4. The DSPT and incidents
Incidents and near misses
A data security incident is anything that puts personal information at risk: loss, theft, wrong disclosure, unauthorised access, or destruction. A near miss is an incident that almost happened or was caught before harm was done, like noticing a letter is misaddressed before it is posted.
The common ones in care
Most incidents in health and care are mundane, which is exactly why they keep happening:
- Misdirected correspondence: a letter, discharge summary or care plan posted or faxed to the wrong address, or handed to the wrong family member.
- Wrong recipient in email: an autocomplete mistake sending details to the wrong person, attaching the wrong document, or putting a group of addresses in To or Cc instead of Bcc so every recipient sees the others.
- Lost paperwork: handover sheets, MAR charts, notes and diaries left on buses, in cars, or in ordinary bins instead of confidential waste.
- Records accessed without a need to know, phones and laptops lost or stolen, and conversations overheard.
Report fast, without fear
If you cause, discover or even suspect an incident or near miss, report it to your manager or data protection lead immediately, the same day. Speed matters for two reasons. First, quick action limits harm: a wrongly sent email can sometimes be recalled, a recipient contacted, a lost device wiped remotely. Second, the clock may be running: where a breach is likely to risk people's rights and freedoms, the organisation must report it to the ICO within 72 hours of becoming aware, and health and care organisations use the DSPT incident reporting route for notifiable incidents. People affected must be told without undue delay when the risk to them is high.
Never sit on an incident hoping it resolves itself, and never try to cover one up. Concealing a breach is treated far more seriously than making an honest mistake. Good organisations run a learning culture, not a blame culture: near misses are gifts, because they show where the process is weak while there is still time to fix it, and standard 5 of the data security standards expects exactly that.
› Course contents
Why care data is different
The rules of sharing
Everyday practice
The DSPT and incidents