The UK National Health Service’s ambitious 10-Year Health Plan to digitize care risks patient harm at an unprecedented scale, according to researchers from University College London. Published in BMJ Innovations, the study reveals that compliance with statutory digital clinical safety standards is not routinely monitored or enforced, leaving thousands of health technologies unassessed across England.
Digital transformation stands as a core pillar of the NHS 10-Year Plan for England, aiming to pivot healthcare delivery from physical clinics to digital platforms (“shifting from bricks to clicks”). However, researchers caution that the foundational safety architecture required to support this rapid technological shift does not exist. Under the Health and Social Care Act 2012, digital health technologies must undergo formal clinical risk assessment. Despite this statutory requirement, oversight mechanisms remain weak.
The Safety Assurance Deficit Across NHS Trusts
In a previous investigation utilizing Freedom of Information requests across 239 NHS trusts and integrated care boards (ICBs) in England, researchers uncovered compliance gaps. Among 14,848 digital health technologies deployed in these organizations, 70 percent lacked any documented safety assurance. Only 17 percent achieved full assurance.
To unpack these systemic failures, investigators conducted a secondary qualitative data analysis alongside an evaluation of Clinical Safety Officer (CSO) capacity. CSOs are clinicians responsible for overseeing the clinical risk management of health IT systems used in patient care. Survey responses gathered between February and March 2025 across 211 responding organizations showed an average of one full-time equivalent CSO per institution. Out of those, 163 organizations provided detailed staffing hours. NHS trusts reported an average of 1.3 full-time equivalent staff, while integrated care boards reported an average of less than half (0.4).
Free-text survey responses indicated that these numbers overstated actual working capacity. CSO duties were typically performed alongside other substantive duties. Twenty-two organizations could not quantify the time spent implementing Digital Clinical Safety (DCB) standards. Meanwhile, 11 organizations identified the CSO function as part of a senior leader’s role—such as associate medical director, chief clinical information officer, or chief nurse. While this places safety within senior clinical leadership, it means the individuals responsible for safety oversight are those with the least available time to undertake it.
In Plain English: The Clinical Takeaway
- The Risk: Digital medical tools and apps are entering NHS hospitals and general practices without proper safety checks.
- The Regulatory Gap: Although UK law mandates formal clinical risk assessments for health technologies, over 70 percent of currently utilized digital tools lack documented safety records.
- Resource Bottlenecks: Hospital clinical safety officers are typically performing risk assessments in the gaps around a full clinical job.
A Vicious Circle of Systemic Failures
Dr. Youssof Oskrochi of the UCL Institute of Health Informatics highlighted the multifaceted breakdown in governance. “We found four failures, each making the others worse: organisations didn’t know when the standards applied, didn’t know how to apply them, couldn’t fit them into their governance, and couldn’t resource the work. Together they form a vicious circle,” Dr. Oskrochi explained.
Co-author Dr. Elliott Roy-Highley, based at UCL’s Global Business School for Health, drew a direct parallel to pharmaceutical regulation. “You wouldn’t roll out a new medicine without checking it’s safe first. Yet that’s essentially what’s happening with much of the technology used for patient care in the NHS,” Dr. Roy-Highley noted. He emphasized that some NHS trusts don’t hold a record of what digital technology they’re using, meaning potential patient safety hazards go unchecked.
| Metric / Parameter | Pharmaceutical Drugs | Digital Health Technologies in NHS (UCL Study Findings) |
|---|---|---|
| Pre-Market Safety Assurance | Checking it’s safe first | 70% lacked documented safety assurance |
| Statutory Compliance Enforcement | – | Not routinely monitored or enforced |
| Dedicated Oversight Personnel | – | Typically 1 CSO per organization (often performing duties alongside other roles) |
Contraindications & When to Consult a Doctor
While patients cannot directly audit the institutional software deployed by their healthcare providers, understanding the limits of digital health tools is vital.
Navigating Innovation Safely Moving Forward
The warning from UCL researchers serves as a critical wake-up call for health policy architects. As the NHS asks hospitals and GP surgeries to adopt AI and other complex technologies at speed, public health bodies must bridge the gap between innovation and rigorous clinical governance. Ensuring patient safety requires adequate resourcing, mandatory enforcement of statutory standards, and protected time for clinical safety officers to audit digital tools entering clinical practice.
References
- University College London (UCL). (2026). NHS 10-year plan ‘risks patient harm at unprecedented scale’. UCL News.
- BMJ Innovations. Research on digital clinical safety standards compliance within NHS trusts and integrated care boards.
- UK Legislation. Health and Social Care Act 2012. UK Government Legislation Archive.
Disclaimer: This report does not constitute formal medical advice. Always consult a licensed physician for personal healthcare decisions.
