Healthcare estates are the hardest kind to scope honestly: shared workstations with generic ward logins, clinical systems whose vendors control patch cycles, medical devices running embedded operating systems, and staff accessing rotas or results from personal phones. The scheme can accommodate all of this, but only with deliberate scoping decisions made up front.
The workable pattern is usually: bring the standard IT estate (staff devices, email, cloud services, network boundary) fully up to the five controls; segregate genuinely unpatchable clinical systems and medical devices onto controlled network segments so they sit outside the certification boundary; and eliminate shared or generic logins wherever a system supports individual accounts. Under the 2026 rules, MFA on cloud services holding patient data, email, rostering, care-planning platforms, is non-negotiable.
Certification will not fix every legacy constraint in a clinical environment, but it draws a defensible security boundary around what can be controlled, and evidences it independently.
Health data commands premium prices in criminal markets and cannot be reissued like a card number, and ransomware against care settings creates patient-safety consequences no other sector faces. Regulators, commissioners and the ICO all treat health data incidents with corresponding severity.
Most incidents affecting healthcare organisations still begin with the basics: a phished mailbox without MFA, an unpatched internet-facing system, a shared login nobody can attribute. These are precisely the failures the five controls, enforced annually, are designed to remove.
Each gap is a documented root cause in real UK healthcare incidents. The certification process puts them on a deadline with independent verification at the end.
Register your interest for a readiness review that respects clinical constraints. We’ll contact you the day our certification service goes live.