
Internal Reference Number: FOI_9380
Date Request Received: 05/05/2026 00:00:00
Date Request Replied To: 02/06/2026 00:00:00
This response was sent via: By Email
Request Summary: Cybersecurity
Request Category: Private Individuals
| Question Number 1: This is a request under the Freedom of Information Act 2000 regarding cybersecurity, cyber resilience and EHR/EPR supplier compliance. Please answer the questions below; where information is not held, please confirm this. Certifications and DSPT status (please tick / fill) Please see attached | |
| Answer To Question 1: See attached To accompany this answer to question 1 please also see the documents listed below: | |
| Question Number 2: DSPT — narrative follow-up If any DSPT requirements were recorded as 'Not Met' or 'Approaching Standards' in your most recent submission (Trust or supplier), please briefly describe the areas affected and confirm whether an improvement plan was submitted to NHS England. | |
| Answer To Question 2: N/A - Standards met | |
| Question Number 3: Clinical safety a. Has the Trust produced a DCB0160-compliant Deployment Safety Case and Hazard Log for its primary EHR/EPR system? b. Has the EHR/EPR supplier produced a DCB0129-compliant Clinical Safety Case Report and Hazard Log? c. Please name the Clinical Safety Officer (CSO) for (i) the Trust and (ii) the EHR/EPR supplier. d. Has the Trust conducted simulation exercises or downtime training with clinical staff to prepare for a ransomware attack? | |
| Answer To Question 3: a. Has the Trust produced a DCB0160-compliant Deployment Safety Case and Hazard Log for its primary EHR/EPR system? Yes b. Has the EHR/EPR supplier produced a DCB0129-compliant Clinical Safety Case Report and Hazard Log? Yes c. Please name the Clinical Safety Officer (CSO) for (i) the Trust and (ii) the EHR/EPR supplier. Trust - BSW Group Clinical Safety Officer: Sithabile (Star) Tshabalala Supplier - Not recorded information, requester would need to contact supplier d. Has the Trust conducted simulation exercises or downtime training with clinical staff to prepare for a ransomware attack? Business continuity plans are developed in collaboration with the respective clinical departments. Systems are required to have downtime e.g. to make upgrades or apply patches and these BCP processes are implemented by the clinical teams. | |
| Question Number 4: Cybersecurity leadership and staffing a. Does the Trust have dedicated cybersecurity staff (separate from general IT)? If yes, please give the FTE count. b. Does the EHR/EPR supplier have a Chief Information Security Officer (CISO), and is this role UK-based? c. Does the supplier have UK-based cybersecurity staff responsible for NHS-deployed systems? If yes, please give the FTE count. Please identify your primary EHR/EPR supplier when answering the supplier-related items above. | |
| Answer To Question 4: a. Does the Trust have dedicated cybersecurity staff (separate from general IT)? If yes, please give the FTE count. Yes - 2FTE b. Does the EHR/EPR supplier have a Chief Information Security Officer (CISO), and is this role UK-based? Not recorded information, requester would need to contact supplier. c. Does the supplier have UK-based cybersecurity staff responsible for NHS-deployed systems? If yes, please give the FTE count Not recorded information, requester would need to contact supplier. | |
| Please see Attachments: | |
| To return to the list of all the FOI requests please click here | |
Our staff at Salisbury District Hospital have long been well regarded for the quality of care and treatment they provide for our patients and for their innovation, commitment and professionalism. This has been recognised in a wide range of achievements and it is reflected in our award of NHS Foundation Trust status. This is afforded to hospitals that provide the highest standards of care.