NHS: Artificial Intelligence

(asked on 8th July 2025) - View Source

Question to the Department of Health and Social Care:

To ask the Secretary of State for Health and Social Care, whether he plans to periodically review NHS AI models to ensure continued alignment with (a) data protection and (b) clinical safety standards.


Answered by
Karin Smyth Portrait
Karin Smyth
Minister of State (Department of Health and Social Care)
This question was answered on 15th July 2025

There are strict safeguards in place throughout the National Health Service to protect data. All providers of services which handle patient data must protect that data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, and every health organisation is required to appoint a Caldicott Guardian to advise on the protection of people’s health and care data, and to ensure that it is used properly. This includes where artificial intelligence (AI) is used in relation to patient records.

The Information Commissioners Office has developed detailed AI guidance which provides an overarching view of data protection, including the need for Data Protection Impact Assessments and to ensure compliance with UK GDPR. They have also produced an AI toolkit to support organisations auditing compliance of their AI-based technologies. NHS bodies are expected to make use of this guidance and toolkit.

The NHS has published two clinical risk management standards relating to clinical safety, with the codes DCB0129 and DCB0160, both of which are applicable to AI. Under the Health and Social Care Act 2012, manufacturers of health IT systems and health organisations that deploy and use these systems must have regard to these standards. In line with current Data Coordination Board practice, each standard comprises of: a specification, which defines the requirements and conformance criteria to be met by the user of the standard, and with the user responsible for how these requirements are met; and implementation guidance, which provides an interpretation of the requirements and, where appropriate, defines possible approaches to achieving them.

Reticulating Splines