3. Day-to-day security that actually holds

Screens and speech

Angle monitors away from the queue. Use a screensaver lock. Call first names, not “Mrs Khan, root canal, HIV”. Close clinical records when you walk away. Do not discuss a case in the lift with another patient behind you.

Logins

One person, one login. Shared “reception” passwords make every audit trail useless and every leaver a risk. Unique passwords and multi-factor authentication where the software offers it. Change access the day someone leaves — not at the next appraisal.

Email and messaging

NHS Mail (or an equivalent secure clinical channel you have actually commissioned) is not the same as a personal Gmail forward. Do not send identifiable radiographs to a lab on an open WhatsApp group. If you must use a consumer app in a genuine emergency, minimise identifiers, move it onto the record, and stop using that channel for routine work.

Phones and USBs

Practice-owned, encrypted devices are the default. Personal phones photographing study models or a child’s face for “the group chat” are a breach waiting for a lost handset. Encrypted USBs only, and a log of who took what off site.

Next module

Module 2 covers subject access and other rights, what counts as a personal-data breach, ICO timescales, retention, and CCTV.

Always follow current UK data protection law, GDC Standards, and your written IG procedures.