{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
IT Equipment Security Policy
1. Purpose
The purpose of this policy is to establish the technical, organisational and physical controls that {{org_field_name}} uses to protect its information, IT equipment and electronic care-record systems. These controls are intended to protect the confidentiality, integrity, availability and resilience of personal data and other organisational information used in the provision of care-at-home services.
{{org_field_name}} will process personal data securely and lawfully in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 and other applicable legislation. Particular care will be taken when processing health information, care records, medication information, safeguarding information and other special category personal data.
This policy supports the organisation’s responsibilities under Scottish care-service legislation, the Health and Social Care Standards, the Scottish Social Services Council Codes of Practice for Social Service Workers and Employers 2024, and the Care Inspectorate quality framework for support services, including care at home and supported living.
The policy applies a proportionate, risk-based approach. Security controls will be selected after considering the nature, scope, context and purpose of the processing, the sensitivity of the information, the likelihood and severity of harm, current technical standards and the cost of implementation.
2. Scope
This policy applies to:
- All employees, agency workers, volunteers, students, directors, contractors and other persons who use or have access to {{org_field_name}} information, systems or IT equipment.
- Management and IT administrators responsible for ensuring secure IT operations.
- Third-party service providers with access to IT equipment or data.
- Cloud-based systems and networks used for storing and processing sensitive information.
- Company-owned, leased and personally owned equipment authorised for work purposes.
- Electronic care-record and care-management systems.
- Rostering, medication, call-monitoring, finance, payroll, recruitment and workforce systems.
- Email, messaging, video-conferencing and collaboration platforms.
- Removable media, printers, scanners, cameras and voice-recording equipment.
- Systems accessed while staff are working in an individual’s home, travelling between visits or working remotely.
- Paper records created, printed or transported using IT equipment.
- Backup systems, archived data and disaster-recovery systems.
- Artificial intelligence, transcription, translation and automated decision-support tools.
- Information processed by third-party suppliers on behalf of {{org_field_name}}.
This policy applies regardless of whether information is accessed from an office, an individual’s home, a vehicle, a public location or another remote-working location. Compliance with this policy is a condition of access to the organisation’s systems and information.
3. Legal and Regulatory Requirements
- UK General Data Protection Regulation.
- Data Protection Act 2018.
- Privacy and Electronic Communications (EC Directive) Regulations 2003, where applicable.
- Computer Misuse Act 1990.
- Human Rights Act 1998, including the right to respect for private and family life, home and correspondence.
- Regulation of Investigatory Powers Act 2000 and the Investigatory Powers Act 2016, where monitoring or interception is undertaken.
- Public Services Reform (Scotland) Act 2010.
- Social Care and Social Work Improvement Scotland (Requirements for Care Services) Regulations 2011.
- Health and Social Care Standards: My support, my life.
- Scottish Social Services Council Codes of Practice for Social Service Workers and Employers 2024.
- Care Inspectorate quality framework for support services, including care at home and supported living models of support.
- National Cyber Security Centre guidance.
- Cyber Essentials requirements, where the organisation holds or is working towards Cyber Essentials certification.
- Contractual information-security requirements imposed by local authorities, health and social care partnerships, NHS bodies or other commissioners.
Cyber Essentials is a government-backed cyber security certification scheme and good-practice framework. It is not, by itself, a substitute for compliance with the UK GDPR, the Data Protection Act 2018 or Scottish care-service requirements. Where {{org_field_name}} claims Cyber Essentials certification, the organisation must ensure that the certification remains valid and that all relevant systems, devices and cloud services are included within the declared scope.
3.1 Data Protection Principles
When using IT equipment or electronic systems, all workers must ensure that personal data is:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes;
- adequate, relevant and limited to what is necessary;
- accurate and kept up to date;
- retained for no longer than necessary;
- protected against unauthorised or unlawful processing and against accidental loss, destruction or damage; and
- processed in a manner that enables {{org_field_name}} to demonstrate compliance.
Health information, medication information, care and support records, adult protection information and information about disability, ethnicity, religion, sexual orientation or other protected characteristics must be treated as sensitive information and protected accordingly.
4. Responsibilities
- Board, directors or provider: Have overall accountability for information governance and cyber security, including the provision of suitable resources, systems, oversight and assurance.
- Senior Information Risk Owner or nominated senior lead: Owns significant information risks and ensures that these risks are recorded, reviewed and escalated appropriately.
- Data Protection Officer or Data Protection Lead: Advises on data protection compliance, monitors compliance, supports data protection impact assessments, maintains breach records and determines whether a personal data breach must be reported to the ICO or communicated to affected individuals.
- IT Security Manager or authorised IT provider: Implements, maintains and monitors technical controls, including access controls, device configuration, patching, backup, recovery, logging, malware protection and vulnerability management.
- Registered Manager: Ensures that this policy is implemented within the care service, workers receive appropriate instruction and training, incidents affecting care delivery are managed, and relevant Care Inspectorate notifications are considered.
- Line managers: Approve access according to job role, review access regularly, ensure access is removed promptly when no longer required, and address non-compliance.
- All workers: Use systems only for authorised purposes, protect passwords and authentication devices, follow confidentiality requirements, maintain accurate records and report incidents or concerns immediately.
- Third-party processors and IT providers: Comply with written contracts, data processing terms, confidentiality obligations, agreed security standards, breach-reporting timescales, audit requirements and secure return or deletion requirements.
- System and information asset owners: Identify the information held in each system, approve access, confirm retention requirements, review supplier assurance and ensure that risks are documented and managed.
Workers must not attempt to investigate a suspected cyber incident themselves beyond taking immediate steps necessary to prevent further disclosure or harm. They must preserve relevant evidence and follow instructions from the authorised incident-response lead.
4.1 Access Authorisation and Leavers
Access to systems and information must be authorised before it is provided. Access must be based on the worker’s role, responsibilities and legitimate need to know.
Managers must notify the IT lead immediately when:
- a worker leaves the organisation;
- a contract or placement ends;
- a worker changes role;
- a worker is suspended;
- access is no longer required; or
- there is concern that an account, password or device may be compromised.
Access for leavers must be disabled no later than the end of their final working period, or immediately where there is a security, safeguarding or misconduct concern. Company equipment, security keys, identity cards and storage media must be recovered and recorded.
Privileged and administrator access must be limited to authorised personnel, protected by multi-factor authentication, used only for administrative tasks and reviewed more frequently than ordinary user access.
5. IT Equipment Security Measures
5.1 Physical Security of IT Equipment
- Workstations, laptops, and mobile devices must be locked when unattended.
- Secure storage: Devices not in use must be stored in locked cabinets or designated secure areas.
- IT equipment and records must not be left unattended in an unsecured location. Equipment should not normally be left in a vehicle overnight. Where equipment must temporarily remain in a vehicle, it must be powered off, concealed from view, stored in a locked compartment and protected by encryption. The worker must assess whether the equipment can safely remain in the vehicle, taking account of the location, duration and sensitivity of the information.
- Removable media must not be used unless there is a documented business need and prior authorisation from the IT lead or manager. Only organisation-issued, centrally managed and encrypted removable media may be used. Personal USB devices and unapproved external storage devices are prohibited.
- Any lost, stolen, misplaced or potentially compromised device, storage medium, security key or paper record must be reported immediately using the organisation’s incident-reporting process. The report must be made even where the device is encrypted or is later recovered.
- Screens must be positioned to prevent unauthorised viewing.
- Privacy screens must be used where there is a foreseeable risk of “shoulder surfing”.
- Confidential telephone or video conversations must not take place where they can be overheard.
- Devices must not be handed to individuals receiving care, relatives or other unauthorised persons unless this is part of an authorised care activity and suitable controls are in place.
- Paper records printed from electronic systems must be collected promptly and stored securely.
- Confidential waste must be placed in approved secure-disposal containers and must not be placed in ordinary household waste or recycling.
5.1.1 Use of Technology in People’s Homes
When using a device in an individual’s home, workers must respect the individual’s dignity, privacy, property and family life. Workers must explain, in an accessible way, why a device is being used and what information is being recorded.
Workers must:
- confirm that they have selected the correct individual’s electronic record before viewing or entering information;
- avoid displaying information about other individuals;
- position the device so that visitors or other household members cannot view confidential information;
- record information discreetly and accurately;
- not photograph, film or make an audio recording unless this has been expressly authorised, is lawful, is necessary for an identified purpose and is covered by the appropriate consent or other lawful authority;
- not use personal messaging accounts, personal email accounts or social media to communicate personal information;
- lock or close the record before leaving the individual’s home; and
- report any concern that information has been seen, heard, altered or accessed by an unauthorised person.
The use of technology must not unnecessarily reduce meaningful contact with the individual or interfere with the delivery of compassionate, person-centred care.
5.2 User Authentication and Access Controls
- Passwords must meet the organisation’s current technical standard. Long, unique passwords or passphrases must be used. Passwords must not be reused across work and personal accounts, written in an insecure location, disclosed to another person or entered in response to an unsolicited request. Approved password managers should be used where provided. Routine password expiry will not be required unless indicated by the organisation’s technical standard, contractual requirements or evidence that a password may have been compromised.
- Multi-factor authentication must be enabled for remote access, cloud services, email, administrator accounts, systems containing sensitive or special category personal data, and any other system identified through risk assessment. Authentication factors must not be shared or approved in response to an unexpected prompt.
- Individual user accounts must be used—shared logins are prohibited.
- Access to sensitive systems is granted based on role-based permissions (least privilege principle).
- Devices and applications must automatically lock after an approved period of inactivity. Workers must manually lock their device whenever it is unattended. The inactivity period must be proportionate to the environment and risk and must be set centrally wherever practicable.
- Access rights must be reviewed at least every six months and following role changes.
- Administrator access must not be used for routine email, web browsing or care-record work.
- Accounts must not be created using generic names where individual accountability is required.
- Emergency or “break-glass” access must be logged, monitored and reviewed.
- Repeated failed login attempts and suspicious authentication activity must be monitored and investigated.
- Access logs must be protected against unauthorised alteration.
5.3 Data Protection and Encryption
- Portable devices, laptops, tablets, mobile telephones and removable media used to store or access personal data must use approved encryption. Full-disk or equivalent device encryption must be enabled where technically possible. Encryption keys and recovery keys must be managed securely and separately from the protected device.
- Personal data must be shared only where there is a lawful purpose, the recipient’s identity and address have been verified, and the minimum necessary information is used. Approved secure email, portal, encrypted attachment or secure file-transfer arrangements must be used according to the sensitivity and risk. Passwords for encrypted attachments must be communicated separately.
- Personal devices must not store, download, copy, photograph or process organisation information unless their use has been formally approved under the organisation’s bring-your-own-device arrangements. Approved personal devices must be enrolled in the organisation’s mobile device management system and must meet the same security, monitoring, access-control and deletion requirements as company-owned devices.
- Only cloud services that have been approved by {{org_field_name}} may be used. Approval must include appropriate due diligence concerning security, data location, international transfers, backup, availability, access controls, subcontractors, exit arrangements, breach notification and secure deletion. Workers must not upload organisation information to personal cloud storage or unapproved file-sharing services.
- Critical information and systems must be backed up in accordance with a documented backup and recovery schedule based on business need, risk and the organisation’s recovery objectives. Backups must be encrypted, protected from alteration or deletion by compromised user accounts, and segregated from the live environment where practicable. Restoration tests must be completed at planned intervals and the results recorded.
5.3.1 Data Protection by Design and Data Protection Impact Assessments
Data protection and information security must be considered from the earliest stage of any new project, system, device, monitoring arrangement or change in working practice.
A data protection impact assessment must be considered before introducing processing that is likely to result in a high risk to individuals. This includes, but is not limited to:
- systematic monitoring;
- tracking workers or individuals by GPS;
- electronic call-monitoring;
- extensive processing of health or safeguarding information;
- biometric access or identification;
- artificial intelligence or automated decision-making;
- body-worn cameras;
- audio or video monitoring;
- new care-record systems;
- large-scale data sharing; or
- technology used to monitor individuals in their homes.
The Data Protection Officer or Data Protection Lead must be consulted before high-risk processing begins.
5.4 Use of IT Equipment and Internet Security
- IT equipment should only be used for authorised business purposes—personal use is strictly limited.
- Supported malware-protection controls must be enabled and managed centrally where practicable. Workers must not disable, bypass or alter malware-protection, web-filtering or endpoint-detection controls.
- Host and network firewalls must be enabled, appropriately configured and reviewed. Unnecessary ports, services and applications must be disabled or removed.
- Workers must avoid accessing confidential systems through unsecured public Wi-Fi. Where remote access is necessary, workers must use an organisation-approved secure connection, such as an approved VPN or another centrally managed encrypted access method. Devices must not automatically connect to unknown wireless networks.
- Operating systems, browsers, applications, firmware and security software must be supported by the supplier and updated within timescales set by the organisation’s vulnerability-management process. Critical or actively exploited vulnerabilities must be prioritised. Unsupported systems or software must not be used unless a documented exception, risk assessment, compensating controls and replacement plan have been approved.
- Workers must not install software, browser extensions or mobile applications without authorisation.
- Macros and executable attachments from untrusted sources must not be enabled.
- Organisation systems must not be used to access unlawful, offensive or unsafe material.
- Suspicious links, attachments, login prompts and unexpected multi-factor authentication requests must be reported.
- Security controls must not be circumvented to improve convenience or speed.
- Unauthorised peer-to-peer file sharing and remote-access software are prohibited.
5.4.1 Artificial Intelligence, Transcription and Online Tools
Workers must not enter personal data, care records, health information, medication information, safeguarding information, commercially confidential information or login credentials into a public or unapproved artificial intelligence, transcription, translation or content-generation service.
Artificial intelligence tools may be used for organisational purposes only where:
- the tool has been formally approved;
- data protection and security risks have been assessed;
- appropriate contractual controls are in place;
- the information entered is limited to what is necessary;
- human review is completed;
- generated information is checked for accuracy, bias and relevance; and
- no decision affecting an individual is made solely on the basis of unreliable or unverified output.
AI-generated text must not be copied into a care record without review and confirmation by an authorised worker.
5.5 Remote Working and Mobile Device Security
- Remote access must use an organisation-approved secure access method and multi-factor authentication. Remote sessions must be protected against unauthorised viewing, recording or access by household members and other persons.
- Mobile devices used for work must be enrolled in an approved mobile device management system where technically possible. Security settings must include encryption, screen locking, device inventory, approved application controls and remote locking or wiping.
- Personal data must not be stored locally unless this is necessary, authorised and protected by approved encryption and access controls. Workers must use approved organisational systems rather than personal cloud storage or device applications. Where temporary local storage is authorised, the information must be deleted securely as soon as the operational need ends.
- Printing personal data while working remotely is prohibited unless specifically authorised. Where printing is authorised, the worker must prevent unauthorised access, store the document securely, transport it safely and return it for confidential destruction.
- Devices must not be shared with family members or other persons.
- Work calls must not be conducted through voice-activated home devices or smart speakers.
- Workers must ensure that video-call backgrounds do not reveal confidential information.
- Devices must not be left unlocked in a shared household area.
- Any change to a device’s telephone number, security status, ownership or operating system must be reported to the IT lead.
5.6 Secure Disposal, Return and Reuse of Equipment
IT equipment, storage media and mobile devices must be returned to the organisation or an approved supplier for secure wiping, reuse or destruction. Workers must not sell, donate, discard or personally retain organisation equipment.
Before equipment is reassigned, returned to a leasing company, recycled or disposed of, data must be securely erased using an approved method. Where secure erasure cannot be verified, the storage component must be physically destroyed by an approved contractor.
The organisation must retain a disposal record showing:
- the asset identifier;
- the device or media type;
- the date of disposal or reuse;
- the method of erasure or destruction;
- the person or contractor completing the action; and
- any certificate of destruction.
5.7 Third-Party Suppliers and Data Processors
Before a supplier is permitted to process personal data or access organisation systems, {{org_field_name}} must complete proportionate due diligence and ensure that an appropriate written contract is in place.
Contracts with data processors must address:
- the subject matter, duration, nature and purpose of processing;
- the types of personal data and categories of individuals;
- confidentiality;
- security measures;
- use of subcontractors;
- assistance with individual rights requests;
- breach notification without undue delay;
- assistance with data protection impact assessments;
- return or secure deletion of information at contract end;
- audit and assurance rights;
- business continuity and disaster recovery;
- data location and international transfers; and
- the supplier’s obligations when the service ends.
Supplier access must be time-limited, authorised, logged and removed when no longer required.
6. Incident Management and Reporting
6.1 Identifying and Reporting Security Incidents
Any actual or suspected cyber security incident, personal data breach, loss of equipment, phishing message, malware infection, unauthorised disclosure, inappropriate access, misdirected communication, alteration of a record or loss of system availability must be reported immediately.
Reports must be made to:
- Registered Manager: {{org_field_registered_manager_email}} / {{org_field_phone_no}}
- Out-of-hours contact: {{out_of_hours_contact}}
A worker must report an incident even where they believe that no harm has occurred, the information was retrieved, the message recipient has deleted it, or the device was encrypted.
Every suspected or confirmed incident must be recorded in the organisation’s incident or breach log. The record must include the facts, dates and times, systems and individuals affected, categories and approximate volume of information, immediate containment actions, risk assessment, notification decisions, communications, recovery actions, lessons learned and any corrective actions.
6.2 Incident Containment, Assessment, Notification and Recovery
The organisation will activate its incident-response arrangements following any suspected or confirmed security incident. Actions may include:
- isolating affected devices or accounts;
- disabling compromised credentials;
- preserving logs and other evidence;
- remotely locking or wiping a device;
- contacting an unintended recipient;
- restoring information from a verified backup;
- engaging an IT, cyber security or forensic specialist;
- assessing the effect on the safety, rights and wellbeing of individuals;
- implementing continuity arrangements to maintain safe care; and
- informing commissioners, insurers, law enforcement or other bodies where appropriate.
Workers must not delete relevant messages, reset affected devices, dispose of equipment or otherwise destroy evidence unless instructed by the incident-response lead.
6.3 Notification to the Information Commissioner’s Office
The Data Protection Officer or Data Protection Lead will assess every personal data breach to determine the likelihood and severity of risk to the rights and freedoms of affected individuals.
A personal data breach must be reported to the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after {{org_field_name}} becomes aware of it, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms.
Where notification is made more than 72 hours after awareness, the reason for delay must be documented and provided to the ICO.
The organisation must document all personal data breaches, including breaches that are not reported to the ICO, and record the reasons for the notification decision.
6.4 Communication with Affected Individuals
Where a personal data breach is likely to result in a high risk to an individual’s rights and freedoms, {{org_field_name}} will communicate the breach to the affected individual without undue delay, unless a lawful exception applies.
The communication will use clear and accessible language and will explain:
- the nature of the breach;
- the likely consequences;
- the action taken or proposed;
- steps the individual can take to protect themselves; and
- how to contact the Data Protection Officer or Data Protection Lead.
Communication needs, capacity, advocacy arrangements and the involvement of authorised representatives must be considered.
6.5 Care Inspectorate and Other Regulatory Notifications
A personal data breach is not automatically reportable to the Care Inspectorate solely because personal data is involved.
The Registered Manager must assess whether the incident:
- has affected or may affect the health, safety, dignity, wellbeing or rights of an individual receiving care;
- has disrupted the safe delivery of the service;
- has resulted in the loss or unavailability of care records, medication records, visit schedules or other essential information;
- forms part of another event that is notifiable under Care Inspectorate requirements;
- constitutes a significant accident, incident, allegation, safeguarding concern or service disruption; or
- must be reported under a condition of registration, contract or commissioner requirement.
Where notification is required, it must be submitted through the appropriate Care Inspectorate process within the applicable timescale. The reason for notifying or not notifying must be recorded.
The organisation will also consider whether notification is required to the police, NHS Scotland, a health and social care partnership, local authority, commissioner, SSSC, professional regulator, insurer, National Cyber Security Centre or another relevant body.
6.6 Continuity of Care During System Failure
{{org_field_name}} must maintain tested arrangements for continuing safe care when electronic systems, mobile devices, internet connections, telephone systems or cloud services are unavailable.
Continuity arrangements must cover:
- access to essential care and support information;
- medication and allergy information;
- visit schedules and staff deployment;
- emergency contacts;
- communication with workers and individuals;
- recording care delivered during downtime;
- reconciliation of paper and electronic records after restoration;
- escalation where care cannot be delivered safely; and
- notification of individuals, representatives and commissioners where disruption affects the service.
Emergency information must be protected, accurate, current and accessible only to authorised personnel.
7. Training and Compliance
All workers must complete data protection, confidentiality and cyber security training during induction and before being given unsupervised access to personal data or operational systems.
Refresher training must be completed at least annually and whenever there is a significant change in legislation, systems, threats or organisational procedures.
Role-specific training must be provided to managers, system administrators, staff handling personal data breaches and workers who use high-risk systems.
Training must include:
- confidentiality and special category personal data;
- secure use of electronic care records;
- phishing, social engineering and fraudulent requests;
- passwords and multi-factor authentication;
- secure email and information sharing;
- mobile and remote working;
- reporting lost devices and breaches;
- ransomware and malware;
- safe use of cloud and artificial intelligence tools;
- use of technology in individuals’ homes; and
- continuity procedures during system failure.
The organisation must maintain training records and follow up overdue or unsuccessful completion.
Periodic awareness exercises, such as simulated phishing or scenario-based breach exercises, may be undertaken proportionately. Exercises must be used for learning and improvement and must not create an inappropriate blame culture.
Failure to comply with this policy may result in restriction or removal of system access, retraining, supervision, investigation or disciplinary action. Serious concerns may require referral to the SSSC or another professional regulator.
8. Record-Keeping and Compliance Monitoring
Security logs, access records, asset records, incident records, breach records, audit evidence and disposal records must be retained in accordance with the organisation’s approved retention schedule. Retention periods must be based on legal, regulatory, contractual, safeguarding, insurance, operational and evidential requirements. Records must not be retained indefinitely without a documented purpose.
Records subject to an active complaint, investigation, litigation hold, safeguarding process, regulatory enquiry or insurance claim must not be destroyed until authorised by the appropriate responsible person.
At the end of the retention period, records must be securely deleted or destroyed and the action documented where appropriate.
The organisation will complete proportionate information-security and data-protection monitoring at planned intervals. Higher-risk controls, accounts and systems may require more frequent review. Monitoring will include, where relevant:
- access rights and privileged accounts;
- inactive and leaver accounts;
- patching and supported software;
- encryption and device compliance;
- malware and endpoint alerts;
- backup success and restoration testing;
- supplier assurance;
- breach and incident trends;
- training completion;
- equipment inventories;
- unauthorised applications; and
- corrective actions from previous audits.
Audit and monitoring findings must be documented, risk rated, assigned to a named person and given a target completion date. Senior management must monitor overdue or high-risk actions and verify that corrective action has been effective. The organisation must maintain an accurate inventory of devices, software, information assets, system owners and approved cloud services.
8.1 Monitoring and Audit of System Use
{{org_field_name}} may monitor the use of its systems, devices and networks for security, operational, audit, regulatory and investigation purposes. Monitoring must be lawful, necessary, proportionate and transparent.
Workers must be informed about:
- the nature and purpose of monitoring;
- the systems and information that may be monitored;
- who may access monitoring information;
- how long monitoring records are retained; and
- the circumstances in which records may be disclosed.
Covert monitoring will only be considered in exceptional circumstances, following senior authorisation and appropriate legal and data protection advice.
9. Related Policies
- Data Protection and GDPR Compliance Policy
- Remote Working Policy
- Acceptable Use of IT Policy
- Incident Reporting and Management Policy
- Information Governance Policy.
- Data Protection Policy.
- Personal Data Breach Response Procedure.
- Records Management and Retention Policy.
- Confidentiality Policy.
- Electronic Care Records Policy.
- Mobile Device and Bring Your Own Device Policy.
- Password and Access Control Standard.
- Business Continuity and Disaster Recovery Plan.
- Cyber Incident Response Plan.
- Data Sharing Policy.
- Photography, Audio and Video Recording Policy.
- Artificial Intelligence Acceptable Use Policy.
- Home and Remote Working Policy.
- Staff Disciplinary Policy.
- Whistleblowing Policy.
- Adult Support and Protection Policy.
- Complaints Policy.
- Significant Event and Care Inspectorate Notification Procedure.
- Supplier and Contract Management Policy.
10. Exceptions and Non-Compliance
Any exception to this policy must be documented, risk assessed, time limited and authorised by the appropriate senior manager, Data Protection Officer or Data Protection Lead and IT security lead.
The exception record must state:
- the control that cannot be met;
- the reason;
- the information and systems affected;
- the risks created;
- the compensating controls;
- the person responsible;
- the expiry date; and
- the planned corrective action.
Workers must not create informal exceptions or bypass security controls without authorisation.
11. Equality, Accessibility and Human Rights
Security arrangements must respect the dignity, privacy, autonomy, communication needs and human rights of individuals receiving care. Security measures must not create unnecessary barriers to communication, participation or access to information.
Information about the use of electronic records, digital systems or monitoring technology must be provided in a format and language that the individual can understand. Reasonable adjustments, communication aids, interpreters, advocacy or representative involvement must be considered where appropriate.
Where an individual lacks capacity in relation to a particular decision, the organisation must act within the applicable legal framework and record the authority and decision-making process relied upon.
12. Policy Review
This policy will be formally reviewed at least annually and sooner where:
- legislation, regulatory guidance or Care Inspectorate expectations change;
- a significant cyber security incident or personal data breach occurs;
- an audit identifies a material weakness;
- a new system, device, supplier or working arrangement is introduced;
- the organisation changes its services or processing activities;
- Cyber Essentials or another certification requirement changes; or
- lessons from complaints, incidents, inspections or staff feedback indicate that amendment is required.
Material changes will be communicated to workers and incorporated into training, supervision and operational procedures.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.