Skip to main content
Download free report
Softblues
Softblues
Back to Blog
AI Strategy & Consulting
July 17, 20269 min read

AI Consulting for Healthcare: Choosing a UK Partner Who Understands the NHS and CQC

Just over half of NHS trusts have invested in AI, yet many partners have never read a clinical-safety standard. How to choose a healthcare AI consulting partner who understands NHS and CQC rules.

AI Consulting for Healthcare: Choosing a UK Partner Who Understands the NHS and CQC

By Ivan Pylypchuk, CEO of SoftBlues. Has led Claude implementations for finance, legal and healthcare teams across the UK and Ireland.

Healthcare AI consulting means hiring a partner to plan, build and run AI inside a clinical or care setting, under the rules that govern the NHS and CQC-registered providers. A good partner proves four things: clinical-safety competence (DCB0129 and DCB0160), data governance under UK GDPR, integration with the systems you already run, and change management with the clinical staff who have to use it. Choose on evidence of all four, not on a demo.

At SoftBlues, an AI consulting firm working with regulated mid-market organisations across the UK and Ireland, we spend most of a healthcare project on the parts that never show up in a demo: the hazard log, the data-flow map, and the sign-off from a clinician who is accountable for patient safety.

The demand is real. Just over half of NHS trusts (52%) have already invested in AI, and 62% of NHS decision makers rate AI as very important or critical to care delivery over the next three to five years (Healthcare Management UK survey, 2025). That pull is drawing in consultancies who understand AI but have never read a clinical-safety standard. In healthcare, that gap is where projects stall or, worse, cause harm.

Key facts

  • Healthcare AI consulting is the work of scoping, building and deploying AI in a clinical or care setting under NHS and CQC rules, not generic AI advice with an NHS logo on the deck.
  • Two clinical-safety standards apply to health IT in England: DCB0129 (for the manufacturer or builder) and DCB0160 (for the deploying organisation). Both require a named clinical safety officer and a hazard log.
  • 52% of NHS trusts have invested in AI; 62% call it critical to care in the next three to five years (Healthcare Management UK, 2025).
  • If the tool makes or informs a clinical decision, it may be a medical device regulated by the MHRA. That question belongs at the start of a project, not the end.
  • Data governance runs on UK GDPR, the ICO framework, and the NHS Data Security and Protection Toolkit. A partner who cannot name these is not ready for healthcare.
  • A credible engagement is staged: discovery and clinical-safety scoping first, a narrow proof of concept second, production rollout only when the hazard log and governance are in place.
  • Who this is for, and who it isn't

    This is for a decision maker at an NHS trust, a private clinical group, a care provider, or a health-tech company building a clinical product, choosing a partner for a first serious AI deployment. It is written for the person who will have to answer to a Caldicott Guardian, a CQC inspector, or an information governance lead.

    It is not for a team wanting a marketing chatbot with no clinical data, or a founder after a weekend prototype. Those are real jobs, but they do not need the clinical-safety scaffolding this article is about, and paying for it would be waste.


    Why choosing a healthcare AI partner is different

    In most sectors, a failed AI pilot costs money and time. In healthcare it can cost a patient. That single fact changes the whole selection process.

    A generalist AI consultancy optimises for accuracy and speed. A healthcare-literate partner optimises for those too, but starts from a different question: what happens when the model is wrong, and who is accountable when it is? That is the logic behind DCB0129 and DCB0160, the clinical-safety standards for health IT in England. They ask you to list every way the software could contribute to harm, rate it, and put controls in place before go-live, with a named clinical safety officer signing it off.

    A partner who has never produced a hazard log will not know to build one. You will find out during a CQC inspection or an incident review, which is the most expensive possible time to learn.

    Important
    Ask any prospective partner to show you a redacted hazard log from a previous project. If they cannot, they have not worked to DCB0129, whatever the deck says.

    What a healthcare AI consultant should actually do

    The real work is four things, in this order. Judge a partner on evidence of each.

    1. Prove clinical safety. They produce a clinical-safety case to DCB0129 and support your DCB0160 duties, appoint or work alongside a clinical safety officer, and maintain a live hazard log through the project. They also flag early whether the tool is a medical device under MHRA rules, because that changes the whole compliance path.

    2. Get the data governance right. They map every data flow, complete a Data Protection Impact Assessment, work within your Data Security and Protection Toolkit position, and design for data to stay in your tenant. For UK healthcare that usually means processing in a UK or EU region under UK GDPR, with the ICO framework as the reference, not a US cloud default.

    3. Integrate with what you run. AI that cannot reach your EPR, your PAS, or your booking system is a science project. A serious partner scopes integration honestly and tells you where a system's limits will slow the work.

    4. Manage the clinical change. The best model fails if clinicians do not trust it or cannot fit it into a ten-minute appointment. Change management with front-line staff is not a nice-to-have here. It is the difference between a tool that gets used and one that gets switched off in a fortnight.

    What does healthcare AI consulting cost?

    Cost depends on the stage and the number of systems and pathways involved, not on a headline day rate. Treat it as a staged spend, where each stage has to earn the next.

    Engagement stageWhat it coversWhat drives the cost
    Discovery and clinical-safety scopingUse-case selection, data-flow map, initial hazard log, integration assessmentNumber of pathways and systems in scope
    Proof of conceptOne workflow built and tested against real (governed) data, hazard log developedData access, integration count, sign-off complexity
    Production rolloutIntegration, training, monitoring, ongoing supportSystems integrated, number of users, monitoring needs

    For day-rate and project-fee ranges across the UK market, see our guide to AI consulting costs in the UK. We work to a fixed price per stage so that clinical-safety and governance work is scoped in, not billed as a surprise.

    How long does it take?

    Discovery and scoping usually run over a few weeks. A narrow proof of concept can follow in a matter of weeks once data access and governance sign-off are in place, which is often the real bottleneck. Production rollout depends on integration and training, and should not be rushed. A partner promising a clinical deployment in days is either skipping the safety work or has not done it before. Our broader view on moving safely from trial to live is in the AI implementation roadmap.

    Generalist AI consultancy or a healthcare-literate partner?

    Both can build a good model. Only one is set up for a regulated clinical setting. This is the comparison to run before you sign anything.

    Generalist AI consultancyHealthcare-literate partner
    Starting questionHow accurate can we make it?What happens when it is wrong, and who is accountable?
    Clinical safetyRarely addressedDCB0129/0160, named safety officer, hazard log
    Data governanceGeneric GDPRUK GDPR, DSP Toolkit, DPIA, data stays in tenant
    Medical-device riskOften missedAssessed against MHRA rules at the start
    Best forNon-clinical back office, marketing contentAny tool that touches patient data or clinical decisions
    Avoid ifThe tool touches clinical careYou only need a non-clinical prototype

    What it looks like under NHS and CQC rules

    A worked example. In pharmacy operations, we built an eight-agent pipeline to check prescriptions against safety and compliance rules, cutting a review that took 15 to 20 minutes down to seconds in testing. That work is a validated proof of concept moving to beta, not a live production system, and we are careful to say so. You can read the full write-up in our AI pharmacy operations case study.

    For clinical research, we built a nine-agent pipeline that turns a plain-English research question into a publication-ready analysis, compressing work that has taken twelve to eighteen months into weeks. That platform is in beta. The detail is in our clinical research platform case study.

    In both, the model was the easy part. The work that made them credible for healthcare was the governance around them: where data sits, what the human still signs, and what the system does when it is unsure.

    💡Tip
    For a wider view of where AI is genuinely useful in a clinical setting, see our overview of the top AI use cases in healthcare.

    Red flags when choosing a partner

  • They cannot name DCB0129, DCB0160, or the DSP Toolkit.
  • They promise a clinical deployment in days.
  • They have no answer for where patient data is processed and stored.
  • They treat the MHRA medical-device question as an afterthought.
  • They show accuracy figures but no hazard log or clinical sign-off.
  • Every reference is non-clinical, or they will not give you a healthcare reference at all.
  • Questions to ask on the call, and what a good answer sounds like

    "Who is your clinical safety officer, and can I see a redacted hazard log?" A good answer names a person and shows a real, redacted log. Silence here is the answer.

    "Where will our patient data be processed and stored?" You want a UK or EU region, in your own tenant where possible, with UK GDPR and the DSP Toolkit named without prompting.

    "Is what you are building a medical device?" A good partner has already asked this and can explain how they assessed it against MHRA guidance.

    "What does the human still decide?" In healthcare the answer should never be "nothing". A credible partner designs the clinician back into the loop by default.

    Before you send anything to a shortlist, our AI vendor security questionnaire and our 12-point buyer's checklist give you the rest of the questions to ask.

    Frequently asked questions

    What is healthcare AI consulting?

    It is the work of planning, building and deploying AI inside a clinical or care setting under the rules that govern it, including NHS clinical-safety standards, CQC expectations, and UK data-protection law. It is different from general AI consulting because clinical safety and governance sit at the centre, not the edge.

    Do we need to follow DCB0129 and DCB0160?

    If you are building or deploying health IT in England, these clinical-safety standards apply. DCB0129 covers the manufacturer or builder; DCB0160 covers the organisation deploying the system. Both require a named clinical safety officer and a hazard log. Your information governance or clinical-safety lead can confirm your exact obligations.

    Is our AI tool a medical device?

    It might be. If the software makes or directly informs a clinical decision, it can fall under MHRA medical-device rules. This should be assessed at the start of a project, because it changes the compliance and evidence path. This is a regulatory question for your compliance team, not something to guess at.

    Where should patient data be processed?

    For UK healthcare, data should normally be processed and stored in a UK or EU region, ideally within your own tenant, under UK GDPR and the NHS Data Security and Protection Toolkit. Avoid partners who default to a US cloud without discussing this.

    Can we start small?

    Yes, and you should. A narrow proof of concept on one workflow, with governance in place, tells you far more than a broad rollout and costs a fraction to correct if it is wrong. Every stage should earn the next.

    How is Claude relevant to healthcare AI?

    Claude can run the clinical and back-office reasoning in these systems, and it can be deployed so that data stays in your own governed environment. The point is not the model on its own; it is the safety, governance and integration built around it, which is where most of the real work sits.

    What if we are a Microsoft 365-native trust?

    Then part of your answer may be Microsoft Copilot for everyday productivity, and a governed Claude deployment for the clinical reasoning where accuracy and control matter most. An honest partner will tell you where each tool fits rather than sell you one for everything. Our comparison of ChatGPT Enterprise, Claude Enterprise and Microsoft Copilot lays out the trade-offs.
    SoftBlues is a registered Anthropic Partner Network member and a Google Cloud Partner. We are practitioners, not slide-writers: we run AI in production ourselves before we recommend it, and in healthcare we start from clinical safety and data governance rather than the demo.

    If you are choosing a partner for a clinical or care deployment and want to pressure-test your shortlist, book a discovery call.

    See it in production

    Systems we have built and run for clients, with the numbers that came out of them.

    Browse all case studies

    Related Articles