Part of Business Applications Guidance
Business applications: generic guidance
There are many business applications used by health and social care consumers. These include:
- clinical applications such as electronic patient records, GPIT systems or diagnostics systems
- voice communications
- email services such as NHSmail;
- national applications such as Summary Care Record (SCR) and eReferral service
- patient access applications
These applications are increasingly moving to internet hosted applications.
NHS Digital is committed to supporting end consumers using these applications and other standard tools and products to collaborate and share information with their partners.
It is important that, regardless of the network used as transit, application services are configured to meet the security, performance and availability requirements of the health and social care business users.
The following guidelines apply to all application services. NHS Digital does not assure supplier services of commodity/off-the-shelf type applications.
All application/service procurements should follow the government Technology Code of Practice.
Information security
The NHS Digital Data Security Centre provides advice and guidance to health and social care organisations. They offer best practice advice along with a knowledge base of security information for the day to day security operational functions to assist health and social care organisations in key infrastructure management decisions.
This links below provide further information on these services.
NHS cyber security and CareCERT
Note that the guidelines provided are general good practice, and should be applied regardless of the network used, whether HSCN, the internet, cloud service connectivity, regional wide area networks (WANs) or direct connectivity to a supplier's data centre.
The sections covered within the appendices of this document refer to various security principles and guidelines. These principles and guidelines should be taken into consideration when an NHS organisation begins the process to procure HSCN business applications.
In addition, it is important to protect your local service whenever using cloud services. The National Cyber Security Centre best practice provides support in this context:
When procuring application services, listed below are areas that should be considered as support for requirements on the service provided by a commercial third party supplier, regardless of the network connectivity method.
Cloud security principles
The National Cyber Security Centre publishes guidance on implementing security in cloud applications. These principles are useful for all application deployments even if hosted locally.
These principles should be used to assess all remotely hosted/cloud hosted applications.
Government frameworks include assessments of services against these principles.
NCSC also provide guidance on:
- data in transit protection methods such as encryption - Using TLS to protect data
- Cloud computing and data security - Cloud storage and data security
ISO27001
A good example of a standard used for security governance and operational controls.
Data Security and Protection Toolkit Assessment
Any commercial third party provider of applications needs to produce an Data Security and Protection Toolkit This is no longer tied to connection agreements for a specific network, as this applies regardless of the networks used for data transit.
The Data Security and Protection Toolkit is an online self-assessment tool that enables organisations to measure and publish their performance against the National Data Guardian's ten data security standards.
All organisations that have access to NHS patient data and systems must use this toolkit to provide assurance that they are practising good data security and that personal information is handled correctly.
Clinical Safety
The Health and Social Care Act 2012 mandates adherence to Clinical Risk Management standards where IT is developed and used to support health and care services.
DCB0129: Clinical Risk Management: its Application in the Manufacture of Health IT Systems, shall be complied with by manufacturers who are developing IT systems that utilise HSCN to support health or care services.
DCB 0160: Clinical risk Management: its Application in the Deployment and Use of Health IT Systems shall be complied with by organisations who are deploying and using IT systems that utilise HSCN to support health or care services.
Read more about resources supporting clinical risk management of IT systems.
Service
Consideration needs to be given to the service requirements - how the application is delivered and managed. Suppliers will often provide catalogues to detail these elements of their service. Consideration should be given to the following:
Last edited: 1 May 2025 12:25 pm