Skip to content

DSPT Business Continuity: Meeting Standard 7 for Small Healthcare Providers

By Brian CrockerLast reviewed: 18 August 2026

Standard 7 of the DSPT — Continuity Planning — is one of the standards where small providers most often have a coverage gap. Not because their recovery procedures are bad, but because they've never written them down.

For a small care home, pharmacy, or dental practice, the business continuity plan doesn't need to be a 50-page ITIL-compliant document. It needs to answer the question: "If our systems went down at 9am on a Monday, what would we do?" If your staff could answer that question and you have a written record of the procedure, you have the foundation of Standard 7 compliance.

What the DSPT requires

Standard 7 requires:

  1. A written business continuity plan covering critical systems and data security scenarios
  2. Evidence that the plan is reviewed at least annually
  3. Evidence that the plan has been tested, with a record of the test and any findings

The plan needs to cover the scenarios most relevant to your setting — not every possible disruption, but the ones that could plausibly happen and affect your ability to care for patients or clients safely.

Identifying your critical systems

Before writing the plan, identify which systems you rely on for safe, continuous care:

For care homes:

  • Care planning software (Nourish, Person Centred Software, Access Care Planning, etc.)
  • Medication management system (if electronic)
  • NHSmail (for GP communications)
  • Building security and door access systems

For GP practices:

  • EMIS Web, SystmOne, or Vision
  • NHSmail
  • Appointment booking and telephone system
  • Repeat prescribing workflow

For dental practices:

  • Practice management software (Dentally, SOE, R4)
  • NHSmail or shared NHS appointment booking access
  • NHS BSA Compass for NHS claim submission

For pharmacies:

  • Dispensing system (EMIS, Pharmacy Manager, Nexphase)
  • NHSmail
  • NHS Spine access for Electronic Prescription Service
  • Online repeat prescription ordering platform (if used)

For each system, record: what it's used for, what data it holds, and what you would do if it was unavailable for 4 hours / 24 hours / 72 hours.

What a small-provider BCP needs to cover

A proportionate business continuity plan for a small provider should address:

System recovery procedures. For each critical system: who do you call? What's the vendor emergency support number? How long is the expected recovery time? Is there a manual backup procedure while the system is down?

Manual backup procedures. This is the core of a healthcare BCP: what paper-based or manual procedures exist when systems are unavailable?

  • Care homes: paper care records, paper MAR charts, paper visit rotas
  • GP practices: paper appointment books, paper prescription pads, paper lab request forms
  • Dental practices: paper appointment lists, paper NHS claim forms (FP17s)
  • Pharmacies: paper dispensing records, paper intervention logs

Your BCP should state explicitly where these paper resources are kept and who is responsible for switching to manual procedures.

Incident command. Who is in charge during a system failure? Who makes the call to go manual? Who communicates with staff, patients, and external partners? In a small organisation, this is usually the registered manager, practice manager, or owner — but it needs to be named.

Communications. How do you notify patients or clients of service disruption? How do you communicate with referring organisations (GP referrals to pharmacy, home care agency notifying community nurses) if your usual communication channel (NHSmail, care system messaging) is unavailable?

Data recovery. For systems where you hold the data (a local server rather than cloud-hosted software), what backup schedule exists? Where are backups stored? How long would restoration take?

Ransomware response. Ransomware is the data security scenario most likely to cause prolonged system unavailability. Your BCP should cover: isolate affected systems, do not pay, contact your IT provider immediately, contact NHS England DSPT support, and notify the ICO within 72 hours if patient data was affected.

Testing the plan

The DSPT requires evidence that the plan has been tested. For small providers, a tabletop exercise is the proportionate approach.

A tabletop exercise involves key staff walking through a scenario together and working out what they would actually do. The point is to test whether the plan is realistic — whether the procedures are documented, accessible, and understood — not to simulate a live disaster.

How to run a tabletop exercise:

  1. Choose a scenario: "Our care management system is unavailable from 8am. It's now 11am and the vendor says recovery will take at least 12 hours."
  2. Gather key staff: registered manager, deputy manager, possibly a senior care worker.
  3. Walk through the scenario: What do we do? Who phones who? Where are the paper records? What do we tell families?
  4. Record what you discussed, what you found (gaps, things that worked, things that didn't), and what actions you're taking.

A one-page exercise record with the date, participants, scenario, and findings is sufficient DSPT evidence. It demonstrates the plan exists, was tested, and is being improved.

Annual review

The BCP needs an annual review date in the document header. The review should check:

  • Are all named contacts still in role?
  • Have any critical systems changed? New software, new cloud platform?
  • Have vendor support numbers changed?
  • Are paper backup resources still stocked and accessible?
  • Has anything changed in care delivery (new services, new client cohorts) that changes your continuity needs?

Update the review date and add a review note. File the previous version so you have an audit trail.

Common gaps before submission

No plan exists at all. Start with a single page covering your most critical system. You can expand it, but having something specific and reviewed is more valuable than having nothing.

Plan exists but hasn't been reviewed. Update the review date and confirm the plan is still accurate.

No test record. Run a 60-minute tabletop exercise and document it. This is often faster than writing the plan if you already have informal procedures.

Plan doesn't address ransomware. Ransomware is the most common serious data security incident affecting NHS-connected organisations. Ensure your plan covers the first response steps.

Manual backup procedures aren't documented. The plan says "go manual" but doesn't say what that means, where the paper records are, or who decides. This is the gap that turns a two-hour incident into a 12-hour one.

Use the DSPT evidence checklist generator to see how your BCP evidence fits into the full submission picture. For Standard 7 in the context of domiciliary care — where BCP has additional field-worker dimensions — see our

domiciliary care guide.

This guide is based on DSPT v8 (2025/26) requirements as published by NHS England. Always verify current requirements on the official DSPT portal. This is not legal or compliance advice.

Sources

Get guided DSPT compliance when we launch

Join the waitlist for early access to DSPTready — step-by-step DSPT guidance built for small providers.

No spam. Unsubscribe any time. Privacy policy