Hello, and welcome to Talking digital health, a podcast by law firm Mills & Reeve, hosted by health and tech lawyers, Sophie Burton-Jones and Charlotte Lewis.
Our aim on this podcast is to discuss key topics of interest to those procuring tech in the NHS, and also those selling tech to the NHS.
I'm Sophie Burton-Jones. And I'm Charlotte Lewis, and we're your hosts for this episode.
We're delighted to be joined by Nadia Kadim, co-founder and CEO of NAQ.
Nadia, would you like to say hello?
Absolutely, thank you both, and very nice to be here.
My name is Nadia Kadim, as you said, co-founder and CEO of NAQ. And NAQ is an automated compliance platform for digital health and medtech companies alike. And we have helped over 150 organisations supply their innovative solutions to the NHS and private hospitals, by automating their compliance.
Thank you, Nadia.
In this episode of Talking digital health, we'll be talking about compliance, security and assurance and what you should be thinking about and when, if you're developing a new health tech product for the NHS market. Just to be clear, we won't be discussing medical device regulation as we're going to be covering that in a separate episode.
Nadia, you've kindly introduced yourself and said a little bit about NAQ. Do you want to talk us through some of the requirements in terms of compliance for digital health businesses?
Absolutely. So in order to work with the NHS or private health care market across the UK and across the world, really, digital health businesses must navigate several compliance requirements. And it's important to recognise that these requirements can vary depending on the specific type of service or product being offered by this organisation. So first, we've got UK GDPR. And the UK GDPR is applicable to any type of organisation, no matter if you operate in health, or defence, or finance, or whatever it is, everybody must comply with the UK GDPR.
Now, this piece of legislation ensures that personal and sensitive health data is protected. And it becomes more and more important the more you handle sensitive information, such as patient information.
For those working with the NHS, they will also need to complete the NHS Data Security and Protection Toolkit, or DSPT, every year. And compliance with the toolkit is actually essential as it demonstrates that your organisation manages data safely and securely. And it's a culmination and combination of UK GDPR, but also Cyber Essentials, which some of your listeners may have heard of. And it comes together in this Data Protection and Security Toolkit.
Then we've also got the DTAC, the Digital Technology Assessment Criteria, which the NHS uses to assess digital health solutions for five topics, clinical safety, data protection, again, interoperability, technical security, and usability. And meeting the DTAC is required for any digital health solution used across the NHS if the solution or organisation doesn't have a clinical component.
The clinical safety element of DTAC is foregone, but the other four elements always stand for any digital health solution. And then finally, if the use of your digital health product could introduce clinical risk to its users, such as apps which aid in clinical decision-making, you'll need to meet compliance with the clinical safety standard, which is DCB0129, which is that clinical safety element of the DTAC that I just mentioned. But of course, there's also private sector compliance requirements. So everything that we just discussed is very specific to the NHS, but a lot of your digital health innovators and medical innovators in the UK might also be looking to enter the private market.
Their ISO standards are very important. You've got ISO 27001, which is often required to demonstrate strong information security management. But you've also got other ISO standards like ISO 9001, which is all about quality, ISO 3485, which is quality for medical devices, which again we won't cover in this podcast. But it's essential to note that many private providers also supply to the NHS. So in addition to these ISO standards, they might also expect you to meet standards like the NHS DSPT, which we discussed, and the DTAC to maintain parity with the NHS requirements, because it's their responsibility to ensure that their suppliers are compliant with the requirements that they need to comply with.
The whole supply chain issue, really.
Exactly, exactly, which we love.
It seems like there's quite a lot going on there. It's quite complex.
So what is a typical timeline, do you think, for sort of going through all of that compliance process?
Yeah, the typical timeline is very difficult to pinpoint for these different compliance processes just because they can vary significantly based on a number of factors like the complexity of the product or service, but also the standard which we're trying to comply with and demonstrate with and the specific legal regulations that apply. So generally, it can take anywhere from a number of weeks to several months. And it also depends, of course, on the capacity of the organisation undergoing all of these compliance changes and processes. processes.
So, for example, DSPT, which we mentioned previously, is a combination of UK GDPR compliance, compliance with cyber essentials, and then a number of additional controls, as we call them, which can be quite similar to ISO 27001.
Now, achieving cyber essentials can often be completed in just a few weeks, a couple of weeks, if your systems are already well configured.
For UK GDPR, getting your data protection policies and processes in place, if you do it all yourself, typically takes around four to six weeks.
Also, again, depending on your organisation's size and complexity, but also, of course, how much knowledge you already have in-house in order to write those policies and know what to do and where to start.
Now, of course, if you've got help from a lawyer or a consultant or a platform, obviously, that can speed up a little bit.
The DSPT self-assessment, because DSPT is a self-assessment that you do once a year, and getting ready for that DSPT assessment, can take about four to eight weeks, especially if it's your first time.
Whereas DTAC and then DCB0129 compliance, so that clinical safety aspect that I mentioned, that can take a bit longer, particularly where clinical safety is involved. because you'll need to appoint a clinical safety officer, you'll need to develop clinical safety documentation, and that clinical safety officer needs to be involved in the whole process, approving or denying certain changes in policies and risks and hazards, as we call them. And then you kind of go into that circle of denial and approval, which can take a little bit of time.
Now, ISO 27001, to continue in our spiel, involves, of course, setting up a comprehensive information security management system, or an ISMS, as it's often referred to. And that not only just takes a lot of time because it's all about implementing the measures prescribed by ISO 27001, but you mostly also need time to generate and collect evidence. And so we often say for larger organisation, it takes about 6 to 9 months.
For smaller organisations, you can do it a lot faster, but it also depends on the scope of your certification. So, I think I've been able to set out the time it can take, but it's highly dependent on your product, the complexity, and of course, also your deadlines, because what we often see that our customers are undergoing procurement at a certain NHS organisation, for instance, there is just a hard deadline. And if there's a hard deadline, you'll run a bit faster. But across the board, no matter what compliance requirement you're trying to go through, and what kind of compliance you need, start early.
Starting your compliance journey early is just the key. Because if you begin this process later, for instance, after developing your solution, you may need to change your documentation or you may need to change your product based on the compliance requirements, so you may face delays and revisiting and reworking aspects of your product and compliance posture just takes time, which costs money. And although starting from scratch might initially feel like it's kind of slowing you down because you kind of feel like you're navigating this red tape when all you want to do is innovate and build and go to market as soon as possible, it definitely will be worth it in the end. And I think it's also, if we think about time and timelines and how long does it take, it's also important to note and to remember always that compliance isn't a one-time thing.
It isn't a one and done deal. It isn't a tick box exercise.
Once you've met the initial requirements, it's always an ongoing process. So, I already mentioned DSPT and then Cyber Essentials are annual. ISA 27001 requires an annual audit, both internal and external. GDPR requires continuous updates, staff training, regular audits. And DTAC and then the DCB0129 requires updates whenever anything in your product changes.
Or, for instance, if the context in which you've sold it to an NHS organisation changes. So, I might be selling online pharmacy, which is one product, to the NHS. And I might be selling it for a certain medicine. If I'm selling Viagra, the hazards are completely different than when I'm selling cancer medication. If there are delays in delivery of the medication for Viagra, somebody might have a calm evening. Whereas if I'm late in delivering my medication for cancer treatment, that has potential life-threatening effects, right? So that sort of elements and understanding of the risks and the hazards is essential in your contextual, in the context. And so, whatever you sell and whoever you sell it to might require changes in your DTAC documentation as well.
Thanks, Nadia.
I mean, I think that point you made very well, which is, you know, you want to be doing this as early as possible and ideally actually at the outset and along your development journey, because then you know that you're sort of compliant by design as opposed to adding it on a layer at the top, over the top later on. which, if it raises issues, is going to cause further delays anyway.
Are there typical areas where you see common gaps or issues in compliance? And I think, I guess, are there things that you can suggest now that people want to be thinking about and be aware of as they are developing their products or even if they've developed them already?
Absolutely.
I mean, look, compliance is nobody's favourite topic except maybe ours, Charlotte and Sophie.
I mean, I could talk about this all day long, but I do really understand that if you're an innovator and you're building an innovation that you're hoping will save patient lives or help clinicians make decisions or make the NHS more efficient and eliminate waiting times, look, you've got other things on your mind you want to build. But I think the most common gap to start with, and I've got a few, is just the understanding that this is essential, this is not elective, this is not something that you can just, you can half do.
You're going to have to put time and resource behind it.
Yeah, I think that's really important for innovators to understand whether they've already built their product. like we mentioned, the compliance requirements are ongoing or you're new to this and you're starting from scratch, you're going to want to take compliance into account as early as possible. So that's the first one.
I think around GDPR compliance, there's often misunderstanding of the applicability of GDPR. of the requirements, and if we're being honest, the follow-up from the government, which is actually the same in both the UK and the EU, is just minimal, right? So the sort of push to be GDPR compliant is more commercial than legal, and I think that just means that organisations don't do the GDPR implementation as well as they should.
An example is data protection impact assessments. These are essential in supplying to the NHS. They will require you to send your DPIA in. There will be a team reviewing it. There will be back and forth, and many companies just skip this step or just don't do it effectively. I think it's crucial to understand why a DPIA is important because it helps you understand and then of course mitigate the risks associated from a personal data perspective with your product. And we often find that the assessments are either too superficial, or they just don't adequately demonstrate how risks have been mitigated. So, I think that's a crucial step to take into account. And then for those needing DCB0129 compliance, so the clinical risk management element of DTAC, which, and by the way, it's also standalone, but clinical risk management, Common Gap is building out the hazard log. The hazard log, again, is not just a tick box exercise to say we've done a risk assessment. It really helps you understand how you can make your product better suited to reach your goals. It can be an essential part of your organisation, of your commercialisation, and not just limited to your compliance.
It requires a detailed assessment of the hazards or risks associated with your technology. And again, documenting the clear mitigation strategies that you've identified. And I think many companies struggle to effectively assess these risks, which then comes to the clinical safety officer that needs to sign off on them, then they'll have to go back and redo the work that they've already done. So, it's important to, from an early starting point, really sit down and take time for your hazard blog and really think about it in a way what we want to do, which is essentially improve patient outcomes, whether it's saving lives or minimising wait times, et cetera, and it's critical for NHS acceptance. And then I think the last two big issues, the first one being continuity. So organisations, because it's nobody's favourite topic, people really think, okay, done, done, done, check, and now I don't have to think about it anymore. And that is just not the case.
I mean, some of these audits and assessments happen annually, right? So that's already a clear example of it being ongoing.
What we're trying to do is protect people, protect our organisation, and that really should just be part of an ongoing strategy of your business as a whole. So, I think meeting the requirements in one year, if you then stop doing anything about it, means you're not complying anymore the next day, the next week, the next month. So it's important to, on an ongoing basis, have meetings, think about this, carry out risk assessments, ensure that your team is trained just to keep on top of things. and cybersecurity.
When we're talking about compliance in the digital health space, I think cybersecurity is often overlooked or misunderstood rather. And maybe that's actually the issue.
The issue is not people don't want to think about it, but they just don't know how to think about it or how to implement it. And it's especially an area where gaps appear when it comes to supplier due diligence, which we mentioned in the beginning, because many digital health companies overlook their responsibility to also ensure that their suppliers are compliant and secure and protect patient data and protect data in general. So if a breach occurs within your supply chain, for instance, and it involves your customer's data, then you are still held accountable. It's crucial not only to maintain your own cybersecurity posture and compliance in that sense but also ensure that your suppliers do the same because the whole supply chain trickles down from the NHS. And so it's a bit of a challenge, especially when you don't quite know what to do, where to start when we're talking about cyber security, but cyber essential is one of the requirements for the NHS and helps you with that. Making sure that you actually take that seriously, I think is essential.
Thanks, Nadia. And I think we've obviously talking about it from the perspective of being able to sell, but I guess it's also worth thinking about it from an investment point of view that if you're looking for investment, there will be due diligence done on you in that context as well. And if you can't show that you've gone through these processes, you might not have all of the answers and everything in place, but if you haven't addressed it or considered it at all, that's going to raise some real red flags.
Exactly.
I mean, I remember from our latest funding round, the due diligence was quite extensive. And what they're looking for is not to catch you out, but to gain some confidence and some comfort around.
The fact that you're thinking about these things, that you're planning around these things, that you may not have everything in place just yet, but you have an understanding of what you will need in order to put the right things in place for your compliance, which is license to operate. And so, yeah, I was actually quite pleasantly surprised by the due diligence process because it actually enabled us to identify the gaps, which were super helpful in all of these areas.
For us, a little bit less on compliance, of course, but maybe a little bit more on the finance side of things or whatever have been. But absolutely, it's very important to think about your compliance, not only for your commercialisation, but also for your investment.
Right. And then I guess a final question from us really, talking about all of that. How can that support digital health businesses with their compliance and all of these considerations that you've been talking through?
We're super passionate about enabling these digital health businesses to operate, to exist, to grow, to make their necessary investments, and then have a return on that investment by selling that NHS deal or the private hospital deal. And we do that by taking the guesswork out of compliance, so we try to make it cheaper, faster, and easier to meet critical standards like GDPR, DSPT, Cyber Essentials, DTAC, DCB0129, and all of the ISO standards that I mentioned. And we know that for many small digital health innovators, compliance can really feel really confusing, complex, and overwhelming, especially when you don't have the time, money, or dedicated staff to navigate it all. And often, our customers, companies just want to make sure that they're doing the right thing, but they just don't know when to start. So, we have a platform, and our platform guides you step-by-step through exactly what you need to do, automating certain elements of the compliance journey, such as the creation of essential documents, policies, risk assessments. And this approach saves digital health innovators over 200 hours of work each year and 10s of thousands of pounds in compliance fees compared to, of course, hiring consultants or doing it yourself. And because you're spending less time on compliance, it's also much more cost effective, freeing up resources to focus on growing the business. And because compliance isn't just about ticking boxes once, which we've established many times, it's about maintaining those standards continuously. Our platform, NAQ, monitors your compliance status, updates the policies, ensures you're always aligned with the latest regulatory changes, which also means you're never sort of scrambling those few months before the deadline, getting that frantic rush to get everything in place. And we don't just verify compliance or mark your homework, or we're not just an assessment tool.
We actively help you achieve that compliance, getting you ready for an external audit, your procurement process. In summation, we've already helped out over 150 customers save thousands and then hundreds of hours on their compliance efforts by making compliance just straightforward, manageable, and predictable.
Thanks, Nadia. That's extremely helpful. I think you've outlined how complex an area this is, but also how crucial it is. And actually then, obviously, NAQ, you're supporting both of those drivers by making it a little bit more straightforward, easy and also an ongoing process for businesses. So, I'm sure that's going to be extremely helpful for any digital health businesses that are listening and I'm sure gives a level of assurance to NHS organisations who are procuring as well and to know that you guys are on board.
If anyone listening would like to know more about NAQ and how NAQ can support you in your compliance journey, then please do contact Nadia and her team via their website, naqcyber.com.
At Mills & Reeve, we're also very happy to discuss the legal side of the compliance journey as well in relation to health tech.
I mean, Nadia, you talked about data protection, GDPR. We do an awful lot of work on these. And like you said, it's the kind of understanding what is actually happening and how to give the confidence to people when they're going out and selling their product that they are totally on top of this and they understand what the impact is for clients. So, we can help with that as well. well. and our individual contact details are available on our website at mills-reeve.com.
Thank you everyone for joining us for this episode of Talking digital health brought to you by law firm Mills & Reeve.