NHS England Data Sharing Audit: Beamtree UK Limited
This report records the key findings of a remote data sharing audit of Beamtree UK Limited (Beamtree UK) between 18 – 27 May 2026.
Audit summary
Purpose
This report records the key findings of a remote data sharing audit of Beamtree UK Limited (Beamtree UK) between 18 – 27 May 2026. It provides an evaluation of how Beamtree UK and its Processors conform to the requirements of:
- the data sharing framework contract (DSFC) CON-779196-H7N1L v2.03
- the data sharing agreement (DSA) DARS-NIC-774448-Q4C6X-v1.2
- the organisations’ own policies, processes and procedures
This DSA covers the provision of the following datasets:
| Dataset | Classification of data | Dataset period |
|---|---|---|
|
Emergency Care Data Set (ECDS) |
Pseudonymised/Anonymised - Non-sensitive |
2020/21 2021/22 2022/23 2023/24 2025/26_M02 – M04 |
|
Hospital Episode Statistics Admitted Patient Care (HES APC) |
Pseudonymised/Anonymised - Non-sensitive |
2020/21 2021/22 2022/23 2023/24 2025/26_M02 – M04 |
|
Hospital Episode Statistics Critical Care (HES Critical Care) |
Pseudonymised/Anonymised - Non-sensitive |
2020/21 2021/22 2022/23 2023/24 2025/26_M02 – M04 |
|
Hospital Episode Statistics Outpatients (HES OP) |
Pseudonymised/Anonymised - Non-sensitive |
2020/21 2021/22 2022/23 2023/24 2025/26_M02 – M04 |
|
Summary Hospital-level Mortality Indicator (SHMI) |
Pseudonymised/Anonymised - Non-sensitive |
Apr 22 - Mar 25 Mar 22 - Feb 25 May 22 - Apr 25 |
|
Emergency Care Data Set (ECDS) |
Pseudonymised/Anonymised - Non-sensitive |
2024/25 2025/26_M05 – M12 2026/27_M01 – M12 2027/28_M01 – M12 2028/29_M01 |
The Controller is Beamtree UK. The Processors are Amazon Web Services (AWS) who provide cloud hosting, with Edge Health Ltd providing initial support to the development of the Evolve Collaboration platform. Beamtree Pty Ltd (Australia) are included as a processor as staff from Australia are involved in the development and management of the platform in the UK.
Beamtree UK requires access to NHS England data for the purpose of creating an analytics platform for NHS acute trusts. The platform will provide performance data and trend-based forecasting, with an ability to compare local performance with peers. These insights will support a collaborative programme (the 'Evolve Collaborative' between Beamtree and the NHS Confederation) aiming to improve services, practices and processes to minimise operational and clinical risks.
The analytics tool intends to use these datasets to provide predictive analytics that support clinical and operational quality improvement in NHS hospitals in England & Wales.
The interviews during the audit were conducted remotely through video conferencing.
This is an exception report based on the criteria expressed in the Data Sharing Audit Guide version 5.
Audit type and scope
|
Audit type |
Routine |
|---|---|
|
Scope areas |
Information Transfer Access Control Data Use and Benefits Risk Management Operational Management and Control Data Destruction |
|
Restrictions |
Access Control - limited visibility of physical controls |
Overall risk statement
Based on evidence presented during the audit and the type of data being shared the following risk has been assigned from the options of Critical - High - Medium - Low.
Current risk statement: Low
In deriving this risk, the Audit Team takes into account compliance, duty of care, confidentiality and integrity, as appropriate.
Data recipient’s acceptance statement
Beamtree UK has reviewed this report and confirmed that it is accurate.
Data recipient’s action plan
Beamtree UK will establish a corrective action plan to address each finding. The Audit Team will validate this plan and the resultant actions will be followed up with Beamtree UK by the IG Risk and Assurance team at NHS England to confirm the findings have been satisfactorily addressed.
The Audit has identified 2 opportunities for improvement which are provided for reference only and will not be followed up.
Findings
The following table identifies the 3 agreement nonconformities, 1 organisation nonconformity, 2 observations, and 2 points for follow-up raised as part of the audit.
| Ref | Finding | Link to area | Clause | Designation |
|---|---|---|---|---|
|
1 |
Access to the Evolve system offers the ability for Trusts to download their own record level data. Whist the functionality was discussed at the time of application, it was not identified as part of the processing within the DSA. Beamtree should liaise with Data Access Service (DAS) to ensure this processing is considered and included within the terms of any future versions of the DSA. |
Access Control |
DSA Annex A, Section 5b, Processing Activities |
Agreement nonconformity |
| 2 |
The DPA Registration Number quoted within the agreement (ZB316773) for Beamtree UK as the named Controller at the time of the audit was invalid. Immediate action should be taken to ensure the Information Commissioners Office (ICO) are contacted and details, as a Controller, are updated. Beamtree UK ensured the registration details have been updated immediately following the interviews. |
Operational Management |
DSA Annex A, Section 1b, Data Controllers |
Agreement nonconformity |
| 3 |
Beamtree UK have an information asset registry (IAR). However, it is used to record more strategic level information, as opposed to specific dataset detail and the information related to these. Entries for the data provided under this agreement should be included within an IAR as required by the DSFC. Beamtree UK will create a separate bespoke IAR exclusively for data received under this DSA, or any other DSA, in the future. |
Operational Management |
DSFC, Part 2, Schedule 2, Section A, Clause 3.2 |
Agreement nonconformity |
| 4 |
The Beamtree Identity and Access Management (IAM) policy indicates an automated lockout period for desktops and laptops. An assurance check is undertaken regularly to supplement this. However domain settings should be updated in accordance with the IAM policy to provide an automated and more reliable review and assurance. |
Access Control |
Identity and Access Management Policy v3.0 09/10/25 Section 4.6.4 |
Organisation nonconformity |
| 5 |
Beamtree UK provided a comprehensive Standard Operating Procedure (SOP) which detailed the roles, responsibilities and actions to be taken in the event of a suspected breach or incident. However it doesn’t include reference to immediately notifying NHSE where NHSE data is involved and should be updated to reflect this requirement within the DSFC. |
Operational Management |
DSFC, Part 2, Terms and Conditions, Clause 4.1.8 Beamtree UK Security Incident Response SOP v2.1 30/10/25 |
Observation |
| 6 |
Beamtree UK should update the current Evolve Data Lifecycle Management SOP to include clear details of all actions required in the event the NHSE data requires destruction. This could be in the event of an incident or because the data reaches its maximum retention period. |
Data Destruction |
Data Review and Deletion SOP, Governance and Security 1.2 28/11/25 |
Observation |
| 7 |
The Audit Team will check that the updated details for Beamtree UK’s DSPT submission are accurately referenced in Section 1b of the DSA. Evidence was provided that standards were met in February 2026, however this isn’t reflected in the DSA audited. |
Operational Management |
|
Follow-up |
| 8 |
The data retention period for the NHSE data held on AWS cloud storage is inconsistent with Beamtree UK policy. Beamtree will update the AWS settings to ensure that retention is accurately aligned to policy requirements. |
Data Destruction |
|
Follow-up |
Opportunities for improvement
The following table identifies 2 opportunities for improvement which could help an organisation improve its controls or processes. Beamtree UK should consider:
|
Ref |
Opportunities for improvement |
Link to Area |
|---|---|---|
|
1. |
Approaching the Data Access Service (DAS) around a review of the current Territory of Use (ToU) (England/Wales) and whether it is feasible and more appropriate to have worldwide access permitted. Whether staff access the data from the UK or Australia the primary (security) controls and where the data resides will not change. |
Access Control |
| 2. |
Including the risks identified within the DPIA as an addition to the otherwise comprehensive Evolve Risks, Assumptions, Issues and Dependencies (RAID) log provided as supporting evidence of risk management. This will aid the tracking and monitoring of the risks identified. |
Risk Management |
Use of Data
Beamtree UK confirmed that the datasets were only being processed and used for the purposes defined in the DSA and were not being linked with another dataset.
Data Location
Beamtree UK confirmed that processing and storage locations, including disaster recovery and backups, of the datasets were limited to the location shown in the following table. These locations conform with the territory of use defined in section 2c of the DSA.
| Organisation | Territory of Use |
|---|---|
|
Beamtree UK |
England / Wales |
Backup Retention
The duration for which data may be retained on backup media is:
| Organisation | Media Type | Period |
|---|---|---|
|
AWS |
Cloud |
7 Years |
Disclaimer
The audit was based upon a sample of the data recipient’s activities, as observed by the Audit Team. The findings detailed in this audit report may not include all possible nonconformities which may exist. In addition, as the audit interviews were conducted through a video conference platform, certain controls that would normally be assessed whilst onsite could not be witnessed.
NHS England has prepared this audit report for its own purposes. As a result, NHS England does not assume any liability to any person or organisation for any loss or damage suffered or costs incurred by it arising out of, or in connection with, this report, however such loss or damage is caused. NHS England does not assume liability for any loss occasioned to any person or organisation acting or refraining from acting as a result of any information contained in this report.
Last edited: 24 July 2026 3:27 pm