NHS: Computer Software

(asked on 16th July 2019) - View Source

Question to the Department of Health and Social Care:

To ask the Secretary of State for Health and Social Care, pursuant to the Answer of 15 July 2019 to Question 275828, what the timeframe is for the full withdrawal of the Windows XP operating system from across the NHS.


Answered by
Jackie Doyle-Price Portrait
Jackie Doyle-Price
This question was answered on 22nd July 2019

0.16% of National Health Service machines are currently using Windows XP.

It is not possible to set a timeframe for complete removal of Windows XP from all NHS machines. This is because removal is not always possible, particularly where Windows XP is embedded in medical devices.

All NHS organisations have been given guidance on how to mitigate the risks if they cannot completely remove Windows XP from their estate, for example, they can segregate the affected machines from the network. They can also contact NHS Digital for further bespoke advice and support to mitigate risks.

All NHS organisations must report through the mandatory Data Security and Protection Toolkit (DSPT) whether or not they continue to run unsupported systems. Through the DSPT organisations must provide assurance that they are managing, monitoring and mitigating the risk. NHS Digital and NHSX then follow up with NHS trusts if that assurance is unsatisfactory.

Reticulating Splines