Digital Systems Cyber Security and DSPT policy
For CQC-registered domiciliary care services · version 1.0 · last reviewed 1 June 2026
Because care records now sit on digital systems, cyber security duties follow, and the Data Security and Protection Toolkit is the framework used here. Access control and authentication, securing devices used out in the community, protecting against phishing and ransomware, backups and resilience, and checks on suppliers and processors are all covered.
What this policy covers
- Why cyber security matters in care
- The framework — dspt, standards and the law
- The data security and protection toolkit
- Access control and authentication
- Device security
- Protecting against threats — phishing and ransomware
- Backups and resilience
- Suppliers and processors
- Cyber incidents
- Everyone’s responsibilities
- Data protection / caldicott lead
- Annex a — cyber security do’s and don’ts (staff)
Regulations and guidance it supports
Supports the fundamental standards at Regulations 12, 17 and 20 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014.
- Data Protection Act 2018
- Data (Use and Access) Act 2025 (G01)
Common questions
- Is the digital systems cyber security and dspt policy CQC-aligned?
- Yes. It is written and reviewed by practising UK compliance consultants against current CQC expectations, and supports the fundamental standards at Regulations 12, 17 and 20. It is a controlled starting-point document that you adapt to your own service — you remain the accountable provider.
- Can I download and edit this policy?
- Yes. It downloads as Word (.docx) or PDF with your company name, registered manager, CQC ID and address already filled in on the cover page and throughout the document. The Word version is fully editable.
- Can I buy this policy on its own?
- Policies are sold as a complete library rather than individually, because CQC expects a coherent set that cross-references properly — a single policy in isolation creates gaps. The domiciliary care library contains 141 policies and can be bought outright as a one-off purchase and kept permanently.
- How often is it reviewed?
- The library is re-reviewed every six months and after any material regulatory change. This policy was last reviewed 1 June 2026, and is at version 1.0. Updates reach you automatically, so downloads always reflect the current version.