Skip to content
HIPAA-Compliant AgencyBAA Signed Before PHINHS Digital StandardsWCAG 2.2 AA
HIPAA-Compliant AgencyBAA Signed Before PHINHS Digital StandardsWCAG 2.2 AA

DSPT Healthcare Website Requirements: What You Need to Know

DSPT compliance for healthcare web portals is mandatory for all NHS patient data handlers. This guide explains the 10 standards and how to map them to your website infrastructure.

DSPT Healthcare Website Requirements: What You Need to Know
Qrolic Health Technical Team
9 min read
DSPT
NHS Compliance
Data Security
UK GDPR
Healthcare Web Portal

Your healthcare web portal must meet DSPT requirements to handle NHS patient data safely and legally. DSPT compliance healthcare web portal is mandatory for all organisations with access to NHS patient data. This guide explains what DSPT means for your website, how to map the 10 standards to your infrastructure, and how to gather the required evidence for annual submission. Based on our healthcare IT experience with NHS organisations, we can help you efficiently navigate the entire DSPT process. With 25.7 Million distinct users logging into the NHS App in 2025, the scale of DSPT compliant platforms is substantial.

All organisations with access to NHS patient data must maintain DSPT compliance annually.

Why DSPT Compliance Matters for Your Healthcare Web Portal

All organisations with access to NHS patient data must maintain DSPT compliance annually. This establishes DSPT as a non-negotiable requirement for any healthcare web portal handling NHS data.

25.7 Million distinct users logged into the NHS App in 2025, operating under DSPT aligned frameworks. This demonstrates the massive scale of NHS digital platforms requiring DSPT compliance.

The NHS Digital Service Standard provides the foundation for digital service delivery. DSPT 2025–26 version 8 is the current requirement for NHS Trusts, ICBs, CSUs, ALBs, and other NHS organisations.

Mandatory annual requirement for NHS data handlers

All organisations with access to NHS patient data must maintain DSPT compliance annually. This is not optional for any healthcare provider or technology vendor working with NHS data.

Scale of NHS digital adoption

25.7 Million distinct users logged into the NHS App in 2025, operating under DSPT aligned frameworks. The NHS App recorded 62.3 Million logins in November 2025, a 43% surge over the prior 12 month average.

National Data Guardian's 10 standards

The National Data Guardian has established 10 standards that all NHS data handlers must meet. These cover governance, data protection, risk management, and other critical areas.

Need DSPT Compliance Support for Your Healthcare Web Portal?

Worried your healthcare web portal has DSPT compliance gaps? Our compliance team can help identify and fix vulnerabilities before your annual submission.

Contact Us for DSPT Compliance

How Your Website Creates DSPT Compliance Exposure

Your website can create significant DSPT compliance exposure through various vulnerabilities. Understanding these risks is the first step to addressing them.

Third-party scripts and tracking pixels

Third-party scripts and tracking pixels can transmit patient data to external vendors without proper safeguards. This creates DSPT compliance risks that must be managed.

In practice, this means auditing all third-party integrations and ensuring proper Data Processing Agreements are in place. However, many organisations are unaware of all the third-party scripts running on their websites.

Unencrypted form submissions

Unencrypted form submissions can expose patient data during transmission. This violates DSPT requirements for data security and protection.

As a result, all form submissions must use encryption to protect patient data in transit. One common issue is assuming that standard form implementations are secure by default.

Analytics tools without Data Processing Agreements

Analytics tools without Data Processing Agreements can improperly process patient data. This creates compliance gaps that must be addressed.

Consider this scenario: a healthcare website implements a standard analytics tool without a DPA. When patient data is processed by the analytics vendor, this creates a DSPT violation.

Staff accessing patient data through unsecured interfaces

Staff accessing patient data through unsecured interfaces can expose data to unauthorized access. This violates DSPT requirements for access controls and data protection.

Outdated or missing security certificates

Outdated or missing security certificates can compromise data security. This creates DSPT compliance risks that must be addressed through proper certificate management.

Mapping the 10 DSPT Standards to Web Infrastructure

Over 5.1 Million prescription orders were triggered digitally via the NHS App in October 2025 alone. This proves the critical role of DSPT compliant web portals in clinical workflows and patient data handling.

The 10 DSPT standards must be mapped to your web infrastructure to ensure comprehensive compliance. Each standard has specific requirements for web portals.

The DTAC compliance for healthcare platforms provides additional guidance. The NHS Digital Service Standard for healthcare websites also offers relevant information.

Standard 1: Governance and Responsibility

Web portal ownership and accountability must be clearly defined. DSPT submission responsibility should be assigned to a specific individual or team. In practice, this means documenting who is responsible for compliance and submission.

Standard 2: Data Protection Impact Assessments

DPIAs for web projects handling patient data are mandatory. Risk assessment documentation must be comprehensive and up to date. All web projects that handle patient data must have a Data Protection Impact Assessment.

Standard 3: Risk Management

Web specific risk registers must be maintained. Mitigation strategies for digital platforms must be documented and implemented. Risk registers specific to web platforms must identify and track all potential risks.

Standard 4: Data Security

Encryption, access controls, and authentication are essential. Secure hosting and infrastructure must be in place to protect patient data. Over 5.1 Million prescription orders were triggered digitally via the NHS App in October 2025 alone.

Standard 5: Staff Training

Web portal access training must be provided to all staff. Data handling procedures for digital systems must be clearly documented and followed. All staff with access to the web portal must receive appropriate training.

Standard 6: Incident Management

Web specific incident response procedures must be in place. Breach notification workflows must be documented and tested. Incident response procedures specific to web platforms must be developed.

Standard 7: Business Continuity

Web portal availability and recovery must be ensured. Disaster recovery planning must be in place to maintain service continuity. Web portal availability must be maintained to ensure continuous service.

Standard 8: Data Sharing and Processing

Third-party integrations must have proper DPAs. Data processing agreements for web services must be in place and maintained. The UK GDPR and data protection requirements also apply.

Standard 9: Subject Access Requests

Web portal data access mechanisms must be in place. Patient data retrieval processes must be documented and efficient. Mechanisms for patients to access their data must be provided.

Standard 10: Data Retention and Disposal

Web data lifecycle management must be implemented. Secure deletion of patient data must be ensured when it is no longer needed. Data lifecycle management must be implemented for all web data.

Getting Your Web Vendor to Support DSPT Evidence Submission

Your web vendor plays a critical role in DSPT compliance. They must provide the necessary documentation and evidence to support your submission.

Required vendor documentation

Required documentation includes security testing results, data flow diagrams, and access control matrices. These demonstrate that your web portal meets DSPT requirements.

In practice, this means working with your vendor to gather all necessary evidence. Across recent compliance projects, we have observed that vendors who understand DSPT requirements provide better support.

Evidence of security testing

Evidence of security testing must be provided. This includes penetration testing results, vulnerability scans, and security audits.

Data flow diagrams for web integrations

Data flow diagrams must document all data flows through your web portal. This demonstrates understanding of how patient data is processed and protected.

Access control matrices

Access control matrices must document who has access to what data. This ensures proper access controls are in place and can be audited.

Incident response procedures

Incident response procedures must be documented and tested. This ensures your web portal can respond effectively to security incidents.

Did You Know ?

DSPT compliance for healthcare web portals requires addressing third-party scripts, unencrypted forms, and analytics tools. All NHS patient data handlers must complete DSPT annually to maintain access to NHS systems and data.

Common DSPT Gaps in Healthcare Websites and How to Fix Them

Many healthcare websites have common DSPT gaps that can be addressed with focused remediation. Understanding these can help you prioritise your compliance efforts.

Missing encryption on contact forms

Missing encryption on contact forms is a frequent DSPT gap. All forms that collect patient data must use encryption to protect data in transit.

In practice, this means implementing SSL/TLS for all form submissions. However, many websites still have unencrypted forms that create compliance risks.

Unvetted third-party scripts

Unvetted third-party scripts can create significant DSPT risks. All third-party integrations must be reviewed and approved before implementation.

As a result, organisations should implement a vetting process for all third-party scripts. One common issue is implementing scripts without understanding their data access requirements.

Inadequate access controls

Inadequate access controls can expose patient data to unauthorized access. Granular access controls based on the principle of least privilege must be implemented.

Consider this scenario: a staff member with excessive access rights could inadvertently or intentionally access patient data they should not see. This creates a DSPT compliance violation.

Lack of audit logging

Lack of audit logging prevents organisations from demonstrating compliance. All access to patient data must be logged and monitored.

Poor session management

Poor session management can expose patient data to unauthorized access. Session timeout and authentication requirements must be properly configured.

Your DSPT Compliance Checklist for Web Portals

This checklist provides the essential steps for achieving DSPT compliance for your web portal. Use it to track your progress and ensure all requirements are met.

Annual submission timeline

Develop a timeline for your annual DSPT submission. This ensures you have adequate time to gather evidence and address any gaps.

In practice, this means starting the process early and setting milestones. Based on our healthcare IT experience, organisations that start early have smoother submissions.

Evidence gathering workflow

Develop a workflow for gathering DSPT evidence. This ensures all required documentation is collected and organised.

Vendor coordination checklist

Develop a checklist for coordinating with vendors. This ensures all third-party providers support your DSPT compliance efforts.

Continuous monitoring requirements

Implement continuous monitoring to maintain DSPT compliance. This ensures your web portal remains compliant between annual submissions.

Our NHS-compliant website design and development services can help you implement these requirements.

Conclusion

DSPT compliance for healthcare web portals is mandatory for all NHS patient data handlers. All organisations with access to NHS patient data must maintain DSPT compliance annually to maintain access to NHS systems and data.

With 25.7 Million distinct users logging into the NHS App in 2025 and 62.3 Million logins in November 2025, the scale of DSPT compliant platforms is substantial. The 43% surge in logins demonstrates growing demand for compliant digital health services.

However, achieving DSPT compliance is not just about meeting requirements. It is about protecting patient data and building trust with NHS organisations and patients. Based on our healthcare IT experience, web portals that achieve DSPT compliance gain significant market advantages.

Need expert help achieving DSPT compliance for your healthcare web portal? Our NHS compliance team can build a roadmap for full certification.

Need Expert DSPT Compliance Help?

Need expert help achieving DSPT compliance for your healthcare web portal? Our NHS compliance team can build a roadmap for full certification.

Get a Quote for DSPT Compliance

Frequently Asked Questions

Qrolic Health Technical Team

Qrolic Health Technical Team

Updated for 2026 Compliance Guidance
Qrolic Health - Healthcare Website Design Specialists

Based on our healthcare IT experience with NHS organisations, we can help you efficiently navigate the entire DSPT process.

Ready to Start Your Healthcare Project?

Let's discuss your goals and show you how we can build a secure, accessible, and high-performing healthcare website.

Healthcare projects portfolio brief - HIPAA & NHS Compliant Web Development