David Jobling
What the NHS Open Source Programme learned the hard way: putting code in a repository is the easy part.
Part of the OpenEyes Conference interview series, recorded on 16 September 2026 in Cardiff, UK.
What Open Source Alone Does Not Solve: Governance, Assurance and the Value Chain
You could create lots of little bits of software, but actually creating something that fundamentally makes a difference … was actually really difficult to do.
About David Jobling
David Jobling works with the Apperta Foundation and was involved in the NHS Open Source Programme from around 2016. He is also Managing Editor of the Digital Health Commons Forum.
Interview summary
The premise the NHS Open Source Programme started from, he says, was that open source would level the playing field with proprietary vendors, and that creating something and making it available would be the problem solved. He is direct that this proved untrue: you cannot put code in a repository and expect contribution to follow. Healthcare software needs governance, assurance, and a clinical safety position; it needs people who can judge whether the code is correct and whether it fits where the product is going. Across the first few years the programme produced many small pieces of software, and found that building something genuinely powerful and usable was far harder.
His account of why proprietary alternatives win is about perception rather than quality. A vendor product arrives packaged, with support and training, and is perceived as less risky - while nobody outside can see the code or what is done to it. Against that, open source was read as something done in a bedroom. The conclusion he draws is that the playing field had to be levelled on a different axis: build something packaged to the same standard, with the same support and assurance, but transparently. Open source stopped being the answer and became one component of a larger one, alongside standards, assurance, trademark and copyright.
That is how he explains the foundation's existence. It was created because NHS England recognised it needed an organisation that was not itself to lead this - an organisation that would outlast the politics. He describes the period as one of constant change in posts and priorities, with a different set of soundbites each week, and argues that something sitting between vendor and state is what has let the work survive a decade in which both would have reshaped it.
On OpenEyes he is clear about the order of events: the product existed before the foundation, developed at Moorfields with contributors elsewhere, already clinician-led and already open source. He does not know who made the licensing decision, and is careful not to overclaim its importance - the transfer would have been possible under another licence, though the open licence made it easier and let the wider community inspect what they were taking on.
The pattern he returns to is organisations mistaking their own value. An NHS trust builds something genuinely good and decides to sell it to other trusts; his response is that saving patients is their value, not maintaining, testing and assuring software, and that the work was publicly funded in the first place. What is worth preserving in those cases, he argues, is not the code but the thinking: the understanding of why it needed to work that way.
He gives a worked example of the limits of technical enthusiasm. During the Covid years, work on keeping people safely in care settings kept producing proposals for a dashboard that combined several clinical scores into one ranking. His position is that correlating a national early warning score against a sepsis score against another score, and ordering patients by the result, is not a technologist's decision to make - and that this is precisely what the governance layer is for: establishing that because something can be built quickly does not make it right.
On data he describes the aim as a common standard data model, so a patient's allergies or height are recorded once and read by every system that needs them, with different interfaces over the same layer. He is realistic about the obstacle: the NHS is a concept rather than an organisation, made of bodies funded differently and competing with each other, where an individual in post for two or three years has every incentive to choose the packaged option.
His sharpest framing is about what is actually being bought. There is no licence; what an organisation purchases is the services of the value chain - deployment, maintenance, and the ability to change the product. His analogy is commissioning an architect to build your house, and then being rented the house back, with the blueprints kept from you. In this model the community affects the change, which he says is why suppliers are held to account by users rather than only by contract.
Asked for the weaknesses, he names culture and two misconceptions: that open source means instant delivery, and that it is nearly free. Doing it properly - documentation, maintenance, testing, assurance - costs money, and while he argues it is cheaper over time, it is not free. He regards it as progress that the conversation has moved from explaining what this is to arguing about who pays for the documentation.
His wish for ten years is multiple custodians internationally, leading in their own regions, more products following the same route, and far more attention to outcomes. He is struck by how little is measured about whether a procedure made a difference to the patient, as against how many patients were seen within a target - and notes that an organisation strapped for cash does the tick-box measures it has been asked for.