Skip to content

2. Information sharing into primary healthcare (PHC)

Core answer

Information entering PHC is governed by a cumulative set of instruments, not one “incoming-data law” or standard. For an England PHC workflow, the sender needs authority and a confidentiality route to disclose, while the PHC recipient needs its own purpose, data-protection basis and controls for receipt, use and any onward disclosure. Add the workflow-specific regulations, contracts, information standards, guidance and receiving controls shown in the selected row.

Return to the Executive summary, or compare Information sharing out of primary healthcare.

Choose a workflow activity

These are broad operational workflows, not authority or mandate labels. Name the exact record-access or order-communications service. In particular, DAPB4101 covers its scoped pathology-reporting leg into the requesting GP organisation; it does not govern every diagnostic order or result workflow.

Select a workflow activity in the first column to open its detailed reference page. The detail page keeps the selected workflow in view while explaining both directions, boundaries, instruments, controls and failure states.

Each row separates the decision route from candidate legislation, regulations, standards, and confidentiality, guidance and other controls. Read across one row, then check every linked instrument for the actual purpose, parties, scope, status, version and dates. Listing does not itself establish authority, applicability or conformance. For this matrix, Legislation groups Acts and the UK GDPR; Regulations means statutory instruments made under Acts. At standard and narrow widths, scroll horizontally to compare all columns. The linked canonical law, standards and evidence pages remain authoritative for status and scope.

Compact link labels use authoritative abbreviations, statutory citations or formal NHS identifiers—for example UK GDPR, DPA 2018, DUAA, SI 2025/950, DCB0129 and DAPB4101. Follow the link for the full title, amendment, version, status and scope.

Workflow activity Typical incoming flow Main route Legislation Regulations Standards Confidentiality, guidance and other controls First control question
Diagnostic test results and order communications A laboratory sends a pathology result to the requesting GP organisation for direct care; or an eligible, onboarded PHC consumer discovers and retrieves prior imaging for a current care purpose. Broader local ordering, results and imaging workflows require their own scope decision Direct-care sharing route
Sharing with the wider NHS
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional sender-side duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
Standards framework only: SI 2025/950; this does not authorise the result flow. Scope-dependent: DAPB4101 (Pathology reporting); NHS Number (ISB 0149-01); SNOMED CT; UK Core FHIR R4 (DAPB4020); DCB0129; DCB0160; DSPT
Boundary: DAPB4101 covers the scoped laboratory-to-requesting-GP pathology-reporting leg; April 2027 is a pilot milestone, not a replacement national conformance date.
Imaging discovery/retrieval only: IHE XCA/XCA-I is current; MHD/FHIR R4 is roadmap.
Conditional imaging service: National Imaging Registry (NIR) requires an accepted direct-care use case, onboarding and organisational agreements; it is not an order-communications standard or universal PHC entitlement.
Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; request and patient matching, sender and provenance, codes and units, abnormal-result status, acknowledgement and error handling, named clinical owner, correction and downtime
Is the patient, request, report, unit, code, abnormal-result status and clinical owner correct and actionable?
Acute discharge and transfer of care An acute provider sends inpatient or day-case discharge information to the GP Direct-care sharing route
Sharing with the wider NHS
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional sender-side duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
Contract-dependent for the receiving practice: GMS Regulations 2015
Standards framework only: SI 2025/950
Scope-dependent: DAPB4042 (Acute discharge); NHS Number (ISB 0149-01); SNOMED CT; dm+d; DCB0129; DCB0160; DSPT
Boundary: DAPB4042 covers acute inpatient or day-case discharge to GP practice systems, not every transfer or clinical letter.
Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; timely review, medicines reconciliation, actionable follow-up, provenance, acknowledgement, correction, duplicate handling and downtime Who owns timely review, medicines reconciliation, follow-up and correction?
Community-pharmacy information A pharmacy sends a service event, vaccination, medicine or consultation outcome to the GP record Direct-care sharing route
Sharing with the wider NHS
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional sender-side duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
Contract-dependent for the receiving practice: GMS Regulations 2015
Standards framework only: SI 2025/950
Scope-dependent: DAPB4008 (Community pharmacy); NHS Number (ISB 0149-01); SNOMED CT; dm+d; DCB0129; DCB0160; DSPT
Boundary: DAPB4008 covers specified community-pharmacy-to-GP flows and available service transports, not all pharmacy information.
Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; unambiguous medicine or event state, allergy and medication reconciliation, duplicate or substitution handling, acknowledgement, correction, escalation and messaging-failure fallback Is the medicine or event state unambiguous, reconciled and safely handled if messaging fails?
Shared-care records and care plans PHC receives or views information from hospital, community, mental-health, social-care or neighbourhood services Direct-care sharing route
Shared care and GP Connect
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional sender-side duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
Contract- and capability-dependent: GMS Regulations 2015; SI 2026/532 (GMS/PMS amendments)
Standards framework only: SI 2025/950
Scope-dependent: Core Information Standard; Personalised Care and Support Plan (DAPB4022); NHS Number (ISB 0149-01); SNOMED CT; UK Core FHIR R4 (DAPB4020); DCB0129; DCB0160; DSPT
Boundary: GP Connect Access Record: Structured – FHIR API retrieves from the GP-held record; it is not a generic inbound-message standard.
Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; current care relationship, role and need-to-know filtering, context, objections, sensitive or third-party content, override, audit, provenance and correction Which source, role, care relationship, context, objection and correction route justify the view?
Referrals and bookings A response, triage outcome, booking, cancellation or return referral enters a PHC workflow Direct-care sharing route
Sharing with the wider NHS
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional sender-side duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
Contract-dependent: GMS Regulations 2015; SI 2026/532 (GMS/PMS amendments)
Standards framework only: SI 2025/950
Scope-dependent: BaRS (DAPB4060); Clinical Referral Information Standard, only if its content and direction fit; NHS Number (ISB 0149-01); SNOMED CT; DCB0129; DCB0160; DSPT
Boundary: the booking and referral standard is mandatory only for its published in-scope use cases.
Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; acknowledgement, triage, acceptance, cancellation, rejection, return, failed or unanswered state, escalation, correction and closure ownership Which published use case applies, and are acknowledgement, cancellation, error and escalation states closed?
Patient or carer information Online consultation, message, proxy request, measurement, questionnaire, wearable or other patient-generated information Five distinct data routes
Direct-care sharing route, only once a service accepts clinical responsibility
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Accessibility and equality: Equality Act 2010 ss. 20, 29 & 149
Standards framework only: HSCA 2012 ss. 250–251
Contract-dependent: GMS Regulations 2015; SI 2026/532 (GMS/PMS amendments)
Actor- and service-dependent: Accessibility Regulations 2018
Standards framework only: SI 2025/950
Scope-dependent: AIS (DAPB1605); DAPB3051 (Identity and authentication); WCAG 2.2; DAPB4031 (Online/video consultation collection), only as its usage-data collection; NHS App API, only for an approved communications integration; DCB0129; DCB0160; DSPT Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; proxy or delegated access, safeguarding, serious-harm and third-party confidentiality, accessibility and reasonable adjustments, response promise, provenance, clinical ownership, correction and non-digital fallback What service has accepted clinical responsibility, what response is promised, and how are provenance and safety limits shown?
Community, mental-health, ambulance, social-care and other-provider updates Independent, voluntary, social-care or commissioned provider information arrives by structured message, document or local platform Sharing with other providers, followed by the Direct-care sharing route or Beyond-care sharing route according to purpose Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional sender-side duty: Section 251B direct-care duty, only for an in-scope sender and flow
Standards framework only: HSCA 2012 ss. 250–251, only if an exact standard applies
No universal provider-to-PHC regulation identified: check the exact provider, service and receiving-practice contract.
Standards framework only: SI 2025/950, where an applicable standard is identified.
Not routine direct-care authority: COPI Regulations 2002 apply only to a separately specified and approved beyond-care purpose.
No universal document or message standard: add a service- or content-specific standard only after matching the exact flow.
Candidate foundations where scoped: NHS Number (ISB 0149-01); SNOMED CT; UK Core FHIR R4 (DAPB4020), where FHIR is used; DCB0129; DCB0160; DSPT
Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; sender identity, commissioner or provider contract, controller and processor roles, data-sharing agreement or Article 28 contract as appropriate, care relationship, provenance, data quality, onward-use limits, audit, correction, incident and service-exit controls Can PHC identify the sender, purpose, data quality, care relationship, clinical owner and onward-use limits?
Patient registration, demographics and GP-record transfer The new practice receives the application, traces and matches PDS, completes PCRM registration, requests and receives GP2GP where applicable, reviews/files the record and returns positive acknowledgement Registration and record-transfer workflow
Current primary-care contract position
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Service powers only: HSCA 2012 does not by itself establish the practice’s purpose or confidentiality route.
Contract-type and case dependent: GMS Regulations 2015, PMS Regulations 2015, SI 2021/995, SI 2024/575 and SI 2026/532 Scope-dependent: NHS Number (ISB 0149-01); GP2GP HL7 V3 production integration; DCB0129; DCB0160; DSPT Common law confidentiality; executed GMS/PMS/APMS terms; Register, PDS, PCRM and GP2GP service rules; correct match, smartcard/RBAC, manual review, degraded-data action, positive acknowledgement, paper fallback, correction and audit Are the patient and practices correctly matched, and who owns review, degraded data, acknowledgement and incomplete or paper-only content?

Core receiving controls

Every incoming row also requires a correct patient and recipient, known sender and provenance, preserved meaning, a named owner for review and action, and tested acknowledgement, correction and downtime handling. Later publication, analytics, artificial intelligence, planning or research is a separate purpose requiring a separate decision.

Read the authority columns as a screen

The matrix owns the cross-workflow comparison. Its four authority columns answer different parts of the exam question:

  • Legislation identifies the data-protection baseline and any purpose- or actor-specific Act. A sender-side power or duty does not establish the PHC recipient’s later purpose.
  • Regulations identifies statutory instruments and contract-dependent requirements only where their exact scope fits.
  • Standards identifies candidate information, terminology, interoperability, safety and assurance standards. “Active” or listed in the directory does not mean universally mandatory.
  • Confidentiality, guidance and other controls identifies the sender’s separate confidentiality route and the recipient’s care-purpose, access, provenance and operational controls.

The Main route column is a decision route, not a fifth source of authority. Use the linked Legislation, powers and duties, Confidentiality and Caldicott, NHS standards applicability register and maintained evidence to confirm full titles, current status and scope.

Confirm applicability on the workflow page

Open the workflow link in the first column before making a decision. Its scope and boundary sections distinguish an incoming message, an on-demand view and later onward use, even where the same product or care pathway is involved.

The detail page owns the operational application: exact service or pathway, direction, message leg, matching, provenance, clinical ownership, acknowledgement, correction, failure states and unresolved checks. It does not repeat the full cross-workflow register.

Continue with one incoming flow

Follow one route without skipping a stage:

  1. Direction: remain on this incoming-PHC matrix and select one row.
  2. Workflow: on the linked detail page, confirm the exact incoming message, view or retrieval leg and candidate instruments.
  3. Decision guide: carry the direction, workflow, sender, recipient, message leg and purpose into Decide a data flow.
  4. Decision record: follow the decision guide to the auditable record only after every applicable layer has been tested.

Do not accept information into an unmanaged inbox or database where no one owns matching, review, action, correction and service failure.