Fresh Tech
NHS Data Security Guidefresh-tech.uk | 01584 517 234

Free Industry Guide

NHS Data Security Guide

Meet DSPT requirements, secure patient data, and pass CQC inspections

Healthcare providers face some of the strictest data protection requirements in any sector. Patient confidentiality is critical, regulators are vigilant, and the consequences of a breach are severe. This guide covers the IT controls needed to protect patient data and meet regulatory requirements.

Read Time
14 min
Checklist Items
20
Last Updated
Dec 2025

Data Security & Protection Toolkit

The DSPT is an annual self-assessment that all organisations handling NHS patient data must complete. It covers 10 National Data Guardian standards.

Key Requirements:

  • Personal Confidential Data: Identify what you hold and where
  • Staff Responsibilities: Training and awareness
  • Training: Annual cyber security training for all staff
  • Managing Access: Principle of least privilege
  • Process Reviews: Regular review of who has access to what
  • Responding to Incidents: Documented procedures
  • Continuity Planning: Backup and disaster recovery
  • Unsupported Systems: No Windows 7/XP without risk mitigation
  • IT Protection: Antivirus, patching, firewalls
  • Accountable Suppliers: Due diligence on third parties

Submission Deadline:

30th June annually. Status affects ability to access NHS systems.

Common Fail Points:

  • Staff training not completed (or not documented)
  • Outdated systems still in use
  • No documented incident response procedure
  • Backup testing not evidenced

Action Checklist

  • Critical
  • Critical
  • High Priority
  • High Priority
  • Recommended

Clinical System Security

Clinical systems (EMIS, SystmOne, Vision, Dentally, etc.) contain highly sensitive patient data. Lose control of them and you have a reportable data breach, lost patient trust, and every clinical record exposed at once.

Access Control:

  • Individual logins for every user (no shared accounts)
  • Role-based permissions (reception can't access clinical notes)
  • Automatic session timeout after inactivity
  • Audit trail of who accessed which records

Integration Security:

  • Secure connections to NHS Spine
  • NHSmail for clinical correspondence
  • Encrypted connections for remote access
  • No patient data on personal email accounts

Workstation Security:

  • Screen positioned away from patient view
  • Automatic screen lock after 5 minutes
  • Privacy screens on reception PCs
  • Smartcard required for NHS Spine access

Action Checklist

  • Critical
  • High Priority
  • Recommended
  • High Priority
  • High Priority

Network Segmentation & Guest WiFi

Patients expect WiFi. But letting them on your clinical network is a serious security risk.

The Three-Network Model:

  1. Clinical Network: Staff PCs, clinical systems, NHS Spine
  2. Corporate Network: Admin PCs, email, non-clinical applications
  3. Guest Network: Patient WiFi, isolated from everything else

Guest WiFi Best Practices:

  • Completely separate VLAN (can't see clinical network)
  • Bandwidth throttling (patients don't slow down clinical work)
  • Content filtering (block inappropriate sites)
  • Terms of use acceptance (liability protection)
  • No password, or simple daily-changing password

Implementation:

Modern access points (like Ubiquiti UniFi) make this straightforward. A single device can broadcast multiple network names (SSIDs), each on a separate VLAN.

Action Checklist

  • Critical
  • High Priority
  • Recommended
  • Recommended
  • Critical

CQC Inspection Preparation

CQC inspectors increasingly ask about IT security as part of the "Safe" and "Well-led" domains.

What Inspectors Look For:

  • Evidence of staff training (certificates, attendance records)
  • Written policies (IT security, acceptable use, BYOD)
  • Business continuity plans (what if systems go down?)
  • Incident records (even if no incidents have occurred)
  • Risk assessments (including cyber risks)

Common Questions:

  • "How do you ensure patient data is kept confidential?"
  • "What would happen if your clinical system was unavailable?"
  • "How are staff trained on data protection?"
  • "When did you last test your backups?"

Documentation to Prepare:

  • IT Security Policy
  • Business Continuity Plan
  • Staff training records
  • Backup test evidence
  • Supplier contracts with data processing terms

Action Checklist

  • High Priority
  • High Priority
  • Critical
  • Critical
  • Recommended

Ready to Implement?

This guide gives you the knowledge. We provide the expertise to make it happen. Book a free consultation to discuss your healthcare IT needs.

Contact Fresh Tech for a free consultation:

Phone 01584 517 234 | Email hello@fresh-tech.uk | Web fresh-tech.uk

Signal for Help

Ready to banish tech headaches? Fill out the form or book a chat directly. Tell us what you need help with and how best to reach you.

Trusted by local businesses for over 10 years

Thinking of switching providers? See how easy it is

Send a message

Tell us what you need help with

Share the basics and we can start with the right context. Please do not include passwords or other sensitive information.

A little more context (optional)

JavaScript is needed to send this secure form. You can still call or email us using the details on this page.

Essentials keep the site working. The rest is up to you: flip it off and we won't load it.

Read the full cookie policy