UK compliance hubClinical safety and NHS assurance

Do clinic AI tools need DTAC and DSPT?

Short answer

Not by law for a purely private clinic. DTAC is the framework NHS buyers use to assess digital health products, and the DSPT is the annual data security self-assessment for organisations with access to NHS patient data or systems. Both still matter: DTAC evidence answers most vendor due-diligence questions, and the DSPT applies once you handle NHS data.

DTAC: a buyer's framework, not a certificate

The Digital Technology Assessment Criteria (DTAC) is NHS England's baseline assessment for digital health technologies. It covers clinical safety, data protection, technical security, interoperability, and usability and accessibility. NHS organisations use it to assure products they buy. It is not a certificate that a vendor 'holds': the buying organisation assesses the product against evidence the vendor supplies, such as its DCB0129 clinical safety case, data protection documentation and security testing.

For a private clinic, DTAC is not a legal requirement. It is still useful. A vendor with a completed DTAC evidence pack has already answered, in writing, most of the questions you would otherwise ask one by one. NHS England's ambient scribing supplier registry also expects suppliers to have completed DTAC.

DSPT: required once you touch NHS data

The Data Security and Protection Toolkit (DSPT) is an annual online self-assessment against the National Data Guardian's data security standards. Organisations with access to NHS patient data and systems must complete it every year. Common triggers for a private clinic are NHS contracts, shared NHS records and NHSmail. A fully private clinic with no NHS data flows is not required to complete it.

DSPT results are published. You can look up any organisation on the DSPT website and check the year and whether standards were met. Because it is annual, a vendor's DSPT claim only means something with a current year attached.

What to ask a vendor

  • Can you share your DTAC evidence pack, including your DCB0129 clinical safety case?
  • What is your current-year DSPT status, and under which organisation name is it published?
  • Do you hold Cyber Essentials? NHS England's ambient scribing guidance asks adopters to check DSPT and Cyber Essentials alongside UK GDPR.
  • Which ISO 27001 scope applies, and is it certified or aligned?
  • Which of these commitments are written into the data processing agreement?

Frameworks are necessary but not sufficient. A certificate does not bind a vendor's behaviour; a contract does. Pair DTAC and DSPT evidence with written answers on data residency, model training and retention.

What Motics does

  • Motics has been assessed against DTAC, covering clinical safety (DCB 0129), data protection, technical security and interoperability. Assessment evidence and clinical safety documentation are on our Trust Centre.
  • Our Information Security Management System is aligned to ISO 27001:2022, with over 100 security controls monitored continuously and reported on the Trust Centre.
  • Independent penetration testing is carried out annually, and dependencies are scanned continuously for known vulnerabilities.
  • If your deployment involves NHS data, ask our team for our current DSPT position as part of your due diligence.

Full detail on our security and compliance page and the Trust Centre. Ask any vendor, including us, to put these answers in writing.

Primary sources

  1. NHS England: Digital Technology Assessment Criteria (DTAC)
  2. NHS: Data Security and Protection Toolkit
  3. NHS England: Guidance on the use of AI-enabled ambient scribing products
  4. CQC: GP mythbuster 109, Use of artificial intelligence (AI) in GP services

Practical orientation for UK clinics, not legal advice. For your own circumstances, take advice from your data protection officer, indemnity provider or a solicitor.

FAQ

Common questions

No. DTAC is an NHS procurement framework, not a legal requirement for private practice. Its five areas map closely onto the risks a private clinic carries anyway, which is why many practice owners use it as a free vendor checklist.

Not exactly. DTAC is assessed by the buying organisation against evidence the vendor supplies, rather than awarded centrally. A credible vendor keeps a completed DTAC evidence pack and shares it on request. Treat reluctance to share one as a warning sign.

Only if you have access to NHS patient data or systems. NHS contracts, shared NHS records and NHSmail are the usual triggers. A fully private clinic with no NHS data flows is not required to, though some complete it voluntarily.

Search the organisation on the public DSPT website. It shows the assessment year and whether standards were met. Check the entry is current, because the toolkit is renewed every year and an old entry means the cycle has lapsed.

Usually that it has completed the DTAC questions and can supply the evidence. Ask for the evidence pack itself, including the DCB0129 clinical safety case, rather than relying on the phrase.

No. DTAC tells you the vendor has thought about clinical safety, data protection and security. You still need contractual answers: a data processing agreement, a no-training commitment, where data is stored and processed, and a retention and deletion schedule.

Running a compliance review?

We work with clinic owners, compliance leads and DPOs. Bring your DPIA or vendor questionnaire and we will come prepared.