The NHS Data Security and Protection Toolkit (DSPT) is often seen as relevant only to NHS organisations. However, care homes that handle NHS data—and most do—must also meet these standards.
With the Data Security and Protection Toolkit becoming increasingly important for commissioning and partnerships with NHS services, understanding compliance is essential for care home managers.
Why DSPT Matters for Care Homes
DSPT compliance is increasingly a commissioning requirement. Local authorities and ICBs (Integrated Care Boards) are asking care providers to demonstrate DSPT "Standards Met" status. Additionally, achieving DSPT demonstrates robust information governance that supports CQC compliance.
Understanding the DSPT Framework
The DSPT is an online self-assessment tool that allows organisations to measure their performance against data security and information governance requirements.
The Three Assertion Levels
Standards Not Met (Red)
Significant gaps in data security. May impact ability to share NHS data or win contracts.
Standards Not Fully Met (Amber)
Working towards compliance but not yet meeting all mandatory requirements. Improvement plan required.
Standards Met (Green)
All mandatory requirements met with evidence. This is the target status for care homes handling NHS data.
The Ten Standards
DSPT is organised into ten standards covering different aspects of data security and protection:
- Personal Confidential Data: Understanding what data you hold and how it flows
- Staff Responsibilities: Ensuring all staff understand their data protection responsibilities
- Training: Mandatory annual data security training for all staff
- Managing Data Access: Controlling who can access what data
- Process Reviews: Regular audits of data security processes
- Responding to Incidents: Having clear processes for data breaches
- Continuity Planning: Ensuring data access during disruptions
- Unsupported Systems: Managing or replacing outdated IT systems
- IT Protection: Technical security measures like firewalls and encryption
- Accountable Suppliers: Ensuring third-party systems are secure
Key Requirements for Care Homes
Let's examine the most relevant DSPT requirements for care homes and what evidence you need.
Staff Training and Awareness
Requirement: At least 95% of staff must complete annual data security awareness training.
Evidence needed:
- Training completion records showing dates and staff names
- Training content covering data protection, confidentiality, and cyber security basics
- Evidence that training is part of induction for new staff
Practical tip:
Use the free e-Learning for Healthcare Data Security Awareness Level 1 training. It's NHS-approved, free, and automatically tracks completion certificates.
Access Control and Passwords
Requirement: Strong password policies and role-based access controls.
Evidence needed:
- Password policy requiring minimum 8 characters (12+ recommended) with complexity rules
- Multi-factor authentication (MFA) enabled for systems containing NHS data
- User access reviews conducted at least annually showing who has access to what
- Process for immediately removing access when staff leave
- No shared logins—each staff member has unique credentials
Incident Response
Requirement: Clear process for reporting and responding to data security incidents.
Evidence needed:
- Incident response policy covering identification, containment, investigation, and reporting
- Process for reporting to ICO within 72 hours for serious breaches
- Incident log showing all data security incidents (even if no breach occurred)
- Evidence of learning from incidents (e.g., additional training, process changes)
Common Data Security Incidents in Care Homes
- Documents left in public areas or visible to visitors
- Care records emailed to wrong recipient (wrong family member)
- Lost or stolen mobile devices with resident data
- Discussing residents by name in public areas where others can hear
- Paper records disposed of in general waste instead of confidential shredding
IT Systems Security
Requirement: Technical security measures to protect systems and data.
Evidence needed:
- Antivirus software installed and updated on all devices
- Firewalls active on network and computers
- Operating systems kept up to date with security patches
- No unsupported systems (e.g., Windows 7, Windows Server 2008) handling NHS data
- Data encryption for portable devices (laptops, tablets, USB drives)
- Regular backups tested for restoration
Third-Party Systems (Care Software)
Requirement: Ensure suppliers of IT systems meet appropriate security standards.
Evidence needed:
- Contracts with care software providers including data processing clauses
- Evidence that software providers have their own DSPT "Standards Met" status or equivalent (ISO 27001)
- Data processing agreements (DPAs) in place with all suppliers who access resident data
- Understanding where data is stored (UK/EU data centres preferred)
Questions to ask your care software provider:
- What is your DSPT status or equivalent certification?
- Where is our data physically stored?
- What encryption do you use for data at rest and in transit?
- How often do you conduct penetration testing?
- What is your incident response procedure?
- Can you provide a copy of your data processing agreement?
Achieving DSPT Compliance: Practical Steps
Here's a step-by-step approach to achieving "Standards Met" status:
Step 1: Register and Assess Current State
- Register your organisation on the DSPT portal
- Assign a Senior Information Risk Owner (SIRO)—typically the registered manager or owner
- Appoint a Data Protection Officer if processing significant amounts of special category data
- Complete the initial self-assessment to identify gaps
Step 2: Address Mandatory Requirements
Focus on mandatory assertions first. These typically include:
- Ensuring 95%+ staff complete annual data security training
- Implementing password policies and MFA
- Documenting incident response procedures
- Ensuring no unsupported operating systems
- Obtaining DSPT evidence from care software suppliers
Step 3: Gather Evidence
For each assertion, you'll need to upload or reference evidence. Common evidence includes:
- Policies: Data Protection Policy, Information Security Policy, Incident Response Policy
- Training records: Screenshots from training platforms showing completion rates
- Technical evidence: Screenshots of antivirus status, backup logs, system update status
- Contracts: Data Processing Agreements with suppliers
- Audit reports: Access reviews, security assessments
Step 4: Submit and Publish
- Complete all mandatory assertions with evidence
- Have your SIRO review and approve the submission
- Submit your assessment (deadline is typically 30 June each year)
- Publish your status—this becomes publicly visible
Step 5: Maintain Compliance
DSPT is annual, but security is year-round. Maintain compliance by:
- Running quarterly training completion reports to stay above 95%
- Conducting monthly IT security checks (antivirus, backups, updates)
- Reviewing and updating policies annually
- Logging and investigating all data security incidents
- Conducting annual access reviews
Common Challenges and Solutions
Challenge: Achieving 95% Training Compliance
Staff turnover and part-time workers make maintaining 95% completion difficult.
Solution:
- Make training part of mandatory induction for all new staff
- Run monthly compliance reports to catch non-completers early
- Use paid work time for training completion, not expecting staff to do it at home
- Consider face-to-face training sessions for staff who struggle with online learning
Challenge: No In-House IT Expertise
Small care homes often lack dedicated IT staff to manage technical requirements.
Solution:
- Engage an external IT support provider who understands DSPT requirements
- Choose cloud-based care software where security is managed by the vendor
- Use managed services for backups, antivirus, and patch management
- Join networks like Digital Social Care for peer support
Challenge: Legacy Paper Systems
Paper records make it difficult to demonstrate technical security controls.
Solution:
- Physical security counts: locked cabinets, restricted access to records room
- Document disposal procedures (confidential shredding)
- Consider hybrid approach: digital for active records, paper archived securely
- Plan digital transition—DSPT compliance is easier with digital systems
Benefits Beyond Compliance
While DSPT might seem like a bureaucratic burden, achieving compliance brings real benefits:
- Reduced data breach risk: Robust security measures protect resident privacy and avoid ICO fines
- Competitive advantage: DSPT compliance increasingly required for LA and NHS contracts
- Better NHS integration: Easier to connect to NHS systems like GP Connect and shared care records
- Staff awareness: Training creates security-conscious culture
- CQC evidence: Strong information governance supports Safe and Well-led domains
Key Takeaway
DSPT compliance is achievable for care homes of all sizes. The key is systematic preparation: assign clear responsibility, address gaps methodically, and maintain compliance through year-round processes rather than annual scrambles. Modern cloud-based care software that is DSPT-compliant significantly simplifies the technical requirements.
DSPT-Compliant Care Management
Revitaco is designed to align with DSPT standards, making your compliance easier. Security best practices built in, so you can focus on care.
Book a Demo