Part of Infrastructure hosting standards for the NHS
Backup and data protection and recoverability
Standards you should meet on Backups, data protection and recoverability.
1. NHS organisations should ensure all locally hosted systems and data are backed up in line with disaster recovery business continuity plans and clinical, operational and regulatory requirements
Importance of meeting the standard
Reliable backups are essential to protect NHS services against data loss, corruption, cyber incidents and system failures and are a core dependency of wider continuity and disaster recovery arrangements.
Backup arrangements underpin patient safety, service continuity and organisational resilience, ensuring that critical clinical and operational data can be recovered when required. They are also a core dependency of wider business continuity and disaster recovery (BCDR) arrangements.
- deploying new hosted systems or services
- making significant changes to infrastructure, storage or applications
- responding to incidents involving data loss, corruption or ransomware
- reviewing business continuity, disaster recovery or cyber resilience arrangements
How to meet the standard
- all hosted systems and datasets are covered by defined backup policies and explicitly referenced in continuity and recovery plans
- backup frequency, retention and scope reflect clinical and operational criticality
- backups are stored securely and protected from unauthorised access
- backup arrangements are documented and reviewed regularly
- backup responsibilities are clearly defined where services are hosted or managed by third parties
- backup arrangements are understood in terms of what data and systems can be recovered, and any known limitations are documented
- backup schedules should be defined and automated where possible
- backups should be protected against deletion, corruption and ransomware where feasible (for example immutable or logically isolated storage)
- backup data should be encrypted in transit and at rest
- backup failures should generate alerts and be investigated promptly
2. NHS organisations should ensure backups are regularly tested and can be restored within clinical and operational recovery timescales
Importance of meeting the standard
Backups are only effective as resilience if data and systems can be restored within an acceptable timeframe. Untested backups present a significant risk and any inability to restore services promptly can result in delayed care, disrupted clinical workflows and increased patient safety risk.
A clear understanding of restoration times is essential to support informed decision‑making during incidents, including service prioritisation, clinical workarounds and escalation.
- defining or reviewing recovery time and recovery point objectives
- introducing systems with high availability or resilience requirements
- following restoration failures or extended outages
- undertaking assurance or resilience testing activity
How to meet the standard
- restoration processes, times and recovery points are documented, accessible and understood by relevant teams
- restore testing is performed on a regular basis and after material change
- test outcomes are documented and any issues identified resolved
- the impact of restoration times on clinical and operational decision‑making is considered as part of recovery planning
- backup solutions scale appropriately as data volumes and service dependency grow
- Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) should be defined for key systems
- restore tests should be performed in non‑production environments where possible and documentation retained for assurance and audit purposes
- backup solutions should support partial and full restores as required
- adequate capacity should exist to restore multiple systems in parallel where necessary
Last edited: 18 June 2026 1:39 pm