{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


Computer Systems and Security Policy

1. Purpose

The purpose of this policy is to ensure that all computer systems, digital devices, and electronic records used at {{org_field_name}} are secure, legally compliant, and used in a way that protects the confidentiality, integrity, and availability of information. The policy outlines the systems and processes in place to prevent unauthorised access, protect sensitive personal data, and ensure business continuity. It is in full compliance with the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, and CIW requirements under the Regulation and Inspection of Social Care (Wales) Act 2016. As the care home routinely stores, accesses, and processes personal and medical data via computer systems, the need for strong digital security and data governance is critical. This policy explains how the organisation mitigates digital risks and trains its staff to operate responsibly and securely.

2. Scope

This policy applies to all staff at {{org_field_name}} who use digital devices or computer systems, including full-time and part-time employees, agency workers, volunteers, contractors, and external professionals accessing care records. It covers all computers, tablets, laptops, smartphones, cloud platforms, servers, email systems, Wi-Fi, USB devices, and any software or systems used to manage care, HR, or business operations.

3. Related Policies

This policy should be read in conjunction with:
CHW34 – Confidentiality and Data Protection (GDPR) Policy
CHW13 – Safeguarding Adults from Abuse and Improper Treatment Policy
CHW04 – Good Governance
CHW29 – Whistleblowing (Speaking Up) Policy
CHW14 – Receiving and Acting on Complaints Policy
CHW27 – Staff Supervision, Training, and Development Policy

4. Policy Details

4.1 System Access and User Controls

Access to computer systems is strictly controlled through individual user accounts and password protection. Each user is assigned a unique login, with permissions based on their job role. Only authorised users may access confidential records. Passwords must be changed every 90 days and must not be shared. Shared devices (e.g., nurses’ stations) must be locked when unattended. Staff must log out of systems at the end of their shift. Admin-level access is limited to the Registered Manager, designated IT support, and key personnel authorised by {{org_field_name}}’s leadership team.

4.2 Data Protection and Confidentiality

All personal data and special category personal data processed electronically by {{org_field_name}} must be handled in accordance with applicable data protection legislation, including the UK General Data Protection Regulation and the Data Protection Act 2018, as amended. Appropriate technical and organisational measures must be implemented to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, alteration, disclosure or damage.

Electronic records containing personal or confidential information must be stored securely and access must be restricted to authorised persons according to their role and legitimate need to access the information. Access permissions must be reviewed and amended when staff change role, leave the organisation or no longer require access.

Where encryption is appropriate to the risks associated with the information being processed, personal data must be encrypted when stored or transmitted. Personal or confidential information must not be stored on personally owned devices, personal email accounts, unauthorised cloud-storage services or unencrypted removable media.

Information relating to individuals receiving care and support must be accurate and kept up to date. Staff must enter information into electronic records promptly, accurately and in accordance with the organisation’s record-keeping requirements. Records must not be altered, deleted or destroyed except in accordance with authorised record-management and retention procedures.

Personal information must only be accessed, used or disclosed where there is a lawful and legitimate reason for doing so. Access must be limited to the minimum information necessary for the person’s role and responsibilities. Where personal information is transferred to another organisation or professional, an approved secure method appropriate to the sensitivity of the information must be used.

Individuals receiving the service must be able to access records held about them in accordance with applicable legal requirements and must be made aware that they can request access to their records. Requests for access to personal information must be dealt with in accordance with the organisation’s data protection procedures.

Records must also be made available to Care Inspectorate Wales when requested in accordance with the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended.

The Data Protection Officer, {{org_field_data_protection_officer_first_name}} {{org_field_data_protection_officer_last_name}}, is responsible for overseeing the organisation’s data protection arrangements, providing advice where required and supporting the investigation and management of suspected or confirmed personal data breaches.

4.3 System Security and Cyber Protection

All computers and devices are protected with up-to-date antivirus software, firewalls, and security patches. Operating systems and software are regularly updated. External devices such as USB sticks are scanned before use, and the use of personal USB drives is discouraged unless authorised. Systems are backed up regularly using secure cloud-based or encrypted on-site storage to ensure recovery in the event of data loss or cyberattack. Regular penetration testing and vulnerability scans are carried out by our IT provider. The organisation maintains a cybersecurity plan which includes response protocols for malware, phishing, ransomware, or unauthorised access attempts.

4.4 Internet and Email Usage

Staff are expected to use the internet and email systems responsibly. Work devices are for business purposes only. Staff must not use care home systems to access inappropriate, harmful, or unauthorised websites. Email communications containing sensitive information must be encrypted or use secure mail services. Attachments should be password-protected where appropriate. Staff must not open suspicious emails, links, or attachments from unknown sources. Any suspected phishing attempts or email scams must be reported immediately to management.

4.5 Use of Personal Devices (Bring Your Own Device – BYOD)

Staff are not permitted to use personal laptops or smartphones to access care home systems or confidential information unless this has been explicitly authorised by the Registered Manager. Any use of personal devices for work-related communication must comply with our data protection and security standards. Use of apps such as WhatsApp or personal email accounts for discussing care information is strictly prohibited. All communications regarding residents or sensitive matters must occur through approved platforms.

4.6 Staff Training and Responsibilities

All staff receive mandatory training on data protection, information governance, and cyber safety as part of their induction and through annual refreshers. Training covers the safe use of passwords, identifying suspicious emails, secure storage of devices, and responsible use of digital systems. Staff are required to read and sign a digital code of conduct that outlines acceptable use of devices and the consequences of breach. The Registered Manager ensures that staff who use care records systems, electronic MAR charts, or digital reporting tools are trained and monitored for competence.

4.7 Monitoring, Audits, and Compliance

{{org_field_name}} maintains systems for monitoring and auditing the security, integrity and appropriate use of its computer systems and electronic records. Monitoring and audit arrangements must be proportionate, necessary for a legitimate organisational purpose and undertaken in accordance with applicable data protection and privacy requirements.

Where staff or other system users are subject to monitoring, they must be provided with appropriate information about the nature and purpose of that monitoring through the organisation’s relevant policies, privacy information or other appropriate communication.

System access and activity logs must be reviewed as appropriate to identify unauthorised access, inappropriate use, security incidents or other anomalies. Access permissions must also be reviewed to ensure that system permissions remain consistent with each person’s authorised duties and responsibilities.

Audits must include, where relevant:

Any identified concern or anomaly must be assessed and investigated promptly. Appropriate corrective action must be taken and recorded.

Where misuse of digital systems, unauthorised access to information or other misconduct is identified, the matter may be dealt with under CHW31 – Disciplinary and Grievance Policy and, where applicable, safeguarding, professional-regulatory or statutory reporting procedures.

Personal data breaches must be documented and managed in accordance with section 4.8 of this policy, including breaches which do not meet the threshold for external notification.

4.8 Responding to Incidents and Breaches

All suspected or confirmed information-security incidents, cyber incidents and personal data breaches must be reported immediately to the Registered Manager and/or Data Protection Officer so that prompt action can be taken to protect individuals, contain the incident and comply with applicable statutory reporting requirements.

Immediate action will be proportionate to the nature of the incident and may include:

Every personal data breach must be documented, whether or not it is reported externally. The breach record must contain sufficient information to establish the facts relating to the breach, its effects, the assessment of risk to affected individuals and the remedial action taken or proposed. Where a decision is made not to report a breach to the Information Commissioner’s Office, the reasons for that decision must also be documented.

Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} must notify the Information Commissioner’s Office without undue delay and, where feasible, not later than 72 hours after becoming aware of the breach. Where notification is made after the 72-hour period, the reason for the delay must be recorded and provided as required.

Where a personal data breach is likely to result in a high risk to the rights and freedoms of an affected individual, {{org_field_name}} must communicate the breach to that individual without undue delay, unless an applicable legal exception applies. The communication must be clear and provide appropriate information about the nature of the breach, its likely consequences, the action taken or proposed and an appropriate contact point for further information.

Notification to Care Inspectorate Wales is considered separately from notification to the Information Commissioner’s Office. The service provider must notify Care Inspectorate Wales where an incident constitutes a notifiable event under Regulation 60 and Schedule 3 of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended. This includes any event which prevents, or could prevent, the provider from continuing to provide the service safely.

Unless the Regulations specify otherwise, a required notification to Care Inspectorate Wales must be made without delay, in writing, and in the manner and form required by Care Inspectorate Wales. The notification must include details of the event.

Where an information-security or cyber incident gives rise to another separately notifiable event under Schedule 3, such as a serious accident or injury, an incident reported to the police, an allegation of abuse or another event specified in the Regulations, the applicable notification requirements must also be followed.

Where an incident creates an immediate risk to an individual’s safety or well-being, protection of the individual and continuity of safe care take priority and appropriate safeguarding, emergency-service, healthcare or other statutory referrals must be made without delay.

Following an incident, the Registered Manager and Data Protection Officer must ensure that the incident is reviewed, that lessons are identified and that reasonable corrective measures are implemented to reduce the likelihood or impact of recurrence. Relevant policies, risk assessments, staff training, system controls and business-continuity arrangements must be updated where required.

Staff must report information-security concerns, suspected breaches, cyber incidents and mistakes immediately. Staff raising a genuine concern in good faith must be supported to report the matter promptly so that appropriate protective action can be taken.

4.9 Business Continuity and Disaster Recovery

{{org_field_name}} maintains business-continuity and disaster-recovery arrangements to ensure that safe care and support can continue where computer systems, electronic care-record systems, internet services, electricity supplies or other essential digital services become unavailable.

Electronic information required for the safe provision of care must be backed up using secure arrangements appropriate to the nature and sensitivity of the information. Backup arrangements must protect information against unauthorised access, loss, corruption or destruction and must enable information required for continuity of care to be recovered within an appropriate period.

Recovery arrangements must be tested periodically to provide assurance that information can be restored and that critical systems can be recovered following an outage, equipment failure, data loss or cyber incident.

Where electronic systems are unavailable, approved contingency arrangements must be implemented. These must include access to sufficient current information to enable staff to continue providing safe care and support, including, where applicable:

Where paper contingency records are used during an outage, staff must record care and relevant events contemporaneously. Once electronic systems are restored, information generated during the outage must be securely incorporated into the appropriate permanent record, with appropriate checks to prevent loss, duplication or inaccurate transcription.

Confidentiality and information-security requirements continue to apply during system outages and emergency situations. Temporary paper records, exported electronic information and other contingency information must therefore be stored, accessed, transported and disposed of securely.

Where an outage, cyber incident or systems failure prevents, or could prevent, {{org_field_name}} from continuing to provide the service safely, the Registered Manager must ensure that the incident is assessed against the notification requirements in Regulation 60 and Schedule 3 of the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, and that Care Inspectorate Wales is notified where required.

Business-continuity and disaster-recovery arrangements must be reviewed following significant incidents, tests, changes to information systems or identified weaknesses.

4.10 Electronic Records: Retention, Access and Service Closure

{{org_field_name}} must keep and maintain all records required under the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, including the records specified in Schedule 2 where applicable to the service.

All electronic records relating to individuals must be accurate, kept up to date and maintained securely. Appropriate safeguards must be used to prevent unauthorised access, alteration, accidental loss, destruction or inappropriate disclosure.

Records must be capable of being retrieved and made available to Care Inspectorate Wales on request.

Individuals receiving the service must:

Records relating to adults receiving the service must be retained for three years from the date of the last entry, unless another applicable legal requirement requires a longer retention period.

Where the service provides care home accommodation to children, records relating to children must be retained for 15 years from the date of the last entry, unless the records are returned to the placing authority in accordance with the Regulations.

Where a care home service provided wholly or mainly for children ceases to provide the service to a child, records must be delivered to the placing authority where required by the Regulations.

Electronic records must not be deleted or destroyed before the applicable statutory retention period has expired. At the end of the relevant retention period, records must be securely disposed of in accordance with applicable data protection requirements and the organisation’s authorised records-management procedures.

If {{org_field_name}} ceases to provide the regulated service or the service closes, arrangements must be made to ensure that all records which remain subject to a statutory retention requirement continue to be kept securely, remain retrievable and are protected from unauthorised access, loss, destruction or disclosure for the remainder of the applicable retention period.

Backup arrangements do not replace the statutory record-retention requirements. Where an electronic system is changed, replaced, migrated or decommissioned, {{org_field_name}} must ensure that records which remain within their required retention period continue to be accessible, complete, accurate and secure.

Access to archived records must remain restricted to authorised persons and must be managed in accordance with applicable confidentiality and data protection requirements.

5. Policy Review

This policy will be reviewed at least annually and sooner where necessary following:

The Registered Manager and Data Protection Officer will ensure that amendments arising from a review are implemented, communicated to relevant staff and reflected in associated procedures and training where required.

This policy forms part of {{org_field_name}}’s governance, information-security, safeguarding, record-management and risk-management arrangements.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *