• Uncategorised

Cyber Security and IT Compliance for Healthcare Providers: The 2026–27 Guide

If you run a clinic, care service, dental practice or any organisation that handles patient information, three things decide whether your cyber security is good enough: the NHS Data Security and Protection Toolkit (DSPT), what the Care Quality Commission (CQC) expects to see, and Cyber Essentials. The 2026–27 DSPT is now live, with a deadline […]

If you run a clinic, care service, dental practice or any organisation that handles patient information, three things decide whether your cyber security is good enough: the NHS Data Security and Protection Toolkit (DSPT), what the Care Quality Commission (CQC) expects to see, and Cyber Essentials. The 2026–27 DSPT is now live, with a deadline of 30 June 2027. Cyber Essentials tightened its rules in April 2026, so missing multi factor authentication on a cloud service is now an automatic fail.

This guide explains each of those in plain English, shows how they fit together, and sets out the practical controls that keep a healthcare provider safe, compliant and running. It is written for practice managers, registered managers, owners and operations leads, not IT specialists.

By the end you will know which rules apply to you, where most providers fall short, what to do this month and what to ask of whoever looks after your IT.

In short: compliance and good security are the same job viewed from two angles. Get the basics right (multi factor authentication, patching, tested backups, trained staff and a written incident plan) and the DSPT, CQC and Cyber Essentials largely look after themselves.

Which rules apply to your organisation?

Most independent healthcare providers in England deal with some mix of the DSPT, CQC registration, UK GDPR and Cyber Essentials. Which ones apply, and how strictly, depends on what you do and whether you touch NHS data or systems.

The table below is a starting point. If you hold an NHS contract, your commissioner’s requirements always take precedence, so check them.

Type of organisationDSPTCQC data and cyber expectationsUK GDPRCyber Essentials
Care home or domiciliary care providerExpected annually; needed for NHSmail and shared care recordsYes, assessed under the well led key questionYesIncreasingly asked for by local authority commissioners
Dental practice (NHS or mixed)Required for NHS work (Category 3)YesYesRecommended
Private clinic, physiotherapy, aesthetics or diagnosticsRequired if you access NHS data or systems; good practice otherwiseYes, if you carry out regulated activitiesYesRecommended; often asked for by insurers and partners
Pharmacy or opticianRequired for NHS work (Category 3)Pharmacies are regulated by the GPhC; opticians mostly by the GOCYesRecommended
GP practiceRequired (Category 4)YesYesCore clinical IT is usually provided through your ICB; local kit and networks often are not
IT, software or service supplier to the NHSRequired (Category 2)Not usually registeredYes, often as a data processorUsually a contract requirement

A note for GP practices: your clinical system and much of your core IT normally come through your Integrated Care Board. A local IT partner earns its place on everything around that, such as phones, broadband, printers, Wi‑Fi, non clinical devices and staff training.

Why are healthcare providers such a target?

Healthcare is attractive to criminals for two reasons. Patient records are valuable, and providers cannot afford to stop working, which makes them more likely to pay or to rush recovery.

The government’s own figures show how common attacks now are. The Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 43% of UK businesses identified a breach or attack in the previous 12 months. That rises to 65% of medium sized businesses. Phishing was by far the most common type, affecting 38% of businesses, and only around a quarter had a formal incident response plan.

Those are cross sector numbers. Two recent UK healthcare incidents show what they look like in practice.

IncidentWhat happenedWhat it costThe lesson for a smaller provider
Synnovis pathology attack (June 2024)Ransomware hit a pathology supplier to several London hospitals and GP services10,152 outpatient appointments and 1,710 elective procedures postponed; an estimated £32.7m loss; later found to have contributed to a patient’s deathYour risk includes your suppliers. One weak link in the chain can stop care for everyone downstream.
Advanced (OneAdvanced) ransomware (August 2022)Attackers got in through a customer account that had no multi factor authenticationNHS 111 and patient record access disrupted; data of 79,404 people affected, including details of how carers access homecare patients’ homes; a £3.07m ICO fine in 2025One account without multi factor authentication was enough. The ICO now fines data processors as well as the organisations they work for.

Neither of these started with anything exotic. Both came back to basics: account security, patching and how well organisations were prepared to keep working when systems went down. That is good news, because the basics are within reach of any provider.

The Data Security and Protection Toolkit (DSPT) explained

The DSPT is a free, online self assessment run by NHS England. You answer a set of questions, upload or reference evidence, and publish the result once a year. It measures you against the National Data Guardian’s ten data security standards, which fall into three areas: people, process and technology.

The 2026–27 version (version 9) has now been released, and the deadline for submission is 30 June 2027. It is aligned to version 4.0 of the National Cyber Security Centre’s Cyber Assessment Framework (CAF).

Which version of the DSPT do you complete?

Not everyone completes the same toolkit. Larger NHS bodies and some independent providers designated as operators of essential services complete the more demanding CAF aligned version. Most smaller providers complete a shorter set of assertions and evidence items based on their category.

CategoryWho it coversWhat it means in practice
CAF alignedNHS trusts, ICBs, arm’s length bodies, and independent providers designated as operators of essential servicesOutcome based assessment with an independent audit; organisations are not expected to reach every outcome in one year
Category 2IT suppliers to health and careA standard set of evidence items, including a mandatory independent audit
Category 3Dentists, opticians, pharmacies, social care providers, local authorities, universities and othersA proportionate set of mandatory and non mandatory evidence items
Category 4GP practicesA GP specific set, with some evidence supplied by your ICB’s GP IT service

What the outcome means

When you publish, you receive a status. Standards Met means you have provided all mandatory evidence. Approaching Standards means some mandatory evidence is still outstanding. Depending on your organisation type, it is reached through an agreed improvement plan or a reduced set of evidence items, and it is meant as a stepping stone, not a resting place. Standards Not Met means mandatory items are missing.

Your status matters for more than a badge. NHS England’s rules for access to shared systems require Approaching Standards or above for NHSmail, and Standards Met for shared care records and GP Connect. Some funding and commissioning arrangements now depend on your status too. Department of Health and Social Care guidance says that to count as a fully digitised care provider, you must use an assured digital social care record and reach Standards Met.

Where providers usually get stuck

The questions themselves are rarely the hard part. The sticking points are evidence that only an IT provider can produce, such as:

  • a list of all devices, with the operating system and patch status of each
  • confirmation that unsupported software has been removed or isolated
  • proof that backups run, are kept separately and have been restored in a test
  • multi factor authentication settings on email and cloud systems
  • records of staff data security training

If you leave this until June, you will be chasing several people at once. Gathering evidence through the year, as part of normal IT management, is far less painful.

What does CQC look for on data and cyber security?

CQC does not inspect your servers or test your firewall. It looks at whether you govern information well, and it treats the DSPT (or equivalent) as key evidence that you do.

Under the single assessment framework, CQC considers digital records and data security under the well led key question, within the quality statement on governance, management and sustainability. Its guidance on digital record systems says it expects providers to demonstrate compliance with the DSPT or equivalent, completed annually. It also states plainly that it does not assess the technical functioning of the systems themselves.

In practice, inspectors and assessors want to see that:

  • someone senior is accountable for data security and protection
  • staff know how to handle personal information and report a concern
  • records are accurate, available when needed and protected from unauthorised access
  • you know what you would do if your systems went down, and have tested it
  • incidents are recorded, learned from and reported where required

The legal basis for this is Regulation 17 (good governance) of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, which requires accurate, complete and secure records.

The most useful thing to remember is that a cyber incident is also a care quality incident. If your care planning system, rota or medication records are unavailable for three days, the question CQC will ask is how you kept people safe in the meantime. A business continuity plan that covers “no IT” is a care plan, not just an IT document.

Cyber Essentials, and what changed in April 2026

Cyber Essentials is the UK government backed certification for basic cyber hygiene. It checks five areas: firewalls, secure configuration, user access control, malware protection and keeping software up to date. Cyber Essentials is a verified self assessment. Cyber Essentials Plus adds a hands on technical audit of a sample of your devices.

For healthcare providers it is not usually a legal requirement, but it is increasingly asked for by commissioners, NHS partners and cyber insurers. It also produces exactly the kind of evidence the DSPT asks for, and NHS guidance confirms that organisations holding Cyber Essentials Plus do not have to answer some DSPT questions.

On 27 April 2026 the scheme moved to version 3.3 of its requirements, using a new question set called Danzell. It is the biggest tightening in several years.

AreaBefore April 2026From 27 April 2026 (version 3.3, Danzell)
Multi factor authenticationMissing MFA on a cloud service could be a non compliance without failingMFA not enabled on any cloud service that offers it is an automatic fail, even if it costs extra to turn on
Cloud servicesRequired in principle, but loosely enforcedStrictly enforced: cloud services holding your data cannot be excluded from scope
PatchingCritical and high risk updates within 14 daysStill 14 days, now with automatic fail questions and closer evidence checks
Cyber Essentials Plus auditOne sample of devices testedA failed sample triggers a second random sample; a second failure can cost you the certificate

One practical point: organisations that opened an assessment before 27 April 2026 can complete it under the previous rules until 27 October 2026. After that, everyone is assessed under Danzell. If your renewal is due in the next few months, plan for the new rules now.

For most healthcare providers, the change that matters most is MFA. Think about every cloud service your team signs into: Microsoft 365, your care planning or practice management system, payroll, rota software, online banking, even your social media pages. Each one that offers MFA now needs it switched on for every user.

UK GDPR and reporting a breach

Health information is special category data under UK GDPR, which means it needs a higher standard of protection. That applies whether or not you have an NHS contract.

If you suffer a personal data breach that is likely to put people’s rights and freedoms at risk, you must report it to the ICO within 72 hours of becoming aware of it. If the risk to individuals is high, you must also tell them without undue delay. Organisations that complete the DSPT report incidents through the toolkit’s own reporting tool, which passes the details to the ICO and the Department of Health and Social Care where required. The tool is not monitored around the clock, so for an urgent cyber incident, call the NHS 24 hour cyber support line as well.

Seventy two hours sounds generous until you are in the middle of an incident. Within that time you need to know what happened, which data was affected, roughly how many people are involved and what you have done to contain it. That is very hard without:

  • logging switched on for email and key systems, so you can see what was accessed
  • a named person who decides whether something is reportable
  • your IT provider’s emergency contact details somewhere that does not depend on your own systems, along with the NHS Cyber Security Operations Centre’s 24 hour support line (0300 303 5222) if you are covered by the DSPT
  • a simple incident log template, ready to fill in

The Advanced case shows the stakes have moved. The ICO’s fine was its first against a data processor, not just the organisation that owned the data. If you supply services to other healthcare organisations, you carry your own responsibility.

The ten controls that matter most

You do not need an enterprise security budget to be well protected. These ten controls cover most of what the DSPT, CQC and Cyber Essentials are looking for, and they stop the most common attacks.

#ControlWhy it mattersWhat good looks like
1Multi factor authenticationStolen or phished passwords are one of the most common ways in, as the Advanced attack showedMFA on every cloud service that offers it, for every user, including managers and admin accounts
2Patching and updatesUnpatched systems are an open door; Cyber Essentials now auto fails late critical patchesCritical and high risk updates applied within 14 days, with a report to prove it
3Supported devices onlyWindows 10 reached end of support on 14 October 2025 and no longer gets free security fixesNo unsupported operating systems on your network; Microsoft’s paid Extended Security Updates as a stop gap if needed; and a documented plan to replace the rest
4Tested backupsRansomware often goes after backupsAt least one copy kept separate from your network, and a restore tested at least once a year
5Email securityPhishing is the most common and most disruptive attackFiltering, link and attachment scanning, and checks that stop people spoofing your domain
6Staff trainingMost incidents start with a person, not a machineAnnual data security training for everyone, plus short refreshers and practice phishing tests
7Access controlLeavers and shared logins are a frequent DSPT findingIndividual logins, access removed on the day someone leaves, admin rights kept to a minimum
8Device protectionLaptops and phones carry patient data out of the buildingEncryption, a screen lock, malware protection and the ability to wipe a lost device remotely
9A business continuity planWhen systems go down, care still has to happenA written plan for running without IT for 24 to 72 hours, including paper fallbacks, tested once a year
10Supplier assuranceYour risk includes every supplier with access to your systems or dataA list of suppliers that handle your data, with their DSPT status or certifications checked

If you only tackle three this quarter, make them multi factor authentication, tested backups and a written continuity plan. Together they protect you from the most likely attacks and from the worst outcome, which is being unable to care for people.

A 12 month DSPT and cyber security plan for 2026–27

The providers who find the DSPT easy are the ones who treat it as a year round routine rather than a June scramble. Here is a simple plan that works back from the 30 June 2027 deadline.

MonthFocusWhat to do
October 2026Get your bearingsDownload the 2026–27 evidence items for your category; check your Cyber Essentials renewal date against the 27 October cut off
November 2026Know what you haveBuild or update a list of every device, user account, system and supplier
December 2026Close the big gapsSwitch on MFA everywhere it is offered; remove or isolate unsupported devices
January 2027PeopleRun annual data security training; check leavers’ accounts have been removed
February 2027BackupsCarry out and record a test restore; confirm one backup copy is kept separately
March 2027ContinuityReview the business continuity plan; run a short tabletop exercise of a “no IT” day
April 2027SuppliersCheck the DSPT status or certifications of every supplier that handles your data
May 2027Draft the toolkitComplete a first pass of the DSPT and list the evidence still missing
June 2027SubmitFinalise evidence, get sign off from your senior lead and publish before 30 June
July 2027LearnNote what was hard this year and fix the process, not just the paperwork
August 2027TestRun a practice phishing exercise and review incident logs
September 2027Plan aheadWatch for the 2027–28 toolkit release and set next year’s IT budget

If you are reading this later in the year, start from the current month and move anything you have missed into the next two months. The order matters less than starting.

What to ask of your IT support provider

Whoever looks after your IT will hold the keys to much of your compliance evidence. Many providers handle the technology well but have never seen a DSPT, which leaves the practice or registered manager translating between the two.

These questions will tell you quickly whether a provider understands healthcare.

Question to askA good answer sounds likeA warning sign
Can you produce the evidence the DSPT needs?A clear list of what they will supply, such as device lists, patch reports and backup test records“What’s the DSPT?”
How do you handle MFA across our cloud systems?They can show you which services have it on, and help switch it on for the restMFA only on email, or only for some staff
When did you last test restoring our backups?A date, and a record of what was restored and how long it took“The backups run every night” with no test on record
What happens if we are hit by ransomware on a Friday night?A named route to an engineer, and a plan that links to your continuity planA ticket queue that opens on Monday
Do you hold Cyber Essentials yourselves?Yes, with the scope explainedNo, or not sure
How do you control your own access to our systems?Individual engineer accounts with MFA, and access loggedShared logins used by the whole team
Will you help us plan the year, not just fix things?Regular reviews tied to your compliance calendar and budgetContact only when something breaks

The last question is the one that matters most over time. The point of good IT support in healthcare is not fast fixes, useful as they are. It is fewer things breaking, evidence that is ready when you need it, and managers who can spend their time on care rather than chasing passwords.

The law is also moving in this direction. The Cyber Security and Resilience Bill, which is in its final stages in the House of Lords and has not yet become law, is expected to bring medium and large managed service providers under formal cyber security duties for the first time, including telling customers when an incident may have affected them. Whatever size your provider is, it is reasonable to expect that standard now.

Frequently asked questions

Is the DSPT mandatory for private healthcare providers?

It is mandatory if you have access to NHS patient data or systems, or deliver care under the NHS Standard Contract. If you do not, it is not strictly required, but CQC recognises it as one of the most effective ways to show you handle data securely, and many commissioners and partners expect it.

When is the 2026–27 DSPT deadline?

The deadline is 30 June 2027. The 2026–27 toolkit (version 9) has been released, so you can start gathering evidence now.

Do care homes need Cyber Essentials?

There is no legal requirement, but local authority commissioners, NHS partners and insurers increasingly ask for it. It also produces evidence that helps with the DSPT, so it is worth considering alongside it.

What changed in Cyber Essentials in April 2026?

From 27 April 2026, missing multi factor authentication on any cloud service that offers it is an automatic fail, the rule that cloud services holding your data must be in scope is strictly enforced, and Cyber Essentials Plus audits test a second sample if the first fails.

Does CQC check our IT systems?

CQC does not test the technical side of your systems. It looks at how you govern information under the well led key question, and expects you to show DSPT compliance or equivalent each year.

How quickly do we have to report a data breach?

Within 72 hours of becoming aware of it, if it is likely to put people’s rights and freedoms at risk. If you complete the DSPT, you report through its incident reporting tool.

We still have some Windows 10 computers. Is that a problem?

Yes. Windows 10 stopped receiving free security updates on 14 October 2025. Unsupported devices are a common reason for falling short on the DSPT and Cyber Essentials, so replace them. As a stop gap, Microsoft’s paid Extended Security Updates run until October 2027; otherwise isolate them with a documented plan.

Where to start

If all of this feels like a lot, start small. Pick the three controls that matter most (MFA, tested backups and a continuity plan), put the June 2027 deadline in the diary, and ask your IT provider the questions above.

If you would like a second pair of eyes, 127 Solutions provides IT support for healthcare providers and NHS adjacent organisations across Wirral, Cheshire and Liverpool. A good first step is our IT Health Check: we look at where you stand against the DSPT and Cyber Essentials and give you a clear list of what to fix first. No jargon, and no obligation.

This guide is general information, not legal advice. Requirements vary by contract and category, so always check the current DSPT guidance for your organisation type.

Sources

Further Reading

  • Uncategorised

Is My IT Support Any Good?

The clearest signs your IT support isn’t doing its job are usually quiet rather than dramatic: slow responses that have become normal, having to chase for updates on…
Read More
  • Uncategorised

How to Set Up a New Starter’s IT on Their First Day

A new starter’s IT should be sorted before they arrive, not on the morning they turn up. That means a working laptop or PC loaded with the software…
Read More
  • Uncategorised

Setting Up IT for Hybrid Working Without the Headaches

Hybrid working IT comes down to four things: secure access from anywhere, files that stay in sync without anyone emailing attachments to themselves, a phone system that doesn’t…
Read More

Get a quote

We aim to respond to requests within 1 hour during our business hours of 08:00-17:30 Monday-Friday