If you run a clinic, care service, dental practice or any organisation that handles patient information, three things decide whether your cyber security is good enough: the NHS Data Security and Protection Toolkit (DSPT), what the Care Quality Commission (CQC) expects to see, and Cyber Essentials. The 2026–27 DSPT is now live, with a deadline of 30 June 2027. Cyber Essentials tightened its rules in April 2026, so missing multi factor authentication on a cloud service is now an automatic fail.
This guide explains each of those in plain English, shows how they fit together, and sets out the practical controls that keep a healthcare provider safe, compliant and running. It is written for practice managers, registered managers, owners and operations leads, not IT specialists.
By the end you will know which rules apply to you, where most providers fall short, what to do this month and what to ask of whoever looks after your IT.
In short: compliance and good security are the same job viewed from two angles. Get the basics right (multi factor authentication, patching, tested backups, trained staff and a written incident plan) and the DSPT, CQC and Cyber Essentials largely look after themselves.
Which rules apply to your organisation?
Most independent healthcare providers in England deal with some mix of the DSPT, CQC registration, UK GDPR and Cyber Essentials. Which ones apply, and how strictly, depends on what you do and whether you touch NHS data or systems.
The table below is a starting point. If you hold an NHS contract, your commissioner’s requirements always take precedence, so check them.
| Type of organisation | DSPT | CQC data and cyber expectations | UK GDPR | Cyber Essentials |
|---|---|---|---|---|
| Care home or domiciliary care provider | Expected annually; needed for NHSmail and shared care records | Yes, assessed under the well led key question | Yes | Increasingly asked for by local authority commissioners |
| Dental practice (NHS or mixed) | Required for NHS work (Category 3) | Yes | Yes | Recommended |
| Private clinic, physiotherapy, aesthetics or diagnostics | Required if you access NHS data or systems; good practice otherwise | Yes, if you carry out regulated activities | Yes | Recommended; often asked for by insurers and partners |
| Pharmacy or optician | Required for NHS work (Category 3) | Pharmacies are regulated by the GPhC; opticians mostly by the GOC | Yes | Recommended |
| GP practice | Required (Category 4) | Yes | Yes | Core clinical IT is usually provided through your ICB; local kit and networks often are not |
| IT, software or service supplier to the NHS | Required (Category 2) | Not usually registered | Yes, often as a data processor | Usually a contract requirement |
A note for GP practices: your clinical system and much of your core IT normally come through your Integrated Care Board. A local IT partner earns its place on everything around that, such as phones, broadband, printers, Wi‑Fi, non clinical devices and staff training.
Why are healthcare providers such a target?
Healthcare is attractive to criminals for two reasons. Patient records are valuable, and providers cannot afford to stop working, which makes them more likely to pay or to rush recovery.
The government’s own figures show how common attacks now are. The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 43% of UK businesses identified a breach or attack in the previous 12 months. That rises to 65% of medium sized businesses. Phishing was by far the most common type, affecting 38% of businesses, and only around a quarter had a formal incident response plan.
Those are cross sector numbers. Two recent UK healthcare incidents show what they look like in practice.
| Incident | What happened | What it cost | The lesson for a smaller provider |
|---|---|---|---|
| Synnovis pathology attack (June 2024) | Ransomware hit a pathology supplier to several London hospitals and GP services | 10,152 outpatient appointments and 1,710 elective procedures postponed; an estimated £32.7m loss; later found to have contributed to a patient’s death | Your risk includes your suppliers. One weak link in the chain can stop care for everyone downstream. |
| Advanced (OneAdvanced) ransomware (August 2022) | Attackers got in through a customer account that had no multi factor authentication | NHS 111 and patient record access disrupted; data of 79,404 people affected, including details of how carers access homecare patients’ homes; a £3.07m ICO fine in 2025 | One account without multi factor authentication was enough. The ICO now fines data processors as well as the organisations they work for. |
Neither of these started with anything exotic. Both came back to basics: account security, patching and how well organisations were prepared to keep working when systems went down. That is good news, because the basics are within reach of any provider.
The Data Security and Protection Toolkit (DSPT) explained
The DSPT is a free, online self assessment run by NHS England. You answer a set of questions, upload or reference evidence, and publish the result once a year. It measures you against the National Data Guardian’s ten data security standards, which fall into three areas: people, process and technology.
The 2026–27 version (version 9) has now been released, and the deadline for submission is 30 June 2027. It is aligned to version 4.0 of the National Cyber Security Centre’s Cyber Assessment Framework (CAF).
Which version of the DSPT do you complete?
Not everyone completes the same toolkit. Larger NHS bodies and some independent providers designated as operators of essential services complete the more demanding CAF aligned version. Most smaller providers complete a shorter set of assertions and evidence items based on their category.
| Category | Who it covers | What it means in practice |
|---|---|---|
| CAF aligned | NHS trusts, ICBs, arm’s length bodies, and independent providers designated as operators of essential services | Outcome based assessment with an independent audit; organisations are not expected to reach every outcome in one year |
| Category 2 | IT suppliers to health and care | A standard set of evidence items, including a mandatory independent audit |
| Category 3 | Dentists, opticians, pharmacies, social care providers, local authorities, universities and others | A proportionate set of mandatory and non mandatory evidence items |
| Category 4 | GP practices | A GP specific set, with some evidence supplied by your ICB’s GP IT service |
What the outcome means
When you publish, you receive a status. Standards Met means you have provided all mandatory evidence. Approaching Standards means some mandatory evidence is still outstanding. Depending on your organisation type, it is reached through an agreed improvement plan or a reduced set of evidence items, and it is meant as a stepping stone, not a resting place. Standards Not Met means mandatory items are missing.
Your status matters for more than a badge. NHS England’s rules for access to shared systems require Approaching Standards or above for NHSmail, and Standards Met for shared care records and GP Connect. Some funding and commissioning arrangements now depend on your status too. Department of Health and Social Care guidance says that to count as a fully digitised care provider, you must use an assured digital social care record and reach Standards Met.
Where providers usually get stuck
The questions themselves are rarely the hard part. The sticking points are evidence that only an IT provider can produce, such as:
- a list of all devices, with the operating system and patch status of each
- confirmation that unsupported software has been removed or isolated
- proof that backups run, are kept separately and have been restored in a test
- multi factor authentication settings on email and cloud systems
- records of staff data security training
If you leave this until June, you will be chasing several people at once. Gathering evidence through the year, as part of normal IT management, is far less painful.
What does CQC look for on data and cyber security?
CQC does not inspect your servers or test your firewall. It looks at whether you govern information well, and it treats the DSPT (or equivalent) as key evidence that you do.
Under the single assessment framework, CQC considers digital records and data security under the well led key question, within the quality statement on governance, management and sustainability. Its guidance on digital record systems says it expects providers to demonstrate compliance with the DSPT or equivalent, completed annually. It also states plainly that it does not assess the technical functioning of the systems themselves.
In practice, inspectors and assessors want to see that:
- someone senior is accountable for data security and protection
- staff know how to handle personal information and report a concern
- records are accurate, available when needed and protected from unauthorised access
- you know what you would do if your systems went down, and have tested it
- incidents are recorded, learned from and reported where required
The legal basis for this is Regulation 17 (good governance) of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, which requires accurate, complete and secure records.
The most useful thing to remember is that a cyber incident is also a care quality incident. If your care planning system, rota or medication records are unavailable for three days, the question CQC will ask is how you kept people safe in the meantime. A business continuity plan that covers “no IT” is a care plan, not just an IT document.
Cyber Essentials, and what changed in April 2026
Cyber Essentials is the UK government backed certification for basic cyber hygiene. It checks five areas: firewalls, secure configuration, user access control, malware protection and keeping software up to date. Cyber Essentials is a verified self assessment. Cyber Essentials Plus adds a hands on technical audit of a sample of your devices.
For healthcare providers it is not usually a legal requirement, but it is increasingly asked for by commissioners, NHS partners and cyber insurers. It also produces exactly the kind of evidence the DSPT asks for, and NHS guidance confirms that organisations holding Cyber Essentials Plus do not have to answer some DSPT questions.
On 27 April 2026 the scheme moved to version 3.3 of its requirements, using a new question set called Danzell. It is the biggest tightening in several years.
| Area | Before April 2026 | From 27 April 2026 (version 3.3, Danzell) |
|---|---|---|
| Multi factor authentication | Missing MFA on a cloud service could be a non compliance without failing | MFA not enabled on any cloud service that offers it is an automatic fail, even if it costs extra to turn on |
| Cloud services | Required in principle, but loosely enforced | Strictly enforced: cloud services holding your data cannot be excluded from scope |
| Patching | Critical and high risk updates within 14 days | Still 14 days, now with automatic fail questions and closer evidence checks |
| Cyber Essentials Plus audit | One sample of devices tested | A failed sample triggers a second random sample; a second failure can cost you the certificate |
One practical point: organisations that opened an assessment before 27 April 2026 can complete it under the previous rules until 27 October 2026. After that, everyone is assessed under Danzell. If your renewal is due in the next few months, plan for the new rules now.
For most healthcare providers, the change that matters most is MFA. Think about every cloud service your team signs into: Microsoft 365, your care planning or practice management system, payroll, rota software, online banking, even your social media pages. Each one that offers MFA now needs it switched on for every user.
UK GDPR and reporting a breach
Health information is special category data under UK GDPR, which means it needs a higher standard of protection. That applies whether or not you have an NHS contract.
If you suffer a personal data breach that is likely to put people’s rights and freedoms at risk, you must report it to the ICO within 72 hours of becoming aware of it. If the risk to individuals is high, you must also tell them without undue delay. Organisations that complete the DSPT report incidents through the toolkit’s own reporting tool, which passes the details to the ICO and the Department of Health and Social Care where required. The tool is not monitored around the clock, so for an urgent cyber incident, call the NHS 24 hour cyber support line as well.
Seventy two hours sounds generous until you are in the middle of an incident. Within that time you need to know what happened, which data was affected, roughly how many people are involved and what you have done to contain it. That is very hard without:
- logging switched on for email and key systems, so you can see what was accessed
- a named person who decides whether something is reportable
- your IT provider’s emergency contact details somewhere that does not depend on your own systems, along with the NHS Cyber Security Operations Centre’s 24 hour support line (0300 303 5222) if you are covered by the DSPT
- a simple incident log template, ready to fill in
The Advanced case shows the stakes have moved. The ICO’s fine was its first against a data processor, not just the organisation that owned the data. If you supply services to other healthcare organisations, you carry your own responsibility.
The ten controls that matter most
You do not need an enterprise security budget to be well protected. These ten controls cover most of what the DSPT, CQC and Cyber Essentials are looking for, and they stop the most common attacks.
| # | Control | Why it matters | What good looks like |
|---|---|---|---|
| 1 | Multi factor authentication | Stolen or phished passwords are one of the most common ways in, as the Advanced attack showed | MFA on every cloud service that offers it, for every user, including managers and admin accounts |
| 2 | Patching and updates | Unpatched systems are an open door; Cyber Essentials now auto fails late critical patches | Critical and high risk updates applied within 14 days, with a report to prove it |
| 3 | Supported devices only | Windows 10 reached end of support on 14 October 2025 and no longer gets free security fixes | No unsupported operating systems on your network; Microsoft’s paid Extended Security Updates as a stop gap if needed; and a documented plan to replace the rest |
| 4 | Tested backups | Ransomware often goes after backups | At least one copy kept separate from your network, and a restore tested at least once a year |
| 5 | Email security | Phishing is the most common and most disruptive attack | Filtering, link and attachment scanning, and checks that stop people spoofing your domain |
| 6 | Staff training | Most incidents start with a person, not a machine | Annual data security training for everyone, plus short refreshers and practice phishing tests |
| 7 | Access control | Leavers and shared logins are a frequent DSPT finding | Individual logins, access removed on the day someone leaves, admin rights kept to a minimum |
| 8 | Device protection | Laptops and phones carry patient data out of the building | Encryption, a screen lock, malware protection and the ability to wipe a lost device remotely |
| 9 | A business continuity plan | When systems go down, care still has to happen | A written plan for running without IT for 24 to 72 hours, including paper fallbacks, tested once a year |
| 10 | Supplier assurance | Your risk includes every supplier with access to your systems or data | A list of suppliers that handle your data, with their DSPT status or certifications checked |
If you only tackle three this quarter, make them multi factor authentication, tested backups and a written continuity plan. Together they protect you from the most likely attacks and from the worst outcome, which is being unable to care for people.
A 12 month DSPT and cyber security plan for 2026–27
The providers who find the DSPT easy are the ones who treat it as a year round routine rather than a June scramble. Here is a simple plan that works back from the 30 June 2027 deadline.
| Month | Focus | What to do |
|---|---|---|
| October 2026 | Get your bearings | Download the 2026–27 evidence items for your category; check your Cyber Essentials renewal date against the 27 October cut off |
| November 2026 | Know what you have | Build or update a list of every device, user account, system and supplier |
| December 2026 | Close the big gaps | Switch on MFA everywhere it is offered; remove or isolate unsupported devices |
| January 2027 | People | Run annual data security training; check leavers’ accounts have been removed |
| February 2027 | Backups | Carry out and record a test restore; confirm one backup copy is kept separately |
| March 2027 | Continuity | Review the business continuity plan; run a short tabletop exercise of a “no IT” day |
| April 2027 | Suppliers | Check the DSPT status or certifications of every supplier that handles your data |
| May 2027 | Draft the toolkit | Complete a first pass of the DSPT and list the evidence still missing |
| June 2027 | Submit | Finalise evidence, get sign off from your senior lead and publish before 30 June |
| July 2027 | Learn | Note what was hard this year and fix the process, not just the paperwork |
| August 2027 | Test | Run a practice phishing exercise and review incident logs |
| September 2027 | Plan ahead | Watch for the 2027–28 toolkit release and set next year’s IT budget |
If you are reading this later in the year, start from the current month and move anything you have missed into the next two months. The order matters less than starting.
What to ask of your IT support provider
Whoever looks after your IT will hold the keys to much of your compliance evidence. Many providers handle the technology well but have never seen a DSPT, which leaves the practice or registered manager translating between the two.
These questions will tell you quickly whether a provider understands healthcare.
| Question to ask | A good answer sounds like | A warning sign |
|---|---|---|
| Can you produce the evidence the DSPT needs? | A clear list of what they will supply, such as device lists, patch reports and backup test records | “What’s the DSPT?” |
| How do you handle MFA across our cloud systems? | They can show you which services have it on, and help switch it on for the rest | MFA only on email, or only for some staff |
| When did you last test restoring our backups? | A date, and a record of what was restored and how long it took | “The backups run every night” with no test on record |
| What happens if we are hit by ransomware on a Friday night? | A named route to an engineer, and a plan that links to your continuity plan | A ticket queue that opens on Monday |
| Do you hold Cyber Essentials yourselves? | Yes, with the scope explained | No, or not sure |
| How do you control your own access to our systems? | Individual engineer accounts with MFA, and access logged | Shared logins used by the whole team |
| Will you help us plan the year, not just fix things? | Regular reviews tied to your compliance calendar and budget | Contact only when something breaks |
The last question is the one that matters most over time. The point of good IT support in healthcare is not fast fixes, useful as they are. It is fewer things breaking, evidence that is ready when you need it, and managers who can spend their time on care rather than chasing passwords.
The law is also moving in this direction. The Cyber Security and Resilience Bill, which is in its final stages in the House of Lords and has not yet become law, is expected to bring medium and large managed service providers under formal cyber security duties for the first time, including telling customers when an incident may have affected them. Whatever size your provider is, it is reasonable to expect that standard now.
Frequently asked questions
Is the DSPT mandatory for private healthcare providers?
It is mandatory if you have access to NHS patient data or systems, or deliver care under the NHS Standard Contract. If you do not, it is not strictly required, but CQC recognises it as one of the most effective ways to show you handle data securely, and many commissioners and partners expect it.
When is the 2026–27 DSPT deadline?
The deadline is 30 June 2027. The 2026–27 toolkit (version 9) has been released, so you can start gathering evidence now.
Do care homes need Cyber Essentials?
There is no legal requirement, but local authority commissioners, NHS partners and insurers increasingly ask for it. It also produces evidence that helps with the DSPT, so it is worth considering alongside it.
What changed in Cyber Essentials in April 2026?
From 27 April 2026, missing multi factor authentication on any cloud service that offers it is an automatic fail, the rule that cloud services holding your data must be in scope is strictly enforced, and Cyber Essentials Plus audits test a second sample if the first fails.
Does CQC check our IT systems?
CQC does not test the technical side of your systems. It looks at how you govern information under the well led key question, and expects you to show DSPT compliance or equivalent each year.
How quickly do we have to report a data breach?
Within 72 hours of becoming aware of it, if it is likely to put people’s rights and freedoms at risk. If you complete the DSPT, you report through its incident reporting tool.
We still have some Windows 10 computers. Is that a problem?
Yes. Windows 10 stopped receiving free security updates on 14 October 2025. Unsupported devices are a common reason for falling short on the DSPT and Cyber Essentials, so replace them. As a stop gap, Microsoft’s paid Extended Security Updates run until October 2027; otherwise isolate them with a documented plan.
Where to start
If all of this feels like a lot, start small. Pick the three controls that matter most (MFA, tested backups and a continuity plan), put the June 2027 deadline in the diary, and ask your IT provider the questions above.
If you would like a second pair of eyes, 127 Solutions provides IT support for healthcare providers and NHS adjacent organisations across Wirral, Cheshire and Liverpool. A good first step is our IT Health Check: we look at where you stand against the DSPT and Cyber Essentials and give you a clear list of what to fix first. No jargon, and no obligation.
This guide is general information, not legal advice. Requirements vary by contract and category, so always check the current DSPT guidance for your organisation type.
Sources
- Data Security and Protection Toolkit 2026–27 version 9 — NHS England
- Access to shared systems and DSPT status — NHS England
- Digital record systems: assessing and inspecting — CQC
- Becoming a fully digitised care provider — DHSC
- Cyber Security Breaches Survey 2025/2026 — DSIT
- UK Cyber Security Breaches Survey 2025/2026: key takeaways — JD Supra
- Cyber Essentials changes: Danzell question set — LRQA
- Cyber Essentials changes April 2026 — Cyphere
- Cyber Essentials update 2026 — URM Consulting
- Synnovis attack led to at least two cases of severe patient harm — Digital Health
- Qilin ransomware attack on NHS supplier contributed to patient fatality — The Register
- Advanced Software fined £3m over LockBit attack — Computer Weekly
- ICO fines NHS IT supplier £3m — Computing
- Report a breach — ICO
- Cyber Security and Resilience Bill: what it means for your organisation — Howden
- Personal data breaches: guidance for IG professionals — NHS England
- Cyber security and resilience for digital healthcare technologies — NHS AI and Digital Regulations Service
- Report a cyber security incident — NHS England