The Data Security and Protection Toolkit (DSPT) has undergone significant changes for the 2024/25 version (V7), which will impact how digital health tech companies in the UK approach their compliance. Here are the key differences and what you need to know to successfully navigate and complete V7 of the DSPT.

Adoption of the Cyber Assessment Framework (CAF)

From September 2024, DSPT V7 has adopted a more flexible, outcomes-based approach aligned with the principles of the Cyber Assessment Framework (CAF) developed by the National Cyber Security Centre (NCSC). This shift aims to encourage not just compliance but ongoing maintenance of security measures.

New Interface for Larger Organisations

NHS Trusts, CSUs, ALBs, and ICBs will encounter a new interface in the DSPT portal, guiding them through security goals aligned with the CAF principles. While this change primarily affects larger NHS entities, it’s important for smaller health tech companies to be aware of this evolution in the NHS digital ecosystem.

Flexible Approach for Smaller Organizations

For now, smaller organisations like digital health tech startups will continue to use the current questionnaire-based system. However, it’s worth noting that there are plans to eventually derive controls for smaller organisations from a CAF profile, though this won’t happen before 2025.

Key Changes for Small Health Tech Companies

  1. Multi-Factor Authentication: Evidence item 4.5.3 covering Multi-Factor Authentication has been added as a key change. Ensure your company implements robust MFA practices.
  2. Annual Self-Assessment: The deadline for completing and publishing your DSPT self-assessment is June 30, 2025. Plan ahead to meet this deadline.
  3. Data Protection Impact Assessment (DPIA): There’s now a requirement to complete a DPIA for all processing activities involving personal data.
  4. Staff Training: You need to provide evidence of staff training in data security and protection.
  5. Outcome-Based Assessment: While larger organisations will use a new CAF-aligned interface, smaller companies should still expect a shift towards more outcome-focused requirements rather than prescriptive controls.

Tips for Successfully Navigating V7 DSPT

  1. Start Early: Begin your self-assessment well before the June 30, 2025, deadline.
  2. Review New Guidance: Familiarise yourself with the new guidance developed to support organisations in completing the updated requirements.
  3. Focus on Outcomes: While still using the questionnaire-based system, start thinking in terms of security outcomes rather than just ticking boxes.
  4. Implement Robust MFA: Prioritise the implementation of strong multi-factor authentication across your systems.
  5. Conduct Regular DPIAs: Make Data Protection Impact Assessments a regular part of your data processing activities.
  6. Invest in Staff Training: Ensure your team is well-trained in data security and protection and maintain records of this training.
  7. Stay Informed: Keep an eye on future updates, as the DSPT is likely to continue evolving towards a more CAF-aligned approach for all organisations.

By understanding these changes and proactively adapting your compliance strategies, your digital health tech company can successfully navigate the new requirements of the 2024/25 V7 DSPT. Remember, the goal is not just compliance but fostering a culture of continuous improvement in data security and protection.

For information on our DSPT service 

References:

  1. https://www.england.nhs.uk/blog-authors/
  2. https://www.dsptoolkit.nhs.uk/News/DSPT-Changes-in-24-25
  3. https://digital.nhs.uk/about-nhs-digital/essential-information-and-alerts-for-stakeholders/essential-information-for-digital-leaders/2024/data-security-protection-toolkit-dspt-changes-for-2024-2025
  4. https://www.dsptoolkit.nhs.uk/News/release-notes
  5. https://www.dsptoolkit.nhs.uk/News/131
  6. https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections/dapb0086-data-security-and-protection-toolkit

Recommended Posts