NHS DSPT
National Health Service
Our published 2025–26 assessment met the data security standards set by the NHS in England.
View the official recordReview our assurance standards, certifications and the safeguards that protect clinic data every day.
Assurance standards and certificates
Review our published NHS assessment and request certificate scope and validity details from our team.
National Health Service
Our published 2025–26 assessment met the data security standards set by the NHS in England.
View the official recordInformation security management
The certificate records its scope, certification body and validity dates.
Request the certificateSoftware process assessment
An independent assessment of software development and process maturity.
Request the certificatePublished assessments and certificates are different forms of evidence. The relevant record or certificate defines its scope and validity.
Security controls
Benefit from secure access, encryption, backups and service continuity without having to manage the technical detail.
Account access
Clinic admins choose what each role can see and do. Optional IP restrictions can block sign-ins outside approved clinic networks.
Data protection
TLS protects data in transit. Supported data stores are encrypted at rest. Backups are encrypted and covered by recovery procedures.
Monitoring & maintenance
Centralised logs and alerts help our team spot service issues. We scan for vulnerabilities, fix findings and use external testing where appropriate.
Staff & support access
Only authorised staff can access systems or data. Access depends on role and need, with confidentiality duties, security training and incident procedures.
Privacy and contact
Review how we handle data in our Privacy Policy or contact our team about a potential security issue.
Security questions
No online service can guarantee absolute security. We use technical and organisational controls to reduce risk, monitor the service and respond to incidents.
Clinic admins assign permissions by role. Optional IP restrictions can limit access to approved networks.
The Trust Centre labels each item as registered, published or certified, links official public sources and provides a form for certificate requests.
Email security@medicasimple.com with enough detail to investigate. Do not publish the suspected vulnerability while we review it.
Evidence for your review
Request the certificate or security document your team needs.