Security & compliance

Your patients’ data is safe with us

When you hand over the running of your practice communications, you’re trusting us with sensitive information. Here’s how we protect it.

A bright, empty clinical corridor in daylight

How we protect your data

UK data residency

Your data never leaves the UK. Every document, letter, appointment note and patient communication is stored and processed exclusively on UK servers. It cannot be accessed, downloaded or stored anywhere else — this is enforced by the technology itself, not just a policy we ask people to follow.

Locked-down workspace

Your team’s work environment is locked down. Our PAs work inside a secure, fully controlled digital workspace. They can see and action your data, but they cannot copy it, download it, print it, or move it outside that environment. Every session carries a visible on-screen watermark identifying the user and time — so there is a clear, permanent record of who accessed what and when.

Access control

Access is strictly controlled. Every member of our team signs in with their own unique account, protected by multi-factor authentication. We use a system that continuously monitors sign-in behaviour and automatically blocks access if anything looks suspicious — an unusual location, an unfamiliar device, or a login pattern that doesn’t match normal activity. If something doesn’t look right, access is cut off before anyone gets in.

Monitoring

Someone is watching around the clock. A dedicated, specialist security team monitors our entire environment 24 hours a day, seven days a week. They’re not waiting for an alarm to go off — they’re actively hunting for unusual behaviour and can isolate a threat within minutes, any time of day or night.

Audit trail

If something ever goes wrong, we know immediately. Our systems generate a continuous audit trail of all activity. In the unlikely event of a security incident, we can identify exactly what happened, when, and take action — including notifying you promptly in line with our legal obligations.

DSPT Standards Met

Halo Desk has been awarded the NHS DSPT Standards Met accreditation (organisation code I6E5R) as evidence of its commitment to data security.

Our current certification

The NHS Data Security and Protection Toolkit is the annual assessment of how organisations handle patient and personal data. Our ‘Standards Met’ status confirms Halo Desk meets the national standard for data security and information governance.

Halo Desk Ltd NHS Data Security and Protection Toolkit Standards Met certificate, 2025-26
A healthcare-trained medical secretary reviewing a practice inbox

Questions about how we protect your data?

Get in touch and we’ll walk you through how we keep your patients’ information safe.

Get in touch →