Medicus Trust Centre

Security, governance & compliance you can trust

Medicus is a cloud-native Foundation GP system, assured by NHS England through the Tech Innovation Framework (TIF), and meeting the NHS Digital Technology Assessment Criteria (DTAC). This is where you can review and verify everything behind it: our security, data protection, clinical safety and interoperability, each independently certified.

Have a question? Talk to our team

Last updated: 26 August 2026

Built for the people who use it every day

You look after patients. We look after the system, the data and the standards behind it, so you can trust what is in front of you.

Your patients' data is safe

Every record is encrypted, access is controlled and audited, and the platform is independently tested against the highest NHS security standards.

It is clinically safe

As the system manufacturer we comply with DCB0129 and DCB0160, with every hazard logged and every release safety-assessed before go-live.

It works with the NHS around you

Built on national standards including GP Connect, EPS, e-RS, PDS and the NHS App, and it keeps working with the third-party tools your practice already uses.

Security

Patient data, protected by design

We are certified to ISO 27001 and Cyber Essentials Plus, and we exceed the standards of the NHS Data Security and Protection Toolkit. All data stays in the UK, encrypted in transit and at rest, with role-based access and two-factor authentication. A CREST-accredited team tests our defences continuously, and we act on every finding, so the system holding your patients' data stays protected.

Cyber Essentials Plus

Cyber Essentials Plus

Certified

Certified to the UK Government-backed Cyber Essentials Plus scheme.

NHS DSPT

NHS DSPT

Compliant

Compliant with all requirements of the NHS Data Security and Protection Toolkit.

ISO 27001

ISO 27001

Certified

Certified to ISO 27001 for information security management.

Penetration testing

Compliant

Independent penetration testing programme.

Information governance & data protection

We use patient data lawfully, and only ever to deliver care

We act as a Data Processor under UK GDPR, registered with the ICO, and process personal data only for agreed purposes. A named Data Protection Officer is accountable for our compliance. Our current sub-processors, and why each is engaged, are published below.

ICO Registration

Registered

Registered with the Information Commissioner's Office, registration number ZA625889.

GDPR processes

In place

UK GDPR-compliant processing, data-subject rights and records of processing.

Data protection controls

In place

Access controls, encryption in transit and at rest, and audit logging.

Sub-processors

Published

Current list of sub-processors and the purposes for which they are engaged.

Data Protection Officer

In place

Data Protection Officer contactable at dpo@medicus.health.

Data Protection Impact Assessment

On request

A completed Data Protection Impact Assessment (DPIA) for the Medicus platform, available to ICBs on request.

Data Processing Agreement

On request

A signed Data Processing Agreement setting out our obligations as a Data Processor, available on request.

DTAC

Completed

Digital Technology Assessment Criteria (DTAC) completed, the NHS national baseline covering clinical safety, data protection, security, interoperability and accessibility.

Business continuity

Always on, and quick to recover

We host on Amazon Web Services and design resilience in from the start, reviewed against the AWS Well-Architected Framework. We test our business continuity plan and our data restores on a schedule, so in the rare event of disruption we recover the service and your data within defined targets.

Business continuity tests

Compliant

Business continuity plan with scheduled testing.

Backup & restore tests

Compliant

Regular backup and restore testing of production data.

AWS Well-Architected Framework

Compliant

Cloud infrastructure reviewed against the AWS Well-Architected Framework.

Clinical safety

Clinically safe, by design

As the system manufacturer we comply with DCB0129, the mandatory NHS clinical risk management standard, and we are registered with the MHRA as a Class I medical device. Every hazard is logged and every weekly release is safety-assessed before go-live. We give your practice the safety case and templates to make its own DCB0160 sign-off straightforward, all overseen by our GMC-registered Clinical Safety Officer, so your team can trust every decision the system supports.

DCB0129

DCB0129

On request

Clinical Risk Management System compliant with DCB0129 (manufacturer).

DCB0160

On request

Supports deploying organisations in meeting their DCB0160 obligations.

MHRA Class I

MHRA Class I

Registered

Registered as a Class I Digital Medical Device with the MHRA.

Clinical Safety Officer

In place

Dr Imran Khan, GMC no. 7278705.

Interoperability & integration

Built to connect with the NHS and the tools you already use

As part of our NHS England Tech Innovation Framework (TIF) assurance, Medicus already delivers the majority of national NHS integrations, including GP Connect, EPS, e-RS, PDS, the Summary Care Record, GP2GP, Smartcard authentication and the NHS App. We also support the third-party tools practices choose to keep, and we maintain every integration as national standards evolve. A full, current integration register is available on request.

See our integrations

Migration & data continuity

A planned move, with nothing lost

A dedicated implementation lead is your single point of contact from planning to go-live. We provide a clear cut-over plan with a rollback position, and carry out data extraction, validation and testing with sign-off beforehand.

See how migration works

Service management

A service you can rely on

Our service management is independently assured to ISO 20000 by LRQA, covering how we handle incidents, changes and problems. We commit to published service level agreements, monitor continuously, and give every practice a clear route to support with defined response times, so help is always there when your practice needs it.

ISO 20000

ISO 20000

Certified

Service management system fully assured against ISO 20000 (LRQA).

SLAs

Compliant

Service level agreements including uptime and support response targets.

Accessibility

Designed for everyone

Independently audited to recognised accessibility standards.

WCAG 2.2 AA

WCAG 2.2 AA

Certified

Audited against WCAG 2.2 AA by the Digital Accessibility Centre (DAC).

FAQ

Frequently asked questions

Quick answers to the questions ICBs ask most often. For anything not covered here, just ask our team.

Yes. Medicus is a cloud-native Foundation GP system, assured by NHS England through the TIF and built to the Foundation Clinical System standard. Our security is certified to ISO 27001 and Cyber Essentials Plus, and we are rated Standards Exceeded against the NHS DSPT, its highest rating. We have also completed the NHS Digital Technology Assessment Criteria (DTAC), the national baseline covering clinical safety, data protection, security, interoperability and accessibility.

Yes. As the system manufacturer we comply with DCB0129, the NHS clinical risk management standard, and we are registered with the MHRA as a Class I medical device. Every hazard is logged, our Clinical Safety Case is owned by a named Clinical Safety Officer on the GMC register, and we give your practice the safety case and templates to make its own DCB0160 sign-off straightforward.

All patient data is hosted in the UK on AWS, encrypted in transit and at rest. Access is role-based and protected by two-factor authentication and automatic log-out, with a separate database for every practice. Security is managed through an ISO 27001 information security management system and Cyber Essentials Plus, with continuous vulnerability management and independent penetration testing by a CREST-accredited provider.

Your practice is the Data Controller and Medicus is the Data Processor, processing patient data only on your instructions under a signed Data Processing Agreement and in line with UK GDPR. We are rated Standards Exceeded against the NHS DSPT and maintain a DPIA.

Medicus runs across multiple availability zones in the AWS London region, with automatic failover on every component. Data is protected by nightly snapshots kept for 45 days and point-in-time recovery, backed by tested disaster recovery and business continuity plans. We monitor the platform continuously, with a defined major-incident process and automated escalation if anything goes wrong.

Yes. The platform scales automatically, so the same system serves a single practice, a PCN or an entire ICB without redesign or migration. Our performance targets are 95 per cent of requests served within one second and 99 per cent within three seconds, reported to NHS England every month.

Medicus is built on national open standards, including GP Connect, GP2GP, EPS, e-RS, PDS, the Summary Care Record, Smartcard authentication and the NHS App, rather than custom point-to-point links. Practices can also keep the third-party tools they choose, from online consultation and telephony to document management, medicines optimisation, diagnostics and shared care records. A full, current integration register is available on request.

Migration follows a proven kick-off to go-live method, typically six to eight weeks, led by a dedicated implementation manager who is your single point of contact. We combine a full data extraction with a final delta migration and a weekend cut-over to a Monday go-live, with data validation and clinical safety sign-off at every gate and a documented rollback plan should it ever be needed.

Medicus leads the implementation from start to finish, so your ICB plays a facilitative role rather than a delivery one. We run discovery and planning, configuration and readiness, the weekend cut-over migration (governed by the NHS England Data Migration Standard) and all training, with in-person sessions for super users and clinical leads and role-based online training for everyone else. Our specialists are on site on go-live day and available throughout, followed by daily check-ins before each practice settles in with our dedicated Medicus support team.

The ICB's main involvement is to support the procurement process for the NHS England call-off. Medicus provides the assurance evidence directly, including the DPIA, DCB0129 Clinical Safety Case, DSPT evidence and information governance documentation, so the ICB's role is to receive and acknowledge it rather than produce it.

There is no cost to your practice. As an approved Foundation Clinical System on the NHS England TIF, Medicus is funded centrally by the NHS. You can procure it through the Digital Care Services Buying Catalogue call-off under Practice Choice, supported by local clinical safety and governance approval and a signed Data Processing Agreement.

Our product specialists are on hand through a dedicated support desk. Core support runs 06:30 to 20:30 every day, including bank holidays, with non-core cover from 20:30 to 06:30. Right after go-live your practice moves into hypercare with hands-on help from your implementation lead, and we ship weekly updates with no downtime.

For ICBs

Assuring Medicus for your ICB?

Explore our full assurance audit on Risk Ledger: our security, data protection and governance posture, independently verified and kept up to date.

Visit our Risk Ledger profile →

Need something specific?

Signed certificates, full reports or anything not published here: our team is one email away. Ask us anything and we will get it to you.

info@medicus.health →