IT Policy

This practice is committed to preserving, as far as is practical, the security of data used by our information systems. This means that we will take all reasonable actions to;

Maintain the Confidentiality of all data within the practice by:

  • Ensuring that only authorised persons can gain access to our systems
  • Not disclosing information to anyone who has no right to see it

Maintain the integrity of all data within the practice by:

  • Taking care over input
  • Ensuring that all changes are reported and monitored
  • Checking that the correct record is on the screen before updating
  • Reporting all apparent errors and ensuring that they are resolved

Maintain the availability of all data by:

  • Ensuring that all equipment is protected from intruders
  • Ensuring that backups are taken at regular, predetermined intervals
  • Ensuring that contingency is provided for possible failure or equipment theft and that any such contingency plans are tested and kept up to date

Additionally we will take all reasonable measures to comply with our legal responsibilities under:

Email Policy

 

Upon receiving an email from a patient that includes clinical information, we will:

  • Upload the email to the patient's record maintained at the surgery

  • Delete the email

If a patient prefers that their email not be uploaded to their clinical record, they must clearly state this in writing. Otherwise, the process above will be followed.

Page last reviewed: 04 February 2026
Page created: 02 December 2022