Care providers, clinics, practices and charities working with the NHS handle the most sensitive data there is, under real operational pressure. We run IT that protects it — and that never gets in the way of delivering care.
Health and care organisations live with a combination nobody else has: special-category data under UK GDPR, staff whose priority is rightly the person in front of them rather than the password prompt, shared computers in clinical and care settings, a workforce that’s often mobile and part-time with high turnover — and, for anyone connected to the NHS, a compliance landscape of its own. The Data Security and Protection Toolkit (DSPT) must be evidenced annually; NHS-connected email may need to meet the DCB1596 secure-email standard; commissioners and the CQC expect governance to be real, not aspirational.
Generic IT providers tend to fail here in one of two directions: security so heavy-handed that care staff work around it (which is worse than no security), or compliance treated as a form-filling exercise with nothing behind it. The job is to hold both lines — genuinely protective, genuinely workable at 3am in a care setting.
Where health and care organisations lean on us hardest.
Microsoft 365 configured to the NHS secure-email standard, preparing you for DCB1596 accreditation — the practical route to safely exchanging patient information with NHS partners.
Help meeting and evidencing the Data Security and Protection Toolkit — with controls that actually exist, so the annual submission describes reality rather than intention.
Fast, patient help for staff whose job isn’t computers — across sites, shifts and community working — without the condescension frontline teams too often get from IT.
Rostering, care records and clinical systems backed up and recoverable — because in this sector, downtime isn’t lost revenue, it’s disrupted care.
Three principles that shape every care environment we look after.
Least-privilege access to records, shared clinical devices with fast, individual sign-in (so audit trails survive shift handover), and mobile devices that protect data even when they’re left in a car. Security built around how care actually happens.
DSPT requirements, DCB1596 readiness and CQC expectations turned into a concrete technical to-do list, implemented, and evidenced. To be clear: the accreditation is your organisation’s — our job is making sure you genuinely meet it.
Bank staff, agency workers, volunteers and high turnover are the norm in care. Our joiner/leaver processes are built for that reality — access granted in minutes, revoked the moment it should be, reviewed on a schedule.
Yes. The DSPT is the NHS’s annual self-assessment for any organisation handling NHS patient data, and it’s where many providers discover their IT reality doesn’t match their policies. We work through the requirements with you, put the missing technical controls in place — access management, MFA, patching, backups, audit — and make sure what you submit is evidenced and true. That matters, because a DSPT submission that overstates your position becomes a liability the day something goes wrong.
DCB1596 is the NHS secure-email standard. If your organisation needs to exchange patient information with NHS bodies by email, meeting it is how you do so safely and acceptably — for Microsoft 365 users it means configuring the tenant to the NHS’s published secure-email specification, and the accreditation is then held (and renewed annually) by your organisation. We configure Microsoft 365 to the standard and prepare you for accreditation. One honesty note: no provider can sell you a “DCB1596 certificate” — anyone offering one is overclaiming.
The wrong answer — and the common one — is a shared login everyone knows, which destroys the audit trail and usually breaches your own policies. The right answer is individual accounts with sign-in fast enough for clinical reality: badge or PIN-based access, sessions that follow the user between devices, and automatic locking that doesn’t strand a nurse mid-record. Done properly, it’s both quicker for staff and defensible when a record access ever has to be explained.
Assume devices will be lost — then make it not matter. Encrypted laptops, tablets and phones under management; data held in the systems rather than on the device; access that can be cut remotely the moment something goes missing; and sensible sign-in so a device left on a train is an inconvenience and a report, not a notifiable breach. Community working also changes support: help has to work over the phone, from a car park, for someone with five minutes between visits. We staff for that.
A straight conversation about your systems, your DSPT position and how your teams actually work — and how we’d make the secure way the easy way.