
Version: V 6
Ratified by: Finance Investment Committee
Date ratified: 05/02/2025
Job Title of author: Head of Health, Safety and Compliance
Reviewed by Committee or Expert Group Property Health Steering Group
Equality Impact Assessed by: Head of Health, Safety and Compliance
Related procedural documents

HSPOL06 Security Policy
HSPOL19 Lone Working Policy
HSPOL16 Violence & Aggression Policy
HSPOL13 Business Continuity & Service
Recovery Policy
IGPOL62 Information Governance Policy
SGPOL02 Safeguarding Children and Young People Policy
SGPOL07 Safeguarding Adults
HSPOL03 Closed Circuit Television (CCTV) Policy
ITPOL006 Asset Management Policy & Procedures
HSPOL08 Health & Safety at Work Policy
IGPOL53 Information Security Policy
QSPOL01 Incident Reporting Policy and Procedure
QSPOL09 Risk Management Policy
Review date: 05.03.2028

It is the responsibility of users to ensure that you are using the most up to date document template – ie obtained via the intranet.

In developing/reviewing this policy Provide Community has had regard to the principles of the NHS Constitution.

Version Control Sheet
Version Date Author Status Comment
v2 June 2016 Head of Safety & Resilience Revised previously IGPOL87
v3 August 2018 Head of Safety & Resilience Revised
V4 May 2023 Head of Health, Safety and Compliance Ratified FIC
V5 Feb 24 Head of Health, Safety and Compliance Reviewed to remove reference to NHS Protect and ASMS Clear desk and general requirements added
V6 Feb 25 Head of Health, Safety and Compliance Annual review


1. Introduction
Security affects everyone who uses our Health or Social Care services. The security and safety of staff, patients/service users, contractors and property must be a priority within the delivery and development of Provide Services. All of those working within Provide have a responsibility to be aware of these issues and to assist in preventing security related incidents and losses. In line with published guidance, Provide is committed to providing the best possible protection for its staff, patients/service users, contractors and property.
The aim of this Security Policy is to ensure that the optimum level of security is achieved and that accessibility to our services is reconciled with integrated security measures, designed to protect staff, patients/service users, contractors’ property, and possessions. Maintaining discreet and effective security and safety enables staff, patients, and visitors alike to be confident in the knowledge that the environment they are in is a safe and secure one.
Provide has a legal duty of care to provide a safe place of work for staff under the Health and Safety at Work Act 1974 (HSW Act). This includes protection from violence or the risk of violence. The duty of care does not mean that the employer should guarantee staff safety, but rather that they should undertake all reasonably practicable actions to protect staff from foreseeable risks.
All staff must be aware of and apply the principles of effective risk management so as to ensure that their own security, health and safety and that of their patients and colleagues are maintained at all times in accordance with the HSW Act 1974 and organisational policies.
Provide is required under General Condition 5.9 of the NHS Standard Contract to have regard to the NHS Violence Prevention and Reduction Standard Strategy with regards to Counter Fraud and the work of the Local Counter Fraud Specialist (LCFS)
2. Purpose
The aim of the Security Policy is to support the organisation in delivering high quality services and the organisations commitment to providing a safe and secure environment for staff, patients/service users and visitors. Security is the responsibility of all staff in not only safeguarding their own wellbeing and personal property but also that of patients/service users, visitors and Provide property.
Provide seeks to provide a safe environment for staff, patients and visitors by providing security measures across sites, training to deal with violence and aggression and to minimise security risk to all through continuous vigilance and improvement.
3. Definitions
CCTV

Closed Circuit TV
LCFS Local Counter Fraud Specialist
SMD Security Management Director
Criminal Damage
Physical Assault
Clinical Assault
Non-Physical Assault
HSW Act
4. Duties
Damage caused by any person to the property of another without lawful consent can include negligent acts. includeS graffiti and vandalism.
The intentional application of force to the person, without lawful justification resulting in physical injury or personal discomfort.
The application of force to the person, without lawful justification, due to the clinical condition, resulting in physical injury or personal discomfort.
The use of inappropriate words or behaviour causing distress and or constituting harassment.
Health and Safety at Work Act 1974
Group Chief Executive Has overall responsibility for all matters pertaining to security and this authority is delegated to the Executive Finance Director, who is the Security Management Director (SMD) for Provide.
The SMD has overall accountability for security and shall ensure:
• Appropriate action is taken to ensure compliance with any Health or Social Care standards for the management of security
• Responsibilities for security matters are properly assigned
• Requirements for additional resources to meet the objectives of the policy are brought to the attention of the Board
• Compliance with the policy is monitored by review reports provided to the Health, and Safety Oversight Group
• Security is given adequate consideration prior to any major changes in the Provides activities
• Staff receive appropriate training in security matters
• Appropriate security procedures are established and implemented
• Security risks are suitable assessed
• Where a criminal offence against Trust employees, contractors or property is suspected the Police are immediately informed, except in the case of a suspicion of fraud where the matter should be reported immediately to the Executive Finance Director and Provides Local Counter Fraud Specialist (LCFS)
Head of Health Safety and Compliance
The Head of Health, Safety and Compliance will act as the Security Management Advisor for Provide and will have responsibility to ensure that:
• Reports as appropriate are generated and presented to the Health, and Safety Oversight Group Accurate records of any breaches or suspected breaches of security are maintained
• Security management work is carried out in accordance with the NHS standards for the management of security

• Appropriate security incidents or breaches are notified to Health, and Safety Oversight Group
• Investigations into security matters are conducted where appropriate
• Advice is given to staff on key preventative and proactive measures to raise security awareness and reduce risk
• Advice is given in relation to site security
• Advice is given in relation to personnel security.
Data Protection Officer
The Information Governance Manager is responsible for supporting the organisation’s information governance and information security agenda, ensuring that the organisation meets its statutory and corporate responsibilities and engenders trust from the public with regard to how it manages their personal information
The organisation’s date Protection Officer’s role is to-
• Maintain an awareness of information governance issues within the organisation
• Review and update the information governance policy and strategy in line with local and national requirements
• Establish protocols on how information is to be shared internally and externally with other providers.
• Develop Information Governance awareness and training programmes for staff.
• Ensure compliance with Data Protection, Confidentiality, Freedom of Information, Information Security and other information related legislation.
• Manage information security issues and involve The Head of Health, Safety and Compliance for physical security where appropriate.
Directors/Assistant Directors and Team Managers
• To be accountable for the practical application of the Security Strategy within their area of control and in line with the organisation’s Security Policy.
• To ensure appropriate overall co-ordination of security within the services within their area of control including compliance with all relevant organisational policies.
• To agree arrangements for risk management responses to security issues
• To receive and act on advice from the Head of Health, Safety and Compliance as required
• To ensure that all staff including temporary staff, contractors, students etc. within their area of responsibility, receive the correct training to ensure their own and others safety as well as promote the protection of Provide Assets
Employees
• To work in compliance with Provide’s Policies and Procedures
• To work within organisational policies and guidelines to ensure the security of Provide/service user/personal property
• To report all security breaches/violent incidents/near misses using the Datix/Access incident reporting system
• To liaise with senior mangers when involved in a violent or security related incident and co-operate with investigations
• To embrace and commit to organisation’s Pro-Security Culture

5. Consultation and Communication
The security management strategy applies to:
• All Provide owned and leased premises
• Service Users
• Staff employed by the organisation including seconded, bank, full-time and part-time employees
• Visitors
• Contractors
• Sub-contractors
• Students
• Volunteers
All other persons engaged in business on behalf of Provide
6. Monitoring
Reports as appropriate are generated and presented to the Health, and Safety Oversight Group, Finance and Investment Committee and the Quality and Safety Committee
7. Training
Provide is committed to ensuring all staff receive training appropriate to their role. All staff will receive Conflict Resolution Training. Staff who are deemed by the organisation’s Occupational Health provider as not sufficiently physically fit to attend the above training will be risk assessed within the terms of their role and appropriate adjustments made and reviewed at a minimum annually. Further training will be arranging following a formal training needs analysis for their role
8. Risk Assessment
Provide has well established risk management arrangements detailed in the Risk Management Strategy.
Risk specific assessments i.e. lone working etc. are completed by staff and by the team managers with assistance from the Health and Safety Team for support and advice.
9. Clear Desk and Clear Screen
To ensure that personal, confidential or otherwise sensitive information (in digital and physical formats) and information assets (for example, computers and mobile devices, notebooks etc.) that hold or provide direct access to confidential information, are not left unprotected at desks or in personal workspaces or public settings when they are not in use.

Clear Desk
• Ensure you have taken reasonable measures to prevent unauthorised access to confidential information. Lock away documents containing Restricted or Confidential information when the records are not in use and, in particular, when the office/workspace is unoccupied or the workstation is left unattended for an extended period of time.
• If you are away from your desk for a short period of time, ensure any hard copy records containing confidential information are not left in view and that devices/screens are locked.
• Avoid printing or duplicating documents unnecessarily. Do not leave printing on or by copiers for others to find: wherever possible, remain at the printer while your print job is in progress. Keep your Smart Card safe and report any loss of a card without delay.
• Store confidential records and files securely and out of sight. Pedestal and tambour units, drawers, filing cabinets and/or shared cupboards and store rooms should be locked when left unattended.
• Keep desks and workspaces free of clutter. Actively manage records and data at all stages of the information life cycle, using appropriate storage solutions to ensure the safekeeping, accessibility and retention of records for as long as required.
• Do not put confidential information on sticky notes and/or leave such notes on monitors, boards or under keyboards.
• Dispose of documents with restricted or confidential information in a timely and secure manner, via confidential waste or by shredding
• Do not place sensitive or confidential documents in the general waste.
• Erase information on white boards and take away or dispose of flip-chart sheets securely after use and remove any documents/papers used during meetings/training/teaching when vacating meeting rooms and dispose of them securely (for example, via confidential waste or shredding).
Clear Screen
• There is a risk that information could be viewed by unauthorised users if left on an unlocked and unattended monitor or display screen. Lock your computer screen whenever it is left unattended. For Windows machines, use Ctrl+Alt+Del and Enter or the Windows key and ‘L’.
• Log out of accounts/applications and devices when they are not in use for any length of time.
• Position/protect screens and devices to prevent members of the public, or people passing by who lack the necessary authority, from being able to see any confidential information that may be displayed there.
Remote/home working
Follow the same policies when working away from the office, including at home. Be aware of the risks of others (including family) being able to view or access confidential material - for instance by ‘shoulder surfing’ or being able to listen into confidential conversations, whether at home, when travelling or in public locations, such as conferences and cafes.
