CareHealthHealthcareHospitalsNewsNHS

NHS 10-Year Plan ‘Risks Patient Harm At Unprecedented Scale’

NHS organisations in England are “systematically failing” to comply with legally required digital safety standards, potentially putting patients at risk as the health service accelerates its use of artificial intelligence and other digital technologies, researchers have warned.

A study published in BMJ Innovations found that 70% of nearly 15,000 digital health technologies in use across NHS trusts and integrated care boards (ICBs) had no documented evidence of clinical safety assurance.

The findings come as digital transformation forms a central part of the NHS 10 Year Health Plan for England, which aims to shift services “from bricks to clicks”.

Under statutory requirements introduced through the Health and Social Care Act 2012, digital health technologies used in patient care are required to undergo formal clinical risk assessment.

However, the researchers said compliance with these requirements is not routinely monitored or enforced.

The study follows an earlier survey of 239 NHS trusts and ICBs, conducted through Freedom of Information requests. Of the 14,848 digital health technologies identified, just 17% were fully assured, while 70% had no documented safety assurance.

The latest research examined why compliance was so poor, using a secondary analysis of free-text responses from the original survey alongside previously unpublished data on the capacity of Clinical Safety Officers (CSOs).
CSOs are clinicians responsible for overseeing the clinical risk management of digital health technologies, including health IT systems used in patient care.

Limited capacity for clinical safety

The researchers found that, on average, each of the 211 organisations responding to the relevant part of the survey had the equivalent of one full-time CSO.

However, the figures appeared to overstate the amount of capacity actually available for digital safety work.

Of the 211 organisations, 163 (77%) provided information on hours worked. NHS trusts reported an average of 1.3 full-time equivalent CSO staff, compared with less than half a post on average — 0.4 FTE — among ICBs.

Free-text responses indicated that CSO responsibilities were commonly undertaken alongside other substantive clinical or leadership roles.

Twenty-two organisations were unable to quantify the amount of time spent implementing the relevant digital clinical safety standards. A further 11 said the CSO function formed part of a senior leadership role, including positions such as associate medical director, chief clinical information officer and chief nurse.

The researchers said this created a significant capacity problem.
“While embedding safety within senior clinical leadership may provide strategic visibility, it also means the individuals responsible for safety oversight are those with the least available time to undertake it,” they wrote.

They warned this could reduce the effectiveness of safety oversight and limit the development of specialist experience.

Four key barriers identified

Analysis of the organisations’ responses identified four major, interconnected reasons for non-compliance:
• Poor understanding of the digital clinical safety standards
• Immature governance infrastructure and oversight
• Ineffective assurance processes
• Clinical Safety Officer responsibilities being treated as an additional duty rather than a dedicated professional role

The researchers said these problems reinforced one another, creating a “vicious circle” in which weaknesses in knowledge, governance, processes and workforce capacity compounded each other.

Lead researcher Dr Youssof Oskrochi, from the UCL Institute of Health Informatics, said the findings raised concerns about the NHS’s ability to safely deliver its planned digital transformation.

“Digital tools now influence almost every part of a patient’s care, and the law requires the NHS to check they are safe before they are used,” he said.

“Our previous study found that across the NHS in England over 70% of those tools had no record of ever having been safety checked. This study asked why.

“We found four failures, each making the others worse: organisations didn’t know when the standards applied, didn’t know how to apply them, couldn’t fit them into their governance, and couldn’t resource the work. Together they form a vicious circle.”

Dr Oskrochi said the scale of planned digital transformation made addressing the issue increasingly urgent.

“The 10-Year Health Plan makes digital transformation one of three foundational shifts for the NHS. Our findings suggest the safety architecture needed to support it does not exist,” he said.

“Innovation and patient safety have to be pursued together, and at the moment only one of them is being planned for.”

Concerns over rapid adoption of AI

Co-author Dr Elliott Roy-Highley, from UCL’s Global Business School for Health, compared the current approach to digital technology with the safety checks applied to medicines.

“You wouldn’t roll out a new medicine without checking it’s safe first. Yet that’s essentially what’s happening with much of the technology used for patient care in the NHS,” he said.

He warned that some NHS organisations did not have a complete record of the digital technologies they were using, making it difficult to establish whether potential risks had been assessed.

The researchers also raised concerns about the planned rapid adoption of AI and other complex technologies.

Dr Roy-Highley said: “The NHS’s 10 Year Plan asks hospitals and GP surgeries to adopt AI and other complex technologies at speed. Without action, we risk scaling up patient harm at the same pace we scale up new technology.”

The researchers called for independent checks by the Care Quality Commission (CQC), dedicated digital safety roles and systems to ensure that safety problems identified in one NHS organisation are shared with others using the same technology.

FOI responses highlight governance gaps

Thirty-seven organisations cited statutory exemptions when responding to the original Freedom of Information request.
The most common reasons were the cost and time required to provide the information. Organisations also cited inaccessible data and the absence of a central register of digital technologies.

The researchers said these responses pointed to “immature clinical safety governance processes”.

They concluded that the current workforce model was “structurally incapable” of delivering the proactive and continuous risk management required by the relevant standards.

The researchers warned that the challenges could become greater as healthcare provision moves further into community settings.

They highlighted concerns around the expansion of digital technology in primary care, where organisations may have fewer resources and less access to specialist clinical safety expertise than NHS trusts and ICBs.

They also said the commissioning of services from a wider range of providers could create accountability gaps if responsibility for digital patient safety is unclear.

Calls for stronger regulation

To improve compliance, the researchers recommended greater regulatory oversight, including a potential role for the CQC.
They also called for digital safety compliance to be incorporated into the patient safety element of the NHS Oversight Framework, signalling that digital safety governance should form part of wider care quality requirements.

Other recommendations included formalising the Clinical Safety Officer career pathway through a tiered, competency-based structure and establishing mechanisms for sharing best practice, common deployment hazards and lessons from clinical incidents.

The researchers said this would bring the NHS closer to the approach taken in other safety-critical industries.

However, they acknowledged limitations to the study.

The analysis relied on free-text responses collected through the original survey rather than traditional qualitative methods such as semi-structured interviews, meaning the researchers had less opportunity to explore the context behind individual responses.

The survey also excluded primary care and adult social care, meaning the extent of digital safety compliance in those sectors remains unknown.

‘A new digital safety architecture’ needed

Despite these limitations, the researchers said their findings demonstrated systemic weaknesses in the NHS’s approach to digital clinical safety.

They concluded that a new digital safety framework should be established before the Government pursues the full ambitions of its digital NHS programme.

They called for a model combining centralised assessment with local risk management, a professionalised CSO workforce, stronger regulatory enforcement and the integration of digital safety into national quality frameworks.

Without such changes, they warned, the digital transformation set out in the NHS 10 Year Health Plan could increase the scale and speed at which patient harm occurs.