Reponsible for the UI/ UX design of the service portal for citizens to access sensitive information on a national scale.
What we did?
We collaborated with a National Health Service Organisations to complete the design and delivery of a data subject notification service to notify those who have had their data breached as part of a ransomware attack.
Key Requirements included:
A centralised system to manage notification and data requests
A portal and ID verification service for citizen engagement
A Contact Centre to handle queries and questions
The development of key processes for the management of a “path to resolution”
This engagement is a shining example of Transformation Realised, placing humans at the centre, bringing technology at speed and innovation at scale, through the design and deployment of case management, portal, ID&V, and contact centre connectivity.
Over 130k data subjects notified across three client organisations
Multiple external stakeholders to keep informed, including Government and Data Protection Commissioner
I was part of a team that was mobilised a cross-service line multi-disciplinary team from Consulting (TC, BC and PAS) and Assurance (Forensics and Data & analytics) from Ireland and the Netherlands to support the National health service to design a process, solution and service to enable notification of data subjects.
The team deployed a solution based on Microsoft Dynamics and Power Platform, ID Pal (an Irish SME and leader in identity verification ID&V) and Twilio (a contact centre specialist technology provider) in addition to Platform Application Support and a Cyber Threat Monitoring Service
EY supported the client to define requirements and complete the detailed design for the notification service, which placed the citizen at the centre and considered the specific needs of vulnerable patients.
Notification service was customised to put extra focus on the most sensitive cases, where the data breach contained highly confidential medical records and data subjects were provided with pre- and post-notification support services.