top of page

Information Security Policy

Information Security Policy

Helen Ward Therapy
Trading name of ResolvedRM Ltd

Version: 1.0
Effective Date: 30/05/26

Review Date: 30/05/26

1. Purpose

Helen Ward Therapy is committed to protecting the confidentiality, integrity and availability of all personal and confidential information processed within the practice.

This Information Security Policy sets out the measures taken to safeguard client information from unauthorised access, loss, misuse, alteration, accidental disclosure or destruction.

The policy has been developed in accordance with:

  • UK General Data Protection Regulation (UK GDPR);

  • Data Protection Act 2018;

  • applicable professional and ethical obligations, including the BACP Ethical Framework for the Counselling Professions.

2. Scope

This policy applies to all personal and confidential information processed by Helen Ward Therapy, regardless of format.

This includes, but is not limited to:

  • client records;

  • therapy notes;

  • assessment records;

  • safeguarding records;

  • appointment records;

  • financial records;

  • emails and correspondence;

  • text and messaging communications;

  • electronic documents;

  • paper records;

  • information held on computers, mobile devices or cloud-based systems.

3. Information Security Principles

Helen Ward Therapy is committed to ensuring that information is:

Confidential accessible only to authorised persons or where disclosure is required or permitted by law.

Accurate maintained as accurately and completely as reasonably possible to support safe and effective therapeutic practice.

Available accessible when required for legitimate professional purposes whilst remaining protected from unauthorised access.

4. Responsibilities

As a sole practitioner, Helen Ward is responsible for maintaining appropriate information security measures, including:

  • protecting confidential information;

  • maintaining secure systems;

  • managing passwords and access controls;

  • ensuring secure storage;

  • reviewing security arrangements;

  • responding appropriately to security incidents.

Information security is also a shared responsibility. Clients are responsible for taking reasonable steps to protect their own devices, passwords, communications and privacy when engaging with Helen Ward Therapy.

5. Access Control

Access to confidential information is restricted to Helen Ward unless disclosure is required or authorised by law.

Appropriate measures include:

  • password-protected devices;

  • strong passwords;

  • multi-factor authentication where available;

  • automatic screen locking;

  • restricted user access;

  • secure storage of authentication credentials.

Passwords must never be shared unnecessarily or stored insecurely.

6. Device Security

All devices used to process client information should be appropriately protected.

Security measures include:

  • password or biometric protection;

  • software updates;

  • antivirus and malware protection where appropriate;

  • encrypted storage where available;

  • secure disposal of devices at end of life.

Devices should not be left unattended where confidential information could be accessed by unauthorised persons.

7. Electronic Communications

Helen Ward Therapy recognises that electronic communication can support a responsive, accessible and supportive therapeutic relationship. Email, text messaging, WhatsApp and online platforms may assist with appointment management, continuity of communication and the therapeutic process.

Whilst every reasonable effort is made to maintain confidentiality, electronic communications cannot be guaranteed to be completely secure.

Clients choosing to communicate electronically acknowledge the inherent security risks associated with electronic communication.

Helen Ward Therapy takes reasonable technical and organisational measures to minimise these risks.

Clients also share responsibility for maintaining the security of electronic communications by:

  • protecting their own devices;

  • using secure internet connections where possible;

  • maintaining password security;

  • keeping communication accounts private;

  • ensuring therapy takes place in a confidential environment;

  • notifying Helen Ward Therapy if confidentiality may have been compromised.

8. Transfer of Electronic Communications to Paper Format

Electronic communications may be converted to paper format where this is necessary for lawful processing, confidentiality, clinical documentation, safeguarding, supervision or compliance purposes.

Only information that is necessary for the intended purpose will be printed.

Any printed material containing personal information must:

  • be collected immediately from printers;

  • be clearly identifiable as confidential where appropriate;

  • be stored securely in access-controlled locations;

  • not be left unattended or accessible to unauthorised persons.

Paper copies are subject to the same confidentiality, retention, storage and secure destruction requirements as electronic records.

Where appropriate, electronic originals will be securely archived or managed in accordance with the Record Keeping Policy and Data Retention and Secure Disposal Policy to minimise unnecessary duplication.

Any loss, unauthorised access, inappropriate disclosure or improper disposal of printed information may constitute a personal data breach and will be managed in accordance with the Data Breach Policy.

9. Physical Security

Paper records and other confidential documents will be stored securely.

Reasonable measures include:

  • locked storage;

  • restricted access;

  • secure transportation where necessary;

  • preventing confidential information from being visible to unauthorised persons.

Confidential information should not be left unattended in public or shared environments.

10. Remote and Online Working

Where therapy is provided remotely, reasonable steps will be taken to maintain confidentiality and security.

This includes:

  • using appropriate technology;

  • conducting sessions in a private environment;

  • protecting client information from unauthorised access;

  • ensuring devices remain secure.

Clients are encouraged to take equivalent steps to protect their own confidentiality.

11. Secure Storage

Information will be stored only for legitimate professional purposes.

Storage systems will be selected with consideration for:

  • security;

  • confidentiality;

  • reliability;

  • legal compliance;

  • professional requirements.

12. Information Sharing

Confidential information will only be shared where:

  • there is a lawful basis;

  • disclosure is required or authorised by law;

  • there is a safeguarding concern;

  • there is a serious risk of harm;

  • another legal or professional obligation applies.

Only the minimum necessary information will be disclosed.

Helen Ward Therapy does not prepare or provide reports, letters, statements, opinions,

assessments, references or other written documentation for third parties or for use by clients for external purposes, except where required by law.

13. Security Incidents

Any actual or suspected security incident involving confidential information will be assessed promptly.

Appropriate action will be taken to:

  • contain the incident;

  • assess risks;

  • protect affected individuals;

  • comply with legal reporting obligations;

  • prevent recurrence.

Security incidents will be managed in accordance with the Data Breach Policy.

14. Disposal of Information

Information that is no longer required will be securely destroyed in accordance with the Data Retention and Secure Disposal Policy.

Confidential information will never be disposed of in a manner that could allow unauthorised access or reconstruction.

15. Business Continuity

Reasonable measures will be taken to maintain the availability of information where required for the safe operation of the practice.

This may include:

  • secure backups where appropriate;

  • secure cloud services;

  • protected storage systems;

  • contingency planning for equipment failure.

16. Policy Review

This policy will be reviewed annually or sooner if there are changes to legislation, technology, professional guidance or business practices.

Related Documents

This policy should be read alongside:

  • Privacy Policy

  • Data Protection Policy

  • Confidentiality Policy

  • Record Keeping Policy

  • Data Retention and Secure Disposal Policy

  • Data Breach Policy

  • Subject Access Request Procedure

  • Consent Policy

  • Safeguarding Policy

Document Control

ICO Reference: ZC204139

Document Owner: Helen Ward Therapy

Approved By: Helen Ward

Version: 1.0

Effective Date: 30/05/26

Review Date: 30/05/27

bottom of page