Data Security Standard 7 Continuity Planning The bigger picture and how the standard fits in

Size: px
Start display at page:

Download "Data Security Standard 7 Continuity Planning The bigger picture and how the standard fits in"

Transcription

1 Data Security Standard 7 Continuity Planning The bigger picture and how the standard fits in 2018 Copyright 2017 Health and Social Care Information Centre. The Health and Social Care Information Centre is a non-departmental body created by statute, also known as NHS Digital.

2 Contents Overview 3 Business continuity and disaster recovery 4 Definition and background 4 A continuity plan for data security incidents 4 Expanding your existing BCP 5 Expanding existing IT disaster recovery plan Creating a data security incident plan Testing the plan 6 Live testing 6 Desktop testing 6 Membership of the group The type and volume of scenarios 8 During the testing 8 Post testing 8 Roles and responsibilities 9 Digital contact list Press material Lessons learnt 10 Appendix 1-11 Table of data security level 7 assertions 11 Appendix 2-12 Useful resources 12 Appendix 3 13 Data security scenarios 13 Appendix 4 15 Example of results of a test 15 Appendix 5 19 The National Data Guardian reports 19 Copyright 2017 Health and Social Care Information Centre. 2

3 Overview The National Data Guardian review s data standard 7 states that: A continuity plan is in place to respond to threats to data security, including significant data breaches or near misses, and it is tested once a year as a minimum, with a report to senior management. A business continuity exercise is run every year as a minimum, with guidance and templates available from the Toolkit. There should be a clear focus on enabling senior management to make good decisions, and this requires genuine understanding of the topic, as well as the good use of plain English. Maintenance Analysis Testing and acceptance Business Continuity Lifecycle Solution Implementation Copyright 2017 Health and Social Care Information Centre. 3

4 Business continuity and disaster recovery Definition and background The terms business continuity and disaster recovery are often interchanged and sometimes viewed as the same thing. A business continuity plan (BCP) is concerned with how you keep the organisation relocating and reshaping services. Disaster recovery is effectively a plan of attack of how you fix the problem and return the organisation back to normality. In the care system, organisation business continuity tends to focus on: "Act of God" Staffing Major Incident Site Unavailbaility Extreme Demand o Flooding o High winds o Medical virus outbreak o Industrial action o Terrorist attack o Major fire o Power outage o Road issues o Winter pressures o Service closures elsewhere The global WannaCry cyber-attack in May 2017 has reaffirmed the potential for cyber incidents to impact directly on patient care and the need for our health and care system to act decisively to minimise the impact on essential frontline services. Your Data: Better Security, Better Choice, Better Care Government Response In addition to this, organisations also need to have a business continuity plan that caters for data security incidents. There are examples of data security incidents and reporting procedures in Big Picture Guide 6. For small organisations, your data security plan can be an extension of your existing business continuity plan. If you are part of a larger organisation and use IT extensively it is recommended that you refer to the general guidance for this data standard as it has more indepth guidance for more complex IT systems. A continuity plan for data security incidents When creating your continuity plan for data security incidents, you can either extend your existing business continuity plan or keep the data security plan as a separate document. Copyright 2017 Health and Social Care Information Centre. 4

5 Whichever route you choose data security should be included in any plan, even those not related to cyber incidents. For example, where a restored system may have the full set of access rights in place. Writing your data security incident plan You are likely to have already considered some aspects of data security in your business continuity plan for example, what you would do if there was a flood or fire and you couldn t access care notes. It is important that you also consider what would happen if your phone line or broadband went down. What work arounds would you use? The 2017 WannaCry attack has also made it clear that health and care are vulnerable to cyber-attacks and your organisation should have considered a plan for if something similar were to happen again. There are examples of business continuity plans in There is a continuity plan in place for data security incidents, and staff understand how to put this into action. Data Security Standard 7.1 Appendix 2. Business Continuity Plan sign off Once your organisation has added a data security plan to your business continuity plan, this needs to be signed off by the appropriate person in senior management. This person may be called the Senior Information Risk Owner (SIRO). The incident management and business continuity plan has been approved by the SIRO or equivalent senior role. Data Security Standard Copyright 2017 Health and Social Care Information Centre. 5

6 Testing the plan Once you have a business continuity plan you should test it at least annually. Testing the plan can generally be done in two ways - through live testing (simulation / active testing) or through desktop-based scenarios. Live testing Desktop testing Live testing For most small organisations, it may be difficult to live test continuity plans due to the amount of resources this will take. This is also designed for more complicated IT systems and so will often require the assistance of an external support service. If your organisation has the resources and need to live test your systems, we recommend you read the general guidance on this data security standard. Desktop testing This should form a realistic scenario and a frank and honest appraisal of your response. The goal of desktop testing is to identify gaps in your response in terms of people, processes and technology. These gaps should inform improvement actions that help your future response to any data security incidents. Copyright 2017 Health and Social Care Information Centre. 6

7 These test(s) need to occur at least annually and have representation from the highest level in your organisation. It will depend on your organisation size how many people should take part in the test. In very small organisations, there might only be one appropriate person who can carry out testing. The procedures in Data Security Standard 5 for reviewing processes might be a good way of managing this. When desktop testing, you should consider a possible scenario and run through how you would deal with it. If changes need to be made to your plan as a result of the test, then these should be recorded, and the plan should be updated. There are example scenarios in Appendix 3. There is an effective annual test of the continuity plan for data security incidents. Data Security Standard 7.2 Copyright 2017 Health and Social Care Information Centre. 7

8 The type and volume of scenarios The type of scenarios should be related to the most likely data security incidents. Some suggestions for the type of incidents are included in Appendix 3. During the testing During the test, the scenario should be explained to the incident team with replies and queries logged. The chair should probe the answer and develop the scenario. The intention is to identify areas for improvement. An example of a log of test is shown in Appendix 4. Where you find gaps, you should log them (together with a name to look at them). The primary purpose is to identify a gap and then move on. Post testing Post testing you should have an action plan with names and dates for who should complete each item. This should be followed up. An example action plan is contained in Appendix 4. Scanned copy of data security business continuity exercise registration sheet with attendee signatures and roles Data Security Standard From the business continuity exercise which issues and actions were documented, with names of actionees listed against each item. Data Security Standard Copyright 2017 Health and Social Care Information Centre. 8

9 Roles and responsibilities When there is an incident, it is essential that people within your organisation know who to contact. Therefore you should keep a hard-copy, up-to-date contact list. It is important that it is also known when it was last updated and printed. Consideration should be given to where the copy contact list is located, especially in a scenario that affects access to the site. You should consider keeping a copy on an appropriate cloud service. The contact list should be reviewed and updated at intervals. When updated the contact list should be reprinted. MANDATORY: All emergency contacts are kept securely, in hardcopy and are up-todate. Data Security Standard MANDATORY: Location of hardcopy of emergency contacts. Data Security Standard MANDATORY: Date emergency contact last updated. Data Security Standard Date emergency contact last printed / shared Data Security Standard Copyright 2017 Health and Social Care Information Centre. 9

10 Lessons Learnt Should form part of the Plan Do Check Act cycle and form part of any altered and new processes (see Data Security Standard 5 Process Reviews). Document any re-defined processes to respond to common forms of cyber-attack in the last twelve months. Data Security Standard Copyright 2017 Health and Social Care Information Centre. 10

11 Appendix 1 - Table of data security level 7 assertions Assertion Mandatory Sub Assertion Evidence 7.1 There is a continuity plan in place for data security incidents, and staff understand how to put this into action. 7.2 There is an effective annual test of the continuity plan for data security incidents. Yes There is an incident management and business continuity plan in place for data security and protection. No The incident management and business continuity plan has been approved by the SIRO or equivalent senior role. No Staff survey - contingency plan (Q17) - if a data security incident was to prevent technology from working in my organisation, there is a clear plan for dealing with this and I know how to continue doing the critical parts of my job. No Scanned copy of data security business continuity exercise registration sheet with attendee signatures and roles held. No From the business continuity exercise which issues and actions were documented, with names of actionees listed against each item. Yes All emergency contacts are kept securely, in hardcopy and are up-to-date. Yes Location of hardcopy of emergency contacts. Yes Date emergency contact last updated. No Date emergency contact last printed/shared No Document any re-defined processes to respond to common forms of cyber-attack in the last twelve months. Copyright 2017 Health and Social Care Information Centre. 11

12 Appendix 2 - Useful resources Business Continuity Plan: Data Security The Care Provider Alliance has guidance and a template for the data security business continuity plans. Emergency Planning / Business Continuity: Pharmaceutical Services Negotiating Committee (PSNC) PSNC has produced a business continuity template to meet the requirements of community pharmacy service providers. Business continuity guidance for health and care organisations: NHS Digital good practice guide Guidance for health and care organisations on the factors to consider when producing an IT and information security business continuity policy and plan, to maintain business functions at acceptable predefined levels following a disruptive incident. The guidance covers incident management, business continuity and disaster recovery through a business continuity plan, as well as training for staff, management, implementation and testing of the plan and policy. Copyright 2017 Health and Social Care Information Centre. 12

13 Appendix 3 Data security scenarios Example A: Stand and deliver! A member of your staff opens up an attachment which looks legitimate. Sometime after they notice they are unable to open up their work documents. This is true for all people in your organisation. You notice that all documents have been encrypted. The member of staff receives a ransom mail detailing where to transfer money to rectify the issue. How do you proceed? Example B: makes you want to cry Your computer reboots and displays a screen asking for a bitcoin ransom to be paid to unlock. All your care plans and staff details are stored on this PC. How do you proceed? Example C: Not so fast, not so furious The company which makes your rota software has an error which causes your rota system to stop working. How do you proceed? Example D: Pass me the remote Your broadband connection is disrupted and you cannot update care plans and send these out to staff working on mobile devices. How do you proceed? Copyright 2017 Health and Social Care Information Centre. 13

14 Example E: Not my problem? Many of your staff share one password to access your computer. It turns out that a malicious former employee has returned to your organisation to use this password to look at records. How do you proceed? Example F: A modern classic? A folder containing care records is found in the staff car park and handed in to reception. It contains a sensitive care data. How do you proceed? Copyright 2017 Health and Social Care Information Centre. 14

15 Appendix 4 Example of results of a test Desktop test Attendance sheet There is a power outage in your area and your computer(s) cannot be turned on. Review venue A meeting room Date / Time hh:mm Attendees role Board member Mrs Patricia Personnel Responsible Person Registered Manager IG / data security Lead Mr Colin Cloud Miss Susan Septum Registered Manager IG Lead IG/ data security Mr Lee Privilege IG / IS Manager IT networks Miss Cat Five Network Manager IT servers Mr Stan Bye IT Server Manager Adjudicator Mr Aton Detail External Audit Service Copyright 2017 Health and Social Care Information Centre. 15

16 Note that this example scenario only considers the data implications of a power outage it does not consider the wider ramifications such as loss of power to clinical fridges, loss of call bells and alarm systems, etc. In a real scenario you would probably want to consider the wider ramifications of such a thing happening. Process review Review venue Log of responses There is a power outage in your area and your computer(s) cannot be turned on. A meeting room Date / time hh:mm Notes the scenario is not known to the group beforehand. PP delivers the scenario. CC suggests going to the fuse board for the site and, if that doesn t solve the problem calling the electricity supplier. SS doesn t know who the supplier is or where to find the number. Action 1: CC to update emergency contact list and ensure that all staff are trained on where to find it. CC says that because care plans are stored and updated digitally, emergency laptops will be used to access vital data and that in the meantime, care records will revert to paper templates. Action 2: SS to ensure that there are template care records stored in the right location for emergency situations. There followed a discussion on what the procedure would be once there was power again to retroactively upload the care records which had been hand written and what the procedure should be around keeping or destroying the paper records. Action 3: PP has said she will review who would be best placed to take on this action and would update the continuity plan. Copyright 2017 Health and Social Care Information Centre. 16

17 Improvement notes for next meeting Useful to bring copies of the BCP, whiteboard for sketching ideas and more role play and time lapsed to give a sense of urgency. Next scenario scheduled dd/mm/yy 123 Room followed by follow up action meeting Copyright 2017 Health and Social Care Information Centre. 17

18 Process review Action plan There is a power outage in your area and your computer(s) cannot be turned on. Review venue Agenda / actions 1) A meeting room Date / time hh:mm Agenda item Action Due Allocated Status Emergency Contact List Updated Emergency Contact List and trained staff on where to find it Action complete dd/mm/yy SS Resolved 2) Back up care record templates 3) Process for care record upload following power failure Blank back up records have been printed and stored in agreed location Action complete CC has been working to redevelop this process and train staff on how it works Actions: ongoing dd/mm/yy SS Resolved dd/mm/yy CC Unresolved Copyright 2017 Health and Social Care Information Centre. 18

19 Appendix 5 The National Data Guardian reports The NDG report Recommendations to improve security of health and care information and ensure people can make informed choices about how their data is used. Review of Data Security, Consent and Opt-Outs The government response Your Data: Better Security, Better Choice, Better Care is the government s response to: the National Data Guardian for Health and Care s Review of Data Security, Consent and Opt-Outs the public consultation on that review the Care Quality Commission s review Safe Data, Safe Care It sets out that the government accepts the recommendations in both the National Data Guardian review and the Care Quality Commission review. It also reflects on what we heard through consultation to set out immediate and longer-term action for implementation. Your Data: Better Security, Better Choice, Better Care Copyright 2017 Health and Social Care Information Centre. 19

BUSINESS CONTINUITY MANAGEMENT POLICY

BUSINESS CONTINUITY MANAGEMENT POLICY BUSINESS CONTINUITY MANAGEMENT POLICY A GUIDE TO BUSINESS CONTINUITY AND SERVICE RECOVERY PLANNING Version 1.2 Ratified by BHR CCGs Governing Bodies Date ratified September 2016 Name of Director Lead Marie

More information

Meeting of Governing Body

Meeting of Governing Body Meeting of Governing Body Date: 7 August 2018 Time: 1.30pm Location: Clevedon Hall, Elton Rd, Clevedon, North Somerset, BS21 7RQ Agenda number: 10.3 Report title: Business Continuity Policy Report Author:

More information

UCL MAJOR INCIDENT TEAM MAJOR INCIDENT PLAN. Managing and Recovering from Major Incidents

UCL MAJOR INCIDENT TEAM MAJOR INCIDENT PLAN. Managing and Recovering from Major Incidents UCL MAJOR INCIDENT TEAM MAJOR INCIDENT PLAN Managing and Recovering from Major Incidents June 2017 MAJOR INCIDENT PLAN - June 2017 Title Primary author (name and title) UCL Major Incident Plan (public

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan Doc Ref: Sitt.149963 1 Contents 1. Executive Summary... 3 2. Objective of the Plan... 7 Definitions... 7 4. Scope of the Plan... 8 5. Stages of Activation of Business Continuity

More information

Information Governance Management Framework

Information Governance Management Framework Framework Policy Folder / Number Folder 3 Version: 1 Ratified by: Policy No. 3.2 Audit Committee Date ratified 5 th March 2013 Name of originator/author: Name of responsible committee/individual: Senior

More information

Investigation: WannaCry cyber attack and the NHS

Investigation: WannaCry cyber attack and the NHS A picture of the National Audit Office logo Report by the Comptroller and Auditor General Department of Health Investigation: WannaCry cyber attack and the NHS HC 414 SESSION 2017 2019 27 OCTOBER 2017

More information

BUSINESS CONTINUITY PLAN

BUSINESS CONTINUITY PLAN Appendix 1. Official BUSINESS CONTINUITY PLAN Enter Department / Directorate Name Enter Section name Force Critical Functions The Force has 8 Critical Functions which must be maintained: To maintain effective

More information

Personal Electronic Devices Acceptable Use Policy

Personal Electronic Devices Acceptable Use Policy Personal Electronic Devices Acceptable Use Policy Version 1.0 Purpose: For use by: This document is compliant with /supports compliance with: This document supersedes: Approved by: To advise Trust staff

More information

PORTER S AVENUE DOCTORS SURGERY UPDATE

PORTER S AVENUE DOCTORS SURGERY UPDATE Concordia Health Ltd Primary Care PORTER S AVENUE DOCTORS SURGERY UPDATE April 2018 Concordia Health Ltd Primary Care Summary of changes Agreement National Data Guardian Security Review (NDGSR) Compliance

More information

HSCN Trust Funding Applications

HSCN Trust Funding Applications HSCN Trust Funding Applications Guidance document Published 03 January 2017 (Updated 06 February 2018) Copyright 2016 Health and Social Care Information Centre. The Health and Social Care Information Centre

More information

Kings Crisis and Critical Incident Management Policy

Kings Crisis and Critical Incident Management Policy Kings Crisis and Critical Incident Management Policy All Kings policies will be ratified by the Board of Directors and signed by the Chairperson. Each policy will be co-signed by the principal of each

More information

NHS HARINGEY CLINICAL COMMISSIONING GROUP EMERGENCY PREPAREDNESS, RESILIENCE AND RESPONSE (EPRR) POLICY

NHS HARINGEY CLINICAL COMMISSIONING GROUP EMERGENCY PREPAREDNESS, RESILIENCE AND RESPONSE (EPRR) POLICY NHS HARINGEY CLINICAL COMMISSIONING GROUP EMERGENCY PREPAREDNESS, RESILIENCE AND RESPONSE (EPRR) POLICY 1 1 SUMMARY This policy sets out how the CCG will ensure that it has prepared and tested arrangements

More information

BUSINESS CONTINUITY PLANNING POLICY

BUSINESS CONTINUITY PLANNING POLICY Agenda No. 8(c) Enclosure No. 11 BUSINESS CONTINUITY PLANNING POLICY REFERENCE CODE (Man.) (For Corporate Key Documents, Reference code will be allocated by the Policy Co-ordinator e.g. upon

More information

Special Presentation: HIPAA Survival. Dr. Ty Talcott, CHPSE C: / PH: /

Special Presentation: HIPAA Survival. Dr. Ty Talcott, CHPSE C: / PH: / Special Presentation: HIPAA Survival Dr. Ty Talcott, CHPSE C: 469.371.8804 / PH: 214.437.7559 Ty.talcott@gmail.com / Info.hipaa@gmail.com Foxworth Video A Little about me. Ski Lift Acrobatics How do they

More information

Emergency Management. 1 of 8 Updated: June 20, 2014 Hospice with Residential Facilities

Emergency Management. 1 of 8 Updated: June 20, 2014 Hospice with Residential Facilities CEMP Criteria for Hospice Lee County Emergency Management The following criteria are to be used when developing Comprehensive Emergency Management Plans (CEMP) for all hospices. The criteria also serve

More information

Getting started.. questions to consider when revising or developing your plans

Getting started.. questions to consider when revising or developing your plans Getting started.. questions to consider when revising or developing your plans DEFINING SERVICE / BUSINESS CONTINUITY Ensure the right people have the right information at the right time. 1. Understand

More information

POLYMER PROCESSING SOCIETY (PPS) International and Regional Conferences. Instructions to the Organizers January 2017

POLYMER PROCESSING SOCIETY (PPS) International and Regional Conferences. Instructions to the Organizers January 2017 POLYMER PROCESSING SOCIETY (PPS) International and Regional Conferences Instructions to the Organizers January 2017 1. International and Regional Conferences (in the past named Meetings ) International

More information

NHS HARINGEY CLINICAL COMMISSIONING GROUP

NHS HARINGEY CLINICAL COMMISSIONING GROUP NS ARINGEY CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY PLAN AND EMERGENCY PLANNING RESPONSE AND RESILIENCE (EPRR) ARRANGEMENTS 1 SUMMARY aringey CCG is required by NS England to plan its emergency

More information

Miami-Dade County, Florida Emergency Operations Center (EOC) Continuity of Operations Plan (COOP) Template

Miami-Dade County, Florida Emergency Operations Center (EOC) Continuity of Operations Plan (COOP) Template Miami-Dade County, Florida Emergency Operations Center (EOC) Continuity of Operations Plan (COOP) Template Miami-Dade County Department of Emergency Management 9300 NW 41 st Street Miami, FL 33178-2414

More information

NHS Digital Audit of Data Sharing Activities: London Borough of Enfield Council Public Health

NHS Digital Audit of Data Sharing Activities: London Borough of Enfield Council Public Health Directorate / Programme Care Services Project Sharing Audits Status Approved Director Catherine O Keeffe Version 1.0 Owner Rob Shaw Version issue date 04/01/2018 NHS Digital Audit of Sharing Activities:

More information

Business Continuity Plan

Business Continuity Plan Business Continuity Plan Telford and Wrekin Clinical Commissioning Group (CCG) Author(s) Date 12/09/2013 Version 0.3 Christine Morris Executive Nurse, Lead for Quality & Safety Approved by: Date 1.0 Document

More information

BUSINESS CONTINUITY PLANNING

BUSINESS CONTINUITY PLANNING BUSINESS CONTINUITY PLANNING May 2015 1 Version Version 1 Ratified By Date Ratified April 2013 Author(s) Responsible Committee / Officers Senior Management Team Date Issue April 2013 Review Date April

More information

Chapter 3: Business Continuity Management

Chapter 3: Business Continuity Management Chapter 3: Business Continuity Management GAO Why we did this audit: Nova Scotians rely on critical government programs and services Plans needed so critical services can continue Effective management

More information

NOTES AND ACTIONS. Turn off power switch, wait a few seconds, turn back on. If paper jammed, remove and reinsert.

NOTES AND ACTIONS. Turn off power switch, wait a few seconds, turn back on. If paper jammed, remove and reinsert. POLICY All ADCs will be plugged into the C&W Emergency Power (RED) plugs. In the event that the main BC Hydro power is off, the cabinets should still run on the Emergency Power system (C&W back up generators).

More information

CEMP Criteria for Ambulatory Surgery Centers Emergency Management

CEMP Criteria for Ambulatory Surgery Centers Emergency Management CEMP Criteria for Ambulatory Surgery Centers Lee County Emergency Management The following criteria are to be used when developing Comprehensive Emergency Management Plans (CEMP) for all ambulatory surgical

More information

Procedure: 3.4.1p2. (II.D.2a.) Business Continuity Planning

Procedure: 3.4.1p2. (II.D.2a.) Business Continuity Planning Procedure: 3.4.1p2. (II.D.2a.) Business Continuity Planning Revised: January 17, 2017; November 7, 2013 Last Reviewed: January 17, 2017; October 14, 2016 Adopted: November 7, 2013 I. PURPOSE: The Business

More information

Amending Inaccuracies in Clinical Records Procedure

Amending Inaccuracies in Clinical Records Procedure SH IG 07 Clinical Record Keeping Policy Amending Inaccuracies in Clinical Records Procedure Version 2 Summary: Procedure attached to Clinical Record Keeping Policy. Keywords (minimum of 5): (To assist

More information

Head of Security and Business Continuity. Incident Response and Crisis Management Ser-Sec /11/2017

Head of Security and Business Continuity. Incident Response and Crisis Management Ser-Sec /11/2017 Services Security and Business Continuity Ser-Sec-004 07/11/2017 Author Name Author Job Title Alan Cain Head of Security and Business Continuity Version No. 1.1 EIA Approval Date 28/06/2017 Committee Recommend

More information

The future of patient care. 6 ways workflow automation will transform the healthcare experience

The future of patient care. 6 ways workflow automation will transform the healthcare experience The future of patient care 6 ways workflow automation will transform the healthcare experience Workflow automation: The foundation for improved patient care The patient lifecycle goes through many phases.

More information

Emergency Preparedness

Emergency Preparedness Emergency Preparedness Emergency Preparedness On September 16, 2016 the final rule on Emergency Preparedness requirements for Medicare and Medicaid participating providers and suppliers was published.

More information

REPORT TO MERTON CLINICAL COMMISSIONING GROUP GOVERNING BODY

REPORT TO MERTON CLINICAL COMMISSIONING GROUP GOVERNING BODY REPORT TO MERTON CLINICAL COMMISSIONING GROUP GOVERNING BODY Date of Meeting: 28 May 2015 Agenda No: 6.4 Attachment: 09 Title of Document: Emergency Preparedness Response and Resilience (EPRR) Policy v0.1

More information

Implied Consent Model and Permission to View

Implied Consent Model and Permission to View NHS CRS - Summary Care Record, Implied consent model and Permission to view Programme NPFIT Document Record ID Key Sub-Prog / Project Summary Care Record NPFIT-SCR-SCRDOCS-0025.02 Prog. Director James

More information

PMA Business Continuity Plan

PMA Business Continuity Plan 1 PMA Business Continuity Plan Emergency notification contacts Name Address Home Mobile phone Ian Jones ian@delegatecentral.com ian@practicemanagersuk.org ian.ljones@tiscali.co.uk 01606 44945 07880 788985

More information

MODELS FOR BUSINESS CONTINUITY PLANNING

MODELS FOR BUSINESS CONTINUITY PLANNING MODELS FOR BUSINESS CONTINUITY PLANNING Case Study DEVELOPING A LOCAL CAMPUS BCP MODEL FIRE AT HARROW SITE-July 2007 Andy Norris Business Continuity Planning Executive Officer HEBCoN 1 st ANNUAL SEMINAR

More information

Security Risk Analysis and 365 Days of Meaningful Use. Rodney Gauna & Val Tuerk, Object Health

Security Risk Analysis and 365 Days of Meaningful Use. Rodney Gauna & Val Tuerk, Object Health Security Risk Analysis and 365 Days of Meaningful Use Rodney Gauna & Val Tuerk, Object Health 2 3 Agenda Guidelines for Conducting a Security Risk Analysis Scope of Analysis Risk of a Breach Security Risks

More information

BCM in the Bundesbank Crisis management at the Bundesbank Christoph Stute October 2015

BCM in the Bundesbank Crisis management at the Bundesbank Christoph Stute October 2015 BCM in the Bundesbank Crisis management at the Bundesbank Christoph Stute October 2015 Agenda Crisis management at the DEUTSCHE BUNDESBANK Definition, Scope Organisation (roles and responsibilities) Procedures

More information

CAMBRIDGESHIRE COMMUNITY SERVICES NHS TRUST BUSINESS CONTINUITY PLAN VERSION 7.0

CAMBRIDGESHIRE COMMUNITY SERVICES NHS TRUST BUSINESS CONTINUITY PLAN VERSION 7.0 CAMBRIDGESHIRE COMMUNITY SERVICES NHS TRUST BUSINESS CONTINUITY PLAN VERSION 7.0 Page 1 of 39 DOCUMENT PROCESS AND CONTROL Title: Synopsis: Who is it for: Cambridgeshire Community Services NHS Trust Business

More information

The impact of a flu or norovirus outbreak could have a significant impact on health and social services and could involve:

The impact of a flu or norovirus outbreak could have a significant impact on health and social services and could involve: NHS National Waiting Times Centre Winter Plan 2010/11 Introduction This plan outlines the proposed action that would be taken to deliver our key business objectives supported by contingency planning. This

More information

ATTACHMENT A STATEMENT OF WORK Request for Quotes (RFQ) PennDOT Specific Traffic Signal Training Solicitation Number:

ATTACHMENT A STATEMENT OF WORK Request for Quotes (RFQ) PennDOT Specific Traffic Signal Training Solicitation Number: ATTACHMENT A STATEMENT OF WORK Request for Quotes (RFQ) PennDOT Specific Traffic Signal Training Solicitation Number: 6100029511 OBJECTIVE - The objective of this project is to conduct and to develop/revise/modify

More information

DATA PROTECTION POLICY

DATA PROTECTION POLICY DATA PROTECTION POLICY Document Number 2010/35/V1 Document Title Data Protection Policy Author Nic McCullagh Author s Job Title Information Governance Manager Department IM&T Ratifying Committee Capacity

More information

NHS England (South) Surge Management Framework

NHS England (South) Surge Management Framework NHS England (South) Surge Management Framework THIS PAGE HAS BEEN LEFT INTENTIONALLY BLANK 2 NHS England (South) Surge Management Framework Version number: 1.0 First published: August 2015 Prepared by:

More information

Corporate Business Continuity Plan. Alison Whitehead, Head of Resilience. Fiona Noden, Director of Operations and Performance

Corporate Business Continuity Plan. Alison Whitehead, Head of Resilience. Fiona Noden, Director of Operations and Performance Trust Board Agenda Item 12. Date: 25.06.14 Title of Report Purpose of the report and the key issues for consideration/decision Corporate Business Continuity Plan The Corporate Business Continuity Plan

More information

Board Report In Public Meeting Title of Paper Information Governance Annual Report inc. Caldicott Guardian Annual Activity/Assurance Reports Author(s)

Board Report In Public Meeting Title of Paper Information Governance Annual Report inc. Caldicott Guardian Annual Activity/Assurance Reports Author(s) Item 18.1 Board Report In Public Meeting Title of Paper Information Governance Annual Report inc. Caldicott Guardian Annual Activity/Assurance Reports Author(s) Sadie Bell, Head of Information Governance

More information

Business Continuity Plan

Business Continuity Plan 1 Business Continuity Plan 2 Buckton Vale Primary has the following Critical Objectives, which must be maintained: Provide Education Care and Safety of children, staff and public Provision of meals Provision

More information

Continuity of Operations Plan for the. Kalamazoo Area Transportation Study. Approved: October 28, Kalamazoo Area Transportation Study

Continuity of Operations Plan for the. Kalamazoo Area Transportation Study. Approved: October 28, Kalamazoo Area Transportation Study Approved: October 28, 2015 Continuity of Operations Plan for the Kalamazoo Area Transportation Study Kalamazoo Area Transportation Study Primary Contact: Jonathan R. Start Executive Director 5220 Lovers

More information

Business Continuity Management Policy and Plan Contacts removed

Business Continuity Management Policy and Plan Contacts removed Business Continuity Management Policy and Plan Contacts removed VERSION CONTROL Version: 5.0 Ratified by: Governing Body Date ratified: 20 September 2017 Name of originator/author: Name of reviewers: Name

More information

CHARITIES ONLINE: GIFT AID - BRIEFING FOR MEMBERS 30 th November 2012

CHARITIES ONLINE: GIFT AID - BRIEFING FOR MEMBERS 30 th November 2012 CHARITIES ONLINE: GIFT AID - BRIEFING FOR MEMBERS 30 th November 2012 1. Introduction At Budget 2011, the Chancellor announced that HMRC will introduce a new system which will enable charities and Community

More information

Strategy for resilience and business continuity

Strategy for resilience and business continuity Strategy for Resilience and Business Continuity Date: 13 th August 2014 Version number: 2.0 Author: Dr Sarah Taylor, Director of Public Health Review Date: August 2017 If you would like this document in

More information

Emergency Preparedness, Are You Ready?

Emergency Preparedness, Are You Ready? Emergency Preparedness, Are You Ready? Dr. Anna Fisher Copyright Hillcrest Health Services Objectives Understand that emergency preparedness involves a cycle of planning, capability development, training,

More information

East Cheshire NHS Trust VitalPAC Business Continuity

East Cheshire NHS Trust VitalPAC Business Continuity East Cheshire NHS Trust VitalPAC Business Continuity Page 1 Document Title: Executive Summary: This plan provides clear instructions on Business Continuity when VitalPAC functions are unavailable Supersedes:

More information

Table 1: Types of Emergencies Potentially Affecting Urgent Care Centers o Chemical Emergency

Table 1: Types of Emergencies Potentially Affecting Urgent Care Centers o Chemical Emergency Developing an Emergency Preparedness Plan Alan A. Ayers, MBA, MAcc Content Advisor, Urgent Care Association of America Associate Editor, Journal of Urgent Care Medicine Vice President, Concentra Urgent

More information

Managing Job Requisitions. Contingent Workforce Solutions Training for Client Users

Managing Job Requisitions. Contingent Workforce Solutions Training for Client Users Managing Job Requisitions Contingent Workforce Solutions Training for Client Users *************************************************************************** NOTE: Screen shots in this job aid are examples

More information

We are the regulator: Our job is to check whether hospitals, care homes and care services are meeting essential standards.

We are the regulator: Our job is to check whether hospitals, care homes and care services are meeting essential standards. Inspection Report We are the regulator: Our job is to check whether hospitals, care homes and care services are meeting essential standards. Waterside Care Centre Leigh Sinton, Malvern, WR13 5EQ Tel: 01886833706

More information

BUSINESS CONTINUITY PLAN

BUSINESS CONTINUITY PLAN BUSINESS CONTINUITY PLAN Version 1.4 Name of Director Lead Marie Price Name of author Lisa Wood Date issued September 2016 Review date October 2017 Target audience All BHR CCGs Staff To be read in conjunction

More information

THE CODE. Professional standards of conduct, ethics and performance for pharmacists in Northern Ireland. Effective from 1 March 2016

THE CODE. Professional standards of conduct, ethics and performance for pharmacists in Northern Ireland. Effective from 1 March 2016 THE CODE Professional standards of conduct, ethics and performance for pharmacists in Northern Ireland Effective from 1 March 2016 PRINCIPLE 1: ALWAYS PUT THE PATIENT FIRST PRINCIPLE 2: PROVIDE A SAFE

More information

National Diabetes Audit Implementation Guidance

National Diabetes Audit Implementation Guidance National Diabetes Audit Implementation Guidance Published 20 th March 2017 Copyright 2017 Health and Social Care Information Centre. The Health and Social Care Information Centre is a non-departmental

More information

Renewal Inspection Report. Ninewells Hospital Date of Inspection: 13 May 2009 Date of Licence Committee: 12 August 2009

Renewal Inspection Report. Ninewells Hospital Date of Inspection: 13 May 2009 Date of Licence Committee: 12 August 2009 Renewal Inspection Report Ninewells Hospital 0004 Date of Inspection: 13 May 2009 Date of Licence Committee: 12 August 2009 0004 Page 1 of 22 Centre Details Person Responsible Nominal Licensee Centre name

More information

Vacancy Announcement

Vacancy Announcement Vacancy Announcement ***When applying for this position, refer to "POSITION # 5345" on your application package.*** POSITION: Cybersecurity Senior Specialist (#5345) DEPARTMENT: Cybersecurity / Systems

More information

Helping healthcare: How Clinical Desktop can enrich patient care

Helping healthcare: How Clinical Desktop can enrich patient care Helping healthcare: How Clinical Desktop can enrich patient care Microsoft UK, 2013 Technology should essentially be about delivering benefits for the whole Trust, from clinical staff using the desktop

More information

Security Risk Analysis

Security Risk Analysis Security Risk Analysis Risk analysis and risk management may be performed by reviewing and answering the following questions and keeping this review (with date and signature) for evidence of this analysis.

More information

Internal Audit. Health and Safety Governance. November Report Assessment

Internal Audit. Health and Safety Governance. November Report Assessment November 2015 Report Assessment G G G A G This report has been prepared solely for internal use as part of NHS Lothian s internal audit service. No part of this report should be made available, quoted

More information

DISASTER CRISIS / CRITICAL INCIDENT MANAGEMENT POLICY

DISASTER CRISIS / CRITICAL INCIDENT MANAGEMENT POLICY DISASTER CRISIS / CRITICAL INCIDENT MANAGEMENT POLICY This is a Trust-Wide Policy which applies to all the schools within the Trust Date of Policy Approval: 2 March 2015 Owner of Policy: Head of Facilities

More information

The software that powers HOME HEALTH. THERAPY. PRIVATE DUTY. HOSPICE

The software that powers HOME HEALTH. THERAPY. PRIVATE DUTY. HOSPICE Today s educational presentation is provided by The software that powers HOME HEALTH. THERAPY. PRIVATE DUTY. HOSPICE 877.399.6538 sales@kinnser.com www.kinnser.com About the presenter SHARON HARDER President

More information

Sandwell and West Birmingham NHS Trust Occupational Health and Wellbeing service Accredited July 1 st 2011

Sandwell and West Birmingham NHS Trust Occupational Health and Wellbeing service Accredited July 1 st 2011 Sandwell and West Birmingham NHS Trust Occupational Health and Wellbeing service Accredited July 1 st 2011 SEQOHS accreditation SEQOHS introduction Brief service overview Reasons for going for accreditation

More information

Agenda item 8.5. Meeting date: Meeting / committee: Board of Directors. 24 th June Title: Emergency Preparedness Annual Report 2013/14.

Agenda item 8.5. Meeting date: Meeting / committee: Board of Directors. 24 th June Title: Emergency Preparedness Annual Report 2013/14. Agenda item 8.5 Meeting / committee: Board of Directors Meeting date: 24 th June 2014 Title: Preparedness Annual Report 2013/14 Purpose: This report outlines and summarises the activities and actions undertaken

More information

Date ratified November Review Date November This Policy supersedes the following document which must now be destroyed:

Date ratified November Review Date November This Policy supersedes the following document which must now be destroyed: Document Title Reference Number Lead Officer Author(s) (name and designation) Ratified by Cleaning Policy NTW(O)71 James Duncan Deputy Chief Executive / Executive Director of Finance Steve Blackburn Deputy

More information

Trust Business Continuity Plan

Trust Business Continuity Plan Trust Business Version No Version 3 Date November 2014 Greg arrison Author(s) Review date November 2015 Contact person: Greg arrison Planning & Performance anager/ Emergency Planning anager Tel: 0114 2263361/07792

More information

Babylon Healthcare Services

Babylon Healthcare Services Babylon Healthcare Services Limited Babylon Healthcare Services Ltd. Inspection report 60 Sloane Avenue London SW3 3DD Tel: 0207 1000762 Website: www.babylonhealth.com Date of inspection visit: 4 July

More information

Emergency Preparedness, Resilience & Response (EPRR) 2016/17 Annual Report Public Board 28th September 2017

Emergency Preparedness, Resilience & Response (EPRR) 2016/17 Annual Report Public Board 28th September 2017 Agenda item 14.4 BLUE BOX Emergency Preparedness, Resilience & Response (EPRR) 2016/17 Annual Report Public Board 28th September 2017 Presented for: Presented by: Author: Previous Committees: Assurance

More information

SIGNIFICANT ADVERSE EVENT REVIEW REPORT WEB MALWARE INCIDENT

SIGNIFICANT ADVERSE EVENT REVIEW REPORT WEB MALWARE INCIDENT Report Author(s) Commissioned By SIGNIFICANT ADVERSE EVENT REVIEW REPORT Kerri Todd, AHPM Lesley Anne Smith, DoQ Calum Campbell, Chief Executive, NHS Lanarkshire Incident Date 12/05/2017 Date of notification

More information

CEMP Criteria for Adult Day Care Centers Emergency Management

CEMP Criteria for Adult Day Care Centers Emergency Management CEMP Criteria for Adult Day Care Centers Lee County Emergency Management The following criteria are to be used for the development of Comprehensive Emergency Management Plans (CEMP) for Adult Day Care

More information

CLINICAL SERVICES POLICY & PROCEDURE (CSPP No. 25) Clinical Photography Policy in the Pre-Hospital Setting. January 2017

CLINICAL SERVICES POLICY & PROCEDURE (CSPP No. 25) Clinical Photography Policy in the Pre-Hospital Setting. January 2017 CLINICAL SERVICES POLICY & PROCEDURE (CSPP No. 25) Clinical Photography Policy in the Pre-Hospital Setting January 2017 DOCUMENT INFORMATION Author: Mark Ainsworth-Smith Consultant in Pre-hospital Care

More information

Kingston CCG Emergency Preparedness, Resilience and Response (EPRR) Policy

Kingston CCG Emergency Preparedness, Resilience and Response (EPRR) Policy M7 Kingston CCG Emergency Preparedness, Resilience and Response (EPRR) Policy Author: Luke Lambert Senior Associate Business Resilience, South East CSU Document Control Review and Amendment History Version

More information

UNIVERSITY OF HOUSTON

UNIVERSITY OF HOUSTON UNIVERSITY OF HOUSTON EMERGENCY MANAGEMENT BUSINESS CONTINUITY PLANNING TEMPLATE University of Texas at El Paso School of Nursing All Hazards - Continuity of Operations Plan (COOP) Instructions: To be

More information

Chapter 9 Legal Aspects of Health Information Management

Chapter 9 Legal Aspects of Health Information Management Chapter 9 Legal Aspects of Health Information Management EXERCISE 9-1 Legal and Regulatory Terms 1. T 2. F 3. F 4. F 5. F EXERCISE 9-2 Maintaining the Patient Record in the Normal Course of Business 1.

More information

Disaster / Hurricane Evacuation Plan

Disaster / Hurricane Evacuation Plan Disaster / Hurricane Evacuation Plan Employee Summary Notes All Stat will answer the phone 24 hours a day, by either land lines or cell phone lines. The appropriate phone numbers are: 941-923-0880 Sarasota

More information

Guidance for organisations applying for both registration and licensing as a new service provider

Guidance for organisations applying for both registration and licensing as a new service provider Guidance for organisations applying for both registration and licensing as a new service provider CQC and Monitor have combined the separate application forms to apply for a CQC registration and an NHS

More information

Policy for the Investigation, Analysis and Learning from Incidents, Complaints and Claims

Policy for the Investigation, Analysis and Learning from Incidents, Complaints and Claims Policy for the Investigation, Analysis and Learning from Incidents, Complaints and Claims Please be aware that this printed version of the Policy may NOT be the latest version. Staff are reminded that

More information

Handling Organisational Complaints

Handling Organisational Complaints Council meeting 12 January 2012 Public business Handling Organisational Complaints Purpose To report to the Council on the handling of organisational complaints for the period 27 September 2010 to 30 September

More information

Third Party Trust Manage your outsourcing arrangements

Third Party Trust Manage your outsourcing arrangements Third Party Trust Manage your outsourcing arrangements Who's keeping your promises October 2014 Issue 1 Contents Page MAS Outsourcing Guidelines and Notice 4 Implications of Notice 6 MAS Outsourcing Guidelines

More information

NHS Commissioning Board. Emergency Preparedness. Framework Framework

NHS Commissioning Board. Emergency Preparedness. Framework Framework NHS Commissioning Board NHS Commissioning Board Emergency Emergency Preparedness Framework 2013 Preparedness Framework 2013-1 - NHS Commissioning Board Emergency Preparedness Framework 2013 Date 21 March

More information

Northfield Lodge Care Home Service

Northfield Lodge Care Home Service Northfield Lodge Care Home Service Provost Fraser Drive Northfield Aberdeen AB16 7JY Telephone: 01224 680606 Type of inspection: Unannounced Inspection completed on: 10 August 2016 Service provided by:

More information

We are the regulator: Our job is to check whether hospitals, care homes and care services are meeting essential standards.

We are the regulator: Our job is to check whether hospitals, care homes and care services are meeting essential standards. Inspection Report We are the regulator: Our job is to check whether hospitals, care homes and care services are meeting essential standards. Clarence House Nursing Home Clarence House, Albert Street, Brigg,

More information

EMERGENCY PREPAREDNESS CHECKLIST RECOMMENDED TOOL FOR EFFECTIVE HEALTH CARE FACILITY PLANNING

EMERGENCY PREPAREDNESS CHECKLIST RECOMMENDED TOOL FOR EFFECTIVE HEALTH CARE FACILITY PLANNING Develop Emergency Plan: Gather all available relevant information when developing the emergency plan. This information includes, but is not limited to: Copies of any state and local emergency planning

More information

4.2. Clinical Trial Monitor (or Monitor): The person responsible for monitoring the data on behalf of the sponsor or contract research organization.

4.2. Clinical Trial Monitor (or Monitor): The person responsible for monitoring the data on behalf of the sponsor or contract research organization. SOP #: MON-101 Page: 1 of 6 1. POLICY STATEMENT: The DF/HCC understands that external sponsors are required to monitor the progress of clinical investigations and ensure appropriate research data collection

More information

Preceptorship Framework for Newly Qualified Nurses, Midwives and Allied Health Professionals

Preceptorship Framework for Newly Qualified Nurses, Midwives and Allied Health Professionals Preceptorship Framework for Newly Qualified Nurses, Midwives and Allied Health Professionals : May 2012 Review date: May 2014 Author: Deborah Dent with acknowledgments to the members of the task & finish

More information

Discussion Assurance Approval Regulatory requirement Mark relevant box with X

Discussion Assurance Approval Regulatory requirement Mark relevant box with X Report to: Board of Directors Date of Meeting: 26 July 2017 Report Title: Emergency Preparedness, Resilience and Response (EPRR) 2016/17 Annual Report, Policy and Major Incident Plan Status: For information

More information

3 ESF 3 Public Works and. Engineering

3 ESF 3 Public Works and. Engineering 3 ESF 3 Public Works and Engineering THIS PAGE LEFT BLANK INTENTIONALLY ESF 3 Public Works and Engineering Table of Contents 1 Purpose and Scope... ESF 3-1 2 Policies and Agreements... ESF 3-1 3 Situation

More information

Request for Quotation

Request for Quotation Request for Quotation For support and preparation of the Cambridge Future Cities Stage 2 Large Scale Demonstrator feasibility study and final report production www.cambridgeshire.gov.uk TSB Future Cities

More information

We are the regulator: Our job is to check whether hospitals, care homes and care services are meeting essential standards.

We are the regulator: Our job is to check whether hospitals, care homes and care services are meeting essential standards. Inspection Report We are the regulator: Our job is to check whether hospitals, care homes and care services are meeting essential standards. The Old Vicarage Bullock Lane, Ironville, Nottingham, NG16 5NP

More information

Business Continuity Plan

Business Continuity Plan San Francisco VA Health Care System (SFVAHCS) San Francisco, California Business Continuity Plan Service/Department Name Version Date: Version: Date 29 Contents Business Continuity Plan Overview... 3 BCP

More information

Clinical Risk Management: Agile Development Implementation Guidance

Clinical Risk Management: Agile Development Implementation Guidance Document filename: NPFIT-FNT-TO-TOCLNSA-1306.03 CRM Agile Development Implementation Guidance v1.1 Directorate / Programme Solution Design Standards and Assurance Project Clinical Risk Management Document

More information

Unit 11: Business Sector Recovery

Unit 11: Business Sector Recovery Unit Introduction Visual 11.1 Recovery of a community s business sector is an essential element in the overall picture of a community s health and vitality. When citizens can see businesses reopen and

More information

SECTION EARTHQUAKE

SECTION EARTHQUAKE SECTION 11.14 EARTHQUAKE PROCEDURES TO BE FOLLOWED IN THE EVENT THAT A SIGNIFICANT EARTHQUAKE AFFECTS LOMA LINDA UNIVERSITY MEDICAL CENTER PREPARATION Education and Training: 1. The Safety Officers oversee

More information

Research Code of Practice

Research Code of Practice National Foundation for Educational Research Research Code of Practice Why have a Code of Practice? A wide range of individuals and organisations contribute to the work carried out by the National Foundation

More information

Policy to Manage. Information and Records

Policy to Manage. Information and Records Policy to Manage Information and Records V3.0 October 2017 Page 1 of 108 Table of Contents 1. Introduction... 3 2. Purpose of this Policy/Procedure... 4 3. Scope... 5 4. Definitions / Glossary... 7 5.

More information

Road Fuel Supply Disruption: Strategic Guidance for NHS Boards in Scotland. NHSScotland Resilience. Scottish Government

Road Fuel Supply Disruption: Strategic Guidance for NHS Boards in Scotland. NHSScotland Resilience. Scottish Government 1 Document Control Document Title Road Fuel Supply Disruption: Strategic Guidance for NHS Boards in Scotland Owner & contact details Scottish Government Sponsor Area Publication Date Future Review Date

More information

EMERGENCY PREPAREDNESS, RESILIENCE & RESPONSE POLICY

EMERGENCY PREPAREDNESS, RESILIENCE & RESPONSE POLICY EMERGENCY PREPAREDNESS, RESILIENCE & RESPONSE POLICY Last Review Date Approving Body N/A Governing Body Date of Approval 21 st November 2013 Date of Implementation 1 st December 2013 Next Review Date November

More information

PETERBOROUGH SAFEGUARDING ADULTS BOARD (PSAB) MULTI-AGENCY TRAINING STRATEGY

PETERBOROUGH SAFEGUARDING ADULTS BOARD (PSAB) MULTI-AGENCY TRAINING STRATEGY SAFEGUARDING ADULTS PETERBOROUGH SAFEGUARDING ADULTS BOARD (PSAB) MULTI-AGENCY TRAINING STRATEGY 2012/2013 Peterborough Safeguarding Adults Board Multi-Agency Training Sub-Group Training Strategy Introduction

More information

Agenda Item. NHS Cumbria CCG Governing Body. 4 February Business Continuity Plan. Purpose of Report:

Agenda Item. NHS Cumbria CCG Governing Body. 4 February Business Continuity Plan. Purpose of Report: NHS Cumbria CCG Governing Body Agenda Item 4 February 2015 9 Business Continuity Plan Purpose of Report: Under the Civil Contingencies Act, Clinical Commissioning Groups have a duty to put in place business

More information