Skip to content

2. Information sharing into primary healthcare (PHC)

Core answer

Receipt is not the end of an information-sharing flow. Primary healthcare must bring incoming information into a controlled clinical workflow with the correct patient and recipient, known sender and provenance, preserved clinical meaning, a named owner for review and action, acknowledgement, reconciliation, correction and safe downtime handling.

Return to the Core PHC summary, or compare Information sharing out of primary healthcare.

Workflow activities

These are broad operational workflows, not authority or mandate labels. Name the exact record-access or order-communications service. In particular, DAPB4101 covers its scoped pathology-reporting leg into the requesting GP organisation; it does not govern every diagnostic order or result workflow.

Apply to every workflow: Legislation, regulations and statutory duties, Confidentiality and guidance, Core receiving controls and Standards and other controls.

The third column adds workflow-specific routes and candidate instruments or controls, including standards and contracts. The detailed sections below provide the full titles and evidence. Listing is not, by itself, authority or proof of applicability.

Workflow activity Typical incoming flow Main route, candidate instruments and controls First control question
Diagnostic test results and order communications A laboratory sends a pathology result to the requesting GP organisation for direct care; broader local ordering and results workflows require their own scope decision Direct-care sharing route, Clinical safety and security, DAPB4101 pathology transition and the NHS standards applicability register Is the patient, request, report, unit, code, abnormal-result status and clinical owner correct and actionable?
Acute discharge and transfer of care An acute provider sends inpatient or day-case discharge information to the GP Sharing with the wider NHS and the NHS standards applicability register Who owns timely review, medicines reconciliation, follow-up and correction?
Community-pharmacy information A pharmacy sends a service event, vaccination, medicine or consultation outcome to the GP record Sharing with the wider NHS and the NHS standards applicability register Is the medicine or event state unambiguous, reconciled and safely handled if messaging fails?
Shared-care records and care plans PHC receives or views information from hospital, community, mental-health, social-care or neighbourhood services Direct-care sharing route and Shared care and GP Connect Which source, role, care relationship, context, objection and correction route justify the view?
Referrals and bookings A response, triage outcome, booking, cancellation or return referral enters a PHC workflow Direct-care sharing route, Sharing with the wider NHS, Clinical safety and security and the NHS standards applicability register, subject to the published use case and scope Which published use case applies, and are acknowledgement, cancellation, error and escalation states closed?
Patient or carer information Online consultation, message, proxy request, measurement, questionnaire, wearable or other patient-generated information Five distinct data routes, Data protection and transparency, Confidentiality and Caldicott, Accessible Information and the Identity Verification and Authentication Standard What service has accepted clinical responsibility, what response is promised, and how are provenance and safety limits shown?
Other-provider documents and messages Independent, voluntary, social-care or commissioned provider information arrives by structured message, document or local platform Sharing with other providers Can PHC identify the sender, purpose, data quality, care relationship, clinical owner and onward-use limits?

Core receiving controls

For every incoming flow, record:

  1. correct patient, requesting organisation and intended recipient;
  2. source organisation, author, provenance, timestamps and version;
  3. preserved codes, display terms, units, negation, uncertainty and clinical context;
  4. a named person or team responsible for review, reconciliation and action;
  5. acknowledgement, duplicate detection, correction and source-feedback routes;
  6. latency, partial-message, outage and downtime behaviour;
  7. role-based access, audit, retention and onward-use controls;
  8. whether later NHS App publication, analytics, artificial intelligence, planning or research is a separate purpose requiring a separate decision.

The Minimum-to-maximum requirement model applies to receipt as well as disclosure. The minimum is the necessary information and full control set for the clinical purpose; the higher-assurance ceiling is the widest purpose-relevant structured content that can be safely used, not whole-record availability.

Legislation, regulations and statutory duties

There is no separate blanket “incoming-data law.” The sender must have authority to disclose, and the PHC recipient must have its own purpose, controller authority and controls for receipt, use, storage and any onward disclosure.

Full title Status and incoming-PHC contribution Maintained information
United Kingdom General Data Protection Regulation (UK GDPR) Current law when personal data are involved. Applies to receipt, matching, clinical use, storage, onward use, transparency, security and accountability as well as to transmission. SRC-001
Data Protection Act 2018 Current law. Supplies UK conditions and safeguards, including Schedule 1 where applicable; receipt does not remove the need for an Article 6 basis, Article 9 condition or confidentiality analysis. SRC-002
Data (Use and Access) Act 2025 Current amending law. Amends rather than replaces UK GDPR and the Data Protection Act 2018. SRC-003, SRC-004
Health and Social Care (Safety and Quality) Act 2015, section 3, inserting Health and Social Care Act 2012 section 251B Conditional direct-care disclosure duty on an in-scope sender. It can support necessary information reaching PHC when the statutory conditions are met; it does not grant the recipient whole-record access or authorise later reuse. SRC-006
Health and Social Care Act 2012, Part 9 Chapter 1, sections 250–251, as amended and Data (Use and Access) Act 2025, Schedule 15 Current information-standards framework. An applicable published standard can impose sender, receiver or supplier requirements in its stated scope. SRC-034, SRC-035
Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82) and Health and Social Care Information Standards (Procedure) Regulations 2025 (SI 2025/950) Current regulations about the standards framework. They do not make every directory entry applicable or provide the clinical purpose. SRC-036, SRC-037
National Health Service (General Medical Services Contracts) Regulations 2015 (SI 2015/1862), as amended, National Health Service (General Medical Services Contracts and Personal Medical Services Agreements) (Amendment) Regulations 2026 (SI 2026/532) and Standard General Medical Services Contract 2026/27 Contract-type conditional. Check the actual practice contract and supplier capability for receiving, updating and acting on information; do not infer a universal obligation from a product name. SRC-047, SRC-048
National Health Service Act 2006, section 251 and Health Service (Control of Patient Information) Regulations 2002 (SI 2002/1438) Conditional only for a later beyond-care purpose. Direct-care receipt does not carry this support into analytics, research or another reuse. SRC-008, SRC-030
Equality Act 2010, sections 20, 29 and 149 and Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018, as amended Actor-, service- and scope-dependent. Relevant when incoming digital routes, documents or communications need reasonable adjustments and accessible alternatives. SRC-061, SRC-062

Confidentiality and guidance

Standards and other controls

Every standard below is scoped. Read its full NHS standards applicability register row and primary evidence before treating it as mandatory.

Explicit incoming-PHC standards

Shared-care, booking and content standards

Identity, terminology, interoperability, safety and security

GP Connect boundary

GP Connect Access Record: Structured – FHIR API primarily retrieves information from the GP-held record for authorised direct-care consumers. It is not a generic inbound-message standard and has no universal section 250 Information Standards Notice. Treat any Update Record or other capability according to the current contract, product specification, onboarding and safety evidence. SRC-015, SRC-038, SRC-039

Apply this to one flow

Use the Sharing route decision workflow and record:

  1. the sender, receiving PHC service, person, purpose, benefit and expected information;
  2. the sender’s disclosure authority and the recipient’s authority for receipt and clinical use;
  3. the applicable standard, version, Information Standards Notice, organisations, use case and dates;
  4. matching, provenance, meaning, acknowledgement, reconciliation, correction and downtime controls;
  5. clinical ownership for review and action, including partial, duplicate, late or failed messages;
  6. the separate decision for any onward disclosure, NHS App publication, planning, analytics, artificial intelligence or research reuse.

Do not accept information into an unmanaged inbox or database where no one owns matching, review, action, correction and service failure.