Skip to content

Chapter 3: from analogue to digital

Decision-use summary

The official heading is “Chapter 3: from analogue to digital — power in your hands”. The chapter is a portfolio of policy commitments, not a single programme, data-sharing purpose or present mandate. It combines patient access, clinical-record exchange, navigation, provider choice, remote care, patient-generated data, research recruitment, app procurement, accessibility, artificial intelligence (AI), staff workflow and a future planned-care platform. Each component needs its own authority, delivery status and assurance decision. SRC-041

This page records the position at 27 July 2026. Use the parent 10 Year Health Plan and digital-first implications page for the current primary-care floor and the sharing route decision workflow for a real flow.

Status key

Status Meaning
Current floor A current law, regulation, contract, direction or applicable information standard establishes a scoped requirement.
Current capability Official product material says the function is live, but availability can still vary by supplier, cohort, provider or geography.
In delivery Official material says work, testing, procurement or rollout is under way; this is not proof of local availability.
Policy ambition The Plan describes an intended outcome but does not establish a current entitlement, duty or live service.
Legislation-dependent The commitment expressly depends on future primary legislation, commencement, regulations or standards.

Words such as “everyone”, “universal”, “full front door”, “soon”, “over time” and “longer-term” are not implementation scope or conformance dates. Plan productivity figures and case-study results are evidence or estimates, not guaranteed national benefits.

Chapter-wide commitments

Plan commitment Date or status in the Plan Position at the research date Primary-care data-sharing consequence
NHS App as the front door, with a 24/7 virtual assistant and easy booking, cancellation and team communication Full front door by 2028; functionality added through the Plan Policy ambition. Current App functions and an active roadmap exist, but the roadmap expressly excludes some Plan services. SRC-050 Verify the exact live feature, supplier, cohort and recipient. A 24/7 automated channel is not a 24/7 GP clinical-response obligation.
Universal access to selected digital tools free at the point of need Over the Plan period Policy ambition; HealthStore is separately proposed Product eligibility, procurement and assurance do not establish authority for clinical-record access or later data reuse.
A secure, authoritative Single Patient Record (SPR) App viewing ambition from 2028, subject to Parliamentary time; maternity first after legislation Legislation-dependent and early-stage. The Bill has not received Royal Assent and no SPR regulations exist. SRC-029 SRC-043 Continue to use current source-system, patient-access, shared-care and GP Connect rules. Do not infer one database or universal read/write access.
A fully digitally enabled NHS operating 24/7 online and offline During the ten-year Plan Policy ambition with an explicit offline and in-person safeguard Digital-by-default is not digital-only. Retain accessible telephone, in-person, paper and assisted routes where current rules or need require them.
Automated booking, digital pre-assessment, straight-to-test pathways and more App messaging “Soon” or undated Mixed current capability, in-delivery work and ambition. NHS Notify is live, while the current framework directs staged migration to it; local onboarding, supplier readiness and some capabilities remain incomplete. SRC-044 SRC-076 Split booking, intake, clinical triage, messaging and referral into separate transactions with supported interfaces and failure routes. App-first routing needs accessible fallback; technical delivery does not prove the message was read or acted on.
NHS-wide single sign-on “As a first step”; no date Mixed. CIS2 is live for more than 40 applications and 760,000 users and is required for specified application/API classes, but “NHS single sign-on” remains on the Care Identity roadmap under “coming later”. SRC-074 Authentication convenience does not determine authorisation, role, care relationship, purpose or record content.
Ambient AI and a new proactive planned-care platform 2026/27 framework procurement for ambient technology; platform procurement undated Ambient products are already used in some settings and current adoption guidance exists; the planned-care platform remains an unnamed future procurement. SRC-065 Treat each product, function, integration and material change as a separate clinical-safety, information-governance and procurement decision.

The Plan’s conclusion says technology will supplement rather than replace human care and that in-person choice will remain for people who prefer or rely on it. That policy safeguard is consistent with, but does not replace, current contractual, equality, accessibility and communication-needs requirements. SRC-041 SRC-047 SRC-052

NHS App commitment map

Advice, choice and access

Named Plan tool Intended function Current-status classification Decisive gates
My NHS GP AI-assisted nonurgent advice, follow-up questions, personalised guidance and routing to self-care, pharmacy, general practice, neighbourhood or emergency care; help with remote or preferred face-to-face booking Limited rollout, not a current national service. NHS England says more than 200,000 patients are due to be reached within 12 months and all App users by April 2028; the current roadmap records live trial/scale work. Traditional GP contact remains available. SRC-050 SRC-071 Intended purpose; clinical responsibility; escalation and emergency failure; meaningful human review; bias; clinical safety; medical-device status; DPIA; accessible alternatives; service capacity and booking integration.
My Choices Compare providers using distance, waiting time, outcomes and patient-satisfaction information Policy ambition. Current legal choice exists only in specified circumstances; other choices depend on clinical appropriateness and commissioned/local availability. SRC-075 Source, timeliness, comparability and contestability of provider metrics; equality effects; separation of public transparency from patient-record data. An App display does not expand statutory choice.
My Specialist Clinically appropriate self-referral, initially to talking therapies, musculoskeletal services, podiatry and audiology; questions to specialists without appointments Policy ambition; “from the outset” is not a dated milestone Service eligibility; referral criteria; identity; clinical triage; correct destination; acknowledgement; BaRS or other applicable transport/content standard; accessible non-digital route.
My Consult Remote clinician consultation and information explaining the appointment purpose Policy ambition; existing remote services do not prove this named tool is live Clinical appropriateness; provider identity; consultation record; confidentiality at each endpoint; platform assurance; failure/escalation; alternative channel.
My Care Care-plan access, appointment management, clinical-trial enrolment and SPR access; later links to voluntary, social enterprise, social-care, community and local-government services Policy ambition and partly legislation-dependent Separate direct care, service transactions, social prescribing, cross-sector sharing and research recruitment. Each has different actors, authority, opt-outs and data.

Knowledge, medicines, measurements and delegated access

Named Plan tool Intended function Current-status classification Decisive gates
My Companion Help people express needs and preferences, understand a condition or procedure, translate information and prepare questions Policy ambition Clinically governed content; translation quality; accessibility; health literacy; provenance; correction; do not infer or disclose sensitive facts merely to personalise content.
My Medicines Repeat-prescription delivery or collection and reminders; later pharmacogenomic interaction guidance Mixed: repeat requests are a current App capability; reminders are in delivery; the full named tool and pharmacogenomic advice are policy ambitions. SRC-050 Authoritative medicines source, dm+d, proxy controls, dispensing status, clinical decision-support safety, genomic purpose and access, device status and human oversight.
My Vaccines Vaccine status, booking and travel-vaccine information Policy ambition; current records or booking functions are not proof of the complete tool Complete and reconciled sources across settings; coding; eligibility; booking route; travel-care boundary; correction.
My Health One view of measurements and investigations, including real-time wearable, biometric-sensor and smart-device data; patient control over real-time care-team sharing Policy ambition Device and measurement provenance, validation, accuracy, units and identity; controller/processor roles; who monitors; alert and response duty; retention; care-team access; reuse; downtime.
My Children Child-health information and advice; later feeding/sleep records and AI-supported interpretation such as a rash Policy ambition Parental responsibility, evolving capacity, proxy transition, safeguarding and coercion; clinical safety and possible device status for AI interpretation; emergency escalation.
My Carer Prove a caring role, act through another person’s App, book and communicate on their behalf Policy ambition built on existing formal proxy-access mechanisms. DAPB3051 v3.1 is a current scoped section-250 identity/authentication standard with a proxy use case and a 31 December 2026 full-conformance date. The National Proxy Service is still an optional private beta; cross-setting portability is roadmap work. SRC-068 SRC-069 SRC-070 Identity is not authority. Record the legal or consent/best-interests route, permitted functions and content, capacity, safeguarding, review/expiry and audit; never share credentials.

Feedback and inclusion

The Plan proposes service, team and provider ratings, storage of feedback, AI-assisted conversion of feedback into actions, and use of ratings in choice, leadership, reward and regulation. This is not one purpose. Collection and response, quality improvement, public display, staff/provider evaluation and regulatory use require separate necessity, transparency, retention, accuracy, moderation, fairness and challenge arrangements. The current roadmap’s work on feedback about messages and 2026 GP Patient Survey access through the App do not establish the wider Plan service. SRC-041 SRC-050 SRC-072

The chapter also promises inclusion by default, tailored information, identification of support needs, British Sign Language and screen-reader support, patient co-creation and community assistance. Apply the current accessibility and equality envelope rather than treating those promises as self-executing specifications: Accessible Information where scoped, WCAG and public-sector accessibility rules where applicable, Equality Act duties, health-inequality duties, user testing and usable offline/assisted routes. The current NHS App accessibility statement records only partial compliance, named defects and separate responsibility for integrated services, so Plan language is not evidence that every journey is accessible. SRC-052 SRC-054 SRC-057 SRC-061 SRC-062 SRC-063 SRC-073

Single Patient Record commitment map

SPR proposition in Chapter 3 Present classification Required interpretation
Bring medical records together as a secure, authoritative patient passport Legislation-dependent policy and early-stage programme “Single” does not determine central, federated or virtual architecture. The current programme expects source systems to retain data and has not settled detailed controller responsibility or objection design.
Secure clinician access across settings Future, role-based access ambition Specify the care relationship, purpose, contributor and consumer, role-filtered view, write/update rights, break glass, audit and objection handling.
Provider duty to make recorded information available to the patient and default SPR access Proposed legislation Do not treat the Plan or Bill as current law. Check enacted text, commencement, regulations, standards and cohort before implementation.
Patient App view from 2028 Conditional ambition “Subject to Parliamentary time” is not a conformance date. Verify actual product, supplier, geography and cohort.
Patient-added data from clinically validated wearables Future capability “Clinically validated” does not name an assessor, validation method or monitoring service. Patient submission is not blanket consent for downstream care, analytics, model training or research.
Personalised risk account using lifestyle, demographic and genomic data Longer-term ambition Define the individual-care or population purpose; minimise variables; test representativeness, accuracy and discrimination; explain profiling; control genomic and family implications.
Opt-out redesign and legal reform for improvement and research, including HDRS Future policy Current Type 1 and national data opt-out mechanisms remain distinct. The Plan is not a lawful basis or confidentiality gateway. SRC-033 SRC-060
Maternity-first rollout Conditional sequence after legislation It is neither a start date nor permission to bypass current maternity-record, confidentiality, safeguarding, equality and safety controls.
Contextual information and tested, validated social-risk assessments Future capability Housing, caring, exclusion and other contextual data can be highly sensitive and contestable. Define source, purpose, provenance, role access, correction, retention, discrimination controls and the consequence of a missing or wrong score.
Clinical-history summary and protocol/guideline support Future decision support Validate completeness, freshness, provenance, omissions and human oversight; distinguish a summary from the legal/source clinical record and a recommendation from a clinical decision.

The SPR, FDP, NHS Online and HDRS remain distinct programmes. The unnamed Chapter 3 planned-care platform must not be labelled FDP, an EPR or the SPR without current authoritative evidence. SRC-043 SRC-058 SRC-059 SRC-060

Enabling standards have their own delivery clocks. DAPB4101 is already a scoped section-250 laboratory-to-GP direct-care standard, but the national FHIR/SNOMED transition remains in pilot. NHS England intends testing and assurance to finish by April 2027 before supplier roadmaps and eventual national rollout, with SNOMED PBCL continuing in the interim. The current ISN still says 30 April 2025 while the July 2026 implementation update says that date will be extended without giving a replacement. Do not treat April 2027 as a new conformance deadline or infer that pathology data is already consistently available through the NHS App, SPR or AI services. SRC-028

HealthStore and digital-tool approval

The Plan proposes a HealthStore through which patients could access approved apps, with NICE-evaluated technologies surfaced first, national procurement, some universal tools and some condition- and clinician-recommendation-dependent tools. Current NHS quality strategy says testing is under way and local services are intended to select from nationally approved apps through the marketplace by summer 2027. That is a future target, not a current universal entitlement or completed procurement. Neither source defines “approved” as a single assurance state. SRC-041 SRC-072

NICE’s Evidence Standards Framework helps developers and decision-makers classify and assess evidence for digital health technologies; meeting it does not mean NICE has assessed or endorsed the product, and it does not confer regulatory approval. SRC-066 Software or AI that meets a clinical need may be a medical device depending on its intended purpose and function; this must be determined under the applicable medical-device regime. SRC-067

For each HealthStore product, keep these questions separate:

  1. Evidence: is effectiveness supported for the exact population, purpose and version?
  2. Regulation: is it a medical device, and is the product/version correctly registered or conformity marked?
  3. NHS assurance: which DTAC, DCB0129/DCB0160, DSPT, accessibility, security, interoperability and App-integration gates apply?
  4. Procurement and commissioning: who buys, recommends, provides, supports, monitors and pays?
  5. Data authority: which organisation controls each collection, disclosure and reuse; what are the Article 6/9 and confidentiality routes?
  6. Operations: what happens on error, non-use, withdrawal, supplier failure, model/version change or clinical deterioration?

National procurement, a marketplace listing or a clinician recommendation cannot answer the other five questions. SRC-001 SRC-005 SRC-053 SRC-064

AI and ambient documentation

Chapter 3 uses AI for navigation, diagnostic processing, feedback analysis, clinical-history summarisation, protocol guidance, child-health interpretation, pharmacogenomic advice, documentation and possible care-plan drafting. These are different intended purposes and risk profiles; “AI” is not an approval class.

The most developed current position is ambient scribing. NHS England’s version 2 guidance describes the supplier registry as self-certified evidence supporting local procurement and assurance, not a replacement for them. It calls for a Clinical Safety Officer, DCB0160 safety case/hazard log/monitoring, a DPIA, supplier DCB0129 evidence, appropriate record integration, transparency, staff training, output auditing and user review and approval before further action. It says generative summarisation is likely to qualify as higher-functionality medical-device software, whereas easily verified simple transcription may not. SRC-065

For a GP consultation:

flowchart LR
  A["Conversation and contextual record data"] --> B["Approved ambient product"]
  B --> C["Draft transcript, summary, code or letter"]
  C --> D{"Accountable clinician reviews and corrects?"}
  D -- "No" --> E["Do not action or write to record"]
  D -- "Yes" --> F["Authorised action or source-record entry"]
  F --> G["Patient view, referral or other controlled disclosure"]

The practice or provider remains accountable for the care and the record. Contract separately for audio/transcript retention, supplier subprocessors and locations, training or model-improvement use, deletion, incident evidence, audit access and exit. Reassess when prompts, templates, models, interfaces or downstream actions materially change.

New proactive planned-care platform

The Plan proposes national procurement of an unnamed platform for all NHS provider organisations with:

  • remote monitoring feeding the NHS App and SPR;
  • care-plan creation and evidence-based scheduling/tracking;
  • possible generative-AI care-plan drafts for patient and clinician review;
  • SPR visualisation/summarisation and ambient capture;
  • multidisciplinary-team workflow and case escalation;
  • separately sourced GPS, emergency buttons and emergency broadcast for community staff.

This is a policy and procurement commitment, not a current universal platform requirement. The chapter does not name FDP, prescribe an architecture or data model, specify FHIR/UK Core, allocate controllers, define patient cohorts, set monitoring response times or publish conformance dates. Staff-location features also process workforce data and require their own employment, necessity, transparency, proportionality, access and retention assessment.

Before a primary-care organisation depends on the platform, verify its official identity, procurement status, service specification, relationship to SPR/FDP/EPRs, controller model, data routes, standards, supplier assurance, clinical responsibilities and local availability.

Minimum and maximum Chapter 3 answer

Minimum current requirement

Chapter 3 creates no new current blanket duty to send primary-care data into the wider NHS or other providers. The minimum remains:

  1. comply with current law, confidentiality, the executed practice contract, directions and every applicable information-standard notice;
  2. retain accessible online, telephone, in-person and assisted routes;
  3. define and authorise each patient-access, direct-care, transactional, operational/planning or research flow separately;
  4. prove the selected current product, integration, cohort and recipient are live and assured;
  5. minimise content, filter by role and purpose, preserve objections/opt-outs, and operate correction, audit, incident and fallback routes.

Maximum defensible readiness

The maximum is not early exposure of the whole GP record. It is an implementation that can adopt each Chapter 3 capability when its authority and delivery gates mature:

  • source data are coded, accurate, traceable and correctable;
  • identity, proxy/delegated authority, care relationship and role are independently enforced;
  • patient access, clinical access, transactions, monitoring, planning and research remain purpose-separated;
  • APIs and records use applicable standards with acknowledgement, provenance and safety feedback;
  • AI and device outputs remain versioned, monitored, explainable enough for their use and subject to accountable human review;
  • non-digital care, accessibility, safeguarding and downtime routes remain first-class;
  • every future law, regulation, standard, programme release and product change triggers revalidation.

That is maximum useful conformance and safe availability—not maximum data, automation or connectivity.

Maintained validation gates

Use VAL-013–VAL-019 for the general programme, inclusion, App, assurance and purpose-separation checks. Chapter-specific uncertainties are recorded in VAL-020–VAL-027.