Dental Practice IT Compliance Checklist: 2026 UK DSPT & CQC Guide
Back to Blog
Managed IT6 min read

Dental Practice IT Compliance Checklist: 2026 UK DSPT & CQC Guide

Coreitech Team
11 September 2026
#it support for dental practices uk#dental it support london#dental practice it compliance checklist uk#dspt compliance dental practices#cqc it compliance checklist dental#dental it support surrey#managed it services for dentists uk#dental practice cyber security uk
Quick Answer

Ensure your dental clinic meets NHS DSPT, CQC, and GDPR requirements with this practical 2026 UK dental practice IT and cybersecurity compliance checklist.

Why IT Compliance Is Non-Negotiable for UK Dental Practices in 2026

Running a dental practice in 2026 means navigating an increasingly complex landscape of regulatory obligations — and IT compliance sits firmly at the centre of it. Between the NHS Data Security and Protection Toolkit (DSPT), CQC inspection criteria, and evolving UK GDPR requirements, practice managers and principal dentists face genuine legal and reputational risk if their IT infrastructure isn't up to standard.

This checklist is designed to help you understand exactly where your practice needs to be — and what steps to take to get there.


Understanding the Two Key Frameworks: DSPT and CQC

NHS Data Security and Protection Toolkit (DSPT)

Any dental practice that handles NHS patient data — which includes the vast majority of NHS-contracted practices — is required to complete an annual DSPT submission. For 2025/26, NHS England expects practices to meet the "Standards Met" threshold, not simply submit an incomplete return.

— Need Expert IT Help?

Get a Free IT Consultation

Our London-based IT experts are ready to help your business. Free 30-minute consultation, no obligation.

Free 30-min consultation No obligation London-based team

The DSPT is built around ten National Data Guardian (NDG) standards, covering everything from staff training and access controls to incident reporting and system patching. Failing to achieve "Standards Met" can affect your NHS contract status and leave your practice exposed during a CQC inspection.

CQC IT Compliance Expectations

The Care Quality Commission doesn't operate a separate IT checklist, but inspectors assess whether your practice meets the Safe and Well-led key questions — and poor IT governance directly impacts both. Inspectors look for evidence of data breach procedures, staff awareness of information governance, and robust systems for protecting patient records.

In short: if your IT is chaotic, your CQC rating will reflect it.


Dental Practice IT Compliance Checklist for 2026

Use this checklist as a working reference. Each item maps to either DSPT requirements, CQC expectations, or both.

1. Data Security and Access Controls

  • [ ] Role-based access controls are in place — staff only access data relevant to their role
  • [ ] All clinical and admin systems require strong, unique passwords (minimum 12 characters)
  • [ ] Multi-factor authentication (MFA) is enabled on email, cloud platforms, and remote access tools
  • [ ] A formal leavers process exists to revoke access immediately when staff depart
  • [ ] Shared login credentials have been eliminated across all systems

2. Device and Network Security

  • [ ] All devices (PCs, laptops, tablets) have up-to-date antivirus and endpoint protection
  • [ ] Operating systems and software are patched within 14 days of critical updates being released
  • [ ] Unsupported software (e.g. Windows 10 after October 2025) has been replaced or isolated
  • [ ] Practice Wi-Fi separates clinical systems from guest/patient networks
  • [ ] Firewall rules have been reviewed in the last 12 months

3. Data Backup and Recovery

  • [ ] Patient data is backed up daily, with at least one copy stored offsite or in the cloud
  • [ ] Backups are tested regularly — not just assumed to be working
  • [ ] A documented recovery time objective (RTO) exists — how quickly can you restore operations after an incident?
  • [ ] Backup access is restricted and monitored

4. DSPT-Specific Requirements

  • [ ] Your DSPT submission is up to date and achieves "Standards Met" (not just "Approaching Standards")
  • [ ] A named Data Security Lead has been appointed within the practice
  • [ ] All staff have completed annual data security awareness training (NHS-approved)
  • [ ] A data security and protection policy is documented and accessible to staff
  • [ ] Personal data breaches are logged, and reportable breaches are submitted to the ICO within 72 hours

5. Clinical System Compliance

  • [ ] Practice management software (e.g. Dentally, SOE, Exact) is on a supported version
  • [ ] Clinical data is stored in line with NHS retention schedules
  • [ ] Access logs for clinical systems are maintained and reviewable
  • [ ] Remote access to clinical systems is only permitted via secure, approved methods (VPN or equivalent)

6. Staff Training and Awareness

  • [ ] All staff — clinical and non-clinical — receive annual cyber security awareness training
  • [ ] Phishing awareness training is included (this is the number one vector for dental practice breaches)
  • [ ] Staff know how to recognise and report a suspected data breach
  • [ ] New starters receive IT security induction before accessing any patient data

7. Incident Response

  • [ ] A written incident response plan exists and is known to relevant staff
  • [ ] Your IT support provider has a clear escalation path for security incidents
  • [ ] ICO reporting obligations are understood by your Data Security Lead
  • [ ] Post-incident reviews are documented

Common Compliance Gaps We See in Dental Practices

At Coreitech, we work with dental practices across London and Surrey, and the same issues come up repeatedly during IT audits:

  • Outdated software running on clinical systems — particularly legacy Windows installations on machines connected to patient record databases
  • No tested backup strategy — many practices assume their software vendor is handling backups, when in reality no verified copy exists
  • DSPT submissions completed in a rush — ticking boxes without the underlying controls actually being in place
  • Staff using personal devices to access patient data with no MDM (Mobile Device Management) policy
  • No formal IT support SLA — meaning that when something goes wrong, there's no guaranteed response time, which can affect CQC evidence of a "well-led" practice

Practical Steps to Get Compliant Before Your Next DSPT Deadline

1. Book an IT audit. Before you can fix problems, you need to know what they are. A structured audit against DSPT standards will give you a clear remediation roadmap.

2. Appoint your Data Security Lead. This person doesn't need to be technical, but they must understand their responsibilities under the NDG standards.

3. Review your software inventory. Identify anything unsupported or unpatched. Windows 10's end-of-life in October 2025 is particularly important — practices still running it in 2026 are carrying significant risk.

4. Formalise your backup and recovery procedures. Document them, test them, and make sure your IT provider can evidence they're working.

5. Deliver staff training now — not the week before your DSPT submission. NHS Digital expects ongoing awareness, not a last-minute tick-box exercise.


Get Expert IT Support for Your Dental Practice

Staying compliant with both DSPT and CQC IT expectations requires consistent, specialist attention — not a once-a-year scramble. Whether you're an NHS practice in central London or an independent mixed practice in Surrey, the obligations are real and the consequences of getting it wrong are significant.

If you'd like a no-obligation IT compliance review for your dental practice, contact the team at Coreitech. We provide managed IT services for dentists across the UK, with specific experience supporting practices through DSPT submissions and CQC preparation.

📞 Call us on 0203 834 9728 📧 Email: sales@coreitech.co.uk 🌐 www.coreitech.co.uk

— Managed IT Support

Need reliable IT support for your business?

Coreitech provides fully managed IT support for UK businesses — unlimited helpdesk, 24/7 monitoring, on-site engineers, and proactive security. From £25/user/month.

4.9★ rated — 112+ reviews15-min critical SLAFrom £25/user/month
— Coreitech

Need IT support for your business?

Coreitech is a London-based managed IT support company helping UK SMEs with cyber security, Microsoft 365, cloud infrastructure, and expert helpdesk support. Based at London Bridge, SE1 — serving businesses across London and the UK.

Free IT audit with no obligation. Typically takes 30–45 minutes.