Skip to main content

NHS England Data Sharing Audit: Beamtree UK Limited

This report records the key findings of a remote data sharing audit of Beamtree UK Limited (Beamtree UK) between 18 – 27 May 2026.

Audit summary

Purpose

This report records the key findings of a remote data sharing audit of Beamtree UK Limited (Beamtree UK) between 18 – 27 May 2026. It provides an evaluation of how Beamtree UK and its Processors conform to the requirements of:

  • the data sharing framework contract (DSFC) CON-779196-H7N1L v2.03
  • the data sharing agreement (DSA) DARS-NIC-774448-Q4C6X-v1.2
  • the organisations’ own policies, processes and procedures

This DSA covers the provision of the following datasets: 

Dataset Classification of data Dataset period

Emergency Care Data Set (ECDS)

Pseudonymised/Anonymised - Non-sensitive

2020/21

2021/22

2022/23

2023/24

2025/26_M02 – M04

Hospital Episode Statistics Admitted Patient Care (HES APC)

Pseudonymised/Anonymised - Non-sensitive

2020/21

2021/22

2022/23

2023/24

2025/26_M02 – M04

Hospital Episode Statistics Critical Care (HES Critical Care)

Pseudonymised/Anonymised - Non-sensitive

2020/21

2021/22

2022/23

2023/24

2025/26_M02 – M04

Hospital Episode

Statistics Outpatients (HES

OP)

Pseudonymised/Anonymised - Non-sensitive

2020/21

2021/22

2022/23

2023/24

2025/26_M02 – M04

Summary Hospital-level

Mortality Indicator (SHMI)

Pseudonymised/Anonymised - Non-sensitive

Apr 22 - Mar 25

Mar 22 - Feb 25

May 22 - Apr 25

Emergency Care Data Set (ECDS)

Pseudonymised/Anonymised - Non-sensitive

2024/25

2025/26_M05 – M12

2026/27_M01 – M12

2027/28_M01 – M12

2028/29_M01

The Controller is Beamtree UK. The Processors are Amazon Web Services (AWS) who provide cloud hosting, with Edge Health Ltd providing initial support to the development of the Evolve Collaboration platform. Beamtree Pty Ltd (Australia) are included as a processor as staff from Australia are involved in the development and management of the platform in the UK.

Beamtree UK requires access to NHS England data for the purpose of creating an analytics platform for NHS acute trusts. The platform will provide performance data and trend-based forecasting, with an ability to compare local performance with peers. These insights will support a collaborative programme (the 'Evolve Collaborative' between Beamtree and the NHS Confederation) aiming to improve services, practices and processes to minimise operational and clinical risks.

The analytics tool intends to use these datasets to provide predictive analytics that support clinical and operational quality improvement in NHS hospitals in England & Wales.

The interviews during the audit were conducted remotely through video conferencing.

This is an exception report based on the criteria expressed in the Data Sharing Audit Guide version 5.

Audit type and scope

Audit type 

Routine

Scope areas 

Information Transfer

Access Control

Data Use and Benefits

Risk Management

Operational Management and Control

Data Destruction

Restrictions 

Access Control - limited visibility of physical controls  

Overall risk statement

Based on evidence presented during the audit and the type of data being shared the following risk has been assigned from the options of Critical - High - Medium - Low.

Current risk statement: Low

In deriving this risk, the Audit Team takes into account compliance, duty of care, confidentiality and integrity, as appropriate.


Data recipient’s acceptance statement

Beamtree UK has reviewed this report and confirmed that it is accurate.

Data recipient’s action plan

Beamtree UK will establish a corrective action plan to address each finding. The Audit Team will validate this plan and the resultant actions will be followed up with Beamtree UK by the IG Risk and Assurance team at NHS England to confirm the findings have been satisfactorily addressed.

The Audit has identified 2 opportunities for improvement which are provided for reference only and will not be followed up.


Findings

The following table identifies the 3 agreement nonconformities, 1 organisation nonconformity, 2 observations, and 2 points for follow-up raised as part of the audit.

Ref Finding Link to area Clause Designation

1

Access to the Evolve system offers the ability for Trusts to download their own record level data. Whist the functionality was discussed at the time of application, it was not identified as part of the processing within the DSA. Beamtree should liaise with Data Access Service (DAS) to ensure this processing is considered and included within the terms of any future versions of the DSA.

Access Control

DSA Annex A, Section 5b, Processing Activities

Agreement nonconformity

2

The DPA Registration Number quoted within the agreement (ZB316773) for Beamtree UK as the named Controller at the time of the audit was invalid. Immediate action should be taken to ensure the Information Commissioners Office (ICO) are contacted and details, as a Controller, are updated.

Beamtree UK ensured the registration details have been updated immediately following the interviews.

Operational Management

DSA Annex A, Section 1b, Data Controllers

Agreement nonconformity

3

Beamtree UK have an information asset registry (IAR). However, it is used to record more strategic level information, as opposed to specific dataset detail and the information related to these. Entries for the data provided under this agreement should be included within an IAR as required by the DSFC.

Beamtree UK will create a separate bespoke IAR exclusively for data received under this DSA, or any other DSA, in the future.

Operational Management

DSFC, Part 2, Schedule 2, Section A, Clause 3.2

Agreement nonconformity

4

The Beamtree Identity and Access Management (IAM) policy indicates an automated lockout period for desktops and laptops. An assurance check is undertaken regularly to supplement this. However domain settings should be updated in accordance with the IAM policy to provide an automated and more reliable review and assurance.

Access Control

Identity and Access Management Policy v3.0 09/10/25 Section 4.6.4

Organisation nonconformity

5

Beamtree UK provided a comprehensive Standard Operating Procedure (SOP) which detailed the roles, responsibilities and actions to be taken in the event of a suspected breach or incident. However it doesn’t include reference to immediately notifying NHSE where NHSE data is involved and should be updated to reflect this requirement within the DSFC.

Operational Management

DSFC, Part 2, Terms and Conditions, Clause 4.1.8

Beamtree UK Security Incident Response SOP v2.1 30/10/25

Observation

6

Beamtree UK should update the current Evolve Data Lifecycle Management SOP to include clear details of all actions required in the event the NHSE data requires destruction. This could be in the event of an incident or because the data reaches its maximum retention period.

Data Destruction

Data Review and Deletion SOP, Governance and Security 1.2 28/11/25

Observation

7

The Audit Team will check that the updated details for Beamtree UK’s DSPT submission are accurately referenced in Section 1b of the DSA. Evidence was provided that standards were met in February 2026, however this isn’t reflected in the DSA audited.

Operational Management

 

Follow-up

8

The data retention period for the NHSE data held on AWS cloud storage is inconsistent with Beamtree UK policy. Beamtree will update the AWS settings to ensure that retention is accurately aligned to policy requirements.

Data Destruction

 

Follow-up

Opportunities for improvement

The following table identifies 2 opportunities for improvement which could help an organisation improve its controls or processes. Beamtree UK should consider:

Ref

Opportunities for improvement

Link to Area 

1.

Approaching the Data Access Service (DAS) around a review of the current Territory of Use (ToU) (England/Wales) and whether it is feasible and more appropriate to have worldwide access permitted.

Whether staff access the data from the UK or Australia the primary (security) controls and where the data resides will not change.

Access Control
2.

Including the risks identified within the DPIA as an addition to the otherwise comprehensive Evolve Risks, Assumptions, Issues and Dependencies (RAID) log provided as supporting evidence of risk management. This will aid the tracking and monitoring of the risks identified.

Risk Management

Use of Data

Beamtree UK confirmed that the datasets were only being processed and used for the purposes defined in the DSA and were not being linked with another dataset.

Data Location

Beamtree UK confirmed that processing and storage locations, including disaster recovery and backups, of the datasets were limited to the location shown in the following table.  These locations conform with the territory of use defined in section 2c of the DSA.

Organisation Territory of Use

Beamtree UK

England / Wales

Backup Retention

The duration for which data may be retained on backup media is:

Organisation Media Type Period

AWS

Cloud

7 Years

 


Disclaimer

The audit was based upon a sample of the data recipient’s activities, as observed by the Audit Team. The findings detailed in this audit report may not include all possible nonconformities which may exist. In addition, as the audit interviews were conducted through a video conference platform, certain controls that would normally be assessed whilst onsite could not be witnessed.

NHS England has prepared this audit report for its own purposes. As a result, NHS England does not assume any liability to any person or organisation for any loss or damage suffered or costs incurred by it arising out of, or in connection with, this report, however such loss or damage is caused. NHS England does not assume liability for any loss occasioned to any person or organisation acting or refraining from acting as a result of any information contained in this report.

Last edited: 24 July 2026 3:27 pm