
Free Industry Guide
NHS Data Security Guide
Meet DSPT requirements, secure patient data, and pass CQC inspections
Healthcare providers face some of the strictest data protection requirements in any sector. Patient confidentiality is critical, regulators are vigilant, and the consequences of a breach are severe. This guide covers the IT controls needed to protect patient data and meet regulatory requirements.
- Read Time
- 14 min
- Checklist Items
- 20
- Last Updated
- Dec 2025
Data Security & Protection Toolkit
The DSPT is an annual self-assessment that all organisations handling NHS patient data must complete. It covers 10 National Data Guardian standards.
Key Requirements:
- Personal Confidential Data: Identify what you hold and where
- Staff Responsibilities: Training and awareness
- Training: Annual cyber security training for all staff
- Managing Access: Principle of least privilege
- Process Reviews: Regular review of who has access to what
- Responding to Incidents: Documented procedures
- Continuity Planning: Backup and disaster recovery
- Unsupported Systems: No Windows 7/XP without risk mitigation
- IT Protection: Antivirus, patching, firewalls
- Accountable Suppliers: Due diligence on third parties
Submission Deadline:
30th June annually. Status affects ability to access NHS systems.
Common Fail Points:
- Staff training not completed (or not documented)
- Outdated systems still in use
- No documented incident response procedure
- Backup testing not evidenced
Action Checklist
- Critical
- Critical
- High Priority
- High Priority
- Recommended
Clinical System Security
Clinical systems (EMIS, SystmOne, Vision, Dentally, etc.) contain highly sensitive patient data. Lose control of them and you have a reportable data breach, lost patient trust, and every clinical record exposed at once.
Access Control:
- Individual logins for every user (no shared accounts)
- Role-based permissions (reception can't access clinical notes)
- Automatic session timeout after inactivity
- Audit trail of who accessed which records
Integration Security:
- Secure connections to NHS Spine
- NHSmail for clinical correspondence
- Encrypted connections for remote access
- No patient data on personal email accounts
Workstation Security:
- Screen positioned away from patient view
- Automatic screen lock after 5 minutes
- Privacy screens on reception PCs
- Smartcard required for NHS Spine access
Action Checklist
- Critical
- High Priority
- Recommended
- High Priority
- High Priority
Network Segmentation & Guest WiFi
Patients expect WiFi. But letting them on your clinical network is a serious security risk.
The Three-Network Model:
- Clinical Network: Staff PCs, clinical systems, NHS Spine
- Corporate Network: Admin PCs, email, non-clinical applications
- Guest Network: Patient WiFi, isolated from everything else
Guest WiFi Best Practices:
- Completely separate VLAN (can't see clinical network)
- Bandwidth throttling (patients don't slow down clinical work)
- Content filtering (block inappropriate sites)
- Terms of use acceptance (liability protection)
- No password, or simple daily-changing password
Implementation:
Modern access points (like Ubiquiti UniFi) make this straightforward. A single device can broadcast multiple network names (SSIDs), each on a separate VLAN.
Action Checklist
- Critical
- High Priority
- Recommended
- Recommended
- Critical
CQC Inspection Preparation
CQC inspectors increasingly ask about IT security as part of the "Safe" and "Well-led" domains.
What Inspectors Look For:
- Evidence of staff training (certificates, attendance records)
- Written policies (IT security, acceptable use, BYOD)
- Business continuity plans (what if systems go down?)
- Incident records (even if no incidents have occurred)
- Risk assessments (including cyber risks)
Common Questions:
- "How do you ensure patient data is kept confidential?"
- "What would happen if your clinical system was unavailable?"
- "How are staff trained on data protection?"
- "When did you last test your backups?"
Documentation to Prepare:
- IT Security Policy
- Business Continuity Plan
- Staff training records
- Backup test evidence
- Supplier contracts with data processing terms
Action Checklist
- High Priority
- High Priority
- Critical
- Critical
- Recommended
Ready to Implement?
This guide gives you the knowledge. We provide the expertise to make it happen. Book a free consultation to discuss your healthcare IT needs.
Contact Fresh Tech for a free consultation:
Phone 01584 517 234 | Email hello@fresh-tech.uk | Web fresh-tech.uk
Signal for Help
Ready to banish tech headaches? Fill out the form or book a chat directly. Tell us what you need help with and how best to reach you.
Trusted by local businesses for over 10 years
Thinking of switching providers? See how easy it is
- Call The Batphone01584 517 234
- Email HQhello@fresh-tech.uk
- Face-to-FaceBook an Intro Call with Sam
Tell us what you need help with
Share the basics and we can start with the right context. Please do not include passwords or other sensitive information.
Thanks. Your message has been submitted.
If the matter is urgent during business hours, call 01584 517 234.
Progress: 0/20
0%
Complete!
