
Consent and AI Medical Scribes - Is It Required?
Part 1 of 4 of a series on AI scribes
Dr. Paul Jewell•Feb 19, 2025
Consent and AI Medical Scribes - Is It Required?Seamlessly meet all of the NHS Digital Technology Assessment Criteria requirements
The Digital Technology Assessment Criteria (DTAC) brings together legislation and best practices in five key areas: clinical safety, data protection, technical security, interoperability and usability and accessibility. By meeting the DTAC standards, both the NHS and patients can have confidence in your product.
Request a demoNHS Digital Technology Assessment Criteria
We are trusted by
Our platform includes a full DTAC service and we can ensure you pass the NHS DTAC assessment with flying colours, in a fraction of the time it would otherwise take you. Accelerate your compliance journey to meet the five pillars of DTAC:
Comply with the mandatory DCB0129 framework by completing deliverable documentation such as your Clinical Risk Management Plan, Clinical Safety Case Report and Hazard Log. Work with our expert Clinical Safety Officers for ad-hoc advice or a fully managed consultancy service.
Achieve GDPR compliance and complete the NHS Data Security and Protection Toolkit (DSPT). Complete your Record of Processing Activities, Information Asset Register and NHS Data Protection Impact Assessments. Work with our expert Data Protection Officers, and undertake our Data Protection Training.
Achieve Cyber Essentials (and Cyber Essentials Plus) certification. Book a scoping call with our expert team, establish security controls and get certified.
Understand your interoperability approach to provide a seamless care journey. Work with our team to create your interoperability strategy, and get support with EHR integration and product APIs.
Ensure your tech meets accessibility guidelines WCAG2.2 AA. Map user journeys, and undergo user acceptance testing. Use our templates to create an Accessibility Statement.
Use intelligent automation and AI to avoid duplication of work, easily meeting requirements in tandem.
Get in touch if we haven’t answered your question below, we are always happy to help!
NHS DTAC was introduced in 2021 by NHSX (now part of NHS England), and is a national baseline criteria for digital health technologies, to be used by healthcare organisations to assess suppliers. You can think of it as a larger framework of multiple smaller risk management frameworks, separated into five sections.
Yes, the Digital Technology Assessment Criteria (DTAC) is a mandatory requirement for all digital health technologies for procurement by the NHS, and a significant proportion of the DTAC form is made up of legislation.
Yes, even initial pilots require completion of the DTAC form.
No, the NHS, nor other organisations, can issue DTAC certification, but using our platform will ensure all the requirements are met.
Ensuring clinical safety is essential when introducing new digital health technologies. There are two key standards in the NHS: DCB0129 and DCB0160. Although very similar in content, DCB0129 is for the Manufacturer of Health IT Systems, whereas DCB0160 is for the Health Organisation (such as the NHS Trust where the product will be deployed). To comply with such standards, the clinical safety team must complete a Clinical Risk Management Plan, a Hazard Log and a Clinical Safety Case Report. Clinical safety is a continuous process, and it is important to have monitoring post deployment of the system.
Please contact us for additional advice on completing DCB0129, or on Clinical Safety Officers.
Data protection is an important component of DTAC. To comply companies must ensure they are compliant with GDPR by registering with the ICO and appointing a Data Protection Officer and Senior Information Risk Owner. Companies must complete key documentation, including a privacy notice, Information Asset Register and a Record of Processing Activities (also known as an Article 30 register). You must have a valid legal basis under GDPR Article 6 in order to process any personal data, and additional justification under Article 9 if the data includes Special Category Data (such as health data). A Data Protection Impact Assessment must also be completed for any Special Category Data.
For NHS procurement, companies must complete the Digital Security Protection Toolkit, which includes GDPR compliance and Cyber Essentials compliance. This also involves an external penetration test (which we can provide).
Please contact us for any additional advice on Data Protection.
To comply with the technical security aspect of DTAC, a company must complete UK Cyber Essentials, which involves a self assessment of your company’s technical security. For procurement, it is recommended to complete Cyber Essentials Plus, which involves both a self assessment and an External Audit. For NHS procurement, companies must complete the Digital Security Protection Toolkit, which includes GDPR compliance and Cyber Essentials compliance. This also involves an external penetration test (which we can provide).
Contact us for further advice on Technical Security.
To provide a seamless care journey, it is important that relevant technologies in the health and social care system are interoperable, in terms of hardware, software and the data contained within. Those technologies that need to interface within clinical record systems must also be interoperable. Application Programme Interfaces (APIs) should follow the Government Digital Services Open API Best Practices, be documented and freely available and third parties should have reasonable access in order to integrate technologies.
While some NHS trusts may request implementation of interoperability to enable a pilot of your innovation, simply having the strategy with awareness and proof of readiness to integrate is sufficient to pass the DTAC . The key part of this strategy is that it must be clear and understandable for the assessors at the NHS trust.
For more advice on interoperability, please contact us.
Usability and accessibility is about ensuring everyone can access the services they need, regardless of background, identity or circumstances. It is important to make sure people with different physical, mental health, social, cultural or learning needs can use your digital health technology, whether it's for the public or staff. This includes people who do not have access to the internet or lack the skills or confidence to use it. An essential part of this is creating a User Journey Map, while meeting accessibility standards including WCAG2.2 AA and the 2018 accessibility regulations.
Compliance is complex, but our AI tools simplify it. Discover features to stay ahead of regulations.
Kelly Klifa
CEO at Heim
Assuric has been transformative for Heim as we looked to achieve DCB0129 and DTAC compliance. The platform is easy to use, and the AI tools and automated reminders make previously dreaded compliance tasks a breeze. Paul and Matt supported us every step of the way.
Katie Baker
Director UK & Ireland at Tandem
Assuric has been fantastic in helping us quickly and safely navigate regulatory compliance in the UK. From completing Cybersecurity requirements to DSPT, DCB0129, and DTAC, the team was supportive, extremely knowledgeable, and the platform made everything quick and straightforward. A separate regulatory company we consulted at the beginning even remarked on how quickly we achieved compliance!
Maks Kozarzewski
COO at VitVio
We couldn't speak highly enough of both the Assuric team and the platform itself, which is incredibly easy to use, and with the skill and hardworking nature of the Assuric team. They've been a key component in accelerating our progress and deployments!
Maja Mazur
CEO at Healthnix
Assuric has been such a blessing in getting our DTAC and GDPR compliance done - completing all the documentation and deciding what needs to be done whilst running the business is very hard, but the team really helped us through that. The platform is easy to use, helps keep track of things and it even allows us to coordinate all the team training easily. Highly recommend them!
Dean Mawson
Clinical Director at DPM
Assuric streamlines the process of achieving and maintaining compliance with DCB0129 standards for digital health technologies. The user-friendly interface simplifies collaboration across multidisciplinary teams, while the built-in templates and workflows save significant time and effort during compliance projects. Assuric’s ability to centralise documentation and provide real-time visibility into project progress is particularly beneficial for Clinical Safety Officers and digital project teams, enhancing both efficiency and assurance.
Part 1 of 4 of a series on AI scribes
Dr. Paul Jewell•Feb 19, 2025
Consent and AI Medical Scribes - Is It Required?If you share data with a third party, you can still be held accountable and fined. What can you do to minimise the risks?
Assuric•Sep 12, 2024
Why data sharing matters under GDPR - accountability and finesGoodbye manual processes, hello automation. Let Assuric manage compliance and security, so you can focus on growth.