AQW 48000/22-27 – Resilience of health service data systems

Mr Patsy McGlone (Mid Ulster): To ask the Minister of Health whether any recent assessment has been made of the resilience of health service data systems to unauthorised access and attempted data breaches.

Minister of Health: My Department and the Health and Social Care (HSC) system maintain ongoing assurance arrangements to manage and test the resilience of data systems to unauthorised access and attempted data breaches.

This assurance is delivered through a combination of technical cyber security activity, information governance processes, and programme-level controls. These include formal data protection impact assessments for new systems and significant changes, ongoing security monitoring and risk management activity, and system assurance processes to identify and mitigate vulnerabilities.

There is a continued focus on strengthening identity and access management, including role-based access controls, user lifecycle processes, and the regular review of access rights. These measures are designed to ensure that access to patient information is appropriate, proportionate, and subject to audit.

In addition, arrangements are in place across HSC organisations to detect, report, and respond to any suspected or actual data breaches. Where issues are identified, they are investigated and managed in line with established incident and information governance procedures.

There is no single, stand-alone assessment of resilience; rather, assurance is provided on an ongoing basis through these combined activities, with controls continually reviewed and strengthened.

ENDS