Security & Compliance

MyCareAudit is built with enterprise-grade security measures, full GDPR compliance, and alignment with the NHS Data Security and Protection Toolkit (DSPT).

GDPR Compliant NHS DSPT Aligned TLS 1.3 Encrypted SOC 2 Infrastructure Daily Backups

Security Measures

NHS DSPT 3.2

Encryption at Rest & In Transit

All data is encrypted using AES-256 at rest and TLS 1.3 in transit. HSTS is enforced with a 2-year max-age and preload directive.

NHS DSPT 4.2

Strong Authentication

NHS DSPT-compliant password policy (10+ chars, mixed case, numbers, symbols). Account lockout after 5 failed attempts. 8-hour session timeout.

NHS DSPT 7.1

Comprehensive Audit Trails

Every login, data access, admin action, and security event is logged with IP address, timestamp, and user agent. Logs retained for minimum 12 months.

OWASP

Security Headers & XSS Protection

Content Security Policy, X-Content-Type-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, CORS, and frame protection headers on every response.

NHS DSPT 4.3

Rate Limiting & Brute Force Protection

IP-based rate limiting on all authentication endpoints. Progressive lockout on failed login attempts. Automated suspicious activity detection.

NHS DSPT 3.4

Data Isolation & Access Control

Multi-tenant architecture with strict data isolation. Role-based access control (RBAC) with 5 granular roles and 40+ permissions. Team members only see their organisation’s data.

GDPR Art. 15-20

GDPR Data Subject Rights

Self-service data export (JSON/CSV), right to erasure (account deletion requests), data portability, and Subject Access Request (SAR) processing.

PECR / GDPR

Cookie Consent & PECR

Granular cookie consent banner with essential, analytics, and preference categories. Full compliance with UK PECR and EU ePrivacy regulations.

OWASP Top 10

Secure API Architecture

All API endpoints require authentication. Input sanitisation prevents SQL injection and XSS. Parameterised queries via Prisma ORM eliminate injection vectors.

NHS DSPT 6.1

Incident Response & Monitoring

Real-time security event monitoring with severity classification. Critical events trigger immediate alerts. Comprehensive incident response procedures.

NHS DSPT 5.1

Infrastructure Security

Hosted on enterprise-grade cloud infrastructure with automated backups, disaster recovery, and 99.9% uptime SLA. Daily encrypted database backups with 30-day retention.

NHS DSPT 3.5

Data Retention & Disposal

Configurable data retention policies aligned with CQC record-keeping requirements. Secure data disposal with cryptographic erasure for deleted accounts.

NHS Data Security & Protection Toolkit

MyCareAudit\u2019s security controls are designed to align with the 10 data security standards defined by the NHS DSPT, helping care providers demonstrate compliance.

NHS DSPT Standards Alignment
1

Personal Confidential Data

Data classified, access controlled, processing lawful under GDPR Art.6 & Art.9

Aligned
2

Staff Responsibilities

Role-based access, team management, deactivation workflows, audit trails

Aligned
3

Training

Built-in training compliance tracking with mandatory/recommended categorisation

Aligned
4

Managing Data Access

RBAC with 5 roles, 40+ permissions, session management, account lockout

Aligned
5

Process Reviews

Governance dashboards, KPI tracking, compliance timeline, audit scheduling

Aligned
6

Responding to Incidents

Incident reporting, investigation workflows, CQC notification tracking

Aligned
7

Continuity Planning

Daily backups, 30-day retention, disaster recovery, data export tools

Aligned
8

Unsupported Systems

Modern tech stack, regular dependency updates, automated security patching

Aligned
9

IT Protection

TLS 1.3, HSTS, CSP headers, XSS protection, CORS, rate limiting

Aligned
10

Accountable Suppliers

Cloud infrastructure with ISO 27001 certification, GDPR DPA in place

Aligned

GDPR Compliance

Full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

ArticleRequirementHow We Comply
Art. 5PrinciplesLawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity & confidentiality
Art. 6Lawful BasisLegitimate interests for service delivery, consent for marketing, contractual necessity for subscriptions
Art. 9Special CategoriesHealth data processed under explicit consent and substantial public interest (social care provision)
Art. 12-14TransparencyPrivacy policy, cookie policy, terms of service, data processing notices
Art. 15Right of AccessSelf-service data export (JSON/CSV) and formal Subject Access Request processing
Art. 17Right to ErasureAccount deletion requests via Data Requests page with admin processing workflow
Art. 20Data PortabilityFull data export in machine-readable format (JSON/CSV) for all user data categories
Art. 25Data Protection by DesignPrivacy built into architecture: encryption, access controls, data minimisation, audit logging
Art. 32Security of ProcessingEncryption, pseudonymisation, resilience, regular testing, incident response
Art. 33-34Breach NotificationSecurity monitoring, incident detection, notification procedures within 72 hours

Data Processing Principles

  • Data collected only for specified, explicit purposes
  • Minimum data collected for each function
  • Data kept accurate and up to date
  • Retained only as long as necessary
  • Processed with appropriate security measures
  • Transparent processing with clear privacy notices

Your Data Rights

  • Access: Export all your data in JSON or CSV format at any time
  • Rectification: Update your personal information via Settings
  • Erasure: Request account and data deletion
  • Portability: Download data in machine-readable format
  • Restriction: Request restriction of processing
  • Objection: Object to processing for direct marketing
Read our full Privacy Policy →

Questions About Security?

Our Data Protection Officer is available to answer any security or compliance questions.