Compliance & Trust

Security at Virtual Triage is

Our Topmost Priority

Virtual Triage follows UK data protection requirements (UK GDPR) and applies strict security controls to keep patient and clinician data protected.

We prioritize the confidentiality and integrity of your communications, so you can focus on what matters.

DSPT Compliant
DSPT Compliant
ICO Registered
ICO Registered
GDPR Compliant
GDPR Compliant
CQC Exempt
CQC Exempt

Are we CQC registered?

CQC regulates healthcare providers. According to CQC Registration Requirements, Virtual Triage is not a healthcare provider, it is the software used to book one.

Adherence to Security Principles and Best Practices

Virtual Triage has completed a Data Security and Protection Toolkit (DSPT) self-assessment for 2025-26, published as 'Standards Met' (valid to 30 June 2027), demonstrating good data security practice and correct handling of personal information. Virtual Triage ensures continuous monitoring and enhancement of security controls, referencing industry best practices and UK GDPR requirements.

Regular Independent Security Assessments

Virtual Triage is registered with the ICO (registration number ZB962983) and has completed the NHS Data Security and Protection Toolkit self-assessment. Both can be independently verified on the public ICO and DSPT registers, linked below.

Penetration Testing

Virtual Triage plans to commission independent, third-party network and application penetration testing. Findings will be reported to leadership, remediated promptly, and made available to clinic partners on completion.

Access Control Measures

Virtual Triage implements role-based access controls, multi-factor authentication for privileged access, and least-privilege principles to ensure that only authorized personnel can access sensitive patient and clinician data.

Secure Cloud Infrastructure

Virtual Triage utilizes healthcare-grade cloud infrastructure with network segmentation, regular backups, and robust disaster recovery procedures to ensure high availability and data protection.

Data Encryption Protocols

All patient and clinician data is encrypted using AES-256 encryption at rest and TLS 1.3 in transit. Encryption keys are managed securely with proper key rotation and access controls.

Endpoint Security

Virtual Triage implements comprehensive endpoint security measures including device management, secure configurations, and monitoring to protect against unauthorized access and malware.

Centralized Log Management

All system activities, access attempts, and security events are logged centrally with audit trails. Logs are retained according to legal and regulatory requirements and are regularly reviewed for security incidents.

Network Protection Strategies

Virtual Triage employs network segmentation, firewalls, intrusion detection systems, and DDoS protection to safeguard against network-based attacks and unauthorized access attempts.

Employee Security Awareness and Compliance

All Virtual Triage employees undergo regular security awareness training and are required to comply with data protection policies. Background checks and confidentiality agreements are standard practice.

Secure Development Lifecycle

Virtual Triage follows secure coding practices, conducts code reviews, implements automated security testing, and performs security assessments throughout the software development lifecycle.

Controlled Third-Party Data Handling

Virtual Triage maintains strict controls over third-party data processors, ensuring Data Processing Agreements (DPAs) are in place, sub-processors are vetted, and data transfers comply with UK GDPR requirements.

Need compliance details?

Contact us for DPIAs, data flow diagrams, sub-processor lists, and security posture information.