Sound familiar?
- Patient forms are PDFs emailed back and retyped
- Referrals arrive by fax, email and post with no single queue
- Care notes are on paper and audited by hand before a CQC visit
- Your clinic system cannot produce the report a commissioner asks for
- Staff share logins because the system has no proper roles
- You are not sure what an NHS customer will ask for in assurance
Key facts
- Designed for UK GDPR special category data: encryption, access control and audit logs
- Awareness of the NHS Data Security and Protection Toolkit (DSPT), DTAC and DCB0129/DCB0160
- Integrations with clinic systems such as Semble, Cliniko and WriteUpp, plus NHS APIs where access is granted
- HL7 FHIR R4 and the UK Core profiles for structured health data exchange
- NHS login and the Personal Demographics Service via NHS England's API platform, subject to onboarding
- UK-hosted infrastructure by default
- Fixed-price quote after a free chat
Who we build for in health and care
dijitul developments works with private clinics, physiotherapy and dental practices, care providers, health and wellbeing services, and suppliers who sell software or services into the NHS. We are not an NHS supplier of clinical record systems and do not claim to be. What we build is the bespoke layer: portals, booking, referral handling, reporting and the integrations between the systems you already run.
Clinics typically use practice systems such as Semble, Cliniko, WriteUpp or Carebit. GP practices run EMIS Web or TPP SystmOne. Care providers use digital social care record systems such as Nourish, Person Centred Software or Birdie. Each has a different integration story, and part of scoping is finding out what each vendor's API actually allows.
The standards that apply
- UK GDPR and the Data Protection Act 2018: health data is special category data. That means a lawful basis plus an Article 9 condition, a data protection impact assessment for most new systems, and tight access control.
- Data Security and Protection Toolkit (DSPT): the annual self-assessment for any organisation with access to NHS patient data or systems. The 2025-26 toolkit (version 8) is aligned to the NCSC Cyber Assessment Framework for NHS organisations, while IT suppliers still complete a non-CAF version this year, with a 30 June 2026 deadline, according to the DSPT website.
- DTAC: NHS England's Digital Technology Assessment Criteria cover clinical safety, data protection, technical security, interoperability and usability. NHS England revised DTAC after a 2024 review, and the previous form should not be used from 6 April 2026.
- DCB0129 and DCB0160: clinical risk management standards for manufacturers and deploying organisations. NHS organisations should not procure health IT without DCB0129 assurance. If your product needs a clinical safety officer and hazard log, we build alongside that process.
- MHRA: software that diagnoses or guides treatment may be a medical device. We help you identify that early; we do not build regulated medical devices without the right regulatory partner.
- CQC: registered providers need records that show safe, effective care, which shapes audit and reporting features.
Integrating with NHS and clinical systems
NHS England publishes APIs through its API platform, including the Personal Demographics Service (PDS) FHIR API, NHS login for patient authentication and GP Connect for appointments and records. Access is not automatic: each requires onboarding, a use case, assurance and often a connection agreement. We help you understand which route fits before any code is written.
For structured data we use HL7 FHIR R4 and the UK Core profiles, and we handle older HL7 v2 messages where a lab or hospital system still sends them. For private clinic systems we use their REST APIs or webhooks. See API integration and systems integration.
How we build securely
Our default for health projects: UK-hosted infrastructure, encryption at rest and in transit, multi-factor authentication, role-based access, immutable audit logs of who viewed what, automatic session timeouts, and documented backup and restore tests. We write the technical sections your DPIA and DSPT submission need, and we support penetration tests by your chosen tester. Ongoing patching and monitoring can be handled through dijitul support.
Typical healthcare projects
Some examples of the kind of work that fits this page:
- A private clinic patient portal. Patients book through the portal, complete medical history and consent forms before the appointment, and receive letters securely. Data flows into the clinic system through its API, so clinicians never retype a form.
- A referral hub. A service receiving referrals from GPs, hospitals and self-referral gets one triage queue, with structured referral forms, attachments, priority rules and status updates back to the referrer.
- Care provider reporting. A group of care homes pulls incident, falls, medication and staffing data from its digital care record system into one set of dashboards, ready for CQC inspections and board meetings.
- A supplier preparing for NHS sales. A company selling a non-clinical tool to NHS trusts needs single sign-on with NHS organisations' Microsoft Entra ID, audit logs, data retention controls and the technical evidence for DTAC and DSPT. We build those features and help assemble the evidence.
In each case the hard work is less about screens and more about access control, audit trails and integration agreements, which is why we scope those first.
Getting started
Start with a free chat. We will ask about the data involved, who needs access and which systems hold it, then scope the build with privacy and clinical safety considered from day one. You get a fixed-price quote for the defined scope. Related: patient and client portals and booking systems.
What we deliver
- Patient or client portals for booking, forms, consent and secure messaging
- Referral management with triage queues and status tracking
- Integrations with clinic and care systems and, where approved, NHS APIs
- Reporting and dashboards for commissioners, CQC and internal governance
- Role-based access, audit logs and data retention controls
- Documentation to support your DSPT, DPIA and clinical safety work
How it works and what it costs
Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data.
Free chat
Tell us the problem in plain English: what you do now, what goes wrong and what "better" looks like. No charge, no obligation.
Scoping
We map the processes, systems and data involved, agree what is in and out, and write it down so there are no surprises.
Fixed-price quote
You get a fixed price for the agreed scope, or a phased plan for bigger builds, so you can start small and prove it works.
Build and test
We build in short stages you can see and try, test against real data, then go live carefully with a rollback plan.
Hand over and look after
You own the code and the data. We can host it, support it and keep improving it, or hand it to your own team.
Frequently asked questions
Do you build NHS-compliant software?
We build software designed around UK GDPR, the DSPT, DTAC and DCB0129 requirements, and provide the technical documentation those assessments need. Compliance is assessed for your organisation and product, so dijitul works with your DPO and clinical safety officer rather than claiming a blanket certification.
Can you integrate with EMIS or SystmOne?
Direct integration with GP systems is tightly controlled. Routes include GP Connect through NHS England's API platform or the vendors' partner programmes, each with onboarding and assurance. We assess which route is realistic for your use case during scoping.
Can patients log in with NHS login?
NHS login is available to services that NHS England approves through its onboarding process, which checks the use case and assurance. Once your service is accepted, dijitul builds the integration using OpenID Connect and maps the verified identity to your patient records.
Where is the data hosted?
In UK data centres by default, for example Microsoft Azure UK South or AWS London, with encryption at rest and in transit. dijitul documents hosting, backups and access controls so your data protection impact assessment and DSPT submission are straightforward.
Is our software a medical device?
It might be if it diagnoses, predicts or guides treatment. Use MHRA guidance and NHS England's DTAC decision tree to check. dijitul helps identify the question early and does not build regulated medical devices without an appropriate regulatory partner.
How is pricing handled?
Every dijitul project is a fixed-price quote after a free chat and a scoping stage. For healthcare work the quote includes the security controls, audit logging and technical documentation that DSPT, DTAC and data protection assessments need, rather than treating them as extras.
Related
Tell us what you need to build
Free chat, clear scope, fixed-price quote. You own everything we build.