Care Circle Network | The 90-Day Digital Maturity Reset: Safer Systems, Stronger Continuity and More Time for Care

Adult social care is becoming dependent on technology.

Digital care records hold the information staff need to support people safely.

Electronic medicines systems guide administration and identify missed actions.

Rostering platforms determine who is expected to deliver care and when.

Email, mobile devices and video calls connect providers with families, commissioners and health professionals.

Sensors and telecare systems identify events, raise alerts and support people to remain independent.

Payroll, recruitment, training and quality systems keep the organisation operating around the care being delivered.

This technology can improve quality, visibility and efficiency.

It can also create a new form of operational vulnerability.

When a paper folder was unavailable, one part of the service might be affected.

When a central digital platform becomes unavailable, the effect can move immediately across:

  • every person receiving care;
  • every employee;
  • every location;
  • every medicine round;
  • every scheduled visit;
  • and every management decision depending on that information.

That does not mean providers should retreat from digital working.

It means digital maturity must include the ability to operate safely when technology does not behave as expected.

The most digitally mature organisation is not necessarily the one with the greatest number of platforms.

It is the one that can explain:

  • why each system is used;
  • which care outcome it supports;
  • who is responsible for it;
  • how information is protected;
  • how employees use it;
  • what happens when it fails;
  • and whether the investment is producing measurable value.

Digital maturity is not proved only when systems work. It is proved when systems improve care—and the service remains safe when they stop.


Adult Social Care Has Reached the Next Digital Stage

By the 30 June 2026 deadline, almost 76.5% of CQC-registered adult social care services in England had an up-to-date Data Security and Protection Toolkit.

That represented 22,429 services, including 12,887 care homes and 9,562 home-care services.

Almost 14,500 had published their DSPT for at least three consecutive years.

This is important progress.

It suggests that data protection and cyber security are becoming routine organisational responsibilities rather than occasional technical projects.

But Digital Care Hub has also made the next challenge clear:

Publishing the DSPT is a milestone. Providers must now turn its commitments into everyday practice.

That means ensuring that policies, training, supplier arrangements, access controls, continuity plans and information-sharing practices operate consistently outside the annual submission process.

A published toolkit cannot restore a care record.

It cannot produce a rota when the scheduling platform is offline.

It cannot tell a night worker how to support someone safely during an outage.

And it cannot ensure that a backup is complete, accessible and capable of being restored.

The sector is therefore moving from digital compliance towards digital operational resilience.


What Does Digital Maturity Actually Mean?

Digital maturity should not be confused with digitisation.

Digitisation means:

  • replacing paper with software;
  • issuing devices;
  • creating user accounts;
  • storing information electronically;
  • and adopting online workflows.

Digital maturity means:

  • selecting technology around an identified care or operational need;
  • integrating it into safe working practice;
  • protecting the information it uses;
  • supporting the workforce to use it confidently;
  • governing suppliers and access;
  • learning from incidents;
  • measuring outcomes;
  • and maintaining care when the technology is unavailable.

A digitally mature provider is not technology-led.

It is care-led and technology-enabled.

It understands that digital systems are now part of:

  • care quality;
  • workforce capability;
  • business continuity;
  • safeguarding;
  • medicines safety;
  • information governance;
  • and organisational sustainability.

That is why responsibility cannot sit only with an external IT company or the employee who happens to know most about computers.

Digital maturity requires ownership from:

  • boards;
  • owners;
  • nominated individuals;
  • registered managers;
  • quality leaders;
  • information-governance leads;
  • system administrators;
  • and frontline teams.

The Seven Foundations of Digital Maturity

A strong digital operating model should be built around seven foundations.

1. Purpose

Every platform should address a defined care, workforce or organisational need.

2. People

Technology should reflect the needs, rights and preferences of people receiving care and the realities of the workforce using it.

3. Information

Data should be accurate, current, connected and available to the right people.

4. Security

Access, devices, suppliers and information-sharing arrangements should protect sensitive data.

5. Continuity

The provider should be able to maintain safe care during outages, cyber incidents, power disruption and supplier failure.

6. Governance

Leaders should understand performance, risk, cost, access, incidents and outcomes.

7. Improvement

Technology should produce measurable improvements rather than simply more digital activity.

The 90-day reset brings those foundations into one practical programme.


Days 1–30: Understand the Digital Estate

The first month should establish what the organisation depends on.

Many providers have added systems gradually.

A platform was purchased to solve one problem.

A second was introduced for medicines.

A separate HR system followed.

New telecare equipment was installed.

Staff began using mobile devices.

An AI-enabled feature arrived through a software update.

Over time, the provider may lose sight of:

  • which technology is operating;
  • which contract governs it;
  • what information it holds;
  • who owns the relationship;
  • and how significant failure would be.

The first stage of maturity is visibility.


Week 1: Create a Digital Asset and Systems Register

List every technology used across the organisation.

This should include:

  • digital social care records;
  • eMAR;
  • rostering;
  • call-monitoring systems;
  • telecare;
  • nurse-call systems;
  • sensors;
  • HR and payroll;
  • recruitment;
  • training;
  • incident management;
  • quality and auditing;
  • email;
  • file storage;
  • Wi-Fi and broadband;
  • mobile phones and tablets;
  • laptops and desktops;
  • printers and scanners;
  • cloud backup;
  • websites;
  • finance systems;
  • CCTV and access control;
  • fire and lift alarms;
  • and any AI-enabled tools or features.

For each asset, record:

  • the supplier;
  • contract owner;
  • renewal date;
  • purpose;
  • number of users;
  • information held;
  • login method;
  • administrator;
  • integrations;
  • support contact;
  • business criticality;
  • backup position;
  • and continuity arrangement.

The register should not become an exercise in recording model numbers for its own sake.

Its purpose is to answer:

Which parts of our service cannot operate safely without this technology?


Classify Systems by Criticality

Not every system requires the same level of resilience.

A useful classification might be:

Critical to immediate care

Examples:

  • care records;
  • medicines systems;
  • emergency call systems;
  • telecare;
  • visit scheduling;
  • and critical clinical information.

Failure may affect people within minutes or hours.

Critical to service operation

Examples:

  • workforce rostering;
  • email;
  • payroll;
  • finance;
  • supplier ordering;
  • and communication systems.

Failure may not create immediate harm but could seriously affect continuity if prolonged.

Important but deferrable

Examples:

  • non-urgent reporting;
  • marketing;
  • some training administration;
  • or longer-term planning systems.

This classification helps the provider decide:

  • which systems require offline alternatives;
  • which backups must be restored first;
  • which supplier failures need immediate escalation;
  • and where investment in resilience matters most.

Week 2: Follow the Critical Care Journeys

Select several real care processes and examine every technology they depend on.

These could include:

  • completing a home-care visit;
  • administering evening medicines;
  • responding to a fall;
  • receiving a hospital discharge;
  • escalating a safeguarding concern;
  • managing an unexpected staff absence;
  • and contacting a person’s representative during an emergency.

For each journey, ask:

  1. Which system provides the starting information?
  2. Which devices and connections are required?
  3. What happens if one element fails?
  4. Is an offline copy available?
  5. Who makes the decision?
  6. How is the action recorded later?
  7. How will information be reconciled when the system returns?

This exposes dependencies that a technology inventory alone may miss.

A care worker may require:

  • the rota;
  • mobile connectivity;
  • the digital care record;
  • building access;
  • a telephone;
  • and the eMAR

to complete one scheduled visit safely.

The failure of any one of those elements may change the care pathway.


Week 3: Review Access, Data and Cyber Controls

Providers hold some of the most sensitive information an organisation can possess.

That includes:

  • health;
  • disability;
  • mental capacity;
  • medication;
  • behaviour;
  • family relationships;
  • safeguarding;
  • finances;
  • employee records;
  • and details of daily routines.

The access review should establish:

  • who has an account;
  • which permissions they hold;
  • whether former employees retain access;
  • whether shared accounts exist;
  • whether administrators are appropriate;
  • whether multi-factor authentication is used where available;
  • how mobile devices are secured;
  • whether updates are installed;
  • and how suspicious activity is reported.

The review should also consider:

  • where information is stored;
  • which suppliers can access it;
  • how data is backed up;
  • whether backup restoration has been tested;
  • and what happens when a device is lost or stolen.

Government research into cyber security in adult social care found that 80% of surveyed providers had a business-continuity plan covering cyber security, while 61% had a cyber-incident response plan and 53% had both.

It also found that 81% backed up data, with 96% of those providers reporting confidence that their backups were usable and complete.

These figures indicate considerable activity.

But confidence is not the same as tested recovery.

A provider does not know that a backup works because a dashboard says it was completed.

It knows when the information has been restored successfully within the timeframe the service requires.


Week 4: Identify Analogue and Supplier Dependencies

The digital maturity review should not look only at systems already recognised as digital.

Some of the greatest risks may sit within older devices that depend on analogue telephone lines.

The Public Switched Telephone Network is being retired, with PSTN-reliant landlines and devices needing to be upgraded by January 2027.

Government guidance identifies alarm systems, telecare devices and door-entry systems among the technologies affected.

The Telecare National Action Plan estimates that around two million people across the UK use telecare and warns that some analogue devices may not operate reliably on digital networks. It says no telecare user should be migrated unless a compatible, functioning solution is confirmed.

Care providers should review:

  • telecare alarms;
  • personal alarms;
  • fire alarms;
  • lift alarms;
  • door-entry systems;
  • intruder alarms;
  • fax lines;
  • monitoring equipment;
  • and any device connected to a traditional telephone socket.

They should establish:

  • whether it relies on the PSTN;
  • whether it is digitally compatible;
  • who supplies and maintains it;
  • whether it has been tested;
  • what happens during a power cut;
  • and when migration will take place.

The issue is particularly important because digital landlines generally depend on mains-powered routers. Government and Ofcom guidance highlights the need for power-resilience arrangements where people depend on landlines for emergency contact.


The End-of-Month Digital Risk Map

At the end of the first 30 days, the provider should be able to place every important digital dependency into one of four positions.

Strong and assured

The system is purposeful, supported, secure, tested and producing identifiable value.

Operational but insufficiently assured

The system works, but supplier, access, backup, training or continuity evidence is weak.

Material weakness with improvement underway

A known risk has an owner, deadline and active mitigation.

Critical unresolved dependency

Failure could affect safe care and the provider lacks an adequate alternative or recovery plan.

Critical unresolved dependencies should not wait for the second month.

Immediate temporary controls may be required while a longer-term solution is developed.


Days 31–60: Close the Highest-Risk Gaps

The second month should focus on a manageable number of material weaknesses.

The provider should not try to redesign its complete technology estate at once.

Prioritise according to:

  • potential harm;
  • number of people affected;
  • speed of impact;
  • likelihood of failure;
  • regulatory significance;
  • and difficulty of recovery.

Priority 1: Create Safe Downtime Arrangements

Digital systems can fail because of:

  • cyber attack;
  • software fault;
  • supplier outage;
  • broadband loss;
  • power failure;
  • damaged hardware;
  • unsuccessful update;
  • or human error.

Digital Care Hub advises providers to assume that incidents and outages may occur and to prepare clear response and recovery arrangements focused on maintaining safe care. Its February 2026 cyber-resilience programme recommended incident checklists, business-continuity templates, recovery planning and practical scenario exercises.

A downtime pack should include the minimum information required to continue care safely.

Depending on the service, this might cover:

  • essential care summaries;
  • medicines information;
  • allergies;
  • emergency contacts;
  • key risks;
  • communication needs;
  • current rota;
  • visit schedules;
  • escalation procedures;
  • supplier contacts;
  • and incident-recording forms.

The provider should consider:

  • how often the offline information is updated;
  • where it is held;
  • who can access it;
  • how confidentiality is protected;
  • and how records completed during the outage will be entered and reconciled afterwards.

Offline records should be sufficient to support safe care.

They should not create an uncontrolled second version of the complete digital record.


Priority 2: Test Backup and Restoration

Backups should answer two separate questions.

Is the information being copied?

A system may report successful backup completion.

Can the information be restored?

The provider needs evidence that the backup can produce usable information after loss or corruption.

Testing should establish:

  • what data is included;
  • how frequently it is backed up;
  • where copies are held;
  • whether the backup is isolated from the live system;
  • who can restore it;
  • how long restoration takes;
  • and what information may be lost between the final backup and the incident.

Digital Care Hub advises providers to test backups regularly and understand how to restore files before an actual incident occurs.

For supplier-hosted software, do not assume the provider has no responsibility because the system is cloud-based.

Ask the supplier:

  • what is backed up;
  • how often;
  • where;
  • how restoration is tested;
  • what recovery time is offered;
  • and what happens if the supplier itself is affected by ransomware or business failure.

Priority 3: Strengthen Account and Device Control

A large proportion of digital risk can be reduced through ordinary operational discipline.

Providers should:

  • remove accounts promptly when employees leave;
  • review high-level administrator access;
  • eliminate inappropriate shared logins;
  • use strong authentication;
  • apply updates;
  • encrypt suitable devices;
  • control downloads;
  • record issued equipment;
  • and define rules for personal-device use.

Managers should know how to respond when:

  • a phone is lost;
  • a tablet is stolen;
  • a password is shared;
  • a suspicious email is opened;
  • or a staff member believes an account has been compromised.

Speed matters.

The first response should not depend on waiting until office hours for one technically confident employee to become available.


Priority 4: Clarify Supplier Accountability

Care providers increasingly depend on suppliers for:

  • hosting;
  • support;
  • backups;
  • cyber security;
  • connectivity;
  • device maintenance;
  • data migration;
  • and system integration.

But outsourcing a function does not outsource all accountability.

The provider should know:

  • who to contact;
  • support hours;
  • escalation routes;
  • contractual recovery targets;
  • planned-maintenance arrangements;
  • data locations;
  • subcontractors;
  • incident-notification commitments;
  • data-export processes;
  • and end-of-contract support.

Digital Care Hub’s cyber guidance for care-technology suppliers emphasises the importance of systems remaining safe, reliable and worthy of the trust placed in them as care software becomes increasingly interconnected.

A supplier should not only explain how it prevents failure.

It should explain how the provider will continue operating while failure is being resolved.


Priority 5: Improve Connectivity and Power Resilience

Digital care depends on the infrastructure beneath the software.

Providers should map:

  • fixed broadband;
  • internal Wi-Fi;
  • mobile coverage;
  • routers;
  • switches;
  • charging;
  • backup power;
  • and alternative communication routes.

Ask:

  • Are there parts of the building without reliable coverage?
  • Can home-care staff record safely in low-signal areas?
  • What happens if the main broadband connection fails?
  • Is mobile tethering available and authorised?
  • How long will essential equipment operate during a power cut?
  • Which devices depend on a router?
  • Can emergency calls still be made?

The digital phone migration makes power resilience especially important.

Digital landlines do not operate in the same way as traditional powered analogue lines during an electricity failure, and providers should understand what battery or mobile alternatives support critical communication and alarm systems.


Priority 6: Move DSPT Commitments into Daily Practice

The DSPT covers more than policy ownership.

It should influence:

  • staff training;
  • information handling;
  • asset registers;
  • supplier assurance;
  • continuity planning;
  • access;
  • incident response;
  • and leadership oversight.

Digital Care Hub’s 2026 update explicitly encouraged providers to move from DSPT publication to implementation and offered Digital Health Checks to identify practical gaps.

Providers should select several toolkit commitments and test them in practice.

For example:

Policy says leavers lose access promptly

Check a sample of recent leavers across every system.

Policy says backups are maintained

Restore a sample.

Policy says staff understand phishing

Run a realistic awareness exercise or scenario.

Policy says digital continuity is covered

Test a system outage.

Policy says supplier risk is reviewed

Inspect current contracts and assurance evidence.

The purpose is not to catch the organisation failing its own policy.

It is to identify the difference between intended and actual practice before an incident exposes it.


Days 61–90: Test, Learn and Embed

A continuity plan that has never been tested remains a theory.

The final month should simulate realistic disruption.

Digital Care Hub recommends tabletop exercises and scenario testing because organisations that practise incident response are better able to protect services and people when disruption occurs.

The test does not need to take systems offline deliberately.

A tabletop exercise can bring leaders and staff together and ask them to work through a scenario in real time.

The value comes from discovering:

  • missing information;
  • unclear roles;
  • unrealistic assumptions;
  • supplier delays;
  • and decisions nobody realised would be required.

Scenario 1: The Digital Care Record Is Unavailable for 24 Hours

At 6:30am, staff cannot access the DSCR.

The supplier’s website says it is investigating a national outage.

Ask:

  • Who confirms the outage?
  • Who contacts the supplier?
  • Who activates the continuity plan?
  • Where are essential care summaries?
  • Can staff access current risks and communication needs?
  • How will daily care be recorded?
  • How will new concerns be escalated?
  • How will agency workers be briefed?
  • How are families and commissioners informed where necessary?
  • Who decides when normal operation has resumed?
  • How will temporary records be reconciled?

The exercise should test both residential and community working where relevant.

A paper pack locked in the manager’s office is not a continuity solution for a home-care employee several miles away.


Scenario 2: eMAR Fails During an Evening Medicine Round

The eMAR platform becomes unavailable during the busiest administration period.

Ask:

  • Can staff identify current prescriptions and allergies?
  • Is a secure downtime MAR available?
  • How is the final administered dose confirmed?
  • How are omissions prevented?
  • Who contacts the pharmacy or prescriber?
  • What if only some devices are affected?
  • How will duplicate administration be prevented when the system returns?
  • Who reconciles the temporary records?
  • Does the supplier provide an audit of the outage?

CQC’s eMAR guidance requires providers to manage any paper or other digital records used alongside eMAR safely and make them accessible where needed.

The test should reflect the exact medicines system and service model rather than a generic continuity template.


Scenario 3: Ransomware Affects Email and Shared Files

Employees discover they cannot access email or central documents.

A ransom message appears.

Ask:

  • Who is informed first?
  • Are staff told to disconnect devices?
  • Can leaders communicate without email?
  • How are emergency contacts reached?
  • Are care records affected?
  • Can new referrals or safeguarding information be received?
  • Who contacts cyber, insurer, suppliers and authorities?
  • How is evidence preserved?
  • Which systems should be restored first?
  • How will decisions be logged?

Digital Care Hub stresses that cyber response is a whole-organisation responsibility and that continuity of safe care should remain the priority while technical recovery takes place.


Scenario 4: The Rostering Supplier Is Unavailable

The provider cannot access the rota before the morning home-care round.

Ask:

  • Is a current schedule held offline?
  • Can staff see addresses and essential visit information?
  • How are last-minute absences managed?
  • Can visit completion still be confirmed?
  • How will missed or delayed calls be identified?
  • How will changes be recorded for later reconciliation?
  • Who communicates with people and families?
  • What happens if the outage continues for three days?

A provider’s continuity plan should consider supplier-system failure, not only cyber attacks directed at the provider itself.


Scenario 5: Power and Broadband Fail at a Care Home

The service loses electricity during the night.

Ask:

  • Which systems stop immediately?
  • Which telephones remain available?
  • Do fire, lift, call and door-entry systems continue?
  • What battery support is available?
  • How long does it last?
  • Can emergency services be contacted?
  • How will staff access care and medicines information?
  • Which people require additional observation?
  • Who contacts the utility and telecoms suppliers?
  • What triggers evacuation or relocation?

The digital phone switchover makes this scenario increasingly important because equipment connected through routers may become unavailable without power unless appropriate resilience is in place.


Scenario 6: An Analogue Telecare Device Stops Communicating

A person’s alarm no longer connects to the monitoring centre following a landline migration.

Ask:

  • How is the failure identified?
  • Who verifies whether the device is compatible?
  • What immediate alternative is provided?
  • Who contacts the telecoms and telecare suppliers?
  • Is the person placed at increased risk?
  • Does the care plan need temporary adjustment?
  • How are family and professionals informed?
  • Are other devices using the same arrangement affected?

The Telecare National Action Plan places the protection of users at the centre of the migration and calls for risk-based identification of people most vulnerable to disruption.

Providers should not assume the telecoms company will know every device connected to a care setting or private home.


The Post-Test Review

Every exercise should end with a structured review.

Record:

  • what worked;
  • what failed;
  • which assumptions were wrong;
  • what information was missing;
  • which roles were unclear;
  • which supplier responses were inadequate;
  • and what action is required.

Actions should include:

  • an owner;
  • deadline;
  • evidence of completion;
  • and retest date.

The test is not complete when participants leave the meeting.

It is complete when identified weaknesses have been corrected and the provider has rechecked the response.

Digital Care Hub advises providers recovering from an incident to maintain a detailed timeline, review controls, learn from what happened and update the business-continuity plan accordingly.


More Time for Care Must Be Measured

The title of this reset includes “more time for care.”

That benefit should not be assumed.

Providers need to measure whether technology is genuinely releasing capacity.

Useful measures may include:

  • time spent recording;
  • duplicated entry;
  • care-plan review time;
  • rota preparation;
  • incident analysis;
  • payroll corrections;
  • chasing missing information;
  • supplier support calls;
  • and time spent correcting digital errors.

Then ask where any released time went.

Did it support:

  • direct care;
  • supervision;
  • care reviews;
  • staff development;
  • family communication;
  • quality improvement;
  • or management visibility?

A system saving managers two hours each week has value only if that capacity becomes available in practice.

Efficiency should be converted into a positive care or workforce outcome.


Digital Skills Must Become Part of Workforce Planning

Technology can fail even when the software is available and secure if employees lack confidence using it.

Providers should understand:

  • which digital skills each role requires;
  • where confidence is weakest;
  • whether agency staff receive appropriate preparation;
  • who supports employees on nights and weekends;
  • and how competence is reviewed after a system change.

Training should cover more than normal operation.

Employees need to know:

  • how to identify a suspicious email;
  • what to do when a device is lost;
  • how to report an incident;
  • how to access downtime information;
  • how to protect screens and passwords;
  • and when not to use an unapproved application.

Digital confidence should be included in:

  • induction;
  • supervision;
  • appraisal;
  • role development;
  • and leadership training.

A digital champion can support local confidence, but the organisation should not make one employee solely responsible for every technical and security issue.


Digital Maturity Requires Supplier Maturity

Care providers should expect more from digital partners as their dependence grows.

A credible supplier should be able to explain:

  • how the system supports care outcomes;
  • its security controls;
  • backup and recovery arrangements;
  • service availability;
  • incident communication;
  • support coverage;
  • integration;
  • data portability;
  • accessibility;
  • staff training;
  • and continuity during failure.

Providers should also ask:

  • When was the supplier’s recovery process last tested?
  • How quickly will we be informed of an incident?
  • What support is available outside office hours?
  • What happens if the business ceases trading?
  • Can we obtain our information in a usable format?
  • Which subcontractors process our data?
  • What parts of continuity remain our responsibility?
  • How are software updates tested?
  • Does the system rely on 2G, analogue lines or other retiring infrastructure?
  • What evidence shows the product is improving care?

The strongest suppliers will not treat continuity questions as an obstacle to the sale.

They will recognise them as evidence of a provider taking its responsibilities seriously.


What Should Boards and Nominated Individuals Review?

Digital performance should sit alongside quality, workforce, finance and risk.

Boards, owners and nominated individuals should receive a proportionate view of:

  • critical systems;
  • availability and outages;
  • cyber incidents;
  • access reviews;
  • DSPT status;
  • backups and restoration tests;
  • continuity exercises;
  • supplier risks;
  • digital skills;
  • analogue migration;
  • technology costs;
  • and measurable outcomes.

They should ask:

  1. Which system failure would affect people fastest?
  2. Can care continue if that system is unavailable for 24 hours?
  3. When were backups last restored successfully?
  4. Are former employees removed promptly from every platform?
  5. Which critical supplier has not been tested or reviewed?
  6. Are there analogue devices still awaiting migration?
  7. Does every service have reliable connectivity and power resilience?
  8. Do employees understand downtime procedures?
  9. What technology is creating unnecessary administration?
  10. What measurable improvement has our digital investment produced?

Digital governance should not be reduced to an annual update stating that there have been no reported data breaches.

Absence of a reported incident is not complete evidence of resilience.


A Proportionate Reset for Smaller Providers

A small provider does not need a dedicated cyber team or digital-transformation department.

It does need to understand its dependencies.

A proportionate approach may include:

  • one systems register;
  • one named digital and data lead;
  • one current DSPT submission;
  • clear supplier contacts;
  • controlled user access;
  • secure devices;
  • tested backups;
  • a simple outage pack;
  • one business-continuity exercise;
  • and a record of analogue systems requiring migration.

External managed IT, DSPT support, telecoms advice or continuity expertise may be more practical than building every capability internally.

The support should remain proportionate.

A small provider does not need a complicated digital strategy full of technical language.

It needs enough control to protect people and keep the service operating.


The Digital Maturity Scorecard

At the end of 90 days, providers can assess progress across six areas.

1. Care value

  • Does technology support personalisation?
  • Are risks identified earlier?
  • Are outcomes improving?

2. Workforce confidence

  • Can employees use systems safely?
  • Are downtime procedures understood?
  • Has duplicated administration reduced?

3. Information quality

  • Is data accurate, current and connected?
  • Can leaders trust reports?
  • Are conflicting records identified?

4. Security and access

  • Are accounts and devices controlled?
  • Are staff trained?
  • Is the DSPT reflected in practice?

5. Continuity and recovery

  • Are critical systems identified?
  • Are backups usable?
  • Have realistic scenarios been tested?
  • Can care continue safely?

6. Supplier and infrastructure resilience

  • Are supplier responsibilities clear?
  • Is connectivity reliable?
  • Are analogue dependencies being removed?
  • Are contracts and exit arrangements understood?

The scorecard should create a baseline, not a badge.

The provider should repeat it periodically and demonstrate progress.


The 90-Day Digital Maturity Reset at a Glance

Days 1–30: Understand

  • map systems, devices and suppliers;
  • classify criticality;
  • follow care-information journeys;
  • review access and backups;
  • assess staff confidence;
  • identify analogue dependencies;
  • and produce a digital risk map.

Days 31–60: Strengthen

  • create downtime packs;
  • test backups;
  • close access gaps;
  • improve supplier assurance;
  • strengthen connectivity and power resilience;
  • complete analogue-migration actions;
  • and turn DSPT commitments into practice.

Days 61–90: Prove

  • run realistic scenarios;
  • test care-record and eMAR outages;
  • simulate cyber and supplier failure;
  • test communication and telecare continuity;
  • record learning;
  • close actions;
  • and report assurance to senior leadership.

The reset should not end digital improvement.

It should establish a disciplined way of continuing it.


Ten Questions Care Leaders Should Be Asking

  1. Which technologies are now essential to safe care?
  2. Do we know who owns every important system and supplier relationship?
  3. Can staff access critical information during an outage?
  4. Have we restored a backup rather than merely assumed it works?
  5. Are our DSPT commitments operating in everyday practice?
  6. Which analogue devices still depend on the retiring PSTN?
  7. Can essential communication and alarms continue during a power cut?
  8. Do employees know who leads a cyber or digital incident?
  9. Is technology releasing time or creating new administration?
  10. What can we prove is safer, stronger or more person-centred than it was 90 days ago?

The final question is the measure of maturity.


What Does Digital Maturity Look Like?

A digitally mature care provider is not immune from disruption.

Systems will fail.

Suppliers will experience incidents.

Employees will make mistakes.

Connectivity and power will be interrupted.

Digital maturity means the organisation is prepared enough that one failure does not become uncontrolled harm.

It is visible when:

  • technology has a clear purpose;
  • people remain involved;
  • information is accurate;
  • access is controlled;
  • employees are confident;
  • suppliers are accountable;
  • backups are usable;
  • outages have been planned for;
  • analogue risks are being removed;
  • and improvement is measured.

The provider knows what it depends on.

It knows what to do when that dependency is unavailable.

And it understands how technology is affecting the lives of the people it supports.


Beyond Digital Adoption

Across this series, the digital conversation has moved through five stages.

Beyond go-live

A digital record has value only when it improves care, decisions and outcomes.

One version of the truth

Several systems can support care only when information remains reliable and connected.

Responsible AI

Artificial intelligence should support human judgement—not obscure accountability or weaken relationships.

Monitoring to prevention

Care technology becomes meaningful when information leads to timely action, independence and measurable benefit.

Digital maturity and continuity

The complete operating model must remain safe, secure and resilient under pressure.

Together, these stages show why digital transformation cannot be led by technology alone.

It must be shaped by:

  • care;
  • rights;
  • workforce reality;
  • leadership;
  • and outcomes.

Adult social care has achieved substantial digital adoption.

The next phase is more demanding.

Providers need to make systems work together.

They need to govern new capabilities.

They need to protect sensitive information.

They need to prepare for disruption.

And they need to prove that digital investment is releasing more time for the human work of care.

The technology should help staff know the person better.

It should help leaders see risk sooner.

It should help people remain independent.

It should create confidence rather than confusion.

And when it fails, the service should still know how to care.

That is digital maturity.

Not the number of systems installed.

Not the completion of one toolkit.

Not the sophistication of one dashboard.

But safer systems, stronger continuity and more time for what matters most.


Frequently Asked Questions

What is digital maturity in adult social care?

Digital maturity means technology is selected and governed around care outcomes, employees can use it confidently, information is protected and reliable, and safe care can continue during outages, cyber incidents or supplier failure.

How many adult social care services completed the 2025/26 DSPT?

By the 30 June 2026 deadline, almost 76.5% of CQC-registered adult social care services in England had an up-to-date DSPT, representing 22,429 services.

Does completing the DSPT mean a provider is cyber secure?

No. The DSPT supports providers to assess and improve data-security arrangements, but policies and commitments must be embedded into daily practice, staff behaviour, supplier management and tested continuity planning.

What should a digital business-continuity plan cover?

It should address loss of critical care systems, eMAR, rostering, email, internet, telephones, power, devices and suppliers. It should explain how essential information will be accessed, how care will be recorded and how normal records will be reconciled afterwards.

How often should providers test their continuity plans?

Testing should be regular and repeated after significant system, supplier or service changes. High-risk systems may require more frequent exercises than less critical technology.

Why is the digital phone switchover relevant to care providers?

PSTN-reliant landlines and devices need to be upgraded by January 2027. Telecare, alarm and door-entry systems may be affected, and digital connections may require separate power-resilience arrangements.

What happens if a cloud software provider has an outage?

The care provider should activate its continuity arrangements, use approved offline information, contact the supplier, record temporary care activity and reconcile records safely once the system returns.

What should care providers ask technology suppliers about resilience?

They should ask about uptime, backups, recovery testing, support hours, incident notification, data export, subcontractors, power or connectivity dependencies and what providers must do during failure.

How can technology release more time for care?

It can reduce duplicated recording, simplify access to information, automate appropriate administration and improve management visibility. Providers should measure whether the saved time reaches direct care, supervision or quality improvement.


Editorial sources

This feature has been developed using evidence available by 5 August 2026, preserving the integrity of its backdated publication position.

  • Digital Care Hub, Record Numbers of Care Services Have DSPT, published 1 July 2026.
  • Digital Care Hub, Cyber in Care: Resilience, Recovery and Incident Response, webinar held 25 February 2026.
  • Department of Health and Social Care, The State of Cyber Security in Adult Social Care.
  • Department of Health and Social Care and NHS England, Digital Working in Adult Social Care: What Good Looks Like.
  • Digital Care Hub, Respond and Recover From a Cyber Security Incident.
  • Digital Care Hub, Reduce the Risk and Impact of a Cyber Incident.
  • Department of Health and Social Care and Department for Science, Innovation and Technology, Telecare National Action Plan.
  • UK Government, Moving Landlines to Digital Technologies.
  • Ofcom, Protecting Customers During the Migration to Digital Landlines.
  • Care Quality Commission, Electronic Medicines Administration Records in Adult Social Care.
CSN Editor
Author: CSN Editor