Unofficial. This site is an experimental reformatting of data published by NHS England. It is not endorsed by NHS England. Always check the official Data Uses Register before relying on anything here.

NHSE UDAL- NHSCFA- For the purposes of the prevention and detection of crime.

NHS Counter Fraud Authority · Agency/Public Body

In term In term in the September 2026 edition: the latest version runs to 26 February 2029.

Reference
DARS-NIC-736310-S6T1Z
Current version
v3.4
Term of current version
27 February 2026 to 26 February 2029
Start date
17 April 2024
Data controller
Sole Data Controller
Commercial purposes
No
Sublicensing
No
Files released to date
0

Why the data was released

Objective for processing

The NHS Counter Fraud Authority (NHSCFA) requires access to NHS England data for the purpose of preventing and detecting fraud and other criminal offences within the NHS. The NHS England data will support NHSCFA in a rolling programme of exploratory analyses aiming to detect fraud across a range of identified concerns. The purpose of this analysis is to identify instances where there is a case for the commencement of a criminal investigation and/or to identify systemic weaknesses which can then be addressed by mitigating fraud risks inherent in the system (e.g. by changing policy).

This purpose is supported in the Directions to NHS Trusts and Special Health Authorities 2017 and the NHS Act 2006.

The NHSCFA, established under the NHS Act 2006, is mandated to prevent, detect, and investigate fraud, corruption, and unlawful activities within the English health service. The NHSCFA has been given the express function of the prevention, detection and investigation of fraud, corruption and unlawful activities against or affecting the health service in England. NHS bodies including Special Health Authorities (such as NHS England) are directed to cooperate with the NHSCFA and to enable the NHSCFA to efficiently and effectively carry out its functions as specified in paragraph 3(1)) of the NHS Counter Fraud Authority and supplemental directions 2017 (https://www.gov.uk/government/publications/nhs-counter-fraud-authority-and-supplemental-directions-2017).

The following NHS England Data will be accessed:

• Secondary Use Services (SUS) Episodes (Uncurated Low Latency Hospital Datasets) – necessary to conduct the necessary work to address several explicit problems highlighted by NHS England and other counter fraud organisations.

• Civil Registrations of Death - This dataset complements a number of wide clinical and staffing datasets and will allow NHSFA to undertake proactive counter fraud analysis and can be utilised to support existing efforts to identify claims made for deceased persons and/or identity fraud in terms of employment.

• Demographics - This dataset will enrichen wider datasets in use by NHSCFA to allow limited and controlled use of patient factors to identify and quantify fraud risks in the NHS across a wide range of recognised fraud risks - for example, by knowing patient age it will be possible to determine inappropriate or nonsensical treatments (for example, that for children or elderly patients). Using pseudonymised data in particular will make it possible to distinguish patients (as opposed to identify them) more widely over wider courses of treatments, to allow inappropriate claims to be detected; for example, duplicate or multiple claims across treatment, splitting of treatments (to maximise reimbursement), impossible timeframes or and misuse / inappropriate provision of controlled drugs. Additionally, linking to patient lists it will determine inappropriate list sizes.

• Medicines dispensed in primary care - This dataset provides granular insight that can complement existing aggregated datasets accessed by NHSCFA and the granular format can address a number of identified system weaknesses linked to medicines, which includes identified issues in the drug tariff and detection of irregularities in dispensing which cannot be identified using the aggregated data.

• ECDS - This dataset has been assessed as having a wide range of use for NHSCFA as both a primary source of information for fraud identification, and also as a secondary source in conjunction with other datasets. In the case where independent providers have been contracted to provide emergency/MIU services, NHSCFA can analyse them directly to see whether their claims are consistent with the expectation derived from activity, and also in comparison with similar NHS organisations. NHSCFA can also use the ECDS data to look into the knock-on from ISP to NHS services. For example, NHSCFA can look at ISPs who routinely leave hospital procedures unfulfilled, requiring patients to access the nearest NHS ED. If any exist, NHSCFA can compare this to payments made (including additional payments via Best Practice Tariffs) to see whether any have been claimed by ISPs despite patients routinely featuring worse outcomes

The level of the Data will be:

• Pseudonymised

The Data will be minimised as follows:

• Limited to the minimum Data required for the purpose of the work including any initial discovery work that is needed to ensure relevant data and data elements are appropriate to cover the problems identified.

• Limited to the activity period from April 2018 to the latest available data.

NHSCFA is the controller as the organisation responsible for ensuring that the Data will only be processed for the purpose described above.

The lawful basis for processing personal data under the UK GDPR is:

Article 6(1)(e) - processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

The lawful basis for processing special category data under the UK GDPR is:

Article 9 (2)(g) processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.

There are 23 conditions set out in paragraphs 6 to 28 of Part 2 of Schedule 1 of the DPA 2018, NHSCFA has determined that condition 14 (Preventing Fraud) aligns with their primary goal of preventing and detecting fraud and other criminal offences within the NHS and

Article 9(2)(j) - processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) based on Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.

The work is self-funded.

Microsoft Limited are a processor acting under the instructions of NHSCFA. Microsoft's role is limited to secure backup of data stored at NHSCFA.

Processing activities

No data will flow to NHS England for the purposes of this Data Sharing Agreement (DSA).

NHS England will provide access to the relevant records from the SUS, Civil Registrations of Death, Demographics and Medicines dispensed in primary care datasets to the NHSCFA. The Data will contain no direct identifying data items. The Data will be pseudonymised and individuals cannot be reidentified through linkage with other data in the possession of the recipient.

NHS England will grant access to the NHSCFA via the Unified Data Access Layer (UDAL) – a data management system within NHS England that enables patient data to be processed and made available for analytical purposes.

UDAL accommodates a series of tools, which enable users to explore patient or aggregate data, to create standardised reports and dashboards, and create statistical models.

NHSCFA will extract subsets of the data where required to carry out analyses using an NHSCFA-managed analytical tool.

NHSCFA will create an analytical product from the data which will be converted into either an intelligence product or an evidential one for the purposes of criminal investigations. These products will be stored on the CFA case management and intelligence system for any subsequent case file submission to the Crown Prosecution Service (CPS) or criminal / civil court.

The Data will not be transferred to any other location.

The Data will be stored on servers at NHS England (UDAL) and NHSFCA (extracted subsets of data)

Microsoft Limited providers cloud hosting services to NHSCFA and will store the data as contracted by NHSCFA.

The Data will be accessed by authorised personnel via remote access.

The Controller(s) must confirm and provide evidence upon audit by NHS England that access via any remote device complies with the data security obligations within this DSA and the Data Sharing Framework Contract.

Remote processing will be from secure locations within England.

The Data will not leave England at any time.

Access is restricted to employees or agents of the NHSCFA.

All personnel accessing the Data have been appropriately trained in data protection and confidentiality.

The extracted subsets will be linked with other data only where such linkage is fundamental to the work intended to detect fraud.

NHSCFA will not share data disseminated via the DSA with any third party other than as part of their investigation as forensic evidence.

There will be no requirement and no attempt to reidentify individuals when using the Data.

Expected output

The outcome will provide either assurances concerning the integrity of NHS business systems from fraud or will identify outliers and associated risks concerning potential NHS fraud.

The expected outputs of the processing will be:

• Documented analyses supporting conclusions either giving assurance concerning the integrity of NHS business systems from fraud or identifying outliers and associated risks concerning potential NHS fraud.)

• Specific fraud concerns drawn from the above that recommend commencement of criminal investigations , informing and supporting a more specific/targeted data share.

• Recognition of overarching fraud risk/system weaknesses which can be addressed through wider activity (for example, through policy changes or provision of guidance)

The above outputs will only contain aggregated/summarised information, with the potential for small examples of limited subsetted extracts of the data itself, only where explicitly necessary, to demonstrate the analysis itself or exemplify the wider findings . This will be produced in line with the relevant disclosure rules for the dataset(s) from which the information was derived .

As this will be a rolling programme of analysis responding to concerns as they are identified, the frequency of outputs will vary according to the nature of the programme and complexity of individual analytical investigations.

Expected measurable benefits

The NHS, like all public sector bodies, has a duty to combat fraud and, when it occurs, to recover monies for the public purse. NHSCFA has been setup with this specific remit, as well as a role in preventative action. This data share therefore supports this activity and the mitigation of fraud risk in the substantial public interest through both the detection and prevention of fraud and fraudsters but also through the mitigation of fraud risk and safeguarding of NHS system.

The overriding benefits of reducing fraud and driving improvements and assurance in any system that protects the public purse is self-explanatory, particularly given the financial and reputational issues that fraud causes, and the areas of mutual interest in resolving it. The approach uses elements taken from recognised crime prevention models and data science frameworks that identify measurable fraud detection and prevention outputs which can be developed in collaboration with all participating organisations and showcased.

Any outcomes associated with this project (whether legal repercussions or financial impact) can be collaboratively determined and their impact ultimately cited as the benefits of NHS England's and NHSCFA’s proactive and collaborative approach and hailed as demonstrative of the conjoined activity that mitigates fraud risks, deters fraudsters and drives savings that can support the treatment of patients.

In terms of wider tangible benefits, the exercise has the opportunity to share a range of domain expertise between organisations and the ability to share approaches, findings and any recommendations with all parties. In doing, all participants can apply a degree of fraud expertise that’s drawn from their operational knowledge to support future work in this remit.

Further details about the work are restricted to maintain the integrity of potential future investigation detection activities.

Benefits reported so far

Analysis using SUS data within the UDAL has already gleaned significant savings, concerning coding practise for payments towards. NHSCFA analysis allowed identification and then quantification of areas of concern that allowed the provider to maximise financial gain by coding activity against higher complexity payments and wider irregularities in the way that it submits invoices. These irregularities include charging for the same patient under different contracts, charging multiple first attendances and charging activity incorrectly (separate appointments on the same day rather than grouped correctly).

The NHS Counter Fraud Authority were able to use the data to highlight deliberate manipulation of the system and a separate investigation is underway to demonstrate a range of specific criminal offences being committed. In addition, NHSCFA have worked with NHS England throughout 2023 and 2024 to disrupt the fraudulent activity. This led to an intervention of changing the payment tariff which has given a saving of £18.9m from April 2023 to March 2024 and April 2024 to Sept 2024.

This saving, alongside a wider projection of the impact of this work, was submitted to the Public Sector Fraud Authority Prevention Panel in January 2025, whose role is to formalise all fraud prevention savings. They have authorised recognition of £28m of current and projected savings for this intervention.

As cited in the NHS England Annual Report, intervention undertaken by NHSCFA and NHS England on BZ34A cataract procedure coding (which was identified, substantiated and informed by the NHSCFA access to UDAL and the data sharing it has prompted) has resulted in a substantial counter fraud impact of the NHS Payment Scheme tariff adjustment. The disruption of fraudulent coding practices and an overall counter fraud impact of this intervention, spanning multiple financial periods, that is projected to reach approximately £47 million. This total reflects the cumulative effect of tariff adjustments and continued fraud prevention activities and has been ratified by the Public Sector Fraud Authority Prevention Panel, through which all fraud prevention data are scrutinised and assured.

Datasets on the current version

Legal basis for provision: Health and Social Care Act 2012 – s261(2)(a)

Datasets approved under DARS-NIC-736310-S6T1Z-v3.4
DatasetType of dataSensitivity FrequencyConfidential data
Civil Registrations of Death Anonymised - ICO Code Compliant Sensitive One-Off Does not include the flow of confidential data
Demographics Anonymised - ICO Code Compliant Sensitive One-Off Does not include the flow of confidential data
Emergency Care Data Set (ECDS) Anonymised - ICO Code Compliant Sensitive One-Off Does not include the flow of confidential data
Medicines dispensed in Primary Care (NHSBSA data) Anonymised - ICO Code Compliant Sensitive One-Off Does not include the flow of confidential data
SUS - CFA (Counter Fraud Authority)_UDAL Anonymised - ICO Code Compliant Non-Sensitive System Access Does not include the flow of confidential data

Files released

Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.

No files recorded as released under this agreement.

Version history

The register lists each renewal of this agreement as a separate row. This site has 4 versions.

DARS-NIC-736310-S6T1Z-v3.4 27 February 2026 to 26 February 2029
Title
NHSE UDAL- NHSCFA- For the purposes of the prevention and detection of crime.
Commercial
No
Sublicensing
No
Datasets
5
Files released
0

Datasets: Civil Registrations of Death; Demographics; Emergency Care Data Set (ECDS); Medicines dispensed in Primary Care (NHSBSA data); SUS - CFA (Counter Fraud Authority)_UDAL

What changed from DARS-NIC-736310-S6T1Z-v2.2

Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.

Fields changed from DARS-NIC-736310-S6T1Z-v2.2
FieldWasBecame
Start date2025-03-172026-02-27
End date2028-03-162029-02-26

Datasets: + Emergency Care Data Set (ECDS)

Objective for processing

[8 paragraphs unchanged] • ECDS - This dataset has been assessed as having a wide range of use for NHSCFA as both a primary source of information for fraud identification, and also as a secondary source in conjunction with other datasets. In the case where independent providers have been contracted to provide emergency/MIU services, NHSCFA can analyse them directly to see whether their claims are consistent with the expectation derived from activity, and also in comparison with similar NHS organisations. NHSCFA can also use the ECDS data to look into the knock-on from ISP to NHS services. For example, NHSCFA can look at ISPs who routinely leave hospital procedures unfulfilled, requiring patients to access the nearest NHS ED. If any exist, NHSCFA can compare this to payments made (including additional payments via Best Practice Tariffs) to see whether any have been claimed by ISPs despite patients routinely featuring worse outcomes [14 paragraphs unchanged]

Benefits reported

[3 paragraphs unchanged] As cited in the NHS England Annual Report, intervention undertaken by NHSCFA and NHS England on BZ34A cataract procedure coding (which was identified, substantiated and informed by the NHSCFA access to UDAL and the data sharing it has prompted) has resulted in a substantial counter fraud impact of the NHS Payment Scheme tariff adjustment. The disruption of fraudulent coding practices and an overall counter fraud impact of this intervention, spanning multiple financial periods, that is projected to reach approximately £47 million. This total reflects the cumulative effect of tariff adjustments and continued fraud prevention activities and has been ratified by the Public Sector Fraud Authority Prevention Panel, through which all fraud prevention data are scrutinised and assured.

Unchanged: Processing activities, Expected output, Expected measurable benefits.

DARS-NIC-736310-S6T1Z-v2.2 17 March 2025 to 16 March 2028
Title
NHSE UDAL- NHSCFA- For the purposes of the prevention and detection of crime.
Commercial
No
Sublicensing
No
Datasets
4
Files released
0

Datasets: Civil Registrations of Death; Demographics; Medicines dispensed in Primary Care (NHSBSA data); SUS - CFA (Counter Fraud Authority)_UDAL

What changed from DARS-NIC-736310-S6T1Z-v1.2

Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.

Fields changed from DARS-NIC-736310-S6T1Z-v1.2
FieldWasBecame
Start date2024-07-122025-03-17
End date2027-07-112028-03-16

Datasets: + Civil Registrations of Death; + Demographics; + Medicines dispensed in Primary Care (NHSBSA data)

Objective for processing

The NHS Counter Fraud Authority (NHSCFA) requires access to NHS England data [7 words unchanged] fraud and other criminal offences within the NHS. The NHS England data willl will support NHSCFA in determining if a rolling programme of exploratory analyses aiming to detect fraud across a range of identified concerns. The purpose of this analysis is to identify instances where there is a case for the commencement of a criminal investigation. investigation and/or to identify systemic weaknesses which can then be addressed by mitigating fraud risks inherent in the system (e.g. by changing policy). [4 paragraphs unchanged] • Civil Registrations of Death - This dataset complements a number of wide clinical and staffing datasets and will allow NHSFA to undertake proactive counter fraud analysis and can be utilised to support existing efforts to identify claims made for deceased persons and/or identity fraud in terms of employment. • Demographics - This dataset will enrichen wider datasets in use by NHSCFA to allow limited and controlled use of patient factors to identify and quantify fraud risks in the NHS across a wide range of recognised fraud risks - for example, by knowing patient age it will be possible to determine inappropriate or nonsensical treatments (for example, that for children or elderly patients). Using pseudonymised data in particular will make it possible to distinguish patients (as opposed to identify them) more widely over wider courses of treatments, to allow inappropriate claims to be detected; for example, duplicate or multiple claims across treatment, splitting of treatments (to maximise reimbursement), impossible timeframes or and misuse / inappropriate provision of controlled drugs. Additionally, linking to patient lists it will determine inappropriate list sizes. • Medicines dispensed in primary care - This dataset provides granular insight that can complement existing aggregated datasets accessed by NHSCFA and the granular format can address a number of identified system weaknesses linked to medicines, which includes identified issues in the drug tariff and detection of irregularities in dispensing which cannot be identified using the aggregated data. [6 paragraphs unchanged] Microsoft Limited are a processor acting under the instructions of NHSCFA. Microsoft's role is limited to secure backup of data stored at NHSCFA. [7 paragraphs unchanged] Microsoft Limited are a processor acting under the instructions of NHSCFA. Microsoft's role is limited to secure backup of data stored at NHSCFA.

Processing activities

[1 paragraph unchanged] NHS England will provide access to the relevant records from the SUS, Civil Registrations of Death, Demographics and Medicines dispensed in primary care datasets to the NHSCFA. The Data will contain no direct identifying data items. The Data will be pseudonymised and individuals cannot be reidentified through linkage with other data in the possession of the recipient. [9 paragraphs unchanged] For remote access: Remote processing will be from secure locations within England. - Remote access will only be from secure locations situated within the territory of use (as further restricted elsewhere within the DSA if so done) stated within this DSA; - Access controls granting users the minimum level of access required are in place; - Remote access is only via secure connections (e.g., VPNs or secure protocols) to protect data; - Multifactor authentication (MFA) is required for remote access; - Device security, including up-to-date software and operating systems, antivirus software, and enabled firewalls are utilised for the remote access; - All remote access is undertaken within the scope of the organisation’s DSPT (or other security arrangements as per this DSA) and complies with the organisation’s remote access policy. The above applies in addition to any condition set out elsewhere within the DSA (e.g. who may carry out processing, and for what purpose). [3 paragraphs unchanged] The Data will not be linked with any other data. The extracted subsets will be linked with other data only where such linkage is fundamental to the work intended to detect fraud. NHSCFA will not share data disseminated via the DSA with any third party other than as part of their investigation as forensic evidence evidence. [1 paragraph unchanged]

Expected output

[1 paragraph unchanged] The expected outputs of the processing will be: • Documented analyses supporting conclusions either giving assurance concerning the integrity of NHS business systems from fraud or identifying outliers and associated risks concerning potential NHS fraud.) • Specific fraud concerns drawn from the above that recommend commencement of criminal investigations , informing and supporting a more specific/targeted data share. • Recognition of overarching fraud risk/system weaknesses which can be addressed through wider activity (for example, through policy changes or provision of guidance) The above outputs will only contain aggregated/summarised information, with the potential for small examples of limited subsetted extracts of the data itself, only where explicitly necessary, to demonstrate the analysis itself or exemplify the wider findings . This will be produced in line with the relevant disclosure rules for the dataset(s) from which the information was derived . As this will be a rolling programme of analysis responding to concerns as they are identified, the frequency of outputs will vary according to the nature of the programme and complexity of individual analytical investigations.

Expected measurable benefits

[1 paragraph unchanged] The overriding benefits of reducing fraud and driving improvements and assurance in any system that protects the public purse is self-explanatory, particularly given the financial and reputational issues that fraud causes, and the areas of mutual interest in resolving it. The approach uses elements taken from recognised crime prevention models and data science frameworks that identify measurable fraud detection and prevention outputs which can be developed in collaboration with all participating organisations and showcased. Any outcomes associated with this project (whether legal repercussions or financial impact) can be collaboratively determined and their impact ultimately cited as the benefits of NHS England's and NHSCFA’s proactive and collaborative approach and hailed as demonstrative of the conjoined activity that mitigates fraud risks, deters fraudsters and drives savings that can support the treatment of patients. In terms of wider tangible benefits, the exercise has the opportunity to share a range of domain expertise between organisations and the ability to share approaches, findings and any recommendations with all parties. In doing, all participants can apply a degree of fraud expertise that’s drawn from their operational knowledge to support future work in this remit. [1 paragraph unchanged]

Benefits reported

NHSCFA only recently received access to UDAL, therefore at this stage, there are no yielded benefits to note. Analysis using SUS data within the UDAL has already gleaned significant savings, concerning coding practise for payments towards. NHSCFA analysis allowed identification and then quantification of areas of concern that allowed the provider to maximise financial gain by coding activity against higher complexity payments and wider irregularities in the way that it submits invoices. These irregularities include charging for the same patient under different contracts, charging multiple first attendances and charging activity incorrectly (separate appointments on the same day rather than grouped correctly). The NHS Counter Fraud Authority were able to use the data to highlight deliberate manipulation of the system and a separate investigation is underway to demonstrate a range of specific criminal offences being committed. In addition, NHSCFA have worked with NHS England throughout 2023 and 2024 to disrupt the fraudulent activity. This led to an intervention of changing the payment tariff which has given a saving of £18.9m from April 2023 to March 2024 and April 2024 to Sept 2024. This saving, alongside a wider projection of the impact of this work, was submitted to the Public Sector Fraud Authority Prevention Panel in January 2025, whose role is to formalise all fraud prevention savings. They have authorised recognition of £28m of current and projected savings for this intervention.

Objective for processing

The NHS Counter Fraud Authority (NHSCFA) requires access to NHS England data for the purpose of preventing and detecting fraud and other criminal offences within the NHS. The NHS England data will support NHSCFA in a rolling programme of exploratory analyses aiming to detect fraud across a range of identified concerns. The purpose of this analysis is to identify instances where there is a case for the commencement of a criminal investigation and/or to identify systemic weaknesses which can then be addressed by mitigating fraud risks inherent in the system (e.g. by changing policy).

This purpose is supported in the Directions to NHS Trusts and Special Health Authorities 2017 and the NHS Act 2006.

The NHSCFA, established under the NHS Act 2006, is mandated to prevent, detect, and investigate fraud, corruption, and unlawful activities within the English health service. The NHSCFA has been given the express function of the prevention, detection and investigation of fraud, corruption and unlawful activities against or affecting the health service in England. NHS bodies including Special Health Authorities (such as NHS England) are directed to cooperate with the NHSCFA and to enable the NHSCFA to efficiently and effectively carry out its functions as specified in paragraph 3(1)) of the NHS Counter Fraud Authority and supplemental directions 2017 (https://www.gov.uk/government/publications/nhs-counter-fraud-authority-and-supplemental-directions-2017).

The following NHS England Data will be accessed:

• Secondary Use Services (SUS) Episodes (Uncurated Low Latency Hospital Datasets) – necessary to conduct the necessary work to address several explicit problems highlighted by NHS England and other counter fraud organisations.

• Civil Registrations of Death - This dataset complements a number of wide clinical and staffing datasets and will allow NHSFA to undertake proactive counter fraud analysis and can be utilised to support existing efforts to identify claims made for deceased persons and/or identity fraud in terms of employment.

• Demographics - This dataset will enrichen wider datasets in use by NHSCFA to allow limited and controlled use of patient factors to identify and quantify fraud risks in the NHS across a wide range of recognised fraud risks - for example, by knowing patient age it will be possible to determine inappropriate or nonsensical treatments (for example, that for children or elderly patients). Using pseudonymised data in particular will make it possible to distinguish patients (as opposed to identify them) more widely over wider courses of treatments, to allow inappropriate claims to be detected; for example, duplicate or multiple claims across treatment, splitting of treatments (to maximise reimbursement), impossible timeframes or and misuse / inappropriate provision of controlled drugs. Additionally, linking to patient lists it will determine inappropriate list sizes.

• Medicines dispensed in primary care - This dataset provides granular insight that can complement existing aggregated datasets accessed by NHSCFA and the granular format can address a number of identified system weaknesses linked to medicines, which includes identified issues in the drug tariff and detection of irregularities in dispensing which cannot be identified using the aggregated data.

The level of the Data will be:

• Pseudonymised

The Data will be minimised as follows:

• Limited to the minimum Data required for the purpose of the work including any initial discovery work that is needed to ensure relevant data and data elements are appropriate to cover the problems identified.

• Limited to the activity period from April 2018 to the latest available data.

NHSCFA is the controller as the organisation responsible for ensuring that the Data will only be processed for the purpose described above.

The lawful basis for processing personal data under the UK GDPR is:

Article 6(1)(e) - processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

The lawful basis for processing special category data under the UK GDPR is:

Article 9 (2)(g) processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.

There are 23 conditions set out in paragraphs 6 to 28 of Part 2 of Schedule 1 of the DPA 2018, NHSCFA has determined that condition 14 (Preventing Fraud) aligns with their primary goal of preventing and detecting fraud and other criminal offences within the NHS and

Article 9(2)(j) - processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) based on Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.

The work is self-funded.

Microsoft Limited are a processor acting under the instructions of NHSCFA. Microsoft's role is limited to secure backup of data stored at NHSCFA.

Expected output

The outcome will provide either assurances concerning the integrity of NHS business systems from fraud or will identify outliers and associated risks concerning potential NHS fraud.

The expected outputs of the processing will be:

• Documented analyses supporting conclusions either giving assurance concerning the integrity of NHS business systems from fraud or identifying outliers and associated risks concerning potential NHS fraud.)

• Specific fraud concerns drawn from the above that recommend commencement of criminal investigations , informing and supporting a more specific/targeted data share.

• Recognition of overarching fraud risk/system weaknesses which can be addressed through wider activity (for example, through policy changes or provision of guidance)

The above outputs will only contain aggregated/summarised information, with the potential for small examples of limited subsetted extracts of the data itself, only where explicitly necessary, to demonstrate the analysis itself or exemplify the wider findings . This will be produced in line with the relevant disclosure rules for the dataset(s) from which the information was derived .

As this will be a rolling programme of analysis responding to concerns as they are identified, the frequency of outputs will vary according to the nature of the programme and complexity of individual analytical investigations.

Benefits reported

Analysis using SUS data within the UDAL has already gleaned significant savings, concerning coding practise for payments towards. NHSCFA analysis allowed identification and then quantification of areas of concern that allowed the provider to maximise financial gain by coding activity against higher complexity payments and wider irregularities in the way that it submits invoices. These irregularities include charging for the same patient under different contracts, charging multiple first attendances and charging activity incorrectly (separate appointments on the same day rather than grouped correctly).

The NHS Counter Fraud Authority were able to use the data to highlight deliberate manipulation of the system and a separate investigation is underway to demonstrate a range of specific criminal offences being committed. In addition, NHSCFA have worked with NHS England throughout 2023 and 2024 to disrupt the fraudulent activity. This led to an intervention of changing the payment tariff which has given a saving of £18.9m from April 2023 to March 2024 and April 2024 to Sept 2024.

This saving, alongside a wider projection of the impact of this work, was submitted to the Public Sector Fraud Authority Prevention Panel in January 2025, whose role is to formalise all fraud prevention savings. They have authorised recognition of £28m of current and projected savings for this intervention.

DARS-NIC-736310-S6T1Z-v1.2 12 July 2024 to 11 July 2027
Title
NHSE UDAL- NHSCFA- For the purposes of the prevention and detection of crime.
Commercial
No
Sublicensing
No
Datasets
1
Files released
0

Datasets: SUS - CFA (Counter Fraud Authority)_UDAL

What changed from DARS-NIC-736310-S6T1Z-v0.2

Text removed is struck through; text added is underlined. Unchanged paragraphs are summarised rather than repeated.

Fields changed from DARS-NIC-736310-S6T1Z-v0.2
FieldWasBecame
TitleFor the purposes of the prevention and detection of crime.NHSE UDAL- NHSCFA- For the purposes of the prevention and detection of crime.
Start date2024-04-172024-07-12
End date2024-08-162027-07-11

Objective for processing

The NHS Counter Fraud Authority (NHSCFA) requires access to NHS England data for the purpose of preventing and detecting fraud and other cinrimal criminal offences within the NHS. The NHS therefore pre-empting England data willl support NHSCFA in determining if there is a case for the potential commencement of a criminal investigation. [8 paragraphs unchanged] • Limited to the activity period from April 2018 to the latest available. available data. [1 paragraph unchanged] Microsoft Limited are a processor acting under the instructions of NHSCFA. Microsoft's role is limited to secure backup of data stored at NHSCFA. [3 paragraphs unchanged] Article 9 (2)(g) processing is necessary for reasons of substantial public interest, [32 words unchanged] measures to safeguard the fundamental rights and the interests of the data subject; and subject. There are 23 conditions set out in paragraphs 6 to 28 of Part 2 of Schedule 1 of the DPA 2018, NHSCFA has determined that condition 14 (Preventing Fraud) aligns with their primary goal of preventing and detecting fraud and other criminal offences within the NHS and [1 paragraph unchanged] The relationship between public sector fraud and “public interest” has been discussed at length in recent years and in particular, against the duty of confidentiality - to that end, the 2021 consultation by the Academy of Medical Royal Academies, supported by the National Data Guardian provides some useful insight (https://www.aomrc.org.uk/wp-content/uploads/2021/06/Disclosing_personal_demographic_data_0621.pdf) identifying that protecting the public sector from fraud supports disclosure and that effective protection of public services and effective management of the public purse in this circumstance falls within the public interest test (even where this breaches confidentiality). [1 paragraph unchanged]

Processing activities

[4 paragraphs unchanged] NHSCFA will create an analytical product from the data which will be [25 words unchanged] management and intelligence system for any subsequent case file submission to the CPS Crown Prosecution Service (CPS) or criminal / civil court. [2 paragraphs unchanged] Microsoft Limited providers cloud hosting services to NHSCFA and will store the data as contracted by NHSCFA. [16 paragraphs unchanged]

Benefits reported

Yielded Benefits is not a requirement for new applications. NHSCFA only recently received access to UDAL, therefore at this stage, there are no yielded benefits to note.

Unchanged: Expected output, Expected measurable benefits.

Objective for processing

The NHS Counter Fraud Authority (NHSCFA) requires access to NHS England data for the purpose of preventing and detecting fraud and other criminal offences within the NHS. The NHS England data willl support NHSCFA in determining if there is a case for the commencement of a criminal investigation.

This purpose is supported in the Directions to NHS Trusts and Special Health Authorities 2017 and the NHS Act 2006.

The NHSCFA, established under the NHS Act 2006, is mandated to prevent, detect, and investigate fraud, corruption, and unlawful activities within the English health service. The NHSCFA has been given the express function of the prevention, detection and investigation of fraud, corruption and unlawful activities against or affecting the health service in England. NHS bodies including Special Health Authorities (such as NHS England) are directed to cooperate with the NHSCFA and to enable the NHSCFA to efficiently and effectively carry out its functions as specified in paragraph 3(1)) of the NHS Counter Fraud Authority and supplemental directions 2017 (https://www.gov.uk/government/publications/nhs-counter-fraud-authority-and-supplemental-directions-2017).

The following NHS England Data will be accessed:

• Secondary Use Services (SUS) Episodes (Uncurated Low Latency Hospital Datasets) – necessary to conduct the necessary work to address several explicit problems highlighted by NHS England and other counter fraud organisations.

The level of the Data will be:

• Pseudonymised

The Data will be minimised as follows:

• Limited to the minimum Data required for the purpose of the work including any initial discovery work that is needed to ensure relevant data and data elements are appropriate to cover the problems identified.

• Limited to the activity period from April 2018 to the latest available data.

NHSCFA is the controller as the organisation responsible for ensuring that the Data will only be processed for the purpose described above.

Microsoft Limited are a processor acting under the instructions of NHSCFA. Microsoft's role is limited to secure backup of data stored at NHSCFA.

The lawful basis for processing personal data under the UK GDPR is:

Article 6(1)(e) - processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

The lawful basis for processing special category data under the UK GDPR is:

Article 9 (2)(g) processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.

There are 23 conditions set out in paragraphs 6 to 28 of Part 2 of Schedule 1 of the DPA 2018, NHSCFA has determined that condition 14 (Preventing Fraud) aligns with their primary goal of preventing and detecting fraud and other criminal offences within the NHS and

Article 9(2)(j) - processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) based on Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.

The work is self-funded.

Expected output

The outcome will provide either assurances concerning the integrity of NHS business systems from fraud or will identify outliers and associated risks concerning potential NHS fraud.

Benefits reported

NHSCFA only recently received access to UDAL, therefore at this stage, there are no yielded benefits to note.

DARS-NIC-736310-S6T1Z-v0.2 17 April 2024 to 16 August 2024
Title
For the purposes of the prevention and detection of crime.
Commercial
No
Sublicensing
No
Datasets
1
Files released
0

Datasets: SUS - CFA (Counter Fraud Authority)_UDAL

Objective for processing

The NHS Counter Fraud Authority (NHSCFA) requires access to NHS England data for the purpose of preventing and detecting fraud and other cinrimal offences within the NHS therefore pre-empting the potential commencement of a criminal investigation.

This purpose is supported in the Directions to NHS Trusts and Special Health Authorities 2017 and the NHS Act 2006.

The NHSCFA, established under the NHS Act 2006, is mandated to prevent, detect, and investigate fraud, corruption, and unlawful activities within the English health service. The NHSCFA has been given the express function of the prevention, detection and investigation of fraud, corruption and unlawful activities against or affecting the health service in England. NHS bodies including Special Health Authorities (such as NHS England) are directed to cooperate with the NHSCFA and to enable the NHSCFA to efficiently and effectively carry out its functions as specified in paragraph 3(1)) of the NHS Counter Fraud Authority and supplemental directions 2017 (https://www.gov.uk/government/publications/nhs-counter-fraud-authority-and-supplemental-directions-2017).

The following NHS England Data will be accessed:

• Secondary Use Services (SUS) Episodes (Uncurated Low Latency Hospital Datasets) – necessary to conduct the necessary work to address several explicit problems highlighted by NHS England and other counter fraud organisations.

The level of the Data will be:

• Pseudonymised

The Data will be minimised as follows:

• Limited to the minimum Data required for the purpose of the work including any initial discovery work that is needed to ensure relevant data and data elements are appropriate to cover the problems identified.

• Limited to the activity period from April 2018 to the latest available.

NHSCFA is the controller as the organisation responsible for ensuring that the Data will only be processed for the purpose described above.

The lawful basis for processing personal data under the UK GDPR is:

Article 6(1)(e) - processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

The lawful basis for processing special category data under the UK GDPR is:

Article 9 (2)(g) processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject; and

Article 9(2)(j) - processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) based on Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.

The relationship between public sector fraud and “public interest” has been discussed at length in recent years and in particular, against the duty of confidentiality - to that end, the 2021 consultation by the Academy of Medical Royal Academies, supported by the National Data Guardian provides some useful insight (https://www.aomrc.org.uk/wp-content/uploads/2021/06/Disclosing_personal_demographic_data_0621.pdf) identifying that protecting the public sector from fraud supports disclosure and that effective protection of public services and effective management of the public purse in this circumstance falls within the public interest test (even where this breaches confidentiality).

The work is self-funded.

Expected output

The outcome will provide either assurances concerning the integrity of NHS business systems from fraud or will identify outliers and associated risks concerning potential NHS fraud.

Benefits reported

Yielded Benefits is not a requirement for new applications.

Register history

When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds.

Cite this page

NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-736310-S6T1Z, “NHSE UDAL- NHSCFA- For the purposes of the prevention and detection of crime.”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-736310-s6t1z/ (accessed [date]).

This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.

Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-736310-S6T1Z to see the original rows.