NHS digital transformation ‘risks propagating patient harm at unprecedented scale’ – experts

NHS digital safety gaps could expose patients to harm as the 10 Year Health Plan drives adoption of AI and other technologies, experts have warned.
An analysis found widespread gaps in compliance with statutory clinical safety standards designed to ensure digital health technologies undergo formal risk assessment.
Previous survey data covering 14,848 technologies in NHS trusts and integrated care boards found 70 per cent lacked documented safety assurance and only 17 per cent were fully assured.
The latest analysis looked at why compliance was low, drawing on responses from the earlier survey and additional data on the availability of clinical safety officers.
Clinical safety officers, or CSOs, are clinicians responsible for overseeing the clinical risk management of digital technologies used in patient care.
The standards, known as DCB0129 and DCB0160, require formal clinical risk assessment of digital health technologies.
Researchers found an average of one full-time CSO at each of the 211 organisations that responded to the original survey, conducted between February and March 2025.
NHS trusts reported an average capacity of 1.3 full-time equivalent staff, compared with 0.4 among integrated care boards.
However, free-text responses suggested the figures could overstate the time actually available for digital safety work, as CSO responsibilities were often combined with other roles.
Twenty-two organisations could not quantify how much time was spent implementing the standards, while 11 said CSO responsibilities formed part of a senior leader’s wider role.
The researchers said: “While embedding safety within senior clinical leadership may provide strategic visibility, it also means the individuals responsible for safety oversight are those with the least available time to undertake it; reducing effective capacity and impairing the development of experiential expertise.”
Thirty-seven organisations used statutory exemptions when responding to the original freedom of information request.
The most common reasons included the cost and time required to provide the information, inaccessible data or the absence of a central register.
“While we have no reason to suspect the validity of these claims, we would nevertheless highlight that both reasons indicate immature clinical safety governance processes,” the researchers wrote.
They said exemptions citing prevention or detection of crime and health and safety indicated a fundamental misunderstanding of what is meant by clinical safety.
“These responses collectively suggest a workforce model that is structurally incapable of delivering the proactive, continuous risk management that the standards require,” they said.
The analysis identified four mutually reinforcing factors behind non-compliance: poor understanding of the standards, immature governance and oversight, ineffective assurance processes and treating the CSO role as an additional responsibility rather than a dedicated position.
The researchers warned these weaknesses matter as the NHS expands its use of technologies including AI, genomics and robotics.
They said greater use of these technologies would require a highly skilled CSO workforce with dedicated time to assess increasingly complex clinical risks.
Moving more care from hospitals into community settings could also increase the use of digital systems in primary care, which is likely to be smaller and less well resourced than trusts and integrated care boards, with less access to specialist CSO capacity.
Researchers also highlighted potential accountability gaps as healthcare services are commissioned from a wider range of providers.
They said the requirement to achieve a 2 per cent year-on-year improvement in productivity under the Medium Term Planning Framework could create tension between rapid technology deployment and thorough safety assurance.
Among their recommendations was the need for regulation, with the Care Quality Commission identified as uniquely placed to provide it.
They also suggested including compliance with DCB0129 and DCB0160 in the patient safety element of the NHS Oversight Framework.
Other proposals included formalising the CSO pathway with a tiered, competency-based structure and developing mechanisms to share best practice, identify standard deployment hazards and their causes, and raise awareness of clinical incidents.
The researchers acknowledged limitations in their analysis, including less detailed qualitative data than would be available through methods such as semi-structured interviews.
Primary care and adult social care were also excluded from the original survey, meaning compliance levels in those areas remain unknown.
They concluded that a new digital safety architecture should be established before the government’s planned digital transformation is pursued.
“A model combining centralised assessment with local risk management, a professionalised CSO workforce, empowered regulatory enforcement, and integration of digital safety into national quality frameworks is needed to ensure that innovation and patient safety are pursued as concurrent priorities.
“Without these changes, the digital transformation envisaged in the 10 Year Health Plan risks propagating patient harm at unprecedented scale and speed.”








