Improvements to NHSMail – the national secure collaboration service for health and social care in England and Scotland – will beef up cybersecurity and save 40,000 hours-a-year in manual process work, according to a senior executive at NHS Digital.

Dan Jeffery, Head of Innovation, Delivery and Business Operations at NHS Digital’s Data Security Centre, has revealed how automation within NHSmail – a partnership between NHS Digital, NHS Scotland and Accenture – is likely to generate ‘millions of pounds worth of efficiency savings’.

In a blog post this week, Jeffrey outlined how the system – which manages the identities of all users within the Microsoft Active Directory in the NHS and allows local administrators to manage accounts within the NHSmail portal – has been upraded to allow for three workflow improvements, which will help alleviate the ‘significant burden on back offices across the NHS’.

Currently, NHS organisations manage local identities within their own Active Directory and use the NHS Electronic Staff Record for workforce management, including the on-boarding and off-boarding of employees. Local organisations have had to manually manage employees that join, move or leave their roles within NHSmail, as well as their local active directories and Electronic Staff Record.

Jeffrey wrote: “With more than 13,000 health and care organisations in England and Scotland using NHSmail and 64,000 movements of user accounts every month, the burden is real and the security implications relating to identity are acute. But that also means the opportunity for improvement is significant.”

Under the improvement plan, NHSMail will see the creation of:

1.  A new Joiners, Movers, Leavers (JML) product integrates the Electronic Staff Record, NHSmail, and local directory services. It automates the movement of user accounts between NHSmail organisations, the synchronisation of attributes and the commissioning and de-commissioning of local identities in the active directories.  When fully implemented, this process is expected to save around 40,000 hours a year, leading to millions of pounds worth of efficiency savings.

2.  A password synchronisation micro-service allows users to synchronise their password from the NHS Directory to their local active directory services and vice versa. This will also improve user experiences by delivering a same sign-on experience regardless of whether they authenticate for services against the NHS Directory or local Active Directory services. It will also improve cyber security by reducing the number of passwords users need to manage, reducing the temptation to store them in an insecure way – such as post-its with user-names and passwords written on them and stuck to desktop or laptop monitors.

  1. Behavioural and transactional analysis will allow us to identify patterns in user behaviour and associated digital transactions to help pinpoint anomalous events. For example, if a user attempts to authenticate a service from an unusual location or an odd time or date the service can block authorisation in case the account has been compromised.

The system has already been upgraded in the past year to include:

-Single sign-on for third party applications allowing digital services, from large national services to small start-ups, to use the NHS Directory as a trusted identity provider. This capability allows users to access services (for example Forward Health’s instant messaging) with their existing NHSmail account


-Multi-factor authentication (MFA) that introduces a second challenge when users sign-in. By adding the extra layer of identity security, we reduce the likelihood of intruders getting access. The capability is live across thousands of users and is available for local organisations to request for priority user groups.

-Intelligent enterprise password management and reset. The NHSmail Password Policy was updated in line with guidance from the National Cyber Security Centre (NCSC) and a new micro-service was launched to dynamically identify and block the use of common and compromised passwords using global intelligence. At the time of writing, we now stop around 100,000 weak passwords from being registered against NHSmail.

Jeffrey added: “These enhancements are complemented by continued filtering and monitoring of spam and malicious activity at the NHSmail gateway. On average, we stop about 500 million malicious events every three months. 

“There is still a lot more we can do to improve user experience and data security on the NHS’s communications systems. As part of our work to support the NHS Cyber Programme and deliver NHSX’s Tech Vision and Long-Term Plan, we will continue to work to improve cyber preparedness and capability while relieving pressure on local teams.”