{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Mobile Devices (Phones and Tablets) Policy
1. Purpose
This policy outlines {{org_field_name}}’s approach to the appropriate and secure use of mobile devices, including phones and tablets, within the care home environment. It ensures compliance with CQC regulations, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, Regulation 12 – Safe Care and Treatment, and Regulation 17 – Good Governance. The policy aims to balance the benefits of mobile technology with the need to maintain privacy, security, professionalism, and the well-being of the people we support.
2. Scope
This policy applies to all staff, including full-time, part-time, agency, and bank staff, as well as volunteers and contractors working at {{org_field_name}}. It covers both work-issued and personal mobile devices used within the care home premises.
3. Legal and Regulatory Framework
The use of mobile devices at {{org_field_name}} must comply with applicable legislation and regulatory requirements, including:
- Health and Social Care Act 2008 and the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014:
- Regulation 10 – Dignity and Respect: requires the privacy, dignity and autonomy of people using the service to be respected. Mobile devices must therefore be used in a manner that does not compromise a person’s privacy or dignity.
- Regulation 11 – Need for Consent: where mobile technology is used as part of the provision of care or treatment, the person’s valid consent must be obtained where required. Where a person lacks capacity to make the relevant decision, staff must act in accordance with the Mental Capacity Act 2005.
- Regulation 12 – Safe Care and Treatment: requires care and treatment to be provided safely, including the assessment and mitigation of risks associated with equipment, information and infection prevention and control.
- Regulation 13 – Safeguarding Service Users from Abuse and Improper Treatment: requires people using the service to be protected from abuse and improper treatment. Misuse of a mobile device, including unauthorised photography, recording, disclosure or sharing of information concerning a person using the service, must be treated as a potential safeguarding matter where appropriate.
- Regulation 17 – Good Governance: requires effective systems and processes to assess, monitor and mitigate risks and requires records relating to people using the service and the management of the regulated activity to be accurate, complete, contemporaneous and securely maintained.
- UK General Data Protection Regulation and Data Protection Act 2018, as amended, including by the Data (Use and Access) Act 2025: personal data and special category data must be processed lawfully, fairly, transparently and securely. Appropriate technical and organisational measures must be used to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage.
- Mental Capacity Act 2005: where a person lacks capacity to make a particular decision relating to the use of mobile technology as part of their care or treatment, any decision made on their behalf must comply with the principles and requirements of the Mental Capacity Act 2005, including the requirement to act in the person’s best interests where applicable.
- Human Rights Act 1998: mobile device use must respect the rights of people using the service, including the right to respect for private and family life.
- Health and Safety at Work etc. Act 1974: mobile devices must be used in a manner that does not create avoidable risks to people using the service, staff or others.
- Care Act 2014: any concern arising from the misuse of a mobile device that indicates abuse or neglect must be managed in accordance with applicable safeguarding duties and local safeguarding procedures.
Staff must also comply with relevant CQC guidance and with {{org_field_name}}’s information governance, confidentiality, safeguarding, consent and record-keeping policies.
4. Use of Mobile Devices in the Workplace
Work-Issued Devices
- Only authorised personnel may use work-issued mobile devices for professional purposes.
- Work devices must be used strictly for business-related activities, including care documentation, communication with teams, and accessing care plans.
Personal Mobile Devices
- Staff must not use personal devices during working hours, except in designated break areas.
- Personal mobile devices must not be used in clinical areas, resident rooms, or communal spaces where care is being provided.
- Phones must be kept on silent or vibrate mode to minimise disruption.
Photography and Recording
- Staff are strictly prohibited from using mobile devices to take photographs or record videos of residents, staff, or confidential documents.
- Any breaches of this policy will be subject to disciplinary action in line with CH31-Disciplinary and Grievance Policy.
5. Confidentiality and Data Security
Access to Confidential Information
- Personal data, special category data, care records, photographs, recordings and other confidential information concerning people using the service must only be accessed where there is a legitimate work-related need and the member of staff is authorised to access that information.
- Staff must not access, download, photograph, copy, store, transfer or otherwise process confidential or personal information relating to people using the service on a personal mobile device unless this is exceptionally necessary during an authorised emergency and the requirements in Section 6 of this policy are followed.
- Work-issued mobile devices used to access or process personal or confidential information must be protected by appropriate technical and organisational security measures proportionate to the nature and sensitivity of the information and the risks involved.
- Security measures must include, where appropriate:
- secure user authentication;
- individual user access wherever practicable;
- appropriate password or passcode protection;
- access controls based on the user’s role and responsibilities;
- encryption of personal information stored on or transmitted by the device where appropriate to the risk;
- supported and appropriately updated operating systems and applications;
- automatic device locking after an appropriate period of inactivity;
- restrictions on unauthorised applications, downloads or transfers; and
- arrangements to remove access promptly when it is no longer required.
- Staff must not share passwords, passcodes or user accounts or permit another person to access confidential information using their credentials.
- Mobile devices displaying confidential information must not be left unattended in a manner that allows unauthorised persons to view or access the information.
Secure Communication
- Personal or confidential information must only be communicated using systems, applications and communication methods approved by {{org_field_name}} for the relevant purpose.
- Personal messaging, social-media or file-sharing applications must not be used to communicate information about a person using the service unless the application and the particular use have been formally approved by {{org_field_name}} as compliant with applicable data protection and information security requirements.
- Staff must verify the intended recipient before sending personal or confidential information and must disclose only the minimum information necessary for the intended lawful purpose.
- Personal information must not be copied from an approved care-record or communication system into an unapproved application or into the personal storage area of a mobile device.
Lost, Stolen, Compromised or Unauthorised Devices
- Any work-issued device that is lost, stolen, misplaced or suspected of having been accessed or compromised by an unauthorised person must be reported immediately to the Registered Manager and to the person or team responsible for information governance or information technology within {{org_field_name}}.
- Staff must also immediately report any incident involving:
- unauthorised access to personal or confidential information;
- accidental disclosure of information to the wrong person;
- information being sent through an unauthorised application or system;
- unauthorised photographs, video or audio recordings;
- loss or deletion of personal information;
- malware or suspected cyber-attack affecting a device used for the service; or
- any other incident that may have compromised the confidentiality, integrity or availability of personal information.
- Where technically possible and appropriate, access to a lost, stolen or compromised work-issued device must be disabled and the device must be remotely locked or wiped in accordance with {{org_field_name}}’s information security arrangements.
Personal Data Breaches
- A suspected or confirmed personal data breach must be escalated immediately in accordance with {{org_field_name}}’s Data Protection and Personal Data Breach Procedure.
- The relevant responsible person must assess the nature and circumstances of the breach, the categories and approximate volume of personal data affected, the people affected, the likely consequences and the measures taken or proposed to contain and address the breach.
- {{org_field_name}} must maintain a record of personal data breaches in accordance with data protection legislation, including the facts relating to the breach, its effects and the remedial action taken.
- Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} must notify the Information Commissioner’s Office without undue delay and, where required by law, no later than 72 hours after becoming aware of the breach.
- Where a personal data breach is likely to result in a high risk to the rights and freedoms of an affected individual, {{org_field_name}} must communicate the breach to the individual without undue delay unless a lawful exception applies.
- Staff must not delay reporting an incident internally because they are uncertain whether it amounts to a reportable personal data breach. The decision as to whether external notification is required must be made by the person authorised by {{org_field_name}} to assess data protection incidents.
6. Mobile Device Use During Emergency Situations
Authorised Emergency Use
- Where normal communication or electronic care-record systems are unavailable because of an emergency, power failure, systems failure or other exceptional event, the Registered Manager or person in charge may authorise the limited use of an alternative mobile device where this is necessary to protect the health, safety or welfare of people using the service or to maintain essential service operations.
- Authorisation to use a personal mobile device during an emergency does not remove the requirement to comply with confidentiality and data protection legislation.
- Where a personal device must exceptionally be used:
- only the minimum personal information necessary for the emergency purpose may be used or disclosed;
- an approved communication method must be used wherever one remains available;
- information must not be saved permanently to the personal device unless this is unavoidable for the immediate emergency purpose;
- photographs, videos, screenshots or copies of care records must not be created or retained on the personal device unless specifically authorised as necessary for the emergency and lawful to do so;
- information must not be uploaded to personal cloud storage, personal email accounts, social-media platforms or unapproved messaging applications;
- any information temporarily held on the device must be securely removed as soon as it is no longer required and after any necessary information has been transferred to the authorised care or business record; and
- the use of the personal device and any relevant information handled must be reported to the Registered Manager.
- Any care, treatment, decision, communication or significant event that would ordinarily be entered into the person’s care record must be entered into the authorised record as soon as reasonably practicable once the system becomes available.
- Any loss, unauthorised disclosure or suspected compromise of personal information during emergency mobile-device use must be managed immediately as a potential personal data breach in accordance with Section 5 of this policy.
Emergency Contact for Staff
- Staff may keep personal mobile devices reasonably accessible where necessary for genuine emergency contact purposes, subject to local arrangements and provided that this does not compromise the safety, privacy, dignity or care of people using the service.
- Personal devices must not be used for routine non-work purposes while staff are providing care or carrying out duties where such use could distract them from their responsibilities or create a risk to people using the service.
7. Infection Control and Hygiene
Cleaning and Disinfection
- Work-issued mobile devices must be cleaned regularly with appropriate disinfectant wipes.
- Devices used in clinical areas must be stored in cleanable cases and sanitised daily.
Hand Hygiene
- Staff must wash hands before and after handling mobile devices to prevent cross-contamination.
8. Monitoring and Compliance
Monitoring
- {{org_field_name}} must maintain effective systems and processes to assess, monitor and mitigate risks associated with the use of work-issued and personal mobile devices in connection with the regulated service.
- Monitoring must be proportionate to identified risks and must include, where relevant:
- compliance with access and confidentiality controls;
- appropriate use of approved applications and communication systems;
- security of devices used to access care records or other confidential information;
- lost, stolen or compromised devices;
- personal data breaches and information-security incidents;
- unauthorised photography, recording or disclosure;
- compliance with infection prevention and control requirements; and
- completion of required staff training.
- Identified deficiencies or risks must be assessed and addressed within a timescale proportionate to their seriousness.
- Significant or repeated breaches, incidents and audit findings must be reviewed to identify patterns, underlying causes and any changes required to policies, procedures, training, technical controls or working practices.
Records
- Records of relevant audits, incidents, investigations, risk assessments, actions and decisions arising from mobile-device use must be accurate, complete, securely maintained and retained in accordance with {{org_field_name}}’s record-retention and data protection requirements.
Breaches and Disciplinary Action
- Any suspected misuse of a mobile device must be reported promptly to the Registered Manager.
- Misuse may include unauthorised access to information, inappropriate disclosure, unauthorised photography or recording, use of unapproved applications for confidential information, sharing access credentials, deliberate circumvention of security controls or inappropriate personal mobile-device use while carrying out care duties.
- Where the circumstances indicate that a person using the service may have experienced or be at risk of abuse, neglect, exploitation, harassment, humiliation or other improper treatment, the matter must also be managed in accordance with {{org_field_name}}’s safeguarding procedures and referred externally where required.
- Information-security or confidentiality incidents must also be considered under the personal data breach requirements in Section 5.
- Where appropriate, breaches by staff may result in action under the CH31-Disciplinary and Grievance Policy.
9. Training and Awareness
Staff Training and Competence
- Staff must receive appropriate instruction and training on confidentiality, data protection and the secure use of mobile devices relevant to their role before they are given access to electronic care records or other confidential information through a mobile device.
- Training must include, where relevant:
- maintaining confidentiality and privacy;
- secure access to electronic records;
- appropriate password and authentication practices;
- recognising and reporting lost, stolen or compromised devices;
- recognising and reporting personal data breaches and information-security incidents;
- restrictions on photographs, video and audio recordings;
- the appropriate use of approved communication applications;
- restrictions on the use of personal devices;
- safeguarding risks associated with mobile-device misuse; and
- the requirements of this policy.
- Staff must understand how to report concerns and incidents promptly and must know who to contact if they believe that personal or confidential information has been lost, disclosed, accessed or otherwise processed inappropriately.
- Additional instruction or training must be provided where monitoring, incidents, changes to systems, changes to legislation or an assessment of staff competence identify that this is required.
- Staff must only use systems and devices for which they have been appropriately authorised and for which they have sufficient knowledge and competence to use safely and securely.
- Compliance with required training must be monitored, and appropriate action must be taken where mandatory training has not been completed.
10. Related Policies
- CH12-Safe Care and Treatment Policy
- CH17-Infection Prevention and Control Policy
- CH18-Risk Management and Assessment Policy
- CH27-Staff Supervision, Training, and Development Policy
- CH30-Confidentiality and Data Protection (GDPR) Policy
- CH31-Disciplinary and Grievance Policy
11. Policy Review
- This policy will be reviewed annually or sooner if updates in CQC regulations, data protection laws, or business needs arise.
- Amendments will be made to ensure compliance with the latest best practices in mobile device management.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.