Image of a Light Bulb
Jul 20 2022

What Is Accreditation And Why Is It So Important To The Health Sector

By Michelle Underwood, Compliance Officer

Those within the health sector across the UK are constantly finding themselves under added pressure. With continuous annual campaigns, staff shortages and an ageing population, there’s always more to be done, but with less time, money and resources available. This combined with the effects of the pandemic means that it’s never been more important for practices to choose reliable, accredited providers that support practices in delivering effective communications to their patient cohorts, so that they remain informed, engaged and up to date.

But what is an accreditation and what accreditations should health organisations look for, in a communications supplier?

What is an accreditation?

Accreditation is an independent recognition that an organisation meets the requirements of governing industry standards. It is an important way to give confidence in goods, services, management systems and people.

You want to partner with companies you can trust and develop a relationship with so that you can rely on and work together to meet your objectives. Accredited suppliers come with a wealth of experience and expertise to give you peace of mind that you are choosing a reliable, NHS-approved supplier.

Here at CFH Docmail, we hold a range of accreditations and certifications and have done for over 30 years. As a processor of data, trusted partner and communication expert, we understand that holding these accreditations is vital for health sector confidence, knowing that your patient data and communications are handled, managed and produced in the best possible way.

But we also recognise that these accreditations and certifications highlight us as a provider of the very best communication service to our different customers. They allow us to demonstrate our practices and prove we are a trusted, reliable and ethical supplier, while also supporting our core brand values.

In this blog, our Accreditation and Certification expert, Michelle Underwood, is going to focus on some of our accreditations and certifications that are most relevant to the health sector, explaining what the accreditation is, why businesses may choose to achieve it and how we achieve it – which may also help you decide on partnering with us, to help you achieve your practice communication goals.

Data security and Information toolkit approved (standards exceeded)

What is it?

The Data Security and Protection Toolkit is a tool that allows organisations to measure their performance against the National Data Guardian’s 10 data security standards.

Why do businesses choose to achieve this?

All organisations that have access to NHS patient information must provide assurances that they have the proper measures in place to ensure that this information is kept safe and secure.

Completion of the DSPT is therefore a contractual requirement specified in the NHS England Standard Conditions contract and it remains the Department of Health and Social Care policy that all bodies that process NHS patient information for whatever purpose provide assurances via the DSPT.

How do we achieve this?

It is an online self-assessment tool that involves us completing an assessment by responding to a range of questions. The DSPT is organised under the 10 data security standards and under each standard there are a number of ‘assertions’ that we work through. To complete each assertion, we are required to provide evidence items which demonstrate compliance with the assertion. Once this is done, we publish our assessment.

If an organisation achieves 'Standards Met' and also has a current Cyber Essentials PLUS certification recorded in its organisation Profile, then its status will be displayed as 'Standards Exceeded'. This is the status that we hold and have done since its inception as well as its previous incarnation, as the IG Toolkit.

As data security standards evolve, the requirements of the DSPT are reviewed and updated to ensure they are aligned with current best practice. Each year, we must review and submit our annual assessment.

ISO 9001:2015 Quality Management System

What is it?

ISO 9001:2015 is a UKAS accredited international standard that specifies requirements for a quality management system (QMS). A QMS is a collection of business processes focused on consistently meeting customer requirements and enhancing their satisfaction. It is aligned with an organisation's purpose and strategic direction.

In short, this accreditation demonstrates the quality controls we have in place to meet our changing customer requirements to a particular standard.

Why do businesses choose to achieve this?

Organisations use the standard to demonstrate the ability to consistently provide products and services that meet customer and regulatory requirements. It helps organisations ensure their customers constantly receive high-quality products and services, which in turn brings many benefits to a business, including satisfied customers, management and employees.

How do we achieve this?

CFH Radstock (our head office) continuously maintain registration to ISO 9001 through BSI (certification governing body) and has held the standard since 1991. CFH Livingston (our site in Scotland) maintains registration to ISO 9001 through NQA (a separate governing body). PRINT.UK.COM (our site in Windsor) maintain registration to ISO 9001 through QMS International, a separate governing body.

Independent certification governing body BSI, carry out continuing assessments against the standard twice per year at the Radstock site. NQA carries out an audit of our Livingston site once per annum, and QMS International carry out an audit of the Windsor site once per annum.

ISO9001:2015 shows our commitment to providing a quality service to all our customers.

ISO 27001:2013 Information Security Management

What is it?

An Information Security Management System (ISMS) is a systematic approach to managing sensitive company information so that it remains secure. It encompasses people, processes and IT systems. BSI published a code of practice for these systems, which has now been adopted internationally as ISO/IEC 27002:2013.

This is one of the most important accreditations we hold, as it demonstrates our ability to securely manage data.

Why do businesses choose to achieve this?

Information is critical to the operation and protection of an organisation. Being certified to ISO/IEC 27001 helps to manage and protect valuable information assets. The key concept of information security management systems (ISMS) is the ability to equivalently protect, maintain and improve confidentiality, integrity, and availability of our information assets that should be protected by the organisation.

ISO27001:2015 Underpins our commitment to take information security seriously and do all we can to protect any data that we have and keep it as secure as possible.

How do we achieve this?

CFH Radstock maintain registration to ISO 27001:2013. An independent audit is carried out by BSI, against the requirements of the standard twice per year at the Radstock site. PRINT.UK.COM has been added as an extension of scope to the Radstock certification to maintain registration to ISO 27001. The Windsor site is audited by BSI once per year as part of the schedule for both sites.

CFH Livingston maintain registration to ISO 27001:2013 through the NQA certification governing body. An independent audit is carried out by NQA, against the requirements of the standard once per year at the Livingston site.

The 3 ISO standards work on a 3 year audit cycle – 2 years of surveillance audits where samples of the standard are audited and then in the third year, a full standard re-certification audit takes place to ensure that we are meeting the required standard and can continue to display the ISO badge.

Cyber Essentials Certification

What is it?

This government-backed scheme is simple but effective, that helps companies to protect their organisation, whatever its size, against a whole range of the most common cyber-attacks.

Cyber Essentials’ trademark is its simplicity of approach. It provides guidance for the protection businesses need to put in place. The Cyber Essentials accreditation is a hands-on self-assessment technical verification that is carried out. The scheme includes five key controls that, when implemented correctly, can stop the majority of cyber-attacks.

Those controls are:

  • Secure configuration

  • Boundary firewalls and Internet gateways

  • Access controls and administrative privilege management

  • Patch management

  • Malware protection

Why do businesses choose to achieve this?

Cyber Essentials permits us to work with the UK government. According to the UK government, achieving Cyber Essentials could prevent “around 80% of cyber-attacks”.

How do we achieve this?

Cyber Essentials certification applies to the whole CFH group that covers all three sites.

Certification to Cyber Essentials requires annual re-assessment which includes carrying out a full technical check across all of our internal systems which includes everything in the control list.

Other achievements we hold

So there you have it, some of our accreditations and certifications explained and they are just the start of it!

We are GDPR compliant and hold other accreditations, including ISO 14001:2015 Environmental Management, Forest Stewardship Council® Certification FSC® certified (FSC®C006025) and Programme for the Endorsement of Forests Certification (PEFC).

We also have places on a number of frameworks including Crown Commercial Services and Shared Business Services for the NHS.

This combined with internal controls and processes we have in place to continuously manage our customer expectations and requirements; means we focus on delivering the best service and solutions possible to help achieve your practice goals and objectives.

Get in touch

Why not get in touch to find out more about the accreditations, certifications and processes we have in place and how we can help you achieve your goals with effective, reliable, industry-leading communications? 

Or why not find out all about how our hybrid mail solution, the Docmail Print Driver, has helped practices transform their communications by reading our blog:
Medical Practices: Using the hybrid mail print driver

Related Content...

Quality and Outcomes Framework: ARE YOU WHERE YOU NEED TO BE?
Jan 31 2024

Quality and Outcomes Framework: ARE YOU WHERE YOU NEED TO BE?

Blogs, Hybrid mail, Docmail, Health
Data Security and Protection Toolkit – Standards Exceeded Achievement
Dec 15 2023

Data Security and Protection Toolkit – Standards Exceeded Achievement

News, Public Sector, Communications
CFH Docmail Ltd named on Crown Commercial Service Framework
Nov 13 2023

CFH Docmail Ltd named on Crown Commercial Service Framework

News, Public Sector, Communications, Hybrid communications, Hybrid Mail
Jul 05 2023

NHS Derby and Derbyshire ICB

Docmail, saving valuable time and money while supporting the NHS Long Term Plan, across 110 surgeries and a combined 1 million patient cohort.

Public Sector, Hybrid communications, Docmail, Health
What is the impact of NHS mail on patients?
Jun 08 2023

What is the impact of NHS mail on patients?

Blogs, Hybrid mail, Docmail
The Power Of The Letter In The Health Sector
Dec 01 2022

The Power Of The Letter In The Health Sector

Blogs, Hybrid mail, Docmail
12 Top Tips For Increasing Patient Engagement This Winter Season
Sept 02 2022

12 Top Tips For Increasing Patient Engagement This Winter Season

Blogs, Hybrid mail, Docmail
8 ways to improve public sector communications
Jun 30 2022

8 ways to improve public sector communications

Blogs, Public Sector, CFH Managed, Managed communications, Communications
What Is Accreditation And Why Is It So Important To The Public Sector?
Jun 08 2022

What Is Accreditation And Why Is It So Important To The Public Sector?

Blogs, Communications
Medical Practices: Using The Hybrid Mail Print Driver
Feb 23 2022

Medical Practices: Using The Hybrid Mail Print Driver

Blogs, Hybrid mail, Docmail
Managing Practice Pressure
Oct 25 2021

Managing Practice Pressure

Blogs, Hybrid mail, Docmail, Health
Flu Vaccine Delays And Increased Eligibility: 3 Ways To Manage With Pre-planned Communications
Sept 13 2021

Flu Vaccine Delays And Increased Eligibility: 3 Ways To Manage With Pre-planned Communications

Blogs, Hybrid mail, Docmail, Health
Best Practice: Patient Communication Management This Winter
Jul 21 2021

Best Practice: Patient Communication Management This Winter

Blogs, Hybrid mail, Docmail, Health
Overcoming Vaccine Hesitancy For Children - How Good Communication Can Help
May 28 2021

Overcoming Vaccine Hesitancy For Children - How Good Communication Can Help

Blogs, Hybrid Mail, Docmail, Health

Derbyshire Community Health Service NHS Trust

Derbyshire Community Health Service NHS Foundation Trust, utilising hybrid mail to streamline patient communication processes and increase engagement.

Public Sector, Hybrid Mail, Docmail, Health

NHS West Suffolk CCG / NHS Ipswich & East Suffolk CCG

Hybrid mail helping increase patient opt in by 40%, for the primary care information sharing programme across 12 surgeries.

Public Sector, Digital Transformation, CFH Transform, Health, Partnerships

University of Nottingham

UK Trial Manager at University of Nottingham uses hybrid mail to attract trial participants by driving patient engagement with print and post.

Public Sector, Hybrid mail, Docmail

The Menston and Guiseley Practice

With an ageing population and specific patient cohorts opting for letters as their communication preference, the surgery required an alternative process for sending printed mail.

CFH Docmail, Hybrid Mail, Docmail, Public Sector, Health

Bingley Medical Practice

Despite communications experiencing a shift towards digital channels, print and post remain critical in engaging and providing important information to patients.

CFH Docmail, Hybrid Mail, Docmail, Public Sector, Health
Blogs, Communications

Subscribe to receive the latest CFH insights straight to your mail box