NHS DTAC Physiotherapy Software: What UK Buyers Need to Know

September 23, 2026

TL;DR

  • DTAC is an NHS assessment framework that supports local assurance and procurement decisions. It is not a central approval or certification.
  • No national register lists “DTAC-approved” physiotherapy software, and DTAC does not provide a universal pass or fail decision.
  • NHS buyers should request current, dated evidence covering clinical safety, data protection, technical security, interoperability, and usability and accessibility.
  • Physitrack is DTAC compliant and holds a current Data Security and Protection Toolkit submission. Each NHS organisation must still complete its own due diligence and make its own deployment decision.

What DTAC actually is, and what it is not

The NHS introduced the Digital Technology Assessment Criteria, known as DTAC, to give health and care organisations a common structure for assessing digital products. DTAC brings clinical safety, data protection, technical security, interoperability, and usability and accessibility into one assessment. NHS trusts and other buying organisations apply the criteria as part of their own assurance and procurement work.

DTAC does not provide central NHS approval or certification. No national certifying body awards permanent DTAC status, and no authoritative public register lists every supplier as approved or rejected. The framework also has no universal pass mark that compels an NHS organisation to buy or deploy a product.

A supplier can complete the DTAC documentation and provide evidence against each assessment area. The buying organisation must then review that material against its intended use, local policies, risk tolerance, technical environment, and clinical pathways. One trust may accept the available evidence for a particular deployment while another requests further controls or decides that the product does not meet its needs.

Claims such as “NHS approved”, “DTAC certified”, or “DTAC accredited” can therefore give buyers the wrong impression. More accurate supplier wording states that the product has completed a DTAC assessment or that the supplier can provide a current DTAC evidence pack for local review.

DTAC also requires continuing scrutiny rather than a one-time check. Product updates, security incidents, changes in data processing, new integrations, and altered clinical uses can affect the evidence behind an earlier assessment. Buyers should request dated documents, confirm which product version and deployment model they cover, and set review points throughout the contract. Each NHS organisation remains responsible for its own assurance decision before deployment and during use.

The five DTAC assessment areas

DTAC divides local assurance into five areas. Buyers should examine the evidence within each area rather than treating a completed questionnaire as proof of suitability.

Clinical safety

Clinical safety evidence should show how the supplier identifies and controls risks that could harm patients. Suppliers should reference DCB0129 and provide a clinical risk management plan, hazard log, clinical safety case, and named clinical safety officer. The deploying NHS organisation retains separate duties under DCB0160 and must assess risks created by its intended configuration, users, and care pathways.

Data protection

Data protection evidence should explain how the product handles personal and special category health data under UK GDPR and the Data Protection Act 2018. Buyers should check the supplier’s current Data Security and Protection Toolkit submission alongside its privacy information, retention rules, and data-flow documentation. The supplier should also identify its subprocessors and explain whether data leaves the UK. A completed DSPT submission supports assurance, but it does not replace a local data protection impact assessment or controller and processor review.

Technical security

Technical security evidence should demonstrate how the supplier prevents, detects, and responds to security incidents. Cyber Essentials or Cyber Essentials Plus can support that review, with Plus providing independent technical verification of the implemented controls. Buyers should also request recent penetration-testing evidence, remediation status, and details of access controls and encryption. Security evidence needs a clear date because product architecture and identified vulnerabilities change over time.

Interoperability

Interoperability evidence should identify exactly how the product exchanges and exports information. Suppliers should name supported standards, such as FHIR or SNOMED CT where relevant, and provide interface specifications or conformance results. Buyers should test whether the proposed connections work with their local records and identity arrangements. A general claim that a platform has an API does not establish that a required integration exists or can transfer data safely.

Usability and accessibility

Usability and accessibility evidence should show that intended users can complete relevant tasks safely and effectively. Suppliers should reference WCAG 2.1 AA and provide an accessibility statement supported by testing. User research should include clinicians and patients who reflect the intended service, including people with disabilities or limited digital confidence. Buyers should assess the actual patient and clinician journeys because technical conformance alone cannot reveal every barrier within a rehabilitation pathway.

What procurement, clinical governance, digital and IG leads should request from suppliers

A supplier should provide dated evidence that covers the product version and deployment model under review. A statement such as “NHS approved” does not identify who assessed the product, what they assessed, or whether the evidence remains current.

Procurement lead

  • Request the completed DTAC response, including its assessment date, scope, product version, and any unresolved actions.
  • Check contract terms for service levels, support responsibilities, liability, insurance, subcontractors, and termination assistance.
  • Confirm pricing assumptions, implementation costs, contract duration, renewal terms, and data export costs.
  • Require the supplier to record its assurance obligations in the contract rather than relying on sales materials.

Clinical safety officer

  • Ask for the supplier’s DCB0129 clinical safety case, hazard log, clinical risk management plan, and named clinical safety officer.
  • Check how the supplier records safety incidents, controls product changes, and communicates new hazards to customers.
  • Request enough product evidence to support your organisation’s DCB0160 clinical risk assessment. Supplier compliance with DCB0129 does not complete the deploying organisation’s DCB0160 duties.
  • Confirm which workflows and intended uses the safety case covers. Evidence for exercise prescription may not cover every telehealth or monitoring workflow.

Digital lead

  • Request a current technical architecture diagram showing hosting arrangements, system boundaries, and data flows.
  • Ask which interoperability standards, APIs, identity services, and single sign-on methods the product supports. Require technical documentation or test evidence for any claimed integration.
  • Review security testing, access controls, audit logging, backup arrangements, recovery objectives, and service monitoring.
  • Check accessibility testing against the stated standard and ask how the supplier manages identified usability barriers.

Information governance lead

  • Request a direct reference to the supplier’s current DSPT submission status and confirm the relevant organisation name.
  • Establish controller and processor roles, then review the data processing agreement and support for your data protection impact assessment.
  • Confirm data locations, international transfer safeguards, retention rules, deletion procedures, and the supplier’s current list of subprocessors.
  • Ask how the supplier manages data subject rights, personal data breaches, and changes to processing activities.

Each lead should record evidence dates, owners, limitations, and review points. Local assurance should treat supplier documents as inputs to a deployment decision, not as a substitute for that decision.

DTAC, DSPT, UK GDPR, clinical safety and related standards compared

These frameworks answer different assurance questions. Buyers should assess them together rather than treating any one item as proof of overall suitability.

Framework or standard What it is Who is responsible Evidence to request
DTAC An NHS assessment framework covering clinical safety, data protection, technical security, interoperability, and usability and accessibility. The supplier provides evidence. Each buying organisation evaluates that evidence and makes its own decision. A dated DTAC response, supporting documents, identified gaps, and evidence of review by the relevant local leads.
DSPT A self-assessment against NHS data security and protection requirements. Organisations handling NHS patient data or accessing relevant NHS systems submit it. Current published submission status, submission date, scope, and any improvement plan.
UK GDPR Data protection law governing the use of personal data. Controllers and processors must meet their respective duties. The ICO regulates compliance. Data processing terms, privacy information, data-flow records, lawful-basis analysis, retention rules, and data protection impact assessments where required.
DCB0129 A clinical safety standard for manufacturers of health IT products. The product manufacturer and its clinical safety officer. Clinical safety case, hazard log, clinical risk management plan, and named clinical safety officer.
DCB0160 A clinical safety standard for organisations deploying and using health IT. The NHS organisation implementing the product. A local clinical safety case, hazard log, deployment controls, and evidence showing how supplier risks were reviewed.
Cyber Essentials and Cyber Essentials Plus Government-backed security schemes. Plus includes independent technical testing. The supplier maintains controls. An accredited certification body assesses certification. A current certificate, certification level, expiry date, and scope covering the service being purchased.
Medical device regulation Legal requirements that apply when the software’s intended purpose makes it a medical device. The manufacturer determines classification and meets the applicable regulatory duties. The MHRA oversees the Great Britain market. Intended-purpose statement, classification rationale, MHRA registration where required, conformity documentation, and the applicable marking evidence.

DTAC completion does not replace any separate legal, clinical safety, cybersecurity, or medical-device obligation.

Physitrack’s DTAC compliance

Physitrack is DTAC compliant and holds a current NHS Data Security and Protection Toolkit submission. Physitrack’s NHS information sets out its position for NHS organisations. This compliance gives buyers a clear supplier assurance baseline, but it does not represent central NHS approval or remove the need for local assessment.

Physitrack supports digital rehabilitation through home exercise programme delivery in PhysiApp and a library of more than 18,000 exercise videos. Clinicians can monitor adherence and patient outcomes, while telehealth supports remote appointments. Physitrack is used across NHS organisations, but one organisation’s deployment decision does not establish assurance for another.

Physitrack can provide its current DTAC evidence for local review, and NHS organisations should verify the scope and date of the supporting DSPT submission. Clinical governance leads should review the supplier’s DCB0129 documentation and complete their organisation’s DCB0160 responsibilities. Digital and information governance leads should assess technical security, data flows, accessibility, and compatibility with local systems.

Local evaluation must also consider the intended clinical pathway and patient population. Physitrack’s features may support home rehabilitation and remote follow-up, but DTAC completion alone cannot confirm clinical suitability, interoperability, legal compliance, or medical-device conformity where relevant. Each NHS organisation remains responsible for its due diligence, risk acceptance, contracting, and deployment decision.

Evaluation checklist for NHS buyers

  • Confirm the supplier’s DTAC evidence covers all five assessment areas and carries a recent review date.
  • Confirm the DSPT submission date, status, and organisation name shown in the public record.
  • Request the supplier’s DCB0129 clinical safety case, hazard log, and named clinical safety officer.
  • Establish what your organisation must produce under DCB0160 before deployment, including its local clinical safety case.
  • Review the supplier’s UK GDPR documentation, data-processing terms, retention periods, subprocessors, and international data transfers.
  • Request information that supports your data protection impact assessment and confirms the roles of controller and processor.
  • Ask for current penetration-testing evidence, vulnerability-management procedures, incident-response arrangements, and Cyber Essentials status.
  • Ask which interoperability standards and interfaces the product supports. Verify each required integration against your local technical environment.
  • Test accessibility against recognised standards and include clinicians and patients with relevant access needs in usability testing.
  • Confirm how the software records home exercise programme delivery, patient activity, clinical outcomes, and audit events.
  • Determine whether any function qualifies as a medical device. If applicable, request its MHRA registration, intended purpose, risk classification, and UKCA or other accepted conformity evidence.
  • Review hosting locations, availability commitments, backup arrangements, disaster recovery evidence, support hours, and exit provisions.
  • Check that contracts cover security incidents, data breaches, service changes, subcontractor changes, and secure data return or deletion.
  • Record who reviewed each evidence item, when they reviewed it, and any conditions attached to the deployment decision.
  • Reject unsupported claims such as “NHS approved” or “DTAC certified”. Ask the supplier to provide the dated evidence behind each claim.

Common misconceptions about DTAC status

  • Can a supplier call its software “DTAC approved”? No. NHS organisations apply DTAC during local assurance. No central NHS body grants universal approval.

  • Does DTAC completion provide certification? No. DTAC does not issue a national certificate or place suppliers on an official register. Ask who assessed the evidence, when they assessed it, and for which deployment.

  • Does DTAC completion guarantee interoperability? No. DTAC prompts buyers to assess interoperability, but each buyer must verify supported standards, interfaces, data formats, and compatibility with local systems.

  • Does DTAC completion confirm medical device conformity? No. Software that meets the legal definition of a medical device requires separate regulatory assessment. Buyers should request relevant MHRA registration, classification, and UKCA evidence where applicable.

  • Does a supplier complete DTAC once? No. Software updates, security risks, processing changes, and new clinical uses can affect the evidence. Buyers should request dated documents and reassess them throughout the contract.

  • Does DTAC replace other assurance duties? No. Buyers still need to examine UK GDPR obligations, DSPT status, clinical safety duties under DCB0129 and DCB0160, cybersecurity evidence, and local governance requirements.

Getting this right for your organisation

Run a local assurance process against your organisation’s intended use, clinical risks, technical environment, and information governance requirements. A supplier’s completed DTAC documentation can support that review, but it cannot replace your organisation’s decision.

For more detail about the platform and NHS deployment, visit Physitrack’s NHS page. Physitrack’s broader NHS digital rehabilitation procurement guide provides further guidance on supplier evaluation and implementation planning.

Your organisation remains responsible for checking current evidence, documenting its assessment, managing identified risks, and deciding whether the software is suitable for deployment.

Kevin Kaminyar
Global Head of Growth