Clinical Governance & Data Security
Overview
Virtual Pharmacist provides a fully managed remote clinical pharmacy service, with clinical governance and quality assurance for the work we deliver. This page sets out the clinical, professional, information-governance and data-security standards that underpin our work.
The DSPT, Cyber Essentials and ICO badges link to their public registers; the DCB0129 badge links to our clinical safety statement.

Clinical governance framework
Our clinical governance framework is overseen by our Clinical Director and encompasses clinical audit, peer review, incident reporting and learning, and continuous quality improvement.
Every service is delivered to documented protocols, with clear escalation routes to a GP or senior pharmacist.
Professional registration and competence
Every pharmacist and pharmacy technician delivering our services is registered with the GPhC and in good standing, and is supported to maintain CPD and revalidation. Before they begin, we complete pre-engagement checks including identity, right-to-work, GPhC registration verification and references, and our clinicians hold DBS checks (enhanced where required). Independent Prescribers hold an active IP qualification and work within their scope of competence.
Clinical accountability and indemnity
Our pharmacists are professionally accountable for their own clinical decisions and any prescriptions they sign. Virtual Pharmacist is accountable for the service we deliver, including its clinical governance, supervision and quality assurance. The commissioning practice or organisation retains its own clinical and regulatory responsibilities. Prescribing follows protocols agreed with the practice: our independent prescribers prescribe within their competence and refer matters outside their scope to the appropriate clinician. Virtual Pharmacist holds medical malpractice insurance, and each of our pharmacists holds their own professional indemnity.

Clinical safety (DCB0129)
We develop clinical software and manage its clinical safety in line with DCB0129, the NHS clinical risk management standard for manufacturers of health IT systems. Our Clinical Safety Officer leads the documented risk management process throughout the software lifecycle.
- We maintain product hazard logs to identify clinical software hazards, assess their risks and record the controls
- Clinical safety case documentation records the safety evidence and controls for each clinical software product
- New clinical software and significant changes are risk-assessed before release and reviewed throughout their use
- We share relevant product safety documentation to support the deploying organisation’s DCB0160 work

Information governance and data security
Virtual Pharmacist has published NHS Data Security and Protection Toolkit (DSPT) “Standards Met” status for 2025/26 (ODS code S6I6X). We handle all patient data in line with UK GDPR, the Data Protection Act 2018 and NHS information governance standards.
- Our clinicians access your clinical systems (EMIS Web, SystmOne, Vision or Medicus) under agreed information-governance arrangements under formal data sharing agreements with each practice and PCN
- System access is provisioned through NHS smartcards
- Patient data is encrypted in transit and at rest
- We apply data minimisation and need-to-know access
For any information-governance or data-security query, contact our Information Governance lead at [email protected].
Cyber security
We hold Cyber Essentials certification, and all connectivity to NHS clinical systems is over the secure Health and Social Care Network (HSCN).
Safeguarding
All clinical personnel complete safeguarding training appropriate to their role, with clear routes to raise and escalate safeguarding concerns.
Quality and standards alignment
Our clinical work is aligned to national guidance, including NICE guidance, the BNF and MHRA drug safety alerts, and supports practices with QOF and CQC readiness.
Compliance at a glance
| Standard | What it covers | Our status |
|---|---|---|
| NHS DSPT | Annual NHS data security & information governance assurance | Standards Met for 2025/26 (ODS S6I6X) |
| UK GDPR & DPA 2018 | Lawful, secure handling of personal data | Compliant; ICO registered (ZB127110) |
| Cyber Essentials | Baseline cyber security controls | Certified |
| DCB0129 | Clinical risk management for health IT | Clinical safety managed in line with DCB0129; Clinical Safety Officer, product hazard logs and safety case documentation |
| HSCN | Secure connectivity to NHS clinical systems | All NHS system access over HSCN |
| GPhC registration | Professional regulation of our clinicians | All clinicians registered and in good standing |
| Professional indemnity | Cover for the clinical services we deliver | Medical malpractice insurance held |
Policies and assurance
We maintain internal policies including an Information Security Policy and data-protection and information-governance policies. Assurance documentation is available to commissioning partners on request.
Accreditations and verification
Public registers and supporting assurance information:
- NHS Data Security and Protection Toolkit: Standards Met. Organisation code S6I6X. Verify our DSPT record.
- Cyber Essentials: certified. Verify on the IASME certificate search.
- DCB0129: clinical safety managed in line with the standard. Read our clinical safety statement.
- GPhC: all our pharmacists and pharmacy technicians are registered with the General Pharmaceutical Council.
- ICO registration (data protection): registered with the Information Commissioner’s Office, registration reference ZB127110. Verify our ICO registration.
- Registered trade mark: “Virtual Pharmacist” is a registered UK trade mark, number UK00004104911. Verify on the IPO trade mark register.
Frequently asked questions
Do you meet the NHS Data Security and Protection Toolkit?
Yes. We have published a “Standards Met” DSPT return for 2025/26 under organisation code S6I6X, and our current status can be verified on the NHS DSPT register.
Where is our patient data held and how do you access it?
Our clinicians access your clinical systems (EMIS Web, SystmOne, Vision or Medicus) under agreed information-governance arrangements. Access is provisioned through NHS smartcards over the secure Health and Social Care Network (HSCN), and patient data is encrypted in transit and at rest. Clinical data handling and any separately recorded information are governed by the agreed data-sharing arrangements and our privacy notice.
Are you registered with the ICO?
Yes. Virtual Pharmacist Ltd is registered with the Information Commissioner’s Office under reference ZB127110, and handles personal data in line with UK GDPR and the Data Protection Act 2018.
Are your clinicians vetted and trained in data security?
Yes. Before anyone begins we complete identity, right-to-work, GPhC registration and reference checks, and our clinicians hold DBS checks (enhanced where required). All personnel complete information governance and safeguarding training appropriate to their role.
Do you meet clinical safety standards?
We manage the clinical safety of the software we develop in line with DCB0129. Our Clinical Safety Officer leads this work, supported by product hazard logs and clinical safety case documentation. We share relevant documentation to support deploying organisations with their DCB0160 work.
What happens if there is a data security incident?
We operate a documented incident management process to contain and investigate any incident, put things right and learn from it. Where we act as a controller, we report a notifiable personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where we act as a processor, we notify the controller without undue delay. We also notify affected individuals without undue delay where the legal high-risk threshold is met, and inform commissioning partners in line with our contractual obligations.
Can we see your policies before we start?
Yes. We can share our information governance, data protection and information security policy documentation, along with our DSPT status and certificates, with commissioning partners on request.
Need our due-diligence pack?
We can share our information-governance and data-security assurance documentation with commissioning partners on request: DSPT status, IG and information security policy summaries, and certificates.




