1. Information sharing out of primary healthcare (PHC)
Core answer
There is no universal outbound PHC dataset or single permission to share. Start with one defined purpose and recipient. For individual care, disclose only necessary, role-relevant information through the applicable direct-care route. For research, planning, commissioning, audit or another beyond-care purpose, make a separate decision and use anonymous information where practicable.
Return to the Core PHC summary, or continue to Information sharing into primary healthcare.
Workflow activities
Start with the work being done, then classify its purpose and recipients in the next section. Use the full record-service name rather than “SCR” alone, and name the exact order-communications system and workflow; similar shorthand can conceal different content, access and failure behaviour. A workflow or product name never supplies authority by itself.
Apply to every workflow: Legislation, regulations and statutory duties, Confidentiality, choices and statutory guidance and Standards and other controls.
The third column adds workflow-specific routes and candidate instruments or controls, including standards and contracts. The detailed sections below provide the full titles and evidence. Listing is not, by itself, authority or proof of applicability.
| Workflow activity | Typical outward PHC activity | Main route, candidate instruments and controls | First workflow question |
|---|---|---|---|
| Shared-care and summary-record access | PHC makes a role-filtered record view, summary or care-plan contribution available to an authorised direct-care team through a specifically named service | Direct-care sharing route, Shared care and GP Connect, Core Information Standard, GP Connect Access Record: Structured – FHIR API and Personalised Care and Support Plan | Which exact record service, care relationship, role and information view are being approved, and how are objection, override, audit and correction handled? |
| Diagnostic test ordering and results | PHC sends a test request, patient and recipient identifiers and the necessary clinical context; acknowledgements, status changes and the later report form linked but distinct message legs | Direct-care sharing route, Sharing with the wider NHS, Terminology and identifiers and Clinical safety and security. Pathology and Laboratory Medicine Reporting Information Standard (DAPB4101) governs its scoped pathology-reporting leg into the requesting GP organisation, not every order-communications workflow. | Can the order, patient, requester, specimen or procedure, acknowledgement, cancellation, correction and final result be correlated end to end? |
| Referrals, triage and bookings | PHC sends referral content or a booking request and receives acknowledgement, triage, acceptance, rejection, appointment and cancellation states | Direct-care sharing route, Sharing with the wider NHS and Clinical safety and security, followed by the Clinical Referral Information Standard and NHS Booking and Referral Standard where the published use case and scope fit | Which exact referral or booking use case applies, and who closes rejected, returned, cancelled, failed or unanswered work? |
| Transfers of care and clinical correspondence | PHC sends a care summary, handover, care plan, clinical letter or other purpose-specific information to another team | Sharing with the wider NHS, Core Information Standard and Personalised Care and Support Plan where their scopes fit | What event triggers the transfer, which content is necessary now, and who owns receipt, reconciliation, follow-up and correction? |
| Medicines, prescribing and pharmacy | PHC sends prescription, medication, allergy, administration, review or reconciliation information to a pharmacy or another care team | Pharmacy and medicines and NHS Dictionary of Medicines and Devices. Community Pharmacy Information Standard (DAPB4008) is the scoped community-pharmacy-to-GP leg, not a universal outbound PHC standard. | What is the authoritative medicine or prescription state, and how are changes, duplicates, substitutions, cancellation, dispensing and reconciliation represented? |
| Patient access, requests and communications | PHC provides record access, proxy access, messages, appointment or prescription transactions and accessible digital or non-digital communications | Five distinct data routes, Data protection and transparency, Confidentiality and Caldicott, Accessible Information and the Identity Verification and Authentication Standard, subject to the distinct NHS App, NHS Notify, record-access, proxy and transaction routes | Is this record access, delegated access, a transaction or a message, and what safeguarding, accessibility, response and fallback controls apply? |
| Population health, research, audit and reporting | PHC supplies a defined extract, collection, disclosure or approved access route beyond an individual-care workflow | Beyond-care sharing route, Research, planning and audit and Opt-outs and section 251 | Can anonymous information achieve the purpose; if not, what exact authority, confidentiality route, opt-out result, specification and recipient apply? |
These rows are operational entry points, not universal mandates. The maintained source evidence is attached to the linked route and standards pages.
Sharing contexts and purposes
Use this second view to classify why information leaves PHC and the type of recipient involved.
| Sharing context or purpose | Typical outward flow | Maintained route | First control question |
|---|---|---|---|
| Direct individual care within the NHS | GP record access, shared-care views, neighbourhood teams, community, mental-health or ambulance care | Direct-care sharing route and Sharing with the wider NHS | Is the recipient genuinely involved in this person’s care, and is each item relevant now? |
| Referrals, booking and clinical transactions | Primary-to-secondary referral, urgent-care booking, care-plan or medicines information | Sharing with the wider NHS and the NHS standards applicability register | Which exact use case, sender, receiver, acknowledgement and correction route apply? |
| Independent and other providers | Commissioned private, voluntary, charitable, community or social-care services | Sharing with other providers | What service and role justify access, and how are onward use and service exit controlled? |
| Patients and carers | Record access, proxy access, messages, appointments, prescriptions and supported digital services | Five distinct data routes | Is this the person’s access, delegated access or a provider disclosure, and what safeguarding or third-party restrictions apply? |
| Research, planning, commissioning and audit | Identifiable or pseudonymised GP data leaving the practice or GP system | Beyond-care sharing route and Research, planning and audit | Can anonymous information achieve the purpose; if not, what separate confidentiality route and opt-out result apply? |
| Required collections or disclosures | A specified NHS England collection, safeguarding, public-health, court or regulator route | Legislation and duties and the Validation queue | What exact current statutory gateway, direction, data specification and recipient apply? |
Legislation, regulations and statutory duties
These instruments are candidates, not a checklist that automatically authorises disclosure. Applicability depends on the purpose, parties, data and scope.
| Full title | Status and outward-PHC contribution | Maintained information |
|---|---|---|
| United Kingdom General Data Protection Regulation (UK GDPR) | Current law when personal data are involved. Requires an Article 6 basis, an Article 9 condition for health data, principles, transparency, security, accountability and a risk-based DPIA. | SRC-001 |
| Data Protection Act 2018 | Current law. Supplies UK conditions and safeguards, including Schedule 1 provisions where applicable; it does not replace Article 6 or confidentiality. | SRC-002 |
| Data (Use and Access) Act 2025 | Current amending law. Amends rather than replaces UK GDPR and the Data Protection Act 2018. | SRC-003, SRC-004 |
| Health and Social Care (Safety and Quality) Act 2015, section 3, inserting Health and Social Care Act 2012 section 251B | Conditional direct-care duty. Applies only to relevant bodies and disclosures likely to facilitate the person’s care, in their best interests and not barred by an objection or another statutory exception. | SRC-006 |
| National Health Service Act 2006, section 251 and Health Service (Control of Patient Information) Regulations 2002 (SI 2002/1438) | Conditional beyond-care route. Requires the defined regulation, approval, conditions and period; it is not self-executing or a blanket permission. | SRC-008, SRC-030 |
| Health and Social Care Act 2012, Part 9 Chapter 1, sections 250–251, as amended and Data (Use and Access) Act 2025, Schedule 15 | Current information-standards framework. Creates the framework under which an applicable published standard can impose scoped requirements; it does not itself authorise a disclosure. | SRC-034, SRC-035 |
| Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82) and Health and Social Care Information Standards (Procedure) Regulations 2025 (SI 2025/950) | Current regulations about the standards framework. They commenced amendments and govern preparation/publication procedure; neither supplies the purpose for sharing. | SRC-036, SRC-037 |
| National Health Service (General Medical Services Contracts) Regulations 2015 (SI 2015/1862), as amended, National Health Service (General Medical Services Contracts and Personal Medical Services Agreements) (Amendment) Regulations 2026 (SI 2026/532) and Standard General Medical Services Contract 2026/27 | Contract-type conditional. Current practice terms can require specific digital capabilities, including in-scope GP Connect enablement; check the executed GMS, PMS or APMS terms and variations. | SRC-047, SRC-048 |
| Equality Act 2010, sections 20, 29 and 149 and Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018, as amended | Actor-, service- and scope-dependent. Relevant to reasonable adjustments, public-sector equality and accessible digital disclosure routes; neither is a general health-data sharing power. | SRC-061, SRC-062 |
| National Health Service Act 2006, sections 13G and 14Z35 | Organisation- and function-specific. Requires NHS England and integrated care boards respectively to have regard to reducing inequalities in access to and outcomes from health services; it is not a general provider disclosure power. | SRC-063 |
Confidentiality, choices and statutory guidance
- Common law duty of confidentiality is separate from data protection. Individual-care sharing may use implied confidentiality consent only where the maintained conditions are met; beyond-care use normally needs a distinct route. SRC-007
- Information Commissioner’s Office Data Sharing Code of Practice is a statutory code covering purpose, roles, DPIA, agreements, transparency, security and review. It is under review following the Data (Use and Access) Act 2025. SRC-005
- National Data Guardian’s eight Caldicott Principles require justified purpose, necessity, minimum information, need-to-know access, accountability, compliance, confidence to share and no surprises. They are not standalone authority. SRC-010
- Type 1 opt-out and national data opt-out are separate choices. For identifiable GP record data leaving the GP system beyond care, record the Type 1 result; separately apply the national data opt-out where the later use or disclosure is in scope. SRC-009, SRC-033
- NHS Notify Service Directions 2025 require NHS England to operate the NHS Notify service; they are not the sending practice’s authority or a universal adoption duty. The Medium Term Planning Framework 2026/27–2028/29 separately sets current planning expectations for named addressees, including integrated care boards’ transition of primary-care messaging. SRC-044, SRC-076
Standards and other controls
The NHS Standards Directory is a signposting service containing both mandated and non-mandatory entries. “Active” is a lifecycle state, not proof of universal mandate. For every candidate below, check its Information Standards Notice, organisations, use case, version and dates.
Direct care, shared records, referrals and access
- Core Information Standard — higher-assurance shared-care content ceiling; no universal section 250 mandate is shown. SRC-014
- GP Connect Access Record: Structured – FHIR API — contractual enablement plus a technical direct-care ceiling; not a universal consumer entitlement or beyond-care route. SRC-015, SRC-038, SRC-039
- Personalised Care and Support Plan (DAPB4022 Amd 38/2021 v1.0.0) — scoped section 250 content standard for specified services and use cases. SRC-023
- Clinical Referral Information Standard — higher-assurance referral-content ceiling without a demonstrated universal section 250 mandate. SRC-026
- NHS Booking and Referral Standard (DAPB4060 Amd 99-2021) — conditionally mandatory only for published in-scope use cases. SRC-027
Cross-cutting identity, meaning, safety and security
- NHS Number for General Practice (ISB 0149-01) — scoped mandatory identity and matching floor. SRC-016
- SNOMED CT (SCCI0034 Amd 35/2016) — scoped mandatory clinical terminology floor. SRC-017
- NHS Dictionary of Medicines and Devices (SCCI0052 Amd 13/2013) — scoped mandatory medicines and devices terminology for direct-care electronic exchange. SRC-018
- UK Core FHIR Release 4 Governance (DAPB4020 Amd 33/2021) — scoped governance for UK Core profiling across system boundaries. SRC-022
- Clinical Risk Management: its Application in the Manufacture of Health IT Systems (DCB0129 Amd 24/2018) — scoped manufacturer/modifier clinical-safety floor. SRC-019
- Clinical Risk Management: its Application in the Deployment and Use of Health IT Systems (DCB0160 Amd 25/2018) — scoped deploying/using organisation clinical-safety floor. SRC-020
- Data Security and Protection Toolkit (DAPB0086 Amd 21/2025 v8.0.0) — scoped assurance floor; completion does not prove that this flow is lawful or secure. SRC-040
Beyond-care, patient-facing and collection routes
- Compliance with National Data Opt-outs (DCB3058 Amd 91/2018) — scoped mandatory operational standard for relevant confidential-patient-information uses beyond individual care. SRC-021
- Accessible Information (DAPB1605 Amd 30/2025 v1.1.0) — scoped standard to identify, record, flag, share, meet and review communication needs. SRC-054
- Online and Video Consultation in General Practices (DAPB4031 Amd 54/2021) — section 259 usage-data collection, not authority for the patient-facing service or general clinical-record exchange. SRC-055
- NHS App API — permissioned communications interface and higher-assurance technical specification, not a universal mandate or general GP-record API. SRC-056
- Web Content Accessibility Guidelines 2.2 — conditional legal or contractual accessibility baseline depending on the organisation and service. SRC-057
- Identity Verification and Authentication Standard for Health and Care Digital Data Analytics and Technology Use (DAPB3051 Amd 59/2025 v3.1.0) — scoped identity and authentication floor; authentication does not itself authorise a function or record item. SRC-069
Apply this to one flow
Use the Sharing route decision workflow and record:
- who in PHC sends what, to which recipient, about whom, for what purpose and benefit;
- whether the purpose is individual care or a separately named beyond-care use;
- the exact organisational authority, Article 6 basis, Article 9 condition and confidentiality route;
- objections, Type 1 and national data opt-out results where each applies;
- the applicable standards, contracts, clinical-safety, security and accessibility controls;
- recipient access, onward-use, correction, incident, retention, exit and review ownership.
Do not proceed if the purpose, recipient, authority or confidentiality route is missing, or if technical access defaults to the whole record.