A patient record doesn’t need a hacker to go missing. It needs an unlabelled crate, an unvetted porter, and forty-five unsupervised minutes in a loading bay.
Healthcare data security relocation planning is usually treated as a compliance exercise – get the paperwork signed, tick the GDPR box, move on. That’s a mistake. The paperwork tells you what you’re obligated to protect. It says almost nothing about who’s physically holding the box at 6am on move day, whether the van left the building on a tracked route, or whether anyone signed for the handover at the other end. This article covers that operational layer: vetted personnel, physical chain of custody, on-site access control, and what to do the moment something goes wrong.
If you need the regulatory grounding – DSPT, National Data Guardian standards, ICO and NCSC expectations – our enterprise IT relocation playbook covers that in full. This piece picks up where that one leaves off: the physical protocol you should be able to demand from any vendor before you sign a contract.
Why a Physical Move Is a Different Risk to a Cyberattack
Cybersecurity teams spend years hardening firewalls, patching servers, and running phishing drills. Then the Trust decides to move buildings, and every one of those controls becomes irrelevant for a weekend.
A move day breach doesn’t look like a breach. It looks like a stack of patient files left on a trolley in a public corridor while the crew takes a tea break. It looks like a decommissioned server going onto a generic van with no manifest, because “it’s just old kit.” It looks like a locum porter nobody vetted, handling boxes marked “confidential” because the regular team called in sick.
None of that trips an intrusion detection alert. There’s no log file. The data has simply left the building’s controlled environment and entered a gap – a physical, human, procedural gap – that most cybersecurity budgets were never built to cover.
The distinct risks during a physical move:
Custody gaps – nobody can say exactly where a specific box or drive was at a given time.
Untrained handling – general movers who don’t know a patient records crate from a stationery box.
Unsecured transit – an unmarked van, no tracking, no lock, sat outside a site overnight.
Informal handoffs – records passed between staff with no signature, no name, no timestamp.
Media left behind – decommissioned drives, backup tapes, or imaging media found in a skip weeks later.
Every one of these is preventable with the right vendor and the right protocol. None of them is prevented by a good firewall.
Vetted Personnel: Who’s Allowed to Touch Your Patient Records

The single biggest control you have over healthcare data security relocation risk is deciding, in writing, who’s allowed near the data – before the move date, not on the morning of it.
DBS checks and clearance levels for relocation teams
Not every mover on a job needs the same level of clearance, but every mover who touches a patient-adjacent crate does.
At minimum, staff handling confidential records or imaging media on an NHS or private healthcare site should hold:
A Basic DBS check as the floor requirement for anyone with any access to the site during the move – no exceptions, no “he’s been with us for years.”
Enhanced DBS clearance for team leads and anyone packing, labelling, or reconciling records directly – the people making the judgement calls about what’s confidential.
Named, photo-ID’d individuals on a pre-approved list submitted to your estates or IG team ahead of the move – not “a crew of six, TBC.”
Site-specific inductions covering your Trust’s own information governance rules, not just the vendor’s generic training slide.
Ask any vendor for their vetting policy in writing, and ask how recently their checks were renewed. A DBS check from three years ago on a subcontractor nobody’s re-verified isn’t vetting – it’s a piece of paper.
What “vetted personnel” should actually mean in a contract
“Our team is fully vetted” is a sentence that means nothing until it’s specific. Push for:
A named team roster for your move, confirmed at least a week out, with clearance level against each name.
No substitutions on the day without written notification and equivalent clearance confirmed before they set foot on site.
Confidentiality agreements signed individually, not as a blanket clause in the master services contract.
Subcontractor parity – if the vendor uses subcontracted labour for loading or transport, the same vetting standard applies to them too. A weak link at the subcontractor level defeats the whole chain.
This matters just as much for a private hospital group as it does for an NHS Trust. Patient data doesn’t become less sensitive because the building doesn’t have “NHS” on the sign.
Chain of Custody: The Protocol You Should Be Able to Demand From Any Vendor
Chain of custody isn’t a nice-to-have add-on. It’s the single control that lets you answer, with certainty, “where was this specific record at 2pm on Tuesday?” If your vendor can’t answer that question for every crate, you don’t have a chain of custody – you have a hope.
Here’s the protocol, step by step. Any credible relocation partner should be able to walk you through each stage without hesitation.
Step 1 – Inventory and sign-off at origin
Every box, crate, drive, and asset containing patient data gets logged against a manifest before it’s sealed – not after. The manifest records what’s inside, who packed it, and a unique reference number. A named individual at the origin site signs the manifest confirming it’s accurate.
Step 2 – Tamper-evident packing
Confidential records and imaging media travel in tamper-evident crates – sealed containers where any attempt to open them in transit leaves a visible, unrepairable mark. Standard cardboard boxes and shrink wrap don’t qualify. If the seal number on arrival doesn’t match the seal number logged at departure, that’s an immediate flag, not a shrug.
Step 3 – GPS-tracked, secure transit
Vehicles carrying patient-adjacent crates should run on GPS-tracked routes, with the route agreed in advance and deviations flagged automatically. No unplanned stops. No shared loads with unrelated cargo. Vehicles should be locked and, ideally, alarmed for the duration of transit – not “kept an eye on” by the driver during a fuel stop.
Step 4 – Signed handoffs at every point
Every time custody changes hands – loading, transfer between vehicles, arrival at a temporary storage facility, final delivery – someone signs for it. Digitally is better than paper, because a digital custody log timestamps automatically and can’t be back-filled after the fact. A chain with a gap in the middle is a broken chain, whatever the two ends look like.
Step 5 – Reconciliation and sign-off at destination
On arrival, every crate is checked against the original manifest by a named receiving officer – seal numbers matched, item counts confirmed, discrepancies logged immediately rather than at the end of the day when memories have blurred. Only once reconciliation is complete does the move count as closed for that asset.
This is exactly the kind of detail that separates a generalist office mover from a partner built for NHS relocation work, where the receiving officer, the manifest, and the sign-off aren’t optional extras – they’re the job.
Secure Handling of Physical Records and Imaging Media
Paper files, X-ray archives, and legacy imaging media (tape backups, old disks, microfiche) carry a different risk profile to a modern server rack, and they get overlooked more often precisely because they look low-tech.
For physical records:
Pack only into tamper-evident, lockable crates – never loose boxes or open trolleys.
Restrict packing of confidential files to enhanced-clearance staff only.
Keep a running crate count reconciled hourly during a live move, not just at the start and end.
For imaging media and legacy storage:
Anything being decommissioned rather than relocated needs secure sanitisation or certified destruction, not a skip. The National Cyber Security Centre’s guidance on secure sanitisation of storage media sets out the standard your disposal partner should be meeting, including certificates of destruction you can file against your asset register.
Media awaiting sanitisation should sit in a locked, access-logged store – never on an open shelf “for a few days” while someone gets round to it.
Get a destruction certificate for every asset, matched against your asset register, not a generic disposal note covering “one pallet of IT equipment.”
A data centre relocation involving patient administration systems or diagnostic archives should follow this same discipline for every drive and tape, whether it’s moving to a new server room or being retired for good.
On-Site Access Control During the Move Itself

The building’s normal access control – swipe cards, reception sign-in – often breaks down precisely when a move crew is on site, because doors get propped open for loading and normal traffic patterns go out the window.
Controls worth insisting on:
A single, controlled access point for the move crew, separate from general building traffic where possible.
High-visibility ID for every crew member, checked against the pre-approved roster at the door – not just glanced at.
No propped-open doors near areas holding confidential records, ever, even for five minutes.
A site supervisor from the vendor, present for the full duration, whose job is specifically to monitor access and custody – not also driving a van.
Restricted zones clearly marked and briefed to the crew before work starts, covering any area with patient-facing systems, medicines storage, or records archives.
This is where a generalist IT relocation team without healthcare-sector experience tends to fall down – treating a hospital corridor like a normal office floor plan, when it’s actually a controlled clinical environment with its own traffic rules.
Real-Time Asset Tracking Technology
Paper manifests and good intentions don’t scale past about a dozen crates. Real-time tracking does.
What to look for in a vendor’s tech stack:
GPS tracking on every vehicle, viewable live by your own project lead, not just the vendor’s dispatcher.
Barcode or RFID tagging on every crate and asset, scanned at each custody handoff automatically.
A digital custody log, accessible to your team in real time, showing exactly who scanned what, where, and when.
Automated alerts for route deviation, unexpected delay, or a seal mismatch – flagged the moment it happens, not discovered at reconciliation.
The point of the technology isn’t novelty. It’s that a digital, timestamped record is far harder to dispute – and far easier to audit after the fact – than a clipboard that could have been filled in anywhere.
If a Custody Break Occurs: Incident Response
Ask your vendor this question before you sign, not after something goes wrong: “What happens the moment a custody break is detected?” If the answer is vague, that’s your answer about the vendor.
A credible incident response protocol includes:
Immediate escalation to a named point of contact on both the vendor’s side and yours – within minutes, not at end of day.
A freeze on the affected shipment – the vehicle stops, the crate stays sealed, nothing else moves until the break is assessed.
A written incident log started immediately, capturing time, location, and everyone involved – this becomes the record your DPO and IG lead will need.
Notification to your Data Protection Officer without delay, so your Trust or organisation can assess whether the incident meets the threshold for wider reporting.
A post-incident review, whatever the outcome, feeding back into the vendor’s protocol so it doesn’t recur on the next job.
For the wider question of what a data incident means for your regulatory obligations – DSPT notification, ICO reporting thresholds – that sits in the compliance layer we cover in depth in our enterprise IT relocation guide. The ICO’s own guide to data security is worth having your IG team review alongside any incident, physical or otherwise.
Vendor Evaluation Checklist for Physical Data Security

Use this before you sign, not after the first crate’s already sealed.
Personnel
Enhanced and Basic DBS clearance confirmed in writing, with renewal dates
Named team roster supplied ahead of the move, no unapproved substitutions
Individually signed confidentiality agreements
Subcontractors held to the same vetting standard as direct staff
Chain of custody
Signed manifest at origin, itemised and reference-numbered
Tamper-evident crates for all confidential records and media
GPS-tracked, locked vehicles on a pre-agreed route
Digital custody log with timestamped handoffs
Reconciliation and sign-off by a named receiving officer at destination
Physical and on-site security
Single controlled access point for the move crew
High-visibility ID checked against roster at every entry
Site supervisor present throughout, dedicated to custody oversight
Restricted zones briefed and marked before work begins
Media and disposal
Secure sanitisation or certified destruction for decommissioned media
Locked, access-logged interim storage for anything awaiting destruction
Destruction certificates matched to asset register
Incident response
Written custody-break protocol with named escalation contacts
Freeze procedure for affected shipments
Incident log template ready before the move, not drafted after
A partner that can produce every line of this without reaching for a generic brochure is one you can trust with a patient record. One that can’t is a risk you’re accepting on someone else’s behalf.
FAQ
What’s the difference between data security and physical chain of custody during a healthcare move?
Data security usually refers to systems, encryption, and access controls protecting digital information. Chain of custody is the physical discipline of knowing exactly who held a specific record or device, at what time, at every point between the old site and the new one. A move needs both – a locked-down IT system doesn’t help if a records crate sits unattended in a corridor.
What DBS check level should relocation staff hold on an NHS site?
At minimum, a Basic DBS check for anyone on site during the move, with Enhanced DBS clearance for team leads and staff directly packing or handling confidential records. Ask your vendor to confirm clearance levels and renewal dates in writing before the move, not verbally on the day.
What happens if a crate goes missing during a healthcare facility move?
A credible vendor freezes the affected shipment immediately, escalates to a named contact on both sides, and starts a written incident log. Your Data Protection Officer should be notified without delay so your organisation can assess whether the incident meets any wider reporting threshold.
Do tamper-evident crates and GPS tracking actually reduce risk, or are they just for show?
They reduce risk in a specific, provable way: they turn “we think nothing went wrong” into “we can show nothing went wrong.” A tamper-evident seal makes any unauthorised access visible and unrepairable. GPS tracking closes the gap where a vehicle goes off-route with no one noticing until arrival.
How is this different from the compliance side of NHS data protection?
Compliance frameworks – DSPT, National Data Guardian standards, ICO and NCSC guidance – set out what you’re legally obliged to protect and how to evidence it. This article covers the operational layer underneath that: the vetted people, sealed crates, and tracked vehicles that make the compliance promise actually true on move day. For the regulatory detail, see our enterprise IT relocation playbook; for the wider planning picture on an NHS move, our guide to NHS office relocation compliance, planning, and continuity covers the full project lifecycle.