Do clinic AI tools need DTAC and DSPT?
Short answer
Not by law for a purely private clinic. DTAC is the framework NHS buyers use to assess digital health products, and the DSPT is the annual data security self-assessment for organisations with access to NHS patient data or systems. Both still matter: DTAC evidence answers most vendor due-diligence questions, and the DSPT applies once you handle NHS data.
DTAC: a buyer's framework, not a certificate
The Digital Technology Assessment Criteria (DTAC) is NHS England's baseline assessment for digital health technologies. It covers clinical safety, data protection, technical security, interoperability, and usability and accessibility. NHS organisations use it to assure products they buy. It is not a certificate that a vendor 'holds': the buying organisation assesses the product against evidence the vendor supplies, such as its DCB0129 clinical safety case, data protection documentation and security testing.
For a private clinic, DTAC is not a legal requirement. It is still useful. A vendor with a completed DTAC evidence pack has already answered, in writing, most of the questions you would otherwise ask one by one. NHS England's ambient scribing supplier registry also expects suppliers to have completed DTAC.
DSPT: required once you touch NHS data
The Data Security and Protection Toolkit (DSPT) is an annual online self-assessment against the National Data Guardian's data security standards. Organisations with access to NHS patient data and systems must complete it every year. Common triggers for a private clinic are NHS contracts, shared NHS records and NHSmail. A fully private clinic with no NHS data flows is not required to complete it.
DSPT results are published. You can look up any organisation on the DSPT website and check the year and whether standards were met. Because it is annual, a vendor's DSPT claim only means something with a current year attached.
What to ask a vendor
- Can you share your DTAC evidence pack, including your DCB0129 clinical safety case?
- What is your current-year DSPT status, and under which organisation name is it published?
- Do you hold Cyber Essentials? NHS England's ambient scribing guidance asks adopters to check DSPT and Cyber Essentials alongside UK GDPR.
- Which ISO 27001 scope applies, and is it certified or aligned?
- Which of these commitments are written into the data processing agreement?
Frameworks are necessary but not sufficient. A certificate does not bind a vendor's behaviour; a contract does. Pair DTAC and DSPT evidence with written answers on data residency, model training and retention.
What Motics does
- Motics has been assessed against DTAC, covering clinical safety (DCB 0129), data protection, technical security and interoperability. Assessment evidence and clinical safety documentation are on our Trust Centre.
- Our Information Security Management System is aligned to ISO 27001:2022, with over 100 security controls monitored continuously and reported on the Trust Centre.
- Independent penetration testing is carried out annually, and dependencies are scanned continuously for known vulnerabilities.
- If your deployment involves NHS data, ask our team for our current DSPT position as part of your due diligence.
Full detail on our security and compliance page and the Trust Centre. Ask any vendor, including us, to put these answers in writing.
Primary sources
- NHS England: Digital Technology Assessment Criteria (DTAC)
- NHS: Data Security and Protection Toolkit
- NHS England: Guidance on the use of AI-enabled ambient scribing products
- CQC: GP mythbuster 109, Use of artificial intelligence (AI) in GP services
Practical orientation for UK clinics, not legal advice. For your own circumstances, take advice from your data protection officer, indemnity provider or a solicitor.