Any compliancy laws for storing medical data?

Hi all

I’ve recently been offered a project by a private clinic to handle the storage of patient data records taken during home visits.

They require a backend system and doctors and nurses on call will take notes via a mobile app and send them back to the office when they visit a patient.

Outside of the standard Data Protection Act, are there any other compliancy laws directly related to storing sensitive medical records in the UK? The data will be stored on a dedicated server and I will of course be looking to heavily protect the data regardless but just wanted to know of any additional requirements I might need to be aware of.


