Hello and welcome to Talking digital health, a podcast by law firm Mills & Reeve, hosted by health and tech lawyers Sophie Burton-Jones and Charlotte Lewis.
Our aim on this podcast is to discuss key topics of interest to those procuring tech in the NHS and also those selling tech to the NHS.
I'm Sophie Burton-Jones. And I'm Charlotte Lewis, and we're your hosts for this episode.
In this episode of Talking digital health, we'll be talking about getting your standard terms ready and compliant with the UK regulatory landscape when you're developing a new health tech product for the NHS market.
As you might expect, there's always some tension between what suppliers and customers expect to have in their contractual terms. When a supplier is trying to break into the NHS or the wider public sector, this can be heightened because NHS customers expect to see various compliance commitments and what we'd call good supplier terms. They're typically more detailed than you'd see in the private sector and which in our experience can catch people out.
So, Charlotte, what in your view are the key contractual provisions NHS organisations would expect to see in a supplier's standard terms?
As you've said, Sophie, NHS customers and the wider public sector, for that matter, will expect to see certain terms in contracts. And in some cases, internal governance processes will mean that such customers will not even sign contracts unless those terms are included.
Some terms are mandatory, but the sorts of non-mandatory terms that they would expect to cover include things like reference to freedom of information, modern slavery, human rights and equality, health and safety law, environmental law and social value.
There's quite a lot there which people may or may not be familiar with.
I think it's fair to say that when we list all of those, there's also a scale of how long or short provisions for each of those could be as well. For example, we could see a Freedom of Information clause it's only about three sentences, but equally we can see one that half a page, a page long.
There's quite a lot of difference there, isn't there, for people to navigate?
Yeah, there is. And actually, most of those clauses are what a lot of people would describe as boilerplate clauses. So you're right, you can cover it in a number of ways. And the extent to which you do that in a greater or lesser amount of detail will largely depend upon the individual circumstances. But I think there's an expectation from NHS customers that there is at least reference to those things.
You acknowledge that they're all things that your customers are required to comply with. And you've also mentioned that some of the provisions, not those ones listed above, but some others are mandatory contracts. What would you say those are?
Yeah, that's right. So depending again on the circumstances, you might need to include terms covering, for example, data protection, if you're processing personal data, and the fact that a breach of procurement rule is a right to terminate the contract, that's required if there's been a procurement process.
In almost all cases, there would need to be a reference to the Bribery Act. And if applicable to the product or service that you're providing, you'll also need to include reference to compliance with clinical safety standards and potentially software as a medical device terms. And although some of these things look quite scary on the face of it, if you're a supplier doing, you know, getting your processes and procedures in place for going to market, hopefully you'll have the answers to quite a lot of these things already that you can build into your terms. So, for example, data protection, you should know what's the status of data, how is it being processed, who's got access to it, and that would help you build the terms as well. So it's not like you're totally in the talk about what you're supposed to be doing with those terms.
Yeah, I think that's right.
I think a lot of these things, whilst it does sound like a long list, as I said earlier, lots of them are boilerplate provisions, or if they're not, they're quite operational, although they've got a legal basis. So if you know what you're doing and you've done the groundwork in terms of compliance, which you should be doing, then you'll know the answers to a lot of these points and really the document is just that it's documenting what you've already got in place operationally. Ones we've been talking about so far are general good supplier, good conduct types of provisions.
Are there any other provisions specifically for digital or tech providers that you normally expect to include in standard terms?
Yeah, there are quite a few actually. It's a relatively long list and not all will apply.
It obviously depends very much on the circumstances, but some examples of provisions that you might want to include or might be expected to include by your customers will include reference to the Network and Information Systems Regulations, DTAC, reference to codes of practice that might be applicable. So for example, the Supplier Code of Conduct, the Technology Code of Practice and the Public Services Network Code of Practice.
You might also want or need to include data and cybersecurity, which includes compliance with minimum standards. interoperability and data standards and also provisions covering business continuity and disaster recovery.
The NHS does have a website for technology suppliers which has some more guidance. And I think it's fair to say it's a good idea to keep checking in on that periodically because things are changing all of the time and the central standards and requirements are not standing still as you might expect as technology advances.
Yeah, absolutely.
You mentioned in there somewhere data and cyber security and we know they're of huge concern to NHS buyers, particularly because some of the incidents that have happened in the in recent years.
What minimum standards are you seeing buyers expecting to have referred to in their contracts?
Yeah, I mean, you're absolutely right. And certainly we see regularly that these are things that customers and clients are expecting to see in contracts. So I think it's important to have this set out in your standard terms. So as a minimum, NHS buyers are expecting suppliers to obviously be GDPR compliant, which we've also talked about earlier. to be cyber essential certified or ISO 27001 certified, to align with the NCSC cloud security principles, to comply with the NHS policies on public cloud first and internet first. And it's also usual for suppliers to have a security management plan and an information security management system in place.
Great.
Yeah, that's a lot of stuff to keep on. And as above, really, a lot of the information about this is available online to look into in more detail. So yeah, and sometimes there's overlap as well. So if you are Cyber Essentials certified, for example, that might cover a number of other things already in those lists.
Great. And you've mentioned that some are mandatory, some are non-mandatory provisions.
We know that startups and smaller companies have tight budgets and they have to be careful about what they want to spend their money on, and they might not necessarily want that to be on legal terms that aren't strictly required. What's your view on that and how to approach that?
Yeah, I think that's a fair comment. And what I would say is that when starting out, it is important to allocate budget to get the foundations in place. And I would say that a good set of standard terms is one of those foundations, obviously, that you can then build on.
Time and again, we see businesses further down the line who are trying to unpick contractual relationships that they were entered into in the early stages on unsuitable terms. And so addressing those points upfront does save money in the long run.
Having terms that reflect your market also demonstrates to customers that you understand the NHS market. So it could actually be a competitive advantage to have terms that reflect your customer marketplace. And what I would say is that undoubtedly, it would build trust and confidence with your customers as well, because you've demonstrated that understanding of their world.
Yeah, as you said, time and time again, where actually not spending the money up front, even though it's difficult and it's a stretch, can lead to more costs later down the line where you're having to get lawyers involved in negotiating or looking at contractual terms and saying, what have we actually entered into and what can and can't we do with this? Because now we're having an argument about it. And I think it's also fair to say that a good law firm should be talking to you about what your budget is and what feasibly you can do within that budget, rather than saying here's a Rolls Royce, we could do everything, it's going to cost you one million pounds. Obviously, that's a ridiculous figure. But you know, being realistic and having those open conversations about what is and isn't doable with your budget is always a good discussion to be having.
Yeah, and I think that in the same way that we're suggesting that if you have a set of standard terms that reflects your customer's world, then the NHS market. I also think it's important that people engage advisors who understand the world in which they're operating, because we can tell you which things are mandatory, which things are not mandatory but recommended, and actually work with you on a scale of what's going to be the most important or what can be covered in less words as we were talking about earlier. But knowing all of that means that we can do that in the most cost effective way possible. Whereas if you go to someone who doesn't know the marketplace, then you're either going to get a very light contract that doesn't have any of the stuff in it that is really needed, or you're going to have something that is completely belts and braces, covers everything, but it costs a lot more money. So that would be my top tip. But we would say that, wouldn't we?
Yeah, we would.
Although we are genuinely there trying to make the best situation possible for our clients. And I think it's worth saying as well that there are lots of public sector and NHS frameworks out there, which quite a few of them have the terms that you'd have to sign up to published and publicly available on their websites. And not saying that that might be the best starting point for you as a supplier to the NHS, but it is worth having a look at those to get yourself familiar with some of those types of terms and seeing what the difference is between your ideal, which may be a five page contract and what is typical on those frameworks to give you an idea of what we're talking about here.
Yeah, absolutely.
It would be that would be a really good suggestion.
Great place to start and do some homework on understanding the importance of having these things in place, because you'll be expected to sign up to them on frameworks anyway. And we'll deal with that in a different episode, I think.
That's a whole other topic to talk about.
Well, thanks very much, Charlotte, for answering the question today. And at Mills & Reeve we're very happy to discuss any legal queries you might have about health tech, including on drafting or negotiating standard terms.
Both of our individual contact details are available on our website at mills-reeve.com.
Thanks for joining this episode of Talking digital health by law firm Mills & Reeve.