We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
Deploying AI in a health setting means more than the Data Security and Protection Toolkit. Clinical safety, medical-device rules, patient-data law, and the incoming AI Act all attach to the same system. We map the overlap, so the evidence you build for one satisfies the others.
A clinical AI tool, or a supplier serving the NHS, meets these regimes together. The DSPT is where most start; it is rarely where the duty ends.
The annual self-assessment for organisations accessing NHS patient data, now aligned to the Cyber Assessment Framework.
A clinical safety case and a nominated clinical safety officer, mandatory for health IT, AI included, on both the build and deploy sides.
Clinical AI with a medical purpose is software as a medical device, needing conformity assessment and MHRA oversight.
Lawful basis, DPIAs, and the common-law duty of confidentiality wherever an AI system processes patient information.
For systems reaching the EU, or held to its benchmark, clinical AI is high-risk and carries the full obligation set.
NHS procurement increasingly asks suppliers to evidence AI governance up front, before a deployment is approved.
The controls DSPT, clinical safety, and the AI Act share are captured once and mapped to each, not rebuilt three times.
A cited, auditable record that stands up for a DSPT submission, a clinical safety case, and a regulator alike.
As the DSPT, MHRA guidance, and the AI Act change, the record tracks them, so your assurance does not go stale.
Standard Intelligence supports, and does not replace, your DSPT submission, clinical safety processes, or regulatory obligations. This page is informational, not legal, clinical, or regulatory advice, and the DSPT standard and health-AI guidance change; confirm the current requirements with NHS England, the MHRA, and qualified advisers.