You are here: Home Services & Applications NHSmail About NHSmail Safe and secure

Why is NHSmail secure?

NHSmail is the only NHS email service that is secure enough for the transmission of clinical data.

  • It is Government accredited to RESTRICTED status and approved for exchanging clinical information with other NHSmail and Government Secure intranet (GSi) users by the Department of Health and endorsed by the British Medical Association, Royal College of Nursing and Chartered Society of Physiotherapy
  • Using NHSmail instead of traditional paper and phone based processes speeds up communication, benefitting patients
  • Users can securely connect to NHSmail using encrypted mobile devices.  The NHSmail connection features an automatic timeout screen lock and remote wipe capability if the device is lost
  • Although emails sent via NHSmail are encrypted between the users' PC and the NHSmail service, only messages sent to other NHSmail users or GSi domains are guarranteed as secure
  • GSi domains that are secure for the exchange of patient data are: .x.gsi.gov.uk; .gsi.gov.uk; .gse.gov.uk; .gsx.gov.uk; .pnn.police.uk; .cjsm.net; .scn.gov.uk; .gcsx.gov.uk, .mod.uk

When sending clinical data users should adhere to their local information governance guidelines as well as the following:

  • Clinical data should only be sent to other NHSmail or GSi users.  Additionally it's important that local procedures are in place to safeguard the security of clinical data
  • Information relating to patients should be clearly marked and properly addressed.  The receiver should be ready to handle the information correctly and it should be stored securely.  Information can be sent to an individual or a controlled group
  • All users of NHSmail must comply with the Acceptable Use Policy presented to them when they register.