Clinical Governance & Data Security

Overview

Virtual Pharmacist provides a fully managed remote clinical pharmacy service, with clinical governance and quality assurance for the work we deliver. This page sets out the clinical, professional, information-governance and data-security standards that underpin our work.

The DSPT, Cyber Essentials and ICO badges link to their public registers; the DCB0129 badge links to our clinical safety statement.

Clinical governance: audit, oversight and continuous improvement

Clinical governance framework

Our clinical governance framework is overseen by our Clinical Director and encompasses clinical audit, peer review, incident reporting and learning, and continuous quality improvement.

Every service is delivered to documented protocols, with clear escalation routes to a GP or senior pharmacist.

Professional registration and competence

Every pharmacist and pharmacy technician delivering our services is registered with the GPhC and in good standing, and is supported to maintain CPD and revalidation. Before they begin, we complete pre-engagement checks including identity, right-to-work, GPhC registration verification and references, and our clinicians hold DBS checks (enhanced where required). Independent Prescribers hold an active IP qualification and work within their scope of competence.

Clinical accountability and indemnity

Our pharmacists are professionally accountable for their own clinical decisions and any prescriptions they sign. Virtual Pharmacist is accountable for the service we deliver, including its clinical governance, supervision and quality assurance. The commissioning practice or organisation retains its own clinical and regulatory responsibilities. Prescribing follows protocols agreed with the practice: our independent prescribers prescribe within their competence and refer matters outside their scope to the appropriate clinician. Virtual Pharmacist holds medical malpractice insurance, and each of our pharmacists holds their own professional indemnity.

Clinical safety: clinical risk managed by design, in line with DCB0129

Clinical safety (DCB0129)

We develop clinical software and manage its clinical safety in line with DCB0129, the NHS clinical risk management standard for manufacturers of health IT systems. Our Clinical Safety Officer leads the documented risk management process throughout the software lifecycle.

  • We maintain product hazard logs to identify clinical software hazards, assess their risks and record the controls
  • Clinical safety case documentation records the safety evidence and controls for each clinical software product
  • New clinical software and significant changes are risk-assessed before release and reviewed throughout their use
  • We share relevant product safety documentation to support the deploying organisation’s DCB0160 work
Information governance and data security: your patient data protected

Information governance and data security

Virtual Pharmacist has published NHS Data Security and Protection Toolkit (DSPT) “Standards Met” status for 2025/26 (ODS code S6I6X). We handle all patient data in line with UK GDPR, the Data Protection Act 2018 and NHS information governance standards.

  • Our clinicians access your clinical systems (EMIS Web, SystmOne, Vision or Medicus) under agreed information-governance arrangements under formal data sharing agreements with each practice and PCN
  • System access is provisioned through NHS smartcards
  • Patient data is encrypted in transit and at rest
  • We apply data minimisation and need-to-know access

For any information-governance or data-security query, contact our Information Governance lead at [email protected].

Cyber security

We hold Cyber Essentials certification, and all connectivity to NHS clinical systems is over the secure Health and Social Care Network (HSCN).

Safeguarding

All clinical personnel complete safeguarding training appropriate to their role, with clear routes to raise and escalate safeguarding concerns.

Quality and standards alignment

Our clinical work is aligned to national guidance, including NICE guidance, the BNF and MHRA drug safety alerts, and supports practices with QOF and CQC readiness.

Compliance at a glance

StandardWhat it coversOur status
NHS DSPTAnnual NHS data security & information governance assuranceStandards Met for 2025/26 (ODS S6I6X)
UK GDPR & DPA 2018Lawful, secure handling of personal dataCompliant; ICO registered (ZB127110)
Cyber EssentialsBaseline cyber security controlsCertified
DCB0129Clinical risk management for health ITClinical safety managed in line with DCB0129; Clinical Safety Officer, product hazard logs and safety case documentation
HSCNSecure connectivity to NHS clinical systemsAll NHS system access over HSCN
GPhC registrationProfessional regulation of our cliniciansAll clinicians registered and in good standing
Professional indemnityCover for the clinical services we deliverMedical malpractice insurance held

Policies and assurance

We maintain internal policies including an Information Security Policy and data-protection and information-governance policies. Assurance documentation is available to commissioning partners on request.

Accreditations and verification

Public registers and supporting assurance information:

Frequently asked questions

Do you meet the NHS Data Security and Protection Toolkit?

Yes. We have published a “Standards Met” DSPT return for 2025/26 under organisation code S6I6X, and our current status can be verified on the NHS DSPT register.

Where is our patient data held and how do you access it?

Our clinicians access your clinical systems (EMIS Web, SystmOne, Vision or Medicus) under agreed information-governance arrangements. Access is provisioned through NHS smartcards over the secure Health and Social Care Network (HSCN), and patient data is encrypted in transit and at rest. Clinical data handling and any separately recorded information are governed by the agreed data-sharing arrangements and our privacy notice.

Are you registered with the ICO?

Yes. Virtual Pharmacist Ltd is registered with the Information Commissioner’s Office under reference ZB127110, and handles personal data in line with UK GDPR and the Data Protection Act 2018.

Are your clinicians vetted and trained in data security?

Yes. Before anyone begins we complete identity, right-to-work, GPhC registration and reference checks, and our clinicians hold DBS checks (enhanced where required). All personnel complete information governance and safeguarding training appropriate to their role.

Do you meet clinical safety standards?

We manage the clinical safety of the software we develop in line with DCB0129. Our Clinical Safety Officer leads this work, supported by product hazard logs and clinical safety case documentation. We share relevant documentation to support deploying organisations with their DCB0160 work.

What happens if there is a data security incident?

We operate a documented incident management process to contain and investigate any incident, put things right and learn from it. Where we act as a controller, we report a notifiable personal data breach to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. Where we act as a processor, we notify the controller without undue delay. We also notify affected individuals without undue delay where the legal high-risk threshold is met, and inform commissioning partners in line with our contractual obligations.

Can we see your policies before we start?

Yes. We can share our information governance, data protection and information security policy documentation, along with our DSPT status and certificates, with commissioning partners on request.

Need our due-diligence pack?

We can share our information-governance and data-security assurance documentation with commissioning partners on request: DSPT status, IG and information security policy summaries, and certificates.

Request the assurance pack