{{org_field_logo}}

{{org_field_name}}

Registration Number: {{org_field_registration_no}}


IT Equipment Security Policy

1. Purpose

The purpose of this policy is to establish the technical, organisational and physical controls that {{org_field_name}} uses to protect its information, IT equipment and electronic care-record systems. These controls are intended to protect the confidentiality, integrity, availability and resilience of personal data and other organisational information used in the provision of care-at-home services.

{{org_field_name}} will process personal data securely and lawfully in accordance with the UK General Data Protection Regulation, the Data Protection Act 2018 and other applicable legislation. Particular care will be taken when processing health information, care records, medication information, safeguarding information and other special category personal data.

This policy supports the organisation’s responsibilities under Scottish care-service legislation, the Health and Social Care Standards, the Scottish Social Services Council Codes of Practice for Social Service Workers and Employers 2024, and the Care Inspectorate quality framework for support services, including care at home and supported living.

The policy applies a proportionate, risk-based approach. Security controls will be selected after considering the nature, scope, context and purpose of the processing, the sensitivity of the information, the likelihood and severity of harm, current technical standards and the cost of implementation.

2. Scope

This policy applies to:

This policy applies regardless of whether information is accessed from an office, an individual’s home, a vehicle, a public location or another remote-working location. Compliance with this policy is a condition of access to the organisation’s systems and information.

3. Legal and Regulatory Requirements

Cyber Essentials is a government-backed cyber security certification scheme and good-practice framework. It is not, by itself, a substitute for compliance with the UK GDPR, the Data Protection Act 2018 or Scottish care-service requirements. Where {{org_field_name}} claims Cyber Essentials certification, the organisation must ensure that the certification remains valid and that all relevant systems, devices and cloud services are included within the declared scope.

3.1 Data Protection Principles

When using IT equipment or electronic systems, all workers must ensure that personal data is:

Health information, medication information, care and support records, adult protection information and information about disability, ethnicity, religion, sexual orientation or other protected characteristics must be treated as sensitive information and protected accordingly.

4. Responsibilities

Workers must not attempt to investigate a suspected cyber incident themselves beyond taking immediate steps necessary to prevent further disclosure or harm. They must preserve relevant evidence and follow instructions from the authorised incident-response lead.

4.1 Access Authorisation and Leavers

Access to systems and information must be authorised before it is provided. Access must be based on the worker’s role, responsibilities and legitimate need to know.

Managers must notify the IT lead immediately when:

Access for leavers must be disabled no later than the end of their final working period, or immediately where there is a security, safeguarding or misconduct concern. Company equipment, security keys, identity cards and storage media must be recovered and recorded.

Privileged and administrator access must be limited to authorised personnel, protected by multi-factor authentication, used only for administrative tasks and reviewed more frequently than ordinary user access.

5. IT Equipment Security Measures

5.1 Physical Security of IT Equipment

5.1.1 Use of Technology in People’s Homes

When using a device in an individual’s home, workers must respect the individual’s dignity, privacy, property and family life. Workers must explain, in an accessible way, why a device is being used and what information is being recorded.

Workers must:

The use of technology must not unnecessarily reduce meaningful contact with the individual or interfere with the delivery of compassionate, person-centred care.

5.2 User Authentication and Access Controls

5.3 Data Protection and Encryption

5.3.1 Data Protection by Design and Data Protection Impact Assessments

Data protection and information security must be considered from the earliest stage of any new project, system, device, monitoring arrangement or change in working practice.

A data protection impact assessment must be considered before introducing processing that is likely to result in a high risk to individuals. This includes, but is not limited to:

The Data Protection Officer or Data Protection Lead must be consulted before high-risk processing begins.

5.4 Use of IT Equipment and Internet Security

5.4.1 Artificial Intelligence, Transcription and Online Tools

Workers must not enter personal data, care records, health information, medication information, safeguarding information, commercially confidential information or login credentials into a public or unapproved artificial intelligence, transcription, translation or content-generation service.

Artificial intelligence tools may be used for organisational purposes only where:

AI-generated text must not be copied into a care record without review and confirmation by an authorised worker.

5.5 Remote Working and Mobile Device Security

5.6 Secure Disposal, Return and Reuse of Equipment

IT equipment, storage media and mobile devices must be returned to the organisation or an approved supplier for secure wiping, reuse or destruction. Workers must not sell, donate, discard or personally retain organisation equipment.

Before equipment is reassigned, returned to a leasing company, recycled or disposed of, data must be securely erased using an approved method. Where secure erasure cannot be verified, the storage component must be physically destroyed by an approved contractor.

The organisation must retain a disposal record showing:

5.7 Third-Party Suppliers and Data Processors

Before a supplier is permitted to process personal data or access organisation systems, {{org_field_name}} must complete proportionate due diligence and ensure that an appropriate written contract is in place.

Contracts with data processors must address:

Supplier access must be time-limited, authorised, logged and removed when no longer required.

6. Incident Management and Reporting

6.1 Identifying and Reporting Security Incidents

Any actual or suspected cyber security incident, personal data breach, loss of equipment, phishing message, malware infection, unauthorised disclosure, inappropriate access, misdirected communication, alteration of a record or loss of system availability must be reported immediately.

Reports must be made to:

A worker must report an incident even where they believe that no harm has occurred, the information was retrieved, the message recipient has deleted it, or the device was encrypted.

Every suspected or confirmed incident must be recorded in the organisation’s incident or breach log. The record must include the facts, dates and times, systems and individuals affected, categories and approximate volume of information, immediate containment actions, risk assessment, notification decisions, communications, recovery actions, lessons learned and any corrective actions.

6.2 Incident Containment, Assessment, Notification and Recovery

The organisation will activate its incident-response arrangements following any suspected or confirmed security incident. Actions may include:

Workers must not delete relevant messages, reset affected devices, dispose of equipment or otherwise destroy evidence unless instructed by the incident-response lead.

6.3 Notification to the Information Commissioner’s Office

The Data Protection Officer or Data Protection Lead will assess every personal data breach to determine the likelihood and severity of risk to the rights and freedoms of affected individuals.

A personal data breach must be reported to the Information Commissioner’s Office without undue delay and, where feasible, no later than 72 hours after {{org_field_name}} becomes aware of it, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms.

Where notification is made more than 72 hours after awareness, the reason for delay must be documented and provided to the ICO.

The organisation must document all personal data breaches, including breaches that are not reported to the ICO, and record the reasons for the notification decision.

6.4 Communication with Affected Individuals

Where a personal data breach is likely to result in a high risk to an individual’s rights and freedoms, {{org_field_name}} will communicate the breach to the affected individual without undue delay, unless a lawful exception applies.

The communication will use clear and accessible language and will explain:

Communication needs, capacity, advocacy arrangements and the involvement of authorised representatives must be considered.

6.5 Care Inspectorate and Other Regulatory Notifications

A personal data breach is not automatically reportable to the Care Inspectorate solely because personal data is involved.

The Registered Manager must assess whether the incident:

Where notification is required, it must be submitted through the appropriate Care Inspectorate process within the applicable timescale. The reason for notifying or not notifying must be recorded.

The organisation will also consider whether notification is required to the police, NHS Scotland, a health and social care partnership, local authority, commissioner, SSSC, professional regulator, insurer, National Cyber Security Centre or another relevant body.

6.6 Continuity of Care During System Failure

{{org_field_name}} must maintain tested arrangements for continuing safe care when electronic systems, mobile devices, internet connections, telephone systems or cloud services are unavailable.

Continuity arrangements must cover:

Emergency information must be protected, accurate, current and accessible only to authorised personnel.

7. Training and Compliance

All workers must complete data protection, confidentiality and cyber security training during induction and before being given unsupervised access to personal data or operational systems.

Refresher training must be completed at least annually and whenever there is a significant change in legislation, systems, threats or organisational procedures.

Role-specific training must be provided to managers, system administrators, staff handling personal data breaches and workers who use high-risk systems.

Training must include:

The organisation must maintain training records and follow up overdue or unsuccessful completion.

Periodic awareness exercises, such as simulated phishing or scenario-based breach exercises, may be undertaken proportionately. Exercises must be used for learning and improvement and must not create an inappropriate blame culture.

Failure to comply with this policy may result in restriction or removal of system access, retraining, supervision, investigation or disciplinary action. Serious concerns may require referral to the SSSC or another professional regulator.

8. Record-Keeping and Compliance Monitoring

Security logs, access records, asset records, incident records, breach records, audit evidence and disposal records must be retained in accordance with the organisation’s approved retention schedule. Retention periods must be based on legal, regulatory, contractual, safeguarding, insurance, operational and evidential requirements. Records must not be retained indefinitely without a documented purpose.

Records subject to an active complaint, investigation, litigation hold, safeguarding process, regulatory enquiry or insurance claim must not be destroyed until authorised by the appropriate responsible person.

At the end of the retention period, records must be securely deleted or destroyed and the action documented where appropriate.

The organisation will complete proportionate information-security and data-protection monitoring at planned intervals. Higher-risk controls, accounts and systems may require more frequent review. Monitoring will include, where relevant:

Audit and monitoring findings must be documented, risk rated, assigned to a named person and given a target completion date. Senior management must monitor overdue or high-risk actions and verify that corrective action has been effective. The organisation must maintain an accurate inventory of devices, software, information assets, system owners and approved cloud services.

8.1 Monitoring and Audit of System Use

{{org_field_name}} may monitor the use of its systems, devices and networks for security, operational, audit, regulatory and investigation purposes. Monitoring must be lawful, necessary, proportionate and transparent.

Workers must be informed about:

Covert monitoring will only be considered in exceptional circumstances, following senior authorisation and appropriate legal and data protection advice.

9. Related Policies

10. Exceptions and Non-Compliance

Any exception to this policy must be documented, risk assessed, time limited and authorised by the appropriate senior manager, Data Protection Officer or Data Protection Lead and IT security lead.

The exception record must state:

Workers must not create informal exceptions or bypass security controls without authorisation.

11. Equality, Accessibility and Human Rights

Security arrangements must respect the dignity, privacy, autonomy, communication needs and human rights of individuals receiving care. Security measures must not create unnecessary barriers to communication, participation or access to information.

Information about the use of electronic records, digital systems or monitoring technology must be provided in a format and language that the individual can understand. Reasonable adjustments, communication aids, interpreters, advocacy or representative involvement must be considered where appropriate.

Where an individual lacks capacity in relation to a particular decision, the organisation must act within the applicable legal framework and record the authority and decision-making process relied upon.

12. Policy Review

This policy will be formally reviewed at least annually and sooner where:

Material changes will be communicated to workers and incorporated into training, supervision and operational procedures.


Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on:
{{last_update_date}}
Next Review Date:
{{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *