AbiHealth Solutions Limited
Bring Your Own Device (BYOD) Policy
| Organisation |
AbiHealth Solutions Limited |
Owner |
IT Team |
| Version |
1.1 |
Effective |
June 2026 |
| Next review |
June 2027 |
|
|
1. Purpose
This policy sets out the rules for using personal devices to access AbiHealth systems, data and services. It applies to all staff, contractors and volunteers.
AbiHealth handles sensitive personal data including service user care records, staff employment information and NHS data. All personal devices must meet the security standards in this policy before accessing any organisational system.
2. Scope
This policy applies to any personal device used to:
- Access Microsoft 365, including email, Teams, SharePoint and OneDrive
- Access Access Care Platform or any other AbiHealth system
- Store, view or transmit any AbiHealth data
- Connect to AbiHealth Wi-Fi or VPN
3. Permitted Devices
The following personal device types are permitted, subject to the security requirements in Section 4:
- Smartphones and tablets running iOS 16 or above, or Android 11 or above
- Laptops and desktops running Windows 11 Pro, or macOS Ventura (13) or above
Devices running end-of-life operating systems are not permitted unless covered by an active manufacturer extended security update programme.
4. Security Requirements
| Requirement |
Detail |
| Screen lock |
PIN, password, fingerprint or Face ID must be enabled. Auto-lock within 5 minutes of inactivity. |
| Device encryption |
Device storage must be fully encrypted. Default on iOS and modern Android. Windows devices require BitLocker. |
| OS updates |
The operating system and all apps must be kept current. Security patches must be applied within 14 days of release. |
| Antivirus |
Windows laptops must have active antivirus software. iOS and Android devices do not require additional antivirus. |
| No jailbreaking |
Jailbroken (iOS) or rooted (Android) devices are not permitted under any circumstances. |
| MFA |
Multi-factor authentication must be active on the staff M365 account accessed from the device. |
| Public Wi‑Fi |
AbiHealth data must not be accessed over public or unsecured Wi‑Fi without a VPN connection active. |
5. Acceptable Use
When using a personal device for work, staff must:
- Only access AbiHealth data through approved applications, including Microsoft 365 apps and the Access Care mobile app
- Do not save AbiHealth data to personal storage, personal cloud accounts or personal apps
Regarding personal messaging apps including WhatsApp:
- WhatsApp and other personal messaging platforms may be used for general staff communication that does not involve any service user information, for example rota queries, shift cover requests, or running late messages between staff with no service user reference
- WhatsApp and other personal messaging platforms must not be used to share any information about service users, including names, addresses, health conditions, care needs, medication, visit times or daily routines
- Care records, care-related documents, screenshots of AbiHealth systems, or any files containing service user or staff personal data must not be sent, shared or stored via WhatsApp or any other personal messaging platform
- If a service user or family member contacts a carer directly via WhatsApp or other personal messaging, the carer must not discuss care matters in that channel and should direct them to contact AbiHealth through official channels
- Not photograph, film or record service users, their home environment, their belongings or any care-related documentation using a personal device
- Ensure the device screen is not visible to others when viewing care records or personal data in public places, including public transport, waiting areas and service user properties
- Connect via VPN before accessing any AbiHealth system on a public or unsecured Wi‑Fi network
- Lock the device immediately when not in use in a public or shared space
- Report any suspected loss, theft or security incident to the IT team immediately at itsupport@abihealth.co.uk
6. Data Protection
- Screenshot or photograph care records, staff data or any sensitive organisational information
- Photograph, film or record service users, their property or their home environment on a personal device without explicit written authorisation from the Registered Manager
- Store images, videos or audio recordings of service users on a personal device under any circumstances
- Use personal devices to print AbiHealth documents containing personal data
- Allow others to access the device while AbiHealth data or applications are open
7. Remote Wipe
By signing the acknowledgement in Section 12, staff consent to AbiHealth remotely wiping the device in the event of loss, theft or a security incident. This may result in the loss of all personal data on the device.
A remote wipe will only be initiated where the device is reported lost or stolen, suspected to have been compromised, or the staff member has left the organisation.
Where device management software (Microsoft Intune) is in use, AbiHealth will perform a selective wipe removing only AbiHealth data and applications rather than a full device wipe wherever this is sufficient to contain the risk.
8. Leaving the Organisation
- All AbiHealth applications removed from personal devices
- IT team to remotely remove AbiHealth account access from all enrolled devices
- Any locally cached AbiHealth data deleted and confirmed in writing to IT
9. Consequences of Policy Violations
- Formal disciplinary action under AbiHealth's disciplinary procedure
- Referral to CQC as a fitness to practice concern
- Referral to the local authority safeguarding team
- Referral to the Disclosure and Barring Service (DBS)
10. Responsibilities
| All staff |
Comply with this policy and report incidents immediately. |
| IT Team |
Maintain this policy and manage device compliance. |
| Line managers |
Ensure staff read and sign this policy. |
11. Version History
| Version |
Date |
Changes |
Author |
| 1.0 |
June 2026 |
Initial policy issued |
IT Team |
| 1.1 |
June 2026 |
Added: WhatsApp permitted for general staff communication that does not involve service user information, prohibition on sharing service user information via personal messaging, prohibition on sending care records, care-related documents, screenshots or files containing service user or staff personal data via personal messaging, prohibition on photographing or recording service users and their homes, public Wi‑Fi and VPN requirement, screen privacy in public spaces, selective wipe clarification, consequences of violations including CQC and safeguarding referrals, IT helpdesk email for incident reporting. |
IT Team |
12. Staff Acknowledgement
By signing below, I confirm I have read and understood this policy. I agree to comply with all requirements and I consent to the remote wipe clause in Section 7, including the potential loss of personal data.
Please scroll through and read the full policy above before completing the acknowledgement below.