NHS DTAC, the Digital Technology Assessment Criteria, is the framework NHS organisations use to assess digital health products before procurement. It does not certify a product once and for all; it consolidates evidence across five domains — clinical safety, data protection, technical security, interoperability and usability with accessibility — into a single assessment that a commissioning body reviews for its own purchasing decision.
DCB0129 and DCB0160 are the two halves of the NHS clinical risk management standard for health IT. DCB0129 applies to the manufacturer of the software and requires a clinical risk management plan, a hazard log identifying and tracking clinical safety hazards through development, and a clinical safety case report signed by a named clinical safety officer before release. DCB0160 applies to the organisation deploying the software into a specific clinical setting and requires its own risk assessment of how the software is configured and used there, built on top of the manufacturer's DCB0129 evidence.
DSPT, the Data Security and Protection Toolkit, is an annual online self-assessment against the National Data Guardian's data security standards. Organisations that access NHS patient data or the NHS network are generally expected to complete it, and NHS commissioners often ask suppliers to evidence their own submission as part of due diligence.
UK GDPR governs the processing of personal data, and health data is classified as special category data under Article 9, which carries a stricter lawful basis test than ordinary personal data. In practice this means a documented lawful basis, a data protection impact assessment for higher-risk processing, defined retention periods, and contractual terms that set out the processor's obligations.
MHRA medical device classification concerns whether software falls within the UK Medical Device Regulations 2002. The determining factor is function rather than technology: software that interprets clinical data to produce or support a diagnosis, or otherwise drives a clinical decision, may be classified as a medical device and require MHRA registration and an appropriate conformity assessment route. Software limited to storing, displaying or transmitting data is generally outside this scope, but the classification is assessed against the specific function of the product rather than assumed from its category.
HIPAA is US federal legislation governing protected health information held by covered entities — broadly, healthcare providers, insurers and clearinghouses — and by their business associates. It requires administrative, physical and technical safeguards, and a business associate agreement between the covered entity and any vendor processing data on its behalf.
SOC 2 is a voluntary examination, conducted by an independent auditor, of a service organisation's controls against defined trust services criteria, most commonly security, availability and confidentiality. It results in a Type I report, assessing controls at a point in time, or a Type II report, assessing whether those controls operated effectively over a review period, and is commonly requested by US enterprise and healthcare buyers during vendor due diligence.