{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Mobile Devices (Phones and Tablets) Policy
1. Introduction
At {{org_field_name}}, mobile devices such as smartphones and tablets play an essential role in delivering high-quality domiciliary care services. They facilitate communication, enable real-time record-keeping, and support staff in accessing essential information while working remotely. However, the use of mobile devices also introduces risks related to data security, misuse, and distractions.
This Mobile Devices Policy sets out the requirements for the lawful, secure, safe and professional use of mobile phones, tablets and other portable devices in connection with the provision of domiciliary care. It applies to organisation-issued devices and, where expressly approved, personally owned devices used to access organisational systems or information.
This policy supports compliance with the UK General Data Protection Regulation, the Data Protection Act 2018, the Health and Social Care Act 2008, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, the Human Rights Act 1998, the Equality Act 2010, the Mental Capacity Act 2005 and applicable road traffic legislation. It also supports compliance with CQC Fundamental Standards, including Regulation 9, Regulation 10, Regulation 11, Regulation 12, Regulation 17 and Regulation 18.
Mobile devices must be used in a manner that protects the privacy, dignity, safety and rights of people receiving care. The convenience of mobile working must never take priority over safe care, meaningful interaction, accurate record-keeping, confidentiality or the wishes of the person receiving care.
2. Purpose and Scope
The purpose of this policy is to:
- Ensure mobile devices are used responsibly and securely in the provision of domiciliary care.
- Protect confidential service user information stored or accessed on mobile devices.
- Promote professionalism and prevent misuse of mobile devices during working hours.
- Clarify expectations for both company-owned and personal mobile devices used for work purposes.
- Ensure compliance with the UK GDPR, the Data Protection Act 2018, confidentiality requirements, CQC record-keeping expectations and the organisation’s information-governance arrangements.
- Ensure that digital care records are accurate, complete, legible, attributable, contemporaneous and available to authorised staff when needed.
- Ensure mobile-device use does not compromise the privacy, dignity, consent, safety or wellbeing of people receiving care.
- Define the conditions under which photographs, audio recordings, video recordings, location information and other digital content may be created or used.
- Establish arrangements for device loss, system failure, loss of connectivity, cyber incidents and other business-continuity events.
- Provide auditable evidence that access to care information is authorised, proportionate and regularly reviewed.
This policy applies to all employees, including full-time, part-time, and temporary staff, as well as contractors and volunteers who use mobile devices for work-related tasks. It covers organisation-issued devices and personally owned devices that have been formally approved for work use under this policy and any separate Bring Your Own Device arrangements.
Staff must not use an unapproved device, account, application, cloud-storage service, email address, messaging platform, removable storage device or artificial-intelligence tool to create, receive, view, transmit or store information relating to a person receiving care.
3. Principles of Mobile Device Use
Our approach to mobile device management is based on the following principles:
- Professionalism and person-centred care: Mobile devices must be used only when necessary for an authorised work purpose. Staff must explain their use of a device where appropriate and must not allow device use to reduce meaningful interaction, compromise dignity or make a person feel ignored, unsafe or uncomfortable.
- Security and resilience: Devices and systems must be protected by proportionate technical and organisational measures, including encryption, secure authentication, automatic locking, supported software, restricted access and, where available and appropriate, multi-factor authentication. Security arrangements must reflect the sensitivity of health and social care information and the risks presented by mobile working.
- Confidentiality and data minimisation: Personal and special category information must only be accessed by authorised persons for a legitimate work purpose. Staff must access only the minimum information necessary for their role. Information relating to people receiving care must not be stored in personal contacts, personal calendars, personal notes, personal photo galleries, personal email accounts, personal cloud backups or unapproved applications.
- Minimal Disruption: Mobile devices must not interfere with care delivery or service user well-being.
- Accountability: Employees are responsible for the security, maintenance, and appropriate use of their devices.
- Accuracy and accountability: Every entry made through a mobile device must identify the person making it and the date and time of the entry. Records must be completed as soon as reasonably practicable after care is provided and must not be falsified, backdated or inappropriately altered.
- Privacy by design: Mobile systems and applications must be configured to prevent unnecessary collection, display, storage or sharing of personal information.
- Availability: Care information required for safe care must remain accessible to authorised staff, including during reasonable periods of system or connectivity disruption.
- Transparency: Staff and people receiving care must be given appropriate information about how mobile technology, monitoring, location services, photographs or recordings are used.
4. Responsibilities and Expectations
4.1 Registered Manager
- Oversees the implementation and monitoring of this policy.
- Ensures staff receive training on safe and responsible mobile device use.
- Investigates any breaches and takes appropriate action.
- Ensures that mobile-device arrangements are consistent with the organisation’s CQC registration, statement of purpose, data protection responsibilities and information-security controls.
- Ensures that risks arising from mobile working are assessed, documented and reviewed.
- Ensures that staff access is based on role and is promptly amended or withdrawn when duties change or employment ends.
- Ensures that mobile-device audits include record quality, access logs, failed log-in attempts, inactive accounts, unsupported software, unauthorised applications and compliance with this policy.
- Ensures that lessons from incidents, complaints, audits and service user feedback are used to improve practice.
- Ensures that suitable contingency arrangements exist where a device, application, network or care-management system is unavailable.
- Ensures that suspected criminal conduct, safeguarding concerns, serious incidents and notifiable events are escalated under the appropriate organisational procedure.
4.2 Line Managers and Supervisors
- Monitor staff adherence to the policy and address any concerns.
- Ensure mobile device use does not interfere with care delivery.
- Review staff compliance during supervision, observation and spot checks.
- Check that mobile care records are accurate, complete, person-centred and entered promptly.
- Challenge excessive, unexplained or inappropriate device use during care visits.
- Escalate repeated late entries, copied entries, identical entries, unexplained amendments or unusual access patterns.
- Ensure staff know how to work safely during system downtime and how to enter records retrospectively without disguising the actual time of entry.
4.3 Employees
- Use mobile devices responsibly, professionally, and in line with this policy.
- Protect devices with passwords, encryption, and security updates.
- Report any lost, stolen, or compromised devices immediately.
- Use only their own unique user account and must never share a password, passcode, security token or authentication method.
- Check that information is being recorded against the correct person before entering or uploading information.
- Record care accurately and promptly and clearly identify any late entry, correction or retrospective entry.
- Prevent family members, friends or any other unauthorised person from viewing or using a device used for work.
- Ensure notifications do not display confidential information on a locked screen.
- Avoid discussing confidential information where conversations may be overheard.
- Report misdirected messages, incorrect care-record entries, suspicious emails, phishing attempts, malware, unusual device behaviour and unauthorised access immediately.
- Stop using a device and seek management advice where its use may compromise safe care, privacy, dignity or consent.
4.4 IT Department (if applicable)
- Manage device setup, security software, and remote wiping capabilities.
- Monitor company-owned devices for compliance with this policy.
- Maintain an up-to-date inventory of organisation-issued devices and approved personal devices.
- Apply security updates, encryption, access restrictions and remote-locking or remote-wiping controls where proportionate.
- Remove access immediately when authorised by management following termination, suspension, role change, device loss or suspected compromise.
- Ensure that devices use supported operating systems and block devices that are rooted, jailbroken or otherwise security-compromised.
- Configure systems so that organisational data is separated from personal information wherever personal devices are permitted.
- Retain appropriate system and access logs in accordance with the organisation’s retention schedule.
- Test backup, recovery, remote-locking and business-continuity arrangements periodically.
5. Use of Company-Owned Mobile Devices
5.1 Device Issuance
- Employees may be issued company-owned mobile devices (phones or tablets) for work-related tasks, such as accessing care plans, recording notes, and communicating with colleagues.
- Devices will be pre-configured with security settings, encryption, and approved applications.
- Each device must be recorded in the organisation’s asset register and allocated to a named member of staff or designated team.
- Staff must sign a device-issue record confirming receipt, condition, permitted use and responsibility for prompt return.
- Devices must be configured to prevent unauthorised installation of applications and unauthorised connection to personal cloud-storage or backup services.
- Confidential information must not be copied into personal contacts, personal calendars or personal applications.
5.2 Acceptable Use
- Organisation-issued devices must be used primarily for authorised work purposes. Any limited personal use expressly permitted by the organisation must be reasonable, lawful, infrequent, must not incur avoidable cost and must not compromise care, security, confidentiality or professional conduct.
- Personal use of company devices is prohibited except in emergencies.
- Devices must not be used for social media, gaming, or non-work-related browsing during working hours.
- Devices must not be used to access, create, transmit or retain offensive, discriminatory, unlawful, sexually explicit or otherwise inappropriate material.
- Devices must not be used to post information, comments, images or recordings concerning the organisation, colleagues or people receiving care on social media.
- Staff must not connect devices to unknown computers, unapproved accessories or untrusted public charging points.
- Confidential work must not be carried out over unsecured public Wi-Fi unless an organisation-approved secure connection is in use.
5.3 Security Measures
- Devices must be protected by an organisation-approved passcode or password and must automatically lock after a period of inactivity determined by the organisation’s documented security risk assessment. Biometric authentication may be used only where approved and must not replace the requirement for an appropriate device passcode. Authentication settings must not be disabled or bypassed.
- Anti-virus software, mobile device management (MDM), and encryption must be installed and regularly updated.
- All devices must be set to receive automatic software and security updates.
- Multi-factor authentication must be enabled for remote access to care systems, email and other systems containing confidential information where the system supports it.
- Lock-screen notifications must be configured so that personal or confidential information is not visible without authentication.
- Passwords and passcodes must not be written on the device, stored with the device or shared with another person.
- Devices must not be rooted, jailbroken or modified to bypass manufacturer or organisational security controls.
- Bluetooth, personal hotspot, file-sharing and location functions must be disabled when not required for an authorised work purpose.
- Staff must not allow browsers or applications to save passwords unless an organisation-approved password-management system is used.
5.4 Monitoring and Auditing
Organisation-issued devices and work accounts may be monitored and audited where this is necessary and proportionate for information security, safeguarding, quality assurance, fraud prevention, regulatory compliance, device management or investigation of a specific concern.
Before monitoring is introduced, the organisation will:
- identify and document the purpose of the monitoring;
- establish an appropriate lawful basis;
- assess whether the monitoring is necessary and proportionate;
- consider less intrusive alternatives;
- complete a data protection impact assessment where the monitoring is likely to result in a high risk to individuals;
- provide staff with clear privacy information explaining what will be monitored, why, by whom, for how long and how the information may be used; and
- restrict access to monitoring information to authorised persons.
Monitoring must not be continuous, excessive or used for an unrelated purpose. The organisation will not routinely access the private content of communications or personal information unless access is lawful, necessary, proportionate and authorised.
5.5 Return of Devices:
- Company-issued devices must be returned upon resignation, termination, or role change.
- Before reissue, disposal, repair or return to a supplier, the device must be securely wiped using an approved method. The organisation must verify that work accounts, authentication tokens, cached information, downloaded files and access permissions have been removed. Where information must be retained, it must first be transferred to an approved system in accordance with the Records Management Policy.
6. Use of Personal Devices (Bring Your Own Device – BYOD)
Personally owned devices must not be used for work unless their use has been expressly authorised in writing by the organisation. Approval may be refused or withdrawn where the organisation considers that the device, operating system, proposed use or security arrangements present an unacceptable risk.
Approval to use a personal device does not permit the local storage of care records, photographs, recordings, messages or other confidential information unless a specific exception has been authorised following a documented risk assessment and appropriate technical controls.
6.1 Registration and Approval
- Personal devices used for work must be registered with the company under the BYOD Policy.
- Before approval, the organisation must confirm that the device meets its minimum security standard. This may include use of a managed work profile, mobile application management or mobile device management. Wherever practicable, organisational information must be contained within a separate encrypted work environment that can be remotely locked or wiped without affecting the employee’s personal information.
6.2 BYOD Agreement
Before using a personal device for work, the employee must sign a BYOD agreement setting out:
- the permitted work applications and activities;
- the organisation’s minimum security requirements;
- the information the organisation can monitor;
- the circumstances in which the work profile may be locked or wiped;
- the employee’s responsibility for backing up personal information;
- arrangements for investigation, repair, loss, theft, employment termination and withdrawal of consent;
- any limitations on technical support or reimbursement; and
- the consequences of non-compliance.
Refusal to permit use of a personal device for work must not, by itself, result in disadvantage where mobile access is required for the employee’s role. The organisation must provide an appropriate alternative method of access.
6.3 Security Requirements
- Personal devices approved for work must use a supported operating system, an approved passcode or password, device encryption where available, automatic locking and current security updates. Security software must be installed where appropriate to the operating system and identified risks.
- Automatic updates must be enabled to ensure the latest security patches.
- Devices must be set to auto-lock after 2 minutes of inactivity.
- The device must not be rooted, jailbroken or shared with another person while organisational systems remain accessible.
- Multi-factor authentication must be used where available.
- Work information must not appear in personal backups, personal cloud storage, personal photo galleries, personal contacts or personal messaging histories.
- The employee must notify the organisation before selling, exchanging, disposing of, repairing or lending the device.
- The employee must remove work access when instructed and must permit the organisation to verify that organisational information has been removed.
6.4 Data Storage and Access
Personal and confidential information relating to people receiving care must not be intentionally stored in the personal area of a privately owned device. Access must be through an organisation-approved application, secure browser or managed work profile that prevents or restricts local downloading, copying, screen capture, printing, forwarding and personal cloud backup wherever technically possible.
Where an approved application temporarily caches information for operational reasons, the information must be encrypted, automatically removed when no longer required and capable of being remotely deleted.
Personally owned devices must not be used to photograph, film or make an audio recording of a person receiving care, their home, their documents, their medication or their property.
Where a photograph or recording is necessary for care, treatment, safeguarding, incident investigation or another legitimate purpose, only an organisation-issued device and approved application may be used. The use must be authorised, necessary and proportionate, and must comply with Section 7A of this policy.
6.5 Monitoring, Managed Work Profiles and Remote Wiping
The organisation will not routinely monitor the personal content of a privately owned device. Monitoring will be limited to information necessary to protect organisational systems and confirm compliance, such as the device model, operating-system version, security status, presence of required work applications, work-account activity and attempted unauthorised access.
Where technically possible, remote locking or wiping will be limited to the managed work profile or organisational application data.
A full-device wipe may be used only in exceptional circumstances where:
- it is technically impossible to remove only organisational data;
- there is a serious and immediate risk to confidential information;
- the action is authorised by the Registered Manager and information-governance lead;
- the action is consistent with the signed BYOD agreement and staff privacy information; and
- the decision and reasons are documented.
The organisation will take reasonable steps to warn the employee before a full-device wipe unless delay would materially increase the risk.
6.6 Costs and Reimbursement
- Employees are responsible for the cost of personal devices, including repairs and maintenance.
- Reasonable work-related expenses, such as mobile data usage, may be reimbursed with prior approval.
7. Data Protection and Confidentiality
7.1 Lawful Processing
The organisation must identify and document an appropriate lawful basis under Article 6 of the UK GDPR for each use of personal information and an additional condition under Article 9 where health information or other special category information is processed.
Staff consent will not ordinarily be relied upon as the lawful basis for routine employment monitoring because of the imbalance of power within the employment relationship. Consent from a person receiving care must not be treated as valid unless it is freely given, specific, informed and capable of being withdrawn.
Mobile devices must be used only for purposes that are compatible with the purpose for which the information was obtained. Information must be adequate, relevant and limited to what is necessary.
7.2 Access to Confidential Information
- Access must be provided according to job role, current duties and the minimum information required.
- Each user must have an individual account. Shared accounts are prohibited unless a documented exceptional arrangement has been approved and provides equivalent accountability.
- Staff must not access their own care records, the records of relatives, friends, colleagues or any other person unless access is required for their authorised duties.
- Access permissions must be reviewed periodically and immediately following a role change, suspension, extended absence or termination of employment.
- Staff must lock the device or sign out whenever it is left unattended.
- Care applications must not remain open where information may be seen by an unauthorised person.
- Where a person receiving care asks to see what is being recorded, staff must respond openly and follow the organisation’s procedure for access to records.
7.3 Data Storage and Transfer
- Service user information must not be stored locally on mobile devices.
- Information must be transferred only through organisation-approved systems that provide security appropriate to the sensitivity of the information. Staff must verify the intended recipient before sending information and must use secure email, an approved care application, an approved portal, encrypted transfer or an approved virtual private network where required by the organisation.
- Personal messaging, social-media and consumer file-sharing applications must not be used to communicate information about people receiving care. An application may be used only where it has been formally approved following an information-security, confidentiality, data-protection, records-management and supplier assessment.
- Authorisation must apply to a specified organisational account or managed application. Informal permission from a manager does not make the use of a personal account acceptable.
- Staff must not use personal email accounts for work.
- Staff must not copy and paste confidential information into unapproved translation, transcription, generative artificial-intelligence or productivity tools.
- Confidential information must not be transferred through ordinary SMS unless a documented exceptional arrangement has been authorised and the information disclosed is limited to the minimum necessary.
- Screen captures, screen recordings and copying of care-record information are prohibited unless technically required and specifically authorised.
- Printed information produced from a mobile system must be protected and securely destroyed when no longer required.
7.4 Personal Data Breach Reporting
Any suspected or confirmed loss, unauthorised disclosure, unauthorised access, alteration, destruction or unavailability of personal information must be reported immediately through the organisation’s incident-reporting procedure. Staff must not delay reporting while attempting to investigate or resolve the matter themselves.
The Registered Manager and information-governance lead will ensure that the incident is contained, investigated, risk-assessed, documented and reviewed.
Where the personal data breach is likely to result in a risk to the rights and freedoms of individuals, the organisation must notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where the breach is likely to result in a high risk to an affected individual’s rights and freedoms, the organisation must also inform the affected individual without undue delay, unless a relevant legal exception applies.
All personal data breaches must be recorded, including those that do not meet the threshold for reporting to the Information Commissioner’s Office. The record must include the facts, effects, risk assessment, decisions, remedial action and lessons learned.
8. Photography, Audio, Video and Digital Recording
Photographs, video recordings and audio recordings must not be created merely for convenience. Before any recording is made, the organisation must establish:
- the specific purpose;
- whether the recording is necessary and proportionate;
- the lawful basis and, where applicable, special category condition;
- whether valid consent is required;
- whether the person has capacity to make the relevant decision;
- whether the recording may capture another person;
- how the recording will be stored, accessed, shared and deleted;
- how long it will be retained; and
- whether a data protection impact assessment is required.
Where consent is relied upon, it must be documented, specific to the proposed recording and capable of being withdrawn. Refusal or withdrawal of consent must not result in disadvantage.
Where a person lacks capacity to consent, staff must follow the Mental Capacity Act 2005 and the organisation’s Consent and Mental Capacity Policy. Any best-interests decision must be decision-specific, documented and must take account of the person’s wishes, feelings, values, privacy and the views of relevant representatives.
Recording must not normally take place during personal or intimate care. Any exceptional recording involving intimate care requires compelling justification, senior authorisation, a documented risk assessment and strict privacy controls.
Recordings must be made only through an approved organisation-issued device or approved care application. They must not be retained in the device’s ordinary camera roll, personal photo storage, personal cloud account or personal messaging application.
Staff must report any recording equipment found in a person’s home in accordance with the Surveillance, Consent and Safeguarding Policies. Staff must not damage, remove, cover, disable or delete material from equipment belonging to the person or their representative without lawful authority.
9. Digital Care Records
Digital records made through a mobile device must:
- be accurate, factual, complete and relevant;
- be recorded as soon as reasonably practicable after the event;
- distinguish fact from professional opinion;
- identify the staff member making the entry;
- record the actual date and time of the care, event or observation;
- record the date and time at which the entry was made;
- include significant changes, refusals, omissions, concerns, actions taken and persons informed;
- use respectful, professional and person-centred language;
- avoid unnecessary abbreviations, copied text and standard wording that does not reflect the care actually provided; and
- be capable of being retrieved and provided to CQC or another authorised body when lawfully required.
Staff must not:
- record care before it has been delivered;
- state that care was completed when it was refused, omitted or only partly completed;
- use another worker’s account;
- share electronic signatures;
- delete or obscure an original entry;
- alter a record to conceal an error or delay; or
- access records out of curiosity or for a non-work purpose.
Corrections must preserve an audit trail. A late or retrospective entry must be clearly labelled and must state when the entry was made and, where relevant, why it was delayed.
Managers must monitor the quality and timeliness of mobile care records and investigate patterns such as identical entries, implausible visit times, unexplained amendments, missing signatures or records completed significantly after the visit.
10. Appropriate Use During Working Hours
To maintain professionalism and ensure service users receive undivided attention:
10.1 Care Settings
- Staff must not make personal calls, send personal messages, browse the internet or use social media while providing care, except in a genuine emergency. Work-related use must be limited to what is necessary for safe care, recording, communication or access to authorised information.
- Devices should be kept on silent mode and stored securely when not in use.
- Emergency personal use is permitted but must be communicated to the line manager.
- Staff should explain to the person receiving care why they are using a device where the purpose may not be obvious.
- Staff must position the screen so that information cannot be seen by visitors, household members or other unauthorised persons.
- Devices must not be placed on surfaces where they may create an infection-control, contamination, trip or manual-handling risk.
- Devices must not be used while undertaking a task that requires the worker’s full attention, including moving and handling, medication administration, personal care or assisting a person who is at risk of falling.
- Where a device interrupts meaningful communication, the worker must pause its use unless immediate use is necessary for safety.
- Staff must respect a person’s reasonable request that a device is not used in their home, unless its use is necessary to provide safe care or meet a legal requirement. The concern must be discussed and an alternative arrangement considered.
10.2 Meetings and Training
- Mobile devices must be turned off or set to silent during meetings, training sessions, and supervision.
10.3 Driving
Staff must not hold or use a mobile phone, tablet, satellite-navigation device or other device capable of sending or receiving data while driving or riding a motorcycle. This prohibition applies whether the device is being used online or offline and includes use while stationary in traffic.
Staff must safely park and switch off the engine before holding or operating a device, except where a specific legal exemption applies.
A hands-free device may be used only where:
- it is securely mounted and does not obstruct the driver’s view;
- it can be operated without holding the device;
- its use does not distract the driver or prevent proper control of the vehicle; and
- the driver considers it safe to continue.
Staff must not make or accept hands-free calls where this would cause distraction. They must end the call or park safely where necessary. No worker will be criticised or disadvantaged for failing to answer a call while driving.
Managers and colleagues must not knowingly require or encourage a worker to respond to calls, messages, care-record alerts or scheduling updates while driving.
Route information must be entered before the journey begins. A device must not be adjusted while driving.
Any road traffic incident involving work-related device use must be reported immediately.
11. Lost, Stolen, or Compromised Devices
To protect company and service user data, employees must:
- Report lost, stolen, or compromised devices immediately to the IT team and Registered Manager.
- Do not personally attempt to track or recover a stolen device where this may place anyone at risk. The organisation will decide whether remote location, locking or wiping should be activated.
- Follow instructions to change relevant passwords, revoke active sessions, disable authentication tokens and review the affected accounts for suspicious activity.
- Complete an Incident Report Form detailing the circumstances.
- Provide details of:
- when and where the device was last seen;
- whether it was locked;
- what applications or records were accessible;
- whether information had been downloaded or cached;
- whether the device contained authentication codes;
- whether any other person may know the passcode; and
- any steps already taken.
- Report theft to the police where directed and retain the crime reference number.
- Preserve relevant evidence and must not remotely delete information unless instructed by an authorised person.
The organisation will assess whether personal information has been compromised, implement immediate containment measures and follow Section 7.3. The loss or theft of a device does not automatically require notification to the ICO; the decision will be based on the likelihood and severity of risk to individuals.
12. Mobile Device Management (MDM)
The organisation may use mobile device management, mobile application management or equivalent security controls where necessary and proportionate. The chosen controls must reflect the risks presented by the device, application, information and working arrangements.
- Enforce Security Policies: Apply encryption, password requirements, and remote wiping capabilities.
- Manage Applications: Restrict app installations and ensure only approved apps are used.
- Monitor Device Health: Track device status, software updates, and security patches.
- Remote Lock or Wipe: Protect sensitive data if a device is lost, stolen, or compromised.
- Separate work and personal information: Use a managed work profile or container where personally owned devices are approved.
- Restrict data leakage: Prevent unauthorised copying, screen capture, printing, downloading, forwarding, cloud backup or transfer to personal applications where technically possible.
- Control access: Require multi-factor authentication, revoke sessions and disable accounts when appropriate.
- Maintain an audit trail: Record device enrolment, security status, administrative actions, remote locks and wipes.
- Protect privacy: Limit the collection of employee information to what is necessary for the stated security purpose.
Before management software is applied, staff will receive clear written information describing the information collected, the administrative controls available to the organisation, the purposes for which the information may be used, the persons who may access it, the retention period and the circumstances in which a device or work profile may be locked or wiped.
13. Monitoring and Auditing
To ensure compliance with this policy:
- Regular Audits: Company-owned devices will be subject to periodic audits, including usage logs, app installations, and data storage.
- Proportionate spot checks: Authorised managers may conduct documented spot checks where necessary for quality, safety, information security or compliance. Spot checks must not involve indiscriminate access to an employee’s private information.
- Technical compliance monitoring: Approved management tools may check device security status, operating-system version, encryption status, required applications, work-account activity and other specified security information. The organisation must not collect more information than is necessary for the documented purpose.
- Incident Reporting: Any breach of this policy must be reported immediately, and corrective actions will be taken.
- Governance reporting: Audit findings, incidents, recurring failures, overdue updates, inappropriate access and record-quality concerns will be reported to the Registered Manager. Actions must be allocated, time-limited, followed up and recorded.
Monitoring must be lawful, fair, transparent, necessary and proportionate. The organisation will provide staff with privacy information and will complete a data protection impact assessment where monitoring is likely to present a high risk. Monitoring information will be retained only for as long as required and accessed only by authorised persons.
14. Breach of Policy
Failure to comply with this Mobile Devices Policy may result in disciplinary action, up to and including termination of employment. Examples of breaches include:
- Inappropriate device use: Personal or work-related device use that compromises care, dignity, safety, confidentiality, productivity or professional conduct.
- Data Breach: Storing or sharing service user information without encryption or authorisation.
- Security Non-Compliance: Failing to protect devices with passwords, encryption, or antivirus software.
- Unreported Loss or Theft: Not reporting lost or stolen devices promptly.
- Sharing an account, password, passcode or authentication code.
- Accessing a record without a legitimate work reason.
- Photographing, filming or recording a person on an unauthorised device.
- Using a personal email, messaging, cloud-storage or artificial-intelligence service for confidential information.
- Disabling security controls, updates, monitoring or mobile device management.
- Falsifying, pre-recording, backdating or improperly altering a care record.
- Failing to report a misdirected message, suspicious access, data breach or device loss promptly.
- Holding or using a device unlawfully while driving.
Disciplinary action will follow the company’s Disciplinary Policy, with the severity depending on the nature of the breach.
A potential breach will be investigated fairly and in accordance with the Disciplinary Policy. The organisation will distinguish between deliberate misconduct, reckless conduct, human error, inadequate training and system failure. Disciplinary action will not replace the need to address underlying organisational or technical weaknesses.
15. Training and Awareness
All staff whose roles involve mobile devices will receive training appropriate to their responsibilities, including:
- secure use of organisation-issued and personal devices;
- confidentiality, the UK GDPR and the Data Protection Act 2018;
- health and social care information as special category data;
- individual accounts, passwords and multi-factor authentication;
- accurate, complete and contemporaneous digital care records;
- person-centred device use, privacy and dignity;
- consent, mental capacity, photographs, recordings and surveillance;
- phishing, malicious links, unsafe QR codes, malware and social engineering;
- safe use of email, messaging and cloud systems;
- lost, stolen and compromised device procedures;
- personal data breach recognition and immediate internal reporting;
- safe working during system or connectivity failure;
- lawful and safe device use while driving; and
- the consequences of unauthorised access, recording, sharing or alteration of records.
Training must be completed before unsupervised access to mobile care systems is granted. Refresher training will be provided at least annually and following significant policy, legal, system or risk changes. Additional training or competency assessment will be provided following an incident, audit concern or identified unsafe practice.
Attendance, completion and competency must be recorded. Where a worker has not demonstrated the required competence, access must be restricted until suitable support, supervision and reassessment have been completed.
16. System Downtime and Business Continuity
The organisation must maintain a documented procedure for situations in which a mobile device, care-management application, communications network or internet connection is unavailable.
The procedure must include:
- how staff obtain essential information needed to provide safe care;
- how urgent changes, risks and safeguarding concerns are communicated;
- how medication and time-critical tasks are managed;
- how temporary records are made securely;
- how duplicate, lost or conflicting records are prevented;
- how temporary records are transferred to the permanent system;
- how retrospective entries are identified;
- who authorises use of contingency arrangements; and
- when the incident must be escalated.
Staff must not omit care or guess instructions because a digital system is unavailable. Where essential information cannot be obtained safely, staff must contact the on-call manager before proceeding, except where immediate action is necessary to prevent serious harm.
Business-continuity arrangements must be tested periodically and lessons from tests and actual outages must be documented.
17. Procurement, Suppliers and Approved Applications
Before a mobile application, cloud service or technology supplier is approved, the organisation must assess:
- the supplier’s security and data-protection arrangements;
- where information is stored and accessed;
- whether international data transfers occur;
- encryption, authentication, access control, logging and backup arrangements;
- the ability to retrieve, export, correct and delete information;
- system availability, support and incident-response arrangements;
- contract terms and data-processing requirements;
- arrangements at the end of the contract; and
- whether the system enables the organisation to meet CQC record-access and governance requirements.
A written data-processing agreement must be in place where required. Supplier access must be authorised, controlled, logged and removed when no longer necessary.
No member of staff may independently install or procure an application for use with information relating to people receiving care.
18. Data Protection Impact Assessments
The organisation will complete a data protection impact assessment before introducing mobile-device processing that is likely to result in a high risk to individuals. This may include:
- systematic worker monitoring;
- location tracking;
- biometric access controls;
- large-scale processing of health information;
- recording or surveillance technology;
- new mobile care-record systems;
- automated decision-making;
- artificial-intelligence functionality; or
- extensive use of personally owned devices.
The assessment must identify the purpose, lawful basis, necessity, proportionality, privacy risks, security measures, consultation and residual risks. The processing must not begin until identified high risks have been addressed or appropriately escalated.
19. Policy Review and Updates
This Mobile Devices Policy will be reviewed annually or sooner if significant changes occur, such as:
- Changes to the UK GDPR, the Data Protection Act 2018, health and social care legislation, CQC regulations or statutory and regulatory guidance.
- Implementation of new technologies or security systems.
- Emerging risks or industry best practices.
- A serious incident, data breach, cyber incident, safeguarding concern or complaint involving mobile technology.
- Findings from internal or external audit, CQC assessment or enforcement action.
- Introduction of a new mobile application, care-record system, monitoring tool or BYOD arrangement.
- Significant changes to supplier, hosting, backup or information-sharing arrangements.
- Evidence that staff do not understand or consistently follow the policy.
Any changes will be communicated to all staff, with training provided where necessary.
20. Staff Acknowledgement
All workers covered by this policy must confirm that they have read, understood and agree to comply with it before being granted access to mobile systems.
The acknowledgement must confirm that the worker:
- understands the rules governing organisation-issued and personally owned devices;
- will protect passwords, passcodes and authentication methods;
- will use only approved accounts, devices, applications and communication channels;
- understands the requirements concerning photographs, recordings, monitoring and consent;
- will report loss, theft, suspicious activity and data breaches immediately;
- understands that work-related activity may be lawfully and proportionately monitored;
- understands that access may be suspended or withdrawn where necessary to protect people or information; and
- understands that serious or repeated non-compliance may lead to disciplinary action.
Signing the acknowledgement does not remove the organisation’s responsibility to provide appropriate equipment, training, supervision, security controls and reasonable alternatives to the use of a personal device.
21. Legal and Regulatory Framework
This policy should be read with reference to:
- Health and Social Care Act 2008;
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014;
- Care Quality Commission (Registration) Regulations 2009;
- UK General Data Protection Regulation;
- Data Protection Act 2018;
- Human Rights Act 1998;
- Mental Capacity Act 2005;
- Equality Act 2010;
- Road Traffic Act 1988 and regulations governing the use of hand-held mobile devices while driving;
- CQC guidance on Regulations 9, 10, 11, 12, 17 and 18;
- CQC guidance on digital records and the use of recording or surveillance technology;
- Information Commissioner’s Office guidance on information security, personal data breaches, worker monitoring and bring-your-own-device arrangements; and
- the organisation’s related policies and procedures.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.