Chapter 3: from analogue to digital
Decision-use summary
The official heading is “Chapter 3: from analogue to digital — power in your hands”. The chapter is a portfolio of policy commitments, not a single programme, data-sharing purpose or present mandate. It combines patient access, clinical-record exchange, navigation, provider choice, remote care, patient-generated data, research recruitment, app procurement, accessibility, artificial intelligence (AI), staff workflow and a future planned-care platform. Each component needs its own authority, delivery status and assurance decision. SRC-041
This page records the position at 27 July 2026. Use the parent 10 Year Health Plan and digital-first implications page for the current primary-care floor and the sharing route decision workflow for a real flow.
Status key
| Status | Meaning |
|---|---|
| Current floor | A current law, regulation, contract, direction or applicable information standard establishes a scoped requirement. |
| Current capability | Official product material says the function is live, but availability can still vary by supplier, cohort, provider or geography. |
| In delivery | Official material says work, testing, procurement or rollout is under way; this is not proof of local availability. |
| Policy ambition | The Plan describes an intended outcome but does not establish a current entitlement, duty or live service. |
| Legislation-dependent | The commitment expressly depends on future primary legislation, commencement, regulations or standards. |
Words such as “everyone”, “universal”, “full front door”, “soon”, “over time” and “longer-term” are not implementation scope or conformance dates. Plan productivity figures and case-study results are evidence or estimates, not guaranteed national benefits.
Chapter-wide commitments
| Plan commitment | Date or status in the Plan | Position at the research date | Primary-care data-sharing consequence |
|---|---|---|---|
| NHS App as the front door, with a 24/7 virtual assistant and easy booking, cancellation and team communication | Full front door by 2028; functionality added through the Plan | Policy ambition. Current App functions and an active roadmap exist, but the roadmap expressly excludes some Plan services. SRC-050 | Verify the exact live feature, supplier, cohort and recipient. A 24/7 automated channel is not a 24/7 GP clinical-response obligation. |
| Universal access to selected digital tools free at the point of need | Over the Plan period | Policy ambition; HealthStore is separately proposed | Product eligibility, procurement and assurance do not establish authority for clinical-record access or later data reuse. |
| A secure, authoritative Single Patient Record (SPR) | App viewing ambition from 2028, subject to Parliamentary time; maternity first after legislation | Legislation-dependent and early-stage. The Bill has not received Royal Assent and no SPR regulations exist. SRC-029 SRC-043 | Continue to use current source-system, patient-access, shared-care and GP Connect rules. Do not infer one database or universal read/write access. |
| A fully digitally enabled NHS operating 24/7 online and offline | During the ten-year Plan | Policy ambition with an explicit offline and in-person safeguard | Digital-by-default is not digital-only. Retain accessible telephone, in-person, paper and assisted routes where current rules or need require them. |
| Automated booking, digital pre-assessment, straight-to-test pathways and more App messaging | “Soon” or undated | Mixed current capability, in-delivery work and ambition. NHS Notify is live, while the current framework directs staged migration to it; local onboarding, supplier readiness and some capabilities remain incomplete. SRC-044 SRC-076 | Split booking, intake, clinical triage, messaging and referral into separate transactions with supported interfaces and failure routes. App-first routing needs accessible fallback; technical delivery does not prove the message was read or acted on. |
| NHS-wide single sign-on | “As a first step”; no date | Mixed. CIS2 is live for more than 40 applications and 760,000 users and is required for specified application/API classes, but “NHS single sign-on” remains on the Care Identity roadmap under “coming later”. SRC-074 | Authentication convenience does not determine authorisation, role, care relationship, purpose or record content. |
| Ambient AI and a new proactive planned-care platform | 2026/27 framework procurement for ambient technology; platform procurement undated | Ambient products are already used in some settings and current adoption guidance exists; the planned-care platform remains an unnamed future procurement. SRC-065 | Treat each product, function, integration and material change as a separate clinical-safety, information-governance and procurement decision. |
The Plan’s conclusion says technology will supplement rather than replace human care and that in-person choice will remain for people who prefer or rely on it. That policy safeguard is consistent with, but does not replace, current contractual, equality, accessibility and communication-needs requirements. SRC-041 SRC-047 SRC-052
NHS App commitment map
Advice, choice and access
| Named Plan tool | Intended function | Current-status classification | Decisive gates |
|---|---|---|---|
| My NHS GP | AI-assisted nonurgent advice, follow-up questions, personalised guidance and routing to self-care, pharmacy, general practice, neighbourhood or emergency care; help with remote or preferred face-to-face booking | Limited rollout, not a current national service. NHS England says more than 200,000 patients are due to be reached within 12 months and all App users by April 2028; the current roadmap records live trial/scale work. Traditional GP contact remains available. SRC-050 SRC-071 | Intended purpose; clinical responsibility; escalation and emergency failure; meaningful human review; bias; clinical safety; medical-device status; DPIA; accessible alternatives; service capacity and booking integration. |
| My Choices | Compare providers using distance, waiting time, outcomes and patient-satisfaction information | Policy ambition. Current legal choice exists only in specified circumstances; other choices depend on clinical appropriateness and commissioned/local availability. SRC-075 | Source, timeliness, comparability and contestability of provider metrics; equality effects; separation of public transparency from patient-record data. An App display does not expand statutory choice. |
| My Specialist | Clinically appropriate self-referral, initially to talking therapies, musculoskeletal services, podiatry and audiology; questions to specialists without appointments | Policy ambition; “from the outset” is not a dated milestone | Service eligibility; referral criteria; identity; clinical triage; correct destination; acknowledgement; BaRS or other applicable transport/content standard; accessible non-digital route. |
| My Consult | Remote clinician consultation and information explaining the appointment purpose | Policy ambition; existing remote services do not prove this named tool is live | Clinical appropriateness; provider identity; consultation record; confidentiality at each endpoint; platform assurance; failure/escalation; alternative channel. |
| My Care | Care-plan access, appointment management, clinical-trial enrolment and SPR access; later links to voluntary, social enterprise, social-care, community and local-government services | Policy ambition and partly legislation-dependent | Separate direct care, service transactions, social prescribing, cross-sector sharing and research recruitment. Each has different actors, authority, opt-outs and data. |
Knowledge, medicines, measurements and delegated access
| Named Plan tool | Intended function | Current-status classification | Decisive gates |
|---|---|---|---|
| My Companion | Help people express needs and preferences, understand a condition or procedure, translate information and prepare questions | Policy ambition | Clinically governed content; translation quality; accessibility; health literacy; provenance; correction; do not infer or disclose sensitive facts merely to personalise content. |
| My Medicines | Repeat-prescription delivery or collection and reminders; later pharmacogenomic interaction guidance | Mixed: repeat requests are a current App capability; reminders are in delivery; the full named tool and pharmacogenomic advice are policy ambitions. SRC-050 | Authoritative medicines source, dm+d, proxy controls, dispensing status, clinical decision-support safety, genomic purpose and access, device status and human oversight. |
| My Vaccines | Vaccine status, booking and travel-vaccine information | Policy ambition; current records or booking functions are not proof of the complete tool | Complete and reconciled sources across settings; coding; eligibility; booking route; travel-care boundary; correction. |
| My Health | One view of measurements and investigations, including real-time wearable, biometric-sensor and smart-device data; patient control over real-time care-team sharing | Policy ambition | Device and measurement provenance, validation, accuracy, units and identity; controller/processor roles; who monitors; alert and response duty; retention; care-team access; reuse; downtime. |
| My Children | Child-health information and advice; later feeding/sleep records and AI-supported interpretation such as a rash | Policy ambition | Parental responsibility, evolving capacity, proxy transition, safeguarding and coercion; clinical safety and possible device status for AI interpretation; emergency escalation. |
| My Carer | Prove a caring role, act through another person’s App, book and communicate on their behalf | Policy ambition built on existing formal proxy-access mechanisms. DAPB3051 v3.1 is a current scoped section-250 identity/authentication standard with a proxy use case and a 31 December 2026 full-conformance date. The National Proxy Service is still an optional private beta; cross-setting portability is roadmap work. SRC-068 SRC-069 SRC-070 | Identity is not authority. Record the legal or consent/best-interests route, permitted functions and content, capacity, safeguarding, review/expiry and audit; never share credentials. |
Feedback and inclusion
The Plan proposes service, team and provider ratings, storage of feedback, AI-assisted conversion of feedback into actions, and use of ratings in choice, leadership, reward and regulation. This is not one purpose. Collection and response, quality improvement, public display, staff/provider evaluation and regulatory use require separate necessity, transparency, retention, accuracy, moderation, fairness and challenge arrangements. The current roadmap’s work on feedback about messages and 2026 GP Patient Survey access through the App do not establish the wider Plan service. SRC-041 SRC-050 SRC-072
The chapter also promises inclusion by default, tailored information, identification of support needs, British Sign Language and screen-reader support, patient co-creation and community assistance. Apply the current accessibility and equality envelope rather than treating those promises as self-executing specifications: Accessible Information where scoped, WCAG and public-sector accessibility rules where applicable, Equality Act duties, health-inequality duties, user testing and usable offline/assisted routes. The current NHS App accessibility statement records only partial compliance, named defects and separate responsibility for integrated services, so Plan language is not evidence that every journey is accessible. SRC-052 SRC-054 SRC-057 SRC-061 SRC-062 SRC-063 SRC-073
Single Patient Record commitment map
| SPR proposition in Chapter 3 | Present classification | Required interpretation |
|---|---|---|
| Bring medical records together as a secure, authoritative patient passport | Legislation-dependent policy and early-stage programme | “Single” does not determine central, federated or virtual architecture. The current programme expects source systems to retain data and has not settled detailed controller responsibility or objection design. |
| Secure clinician access across settings | Future, role-based access ambition | Specify the care relationship, purpose, contributor and consumer, role-filtered view, write/update rights, break glass, audit and objection handling. |
| Provider duty to make recorded information available to the patient and default SPR access | Proposed legislation | Do not treat the Plan or Bill as current law. Check enacted text, commencement, regulations, standards and cohort before implementation. |
| Patient App view from 2028 | Conditional ambition | “Subject to Parliamentary time” is not a conformance date. Verify actual product, supplier, geography and cohort. |
| Patient-added data from clinically validated wearables | Future capability | “Clinically validated” does not name an assessor, validation method or monitoring service. Patient submission is not blanket consent for downstream care, analytics, model training or research. |
| Personalised risk account using lifestyle, demographic and genomic data | Longer-term ambition | Define the individual-care or population purpose; minimise variables; test representativeness, accuracy and discrimination; explain profiling; control genomic and family implications. |
| Opt-out redesign and legal reform for improvement and research, including HDRS | Future policy | Current Type 1 and national data opt-out mechanisms remain distinct. The Plan is not a lawful basis or confidentiality gateway. SRC-033 SRC-060 |
| Maternity-first rollout | Conditional sequence after legislation | It is neither a start date nor permission to bypass current maternity-record, confidentiality, safeguarding, equality and safety controls. |
| Contextual information and tested, validated social-risk assessments | Future capability | Housing, caring, exclusion and other contextual data can be highly sensitive and contestable. Define source, purpose, provenance, role access, correction, retention, discrimination controls and the consequence of a missing or wrong score. |
| Clinical-history summary and protocol/guideline support | Future decision support | Validate completeness, freshness, provenance, omissions and human oversight; distinguish a summary from the legal/source clinical record and a recommendation from a clinical decision. |
The SPR, FDP, NHS Online and HDRS remain distinct programmes. The unnamed Chapter 3 planned-care platform must not be labelled FDP, an EPR or the SPR without current authoritative evidence. SRC-043 SRC-058 SRC-059 SRC-060
Enabling standards have their own delivery clocks. DAPB4101 is already a scoped section-250 laboratory-to-GP direct-care standard, but the national FHIR/SNOMED transition remains in pilot. NHS England intends testing and assurance to finish by April 2027 before supplier roadmaps and eventual national rollout, with SNOMED PBCL continuing in the interim. The current ISN still says 30 April 2025 while the July 2026 implementation update says that date will be extended without giving a replacement. Do not treat April 2027 as a new conformance deadline or infer that pathology data is already consistently available through the NHS App, SPR or AI services. SRC-028
HealthStore and digital-tool approval
The Plan proposes a HealthStore through which patients could access approved apps, with NICE-evaluated technologies surfaced first, national procurement, some universal tools and some condition- and clinician-recommendation-dependent tools. Current NHS quality strategy says testing is under way and local services are intended to select from nationally approved apps through the marketplace by summer 2027. That is a future target, not a current universal entitlement or completed procurement. Neither source defines “approved” as a single assurance state. SRC-041 SRC-072
NICE’s Evidence Standards Framework helps developers and decision-makers classify and assess evidence for digital health technologies; meeting it does not mean NICE has assessed or endorsed the product, and it does not confer regulatory approval. SRC-066 Software or AI that meets a clinical need may be a medical device depending on its intended purpose and function; this must be determined under the applicable medical-device regime. SRC-067
For each HealthStore product, keep these questions separate:
- Evidence: is effectiveness supported for the exact population, purpose and version?
- Regulation: is it a medical device, and is the product/version correctly registered or conformity marked?
- NHS assurance: which DTAC, DCB0129/DCB0160, DSPT, accessibility, security, interoperability and App-integration gates apply?
- Procurement and commissioning: who buys, recommends, provides, supports, monitors and pays?
- Data authority: which organisation controls each collection, disclosure and reuse; what are the Article 6/9 and confidentiality routes?
- Operations: what happens on error, non-use, withdrawal, supplier failure, model/version change or clinical deterioration?
National procurement, a marketplace listing or a clinician recommendation cannot answer the other five questions. SRC-001 SRC-005 SRC-053 SRC-064
AI and ambient documentation
Chapter 3 uses AI for navigation, diagnostic processing, feedback analysis, clinical-history summarisation, protocol guidance, child-health interpretation, pharmacogenomic advice, documentation and possible care-plan drafting. These are different intended purposes and risk profiles; “AI” is not an approval class.
The most developed current position is ambient scribing. NHS England’s version 2 guidance describes the supplier registry as self-certified evidence supporting local procurement and assurance, not a replacement for them. It calls for a Clinical Safety Officer, DCB0160 safety case/hazard log/monitoring, a DPIA, supplier DCB0129 evidence, appropriate record integration, transparency, staff training, output auditing and user review and approval before further action. It says generative summarisation is likely to qualify as higher-functionality medical-device software, whereas easily verified simple transcription may not. SRC-065
For a GP consultation:
flowchart LR
A["Conversation and contextual record data"] --> B["Approved ambient product"]
B --> C["Draft transcript, summary, code or letter"]
C --> D{"Accountable clinician reviews and corrects?"}
D -- "No" --> E["Do not action or write to record"]
D -- "Yes" --> F["Authorised action or source-record entry"]
F --> G["Patient view, referral or other controlled disclosure"]
The practice or provider remains accountable for the care and the record. Contract separately for audio/transcript retention, supplier subprocessors and locations, training or model-improvement use, deletion, incident evidence, audit access and exit. Reassess when prompts, templates, models, interfaces or downstream actions materially change.
New proactive planned-care platform
The Plan proposes national procurement of an unnamed platform for all NHS provider organisations with:
- remote monitoring feeding the NHS App and SPR;
- care-plan creation and evidence-based scheduling/tracking;
- possible generative-AI care-plan drafts for patient and clinician review;
- SPR visualisation/summarisation and ambient capture;
- multidisciplinary-team workflow and case escalation;
- separately sourced GPS, emergency buttons and emergency broadcast for community staff.
This is a policy and procurement commitment, not a current universal platform requirement. The chapter does not name FDP, prescribe an architecture or data model, specify FHIR/UK Core, allocate controllers, define patient cohorts, set monitoring response times or publish conformance dates. Staff-location features also process workforce data and require their own employment, necessity, transparency, proportionality, access and retention assessment.
Before a primary-care organisation depends on the platform, verify its official identity, procurement status, service specification, relationship to SPR/FDP/EPRs, controller model, data routes, standards, supplier assurance, clinical responsibilities and local availability.
Minimum and maximum Chapter 3 answer
Minimum current requirement
Chapter 3 creates no new current blanket duty to send primary-care data into the wider NHS or other providers. The minimum remains:
- comply with current law, confidentiality, the executed practice contract, directions and every applicable information-standard notice;
- retain accessible online, telephone, in-person and assisted routes;
- define and authorise each patient-access, direct-care, transactional, operational/planning or research flow separately;
- prove the selected current product, integration, cohort and recipient are live and assured;
- minimise content, filter by role and purpose, preserve objections/opt-outs, and operate correction, audit, incident and fallback routes.
Maximum defensible readiness
The maximum is not early exposure of the whole GP record. It is an implementation that can adopt each Chapter 3 capability when its authority and delivery gates mature:
- source data are coded, accurate, traceable and correctable;
- identity, proxy/delegated authority, care relationship and role are independently enforced;
- patient access, clinical access, transactions, monitoring, planning and research remain purpose-separated;
- APIs and records use applicable standards with acknowledgement, provenance and safety feedback;
- AI and device outputs remain versioned, monitored, explainable enough for their use and subject to accountable human review;
- non-digital care, accessibility, safeguarding and downtime routes remain first-class;
- every future law, regulation, standard, programme release and product change triggers revalidation.
That is maximum useful conformance and safe availability—not maximum data, automation or connectivity.
Maintained validation gates
Use VAL-013–VAL-019 for the general programme, inclusion, App, assurance and purpose-separation checks. Chapter-specific uncertainties are recorded in VAL-020–VAL-027.