Skip to content

Community, mental-health, ambulance, social-care and other-provider updates

At a glance

Use this residual incoming workflow for an event-driven document or message from another provider that is not better classified as a diagnostic result, referral response, transfer of care, pharmacy event or shared-record view.

Return to the Into-PHC row.

Scope and boundaries

This family can include community, mental-health, ambulance, social-care, voluntary, independent or commissioned-provider documents and messages. Provider ownership does not determine the route: the purpose, care relationship, service, content and receiver obligations do.

If the message is a referral state, discharge/handover, diagnostic report, pharmacy event or shared-record view, use that more specific workflow page. If it is for planning, research or another beyond-care purpose, use the Beyond-care sharing route.

Into primary healthcare

PHC must identify the sender, service, patient, purpose, data quality and intended clinical owner. It must decide whether the information is merely available for reference, needs incorporation into the GP record, requires action or correction, or is outside the expected pathway.

Non-NHS ownership does not prohibit legitimate sharing, and an NHS badge or commissioning contract does not create authority. Confirm controller and processor roles from the facts and control onward use and service exit. CLM-014

How the requirement layers apply

Layer Workflow-specific position
Legislation UK GDPR and DPA 2018 apply. A qualified Section 251B duty applies only to an in-scope sender and direct-care flow.
Regulations and contract No universal provider-to-PHC regulation is identified. Check the exact provider type, commissioned service, receiving-practice contract and any specialist statutory regime. COPI is not routine direct-care authority.
Standards There is no universal document/message standard for this residual category. Add a service- or content-specific standard only after matching the exact flow. Candidate foundations can include NHS Number, SNOMED CT, UK Core FHIR, DCB0129, DCB0160 and DSPT.
Confidentiality and other controls Apply common-law confidentiality, Caldicott, sender identity, controller/processor analysis, appropriate agreements, care relationship, provenance, data quality, onward-use limits, audit, correction, incident management and service-exit controls.

Minimum, conditional and higher assurance

  • Required floor: identified sender and patient, defined service and purpose, necessary content, authority and confidentiality, provenance, a named clinical owner and safe correction/failure route.
  • Conditional envelope: accept or use only information relevant to the expected service and current care; separate any onward or beyond-care purpose.
  • Higher-assurance ceiling: structured, interoperable provider updates with dependable identity, provenance, status and acknowledgement, tested integration, correction feedback and controlled service exit.

Failure states and ownership

Test unknown or spoofed senders, wrong-patient documents, incompatible formats, missing author/time/status, duplicates, unexpected sensitive content, unread inboxes, ambiguous clinical responsibility, unsafe local record incorporation, missing corrections, supplier exit and loss of audit history.

Evidence and open checks

Maintained evidence: SRC-001, SRC-005, SRC-007, SRC-012, SRC-031, SRC-038, SRC-039. Use Sharing with other providers for the organisational assurance layer and VAL-003 for the real controller/confidentiality decision.

Continue to Assess and record this workflow.