Skip to content

10 Year Health Plan and digital-first implications

Bottom line

The 10 Year Health Plan for England sets strategic direction. It does not itself create a lawful basis, confidentiality gateway, general right of access to GP records, contractual term, or statutory information-standard mandate. Its three shifts—hospital to community, analogue to digital, and sickness to prevention—must be translated into current law, regulations, contracts, scoped standards, commissioned services and assured technical products before they become operative requirements. SRC-041

The Chapter 3 analogue-to-digital commitment map provides the detailed named-tool, delivery-status and implementation-gate analysis; this page remains the cross-cutting policy-to-authority synthesis.

As at 27 July 2026:

  • the current primary-care digital floor is mainly found in the applicable GMS/PMS/APMS contract or variation, regulations and directions—not in the Plan;
  • “digital-first” is multi-channel, not digital-only: online, telephone and in-person routes remain available during core hours, with paper or assisted routes where specified;
  • the NHS App has live functions, but its roadmap distinguishes delivered capability from work in progress and does not represent every Plan commitment;
  • the Single Patient Record (SPR) remains an early-stage programme supported by a Bill that has not received Royal Assent;
  • shared-care records, GP Connect, the Federated Data Platform (FDP), SPR and the Health Data Research Service (HDRS) are different products or programmes with different purposes and governance;
  • every proposed data flow still passes the minimum-to-maximum requirement model and the sharing route decision workflow.

Authority and delivery ladder

Layer What it can establish What it cannot establish by itself
Current law and regulations Statutory functions, powers, duties, safeguards and regulatory terms. That a planned national capability is live or technically available.
Current practice contract, direction or variation Binding operational duties for the organisations and contract types in scope. A duty on every recipient, supplier or other provider; a new confidentiality or data-protection authority.
Section 250 Information Standards Notice A scoped information-standard requirement, with the organisations, use cases and dates stated in the notice. Universal application outside that scope; a lawful purpose for a disclosure.
Section 259 collection direction A scoped duty to provide specified data to NHS England. A patient-facing service requirement or general clinical-record exchange permission.
Planning framework or commissioning instruction Accountable delivery expectations for the named organisations and planning period. A new GP contractual term or a general legal gateway.
Product specification and assurance gate Conditions for connecting to or safely deploying a product. Legal authority to share, proof that the product is nationally live, or proof every feature is enabled locally.
Policy plan, roadmap or programme page Direction, intended outcomes, milestones and programme status. Present law, a blanket mandate, or evidence that an ambition has been delivered.

This ladder is cumulative: a future programme can require legislation, a current contract can require technical enablement, and an actual disclosure can still fail because its purpose, confidentiality route, access model or safeguards are not justified.

How “digital first” evolved

Period Maintained interpretation
2019 The NHS Long Term Plan described a digital-first primary-care option alongside face-to-face care and set a 2023/24 ambition. The associated consultation and five-year framework were policy and delivery lineage, not enduring standalone authority. SRC-046
2021–2025 Successive contract changes embedded specific duties: online consultation and secure communications, video where appropriate, directly bookable appointments, prospective record access, core-hours online requests and GP Connect enablement. The current contract consolidates the operative position. SRC-047 SRC-048 SRC-049
July 2025 The 10 Year Health Plan made analogue-to-digital one of three strategic shifts and set an ambition for the NHS App to become a fuller front door by 2028. SRC-041
2026–2029 The Medium Term Planning Framework turns selected Plan commitments into system and provider planning expectations, while NHS England’s digital-by-default material describes the transformation programme. Their exact addressee and service scope must be preserved; an acute-provider or ICB expectation must not be silently transposed onto a GP practice. SRC-044 SRC-045
2027 onward NHS Online is expected to begin as an optional specialist-care service from 2027; it is not a current nationwide entitlement. SRC-059
2028 onward NHS App and SPR dates are programme ambitions or expected delivery points unless a then-current instrument, contract or standard makes a scoped obligation operative. SRC-043 SRC-050
flowchart TD
  A["10 Year Health Plan: strategic direction"] --> B["Current law, regulations and confidentiality"]
  A --> C["Current contracts and planning instructions"]
  A --> D["Future Bill, regulations and standards"]
  B --> E["Flow-specific authority and safeguards"]
  C --> F["Scoped service and technical duties"]
  D --> G["Track; do not use as present authority"]
  E --> H["Assured implementation"]
  F --> H
  H --> I{"Canonical URL, product and local workflow actually ready?"}
  I -- "No" --> J["Do not claim delivery; remediate or retain another channel"]
  I -- "Yes" --> K["Approve, monitor and revalidate"]

What the three shifts mean for primary-care data

Strategic shift Likely data implication Required boundary
Hospital to community More neighbourhood multidisciplinary working, referrals, transfers, shared-care views, care plans and remote monitoring. A care relationship does not give every team the whole GP record. Apply role, purpose, best-interests, objection, identity, audit and applicable content/transport standards.
Analogue to digital NHS App access, online requests, messaging, booking, record access, virtual consultations, structured APIs and an eventual SPR. Digital access does not replace telephone/in-person support, create sharing authority, prove capability or turn patient-facing access into clinician access.
Sickness to prevention Population-health management, risk stratification, wearable/patient-generated data, proactive care, research and AI-assisted pathways. Separate individual care from planning/research and automated-risk purposes; re-run necessity, confidentiality, opt-outs, DPIA, transparency, bias and clinical-safety analysis for each.

The Plan’s impact and equality assessments explicitly identify maturity, legacy integration, vendor lock-in, cybersecurity, data quality and digital-exclusion risks. These are programme-risk evidence, not substitutes for a local DPIA, equality analysis, clinical-safety case or benefits assessment. SRC-042

Current primary-care minimum

The current standard 2026/27 GMS contract is the strongest general operational baseline for GMS practices. A real decision must still check the practice’s actual GMS, PMS or APMS terms and every local variation. SRC-047

Area Current floor or distinction
Access channels In-person, telephone and online-consultation routes are available throughout core hours. Digital does not extinguish the other routes.
Online demand and response The tool must not limit request numbers during core hours. Separately, the contractor must not ask a patient to contact the practice on another day. This does not create unlimited appointments or a universal same-day-appointment entitlement: clinically urgent requests require the contractually specified urgent response, while nonurgent matters require an appropriate response by the end of the next working day.
Registration The NHS-specified form and NHS online registration service must both be available. For a form application, practice staff must submit the details through the online service except where the clinical system does not facilitate interconnectivity; supplementary guidance also preserves non-digital and assisted routes.
GP Connect Provider-side Access Record HTML/Structured and Update Record configuration is a contractual enablement duty in scope. It is not a universal consumer entitlement and does not relax direct-care purpose, assurance, preference or access-control rules.
Patient record access Automatic prospective access is provided through approved patient-facing services from the applicable date, subject to safeguarding, third-party confidentiality, data-protection, patient-choice and technical exceptions. A written request for access to remaining relevant digital medical information is separate, depends on system capability, and excludes already-accessible and excepted information.
Booking and prescriptions Directly bookable appointments are made available online as well as by telephone or in person; online prescription and appointment functions are promoted.
Communications and video Secure electronic communications are offered and video is offered where clinically and contextually appropriate.
Software Relevant software must meet applicable GP IT operating-model or equivalent requirements. Product assurance does not create authority for a data flow.

NHS England’s supplementary material is useful interpretation, but expressly does not create a new requirement; the contract, regulations, directions and local terms control. SRC-048 NHS digital-requirements guidance explains the lineage but should not replace clause-level checking. SRC-049

Five distinct data routes

Do not use “NHS App”, “single record” or “digital platform” as a purpose.

Route Typical actors Core decision
Patient access to their own GP record Practice as controller, patient, GP system, approved patient-facing service including the NHS App Automatic prospective versus written-request remaining-record scope; system capability; already-accessible/excepted information; serious-harm and third-party redaction; child/proxy access; identity; correction and transparency. SRC-051
Direct-care professional access GP practice, NHS or assured commissioned care provider, shared-care/GP Connect product, or approved local FDP direct-care product Current care relationship, best interests, objection, role-filtered minimum necessary view, audit and clinical safety.
Transactional service access Booking, prescription, referral, messaging, registration or consultation services Exact function, contract/specification, identity, availability, accessibility, failure and fallback handling.
Operational and planning use Provider/ICB teams, an FDP operational/population-health product or another analytics environment Controller purpose, minimum/pseudonymised data, separation from care access, transparency, opt-out and processor/platform governance. SRC-058
Research and broader secondary use Approved researchers, HDRS or other data-access environment Existing statutory/lawful/confidentiality route, approvals, opt-outs, secure access, output controls and public transparency. The programme is not the lawful basis. SRC-060

Patient-generated and wearable data can cross several routes: information submitted for a clinical episode may become part of direct care, continuous monitoring may create a new clinical service, and reuse for model development or research is a separate purpose. “Patient chose to upload” is not a blanket consent to every downstream use.

NHS App: current capability versus roadmap

The NHS App is a patient-facing access channel and integration platform. The current technical specification describes integrations with GP systems and national services, while the roadmap separates recently delivered work from work under way or planned. The roadmap also warns that it is the App team’s view, not a complete schedule for every 10 Year Plan commitment. SRC-050

For each proposed App-dependent flow, verify:

  1. the feature is live for the relevant cohort, supplier and geography;
  2. the accountable controller and processor chain for that function;
  3. the exact record content, date range and visibility rules;
  4. NHS login, proxy/delegated-access and child-transition behaviour;
  5. the redaction, serious-harm, third-party and domestic-abuse safeguards;
  6. correction, support, incident and non-digital fallback routes;
  7. the applicable integration, accessibility, clinical-safety, medical-device, security and data-protection gates. SRC-051 SRC-064

Twenty-four-hour availability of an App function does not mean a GP practice owes a 24-hour clinical response. A roadmap entry does not prove a local supplier has enabled it.

NHS Notify and App-first messaging

The supplied NHS Notify strategy page restates the 2025/26 expectation that providers use NHS App-first messaging through NHS Notify while avoiding digital exclusion. The current planning evidence is now the 2026/27–2028/29 Medium Term Planning Framework: for 2026/27 it tells all ICBs to transition primary-care messaging to NHS Notify with NHS App push as the default; it separately expects acute, community and mental-health providers to begin moving all direct-to-patient communications in 2026/27 and complete by the end of 2028/29. These are planning requirements for the named addressees, not a section-250 information standard or an automatic clause in every GP contract. SRC-044 SRC-076

Decision point Maintained position
Live service and route NHS Notify is a live Gold service. A connecting party sends NHS numbers and message details through the production API or MESH; NHS Notify resolves contact details through PDS, filters restricted, invalid and deceased records, then uses NHS App, email, SMS or letter according to the configured message plan. Onboarding, templates, testing and a connection route are still required.
Authority and roles The 2025 Directions require NHS England to operate the service and support NHS England’s controller role for that operation. The sending organisation remains an independent controller for its purpose, recipients, content, timing and channels and must establish its own data-protection and confidentiality route, DPIA, transparency, preference/objection handling and applicable opt-out result. The Directions are not the sender’s lawful basis.
App first and fallback App-first is implemented through a configured routing plan, not a universal automatic sequence. Missing contact details, rejection, timeout, unread status or technical failure can trigger a configured email, SMS or letter fallback; PDS contact details are resolved once at the start. Digital-first is not digital-only.
Delivery and urgency “Delivered”, “notified” and “read” are different. NHS Notify does not guarantee timely processing for clinically time-critical content, ordinary push and channel delivery windows vary, and recipients cannot currently reply directly through the service. A sender must provide a usable response route and use an appropriate urgent alternative such as telephone where delay could affect care.
Inclusion Large-print, Braille and audio-CD letters are available only when the sender configures matching templates and recipient routing. Easy Read, BSL links and translations remain the sender’s responsibility; current digital channels are English-only. Locally held communication preferences, objections and reasonable adjustments are not applied automatically by NHS Notify.
App API distinction NHS Notify’s production API orchestrates multiple channels, PDS enrichment and fallbacks, with the NHS App as one delivery supplier. The separately registered NHS App communications API is a permissioned direct in-App interface with its own capabilities and onboarding; the two are not interchangeable and neither transfers a GP clinical record to another provider.

For a real message flow, record the source-system event, sender and recipient, message purpose and minimum content, routing plan and timeout, status-to-action rules, accessible variants, reply/urgent route, audit correlation and the treatment of an unsuccessful or unacknowledged message. Service retention of message/PDS data for up to 18 months must appear in transparency and lifecycle analysis. SRC-054 SRC-056 SRC-076

Single Patient Record: future, not a shortcut

The Plan describes a secure, authoritative account bringing information together across care settings and accessible through the NHS App. The current NHS England programme page says design is still at an early, test-and-learn stage. Central, federated/hub-and-spoke and virtual data-layer approaches have been explored; original source systems are expected to retain their data. Architecture, detailed controller responsibility and objection arrangements are not settled. SRC-043

As at 27 July 2026, the current text is Bill 131, as amended in Public Bill Committee on 16 July 2026; it has not received Royal Assent. Clause 51 would empower the Secretary of State to make regulations establishing the SPR, including requiring or authorising processing, specifying access and financial-penalty enforcement, and potentially providing a confidentiality gateway for processing under those regulations. No such SPR regulations currently exist. The Bill does not create a new gateway for planning, commissioning or research: SPR information could be used for those purposes only where it could otherwise lawfully be processed under an existing, separate route. SRC-029

Therefore:

  • do not equate a “single” record with one central database;
  • do not infer universal clinician read/write access;
  • do not treat “patient control” language as a settled GDPR-consent model or universal direct-care veto;
  • do not use the expected 2028 NHS App access point as a current conformance date;
  • do not pre-empt future regulations, information standards, controller allocation, opt-out design or phased cohorts;
  • continue to apply today’s source-system, shared-care, GP Connect, contract, confidentiality, data-protection and assurance rules.

The SPR is also not the FDP. NHS England describes the live, multi-instance FDP as supporting approved direct-care, care-coordination, operational and population-health-planning products, with product-specific purpose, controller, role and information-governance controls; it is not the patient-accessible longitudinal record promised by the SPR programme. SRC-043 SRC-058

Digital inclusion is part of the floor

NHS England’s inclusion framework says digital approaches should complement non-digital services and support. It identifies five action domains: devices/data, accessibility/ease of use, skills/capability, beliefs/trust, and leadership/partnerships. The framework is guidance: Equality Act duties and NHS England/ICB health-inequality duties arise from legislation and apply according to the actor, function and service facts. SRC-052 SRC-061 SRC-063

The standards position is more specific:

  • Accessible Information (DAPB1605 Amd 30/2025 v1.1.0) has a section 250 Information Standards Notice covering all providers of publicly funded NHS, public-health and adult-social-care services, expressly including GP practices and commissioned private providers. The notice refers implementation and full-conformance dates to the standard rather than stating exact dates, so none should be invented without checking the current standard and guidance. SRC-054
  • WCAG 2.2 is an active international specification and the directory associates it with public-sector systems and services. Public Sector Bodies Accessibility Regulations applicability depends on the organisation and service; NHS integration or procurement rules may impose an additional contractual baseline. Equality Act duties remain relevant. SRC-057 SRC-061 SRC-062
  • the GMS multi-channel provisions provide a concrete operational safeguard: online access cannot be the only access route. SRC-047

Record communication needs once, flag them safely, share them within the standard’s scope and meet them in every channel. Test with affected people and provide assisted routes, interpreters, proxy/delegated access and reasonable adjustments as the use case requires.

Standards and assurance for digital pathways

Standard or gate Requirement contribution Guardrail
Accessible Information Scoped section 250 accessibility floor. Check organisation/service scope and current specification; do not invent a missing notice date. SRC-054
Online and Video Consultation in General Practices (DAPB4031) Weekly usage-data collection across GP practices under section 259. This is a collection duty, not the source of the patient-facing consultation offer and not permission to exchange clinical records. SRC-055
NHS App communications API Production/beta FHIR communications API for approved services to message NHS App users and receive supported replies/receipts; onboarding and permissions are required; it uses UK Core STU1 extensions. Directory “Active” status does not make it a generic integration route, universal mandate or sharing authority. Wider NHS App integrations use separate feature-specific gateway and assurance routes. SRC-056 SRC-064
WCAG 2.2 Accessibility specification and public-sector baseline where the relevant legal/contractual scope applies. Determine the body/service and procurement scope; directory registration does not settle every independent contractor’s legal status. SRC-057
DCB0129 / DCB0160 Manufacturer/modifier and deployer/operator clinical-risk management where scoped. Apply the relevant role and product/use-case; a consultation or future revision does not replace the current standard.
DSPT / cyber controls Organisational security assurance and incident-handling floor in scope. Toolkit completion is not proof that the flow is lawful or the particular design is secure.
DTAC Five-domain assessment covering clinical safety, data protection, technical security, interoperability and usability/accessibility. DTAC is best-practice guidance rather than a generic legal requirement, although procurement, commissioning, contract or integration conditions can require it. It is not a sharing gateway and does not replace a DPIA or safety case. SRC-053

Use the NHS standards applicability register for exact authority, scope, version and date fields.

Wider NHS and other-provider boundary

Digital policy does not erase organisational boundaries.

  • Another NHS organisation: NHS status does not establish purpose, a care relationship or need-to-know access.
  • Commissioned private, voluntary or social-care provider: direct care can be legitimate, but the commissioner, provider, contract, controller roles, assurance and product onboarding must all support the exact flow. A general “wider care team” label is insufficient.
  • Private provider outside an NHS-commissioned/assured route: do not infer GP Connect or shared-record access from technical capability. Validate current national rollout, patient-permission and supplier-assurance conditions.
  • ICB or neighbourhood platform: separate direct-care views from planning, population-health and service-management data planes.
  • Patient-facing third-party app: distinguish an NHS App integration from independent patient-directed access, clinical service provision, regulated medical-device functionality and later reuse.

Minimal and maximal answer

Minimal current requirement

For a digital primary-care flow, the minimum is not “put the whole record online”. It is:

  1. retain the required accessible online, telephone, in-person and assisted channels;
  2. implement the exact current contract, regulation, direction and applicable ISN in scope;
  3. expose or transmit only the data necessary for a defined function and authorised recipient;
  4. satisfy data protection, confidentiality, objection/opt-out, transparency, safety, security and equality layers;
  5. prove the selected product and local workflow are live, usable and recoverable when digital service fails.

Maximal defensible implementation

The higher-assurance ceiling is a joined but purpose-separated ecosystem:

  • a patient can see and contribute appropriate information through accessible channels;
  • authorised professionals see current, coded, role-filtered information across organisational boundaries;
  • transactional functions use supported APIs with identity, acknowledgement, audit and correction;
  • direct-care, operational/planning and research data planes have explicit governance boundaries;
  • accessibility, proxy access, safeguarding, break-glass, downtime and non-digital pathways are designed in;
  • data quality and clinical-safety feedback return to source;
  • every additional capability is commissioned, assured, monitored and revalidated.

That ceiling maximises safe availability and interoperability—not the volume of data or number of users.

Programme gates and revalidation

Before relying on a Plan commitment, record:

Gate Evidence needed
Status Policy / current instruction / contract / regulation / enacted and commenced law / applicable ISN.
Scope Country, organisation type, contract type, provider/consumer role, cohort, product and use case.
Delivery Live capability for the actual supplier, cohort and geography; canonical endpoint health where applicable.
Authority Purpose, controller function, Article 6/9, DPA safeguard and confidentiality route.
Choice Direct-care objection, patient preference, Type 1 and national data opt-out result as applicable.
Standards Current notice/specification/version, implementation date, conformance date and local evidence.
Assurance DPIA, equality/accessibility, clinical-safety, cyber, supplier, medical-device and AI governance as applicable.
Operations Multi-channel fallback, support, data-quality correction, incident, audit, retention and review ownership.

Open research and delivery questions are maintained in VAL-008 and VAL-012–VAL-019.