Skip to content

Clinical safety and security

Clinical safety

DCB0129 applies to organisations manufacturing or modifying health IT within its scope. DCB0160 applies to health organisations deploying, using, maintaining or decommissioning health IT. Both are active mandatory standards under section 250; both were under consultation for revision at the research date, with no replacement assumed. SRC-019 SRC-020

For a sharing flow, the safety case should span:

  • source capture and coding;
  • patient matching and selection;
  • transformation, filtering and transport;
  • receiving display, alerting and workflow;
  • latency, outage, partial record and stale-data behaviour;
  • correction, reconciliation, duplication and onward use;
  • access rules that hide necessary information or reveal harmful excess;
  • human factors and training.

Security and information governance assurance

The Data Security and Protection Toolkit is a mandatory assurance mechanism for in-scope organisations accessing NHS patient information or systems. Completion is not proof that a particular flow is lawful or secure. SRC-012 SRC-040

Flow-specific controls include strong identity, least privilege, current care-relationship or equivalent policy signals, encryption, environment separation, immutable-enough audit, active monitoring, vulnerability and supplier management, tested incident response, retention/deletion and service-exit controls.

Use DCB3058 for national data opt-out compliance where the purpose is beyond individual care. SRC-021