Evidence method
Source hierarchy
- In-force legislation and official consolidated/amending text.
- Statutory codes, Information Standards Notices and regulator statements.
- Official NHS England, Department of Health and Social Care, National Data Guardian and Standards Directory publications.
- Current technical specifications and operational guidance from the responsible national body.
- Secondary commentary only as discovery input; it is not used to establish maintained claims here.
Claim classification
Each important statement is classified by:
- legal layer: data protection, confidentiality, sector power/duty, information standard, contract/policy, ethics, safety or assurance;
- purpose: individual care or beyond individual care;
- data dimensions: record identifiability, special-category status, and confidentiality/CPI status independently because they overlap;
- role: controller, joint controller, processor, manufacturer, deployer or recipient;
- jurisdiction: UK, England or another territory requiring validation;
- status: current, conditional, guidance under review, consultation, draft/future, or validation required.
Requirement vocabulary
- Mandatory: primary authority or an applicable ISN uses a binding requirement for the organisation/use case and the date has arrived.
- Conditional: mandatory only when the stated scope, role, data, purpose or technical use case applies.
- Guidance / ceiling: approved or active good practice without a demonstrated universal mandate.
- Future: Bill, consultation, draft, in-development or not-yet-commenced change.
- Validate: the generic source cannot decide the local facts.
“MUST” inside a technical specification can be a conformance rule for adopters without making adoption itself statutory.
Maintenance protocol
For substantive edits:
- open the primary source and confirm title, publisher, status, date and scope;
- update the source register, then the evidence matrix;
- revise synthesis and add unresolved points to the validation queue;
- update the standards dataset if applicable;
- run
npm run citations:update,npm run kb:update, andnpm run verify; - record the change in the research log.