United Kingdom - Good Practice in Health Technologies
A guide to good practice for digital and data-driven health technologies (NHSX / DHSC)
United Kingdom
RAI-GB-NA-GGPDDXX-2021A practical guide published by the UK Department of Health and Social Care and NHSX that updates and expands the earlier Code of Conduct for Data-Driven Health and Care Technologies. It sets out principles, technical and clinical assurance expectations, data protection and transparency requirements, and procurement-relevant guidance for innovators and suppliers seeking to deploy digital and data-driven technologies in the NHS.
Summary
"A guide to good practice for digital and data-driven health technologies" (updated 19 January 2021) is an official UK guidance document produced under the auspices of NHSX and the Department of Health and Social Care. It replaces and expands the earlier Code of Conduct for Data-Driven Health and Care Technologies and aims to give innovators, suppliers, manufacturers and NHS procurers a single, practical reference describing what good practice looks like across ethics, clinical safety, data protection, technical assurance, cybersecurity, interoperability and evidence generation. The guide is structured into twelve practical chapters covering: ethical operation (including the Data Ethics Framework), a clear value proposition and user-centred design, usability and accessibility, technical assurance and testing, clinical safety (including compliance with clinical safety standards DCB0129 and DCB0160), data protection and privacy (aligned with the Data Protection Act 2018 and UK GDPR), data transparency and model reporting, cybersecurity expectations, relevant regulation (medical device regulation and registration obligations where applicable), interoperability and open standards, evidence generation (clinical and economic), and commercial strategy for working with the NHS.
The guidance is not a binding regulation but functions as a procurement and good-practice benchmark used by NHS organisations and buyers. It calls for documented risk management, clinical safety management systems, data protection impact assessments (DPIAs), data flow maps, continuous monitoring of deployed models, and clear transparency about model limitations and training data. For technologies that meet the definition of a medical device, the guide points innovators to regulatory obligations managed by the MHRA and to the appropriate conformity assessment routes. The guide also signposts existing UK standards and frameworks such as NICE’s Evidence Standards Framework for digital health technologies, NHS Digital technical standards (including clinical safety standards), the National Data Opt-Out, and the Government Data Ethics Framework. Practical expectations include implementing secure software development lifecycle processes, adhering to recognised usability and accessibility standards, providing evidence of clinical effectiveness and cost-effectiveness proportional to risk, and preparing contractual and commercial plans suitable for NHS procurement.
In effect, the document operationalises a risk-based approach: higher-impact clinical decision-support or autonomous tools require more stringent evidence, conformity assessment and post-deployment monitoring than low-risk wellness or administrative tools. The guide also clarifies the responsibilities of suppliers and of NHS customers in procurement and deployment, emphasising transparency, accountability, and the need to embed ethical and legal requirements by design. While not imposing statutory penalties itself, non-compliance with the guide’s expectations can lead to procurement exclusion, clinical governance action, and referral to regulators such as the Information Commissioner’s Office (ICO) for data protection breaches or the MHRA for regulatory non-conformity. The guide has been maintained on GOV.UK and referenced in subsequent NHS and DHSC procurement and assurance frameworks.
Full article
Read full text ↗Overview
The guide titled "A guide to good practice for digital and data-driven health technologies" was issued as an update to the earlier Code of Conduct and published on GOV.UK; the guidance was updated on 19 January 2021 and later referenced in updated GOV.UK listings. It is aimed at innovators, suppliers, manufacturers and NHS customers to describe the NHS's expectations when procuring or deploying digital and data-driven technologies. The guide sets out practical principles covering ethical operation, clinical safety, technical assurance, data protection and transparency, cybersecurity, interoperability and evidence generation. It is designed to help organisations build good practice into product development 'by design' and to smooth the path between development, assessment and procurement. The full official publication is available on GOV.UK: A guide to good practice for digital and data-driven health technologies (GOV.UK).
Definitions
The guide uses practical, procurement-focused definitions. Key terms include 'digital and data-driven health technologies' (software and systems that use data analytics, machine learning or automated decision-making to inform clinical or care processes), 'innovator' and 'supplier' (organisations developing or offering such technologies), and 'clinical safety' (the systematic management of risks that could cause patient harm). The document cross-references other definitional sources such as the Data Ethics Framework and NICE evidence tiers, and distinguishes between tools that are 'medical devices' under the medical devices regulatory regime and those that are not; where medical device definitions apply, MHRA requirements are highlighted. The guide also distinguishes training data sets from deployment data, and defines obligations around data minimisation, anonymisation and the national data opt-out where applicable.
Governance and Institutional Framework
The guide positions responsibility for assurance on both suppliers and NHS organisations. Suppliers are expected to maintain a documented governance framework covering clinical safety management (for example complying with clinical safety standards such as DCB0129 and DCB0160), data protection by design and default, secure development lifecycle processes and product lifecycle risk management. NHS bodies and procurers are expected to exercise institutional oversight via procurement specifications, local clinical governance processes, and by using tools such as the NICE Evidence Standards Framework and buyer guidance. The guide refers to the Centre for Improving Data Collaboration (for legal and commercial support to NHS purchasers) and encourages clear allocation of roles and responsibilities in contracts, including monitoring, incident reporting, and model update procedures. It also cross-references national frameworks (for example the Data Ethics Framework) that NHS organisations use to evaluate ethical considerations.
Key Focus Areas
There are twelve substantive chapters in the guide; the key focus areas emphasise: 1) ethical operation and public trust; 2) articulating a clear value proposition and measurable outcomes; 3) usability and accessibility (including ISO standards and Government digital guidance); 4) technical assurance and systematic testing across functional, performance and safety domains; 5) clinical safety management and evidence of safety and efficacy; 6) data protection and privacy compliance with the Data Protection Act 2018 and UK GDPR, including DPIAs and data flow mapping; 7) data transparency and appropriate explanation of model limitations; 8) cybersecurity expectations and secure design; 9) regulatory compliance and when MHRA/medical device rules apply; 10) interoperability and open standards for integration with NHS infrastructure; 11) generation of proportionate clinical and economic evidence (NICE’s Evidence Standards Framework is referenced); and 12) a commercial strategy aligned with NHS procurement norms. The guide repeatedly frames these focus areas within a risk-based approach: higher-risk clinical tools must meet higher assurance and evidence thresholds.
Implementation Framework
Implementation guidance in the document is practical and stepwise. It recommends adopting 'by design' approaches to ethics, privacy and safety: undertake early user research, produce a clear value proposition, create data flow maps and DPIAs, document clinical safety management systems, follow recognised technical standards (for example IEC 62304 for medical software lifecycle where relevant), and demonstrate testing from unit to end-to-end environments. Suppliers are advised to prepare evidence dossiers suitable for procurement review (including outcomes, KPIs, usability testing, data provenance and model performance metrics), and to adopt post-deployment monitoring plans (continuous performance and fairness monitoring). For procurement, the guide suggests contract clauses on data handling, model updates, incident reporting and clinical governance, and refers NHS organisations to the Centre for Improving Data Collaboration for exemplar contractual wording and commercial advice. It also points innovators to NICE and NHS Digital resources to align evidence and standards.
Monitoring and Evaluation
The guide requires ongoing monitoring and re-evaluation after deployment: continuous anomaly detection for data quality, scheduled model performance reviews, logging and audit trails, and mechanisms for clinicians and users to report concerns. The document recommends data quality metrics and maturity indices (as published by NHS Digital) and describes a two-stage approach to data-driven analytics where systems first assess data quality and then produce outputs conditioned on that assessment. The guide also expects post-market performance measurement aligned with predeployment claims and KPIs; where NICE or other national assessments apply, submitted evidence should support both clinical effectiveness and economic impact. Monitoring obligations are typically split between suppliers (technical and operational monitoring) and NHS customers (clinical governance, local incident response and procurement oversight).
Penalties, Liability, and Appeals
The guide itself does not create a new criminal or civil penalty regime but highlights enforcement avenues arising from failures to meet legal obligations or procurement expectations. Consequences include commercial remedies (contract termination, exclusion from procurement frameworks), professional and clinical governance action (local incident investigations, service suspension), regulatory enforcement (referral to the Information Commissioner’s Office for data protection breaches with potential fines under the Data Protection Act 2018/UK GDPR), and MHRA action where regulatory conformity for medical devices is lacking. The guide advises clear contractual liability allocations, insurance arrangements and dispute resolution clauses. It also underlines that organisations retain obligations under broader UK law (for example health and safety, negligence liability and consumer protection where relevant) and should prepare appeals and dispute mechanisms in procurement and regulatory contexts.
Relationship to Other Instruments
The guide is explicitly linked to, and updates, the former Code of Conduct for Data-Driven Health and Care Technologies. It cross-references multiple existing instruments: the Data Ethics Framework, NICE’s Evidence Standards Framework for digital health technologies, NHS Digital clinical safety standards (DCB0129 and DCB0160), national data opt-out policy (National Data Opt-Out) and MHRA guidance on medical device regulation. The guide is intended to be complementary to statutory regimes (data protection, medical device law) and to inform procurement specifications used by NHS bodies.
International Alignment
While UK-focused and framed around NHS procurement, the guide references internationally-recognised standards (ISO, IEC), NICE and internationally-used evidence principles, and encourages alignment with global best practice in clinical evaluation, usability, cybersecurity and data governance. It acknowledges cross-border data and regulatory changes post-Brexit and directs developers to MHRA and UK-specific conformity requirements while encouraging interoperability with established open standards to facilitate international collaboration and vendor portability.
Implementation Timeline
| Event | Date |
|---|---|
| Guide updated and republished | 2021-01-19 |
| GOV.UK summary listing (latest site update) | 2025-01-27 |
| Expected ongoing adoption within NHS procurement cycles | Ongoing |
Sources and References
Requirements for a company
What an organisation has to do under United Kingdom - Good Practice in Health Technologies, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
13- Maintain a documented governance framework for clinical safety management.Innovators and suppliers of digital health technologies.
- Implement data protection by design and default, including DPIAs and data flow mapping.Innovators and suppliers of digital health technologies.
- Ensure full regulatory compliance where medical device rules apply, including MHRA requirements.Innovators and suppliers of digital health technologies classified as medical devices.
- Implement secure development lifecycle processes and robust cybersecurity measures.Innovators and suppliers of digital health technologies.
- Conduct systematic technical assurance and testing across functional, performance, and safety domains.Innovators and suppliers of digital health technologies.
- Articulate a clear value proposition and measurable outcomes for the technology.Innovators and suppliers of digital health technologies.
- +7 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under United Kingdom - Good Practice in Health Technologies, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Innovators and suppliers of digital health technologies. | Maintain a documented governance framework for clinical safety management. “Suppliers are expected to maintain a documented governance framework covering clinical safety management (for example complying with clinical safety standards such as DCB0129 and DCB0160)” | Before placing on market | Governance and Institutional Framework | Critical |
| 2 | Innovators and suppliers of digital health technologies. | Implement data protection by design and default, including DPIAs and data flow mapping. “data protection and privacy compliance with the Data Protection Act 2018 and UK GDPR, including DPIAs and data flow mapping” | Before placing on market | Key Focus Areas | Critical |
| 3 | Innovators and suppliers of digital health technologies classified as medical devices. | Ensure full regulatory compliance where medical device rules apply, including MHRA requirements. “regulatory compliance and when MHRA/medical device rules apply” | Before placing on market | Key Focus Areas | Critical |
| 4 | Innovators and suppliers of digital health technologies. | Implement secure development lifecycle processes and robust cybersecurity measures. “secure development lifecycle processes and product lifecycle risk management.” | Before placing on market | Governance and Institutional Framework | Critical |
| 5 | Innovators and suppliers of digital health technologies. | Conduct systematic technical assurance and testing across functional, performance, and safety domains. “technical assurance and systematic testing across functional, performance and safety domains” | Before placing on market | Key Focus Areas | Important |
| 6 | Innovators and suppliers of digital health technologies. | Articulate a clear value proposition and measurable outcomes for the technology. “articulating a clear value proposition and measurable outcomes” | Before placing on market | Key Focus Areas | Important |
| 7 | Innovators and suppliers of digital health technologies. | Ensure the technology meets usability and accessibility standards, including ISO and Government guidance. “usability and accessibility (including ISO standards and Government digital guidance)” | Before placing on market | Key Focus Areas | Important |
| 8 | Innovators and suppliers of digital health technologies. | Provide appropriate data transparency and explain model limitations to users. “data transparency and appropriate explanation of model limitations” | Before placing on market | Key Focus Areas | Important |
| 9 | Innovators and suppliers of digital health technologies. | Adopt post-deployment monitoring plans for continuous performance and fairness, and re-evaluation. “adopt post-deployment monitoring plans (continuous performance and fairness monitoring).” | Ongoing | Implementation Framework | Important |
| 10 | Innovators and suppliers of digital health technologies. | Generate proportionate clinical and economic evidence, aligning with NICE’s Evidence Standards Framework. “generation of proportionate clinical and economic evidence (NICE’s Evidence Standards Framework is referenced)” | Before placing on market | Key Focus Areas | Important |
| 11 | Innovators and suppliers of digital health technologies. | Clearly allocate roles, responsibilities, and liabilities in contracts, including monitoring and incident reporting. “encourages clear allocation of roles and responsibilities in contracts, including monitoring, incident reporting, and model update procedures.” | Before contract signing | Governance and Institutional Framework | Important |
| 12 | Innovators and suppliers of digital health technologies. | Follow recognised technical standards, such as IEC 62304 for medical software lifecycle where relevant. “follow recognised technical standards (for example IEC 62304 for medical software lifecycle where relevant)” | Before placing on market | Implementation Framework | Important |
| 13 | Innovators and suppliers of digital health technologies. | Prepare comprehensive evidence dossiers suitable for procurement review by NHS organizations. “Suppliers are advised to prepare evidence dossiers suitable for procurement review” | Before procurement submission | Implementation Framework | Important |
Related Regulations
MHRA guidance: Software and AI as a Medical Device (updated guidance)
United Kingdom90% similar
Ethics and governance of artificial intelligence for health: WHO guidance
WHO88% similar
Artificial Intelligence Playbook for the UK Government
United Kingdom88% similar
Generative AI Framework for HMG
United Kingdom87% similar
Joint AI plan for the safe and effective use of AI in the Norwegian health and care services 2024–2025
Norway87% similar
© Regulations.AI · updated on 13-Jun-2026