Publish your NHS DSP Toolkit (DSPT) by 30th June 2022

Your organisation needs to complete and publish its Data Security and Protection Toolkit (DSPT) self-assessment by 30th June 2022.

Publishing an annual DSTP self-assessment will also help your organisation demonstrate its GDPR and cyber maturity. This is required for you to meet your NHS contractual obligations.

NHS DSPT

Health and care organisations that have access to NHS Patient Data and Systems should complete and publish a DSPT self-assessment every year. These organisations will publish against the standard to provide assurance that they are practising good data security. The standard also requires proof that they are handling personal information correctly. This includes maintaining the security of patient information.

What should I do now?

Please log in to your DSPT account and complete your assessment for 2021-2022.  If you completed an assessment for 2020-2021 but have not had any evidential change for 2021-22, then this is good news. Your existing responses will be carried forward to your new toolkit. However, you should review and confirm these as well as working on any new or changed evidence items.

It is important that you actually have the evidence at this stage as auditing is likely. Simply saying you have evidence is no longer enough.

Don’t forget to complete and publish your self-assessment by 30th June 2022.

If you need help, we have helped many care providers with their assessment. This includes compiling or producing documentary evidence and we can help you.

You can call us on 03333 22 1011 or contact us here.

DSP Toolkit for Care Homes

The recently launched NHS DSP Toolkit for Care Homes was designed to help care homes with an NHS email address. Full compliance, or standards met is also available allowing care homes to take part in Coordinate My Care.

When registered, the care home faces a task which initially looks simple enough. A small number of questions to be answered, what could be simpler? However, the reality is quite different. Home Management need to create a full set of GDPR compliance documents in order to complete a relatively few questions in the toolkit.

Read More

Nursing home fined following laptop theft

A nursing home was fined following a laptop theft which contained residents’ details.

A nursing home in County Antrim has been fined £15,000 for failing to adequately protect sensitive data relating to its staff and residents. 

This story is a look back in history but reminds me of similar incidents involving many different types of business including a building society.

The Information Commissioner’s Office (ICO) launched the investigation in 2014. The unencrypted laptop, taken home by a member of staff at Whitehead Nursing Home, was stolen in a domestic burglary. 

Read More

GP surgery secretary fined

A former GP surgery secretary has been fined for reading medical records of 231 patients in two years, the ICO reported in 2018.

A trip back in time to November of 2018 for this blog. We shouldn’t forget that whilst this story may have a few cobwebs on it, this could be happening in your business, today.

A former trainee secretary at a GP surgery has been fined. She admitted unlawfully reading the records of 231 patients in two years.

Read More