---
title: "Information Classification, Handling and Disposal Policy"
canonical: "https://wiki.patientsknowbest.com/space/IG/3759734846/Information%20Classification%2C%20Handling%20and%20Disposal%20Policy"
format: markdown
---
> Macro (iframe)

## **Purpose**

All information has a value to PKB, however not all information has an equal value or requires the same level of protection. Being able to identify the value of an information asset is key to understanding the level of security that it requires to ensure it is both confidential and yet available to those who need to use it.

The purpose of this Policy is to establish the key principles of appropriate information classification, handling and disposal of all the information created, collected, processed and disseminated both within the organisation and to applicable third parties.

These rules help to protect PKB, our customers, our employees, and our partners from security risks including information loss, it also protects the company from legal, financial and reputational harm. This policy sets out the standards for individual and corporate information classification and handling to ensure we meet the expectations of our customers, employees, partners, third parties and the wider community in relation to business conducted on PKB’s behalf.

## **Scope**

This Policy applies to all information held by PKB whether held electronically or as hard copy. This policy must be adhered to by all those who develop and have access to PKB information, regardless of location and types of information or systems that they have access to; this includes both permanent and temporary employees, contractors, suppliers and agents working on behalf of PKB.

## **Responsibilities**

Access to PKB systems and information imposes certain responsibilities and obligations on the individual and is granted subject to PKB policies, UK and international law. All employees and third parties are responsible for understanding and adhering to the requirements of this policy and the details defined in the various other PKB policies, and where applicable, the policies of PKB’s customers.

Employees are reminded that this policy comprises part of the standard terms and conditions of employment and any breach of the rules in this policy could result in disciplinary action up to and including dismissal.

Line managers are responsible for day to day management of staff and should be the first point of contact for advice on the implementation of security policies within their business areas and for ensuring compliance by their staff.

Information owners are responsible for classifying the information assets based on the requirements of this policy, legal, regulatory and contractual obligations.

System and device owners are responsible for ensuring the security controls of the system based on the highest classification of information stored, processed and/or transmitted by that system or device.

Customer facing teams are responsible for understanding the customers’ information classification and handling requirements and ensuring all teams involved in the handling of such information are aware of the requirements.

# **Policy**

All users of PKB systems have a responsibility to ensure the Confidentiality, Integrity and Availability of the systems they use and ensure that any personal, sensitive or business confidential information, whether commercial, proprietary or personal is protected and only accessible by those who are authorised.

Each of us has a responsibility to handle, store and dispose of information with the highest professionalism, whether it belongs to PKB, our customers, partners, or one of our suppliers. 

It is the policy of PKB to ensure that all information is classified and handled in line with its sensitivity, legal, regulatory and contractual obligations.

To help provide guidance on how to ensure this, we have adopted a classification policy for internal and customer information. This policy identifies these areas and principles on how to classify, handle and eventually dispose of, this information whether it is stored on paper or electronic media. 

## **Key Principles**

PKB follows the key principles below, in the classification and handling of information:

- All information is valuable and should be treated with care at all times.
- Information must receive an appropriate level of protection.
- The requirement for protection of information is communicated to those who handle or receive the information.
- All third parties that store, process and/or transmit PKB or its customer’s information must handle that information in line with PKB policies and expectations.
- Information owners must classify all information they are responsible for in line with this policy.
- IT systems, containing information of more than one sensitivity classification, must be classified in line with the most confidential information on the system.
- Supplier or customer classification systems are to be aligned with an internal PKB classification where possible and handled as such.
- Any supplier classification that cannot be directly aligned with a PKB classification is to be aligned with the next classification upwards (i.e. if between “Internal” and “Confidential” then it is to be treated as Confidential.
- Information must only be shared with those who have a legitimate need to know.
- All actual or suspected security incidents involving PKB and/or its customer information must be reported to the Support Team immediately.

## **Data Protection**

PKB, its partners and suppliers have a legal responsibility to its customers, employees and partners to ensure that all personal, sensitive or business confidential information is adequately protected when in our custody. You are responsible for ensuring that you:

- Understand your responsibilities when handling personal, sensitive or business confidential information.
- Do not share or allow access to information to those that do not require access.
- Do not store any personal, sensitive or business confidential information unless PKB has a clear legal or business justification to do so.
- Ensure personal, sensitive or business confidential information that is stored on portable devices, such as USB drives, CDs or Personal Mobile Devices is encrypted and classified at ‘Confidential’.
- Continually review all information stored on portable devices and delete any that is no longer required.
- Classify all the information that you produce to determine the level of security it requires and the way in which it must be handled.
- Report any suspicious activity, information loss or breach immediately to the Support Team.
- Ensure that third parties providing services to PKB must also report actual or suspected breaches via the pre-agreed communication channels.
- If you receive personal, sensitive or business confidential information from an unauthorised source or about someone you should not, then report it immediately to the SupportTeam and your line manager.

## **Information Classification**

PKB will use classifications as described in this document.  Where a customer has their own classification system, then it should, where possible, align with PKBs internal classification system, even if the classification naming convention is different. This will simplify the use of shared services and other multi-tenant systems within PKB.

## **Responsibility for Classification**

The information creator or owner or the document, IT system and device owners are responsible for classifying the system based on the highest classification of the information stored, processed and/or transmitted by the system or device. Due consideration of aggregation of the information, must take place when classifying a system or device, such that the disclosure, modification or loss of total contents justifies a higher classification than that of an individual item. 

Once the appropriate level of security is identified the appropriate control can be implemented to prevent loss, damage or compromise of the asset, disruption of business activities, and prevention of the compromise or theft of information and informationprocessing facilities. Incorrect classification of assets may result in inadequate or incorrect controls being implemented to protect them.

**Over Classification** Information is classified to indicate whether protection is needed, protection priorities and the degree of protection. Therefore it is important not to over-classify which will avoid unnecessary business restrictions and cost. 

## **Classified Information Marking**

The classification must be indicated in/on the item so that it is obvious to anyone handling it. Documents and diagrams must have the classification in the header and the footer of each page located at the centre, in Capitals, of each page. Emails containing information classified as Confidential must have the classification clearly marked at the beginning and end of the text in the subject line or body of the email. 

## **Classified Information Transmission**

Appropriate security controls should be in place for the transmission of all classifications of information, however, when an item of personal, sensitive or business confidential  information, classified at Confidential is to be transmitted electronically, or sent by post, the classification must be taken into account and an increase in security controls implemented.

## **Email and Electronic Transmission**

Information classified as Confidential is only to be transmitted to individuals authorised to receive such information. If Confidential information must be sent via email to external parties, it must be encrypted by the sender. The encryption techniques used must align with the PKB’s policies.

Where passwords to decrypt the information needs to be shared to the recipients, the sender must send the password through a different communication media i.e. not by email. The construction of passwords must comply with the PKB Password Policy.

If in doubt on how to encrypt information and/or transmission of that information contact the Information Governance Team.

### Secure transfer of Personal Information via email

At times we will be required to send or receive personal information outside of usual automated processes to support a business need.

**Note:** Always remember when sending or receiving personal information to ensure that it is done in a secure way. 

Once we have satisfied ourselves that the request has been received from a legitimate source, i.e. a person known to us at an organisation we provide a service to, then we can begin the process described below.

#### Procedure for Receiving Personal Information from an External Organisation

**Note:** Generally an organisation will have their own process in place for the transfer of personal information to PKB, but incase they have not or it is not compatible, we follow the process below.

#### **Process Using Email **

Receiving an email from an External Organisation’s email address to a PKB email address, e.g. from <u>[fred@anytrust.nhs.uk](mailto:fred.anytrust@nhs.uk)</u> to <u>[fred@patientsknowbest.com](mailto:fred@patientsknowbest.com)</u> is not secure; so additional security measures will be required. 

1. Ask the sender to confirm that the file has been encrypted, this will normally be defined in one of their organisation's existing policies.
2. Ensure a ticket is logged within our support system.
3. Ask the sender to email the encrypted file to <u>[help@patientsknowbest.com](mailto:help@patientsknowbest.com)</u> or if they are using Secure File Storage, such as ‘Firefox Send’, ask them to email the link to the file to <u>[help@patientsknowbest.com](mailto:help@patientsknowbest.com)</u>
4. Confirm with the sender that the encrypted file has been received.
5. Ask the Sender for the password or one time secret code, this must be by using a different method to how the encrypted file has been sent, such as SMS.
6. Provide the password or one time secret code to the nominated PKB staff member with the appropriate access permissions, who will decrypt the file and store the information in a secure area.

## **Uploading to a Third Party Cloud Storage Service**

Information classified Confidential or Highly Confidential to public cloud services is to be encrypted as if it was being sent via email and only unencrypted on the local device. Storing information of a higher classification on public cloud services is strictly prohibited.

## **Changes to Classification**

The classification level can be upgraded (for example changed from internal to confidential) by any individual when deemed necessary but only the information owner can “declassify” or downgrade the classification level (for example change the classification level from confidential to internal).

## **Information Retention**

Information (especially that containing personal, sensitive or business confidential  information) should only be retained if there is a clear business reason to do so. If in doubt, refer to the **Information** **Retention Register** for PKB information and if customer information is involved, refer back to the original customer contractual commitments which as a minimum for patient information will be 8 years from last interaction.

In all cases only keep information to a minimum and only for as long as required. Outdated or unusable information only creates uncertainty and has the potential to be used inappropriately.

## **Information Disposal**

All classified information, regardless of format or storage media (paper, hard disk, USB storage devices etc.), needs to be disposed of in accordance with the PKB policies. 

# **Incident Management**

Unauthorised access to company information can cause damage to PKB, both financial and reputational, as such all suspected or actual security incidents must be reported to the Support Team immediately.

- Employees must report any suspicious activity, information loss or information breach immediately to the Support team and their line manager.
- Third Parties must report any suspicious activity, information loss or information breach immediately to PKB through the pre-agreed communication channels.

# **Monitoring and Enforcement**

PKB systems and information remain the property of PKB at all times and PKB reserves the right to monitor compliance to policies in line with all applicable laws and with due regard and respect for the fair treatment of all employees and to protect its network from systems and events that threaten or degrade operations.

PKB reserves the right to copy and examine any PKB owned files or information resident on systems or devices if the device or its use is in contradiction to PKB Policy or allegedly related to unacceptable use.  Those responsible may be subject to disciplinary action up to and including dismissal and where applicable may be referred to law enforcement agencies for prosecution.