Skip to content
All posts

Help employees care about data

Watch the TSC webinar on helping healthcare employees care about data, covering patient data protection, DSPT compliance, supply chain risk, SolarWinds and WannaCry-style threats, and how to build secure behaviours across health and care teams.

Your people care about patients. How do you get them to care about data?

The health and care sector is one of the most targeted in the country because it holds some of the most sensitive data that exists. But the people on the front line are focused on patients, not data flows. With around one million GP appointments and 50,000 A&E visits every day, even a short period of disruption can have a real human impact. This webinar explores how to help every individual understand the value of the data they handle, work securely and connect data protection directly to patient care.

Featuring TSC's Head of Communications and the Department of Health and Social Care's Data Protection Officer, the session examines DSPT compliance, secure culture, human risk, supply chain exposure, interrelated systems and the importance of moving towards a just culture. Drawing on real ICO cases, WannaCry, SolarWinds and everyday examples from health and care, it sets out a practical building-block approach to raising awareness, sustaining behaviour change and making data protection an enabler rather than a blocker.

Essential viewing for anyone responsible for healthcare data protection, DSPT compliance, cyber security awareness, secure culture or patient data security.

In this webinar, you'll discover:

Why the health and care sector is such a high-value target for cyber criminals
How to connect secure behaviours back to the patients your people care about
What the DSPT version 6 update means for building a secure, just culture
Why interrelated systems create a cascade of risk across the sector
How supply chain attacks like SolarWinds reach you through trusted providers
Lessons from real ICO breaches, from lost referrals to misdirected emails
A building-block approach to raising awareness and sustaining behaviour change
How to speak the language of the board and treat data protection as an enabler

Turn healthcare data awareness into practical security behaviour

This webinar explores how healthcare employees can connect data protection with patient care. TSC's security awareness training and eLearning modules help your people understand the value of the data they handle, recognise everyday risks and build safer behaviours across health and care teams.

Book eLearning demo


View full webinar transcript

Introduction

The people on the front line in your organisations are there to support and care for the people using your services. But behind that care is a whole infrastructure of data flowing in the background, and the individual can't do their job without it. So the key question for this webinar is: how do we empower the people who clearly care about the people they support to also care about the data, and all the things going on behind the scenes? If we can build a culture where there's an understanding of the value of data, the importance of protecting it, and how it underpins the work with patients, you'll have a genuinely secure culture in your workplace.

Over the next hour we'll cover the context and the challenges, the Data Security and Protection Toolkit (DSPT) from a people perspective, the human factor and the greatest human risk in your organisations, and some of the common blockers to a secure culture along with solutions, all in the context of moving towards what the policy documents call a "just culture".

About TSC and today's focus

For those new to TSC, The Security Company, we've been in this field for around 30 years, supporting organisations across the globe on information and cyber security awareness, and increasingly on behaviour-change solutions to help them build a mature culture. We work with many organisations providing essential services and critical national infrastructure, utilities, transport, food distribution, and health and care. My background is more than 30 years in training and development, and before TSC I worked in care homes, the NHS, the county council and private organisations, so today feels like a coming home, combining that with my information and cyber security experience.

The context: care depends on data

Whatever service you provide, audiology, optometry, dentistry, a care home, radiology, ultimately it's about delivering effective care, and that isn't possible without the technology and data that underpin it. The health sector is at the forefront of integrating artificial intelligence, which is fantastic but brings its own challenges. At the same time you have legacy systems with their own vulnerabilities. So you're operating in a complex technological environment, and the task is to secure it as well as possible to reduce the ever-present risks. Technology and data are critical to the services you provide, and protecting that data is equally critical, because it enables effective care.

Why health and care is a high-value target

We know from the research and the attacks happening that the health and care sector is a high-level target, because of the data you hold. You have some of the most sensitive data there is, and it has high value to criminals, whether they're motivated by disrupting your services, extracting and selling your data, or targeting plans around how you use AI. Whatever the motivation, the sector is susceptible, and attacks cause downtime. The scale is enormous, around a million GP appointments and 50,000 A&E visits every single day, so even one hour of disruption has a massive impact on the people you're focused on.

Interrelated systems and the cascade of risk

What's unique about health and care is that you have interrelated systems. With other clients I might work with organisations that have detailed systems supporting their own structure, but in health and care the systems are interrelated, which adds a whole other level of complexity. If there's an attack on one part, the risk cascades through to other parts of the linked infrastructure.

Supply chain risk

Because the sector is so large, supply chain risks are huge. You can't deliver your services without people supplying parts, products and other elements, so attacks can come through that route. It's important to have a clear view of who's in your supply chain, how they connect to you, what data they handle on your or your patients' behalf, how it's protected, and what due diligence you have in place. And although there's infrastructure at a governmental level, individual organisations still have to take individual responsibility for their information and cyber security.

The attack surface: it's about people

Cyber criminals don't care where you are, which county or country, whether you're in an office or on the move. What they are vigilant about is misconfigurations in your servers, vulnerabilities in your software, and, very importantly, the people who work for you, because people are a route into your systems and your valuable data. So the attack surface is as big as your workforce. As an example, at the start of the pandemic two construction companies named in the press as building the Nightingale hospitals were hit by significant cyber attacks, because criminal networks look for anything new they can disrupt, especially when your attention is elsewhere.

Real-world breaches

These are all open-source examples you can find on the ICO website. As recently as October 2023, an NHS trust failed to protect data from accidental loss; around 5,000 patients were affected, referrals were delayed, and for 570 patients the referral disappeared from the system altogether. In September 2023 someone at a county council sent sensitive personal information about an individual to an abusive ex-partner, creating a whole range of extra risks for the person they were trying to protect. In July 2023 a group of practitioners in an NHS trust set up a WhatsApp group to share patient data, and the trust was penalised by the ICO for sharing data by unauthorised means. The ICO has said the biggest cause of a data breach is simply sending information to the wrong people, including bulk emails where everyone can see everyone else's details. Small things, like not using blind carbon copy, can cause a breach, and we are only custodians of people's data; protecting it is our responsibility.

WannaCry and SolarWinds

We all know the impact of WannaCry in 2017, which has driven a lot of work to strengthen the infrastructure across health and social care. That breach happened because software hadn't been updated, so part of the guidance to people is always to do software updates when prompted, because they patch vulnerabilities and keep criminals out. SolarWinds flipped that. Attackers targeted a software provider with contracts with over 30,000 organisations, planted malware into its Orion IT management software, and when SolarWinds asked everyone to update, the malware spread to all those organisations. It's a supply chain attack: not a direct target on you, but reaching you through the systems and services you buy. So it's about having eyes everywhere.

The building blocks of a secure culture

Through your annual DSPT compliance you know you need to know your people and your processes, and with the version 6 update the focus is very much on building a secure culture. Our building-block approach starts with raising awareness of the risks, threats and good practices, so people understand the value of data and have good cyber hygiene as a daily habit rather than something they consciously think about. Once that foundation is in place, you build skills and knowledge further, help people understand the wider context, and support them to apply secure behaviours day in, day out, then evidence it back on the DSPT. Ultimately it's about maintaining and sustaining behaviour change so it becomes embedded.

Raising awareness and sustaining behaviour

Phishing, malware and ransomware are high-risk areas, so raising awareness means posters, infographics and conversations, making it real, live, open and honest, with no blame culture; it's more important that people report a mistake than hide it. The NHS provides free e-learning, but version 6 of the DSPT also expects consistent messaging and support throughout the year, so supplement e-learning with videos, team discussions, games and animations. Tell people how you want them to behave, because they won't know unless you do, and build in a feedback loop: positive feedback when people do what's expected, and addressing it when they don't, which is what I mean by consequences.

Leadership, feedback and resources

Leadership is critical. If leaders aren't modelling the behaviours you want, you have an inherent challenge, so you need a strategic, embedded approach across the whole organisation. To help, we have a suite of infographics, reminders about passwords, shredding documents, double-checking emails before sending, the difference between anonymised and confidential data, and phishing and social engineering, including the difference between vishing, phishing, smishing and the latest, quishing (QR-code phishing), plus Caldicott principles. We also have games that show how open-source information shared on social media, where you work, how long you've been there, key dates, can be used for spear phishing, and infographics on the vulnerabilities of mobile devices.

The cultural aspect: social norms and storytelling

Because we're human, we look at the people and leaders around us and replicate their behaviour, which is why modelling matters. If people aren't behaving securely, you have to tackle that first to establish the social norms, then ride on peer pressure so secure behaviour becomes the norm. Keep your ear to the ground about how people feel; if they're negative, you have work to do to help them see the benefits, and always bring it back to the patients, because that's why they're there. People learn from stories, so bring it back to a real person. Make secure behaviour easy: if you want people to report phishing, make reporting easy and something people talk about, so it becomes the social norm.

In conversation with Lee: data protection as an enabler

Lee: I'm the data protection officer for the Department of Health and Social Care, and I'm also responsible for cyber security for the department. I started life as an auto electrician, and I've since been a CISO at a large charity and done legal enforcement and performance research, so I understand the data side well. I always ask people: what is your biggest concern or blocker in protecting data for your service? People often think data protection is the problem, but I've spent years explaining that data protection isn't a blocker, it's an enabler. The Caldicott principles, the GMC, "data saves lives", the NHS Long Term Plan, all of this legislation actually encourages you to share data on behalf of the patient.

Lee: One concern from the chat is colleagues being too busy and making mistakes by cutting corners. Linked to that, we tend to build systems in silos. If you look at a care record, how much of that data is actually required to give care, and how much is collected for some other output? Collecting data costs money to store, licence and process, and it costs frontline time too. We ask professionals who've trained for five to seven years to spend a large part of their time inputting data instead of caring for the patient. We build systems for outputs without really understanding the output we want.

Understanding the value of data

Lee: How do you know how much to spend on security if you don't understand the data in the system? The key is getting people to understand the value of that data. Think of it like insuring a shed: you list what's in it, the lawnmower, the strimmer, those are your data assets. With that inventory you can quickly value what's there and decide how much security it warrants; you wouldn't spend £80 on a lock for £50 of tools. And if it's broken into, you know instantly what's missing. Data is the same. When a supplier goes down, the first question everyone asks is "what data went missing?", and most people aren't sure, because we don't understand the data at the outset. A data flow diagram helps. Once you understand the data coming in and its value, you can have real conversations about why it matters, set the right controls, and put proper terms and conditions and roles with your suppliers.

Bringing it back to the patient

BB: To echo Lee, it's the value of the data, but very much the impact on the individuals people support. Bring it back to that: I work for this service, I need to collect this information, I understand why, and if it's lost, the person sitting in front of me will be devastated. Some people are fortunate enough to be setting up new systems and can ask what data they actually need; more often people work with complex existing systems, so it's about understanding what you have, what the data assets are, and the impact of their loss.

Speaking the language of the board

BB: A common chat comment is a lack of awareness or buy-in from senior leadership, and technology being put in too hastily. So part of our job in data security is learning to speak the language of the board. There's an arms race around new technology and AI, and sometimes understanding the data and its flows well actually reveals an opportunity to retire three or four other systems. I liken many of our systems not to a neat jigsaw but to a kaleidoscope, shake it and it's a pretty mishmash that's hard to make sense of.

Lee: When I worked for the fire service, I got them to dispose of a lot of unnecessary data by learning what mattered to them. They were struggling to fund firefighters, so I showed that deleting a certain amount of data would pay for three new firefighters a year. It's about speaking the board's language, which is usually risk mitigation, and understanding the pressures they're under. At the end of the day this always comes down to humans and the impact on them. A new system might be brilliant, but if a district nurse still can't prescribe and has to go back to the GP anyway, you have to think these things through.

BB: Everyone has different priorities, so understand the board's, usually risk mitigation, and frame what you present in those terms, while at the other end making the frontline person's job easier too. It's about relaying the same message in different language for different people.

Security and privacy by design

Lee: On putting technology in too hastily, the Cabinet Office has released new security principles, ten of them, one of which mirrors data protection: alongside privacy by design there's now security by design. Cabinet Office colleagues have also released design principles for integrating AI, and the ICO has useful examples. If a system has already been introduced and you're working out its impact retrospectively, use it as an opportunity to raise the challenges positively: explain to the board the risks, what it does for staff, and frame it around what matters to them. It's genuinely difficult, I get requests to approve new AI technology at short notice because someone needs to share data tomorrow.

BB: And that's exactly why data protection by design and security by design matter, having that thought process at the very beginning: what, why, how, and who does this serve?

Closing thoughts

BB: Thank you to Lee for joining us and sharing such practical insight, and the examples of sheds and shovels that bring it to life. Thank you to everyone who joined. We'll be running a series of these webinars, so watch your inboxes for more invitations as the topics evolve.

Healthcare data protection FAQ

Why is data protection important in health and care?

Data protection in health and care is essential because patient data is highly sensitive and directly supports safe, effective care. If data is lost, misdirected, unavailable or exposed, it can delay treatment, disrupt services, harm patients and create regulatory risk.

How does cyber security awareness support DSPT compliance?

Cyber security awareness supports DSPT compliance by helping employees understand secure behaviours, report risks, protect patient data and follow consistent security messages throughout the year. DSPT version 6 places greater focus on building a secure culture, not just completing annual training.

How can healthcare organisations help employees care about data?

Healthcare organisations can help employees care about data by linking secure behaviours back to patient impact, making reporting easy, using real examples, reinforcing messages through regular training and communications, and showing that data protection enables better care rather than blocking it.


Related pages

Human Risk Platform
Products & Services