Skip to content
Wadiwa Ltd logo
All articles

· 5 min read

Care providers and the DSPT: what to expect before you start

The NHS Data Security and Protection Toolkit, usually shortened to DSPT, is an annual online self-assessment. Care providers that handle health and care information are expected to complete it, and commissioners increasingly ask to see it.

Most of the difficulty is not the questions themselves. It is gathering evidence that reflects how your service really operates across sites, shifts and community staff.

Three areas cause the most work. First, accounts: who has access to what, and how quickly access is removed when someone leaves. With high turnover this is where the gaps usually are. Second, devices: whether staff phones and tablets are managed, encrypted and can be wiped if lost. Third, training records: showing that staff have completed data security training, and being able to find that proof.

The practical approach is to make the everyday process produce the evidence. If starter and leaver steps run through one managed system, the record exists without anyone compiling it later. The same is true of device compliance.

We help providers get those foundations in place and then support the submission itself. To be clear about what that means: we help you meet your obligations. We are not an accreditation body, and completing the toolkit remains your service's responsibility.