Security Policy
Standards: NHS DSP Toolkit Aligned | Cyber Essentials | UK GDPR
At Queensway Chemist, the security and confidentiality of patient and visitor data is fundamental to our clinical practice. This policy outlines the technical, physical, and organisational controls protecting our digital platforms and dispensary premises.
1. Architectural Isolation (Privacy-by-Design)
Unlike typical health portals, Queensway Chemist maintains strict architectural separation between our public website and our NHS clinical dispensing systems:
- No Web-Based Health Records: We do not store prescription records, patient medication records (PMR), or NHS clinical consultation histories on public web servers.
- No Payment Data: We do not store, process, or transmit cardholder or bank account details. No payment processing occurs on this website.
- Reduced Threat Surface: By eliminating patient logins and electronic health databases from our web layer, we remove the primary attack vectors targeted in healthcare data breaches.
2. Web Technical Safeguards
Our website employs modern defensive engineering standards:
- TLS 1.3 Transport Encryption: All traffic between your browser and our website is encrypted using industry-standard TLS 1.3 protocols.
- HSTS Enforced: HTTP Strict Transport Security (HSTS) prevents downgrade attacks and protocol manipulation.
- Content Security Policy (CSP): Restricts executable script origins to mitigate cross-site scripting (XSS) and code injection threats.
- Sandboxed Scheduling: Clinical appointment slots booked online utilise an isolated Cal.com booking widget, which collects only basic contact details (name, phone, email) without medical history.
3. Dispensary & NHS Network Security
Within our physical pharmacy at 14 Manchester Road, Chorlton, clinical dispensing data is managed in accordance with the NHS Data Security and Protection Toolkit (DSPT):
- NHS Smartcard Authentication: Access to the NHS Electronic Prescription Service (EPS) and Patient Medication Records requires physical Smartcards with individual two-factor PIN credentials.
- Health and Social Care Network (HSCN): Dispensary systems connect through encrypted, dedicated HSCN connections approved by NHS England.
- Physical Security: Dispensary access is restricted to authorised pharmacy staff. Paper documentation is shredded via certified confidential waste services.
- Staff Training: Every member of our pharmacy team undergoes annual mandatory training in data protection, Caldicott Principles, and cyber hygiene.
4. Vulnerability Reporting
We take potential security issues seriously. If you discover a vulnerability or security concern, please consult our Responsible Disclosure Policy or contact our security team at security@queenswaychemist.co.uk.