Skip to main content

The secure email standard

Emails sent to and from health and social care organisations must meet the secure email standard (DCB1596) so that everyone can be sure that sensitive and confidential information is kept secure.

Meeting the secure email standard

There are two ways to meet the secure email standard. Organisations must select one of these methods to comply.

  1. Implement an already compliant service such as NHSmail, Office 365 or Google Workspace for all staff at your organisation.
  2. Demonstrate your own service is compliant with the secure email standard by following the secure email accreditation process.

Implement an already compliant service

NHSmail

Meet the organisation requirements of the standard by following the steps below.

  1. Ensure there is a process in place to notify the NHSmail team upon becoming aware of any breach of security, including an actual, potential or attempted breach of, or threat to, the security policy and / or the security of the services or the systems used to provide the services.
  2. Health and care organisations SHOULD set policies and procedures for the use of secure email using mobile devices and ensure the email service enforces them.
  3. Health and care organisations SHOULD comply with the provisions of DCB0160: Clinical Risk Management: its Application in the Deployment and Use of Health IT Systems
  4. Health and care organisations MUST set policies and procedures for staff who use the secure email service to ensure that they understand how to use it appropriately and safely, including how to send emails to insecure email systems such as those used by patients.
  5. Migrate all users/staff to the NHSmail email service: To migrate all email users to NHSmail follow the migration guidance on the NHSmail support site.

Microsoft Office 365 (O365): Secure email configuration guide

Meet the organisation requirements of the standard by following the steps below.

  1. Ensure there is a process in place to notify the NHSmail team upon becoming aware of any breach of security, including an actual, potential or attempted breach of, or threat to, the security policy and/or the security of the services or the systems used to provide the services.
  2. Health and care organisations SHOULD set policies and procedures for the use of secure email using mobile devices and ensure the email service enforces them.
  3. Health and care organisations SHOULD comply with the provisions of DCB0160: Clinical Risk Management: its Application in the Deployment and Use of Health IT Systems.
  4. Health and care organisations MUST set policies and procedures for staff who use the secure email service to ensure that they understand how to use it appropriately and safely, including how to send emails to insecure email systems such as those used by patients.
  5.  Register compliance with the NHSmail team.

It is the responsibility of each organisation to verify their own configuration, to ensure that their environment has been configured appropriately. To assist we are providing a CIS (centre for Internet Security) Microsoft Office 365 foundation benchmark assessment Level 2 criteria that we assess against for compliance to the secure email standard.

Conformance to this standard will therefore be evidenced by completing an ITHC using the scope and CIS MIcrosoft 365 Foundation Benchmark Testing Results and Corrective Action Plan template. Each organisation should define any mitigation or remedial action plans and submit to NHS Digital Secure email standard service for assessment/approval. Further guidance can be found in the CIS Microsoft 365 Foundation Benchmark Testing Results and Corrective Action Plan template.

Microsoft Office 365 (O365) accreditations must include confirmation that the email service has been configured to securely communicate with NHSmail. The Microsoft Office 365: Secure email configuration guide has been co-produced with Microsoft, allowing instances of O365 to be enabled to securely route emails to and from NHSmail.

Google Workspace Secure email configuration guide

Meet the organisation requirements of the standard by following the steps below.

  1. Ensure there is a process in place to notify the NHSmail team upon becoming aware of any breach of security, including an actual, potential or attempted breach of, or threat to, the security policy and/or the security of the services or the systems used to provide the services.
  2. Health and care organisations SHOULD set policies and procedures for the use of secure email using mobile devices and ensure the email service enforces them.
  3. Health and care organisations SHOULD comply with the provisions of DCB0160: Clinical Risk Management: its Application in the Deployment and Use of Health IT Systems.
  4. Health and care organisations MUST set policies and procedures for staff who use the secure email service to ensure that they understand how to use it appropriately and safely, including how to send emails to insecure email systems such as those used by patients.

  5. Register compliance with the NHSmail team: Google Workspace accreditations must include confirmation that the email service has been configured to securely communicate with NHSmail. 

Google workspace: Secure email configuration guide has been co-produced with Google, allowing instances of Workspace to be enabled to securely route emails to and from NHSmail.

Exchange, hybrid or other email services

In addition to completing the organisation section of the standard, those hosting their own email services must submit assertions and evidence that they meet the ICT Service Provider elements of the standard. These will be reviewed by the NHS Digital Data Security Centre. 

To help organisations with their accreditation process to the DCB1596 standard, we have provided Secure email standard (DCB159) guidance to help you understand what actions organisations need to take to make the changes in the DCB1596 secure email standard.


List of accredited organisations

Please see the list of all organisations that have accredited to the DCB1596 secure email standard. These systems meet the minimum requirements and will be accredited to a level that will enable the secure transmission of personal confidential data and sensitive information to other secure email domains. 

It includes the organisation, their domain and other information of use relating to DMARC and SPF policies that are aimed at those technical resources within organisations that will be consuming this list into their own systems.

This list is maintained and updated as soon as an organisation accredits to the DCB1596 standard.

It was last updated on 15 April 2024. 


Secure email accreditation process

The steps below illustrate the end to end accreditation process.

  1. Submission of a signed self-accreditation statement, with evidence.
  2. Evidence checked by the NHS Digital Data Security Centre and NHSmail team.
  3. Rectification of findings and re-submission to the NHSmail team.
  4. DCB1596 met.

Secure email accreditation templates

The templates to accredit your email service to the secure email standard are listed below and should be returned with the required evidence to [email protected].

In the 'Health and Care Organisation' section of the templates, please provide the name and date of the policy or document covering each requirement and ensure the requisite approvals are in place.


Conformance statements

The statements below confirm how Microsoft Office 365 and Google Workspace meet their email security obligations:

Re-accreditation

Accreditations to the secure email standard last for one calendar year. After this period organisations are required to re-accredit.

The re-accreditation process will involve the organisation re-submitting evidence for review. In most instances this will be very similar to the information previously submitted.

Penetration test results and ISO27001 certificates must be within the last 12 months.

As accreditations come to the end of their term the NHSmail team will send out a reminder to each organisation. 


Contact

For any further queries regarding the secure email standard please contact [email protected]. You will receive a response within 10 working days.

Last edited: 15 April 2024 4:57 pm