Aim — To respond to a live personal data breach in a hospital pharmacy — containing it, assessing its scope, deciding notifiability under the Digital Personal Data Protection Act, and handling the requests and pressures that arrive while you do so.
You are the pharmacy lead and the department’s data protection point of contact. It is Monday morning. Something has gone wrong over the weekend, and by the end of the exercise you will have had to make six decisions under time pressure.
| Assessment criteria | Marks |
|---|---|
| Immediate containment — correct actions in the correct order | 25 |
| Scope and risk assessment | 15 |
| Notifiability decision | 20 |
| Handling the subject access request | 15 |
| Refusing improper disclosure | 15 |
| Preventive action | 10 |
| Total | 100 |
Pass 50. The Containment and Compliance indices are reported separately.
Alizon Teaching Hospital · Pharmacy Department · data protection point of contact
Complete the incident to generate your report, then write and submit it below.