DSPT Healthcare Website Requirements: What You Need to Know
DSPT compliance for healthcare web portals is mandatory for all NHS patient data handlers. This guide explains the 10 standards and how to map them to your website infrastructure.

Your healthcare web portal must meet DSPT requirements to handle NHS patient data safely and legally. DSPT compliance healthcare web portal is mandatory for all organisations with access to NHS patient data. This guide explains what DSPT means for your website, how to map the 10 standards to your infrastructure, and how to gather the required evidence for annual submission. Based on our healthcare IT experience with NHS organisations, we can help you efficiently navigate the entire DSPT process. With 25.7 Million distinct users logging into the NHS App in 2025, the scale of DSPT compliant platforms is substantial.
All organisations with access to NHS patient data must maintain DSPT compliance annually.
Why DSPT Compliance Matters for Your Healthcare Web Portal
All organisations with access to NHS patient data must maintain DSPT compliance annually. This establishes DSPT as a non-negotiable requirement for any healthcare web portal handling NHS data.
25.7 Million distinct users logged into the NHS App in 2025, operating under DSPT aligned frameworks. This demonstrates the massive scale of NHS digital platforms requiring DSPT compliance.
The NHS Digital Service Standard provides the foundation for digital service delivery. DSPT 2025–26 version 8 is the current requirement for NHS Trusts, ICBs, CSUs, ALBs, and other NHS organisations.
Mandatory annual requirement for NHS data handlers
All organisations with access to NHS patient data must maintain DSPT compliance annually. This is not optional for any healthcare provider or technology vendor working with NHS data.
Scale of NHS digital adoption
25.7 Million distinct users logged into the NHS App in 2025, operating under DSPT aligned frameworks. The NHS App recorded 62.3 Million logins in November 2025, a 43% surge over the prior 12 month average.
National Data Guardian's 10 standards
The National Data Guardian has established 10 standards that all NHS data handlers must meet. These cover governance, data protection, risk management, and other critical areas.
Need DSPT Compliance Support for Your Healthcare Web Portal?
Worried your healthcare web portal has DSPT compliance gaps? Our compliance team can help identify and fix vulnerabilities before your annual submission.
Contact Us for DSPT Compliance →How Your Website Creates DSPT Compliance Exposure
Your website can create significant DSPT compliance exposure through various vulnerabilities. Understanding these risks is the first step to addressing them.
Third-party scripts and tracking pixels
Third-party scripts and tracking pixels can transmit patient data to external vendors without proper safeguards. This creates DSPT compliance risks that must be managed.
In practice, this means auditing all third-party integrations and ensuring proper Data Processing Agreements are in place. However, many organisations are unaware of all the third-party scripts running on their websites.
Unencrypted form submissions
Unencrypted form submissions can expose patient data during transmission. This violates DSPT requirements for data security and protection.
As a result, all form submissions must use encryption to protect patient data in transit. One common issue is assuming that standard form implementations are secure by default.
Analytics tools without Data Processing Agreements
Analytics tools without Data Processing Agreements can improperly process patient data. This creates compliance gaps that must be addressed.
Consider this scenario: a healthcare website implements a standard analytics tool without a DPA. When patient data is processed by the analytics vendor, this creates a DSPT violation.
Staff accessing patient data through unsecured interfaces
Staff accessing patient data through unsecured interfaces can expose data to unauthorized access. This violates DSPT requirements for access controls and data protection.
Outdated or missing security certificates
Outdated or missing security certificates can compromise data security. This creates DSPT compliance risks that must be addressed through proper certificate management.
Mapping the 10 DSPT Standards to Web Infrastructure
Over 5.1 Million prescription orders were triggered digitally via the NHS App in October 2025 alone. This proves the critical role of DSPT compliant web portals in clinical workflows and patient data handling.
The 10 DSPT standards must be mapped to your web infrastructure to ensure comprehensive compliance. Each standard has specific requirements for web portals.
The DTAC compliance for healthcare platforms provides additional guidance. The NHS Digital Service Standard for healthcare websites also offers relevant information.
Standard 1: Governance and Responsibility
Web portal ownership and accountability must be clearly defined. DSPT submission responsibility should be assigned to a specific individual or team. In practice, this means documenting who is responsible for compliance and submission.
Standard 2: Data Protection Impact Assessments
DPIAs for web projects handling patient data are mandatory. Risk assessment documentation must be comprehensive and up to date. All web projects that handle patient data must have a Data Protection Impact Assessment.
Standard 3: Risk Management
Web specific risk registers must be maintained. Mitigation strategies for digital platforms must be documented and implemented. Risk registers specific to web platforms must identify and track all potential risks.
Standard 4: Data Security
Encryption, access controls, and authentication are essential. Secure hosting and infrastructure must be in place to protect patient data. Over 5.1 Million prescription orders were triggered digitally via the NHS App in October 2025 alone.
Standard 5: Staff Training
Web portal access training must be provided to all staff. Data handling procedures for digital systems must be clearly documented and followed. All staff with access to the web portal must receive appropriate training.
Standard 6: Incident Management
Web specific incident response procedures must be in place. Breach notification workflows must be documented and tested. Incident response procedures specific to web platforms must be developed.
Standard 7: Business Continuity
Web portal availability and recovery must be ensured. Disaster recovery planning must be in place to maintain service continuity. Web portal availability must be maintained to ensure continuous service.
Standard 8: Data Sharing and Processing
Third-party integrations must have proper DPAs. Data processing agreements for web services must be in place and maintained. The UK GDPR and data protection requirements also apply.
Standard 9: Subject Access Requests
Web portal data access mechanisms must be in place. Patient data retrieval processes must be documented and efficient. Mechanisms for patients to access their data must be provided.
Standard 10: Data Retention and Disposal
Web data lifecycle management must be implemented. Secure deletion of patient data must be ensured when it is no longer needed. Data lifecycle management must be implemented for all web data.
Getting Your Web Vendor to Support DSPT Evidence Submission
Your web vendor plays a critical role in DSPT compliance. They must provide the necessary documentation and evidence to support your submission.
Required vendor documentation
Required documentation includes security testing results, data flow diagrams, and access control matrices. These demonstrate that your web portal meets DSPT requirements.
In practice, this means working with your vendor to gather all necessary evidence. Across recent compliance projects, we have observed that vendors who understand DSPT requirements provide better support.
Evidence of security testing
Evidence of security testing must be provided. This includes penetration testing results, vulnerability scans, and security audits.
Data flow diagrams for web integrations
Data flow diagrams must document all data flows through your web portal. This demonstrates understanding of how patient data is processed and protected.
Access control matrices
Access control matrices must document who has access to what data. This ensures proper access controls are in place and can be audited.
Incident response procedures
Incident response procedures must be documented and tested. This ensures your web portal can respond effectively to security incidents.
Did You Know ?
DSPT compliance for healthcare web portals requires addressing third-party scripts, unencrypted forms, and analytics tools. All NHS patient data handlers must complete DSPT annually to maintain access to NHS systems and data.
Common DSPT Gaps in Healthcare Websites and How to Fix Them
Many healthcare websites have common DSPT gaps that can be addressed with focused remediation. Understanding these can help you prioritise your compliance efforts.
Missing encryption on contact forms
Missing encryption on contact forms is a frequent DSPT gap. All forms that collect patient data must use encryption to protect data in transit.
In practice, this means implementing SSL/TLS for all form submissions. However, many websites still have unencrypted forms that create compliance risks.
Unvetted third-party scripts
Unvetted third-party scripts can create significant DSPT risks. All third-party integrations must be reviewed and approved before implementation.
As a result, organisations should implement a vetting process for all third-party scripts. One common issue is implementing scripts without understanding their data access requirements.
Inadequate access controls
Inadequate access controls can expose patient data to unauthorized access. Granular access controls based on the principle of least privilege must be implemented.
Consider this scenario: a staff member with excessive access rights could inadvertently or intentionally access patient data they should not see. This creates a DSPT compliance violation.
Lack of audit logging
Lack of audit logging prevents organisations from demonstrating compliance. All access to patient data must be logged and monitored.
Poor session management
Poor session management can expose patient data to unauthorized access. Session timeout and authentication requirements must be properly configured.
Your DSPT Compliance Checklist for Web Portals
This checklist provides the essential steps for achieving DSPT compliance for your web portal. Use it to track your progress and ensure all requirements are met.
Annual submission timeline
Develop a timeline for your annual DSPT submission. This ensures you have adequate time to gather evidence and address any gaps.
In practice, this means starting the process early and setting milestones. Based on our healthcare IT experience, organisations that start early have smoother submissions.
Evidence gathering workflow
Develop a workflow for gathering DSPT evidence. This ensures all required documentation is collected and organised.
Vendor coordination checklist
Develop a checklist for coordinating with vendors. This ensures all third-party providers support your DSPT compliance efforts.
Continuous monitoring requirements
Implement continuous monitoring to maintain DSPT compliance. This ensures your web portal remains compliant between annual submissions.
Our NHS-compliant website design and development services can help you implement these requirements.
Conclusion
DSPT compliance for healthcare web portals is mandatory for all NHS patient data handlers. All organisations with access to NHS patient data must maintain DSPT compliance annually to maintain access to NHS systems and data.
With 25.7 Million distinct users logging into the NHS App in 2025 and 62.3 Million logins in November 2025, the scale of DSPT compliant platforms is substantial. The 43% surge in logins demonstrates growing demand for compliant digital health services.
However, achieving DSPT compliance is not just about meeting requirements. It is about protecting patient data and building trust with NHS organisations and patients. Based on our healthcare IT experience, web portals that achieve DSPT compliance gain significant market advantages.
Need expert help achieving DSPT compliance for your healthcare web portal? Our NHS compliance team can build a roadmap for full certification.
Need Expert DSPT Compliance Help?
Need expert help achieving DSPT compliance for your healthcare web portal? Our NHS compliance team can build a roadmap for full certification.
Get a Quote for DSPT Compliance →Frequently Asked Questions
Qrolic Health Technical Team
Updated for 2026 Compliance GuidanceBased on our healthcare IT experience with NHS organisations, we can help you efficiently navigate the entire DSPT process.
Insights for modern healthcare teams
Practical articles on compliance, UX, websites, SEO, and patient acquisition from healthcare specialists.

DTAC Compliance for Healthcare Websites: The Complete NHS Guide
Understand DTAC compliance for NHS healthcare websites. Learn the 5 criteria and how to pass assessment for patient facing platforms.

HIPAA OCR Enforcement: What Healthcare Websites Learned in 2024
Track HIPAA OCR enforcement in 2024: $9.9M in tracking pixel fines, 55% of penalties hit small practices. Learn violation patterns and how to avoid costly fines.
Ready to Start Your Healthcare Project?
Let's discuss your goals and show you how we can build a secure, accessible, and high-performing healthcare website.
