NHS Digital Technology Assessment Criteria
Assessed against the NHS baseline for clinical safety, data protection, technical security, interoperability and usability - the standard NHS organisations apply before procurement.
LUTI is built for the standards your Information Governance, Caldicott and Clinical Safety teams already work to - assessed, audited and independently tested.
We have been building software for frontline clinicians for over a decade. We know what works, what breaks, and what matters when patient safety is on the line.
EHR and referral management platform experience
Between 2012 and 2026
Across NHS and Private organisations
Every layer of LUTI is shaped by independent assessment, clinical governance and continuous testing - so your organisation can adopt with confidence.
Assessed against the NHS baseline for clinical safety, data protection, technical security, interoperability and usability - the standard NHS organisations apply before procurement.
A documented clinical safety case maintained by a qualified Clinical Safety Officer. Hazards identified, mitigated and reviewed across every release.
Annual NHS Data Security and Protection Toolkit submission. Aligned to the National Data Guardian's ten standards for handling patient information.
Hands-on technical audit of our infrastructure, endpoints and access controls against the UK government's advanced cyber security certification.
An ISMS aligned to ISO/IEC 27001 - risk-based controls covering people, process and technology, with continuous monitoring and improvement.
Regular penetration tests by accredited third parties across our mobile, web and API surfaces. Findings tracked to remediation with re-test sign-off.
A DPIA template ready to share with your Information Governance team, covering lawful basis, data flows, retention and the rights of data subjects.
Registered with the UK Information Commissioner's Office. UK GDPR compliant, with clear records of processing and a published privacy notice.
The controls behind every message - the same ones your IG team would specify if they were building it themselves.
Messages secured in transit and at rest. Keys we cannot read.
Every user tied to a registered professional record - GMC, NMC, HCPC.
Reach a role, not a personal phone number. Cover and rota aware.
Every thread searchable and exportable for disclosure or SAR.
Conversation history retained for as long as your policy requires.
Share clinical images and identifiers inside a compliant container.
DTAC response, DCB0129 clinical safety case, DSPT publication, ISO 27001 certificate, Cyber Essentials Plus certificate, pen test summary and DPIA - sent under NDA to your IG lead.
Join clinicians already using LUTI" to move care forward.
NHS DTAC · DSPT · Cyber Essentials Plus · ISO 27001 · Mobile & browser