E2ERisk helps NHS trusts, ICBs and care providers assure the suppliers behind patient-facing services - now the Data Security and Protection Toolkit (DSPT) is aligned to the NCSC CAF and annual submissions no longer reflect live risk.
NHS trusts, ICBs and care providers run patient-facing services on top of a deep supply chain: electronic patient records, e-referral and booking systems, diagnostics and pathology platforms, shared care records, and the processors and managed providers behind them. When one of those suppliers is breached or goes offline, the impact lands on clinical workflows, cancelled appointments and patients - not just a compliance report.
Now the DSPT is aligned to the NCSC CAF, the bar on supplier assurance has risen - and a once-a-year toolkit submission no longer reflects an estate that changes constantly. E2ERisk links every supplier and processor to the patient data it handles and the clinical services it supports: DSPT- and DTAC-aligned assessment, DPIA linkage and continuous outside-in monitoring, in one place.
Built for health-and-care data environments - UK data residency, customer-tenant deployment and an append-only audit trail - so privacy, security and continuity sit together rather than in three disconnected tools.
Most health-and-care organisations understand their obligations; what they lack is a current, connected view of which supplier holds which data. A single trust or ICB can depend on dozens of clinical-system, diagnostics and managed-service providers - each touching patient information - and a once-a-year DSPT scramble cannot keep pace. Here is the difference one shared evidence base makes.
Every clinical supplier follows the same path, from the moment it is engaged through to continuous monitoring long after onboarding. How deep the assessment goes is set by the patient data it touches and the service it underpins - so a small information-governance team spends its effort where patient risk actually concentrates, not spread evenly across every vendor.
You know which supplier holds which patient data - and that it is assured.
The obligations do not change; the work behind them does. Instead of rebuilding the DSPT evidence by hand each year and tracking clinical suppliers in a spreadsheet, the same activity runs as one connected, auditable process - line by line, here is what moves.
| What you do | Toolkit + spreadsheets | E2ERisk |
|---|---|---|
| DSPT evidence | Assembled once a year, by hand | Captured once and kept current |
| Clinical suppliers | Tracked loosely | Assessed by the data they touch |
| Patient data flows | Hard to see end to end | Mapped to suppliers and DPIAs |
| DPIAs | Word files | A living register, ICO-ready |
| Continuity | Per-supplier guesswork | Suppliers mapped to clinical services |
| An audit | A fire drill | An evidence pack on demand |
The result is not just an easier toolkit submission - it is a defensible position on patient data. The moment a regulator or a board asks, you can show which supplier holds what, that it has been assessed, and that a DPIA covers the processing.
You do not have to start everywhere. Most health-and-care teams begin with Supplier Assurance and the DPO Centre - the suppliers and processing that touch patient data - then add CAF and Business Resilience as the shared evidence base proves itself. Because every module runs on one engine, what you build for the first carries straight into the next.
For a health-and-care organisation the payoff is a single, current picture of every supplier that touches patient information. One register holds every clinical supplier, each DPIA is linked to the processing and the suppliers behind it, and the DSPT evidence is captured once rather than rebuilt from scratch each year.
And because exposure is monitored continuously rather than checked once a year, you learn about a supplier problem as it emerges - not at the next audit, and not when it has already affected patient services.
A trust answers to more than one regime at once, and an assessor for the DSPT will not accept evidence shaped only for ISO. E2ERisk maps a single body of assessment answers to every regime health-and-care providers are held to - so the evidence holds up whichever one is asking.
A 30-minute walkthrough on your clinical suppliers and the DSPT - no slides.