Skip to content

Shared records, summary records and care plans

At a glance

This workflow makes a purpose- and role-filtered record view, summary or care-plan contribution available across organisational boundaries for individual care. A shared platform or technical connection does not create a universal right to the whole record.

Return to the Out-of-PHC row or Into-PHC row.

Scope and boundaries

This family includes on-demand shared-care record viewing, a GP-held summary exposed through a named service, and purpose-specific care-plan content. It does not automatically include a pushed referral, discharge message, diagnostic result, bulk extract or later planning/research use. Record access and contribution or write-back are different capabilities and need separate evidence.

The Direct-care sharing route is the usual starting route. Use the exact service name, consumer and provider roles, care relationship, permitted function and information view. CLM-011 CLM-019

Out of primary healthcare

PHC may expose a role-filtered view or contribute agreed content to an authorised care team. The outward decision must identify the current care purpose, recipient organisation and staff role, necessary content, objection or restriction handling, audit, correction and what the recipient may do next.

GP Connect Access Record is a read-only product route in the scopes described by its current contract and product rules; it is not generic write access or a universal section-250 mandate. SRC-015 SRC-038 SRC-039

Into primary healthcare

When PHC views or receives information from a shared record or care plan, it must preserve source, author, time, status and context. Someone must own review, reconciliation, correction and action. Visibility in an external record does not by itself update the GP record or transfer clinical responsibility.

How the requirement layers apply

Layer Workflow-specific position
Legislation UK GDPR and DPA 2018 apply when personal data are processed. The Section 251B direct-care duty is conditional on its statutory organisations and tests.
Regulations and contract The GMS Regulations and current contract can require particular GP Connect enablement or access functions for in-scope practices; check the executed contract and capability.
Standards Candidate standards include the Core Information Standard, GP Connect Access Record, Personalised Care and Support Plan, NHS Number, SNOMED CT, UK Core FHIR, DCB0129, DCB0160 and DSPT. Each remains scope-dependent.
Confidentiality and other controls Apply the Common law duty of confidentiality and Caldicott Principles, care-relationship and need-to-know checks, patient expectations and objections, sensitive/third-party content controls, break-glass, audit, provenance and correction.

Minimum, conditional and higher assurance

  • Required floor: prove the purpose, care relationship, authorised role, necessary view, confidentiality route and every applicable product, contract, safety and security condition.
  • Conditional envelope: disclose or view only the content relevant to the current care function; record how objections, restrictions and exceptional access are handled.
  • Higher-assurance ceiling: use structured, coded, provenance-rich content with reliable identity, context-sensitive access, closed correction feedback and monitored break-glass use—not whole-record availability. CLM-013

Failure states and ownership

Test wrong-patient selection, stale or duplicate information, missing provenance, inappropriate role access, unavailable source systems, break-glass misuse, failed correction and ambiguity over whether information was merely viewed or incorporated into the local record.

Evidence and open checks

Maintained evidence: SRC-006, SRC-007, SRC-014, SRC-015, SRC-023, SRC-038, SRC-039, SRC-047, SRC-048. Recheck the live product, supplier combination and access model through VAL-005.

Continue to Assess and record this workflow.