did not, by chance or because it was caught in time.
Patch
A software update that fixes a fault or closes a security weakness.
Personal data breach
A security failure that leads to personal data being lost, stolen, destroyed, altered or seen by the wrong people.
Phishing
A fraudulent message, usually by email, that tries to trick someone into revealing passwords or details or into installing malicious software.
Ransomware
Malicious software that locks or encrypts data and demands payment to restore access.
Registered Manager
The person registered with the regulator as responsible for the day-to-day running of a service.
Regulated activity
A type of care or treatment the law requires a provider to register with the regulator to deliver.
Risk assessment
A structured check identifying what could cause harm and what is being done to prevent it.
Senior Information Risk Owner (SIRO)
The senior person accountable for managing information risk across the organisation.
Single assessment framework
The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
Special category data
Sensitive personal data, including information about a person's health, which the law gives extra protection.
Standard Operating Procedure (SOP)
A written, step-by-step instruction setting out how a particular task or process should be carried out consistently.
Subject Access Request (SAR)
A person's legal right to ask for a copy of the personal information an organisation holds about them.
UK General Data Protection Regulation (UK GDPR)
The UK's main data-protection law governing how personal information is collected and used.

How it works

  1. Buy securely with Stripe - instant, no VAT, no account needed.
  2. Download your editable Word file from the link we email you straight away.
  3. Complete the placeholders for your service, then have it approved before use.
  4. Add the optional updates subscription and we keep it current as guidance changes.

Related documents

PolicyTelehealth Consent Policy£54.99
PolicyCybersecurity Policy£54.99
PolicyRemote Assessment Policy£54.99
PolicyData Protection Policy£54.99

Need the whole set?

Buy the full Telehealth & Online Clinic pack and save versus buying documents individually.

View the Telehealth & Online Clinic pack