IOC Recommendations to Lanarkshire2 Aug 2023 12:20
Quote:
The ICO recommended that NHS Lanarkshire should take action to ensure their compliance with data protection law, including:
Consider implementing a secure clinical image transfer system, as part of NHS Lanarkshire’s exploration regarding the storage of images and videos within a care setting.
Before deploying new apps, consider the risks relating to personal data and include the requirement to assess and mitigate these risks in any approval process.
Ensure explicit communications, instructions or guidance are issued to employees on their data protection responsibilities when new apps are deployed.
Review all organisational policies and procedures relevant to this incident and amend where appropriate.
Ensure all staff are aware of their responsibilities to report personal data breaches internally without delay to the relevant team.
The ICO has asked NHS Lanarkshire to provide an update of actions taken within six months of the reprimand being issued.
The ICO has a revised approach to public sector enforcement, aiming to encourage greater data protection compliance from public authorities to prevent harms before they occur.
Repeat:
“ Consider implementing a secure clinical image transfer system, as part of NHS Lanarkshire’s exploration regarding the storage of images and videos within a care setting.”
Hmmm I wonder what the only completely compliant system is……?