Introduction
The NHS 10-Year Health Plan for England, with its ambitious vision to shift healthcare 'from bricks to clicks,' is a cornerstone of modernizing the country's health service. However, a new analysis published in BMJ Innovations raises serious concerns that this digital transformation, without a robust safety architecture, could lead to patient harm on an unprecedented scale. The authors, drawing on data from NHS trusts and integrated care boards (ICBs), highlight significant gaps in compliance with statutory digital clinical safety standards, raising urgent questions about the readiness of the NHS to embrace a digital-first future safely.
The Digital Transformation Vision
The NHS 10-Year Plan is built on the premise that digital technologies will revolutionize patient care, making it more efficient, accessible, and personalized. The shift from traditional brick-and-mortar services to digital platforms promises to reduce waiting times, enable remote monitoring, and empower patients with greater control over their health data. However, the plan's success hinges on the safe implementation of these technologies. The authors of the analysis argue that the current safety infrastructure is woefully inadequate to support such a large-scale digital leap.
Statutory Safety Standards and Compliance Gaps
Under the Health and Social Care Act 2012, digital health technologies used in the NHS must undergo formal clinical risk assessment, specifically DCB0129 and DCB0160 standards. These standards are designed to ensure that any software or digital tool used in patient care is thoroughly evaluated for potential risks. Despite these statutory requirements, the researchers found that compliance is not routinely monitored or enforced. In a previous survey of 239 NHS trusts and ICBs in England, they discovered that among 14,848 digital health technologies in use, a staggering 70% lacked documented safety assurance, and only 17% were fully assured. This means that the vast majority of digital tools currently in use have not been adequately vetted for safety, a situation that could have dire consequences for patients.
Clinical Safety Officer Capacity: A Critical Bottleneck
To understand why compliance rates are so low, the researchers conducted a secondary analysis of qualitative data from the original survey, supplemented by previously unpublished quantitative data on Clinical Safety Officer (CSO) capacity. CSOs are clinicians responsible for overseeing the clinical risk management of digital technologies used in patient care. The survey, conducted from February to March 2025, revealed that on average, each of the 211 responding organizations had only one full-time CSO. However, this figure masks significant variation: NHS trusts reported slightly higher capacity, with an average of 1.3 full-time equivalent staff, while ICBs had less than half that number, at 0.4. Moreover, free-text responses indicated that these numbers overstated actual capacity, as CSO duties were often performed alongside other substantive roles. Twenty-two organizations could not even quantify the time spent on DCB implementation, and 11 identified the CSO function as part of a senior leader's role, such as an associate medical director or chief clinical information officer.
The Implications for Patient Safety
The lack of adequate CSO capacity and poor compliance with safety standards create a perfect storm for patient harm. Digital health technologies, from electronic health records to AI-driven diagnostic tools, have the potential to cause harm if not properly managed. For example, a flawed algorithm could misdiagnose a condition, leading to incorrect treatment. A poorly designed patient portal could result in missed appointments or miscommunication. The authors argue that without a robust safety architecture, the NHS 10-Year Plan's digital transformation could propagate harm at an unprecedented scale.
Case Studies and Real-World Impact
While the analysis does not provide specific case studies, it references the broader context of digital health failures. In recent years, there have been high-profile incidents where digital systems have malfunctioned, causing patient harm. For instance, the WannaCry cyberattack in 2017 disrupted NHS services, leading to canceled appointments and delayed treatments. More recently, concerns have been raised about the safety of AI-powered chatbots in healthcare. These examples underscore the need for rigorous safety assessments before digital tools are deployed.
Recommendations for Improvement
The authors of the analysis propose several recommendations to address these gaps. First, they call for mandatory compliance with DCB0129/0160 standards, with routine monitoring and enforcement by regulatory bodies. Second, they advocate for increased investment in CSO roles, ensuring that these positions are adequately staffed and resourced. Third, they suggest that the NHS should develop a centralized repository of digital health technologies that have been safety-assured, making it easier for trusts and ICBs to select safe products. Finally, they emphasize the need for a culture of safety within the NHS, where digital transformation is not pursued at the expense of patient well-being.
Conclusion
The NHS 10-Year Health Plan represents a bold vision for the future of healthcare, but it must be grounded in a solid safety foundation. The analysis published in BMJ Innovations serves as a stark warning that without addressing the current deficiencies in digital safety compliance and CSO capacity, the plan could cause more harm than good. As the NHS moves forward with its digital agenda, it is imperative that patient safety remains the top priority. The authors' recommendations provide a roadmap for achieving this, but they require urgent action from policymakers, NHS leaders, and clinicians alike.
This article is based on reporting by Medical Xpress. Read the original article.
Originally published on medicalxpress.com








