Standards decision brief | 17 September 2026
Prepared in response to Cain's question in viewee-hq #product: "We should align to NHS digital standards - believe there was a recent requirement for all products in this space to have set fields, etc. Believe this will cover future APIs should we need to."
Part 1 is regulatory fact with sources. Part 2 is recommendation. Related docs: "Certifications: ISO 27001, Cyber Essentials Plus and NHS assurance" and "DRAFT - Viewee DSPT Preparation Plan" (same folder).
Bottom line
Cain's claim checks out in a specific, narrower form than stated. There is a recent "set fields" requirement: the Adult Social Care Minimum Operational Data Standard (MODS, DAPB4102), a defined set of data fields that suppliers of Digital Social Care Record (DSCR) systems on the NHS England assured solutions list must implement by 1 July 2026. It applies to care record systems, not to feedback products. Nothing requires Viewee, a feedback and improvement tool, to implement a mandated field set today, and no field standard exists for feedback tools.
The direction of travel Cain senses is real. The Health and Care Act 2022 made mandatory information standards binding on private care providers, and the Data (Use and Access) Act 2025 (Schedule 15, in force 5 February 2026) now lets government publish information standards that bind IT suppliers directly, covering functionality, interoperability, portability, storage and security, with compliance notices and public censure as enforcement. No such standard has yet been designated that would reach a feedback tool.
The standards that do apply to Viewee in practice are DTAC (procurement gateway, current form since February 2026), DSPT (required in practice), WCAG 2.2 AA accessibility, and a documented DCB0129 clinical safety applicability decision. DCB0129/0160 itself is almost certainly out of scope because Viewee does not influence near-real-time direct care.
Recommendation: align the product data model to MODS field definitions and CQC quality statements now. Use typed CQC location IDs and ODS codes, proportionate About Me-style person fields, stable record IDs, ISO 8601 timestamps, and versioned quality-statement mappings on feedback and actions. This is voluntary product-model alignment for future optionality, not a claim that MODS legally applies to Viewee's current feedback product. Defer formal MODS/PRSB conformance, a FHIR server and NHS API onboarding until a DSCR integration, NHS procurement or designated standard creates a concrete route.
Part 1: Regulatory facts
1. The "set fields" claim, verified
What it most plausibly refers to: MODS. The Adult Social Care Digital Social Care Record: Minimum Operational Data Standard (MODS), reference DAPB4102 Amd 66/2023, is published under section 250 of the Health and Social Care Act 2012. It defines "the data that is recorded and used by CQC-regulated adult social care service providers using or creating a Digital Social Care Record": a standard set of data items and definitions so every care system labels and formats care information the same way. Key facts:
Applies to: CQC-registered adult social care providers and the suppliers of their Digital Social Care Record systems. A DSCR is a care planning and delivery record (care plans, daily notes, medication, risk assessments, incidents). Viewee is not a DSCR.
Mandatory status: mandatory for suppliers on, or intending to remain on, the NHS England DSCR Assured Solutions List. It is a contractual requirement for those suppliers, with an effective compliance date of 1 July 2026. For everyone else, adoption is the sector's ambition, not a legal duty.
It ships with FHIR profiles and implementation guidance, which is the part relevant to Cain's API point.
Post-implementation review is dated 31 August 2026, so the standard may be revised soon.
The wider legal machinery (probably why Cain heard "recent requirement"):
The Health and Care Act 2022 amended section 250 of the Health and Social Care Act 2012 so that both public and private health and adult social care providers have a statutory duty to comply with any mandatory information standard that applies to them, with monitoring and enforcement powers.
The Data (Use and Access) Act 2025, section 121 and Schedule 15, in force 5 February 2026, extended the same framework to IT suppliers. A "relevant IT provider" (anyone marketing or supplying IT or IT services used in health or adult social care in England, which would include Viewee) can now be made subject to information standards about functionality, connectivity, interoperability, portability, storage of and access to information, and security. Enforcement includes compliance notices (new s251ZB), public censure (s251ZC), and a possible accreditation scheme. As of September 2026, no standard under these powers has been designated that covers feedback or experience tools.
What the claim gets wrong: there is no requirement for "all products in this space" to have set fields. The requirement is real but scoped to DSCR care record systems on the assured list. A feedback platform sits outside MODS entirely.
On "this will cover future APIs": partially true. Aligning the data model to national standards now is exactly what keeps future NHS and care-system integration open, and MODS alignment would matter if Viewee ever integrates with DSCR products. But API assurance in the NHS is route-specific (a named integration, programme or procurement), so no field set bought today is a blanket API pass. See the certifications brief for the assurance routes.
2. Standards-by-standard verdict for a feedback product
| Standard | What it is | Does it apply to Viewee? |
|---|---|---|
| DTAC (Digital Technology Assessment Criteria) | NHS England's assessment framework for digital health technology: clinical safety, data protection, technical security, interoperability, usability and accessibility. Used by buyers at procurement; not a statutory instrument. | Yes, in practice. Expect it from NHS, ICB and local authority buyers, and increasingly from large care groups. New shorter form published February 2026; the old form is rejected from 6 April 2026. |
| DSPT (Data Security and Protection Toolkit) | Annual organisational data security self-assessment, CAF-aligned since v8. | Yes, in practice. Not legally forced on Viewee today (no NHS patient data), but expected in procurement. See the existing DSPT analysis and preparation plan. |
| DCB0129 / DCB0160 (clinical risk management) | Clinical safety standards for manufacturers (0129) and deployers (0160) of health IT. Information standards under s250. | Almost certainly out of scope. The NHS applicability decision tree scopes these to products that support health or social care services and influence near-real-time direct care of individuals. Population-level and quality-improvement tools are explicitly out of scope. Viewee collects feedback and drives service improvement; it does not influence an individual's care in real time. Caveat: DTAC section C1 requires a written rationale when a supplier judges DCB0129 not applicable, and the deploying organisation makes its own DCB0160 call. |
| WCAG 2.2 AA accessibility | Web accessibility standard. Public sector buyers carry their own accessibility duties; DTAC section D1 expects WCAG 2.2 AA evidence and consideration of the Accessible Information Standard. | Yes, via DTAC and buyer expectations. Viewee's existing WCAG 2.2 AA audit work (in this folder) is the right evidence base. |
| MODS (DAPB4102) | Set fields for Digital Social Care Records; mandatory for assured-list DSCR suppliers by 1 July 2026. | No. Viewee is not a DSCR. Worth monitoring because future DSCR integrations will speak this language. |
| PRSB standards (About Me, Personalised Care and Support Plan, Core Information Standard) | Standardised record content for person-centred care information. PRSB is the assurance body for the About Me and care plan capabilities on the DSCR assured list. | Not directly. No PRSB standard covers feedback tools. About Me is a useful free reference for person fields (communication needs, preferences) if Viewee ever links feedback to residents. |
| DUAA 2025 IT supplier standards | New power (in force 5 Feb 2026) to publish mandatory standards binding IT suppliers directly. | Nothing designated yet for this product category. This is the channel through which a future "set fields" rule could legally reach Viewee, so it is the thing to watch. |
| FHIR / HL7 UK Core (R4) | The NHS interoperability standard family; UK Core profiles unify health data exchange across the four nations. NHS APIs are built on it. | No obligation. It is the right alignment target for any future API work. |
| Standard identifiers (NHS number, ODS codes, CQC location IDs) | NHS number for people; ODS codes for health and care organisations; CQC location ID for registered services. | No obligation. DTAC's interoperability section asks about NHS number handling (with a proper verification method) where products use it. |
3. Notes on scope calls
DCB0129 rationale needs writing down even when the answer is "no". The applicability test: is the product publicly funded or deployed in publicly commissioned care (likely yes for some Viewee customers), does it support care services (arguable), and does it influence real-time or near-real-time direct care of an individual (no for a feedback tool). Document this with the intended-use statement; if Viewee ever adds features that trigger care interventions on individuals (for example, alerting that routes straight into care delivery decisions), revisit.
Medical device check. A feedback tool is not a medical device; keep the intended-use statement clear that Viewee supports quality improvement and does not diagnose, treat or make care decisions about individuals.
DTAC is assessed per product by the buyer. There is no central submission. The output is an evidence pack reused across procurements, which is why maintaining it once, centrally, pays off.
Part 2: Recommendations
4. Adopt in the data model now (low cost, keeps every route open)
Standard identifiers as first-class fields, not free text: CQC location ID for each home/service; ODS code where the customer has one; NHS number as an optional, format-validated resident field (add verification only when an integration demands it). These three fields alone make future joins to DSCRs and NHS systems cheap.
Person fields shaped like the national pattern: name, preferred name, date of birth, communication needs and preferences, accessibility needs (the Accessible Information Standard categories). Mirrors PRSB About Me so any future resident-level integration maps cleanly.
Structured records, not documents: every feedback item, theme, action and outcome as a structured record with stable IDs, ISO 8601 timestamps, status enums and a respondent-type field (resident / family / staff). This is the same discipline MODS imposes on DSCRs, applied to Viewee's own domain, and it maps naturally to FHIR resources later (QuestionnaireResponse for feedback, Task for actions, Location for services).
A documented read API in GDS style: REST + JSON, documented and versioned, matching what DTAC section C4 asks about (open APIs, reasonable third-party access). Design the resources so they can be expressed as FHIR R4 UK Core profiles later, but do not build a FHIR server now.
Full export per provider: complete data export in open formats (CSV/JSON). Cheap to build, expected by buyers, and aligned with the portability direction in the DUAA powers.
Feedback taxonomy kept mappable: keep theme codes in a maintained list that can be re-mapped to CQC quality statements and to MODS/DSCR vocabularies if integrations appear.
5. Document (evidence that pays off at procurement)
Build the DTAC evidence pack on the current (February 2026) form: C1 with the written DCB0129 non-applicability rationale and intended-use statement; C2 from the DSPT work and DPIA; C3 from Cyber Essentials, pen test and security docs; C4 covering the API documentation and identifier handling; D1 with the WCAG 2.2 AA audit and an Accessible Information Standard statement.
One-page standards position for sales: Viewee is not a DSCR and MODS does not apply; Viewee uses standard identifiers (CQC location ID, ODS, optional NHS number), aligns person fields with About Me, and offers documented APIs and full export. This pre-empts the exact question Cain raised when customers ask it.
Keep the clinical safety applicability decision and intended-use statement versioned with the product, and re-run both when scope changes.
6. Defer (real triggers only)
Formal MODS and PRSB conformance assessment: align the Viewee product model now to MODS fields and CQC quality statements, but pursue formal conformance only if Viewee builds DSCR-like care recording or a DSCR integration/procurement makes assurance necessary.
FHIR server, NHS login, PDS integration: only when a named NHS integration or procurement requires it.
NHS England API/service assurance onboarding: route-specific, needs a concrete integration target.
Watch list: first IT-supplier standards designated under the DUAA Schedule 15 powers (the channel a future mandatory field set would arrive through); the MODS post-implementation review (dated 31 August 2026); DTAC updates; the DSCR standards roadmap.
Sources
Official and primary
NHS Standards Directory, Adult Social Care DSCR Minimum Operational Data Standard (DAPB4102 Amd 66/2023): https://standards.nhs.uk/published-standards/adult-social-care-digital-social-care-record-minimum-operational-data-standard-mods
Digitising Social Care, MODS (publication, 1 July 2026 supplier obligation): https://beta.digitisingsocialcare.co.uk/data-standards-social-care/minimum-operational-data-standard-mods
Digitising Social Care, MODS FAQs: https://beta.digitisingsocialcare.co.uk/frequently-asked-questions-mods
NHS England, assured solutions for digital social care records: https://adultsocialcare.standards.nhs.uk/assured-solutions
NHS England, legislative changes and mandatory information standards (Health and Care Act 2022 duties on providers): https://digital.nhs.uk/data-and-information/information-standards/governance/legislative-changes-and-mandatory-information-standards
Health and Social Care Act 2012, section 250: https://www.legislation.gov.uk/ukpga/2012/7/section/250
Data (Use and Access) Act 2025, section 121 and Schedule 15 (IT supplier standards, in force 5 February 2026): https://www.legislation.gov.uk/ukpga/2025/18/section/121 and https://www.legislation.gov.uk/ukpga/2025/18/schedule/15
NHS England, DTAC guidance for buyers and suppliers (new form February 2026, old form unusable from 6 April 2026): https://transform.england.nhs.uk/key-tools-and-info/digital-technology-assessment-criteria-dtac/
AI and Digital Regulations Service, using the DTAC: https://www.digitalregulations.innovation.nhs.uk/regulations-and-guidance-for-developers/all-developers-guidance/using-the-digital-technology-assessment-criteria-dtac/
DTAC criteria, published v1.0 copy (structure of C1-C4 and D1; superseded by the current form): https://concentric.health/assets/img/resources/nhsx-dtac.pdf
NHS England, applicability of DCB0129 and DCB0160, step-by-step guidance: https://digital.nhs.uk/services/clinical-safety/applicability-of-dcb-0129-and-dcb-0160/step-by-step-guidance
PRSB, digitising adult social care with standards (About Me and Personalised Care and Support Plan conformance on the assured list): https://theprsb.org/standards/digitisingadultsocialcarewithstandards/
PRSB, About Me standard: https://theprsb.org/standards/aboutme/
NHS England, FHIR UK Core API standards: https://digital.nhs.uk/developer/api-catalogue/fhir-uk-core-standards
NHS England, Organisation Data Service (ODS codes): https://digital.nhs.uk/services/organisation-data-service
Secondary (compliance vendor, used to corroborate the DTAC V2 changes)
Naq, DTAC V2 for NHS Suppliers: the 2026 compliance guide: https://www.naqcyber.com/blog/dtac-v2-nhs-suppliers-2026-compliance-guide
Standards, forms and deadlines change. Confirm the current DTAC form, MODS status and any new DUAA designations before making public claims or commitments.
