Digital & Innovation Services (D&I)

About Us

University Hospitals Plymouth NHS Trust’s Digital & Innovation department (D&I) provides ICT support and services to more than 11,000 users across multiple organisations in the Plymouth Health Community, including:

Our service is designed using ITIL® methodologies and projects are managed in accordance with PRINCE2. D&I is a multi-discipline department consisting of over 300 employees with a range of teams.

 

UHP Digital Strategy 

 UHP Digital Strategic Intent [pdf] 770KB

 

Senior Management Team

  • Kath Potts - Chief Digital Officer 

  • Mandy Stewart - Chief Business & Governance Officer

  • Katie Greenhill - Chief Support Officer and Head of Health Records

  • James Barrett - Chief Technology Officer

  • Simeon Brundell - Chief Clinical Information Officer (CCIO)

  • Sarah Dormor - Chief Nurse Information Officer (CNIO)

  • Mark Catolico - Chief Medical Information Officer (CMIO)

Contact us: plh-tr.dibusinessservices@nhs.net

 

Electronic Patient Record (EPR)

Find more information about our Electronic Patient Record (EPR)

 

Artificial Intelligence (AI)

Artificial Intelligence (AI) is the use of digital technology to create systems capable of performing tasks commonly thought to require human intelligence. At University Hospitals Plymouth NHS Trust, we are embracing and supporting the introduction of appropriately regulated and governed uses of AI related technologies to address our clinical and business needs.

As AI continu es to take centre stage, we will make sure our use of AI is fair, explainable, and secure. The public have both a legal right and a reasonable expectation that their personal data will be handled in compliance with data protection law and treated with appropriate care.

Our AI policy focuses on the governance and safe use of AI, preventing any use without strict checks on Cyber Security, Ethics, Technical conformity and Information Governance. Artificial Intelligence Policy

Some of our AI Principles:

  •           We will be inquisitive and open to the new advancements in Artificial Intelligence and the potential efficiency and clinical benefits it can offer.
  •           All individuals must have equal access to the services and opportunities provided by AI systems. AI should not create barriers or restrict access based on discriminatory factors.
  •           All recommendations made by AI must be subject to human review (Human-in-the-loop). No Generative AI is allowed to be used for any clinical decision-making or direct patient care, or any activity requiring clinical judgement. We will not carry out any automated decision making 
  •           People - not machines - must be accountable for communications outputs. AI tools should be used to augment professional judgement, not replace it.

Our Current Use of AI:

  •           Microsoft Copilot is the Trust-approved and recommended Generative AI solution and is protected by the same security and data protection controls as Microsoft 365. No information is ever shared outside of our NHS version of Microsoft or used to train AI.
  •           Brainomix - Used to interpret scans and identify the most appropriate stroke treatment for patients.
  •           GE Apex - Metal artefact image reconstruction algorithm.
  • QCT Qure.ai - CT Chest AI lung nodule detection and analysis ( Read the news article: New AI tool is helping in the treatment of lung cancer from Peninsula Diagnostic Network ).  
  • Github Copilot - AI Coding assistant used with some of our internal Software Development.

Managed Print Service (MPS)

University Hospitals Plymouth’s Managed Print Service (MPS) is managed by Ricoh UK.

Toner logistics are managed centrally; this central store then delivers toner to the individual printers. Except in a very few situations, printers are set up to pull print via “follow me printing”.  This requires the user to log in to a printer and collect their prints as required. Colour printing is restricted.

 

Contract Details

The purchasing activities of University Hospitals Plymouth NHS Trust’s D&I Department are conducted in accordance with UK laws, regulations, and directives, as well as the Trust’s Standing Financial Instructions. All purchase orders are issued with a focus on achieving value for money.

UHP uses the central NHS tendering portal, Atamis, for above threshold tendering activities. If you are not already registered on this platform, we recommend that you do so in order to receive tender notifications and stay informed about future opportunities.

 

NHS.net Connect

For FOI requests regarding our email system, please be advised that the Trust uses NHS.net Connect provided by NHS England. Visit NHS England’s NHS.Net Connect page for further information about the service

 

Cyber security and the Freedom of Information Act 2000

For more information, visit our Freedom of Information page

University Hospitals Plymouth NHS Trust has, following careful consideration of its experts, concluded that it will refuse requests that ask about cybercrime events or ask for information that assists criminals.

The Trust, following a public interest test considers such information exempt from supply in compliance with both:

  • section 31.-(1)(a) the Law enforcement exemption about the prevention and detection of crime

  • section 38-(1) (a) and (b) the Health and Safety exemption

Additionally, the Trust will neither confirm nor deny it holds information in compliance with sections 31.(3) and 38(2). This is because the revealing of facts enables others to utilise such data to identify weaknesses or strengths. Please refer to our rationale.

All future requests for similar information will be referred to this statement and considered exempt from supply in accordance with section 21.-(1) - information accessible by other means. This avoids the need for repeated responses that are substantially the same.

 

Our rationale

The Trust seeks to be an open organisation and makes much non personal information available to the public as possible, however it will not jeopardise the care of its patients and staff if making information public put them in danger. 

These exemptions apply because disclosing details of our security arrangements could prejudice the security and integrity of the Trust’s network and increase the risk of unauthorised access to information held by the Trust, much of which is confidential and sensitive.  The level of detail that would be released would enable external parties, who are not privy to the confidential aspects of Trust’s IT systems, knowledge of our security equipment and by association its integrated network security.  The Trust employs a range of security tools to mitigate the risk from different types of security threats.  Firewalls, Intruder Detection Devices Antivirus and other products form a mesh of security that protects the Plymouth NHS Network and data, the more of these vectors that are known, the weaker the security of the network protection.  There is a real risk that this knowledge could assist external parties in attempting a cyber-attack/hack into the Plymouth NHS Network.  The anticipated harm from this is a breach of data protection (failure to adequately protect information resulting in an unauthorised disclosure), data loss, and disruption to patient care through a loss of IT services.  The severity of harm is extensive with millions of patient records put at risk of unauthorised disclosure.

Systems failure endangers the physical or mental health and safety of patients and staff. Examples were frequently reported throughout the media following the WannaCry attack on various parts of the NHS and other organisations. The impact on the NHS has since been the subject of further investigations by both the press and educational institutions and their findings validate the approach we have taken.

 

Future requests

The Trust has consistently applied both section 31 and 38 to all “Right to know” requests received this financial year and will do so in the future.  The responses to such questions are displayed within the Trust’s disclosure log.  To avoid processing substantially similar requests, we will refer any new applicants to this standard explanation, when applicable. 

Those with legitimate business enquiries should contact the ICT’s Procurement team using this email address: plh-tr.dibusinessservices@nhs.net rather than make Freedom of Information Act requests. 

If you are unhappy with this approach, you have the right to complain.  This should be in writing to the address below or preferably by email to plh-tr.foi-requests@nhs.net.  We will then arrange for an independent appeal.

University Hospitals Plymouth NHS Trust
Freedom of Information Manager
Information Governance Team
Ground Floor, Brittany House
Brest Road
Plymouth
PL6 5YE

If you remain dissatisfied with the outcome of the appeal, then you have the right to appeal again to the Information Commissioner at:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Visit the Information Commisioner's Office make a complaint page

Tel: 0303 123 1113

Updated 10/09/2026

Was this page helpful?

Was this page helpful?
Rating

Please answer the question below, this helps us to reduce the number of spam emails that we receive so that we can spend more time responding to genuine enquiries and feedback. Thank you.

*