Vendor-neutral guide · 9 min read
NHS Data Security and Protection Toolkit: remote access expectations
Written by the 247connect Marketing Team
Shape of the topic
In short
The Data Security and Protection Toolkit, known as the DSPT, is the self-assessment framework that health and care organisations in England use to show they are meeting the National Data Guardian's data security standards. It is completed annually and covers everything from staff training to technical resilience. Remote access is not a single line item in the toolkit, but it runs through several of its standards: access to systems must be controlled and monitored, third-party suppliers who connect remotely must be managed, and any support session touching patient data has to be accounted for. This guide sets out what to check when remote access or remote support tooling is used anywhere near an NHS or care system.
Key takeaways
- The DSPT is an annual self-assessment against the National Data Guardian's data security standards, not a one-off certificate.
- Remote access by staff and by third-party suppliers both fall under the toolkit's access control and third-party assurance standards.
- Suppliers who connect remotely to NHS systems are typically expected to complete their own DSPT submission or provide equivalent assurance.
- Session logging and named accounts support the toolkit's requirement to know who accessed what, and when.
- Unattended access to clinical systems needs particularly tight controls, since patient safety and confidentiality both depend on it.
- Organisations should check their specific DSPT obligations with NHS England or their integrated care board rather than relying on general summaries.
What the DSPT asks organisations to show
The DSPT is structured around ten National Data Guardian standards, covering areas such as personal confidential data, staff responsibilities, training, managing data access, process reviews, responding to incidents, continuity planning, unsupported systems, IT protection, and accountable suppliers. Organisations self-assess against a set of mandatory evidence items each year and submit their status as not satisfactory, approaching standards, or standards met.
Remote access sits mostly within the standards on managing data access, IT protection, and accountable suppliers. Any route by which a person, whether staff, contractor or software vendor, can reach a system holding patient or care data remotely needs to be identified, controlled and reviewed as part of that self-assessment.
Access control for remote users
The toolkit expects organisations to know who has access to which systems, to grant that access on a least-privilege basis, and to remove it promptly when it is no longer needed. For remote access this means every remote session, whether it is a clinician working from home or a technician providing remote support, should be tied to an identifiable, authorised individual rather than a shared or generic account.
Multi-factor authentication is expected wherever remote access reaches systems holding patient data, reflecting the wider move across public sector guidance towards MFA as a baseline control rather than an optional extra. Organisations should also be able to show that access rights are reviewed on a regular cycle, not granted once and forgotten.
- Named accounts for every remote user, staff or supplier
- Multi-factor authentication on any remote route into clinical or care systems
- Regular review of who still needs remote access, not a one-off grant
Third-party and supplier remote access
A significant part of the DSPT's accountable suppliers standard concerns organisations that connect to NHS systems remotely, including IT support providers, software vendors and managed service providers. Where a supplier needs remote access to provide support, the expectation is that the relationship is covered by a data processing or data sharing agreement, and that the supplier can demonstrate its own equivalent data security assurance, typically by completing a DSPT submission of its own.
This matters in practice because a support session that reaches into a clinical system is, from a data protection standpoint, no different to any other form of access to patient data. The supplier's remote access tool, its session logging and its account management practices become part of the wider organisation's risk picture, not a separate concern that sits outside it.
Session logging and evidence
Several DSPT evidence items rely on being able to show, after the fact, who accessed a system and when. Remote access tools that produce clear session logs, recording the operator, the device or system accessed, and the time and duration of the session, give an organisation the raw material to answer these evidence requests directly rather than relying on assurances.
Tools such as 247connect, which support named operator accounts, session audit logs, and encrypted connections, are the kind of feature set that helps an organisation evidence its access control and audit standards, though the DSPT assessment always looks at the organisation's practices as a whole rather than crediting any single product.
- Retain session logs long enough to support an incident investigation or audit request
- Record operator identity, system accessed, and session duration for every remote connection
- Make logs retrievable within a reasonable timeframe if requested by an auditor
Unattended access to clinical systems
Unattended remote access, where a device can be reached without a person present to approve the session, needs particular care in a health and care setting. Systems that hold live patient information, or that control clinical devices, should be reserved for access models with the tightest controls, and any unattended access should be justified, documented and reviewed rather than the default configuration.
Because patient safety, not just data confidentiality, can be affected if an unauthorised or poorly controlled remote session interferes with a clinical system, organisations should treat this category of access as higher risk than routine office IT support, and apply correspondingly stronger approval and monitoring.
Best-practice checklist
1. Map every remote access route into clinical systems
List staff remote working access, supplier remote support access and any remote monitoring tools that reach systems holding patient data.
2. Confirm supplier DSPT status
For any third party that connects remotely, check whether they have their own current DSPT submission or equivalent data security assurance in place.
3. Require named accounts and MFA
Ensure every remote user, internal or external, connects through a named account protected by multi-factor authentication.
4. Put a data processing agreement in place
Where a supplier's remote access touches patient data, confirm a data processing or sharing agreement covers that access.
5. Review remote access rights regularly
Set a cycle, at least annually, for reviewing who still needs remote access and removing rights that are no longer justified.
6. Restrict unattended access to justified cases
Document why any device is configured for unattended remote access, particularly where clinical systems are involved.
7. Test that session logs can be retrieved
Periodically pull a sample session log to confirm the data an auditor would ask for is actually available and complete.
8. Confirm obligations with your ICB or NHS England
DSPT scope and evidence requirements can vary by organisation type, so check specific obligations directly rather than relying on general guidance.
Common pitfalls
- Assuming a supplier's general reputation substitutes for checking their actual DSPT status
- Leaving remote access to clinical systems on shared or generic accounts
- Not having a data processing agreement in place before a supplier is given remote access
- Treating unattended access as the default configuration rather than a deliberate, reviewed exception
- Discovering during an audit that session logs are not actually retrievable
What to measure
| Suppliers with confirmed DSPT status | Target 100% before remote access is granted |
|---|---|
| Remote accounts using MFA | Target 100% coverage for systems holding patient data |
| Access review frequency | At least annually, more often for high-risk systems |
| Time to remove a leaver's remote access | Should be measured in hours |
Select any column heading to sort.
Frequently asked questions
- Does the DSPT apply to IT support companies as well as NHS organisations?
- Yes, where a supplier processes or has access to NHS patient data, including through remote support, they are generally expected to complete their own DSPT submission or provide equivalent assurance, since the toolkit's accountable suppliers standard covers third-party access.
- Is multi-factor authentication mandatory under the DSPT?
- The toolkit's evidence items increasingly expect MFA on remote access to systems holding patient data, reflecting wider public sector direction, though exact mandatory items can change between toolkit versions, so it is worth checking the current year's assertions directly.
- Can a third-party IT support provider have unattended access to an NHS system?
- It is possible but should be treated as higher risk, justified in writing, covered by a data processing agreement, and subject to tighter monitoring than routine attended support, given the potential impact on patient data and clinical systems.
- How often does the DSPT need to be completed?
- Organisations self-assess and submit their DSPT status annually, though the underlying access controls and supplier assurance work should be maintained continuously rather than treated as an annual exercise.
- What happens if a supplier's remote access does not meet DSPT expectations?
- This can affect the commissioning organisation's own DSPT status and, depending on the contract, may need to be addressed through the supplier relationship, additional controls, or a decision not to proceed with that supplier for data-touching work.
Sources
Independent, standards-body and peer-reviewed material. None of these sources is affiliated with 247connect.
- Data Security and Protection Toolkit
NHS England
Official toolkit portal, including the current year's standards, evidence items and guidance.
- Data security standards
National Data Guardian, GOV.UK
The ten National Data Guardian standards that underpin the DSPT structure.
- Guidance for third-party suppliers
NHS England, DSPT
Guidance addressing how suppliers connecting remotely to NHS systems are expected to demonstrate assurance.
Putting it into practice
This guide is deliberately product-neutral. If you want to see how one implementation handles these requirements — attended and unattended access, named operator accounts, AES-256 encryption, audit logs and fixed pricing — the reference pages on this hub document 247connect in detail, and the product itself lives at 247connect.cloud.
More best-practice guides
ISO 27001 & remote support
Which ISO/IEC 27001:2022 Annex A controls remote support touches, and what evidence an auditor typically asks for.
UK GDPR & session recording
How UK GDPR principles apply to remote session recording and access logs: lawful basis, transparency and how long to keep them.
Schools digital standards & remote access
How DfE digital and technology standards and safeguarding expectations apply to remote access and remote IT support in schools and academy trusts.