1. What the regulation says
Care and treatment must be provided in a safe way for service users. (Reg 12(1) (the headline duty))
assessing the risks to the health and safety of service users of receiving the care or treatment, (Reg 12(2)(a) (risk assessment))
doing all that is reasonably practicable to mitigate any such risks, (Reg 12(2)(b) (risk mitigation))
ensuring that persons providing care or treatment to service users have the qualifications, competence, skills and experience to do so safely, (Reg 12(2)(c) (staff competence))
The full text is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/12. Where this policy and the regulation diverge, the regulation wins.
2. Plain-English summary
Care and treatment must be provided in a safe way. The regulation lists the areas a provider must address, including risk assessment, risk mitigation, staff competence, safe premises, safe equipment, sufficient equipment and medicines, medicines safety, infection prevention and shared-care planning. Regulation 12 is central to CQC's safety expectations.
3. Purpose
Teledermatology, assessing skin remotely from images, is convenient and often effective, but a remote view has limits: an image can miss a lesion, hide a worrying feature, or be too poor to judge. This policy sets out when the Service assesses skin remotely, the standards the images must meet, and how it makes sure a patient who needs to be seen in person is seen.
The Service must verify this policy against current British Association of Dermatologists teledermatology guidance and GMC guidance on remote consultations before adoption.
4. Sources to verify before adoption
- British Association of Dermatologists, teledermatology guidance: https://www.bad.org.uk/
- GMC, guidance on remote consultations and prescribing: https://www.gmc-uk.org/
- Data Protection Act 2018 and the UK GDPR (clinical images and remote-consultation data): https://www.legislation.gov.uk/ukpga/2018/12/contents
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, Regulation 12 (safe care and treatment): https://www.legislation.gov.uk/uksi/2014/2936/regulation/12
5. Scope
This policy applies to:
- skin assessment carried out remotely from images or video
- the decision to manage remotely or to bring the patient in
- the clinicians who assess remotely and the staff who support the service
6. When remote assessment is appropriate
- the Service assesses remotely only where it can reach a safe decision from what it can see
- where the images are inadequate, the history raises concern, or the lesion may be cancer, the patient is brought in for a face-to-face assessment rather than judged on a poor remote view
- a remote consultation is not used to avoid an examination that the patient needs
7. Image quality and what is captured
- the Service sets the standard for the images it needs, including a clear overview, a close-up and, where used, a dermoscopic image, with the lesion site identified
- where the images do not meet the standard, the patient is asked for better ones or brought in
- the clinician records what they could and could not see, so the limits of the assessment are clear
8. Identity, consent and the record
- the patient's identity is confirmed before a remote consultation
- the patient consents to the remote consultation and to the images, and the consent is recorded
- the remote consultation, the images relied on, the assessment, the decision and the advice are recorded as fully as a face-to-face consultation
9. Safety-netting
The patient is told, in a form they can keep:
- the outcome and any uncertainty in it
- what to watch for and what to do if the lesion changes
- how and when to come in if needed, and how to reach the Service
The Service does not close a remote case where the assessment was uncertain without arranging the next step.
10. Protecting remote-consultation data
- images and consultation data are handled on secure systems, not personal phones or unprotected apps
- patient images are linked to the right record and protected as sensitive personal data
- any loss or exposure of remote-consultation data is treated as a possible data breach and reported at once
Operational controls to adapt
Roles and responsibilities
- Registered Manager: owns the remote-consultation system and makes sure safety, privacy and audit controls are in place.
- Remote assessing clinician: decides whether remote assessment is safe, records the limits of the assessment, and escalates to face-to-face care where needed.
- Image taker or support staff: confirms identity and consent, captures images to the required standard, and uploads them only through the approved route.
- Information Governance Lead: controls image transfer, storage, access, retention and breach response.
- Governance lead: reviews remote-assessment incidents, image-quality failures, data breaches and improvement actions.
Teledermatology procedure
- Triage suitability. Decide whether remote assessment is safe for the concern, patient group, lesion type and available image quality.
- Confirm identity and consent. Confirm the patient, explain remote assessment and image use, and record consent.
- Capture the required images. Obtain overview, close-up and dermoscopic images where needed, with the lesion site clearly identified.
- Reject unsafe image sets. If images are out of focus, incomplete, wrongly labelled or clinically inadequate, request new images or arrange face-to-face review.
- Record the assessment limits. State what could and could not be assessed remotely, and the level of confidence in the decision.
- Escalate to face-to-face care. Escalate where cancer, infection, safeguarding, treatment failure, uncertain diagnosis or patient deterioration cannot be safely managed remotely.
- Close only when safe. Give the patient clear advice, follow-up, safety-netting and a contact route before closing the remote case.
- Protect the data trail. Store images only in the approved system and treat any wrong-recipient, lost image or personal-device use as a possible data breach.
Records and register links
The remote-consultation record should include:
- suitability decision and reason remote assessment was or was not safe
- identity check, consent and contact method
- image set received, quality check and any rejected image reason
- clinical history, lesion site, assessment limits and decision
- face-to-face escalation, urgent referral, follow-up or safety-net advice
- data-transfer route, storage location and any breach assessment
- incident, data-breach record, risk entry or improvement action where relevant
Unsafe remote assessment, delayed escalation, image mix-up and data breaches are opened on the incident or data-breach route. Repeated image-quality or pathway failures are tracked through the risk register and improvement-actions register.
11. Training
Clinicians assessing skin remotely are competent to do so and understand the limits of remote assessment, and are refreshed on a stated cadence. The Service records who is competent and the next refresher date.
12. Audit cadence
The Service checks, on a stated cadence, that:
- remote assessments were made only where a safe decision was possible, with patients brought in where needed
- images met the standard and their limits were recorded
- identity and consent were confirmed and the consultation fully recorded
- safety-netting and next steps were given, and remote-consultation data was handled securely
The Registered Manager and the clinical lead review the results and record the improvement actions that follow.
13. Sources and further reading
This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.
- CQC Regulation 12: Safe care and treatment
- CQC Regulation 17: Good governance
- GMC guidance on remote consultations and prescribing
- British Association of Dermatologists teledermatology guidance
- Clinical image standards for skin assessment (BAD / Primary Care Dermatology Society guidance)
- Data Protection Act 2018 and the UK GDPR; ICO personal data breach guidance (clinical images and remote-consultation data)
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (https://www.legislation.gov.uk/uksi/2014/2936/regulation/12)
Related reading
- Related policy: Dermoscopy and lesion documentation policy
- Related policy: Skin cancer recognition and urgent referral policy
- Related policy: Personal Data Breach Notification Policy
- Related policy: Record Keeping and Documentation Standards Policy
14. When to seek further advice
Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.
15. Document control
| Version | Date | Author | Changes |
|---|---|---|---|
| v1.1 | 2026-07-14 | Verivius (sample) | Added role ownership, teledermatology workflow, record fields, register links and related reading. |
| v1 | 2026-06-10 | Verivius (sample) | Conformed to the Verivius policy standard: added statutory anchor, verbatim Regulation 12 text and plain-English summary, sources and further reading, and document control. Original purpose, scope and operational sections preserved. |
This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.