Data and digital

Data & Digital@2x.png

Why it is important

Expanding privacy and security regulations, and an increasingly hostile online environment, have made information privacy and cyber security an increasing concern. The digitisation of services and increasing use of data for decision-making are key drivers in the health care industry’s transformation.

Our management approach

Ramsay recognises the significant importance of information privacy, data governance, cyber security and responsible AI use to our business, particularly in an environment of expanding information privacy and security regulations, and an increasingly hostile online landscape.

Ramsay engages third parties and utilises internal information systems to perform key functions essential to our ability to operate, provide care and manage patient information.

Each Ramsay regional business monitors cyber risks and data and privacy concerns. Each region has its own accountability framework to reduce risk, protect all data held, meet regulatory requirements and undertake training and awareness which forms part of continual improvement processes.

Privacy and data governance

Each region has a Privacy Policy which complies with jurisdictional requirements regarding information collection, use, disclosure, retention and raising concerns:

Measures include:

  • Dedicated data protection and privacy officers (or equivalent) in each region.
  • Privacy training is provided to employees and is supported by regular awareness and education communications via staff newsletters and targeted campaigns.
  • Data breach concerns are managed by a framework which incorporates a data breach policy and response plan including a Data Breach Triage and Response Teams, period testing and notification and escalation processes.
  • Privacy Impact Assessment for new or significantly changed projects, systems, programs, products or services that will involve the processing of personal information to identify and manage privacy risks.
  • Regular reporting on privacy and data breach management is provided to the Group Executive, the Board and Risk Management Committee.

Cyber security

Ramsay has implemented a global cyber security control framework aligned to the NIST Cyber Security Framework v2.0 including increasing annual maturity targets for all regions.  The NIST Framework defines a set of controls across six categories (Govern, Identify, Protect, Detect, Respond, and Recovery) and is designed to provide both protection and resilience against the broad range of cyber security risks.

Measures include:

  • Internal self-assessments of maturity against the NIST CSF 2.0 and control effectiveness, calibrated across the group, every six months
  • External assessments of maturity against NIST CST 2.0 every two years.
  • Pre-procurement assessment of supplier cyber security management practices and any accreditation (e.g. ISO27001, SOC 2 Type II, etc.) and annual reassessment of any high-risk suppliers.
  • Each region has a cyber incident response plan, these are exercised regularly with technical teams and management.
  • All facilities have a business continuity plan and disaster recovery plans.
  • RHCUK is ISO27001 accredited.
  • Ramsay UK and Elysium Healthcare implement the NHS Data Security and Protection Toolkit (DSPT) and have achieved the NHS (category 1) Standard which is externally audited. Ramsay UK achieved “Standards Exceeded” for their assessment, Elysium achieved “Standards Met”.
  • Cyber security training is provided to employees and is supported by regular awareness and education communications via staff newsletters and targeted campaigns.
  • Regular reporting on cybersecurity is provided to the Group Executive, the Board and Risk Management Committee.

Responsible Artificial Intelligence (AI) use

Artificial Intelligence (AI) tools provide the opportunity to improve clinical outcomes and ease frontline workload. To support safe implementation, Ramsay has introduced additional governance, including an AI Governance Framework and Committee. Our AI Governance Framework is designed to ensure that approved AI initiatives are safe, ethical, and aligned with our values. The Framework provides oversight across the full lifecycle of AI use - from pilot to deployment - ensuring transparency, accountability, and responsible innovation.

Regular reporting on AI use is provided to the Group Executive and Risk Management Committee.

Impact boundary and stakeholders

  1. Patients
  2. Doctors
  3. Employees
  4. Government and regulators

Measures

Our measures are provided in our annual reporting suite and Funding Group Data Book (Voluntary disclosures) Quality Scorecard and include notifiable breaches of patient privacy.

Alignment 

  • GRI disclosures: 418-1 Customer privacy
  • SASB topic areas: Patient privacy and electronic health care records
  • SDGs: 3, 8,17