Security & Compliance
Patient trust depends on the security and confidentiality of health information. SystmOne uses multiple layers of protection — encryption, role-based access controls, audit trails, and compliance frameworks — but technology alone is not enough. Daily user behaviour is what ultimately protects patient data.
Every action you take under your login is logged and auditable. Protect your credentials, lock your screen, and access only what you need for legitimate clinical duties.
Start Here
Not sure where to begin? Pick the path that matches your role:
Why Security and Privacy Matter
Defense in Depth
SystmOne uses a defense-in-depth model. Multiple layers work together so that if one layer fails, others still protect the data.
Your Security Essentials
The Non-Negotiables
| Rule | Why It Matters |
|---|---|
| Never share your login | You are personally accountable for every action under your account |
| Lock your screen when you step away | Prevents unauthorized access in shared clinical areas |
| Access records only for legitimate care | Curiosity access is a breach of ethics and policy |
| Log out at shift end | Ends your session completely; auto-lock is not enough |
| Report concerns immediately | Early reporting protects patients, staff, and the clinic |
Quick Reference: Common Mistakes to Avoid
| Risk | Correct Practice |
|---|---|
| Leaving workstation unlocked | Lock screen before stepping away (Windows key + L) |
| Sharing passwords during busy periods | Each person logs in with their own credentials |
| Writing passwords on sticky notes | Use approved secure password management methods |
| Accessing records out of curiosity | Access only records needed for clinical duties |
| Multiple users logged in on the same workstation | One user logs out fully before the next logs in |
| Discussing patient details in waiting areas | Keep discussions in private clinical spaces |
Emergency? Contact Now
Contact the Clinic ICT Security Officer (ICTSO) or Clinic Administrator if you observe or suspect:
- Unauthorized access to patient records
- Lost or stolen devices with patient data
- Forgotten passwords or unusual account lockouts
- Suspicious system behaviour or error messages
- Security policy violations by staff
- Accidental disclosure of patient information
Report early, even if unsure. Early reporting protects both patients and staff.
What This Section Covers
Find a Topic
| If you need to understand… | Go to… |
|---|---|
| What I must and must not do every day | User Responsibilities |
| How roles and permissions work | Access Control & Data Security |
| How every action is logged | Audit Trail |
| How to correct errors safely | Mark In Error |