The NHS 10 year Health Plan "risks propagating patient harm at an unprecedented scale" due to the lack of appropriate safety architecture to support the envisaged digital transformation, warn experts in an analysis published in the online journal BMJ Innovations.
Digital transformation is key to the realisation of the NHS 10 Year Plan for England, "shifting from bricks to clicks," but compliance with statutory digital clinical safety standards is not routinely monitored or enforced, explain the researchers.
This is despite statutory requirements under the Health and Social Care Act 2012 for digital health technologies to undergo formal clinical risk assessment (DCB0129/160), they point out.
The researchers previously reported compliance rates in a survey of 239 NHS trusts and integrated care boards (ICBs) in England, using freedom of information requests. They found that among the 14,848 digital health technologies in use in these organisations, 70% lacked documented safety assurance; only 17% were fully assured.
To better understand the drivers behind the poor compliance rates, the researchers carried out a secondary analysis of qualitative data from the original survey responses and additionally drew on previously unpublished quantitative data on Clinical Safety Officer (CSO) capacity.
CSOs are clinicians who are responsible for overseeing the clinical risk management of digital technologies used in the delivery of patient care.
On average, one full time CSO was deployed at each of the 211 organisations that responded to the original survey (February to March 2025). In all, 163 organisations (77%) provided data on hours worked
NHS trusts reported slightly higher capacity (average of 1.3 full time equivalent staff) than ICBs who reported an average of less than half (0.4).
Free text responses suggested the figures overstated actual capacity, with CSO duties typically performed alongside other substantive duties.
Twenty two organisations couldn't quantify time spent on DCB implementation. And 11 identified the CSO function as part of a senior leader's role, which included associate medical director, chief clinical information officer, and chief nurse.
"While embedding safety within senior clinical leadership may provide strategic visibility, it also means the individuals responsible for safety oversight are those with the least available time to undertake it; reducing effective capacity and impairing the development of experiential expertise," point out the researchers.
Thirty-seven organisations invoked statutory exemptions to the original FOI request, with the most common being cost and time required to meet it, with inaccessible data and/or the absence of a central register, the most common justifications.
"While we have no reason to suspect the validity of these claims, we would nevertheless highlight that both reasons indicate immature clinical safety governance processes," write the researchers.
Of particular note were the exemptions claimed under prevention or detection of crime and health and safety, which indicate a fundamental misunderstanding of what is meant by clinical safety, they highlight.
"These responses collectively suggest a workforce model that is structurally incapable of delivering the proactive, continuous risk management that the standards require," they point out.
Thematic analysis of the free text comments pinpointed four major and mutually reinforcing drivers of non-compliance: poor understanding of the standards; immature governance infrastructure and oversight; ineffective assurance processes; and the perception of a CSO not as a dedicated, professionalised post, but as an ancillary responsibility absorbed into existing roles.
"These themes do not operate in isolation," emphasise the researchers. "The result is a system in which no single component (ie, knowledge, governance, process or workforce) functions adequately, and the failure of each compounds the others."
This matters, say the researchers, because:
The Plan's ambition to rapidly adopt frontier technologies, including AI, genomics and robotics, demands a highly skilled CSO workforce with dedicated time to undertake risk assessments of increasing complexity
Despite the recognition (Topol Review) that preparing healthcare workers for a digital NHS requires embedding digital safety knowledge at undergraduate and postgraduate level, this study's findings suggest that this hasn't happened
The shift from hospital to community will also likely require concomitant expansion of the community digital footprint, especially in primary care, which is likely to be smaller and less well resourced than trusts and ICBs, with less access to specialist CSO capacity
The commissioning of services from diverse providers means extending digital safety obligations across a wider, heterogeneous provider landscape, which risks creating accountability gaps where ultimate responsibility for patient safety is unclear
The Medium Term Planning Framework mandates a 2% year-on-year improvement in productivity, creating tension between the speed of deployment and the rigour of assurance
To tackle these issues, the researchers suggest:
the need for regulation, with the Care Quality Commission uniquely placed to do this
adding DCB0160/0129 compliance to the patient safety domain of the NHS Oversight Framework to signal that digital safety governance is core to care quality
formalising the CSO pathway, introducing a tiered competency based structure for operational delivery to bring the NHS into line with other safety critical industries
the development of mechanisms for sharing best practice, identifying standard deployment hazards and causes, and raising awareness of clinical incidents
The researchers acknowledge that their data lacked the depth, contextual detail, and opportunities for clarification that would typically be afforded by traditional qualitative methods, such as semi-structured interviews. And their survey excluded primary care and adult social care, so compliance remains unknown in these sectors.
Nevertheless, they conclude: "NHS organisations in England are systematically failing to comply with legislated digital safety standards…Before the UK Government pursues its ambitious digital future for the NHS, a new digital safety architecture must be established."
They continue: "A model combining centralised assessment with local risk management, a professionalised CSO workforce, empowered regulatory enforcement, and integration of digital safety into national quality frameworks is needed to ensure that innovation and patient safety are pursued as concurrent priorities.
"Without these changes, the digital transformation envisaged in the 10 Year Health Plan risks propagating patient harm at unprecedented scale and speed."
The NHS 10 year Health Plan "risks propagating patient harm at an unprecedented scale" due to the lack of appropriate safety architecture to support the envisaged digital transformation, warn experts in an analysis published in the online journal BMJ Innovations.
Digital transformation is key to the realisation of the NHS 10 Year Plan for England, "shifting from bricks to clicks," but compliance with statutory digital clinical safety standards is not routinely monitored or enforced, explain the researchers.
This is despite statutory requirements under the Health and Social Care Act 2012 for digital health technologies to undergo formal clinical risk assessment (DCB0129/160), they point out.
The researchers previously reported compliance rates in a survey of 239 NHS trusts and integrated care boards (ICBs) in England, using freedom of information requests. They found that among the 14,848 digital health technologies in use in these organisations, 70% lacked documented safety assurance; only 17% were fully assured.
To better understand the drivers behind the poor compliance rates, the researchers carried out a secondary analysis of qualitative data from the original survey responses and additionally drew on previously unpublished quantitative data on Clinical Safety Officer (CSO) capacity.
CSOs are clinicians who are responsible for overseeing the clinical risk management of digital technologies used in the delivery of patient care.
On average, one full time CSO was deployed at each of the 211 organisations that responded to the original survey (February to March 2025). In all, 163 organisations (77%) provided data on hours worked
NHS trusts reported slightly higher capacity (average of 1.3 full time equivalent staff) than ICBs who reported an average of less than half (0.4).
Free text responses suggested the figures overstated actual capacity, with CSO duties typically performed alongside other substantive duties.
Twenty two organisations couldn't quantify time spent on DCB implementation. And 11 identified the CSO function as part of a senior leader's role, which included associate medical director, chief clinical information officer, and chief nurse.
"While embedding safety within senior clinical leadership may provide strategic visibility, it also means the individuals responsible for safety oversight are those with the least available time to undertake it; reducing effective capacity and impairing the development of experiential expertise," point out the researchers.
Thirty-seven organisations invoked statutory exemptions to the original FOI request, with the most common being cost and time required to meet it, with inaccessible data and/or the absence of a central register, the most common justifications.
"While we have no reason to suspect the validity of these claims, we would nevertheless highlight that both reasons indicate immature clinical safety governance processes," write the researchers.
Of particular note were the exemptions claimed under prevention or detection of crime and health and safety, which indicate a fundamental misunderstanding of what is meant by clinical safety, they highlight.
"These responses collectively suggest a workforce model that is structurally incapable of delivering the proactive, continuous risk management that the standards require," they point out.
Thematic analysis of the free text comments pinpointed four major and mutually reinforcing drivers of non-compliance: poor understanding of the standards; immature governance infrastructure and oversight; ineffective assurance processes; and the perception of a CSO not as a dedicated, professionalised post, but as an ancillary responsibility absorbed into existing roles.
"These themes do not operate in isolation," emphasise the researchers. "The result is a system in which no single component (ie, knowledge, governance, process or workforce) functions adequately, and the failure of each compounds the others."
This matters, say the researchers, because:
The Plan's ambition to rapidly adopt frontier technologies, including AI, genomics and robotics, demands a highly skilled CSO workforce with dedicated time to undertake risk assessments of increasing complexity
Despite the recognition (Topol Review) that preparing healthcare workers for a digital NHS requires embedding digital safety knowledge at undergraduate and postgraduate level, this study's findings suggest that this hasn't happened
The shift from hospital to community will also likely require concomitant expansion of the community digital footprint, especially in primary care, which is likely to be smaller and less well resourced than trusts and ICBs, with less access to specialist CSO capacity
The commissioning of services from diverse providers means extending digital safety obligations across a wider, heterogeneous provider landscape, which risks creating accountability gaps where ultimate responsibility for patient safety is unclear
The Medium Term Planning Framework mandates a 2% year-on-year improvement in productivity, creating tension between the speed of deployment and the rigour of assurance
To tackle these issues, the researchers suggest:
the need for regulation, with the Care Quality Commission uniquely placed to do this
adding DCB0160/0129 compliance to the patient safety domain of the NHS Oversight Framework to signal that digital safety governance is core to care quality
formalising the CSO pathway, introducing a tiered competency based structure for operational delivery to bring the NHS into line with other safety critical industries
the development of mechanisms for sharing best practice, identifying standard deployment hazards and causes, and raising awareness of clinical incidents
The researchers acknowledge that their data lacked the depth, contextual detail, and opportunities for clarification that would typically be afforded by traditional qualitative methods, such as semi-structured interviews. And their survey excluded primary care and adult social care, so compliance remains unknown in these sectors.
Nevertheless, they conclude: "NHS organisations in England are systematically failing to comply with legislated digital safety standards…Before the UK Government pursues its ambitious digital future for the NHS, a new digital safety architecture must be established."
They continue: "A model combining centralised assessment with local risk management, a professionalised CSO workforce, empowered regulatory enforcement, and integration of digital safety into national quality frameworks is needed to ensure that innovation and patient safety are pursued as concurrent priorities.
"Without these changes, the digital transformation envisaged in the 10 Year Health Plan risks propagating patient harm at unprecedented scale and speed."