Skip to main content

NHS and digital health security

NHS Application Security and Assurance

Develop secure digital health applications and prepare the evidence needed for NHS assurance, procurement and deployment. Astaria helps product teams address technical security, clinical safety, data protection and secure software-development requirements from discovery through operation.

For health technology companies, NHS suppliers, digital health teams and software vendors building products for UK health and care environments.

Security and assurance support tailored to your product, data, clinical functionality, integrations and deployment environment.

Direct answer

What security requirements apply to an NHS application?

There is no single security standard that applies identically to every application developed for NHS use. The appropriate assurance route depends on the product's intended purpose, users, clinical functionality, data processing, integrations and deployment environment.

Depending on scope, an application may need to address the Digital Technology Assessment Criteria, DCB0129 clinical risk management, Data Security and Protection Toolkit requirements, UK GDPR, accessibility, interoperability and medical-device regulation.

Astaria begins by establishing which requirements are relevant, who owns each responsibility and what evidence must be created.

The requirements depend on the product

A patient communication application, clinical decision-support system, staff portal and administrative website will not necessarily follow the same assurance route. Applicability should be established before making compliance claims or commissioning unnecessary work.

Assess my application

Suitability

Who we help

  • Digital health startups

    Preparing a product for an NHS pilot, procurement exercise or first deployment.

  • Established health technology suppliers

    Updating products, evidence and development controls for new NHS opportunities.

  • NHS software development partners

    Building applications or integrations on behalf of NHS organisations.

  • SaaS and platform providers

    Supplying hosted products that process health, patient or operational data.

  • NHS and healthcare innovation teams

    Assessing technical risks before piloting or deploying new technology.

  • AI health product teams

    Developing AI-enabled interpretation, documentation or workflow features that need careful risk and safety treatment.

Deliverables

What the work covers

Applicability assessment
Which assurance requirements are likely to apply to your product, who owns each responsibility and what evidence has to exist.
DTAC readiness support
Working through the Digital Technology Assessment Criteria sections, identifying gaps and preparing the supporting material.
DCB0129 clinical risk support
Where the product has clinical functionality, support for hazard logging, clinical safety case documentation and the clinical safety officer's process.
DSPT evidence preparation
Assembling the policies, technical controls and records that support Data Security and Protection Toolkit submissions.
Secure development controls
Threat modelling, secure coding practice, dependency and secrets management, access control, logging and release controls built into your pipeline.
Data protection support
UK GDPR considerations, data minimisation, retention, lawful basis, DPIA preparation and processor documentation.
Independent security testing
Coordinating penetration testing, agreeing scope, triaging findings and tracking remediation to closure.
Remediation and evidence pack
Fixing what testing and review found, then assembling the material buyers and assurance teams ask for.

Our approach

How we deliver it

  1. 01Establish applicability

    We map intended purpose, users, clinical functionality, data flows, integrations and hosting, then determine which requirements are genuinely relevant.

  2. 02Baseline the product

    A review of the current architecture, controls, documentation and development process against those requirements.

  3. 03Agree the plan

    A prioritised plan separating what must exist before procurement from what can follow, with owners and evidence named.

  4. 04Build the controls

    Security, privacy and safety work delivered alongside development rather than bolted on before a deadline.

  5. 05Test independently

    Security testing scoped and coordinated, with findings triaged by severity and exploitability rather than scanner output.

  6. 06Assemble the evidence

    Documentation packaged so an NHS assurance or procurement team can follow it without a further round of questions.

  7. 07Operate and maintain

    Patching, monitoring, dependency review and periodic reassessment as the product and its requirements change.

Standards

Frameworks and regulations we work to

We work to the requirements that apply to your product, and we say plainly where a requirement does not apply or where specialist advice is needed.

  • Digital Technology Assessment Criteria (DTAC) as a supplier self-assessment, completed accurately rather than optimistically.
  • DCB0129 clinical risk management for manufacturers, where the product has clinical functionality.
  • Data Security and Protection Toolkit evidence, aligned to the organisation submitting it.
  • UK GDPR and the Data Protection Act 2018, including DPIA preparation where processing warrants one.
  • WCAG 2.2 AA accessibility for user-facing interfaces, including clinical and administrative screens.
  • Secure development practice informed by the OWASP Top Ten and OWASP ASVS.
  • NHS interoperability expectations where the product exchanges data with national or local systems.
  • UK medical device regulation, where intended purpose may bring the product into scope. We will say when specialist regulatory advice is needed.

Questions

Frequently asked questions

Can Astaria certify our product for NHS use?

No. Astaria is not NHS approved, NHS certified or a DTAC certification body, and no supplier can guarantee acceptance by an NHS organisation. We help you build the controls and produce accurate evidence; the assessing organisation makes the decision.

Is DTAC a security standard?

DTAC is an assessment framework used by NHS and social care organisations when buying digital technology. It draws on clinical safety, data protection, technical security, interoperability and usability, and it is completed by the supplier and reviewed by the buyer.

Do we need DCB0129?

It applies to manufacturers of health IT systems where the product could affect patient care. Whether it applies depends on intended purpose and clinical functionality, which is one of the first things we establish.

Do you provide a clinical safety officer?

The clinical safety officer role must be held by a suitably qualified clinician. We support the process, documentation and hazard analysis, and will tell you where a clinician must sign.

Do you carry out the penetration testing yourselves?

We carry out security testing and can also coordinate an independent tester where assurance requires separation between the builder and the tester. We will recommend which is appropriate for your situation.

We already have a product in use. Can you help retrospectively?

Yes. Most of this work starts with an existing product, a live opportunity and a gap between current evidence and what the buyer is asking for.

How long does readiness take?

It depends on the product's complexity and how much documentation already exists. An applicability assessment and gap review typically takes two to three weeks; remediation and evidence work follows from what that finds.

Related

Related services

Contact

Tell us about your application

Describe the product, its users and the opportunity you are preparing for, and we will reply with the requirements likely to apply and a suggested first step.

A sentence or two is plenty. Include a website address if you have one.

We use your details only to reply to this enquiry. See our privacy notice.