Plain-English explanations of the technical terms and legislation used in this document.
- Action Fraud
- The United Kingdom's national reporting centre for fraud and cyber crime, run with the police.
- Care Quality Commission (CQC)
- The independent regulator of health and social care services in England.
- Containment
- Action taken to stop a cyber incident spreading or causing further harm, such as isolating an affected device or account.
- Controlled drug
- A medicine whose supply, storage and records are tightly restricted by law because of its potential for misuse.
- Cyber incident
- Any event that harms, or could harm, the security of an organisation's information or the systems that hold it.
- Data processor
- An organisation that handles personal data on behalf of, and on the instructions of, the service that decides how the data is used.
- Data Protection Act 2018
- The United Kingdom law that sits alongside the UK GDPR and governs how personal information is handled.
- Data protection lead
- The person responsible for advising on and overseeing the organisation's handling of personal data and its breach duties.
- Data Security and Protection Toolkit (DSP Toolkit)
- An online self-assessment and incident-reporting tool for organisations that handle certain patient data or connect to national health systems.
- Denial-of-service attack
- An attack that floods a system or website with traffic so that it becomes slow or unavailable to genuine users.
- Encryption
- Scrambling data so that it can only be read by someone who holds the correct key, protecting it if it is lost or stolen.
- Exfiltration
- The unauthorised copying or transfer of data out of an organisation's systems.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- The regulations setting the fundamental standards that registered health and care providers must meet.
- Information Commissioner's Office (ICO)
- The United Kingdom's independent regulator for data protection and information rights, to which serious data breaches are reported.
- Information governance
- The framework for handling people's personal and health information legally, securely and appropriately.
- Malware
- Malicious software designed to damage, disrupt or gain unauthorised access to a computer system.
- National Cyber Security Centre (NCSC)
- The United Kingdom's technical authority for cyber security, which provides guidance and support during incidents.
- Near miss
- An event that could have caused harm but did not, by chance or because it was caught in time.
- Patch
- A software update that fixes a fault or closes a security weakness.
- Personal data breach
- A security failure that leads to personal data being lost, stolen, destroyed, altered or seen by the wrong people.
- Phishing
- A fraudulent message, usually by email, that tries to trick someone into revealing passwords or details or into installing malicious software.
- Ransomware
- Malicious software that locks or encrypts data and demands payment to restore access.
- Registered Manager
- The person registered with the regulator as responsible for the day-to-day running of a service.
- Regulated activity
- A type of care or treatment the law requires a provider to register with the regulator to deliver.
- Risk assessment
- A structured check identifying what could cause harm and what is being done to prevent it.
- Senior Information Risk Owner (SIRO)
- The senior person accountable for managing information risk across the organisation.
- Single assessment framework
- The structure the regulator uses to judge a service, built around quality statements and five key questions (safe, effective, caring, responsive, well-led).
- Special category data
- Sensitive personal data, including information about a person's health, which the law gives extra protection.
- Standard Operating Procedure (SOP)
- A written, step-by-step instruction setting out how a particular task or process should be carried out consistently.
- Subject Access Request (SAR)
- A person's legal right to ask for a copy of the personal information an organisation holds about them.
- UK General Data Protection Regulation (UK GDPR)
- The UK's main data-protection law governing how personal information is collected and used.