2. Information sharing into primary healthcare (PHC)
Core answer
Receipt is not the end of an information-sharing flow. Primary healthcare must bring incoming information into a controlled clinical workflow with the correct patient and recipient, known sender and provenance, preserved clinical meaning, a named owner for review and action, acknowledgement, reconciliation, correction and safe downtime handling.
Return to the Core PHC summary, or compare Information sharing out of primary healthcare.
Workflow activities
These are broad operational workflows, not authority or mandate labels. Name the exact record-access or order-communications service. In particular, DAPB4101 covers its scoped pathology-reporting leg into the requesting GP organisation; it does not govern every diagnostic order or result workflow.
Apply to every workflow: Legislation, regulations and statutory duties, Confidentiality and guidance, Core receiving controls and Standards and other controls.
The third column adds workflow-specific routes and candidate instruments or controls, including standards and contracts. The detailed sections below provide the full titles and evidence. Listing is not, by itself, authority or proof of applicability.
| Workflow activity | Typical incoming flow | Main route, candidate instruments and controls | First control question |
|---|---|---|---|
| Diagnostic test results and order communications | A laboratory sends a pathology result to the requesting GP organisation for direct care; broader local ordering and results workflows require their own scope decision | Direct-care sharing route, Clinical safety and security, DAPB4101 pathology transition and the NHS standards applicability register | Is the patient, request, report, unit, code, abnormal-result status and clinical owner correct and actionable? |
| Acute discharge and transfer of care | An acute provider sends inpatient or day-case discharge information to the GP | Sharing with the wider NHS and the NHS standards applicability register | Who owns timely review, medicines reconciliation, follow-up and correction? |
| Community-pharmacy information | A pharmacy sends a service event, vaccination, medicine or consultation outcome to the GP record | Sharing with the wider NHS and the NHS standards applicability register | Is the medicine or event state unambiguous, reconciled and safely handled if messaging fails? |
| Shared-care records and care plans | PHC receives or views information from hospital, community, mental-health, social-care or neighbourhood services | Direct-care sharing route and Shared care and GP Connect | Which source, role, care relationship, context, objection and correction route justify the view? |
| Referrals and bookings | A response, triage outcome, booking, cancellation or return referral enters a PHC workflow | Direct-care sharing route, Sharing with the wider NHS, Clinical safety and security and the NHS standards applicability register, subject to the published use case and scope | Which published use case applies, and are acknowledgement, cancellation, error and escalation states closed? |
| Patient or carer information | Online consultation, message, proxy request, measurement, questionnaire, wearable or other patient-generated information | Five distinct data routes, Data protection and transparency, Confidentiality and Caldicott, Accessible Information and the Identity Verification and Authentication Standard | What service has accepted clinical responsibility, what response is promised, and how are provenance and safety limits shown? |
| Other-provider documents and messages | Independent, voluntary, social-care or commissioned provider information arrives by structured message, document or local platform | Sharing with other providers | Can PHC identify the sender, purpose, data quality, care relationship, clinical owner and onward-use limits? |
Core receiving controls
For every incoming flow, record:
- correct patient, requesting organisation and intended recipient;
- source organisation, author, provenance, timestamps and version;
- preserved codes, display terms, units, negation, uncertainty and clinical context;
- a named person or team responsible for review, reconciliation and action;
- acknowledgement, duplicate detection, correction and source-feedback routes;
- latency, partial-message, outage and downtime behaviour;
- role-based access, audit, retention and onward-use controls;
- whether later NHS App publication, analytics, artificial intelligence, planning or research is a separate purpose requiring a separate decision.
The Minimum-to-maximum requirement model applies to receipt as well as disclosure. The minimum is the necessary information and full control set for the clinical purpose; the higher-assurance ceiling is the widest purpose-relevant structured content that can be safely used, not whole-record availability.
Legislation, regulations and statutory duties
There is no separate blanket “incoming-data law.” The sender must have authority to disclose, and the PHC recipient must have its own purpose, controller authority and controls for receipt, use, storage and any onward disclosure.
| Full title | Status and incoming-PHC contribution | Maintained information |
|---|---|---|
| United Kingdom General Data Protection Regulation (UK GDPR) | Current law when personal data are involved. Applies to receipt, matching, clinical use, storage, onward use, transparency, security and accountability as well as to transmission. | SRC-001 |
| Data Protection Act 2018 | Current law. Supplies UK conditions and safeguards, including Schedule 1 where applicable; receipt does not remove the need for an Article 6 basis, Article 9 condition or confidentiality analysis. | SRC-002 |
| Data (Use and Access) Act 2025 | Current amending law. Amends rather than replaces UK GDPR and the Data Protection Act 2018. | SRC-003, SRC-004 |
| Health and Social Care (Safety and Quality) Act 2015, section 3, inserting Health and Social Care Act 2012 section 251B | Conditional direct-care disclosure duty on an in-scope sender. It can support necessary information reaching PHC when the statutory conditions are met; it does not grant the recipient whole-record access or authorise later reuse. | SRC-006 |
| Health and Social Care Act 2012, Part 9 Chapter 1, sections 250–251, as amended and Data (Use and Access) Act 2025, Schedule 15 | Current information-standards framework. An applicable published standard can impose sender, receiver or supplier requirements in its stated scope. | SRC-034, SRC-035 |
| Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82) and Health and Social Care Information Standards (Procedure) Regulations 2025 (SI 2025/950) | Current regulations about the standards framework. They do not make every directory entry applicable or provide the clinical purpose. | SRC-036, SRC-037 |
| National Health Service (General Medical Services Contracts) Regulations 2015 (SI 2015/1862), as amended, National Health Service (General Medical Services Contracts and Personal Medical Services Agreements) (Amendment) Regulations 2026 (SI 2026/532) and Standard General Medical Services Contract 2026/27 | Contract-type conditional. Check the actual practice contract and supplier capability for receiving, updating and acting on information; do not infer a universal obligation from a product name. | SRC-047, SRC-048 |
| National Health Service Act 2006, section 251 and Health Service (Control of Patient Information) Regulations 2002 (SI 2002/1438) | Conditional only for a later beyond-care purpose. Direct-care receipt does not carry this support into analytics, research or another reuse. | SRC-008, SRC-030 |
| Equality Act 2010, sections 20, 29 and 149 and Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018, as amended | Actor-, service- and scope-dependent. Relevant when incoming digital routes, documents or communications need reasonable adjustments and accessible alternatives. | SRC-061, SRC-062 |
Confidentiality and guidance
- Common law duty of confidentiality remains separate from data protection. The sender’s confidentiality route and the recipient’s care purpose, access limits and reasonable patient expectations must be evidenced. SRC-007
- Information Commissioner’s Office Data Sharing Code of Practice supports documented purposes, roles, DPIA, agreements, transparency, security and review; it is currently under review following the Data (Use and Access) Act 2025. SRC-005
- National Data Guardian’s eight Caldicott Principles apply to receiving design as well as sending: justified purpose, necessity, minimum information, need-to-know access, accountability, legal compliance, confidence to share and no surprises. SRC-010
Standards and other controls
Every standard below is scoped. Read its full NHS standards applicability register row and primary evidence before treating it as mandatory.
Explicit incoming-PHC standards
- Pathology and Laboratory Medicine Reporting Information Standard (DAPB4101 Amd 63/2023 v1.0.0) — scoped section 250 standard for pathology reports from laboratories to requesting GP organisations for direct care. Its current Information Standards Notice still states 30 April 2025; NHS England says the date will be extended but has not published a replacement. April 2027 is a pilot testing and assurance milestone, not a replacement deadline or proof of national rollout. SRC-028
- Transfer of Care – Acute Inpatient Discharge (DAPB4042 Amd 75/2021 v1.0.0) — scoped section 250 and NHS Standard Contract requirement for acute or day-case discharge information sent to GP practice systems. SRC-025
- Community Pharmacy Information Standard (DAPB4008 5/2023) — scoped section 250 standard for community-pharmacy information sent to GP practices, with service-specific transport and implementation considerations. SRC-024
Shared-care, booking and content standards
- Core Information Standard — non-prescriptive shared-care content ceiling without a demonstrated universal section 250 mandate. SRC-014
- Personalised Care and Support Plan (DAPB4022 Amd 38/2021 v1.0.0) — scoped section 250 care-plan content standard for specified GP, community, mental-health and hospital services. SRC-023
- NHS Booking and Referral Standard (DAPB4060 Amd 99-2021) — conditionally mandatory only for published in-scope booking and referral use cases. SRC-027
- Accessible Information (DAPB1605 Amd 30/2025 v1.1.0) — scoped standard requiring communication needs to be identified, recorded, flagged, shared, met and reviewed. SRC-054
Identity, terminology, interoperability, safety and security
- NHS Number for General Practice (ISB 0149-01) — scoped mandatory identity and matching floor. SRC-016
- SNOMED CT (SCCI0034 Amd 35/2016) — scoped mandatory terminology floor for coded clinical meaning. SRC-017
- NHS Dictionary of Medicines and Devices (SCCI0052 Amd 13/2013) — scoped medicines and devices terminology floor for electronic direct-care exchange. SRC-018
- UK Core FHIR Release 4 Governance (DAPB4020 Amd 33/2021) — scoped cross-boundary FHIR profiling governance. SRC-022
- Clinical Risk Management: its Application in the Manufacture of Health IT Systems (DCB0129 Amd 24/2018) — scoped manufacturer/modifier clinical-safety floor covering creation, transformation and product hazards. SRC-019
- Clinical Risk Management: its Application in the Deployment and Use of Health IT Systems (DCB0160 Amd 25/2018) — scoped deploying/using organisation clinical-safety floor covering receiving workflow, downtime and use. SRC-020
- Data Security and Protection Toolkit (DAPB0086 Amd 21/2025 v8.0.0) — scoped assurance floor; completion does not prove the particular incoming flow lawful, accurate or safe. SRC-040
- Identity Verification and Authentication Standard for Health and Care Digital Data Analytics and Technology Use (DAPB3051 Amd 59/2025 v3.1.0) — applies where the incoming service gives people scoped digital access; authentication does not establish care relationship or function-level authority. SRC-069
GP Connect boundary
GP Connect Access Record: Structured – FHIR API primarily retrieves information from the GP-held record for authorised direct-care consumers. It is not a generic inbound-message standard and has no universal section 250 Information Standards Notice. Treat any Update Record or other capability according to the current contract, product specification, onboarding and safety evidence. SRC-015, SRC-038, SRC-039
Apply this to one flow
Use the Sharing route decision workflow and record:
- the sender, receiving PHC service, person, purpose, benefit and expected information;
- the sender’s disclosure authority and the recipient’s authority for receipt and clinical use;
- the applicable standard, version, Information Standards Notice, organisations, use case and dates;
- matching, provenance, meaning, acknowledgement, reconciliation, correction and downtime controls;
- clinical ownership for review and action, including partial, duplicate, late or failed messages;
- the separate decision for any onward disclosure, NHS App publication, planning, analytics, artificial intelligence or research reuse.
Do not accept information into an unmanaged inbox or database where no one owns matching, review, action, correction and service failure.