Secure and Compliant
Cyber Essentials
NHS Data Security and Protection Toolkit
ISO 27001 Data Centre
UK GDPR Compliant
G-Cloud Crown Commercial Service Approved Supplier
PCI DSS Validated
ICO Registered
WCAG 2.2 (Level AA) Compliant
From the 23rd of September 2020 the websites of public sector bodies, including GP Surgeries, were required to meet a certain accessibility standard (WCAG 2.1, Level AA). Since October 2023, the required standard is WCAG 2.2 Level AA.
NHS Design Guidelines and Benchmarking Tool Compliant
Our latest templates fully comply with new NHS Design guidelines and the design/structural elements of the NHS Benchmarking audit tool.
HTTPS
Every page of your Practice Website with us is https-secured. This means communication between the patient’s web browser and the server hosting the website is encrypted and cannot be intercepted en route. It also means a padlock icon is visible in the browser address bar at all times, on every page, which reassures patients that they are on a secure site.
This is the only way that your patients can be certain the content they see on your website has not been intercepted and changed.
We achieve the highest possible rating of A+ in tests by SSLLabs on the security & encryption quality of our HTTPS connection.
Data Security & GDPR
Your Practice Website needs to comply with the General Data Protection Regulations (GDPR), introduced in May 2018.
Our system gives you full control over information sent to you by patients through your Website.
Information submitted through contact forms is only retained for a set period of time before being automatically deleted, complying with the GDPR requirement to only retain personal data as long as it is required. The retention period for data submitted through the Friends & Family Test or Practice Surveys can be set by the Practice.
All information submitted through secure forms is encrypted and can only be accessed by nominated Practice staff over a secure connection.
Each form on our GP Websites automatically includes a comprehensive privacy statement and a box which the patient must tick to indicate their consent to the information being used for the purposes indicated. The privacy statement on each contact form can be customised as required.
Each of our Practice Websites includes an automatically generated 'Website Privacy' page which describes all information collected by the Website and how it is safely handled.
Data Storage
All Website data is stored in a secure, ISO/IEC 27001 certified data centre. ISO/IEC 27001 demonstrates best practice for an information security management system. Servers are proactively monitored for security, are virus scanned and are backed-up on a daily basis.
A range of technical steps are taken to ensure only authorised users can access the data submitted through your Website or can edit Website content. All content entered by Practice staff into websites is also scanned for potential issues.
Patients can be confident that their information is safe.
Our GP Website system was purpose-built from day one by a world class development team. It is bespoke and is not based on a free system such as Wordpress.
Oldroyd Publishing Group is Cyber Essentials certified.
We are registered with the Information Commissioner's Office.
ICO Registration Numbers
Oldroyd Publishing Group Ltd - Z4956631
Neighbourhood Direct Ltd - Z4874377