Information Security Policy

Last updated: January 2026

This Information Security Policy sets out how Medical Pros LTD protects information and systems from unauthorised access, misuse, loss, or damage. It applies to all employees, contractors, and third parties who access or handle information on behalf of Medical Pros LTD.

Purpose of This Policy

The purpose of this policy is to ensure the confidentiality, integrity, and availability of information handled by Medical Pros LTD, particularly sensitive medical, legal, and personal data used in medico-legal services.

About Medical Pros LTD

Medical Pros LTD
21a Hardshaw Street, St Helens, WA10 1QX
Company Registration Number: 12129141
ICO Registration Number: ZA551439
Email: info@medicalpros.co.uk

Medical Pros LTD operates as a medical agency supporting law firms with medical reporting, expert instruction, rehabilitation coordination, diagnostics, and related services.

Scope

This policy applies to all information assets, including but not limited to:

  • Electronic records and databases
  • Emails and electronic communications
  • Paper records and files
  • IT systems, devices, and networks
  • Third-party systems used to process data on our behalf

Information Security Principles

Medical Pros LTD is committed to maintaining:

  • Confidentiality: ensuring information is accessible only to authorised individuals
  • Integrity: safeguarding the accuracy and completeness of information
  • Availability: ensuring information and systems are accessible when required

Access Control

Access to information and systems is granted strictly on a need-to-know basis. Controls include:

  • Unique user credentials
  • Strong password requirements
  • Restricted access to sensitive or special category data
  • Removal or adjustment of access when roles change or end

Unauthorised access attempts are monitored and investigated.

Data Storage and Handling

Information is stored securely using appropriate physical, technical, and organisational safeguards. This includes:

  • Secure servers and systems
  • Encrypted data transfer where appropriate
  • Secure storage of physical records
  • Clear procedures for handling and transporting information

Sensitive medical and case-related information is subject to enhanced controls.

Device and System Security

Medical Pros LTD takes steps to secure all devices and systems used for business purposes, including:

  • Use of up-to-date security software
  • Regular system updates and patching
  • Protection against malware and unauthorised software
  • Secure configuration of hardware and networks

Third-Party and Supplier Security

Where third-party providers are used, Medical Pros LTD ensures that appropriate security measures are in place. Third parties must demonstrate compliance with information security requirements and are required to protect information to an equivalent standard.

Incident Management and Breach Response

Procedures are in place to identify, report, and respond to information security incidents, including data breaches. Any incident is investigated promptly, and appropriate steps are taken to mitigate risk, restore security, and comply with legal and regulatory reporting obligations.

Business Continuity

Measures are in place to support continuity of operations in the event of system failure, security incidents, or unforeseen disruption. This includes data backup processes and recovery planning to ensure critical information remains available.

Training and Awareness

All staff and relevant third parties receive training on information security responsibilities and best practices. Awareness is maintained to reduce the risk of human error, misuse, or security breaches.

Monitoring and Review

Information security controls are monitored and reviewed regularly to ensure effectiveness. This policy is reviewed periodically and updated as required to reflect changes in technology, risk, or legal obligations.

Compliance

Failure to comply with this Information Security Policy may result in disciplinary action or termination of contracts, and may lead to legal or regulatory consequences.

Contact Details

If you have any questions about this Information Security Policy or information security matters, please contact:

Email: info@medicalpros.co.uk
Post: Medical Pros LTD, 21a Hardshaw Street, St Helens, WA10 1QX