Unofficial. This site is an experimental reformatting of data published by NHS England. It is not endorsed by NHS England. Always check the official Data Uses Register before relying on anything here.

Improving Resilience against cyber-attacks in Healthcare (iReACH)

Imperial College London · Academic

In term In term in the September 2026 edition: the latest version runs to 11 January 2027.

Reference
DARS-NIC-778927-P3D9Z
Current version
v0.2
Term of current version
12 January 2026 to 11 January 2027
Start date
12 January 2026
Data controller
Sole Data Controller
Commercial purposes
No
Sublicensing
No
Files released to date
0

Why the data was released

Objective for processing

The Data will be used for the purpose of a research project: Improving Resilience Against Cyberattacks in Healthcare (iReACH).

The Data will be used for the following objectives:

1. Mapping hospital connections and simulating cyberattacks

The researchers will use NHS data showing how patients move between hospitals to build a map of how hospitals are digitally connected. This helps them see how a cyberattack could spread across the NHS, not just hitting one hospital but potentially affecting many others through shared systems. HES data (ECDS, APC, OP; April 2022–March 2025) will be utilised to build a network of patient flows between NHS hospitals. Graph theory will map transfers, referrals, and shared care records, identifying interdependencies and critical nodes for potential cyberattack propagation.

2. Predicting A&E demand and patient choices

The researchers will create models to predict how busy each A&E department gets, and how patients (or ambulance services) decide which hospital to go to if their usual one is closed. These models take into account things like distance, waiting times, and hospital quality ratings to understand how demand shifts when services are disrupted. This will be achieved through analysis of HES ECDS data to model baseline demand at Type 1 A&E departments and predict patient redistribution during service closures. Discrete choice modelling, incorporating LSOA residence data and travel distances, will estimate determinants of hospital selection using robust econometric methods.

3. Designing smarter ways to redirect patients during attacks

Using advanced optimisation techniques, the study team will test strategies for redistributing patients across hospitals in the safest and fairest way during a cyber crisis. The end product will be a prototype tool that NHS cyber‑operations teams can use in real time to simulate hospital closures, see where patients would go, and plan how to avoid overwhelming certain hospitals. This will be achieved by combining outputs from Objectives 1 and 2 into an optimisation framework to design redistribution strategies during large-scale cyberattacks. Simulation-optimisation will account for stochastic demand and attack scenarios to minimise travel time, reduce overload risk, and ensure equitable access.

Processing activities

No data will flow to NHS England for the purposes of this Data Sharing Agreement (DSA).

NHS England will grant access to the Data via the Secure Data Environment (SDE). The SDE is a secure data and research analysis platform. It allows approved researchers with approved projects access to pseudonymised data and industry-leading analytics tools.

NHS England will provide access to the relevant records to Imperial College London via NHS England Secure Data Environment (SDE). The Data will contain no direct identifying data items. The Data will be pseudonymised and individuals cannot be reidentified through linkage with other data in the possession of the recipient.

SDE users can request exportation of aggregated analysis results (suppressed and summarised according to the NHSE SDE Disclosure Control rules) subject to review and approval by the NHS England SDE Output Checking team. The SDE Output Checking team will ensure that no output contains information which could be used either on its own or in conjunction with other data to breach an individual's privacy.

Users must identify themselves via a multi-factor authentication mechanism and are only able to access the datasets detailed within this DSA. The access and use of the system is fully auditable, and all users must comply with the use of the Data as specified in this DSA.

The Data will be stored on servers at NHS England.

The Data will be accessed by authorised personnel via remote access.

The Controller(s) must confirm and provide evidence upon audit by NHS England that access via any remote device complies with the data security obligations within this DSA and the Data Sharing Framework Contract.

For remote access:

- Remote access will only be from secure locations situated within the territory of use (as further restricted elsewhere within the DSA if so done) stated within this DSA;

- Access controls granting users the minimum level of access required are in place;

- Remote access is only via secure connections (e.g., VPNs or secure protocols) to protect data;

- Multifactor authentication (MFA) is required for remote access;

- Device security, including up-to-date software and operating systems, antivirus software, and enabled firewalls are utilised for the remote access;

- All remote access is undertaken within the scope of the organisation’s DSPT (or other security arrangements as per this DSA) and complies with the organisation’s remote access policy.

The above applies in addition to any condition set out elsewhere within the DSA (e.g. who may carry out processing, and for what purpose)

Expected output

The expected outputs of the processing will be:

A prototype for proof-of-concept interactive visualisation tool that DHSC leaders and NHS disaster recovery planners will be able to visualise and simulate closures of one or more hospitals, manage patient redistribution, adjust parameters such as capacity or travel thresholds, and identify facilities at highest risk of overflow.

Updates on study progress and final results will be developed into reports and shared with the Department of Surgery and Cancer, the Centre for Health Policy, and the Centre for Active Resilience and Security (CARS) at Imperial College London. Collaboration with these centres will support the production of appropriate reports for DHSC’s Cybersecurity and NHS Resilience teams, along with a simulated model and key recommendations to inform preparedness for large-scale cyberattacks.

Conferences: Findings will be presented at digital health forums, DHSC policy briefings, and national and international conferences focused on health informatics, operational research, cybersecurity in healthcare, and AI in medicine. Target conferences include CyberUK (NCSC) and Health Data Research UK events.

Peer-reviewed publications: Outputs will be submitted to high-impact journals in health informatics, healthcare operations, and cybersecurity, such as Nature Digital Medicine, Lancet Digital Health, and the European Journal of Operational Research. Anticipated submissions include:

• Network analyses of patient-sharing patterns across NHS hospital trusts

• Simulation studies of cyberattack propagation across NHS providers

• Predictive models of A&E demand and system resilience during provider outages

• Optimisation strategies for patient redistribution under multi-provider outage scenarios

Modelling algorithms will be generate, which will provide the simulation models in a packaged form for use and further development by national healthcare research teams within NHS England. These tools will help the NHS test different “what if” scenarios, plan ahead, and stay prepared for future cyberattacks that could disrupt hospital services.

The outputs will not contain NHS England Data and will only contain aggregated information with small numbers suppressed as appropriate in line with the relevant disclosure rules for the dataset(s) from which the information was derived. All outputs will undergo internal security classification review by a research team with expertise in cybersecurity and healthcare policy, including specialists from the Centre for Active Resilience and Security (CARS) with experience in critical infrastructure protection. Manuscripts, reports, presentations, and visualisations will be submitted to DHSC Cyber Security Operations and NHS England Resilience for classification prior to publication, with no materials released without formal approval.

The outputs will be communicated to relevant recipients through the following dissemination channels:

Workshops involving cyber resilience managers at a national and regional level.

• Journals

• Reports

• White paper

• open-access publications

• conferences

• Social media

• webinars

• Public reports

• Briefing documents provided to national leaders

Outputs from the project will be communicated with the UK government and national healthcare bodies (NHS England, DHSC) to Integrated Care Boards, individual hospital trusts, patients and the wider public. This will be communicated via meetings with the DHSC and Cyber Operations team and national conferences on cyber resilience.

Individual cybersecurity leaders in the NHS will be engaged with the outputs of the project such as simulation based interactive tool to monitor cyberattack propagations and strategically plan redistribution during cyberattack scenarios.

Expected measurable benefits

It is hoped that the prototype for proof-of-concept interactive visualisation tool will support three specific national functions:

• National preparedness planning: NHS England Resilience will use network vulnerability mapping to identify which hospital closures pose the greatest systemic risk, informing national critical infrastructure protection priorities and patient redistribution decisions.

• National incident response protocols: The optimisation framework will provide DHSC's Resilience unit with evidence-based patient redistribution strategies that can be activated during actual cyber incidents.

• Strategic capacity planning: NHS England regional teams will be able to use demand redistribution predictions to pre-position resources and establish mutual aid agreements between trusts based on predicted patient flow patterns during disruptions.

The findings will contribute to a better understanding of regional and national trends in health and care demand, highlighting hospitals and areas where dependencies and capacity pressures are most prevalent. This knowledge will support strategic planning of healthcare services, allowing resources to be allocated more effectively, reducing delays in urgent care, and ensuring equitable access to treatment across populations. The modelling of patient flows and hospital capacity will also provide mechanisms for identifying areas of best practice and highlighting vulnerabilities in the system that require attention, ultimately enhancing the quality and reliability of care.

This research is expected to generate significant public benefits by improving the resilience, responsiveness, and equity of NHS services, particularly in emergency care. By analysing patient mobility across hospital trusts and simulating the redistribution of A&E demand under cyberattack scenarios, the project will provide evidence-based insights that can inform decisions by policymakers, hospital administrators, and clinicians. These insights will help ensure that care is maintained safely and efficiently even when services are disrupted, directly improving patient experience and outcomes.

In the context of the UK Cyber Resilience Bill, which emphasises the importance of protecting critical national infrastructure (including healthcare systems) this research directly supports compliance by identifying vulnerabilities and informing strategies to strengthen cyber resilience in NHS services.

Outputs will be communicated to NHS stakeholders, policymakers, and the broader scientific community. Where appropriate, charities, patient advocacy groups, and professional societies will be informed of the results, ensuring that the knowledge generated is shared with organisations directly involved in patient care and health service planning. By making the outputs accessible and actionable, the project aims to support evidence-based improvements in the organisation, design, and delivery of healthcare services, ultimately benefiting patients and the wider public.

Benefits reported so far

Yielded Benefits is not a requirement for new applications.

Datasets on the current version

Legal basis for provision: Health and Social Care Act 2012 - s261(2)(d); Health and Social Care Act 2012 – s261(2)(a)

Datasets approved under DARS-NIC-778927-P3D9Z-v0.2
DatasetType of dataSensitivity FrequencyConfidential data
Emergency Care Data Set (ECDS) Anonymised - ICO Code Compliant Non-Sensitive System Access —
Hospital Episode Statistics Admitted Patient Care (HES APC) Anonymised - ICO Code Compliant Non-Sensitive System Access —
Hospital Episode Statistics Outpatients (HES OP) Anonymised - ICO Code Compliant Non-Sensitive System Access —

Files released

Files released counts only files released externally by DARS. Access granted in NHS England's own systems, such as its Secure Data Environment, is not included.

No files recorded as released under this agreement.

Version history

The register lists each renewal of this agreement as a separate row. This site has 1 version.

DARS-NIC-778927-P3D9Z-v0.2 12 January 2026 to 11 January 2027
Title
Improving Resilience against cyber-attacks in Healthcare (iReACH)
Commercial
No
Sublicensing
No
Datasets
3
Files released
0

Datasets: Emergency Care Data Set (ECDS); Hospital Episode Statistics Admitted Patient Care (HES APC); Hospital Episode Statistics Outpatients (HES OP)

Register history

When this agreement appeared in, or was edited in, each monthly edition of the register. Built by comparing every edition this site holds.

Cite this page

NHS England (2026) Data Uses Register, September 2026 edition, agreement DARS-NIC-778927-P3D9Z, “Improving Resilience against cyber-attacks in Healthcare (iReACH)”. Read via NHS Data Access Explorer (unofficial), https://healthdatauses.uk/agreements/dars-nic-778927-p3d9z/ (accessed [date]).

This address stays the same, but the page is rebuilt with each monthly edition, so the citation names the edition it shows. Every edition's data is kept in the facts store.

Source: datausesregister_september2026.xlsx, September 2026 edition of the NHS England Data Uses Register. Search that workbook for DARS-NIC-778927-P3D9Z to see the original rows.