Neurodivergent Speech Therapist in Kent - Jamie Louise Hollis - ADHD SLT

information security policy

Date reviewed: 12th march 2026

Effective Date: 2nd November 2023

Next Review Due: 12th march 2027

1: introduction

This Information Security Policy outlines the measures I take to protect the confidentiality, integrity, and availability of information within my practice. As the sole practitioner at ADHD SLT, I am responsible for maintaining information security procedures and ensuring that personal data is handled securely. Ensuring the security of your personal data is a top priority, and this policy defines how I safeguard your information from unauthorised access, disclosure, alteration, and destruction. As a speech and language therapist, I agree to the standards of proficiency as set out by Health and Care Professions Council.

This policy supports compliance with UK GDPR, the Data Protection Act 2018, and professional standards set by the Health and Care Professions Council (HCPC).

2: purpose of the policy

The purpose of this policy is to:

  • Protect personal and sensitive data against security threats.
  • Ensure compliance with legal and regulatory requirements.
  • Maintain trust and confidence with clients by securing their information.

3: scope

This policy applies to all information handled within my practice, including:

  • Personal and sensitive client data.
  • Therapy records and communication.
  • Digital and physical information storage.

4: data security measures

To safeguard your information, I employ the following security measures:

  • Physical Security:
  • Document Storage: All physical documents containing personal data are stored in a locked filing cabinet.
  • Office Security: Access to the office is restricted to authorised individuals only.
  • Digital Security:
  • Encryption: Sensitive data, including digital records, is encrypted both in transit and at rest.
  • Secure Access: Access to digital records is protected by strong passwords and, where applicable, multi-factor authentication.
  • Software Security: Antivirus and anti-malware software are regularly updated to protect against threats.
  • Data Backups:
  • Backup Procedures: Regular backups of digital data are performed to ensure data can be restored in case of loss or corruption.
  • Secure Storage: Backup data is stored securely, with encryption applied to protect against unauthorised access.
  • Strong passwords are used to protect devices and systems. Passwords are kept confidential and changed periodically where appropriate.
  • All devices used to access or store client data are protected by passwords and appropriate security settings to reduce the risk of unauthorised access.

5: access control

I enforce access control measures to ensure that only authorised individuals can access personal and sensitive information:

  • Access to client data is restricted to the practitioner unless disclosure is required for clinical care, safeguarding, or legal reasons.
  • Authentication: Strong authentication methods are used to control access to digital systems and information.

6: Data handling and transmission

I take the following precautions when handling and transmitting information:

  • Data Handling: Information is handled with care, and sensitive data is not left unattended or accessible to unauthorised individuals.
  • Data Transmission: When transmitting data electronically, secure methods such as encrypted email or secure file transfer protocols are used.
  • When personal data is no longer required and the retention period has expired, records are securely destroyed or permanently deleted in accordance with data protection requirements.

7: incident response

In the event of a data security incident, I follow a structured incident response plan:

  • Detection: Monitoring systems and procedures are in place to detect potential security incidents.
  • Response: An immediate response is initiated to contain and mitigate the impact of the incident.
  • Notification: Affected individuals and relevant authorities are notified as required by law.
  • Review: Incidents are reviewed to identify causes and improve security measures.
  • Data security incidents will be managed in accordance with the Data Breach Policy, which outlines procedures for assessing, reporting, and documenting breaches.

8: student training

I ensure that all students under my supervision receive appropriate training regarding information security and data protection:

  • Training Programs: Students receive regular training on data protection principles and information security best practices to ensure they understand their responsibilities.
  • Awareness: Students are educated about potential security threats and the importance of safeguarding client information.

9: policy review

This Information Security Policy is reviewed periodically to ensure it remains effective and compliant with current regulations and best practices. Updates are made as necessary, and changes are communicated through my website and directly to affected individuals if applicable.

10: contact

If you have any questions or concerns regarding this Information Security Policy or the security of your information, please contact me at:

Jamie Louise Hollis
Email: adhdslt@outlook.com

Signed: Jamie Louise Hollis
Job Title: Speech and Language Therapist