Health Bill (Eleventh sitting) Debate
Full Debate: Read Full DebateCaroline Johnson
Main Page: Caroline Johnson (Conservative - Sleaford and North Hykeham)Department Debates - View all Caroline Johnson's debates with the Department of Health and Social Care
(4 weeks, 1 day ago)
Public Bill Committees
Dr Chambers
The hon. Gentleman makes an interesting point. I suppose this is another chance to use the developing single patient record to ensure that we close the gap. The record could be formed in such a way, and the process put in place, to ensure equity in the system, with mandatory markers.
Amendment 72, also tabled by my hon. Friend the Member for Epsom and Ewell, would require prior membership of the armed forces to be visible to all relevant healthcare workers under the establishment of a single patient record. It would also require the Secretary of State to publish a report on making prior armed forces membership visible on the single patient record.
There are just over 1.85 million armed forces veterans in the UK, 13.6% of them women and 86.4% men. The transition from serving in the armed forces to civilian life can mean that many of those individuals struggle with mental health issues, such as post-traumatic stress disorder. The issues are often specific to the service the individuals have given. Some stats show that more than half of England’s Army veterans have some sort of health problem. I should point out that veterans do not only have mental health problems. Specific back and knee problems are much more common among infantry soldiers because of the type of training they have done over many years.
The amendment seeks to make prior armed forces membership visible to all relevant healthcare workers, and to make the Secretary of State consult on the merits of doing so, so that when a GP is treating a patient, they are aware of that person’s service history without having to ask about it specifically.
I have a couple of questions about amendment 71 for the hon. Member for Winchester. First, can he comment on why the amendment refers to firearms, which have stricter licensing conditions than shotguns? Also, the GP should be aware, because all relevant medical information should filter back to them, that the person has a firearms licence, which, as I say, has stricter criteria. It is essentially harder to get a firearms licence than a shotgun licence. I am interested to hear the hon. Gentleman’s thoughts on that.
On amendment 72, I have a large veteran population in my constituency, and I am very grateful to all those who have put their lives on the line to keep us safe, both today and in the past. I can see that there may be benefits to the amendment in respect of the delivery of the armed forces covenant and aspects of veterans’ care, but I am curious about how it is written. Proposed new subsection (3A) of proposed new section 250E of the National Health Service Act 2006 says that
“regulations must make provision for prior membership…to be visible to all relevant healthcare workers under the establishment of a single patient record”,
but proposed new subsection (3B) requires a report on the potential merits of doing that. It seems slightly counterintuitive to do it and then decide whether it is a good idea, rather than decide whether it is a good idea, consider the pros and cons, and then do it afterwards. I am interested to understand why the hon. Gentleman thinks the amendment is drafted in that way.
Gregory Stafford
It is a pleasure to serve under your chairmanship again, Ms Lewell. On amendment 71, I ought to declare that I am a supporter of the Countryside Alliance. Although I do not own a shotgun myself, I represent a large shooting community and I have been on a shoot relatively recently, but without a gun, so I did not shoot anything.
As I alluded to in my intervention on the hon. Member for Winchester, I spoke on this issue in Westminster Hall some months ago, when it was clear to me that there was a significant level of cross-party support for the idea of mandatory markers for GPs. As mandatory markers for firearms licensing are technically a Home Office issue rather than a Department of Health and Social Care one, the Under-Secretary of State for the Home Department, the hon. Member for Dover and Deal (Mike Tapp), responded to that debate, but he was unable to reassure us that provision would be made. I did not understand the arguments he made, because I think mandatory markers are probably the way forward. Given that they are supported by organisations such as the British Association for Shooting and Conservation and the Countryside Alliance—organisations that one might not have expected to be in favour of them—the Government should look into the idea.
There would clearly be a benefit to the proposal in amendment 71. If a patient who holds a firearms licence presents a serious medical risk because of a mental health crisis, suicidal ideation or behaviour that raises concerns about risks to themselves or others, an immediately visible marker would help clinicians to make informed decisions and take the appropriate safeguarding action. But a firearms licence is obviously not a medical condition, nor is it health information in any traditional sense. This goes back to the point I made in the debate on a previous amendment, about how broad the information that we keep on the single patient record will be. The inclusion of such a marker across the single patient record could lead to issues relating, as we talked about in previous debates, to who would want to see that information.
For example, there may be people out there who are not in favour of recreational shooting, and someone may hold a firearms license for recreational shooting. Of course, section 2 firearms licences, especially for shotguns, are often held by farmers and people involved in conservation, and for all sorts of other reasons, including the control of pest populations. But if someone has a licence for recreational use, there may be people who, for whatever reason, find that to be against their own beliefs and opinions. That might lead to a patient being subjected to a level of intrusion or bias, or perhaps not receiving the care they deserve, because someone has made an assumption about what they are like based on that information. We need to be careful about that.
Before my hon. Friend moves on, may I ask him about security? It might also be possible for someone who looked at the records to identify where guns are kept. That information is currently is more protected than that.
Gregory Stafford
I thank my hon. Friend for that helpful intervention; I had not appreciated that. If that is true, the security and safety of the individual who holds the firearms licence, and indeed of anybody else in the vicinity, is paramount, and we generally would not want people to know precisely where guns are held, because that could be a security risk. I think the hon. Member for Winchester has the best of intentions, but the consequences have not been fully thought through.
Wherever possible, the single patient record will build on source records such as GP records. As such, it will include relevant patient information and, where appropriate, digital markers such as those suggested in the amendments. We have had some useful discussion as a result of the amendments, but such considerations are generally operational, and legislation is neither necessary nor practical.
On amendment 71, Members will know that the Government have been doing significant work in support of a digital medical marker for firearms. Medical information for firearms licensing provided by the applicant has been a mandatory requirement for every firearm and shotgun licence application since November 2021, as we have heard, when the new statutory guidance for chief officers of police on firearms licensing was introduced. When any individual applies for a firearms licence, the applicant’s doctor must provide details of any relevant medical conditions, such as depression, dementia, mental health conditions or drug or alcohol abuse.
A digital maker is placed on the GP patient record when a certificate is granted, and a GP can alert the police if a licence holder has a relevant medical condition. The digital marker automatically flags to the GP if a patient is suffering from a relevant medical condition and is a firearms certificate holder. It is true that the marker is not legally mandated, but it is supported by the British Medical Association and the Royal College of General Practitioners, and the former issues guidance to GPs about the firearms marker.
GPs already have professional duties to consider patient and public safety, and existing firearms licensing arrangements support GPs to share relevant concerns with the police where appropriate, while the responsibility for licensing decisions rests with the police. Data shows that, since its introduction in 2023, the marker is being used and that GPs are notifying police of medical issues that have arisen. There is nothing to suggest that the system is not effective.
Is it not also the case that anyone who is aware that an employee or relative has a licence and is concerned about their mental health can make such a report?
I am afraid I do not know the answer to the hon. Lady’s question, but if it is relevant, I will try to get back to her on it.
People applying for a licence must now indicate whether they have seen a medical practitioner other than their GP. The Government also intend to make a statutory instrument to require licence holders to inform the police if they consult a third-party medical practitioner who is not their GP.
The single patient record will build on and connect with information from GP source records where appropriate; no new provision is needed for that to happen. That process should be agreed as part of operational arrangements with the profession, in line with the current approach to markers in the GP record. If it is agreed that it would be beneficial for health and care professionals to have wider access to the firearms marker, the single patient record could facilitate that, but we do not intend to fill the Bill with detailed operational requirements such as that.
We do not believe that the SPR is the appropriate vehicle for having a debate about regulations requiring a report on the merits of a mandatory marker. As the hon. Member for Farnham and Bordon said, we should not expand the clearly defined scope of the single patient record—the scope is limited to direct care—to include a debate about what is stored more generally in NHS records. For those reasons, I ask the hon. Member for Winchester to withdraw amendment 71.
On amendment 72, as I have already outlined, the single patient record will build on and connect with existing source records, such as GP or hospital records, wherever possible. Where a person’s status as a military veteran is recorded, it will be possible to make that information available in the single patient record. Therefore, the provisions already ensure that the information is made available, where veterans opt to have that status recorded—that addresses some of the other issues raised by the hon. Member for Farnham and Bordon. There is no need to make any statutory requirement to ensure that staff have that information and consider any necessary adjustments or potential treatment options that may be relevant to ensure safe and effective care.
In addition, the clause contains powers to make regulations to allow people involved in the provision of an individual’s direct care, including that of any veteran after they have left the military, to access their single patient record. We want the single patient record to improve the accessibility and effectiveness of care for everyone. That includes making sure that military veterans can access necessary support and that staff can provide them with appropriate care. Furthermore, duties in the Armed Forces Act 2006 require the NHS and local authorities to have due regard to the armed forces covenant, which, of course, I fully support. For those reasons, I ask the hon. Member for Winchester not to press amendment 72.
Amendment 70, tabled by my hon. Friend the Member for Epsom and Ewell, would require the Secretary of State to prepare and publish a risk assessment on the potential for digital exclusion under the establishment of a single patient record. I declare an interest as the current chair of the all-party parliamentary group on digital communities.
I hope that we Liberal Democrats have been clear that overall, we are supportive of the single patient record; it is important that every patient can access their own health records. Under the SPR, however there is a risk that people belonging to already vulnerable groups will be digitally excluded from accessing their health information. Research commissioned by Ofcom suggests that 2.8 million people—5% of the UK population—do not have access to the internet at all. Although age is a predictor for a person not having access to the internet at home, especially if they are over 85, more than half of such people are younger than 75.
Amendment 70 would ensure that the Secretary of State assesses the potential for digital exclusion with relevant stakeholders, including patient groups, and that the assessment is laid before Parliament. It would also ensure that the Secretary of State takes into consideration the risk of exclusion for those lacking access to a suitable electronic device or suitable broadband connectivity, including people who have disabilities, who belong to socially excluded groups or who lack digital skills.
Amendment 70, as the hon. Member for North Shropshire said, would require the Secretary of State to publish a risk assessment on the potential for digital exclusion in the single patient record. That is important because, as our lives become more electronic and online, there are people who are getting left behind. That could be because they have a disability that prevents or makes it more difficult for them to access online facilities, because they do not have the resources, because they live an area of the country that is less well served by digital or broadband provision, or because they are elderly and have decided that they will not get involved in the digital world.
In fact, according to the Good Things Foundation, 7.9 million people in the UK lack basic digital skills and 1.6 million adults do not have a smartphone, tablet or laptop. Of those with no basic digital skills, 77% are over 65. People need more healthcare as they get older, yet those individuals have fewer digital skills, so this issue needs to be addressed. The NHS Alliance published a report on digital inclusion in March 2026, which found that rural and coastal areas typically have higher levels of digital exclusion than urban areas.
Lincolnshire ICB, which covers the area that I represent, estimates that 21.3% of Lincolnshire’s population live in the most digitally deprived areas. The ICB has a digital inclusion strategy for 2025 to 2028, which includes efforts to try to reduce digital exclusion; I am interested in the Minister’s thoughts on how she might expand that sort of initiative across the country.
The Government’s equality impact assessment for the single patient record recognises that digital exclusion is a significant challenge in several groups with particular protected characteristics and other characteristics. I am interested in learning more from the Minister about how she intends to mitigate that challenge. In many ways, digital availability is a good thing, and it makes things much easier for many people—I am not knocking it in any way—but we need to ensure that people do not get left behind.
I understand that NHS England is supporting public libraries to signpost users to the NHS website and help them navigate it. What will happen to that support as NHS England gets abolished? Does the Minister intend the Department of Health and Social Care to provide something similar?
Amendment 49, tabled in my name, is basically about public awareness. Although we get immersed in what we are doing here, the public are not necessarily following every word that is said in Committee or in this House—or even necessarily every word that appears in the press—so when the single patient record is launched, it is important that they are aware of it, and in particular, aware of their rights.
We have talked about whether a person might want to let a carer see the single patient record or whether they might want to let someone see part but not all of the record. If the record goes live before people are aware of their rights and abilities in relation to it, they might find that things are available to people, or can be viewed by people, who they would not have wished to see them, which could lead to a number of problems. The amendment would allow people to be more aware of the single patient record for a period of time before it is brought in to try to make sure that that sort of problem is mitigated, and I am interested to understand the Minister’s view on it.
Joe Robertson (Isle of Wight East) (Con)
It is a pleasure to serve with you in the Chair, Ms Lewell. I wish to speak on this aspect of the single patient record. Although I support the general intention and aim of the single patient record, I have some wider concerns about how it will be implemented. I will restrict my remarks to the issues related to this group of amendments, and particularly amendment 49 in the name of the shadow Minister, my hon. Friend the Member for Sleaford and North Hykeham.
Plainly, most people—I would probably include myself in this—are not immediately familiar with all the ins and outs of how their medical records are kept and used, and why should they be? However, they have some pretty clear views on what they expect, whether that is confidentiality or their records being used and stored in such a way that does not inadvertently act as a barrier to accessing healthcare in an efficient and timely way. That is why the Government have introduced these proposals, which I mainly support.
I want to speak primarily to amendment 49, in the name of my hon. Friend the Member for Sleaford and North Hykeham, the shadow Minister, and to agree with what my hon. Friend the Member for Farnham and Bordon has just said. Sadly, there will be a large number of people who do not follow the debates in this House or this Committee in great detail, however fascinating they may be. That is perfectly understandable.
The single patient record has genuine potential. It has the potential to put all the different bits of data in one place, so that when, for example, someone is blue-lighted to hospital, their consultant or the doctors treating them in A&E can access the information they need about their medical history and any medications they are on, which could improve clinical outcomes for patients.
I can entirely see the potential of the single patient record, but I am also conscious of the genuine concern among those of our constituents who are aware of this about what it might mean in practical terms for them and their data—it is important to remember that it is their data. They will have concerns, as my hon. Friend the Member for Farnham and Bordon set out, about who can access it, what safeguards are in place, whether they can opt out, and a range of other legitimate questions about how it will work.
I have to say that amendment 49, tabled by my hon. Friend the Member for Sleaford and North Hykeham, is not unreasonable. It would give the Government an opportunity to reassure our constituents and bring them along on this journey, rather than leaving questions unanswered or just addressing them in a Q&A on a Government webpage. People have genuine questions, and in many cases I am confident that the Minister will be able to allay those concerns or put them to rest, but some campaign of that sort is needed.
Such campaigns happen regularly on a range of subjects. The Department of Health and Social Care spends a significant amount of money on public health and awareness campaigns, and His Majesty’s Revenue and Customs spends a large amount of money on reminding everyone to get their tax returns in on time, in the lead up to that, or to remind them of the penalties if they do not. Government do that day in, day out across a range of services and where major changes are being made.
The Government have a genuine opportunity to accept amendment 49, which will help them to bring the people we serve on this journey, and potentially help to realise the benefits and allay people’s concerns. I genuinely hope that the Minister will be able to accept the amendment or will commit to take it away, look at it, engage with my hon. Friend the shadow Minister and possibly bring back a Government amendment that does exactly this on Report.
I am advised to declare that, although I am not a licence holder of a shotgun or a rifle, my husband has both a shotgun and a firearms licence.
I am grateful to hon. Members for this debate. Meaningful public engagement will be key to the success of the single patient record—we absolutely understand that—in building awareness and in designing the system. It has to have digital inclusion at its heart, but adding statutory requirements for public awareness campaigns and risk assessments is not the way forward. Amendment 49 seeks to put such a requirement on a statutory footing. I want to reassure the Committee and all Members: as the right hon. Member for Melton and Syston said, public awareness is absolutely key and will be integral to success. Work is already under way to ensure that we do that; we do not need to wait, nor should we be constrained by the proposed amendment.
In 2024, we began extensive public engagement on the use of data across health and social care, which showed strong support for the single patient record. We have heard that most people felt it was
“long overdue and a necessary step towards better care”.
The public engagement findings indicated support to progress at pace on the concept of a single patient record, to resolve the frustrations that patients and the public have when they have to repeat their story at multiple health and care settings.
As we move towards our ambition to give all patients in England access to a core set of their data through the single patient record from 2028, we will maintain a sustained drumbeat—as they say in the jargon—of public communications to raise awareness of the single patient record. We have heard some examples of where the Government do that well. Of course we want to learn from such examples across the country and from previous Government campaigns that have worked well, to explain the benefits and safeguards in plain English, and to signpost accessible information and feedback routes for patients and the public. I heard the comments made about people who may be excluded or have particular disabilities, including some older people—from conversations with my own constituents, it is often older people or those with multiple disabilities who can have their experience enhanced. We should make no assumptions about who does or does not feel excluded in this space; we need to learn from them all.
Furthermore, we have already published public-facing single patient record information and a dedicated feedback route. We will continue to co-create plain English, easy-read and translated materials, frequently asked questions and “voices heard/action taken” updates with public panels and patient groups ahead of roll-out. We will build on what we learn from that ongoing work as we develop the regulations. For those reasons, I respectfully ask the hon. Member for Sleaford and North Hykeham not to move amendment 49.
On the lead amendment, moved by the hon. Member for North Shropshire, we recognise, as I hope I have assured the Committee, that digital inclusion is an important issue. To quote another Member, we are eager to get it right, and we are taking it very seriously. Digital inclusion is a key driver in addressing health inequalities, supporting individuals and empowering people to better manage their health, which is at the heart of our 10-year plan. It is a system-wide issue, and one that the health and care system is taking action to address. We have considered this as part of the equality impact assessment of the single patient record provisions in the Bill, and will continue to keep those issues and potential mitigations under consideration throughout the development and implementation of the SPR. Therefore, although we agree with the aim of the amendment, we do not consider it necessary. Indeed, it would duplicate work that has already been done.
The Chair
We will vote on amendment 49 later if the hon. Member for Sleaford and North Hykeham wishes to.
I beg to move amendment 48, in clause 47, page 36, line 1, at end insert—
“(4A) Regulations may not be laid under this section unless the Secretary of State has published a plan setting out the measures to be taken to prevent clinicians and other persons involved in the provision of health care or social care from accessing patient information made available through the system otherwise than for the purposes of the care of the patient concerned (an ‘inappropriate access prevention plan’).
(4B) The inappropriate access prevention plan must include—
(a) a description of the technical controls to be applied to restrict access to patient information to those with a legitimate care relationship with the patient;
(b) the system of audit logging to be applied to record each instance of access to patient information, including the identity of the person accessing the information and the time and circumstances of access;
(c) the sanctions applicable to persons who access patient information without lawful authority or without a legitimate care relationship with the patient;
(d) the arrangements for detecting and investigating suspected cases of inappropriate access; and
(e) the role of the Care Quality Commission, the Information Commissioner and any other regulatory body in enforcing compliance with access controls.
(4C) The Secretary of State must lay the inappropriate access prevention plan before both Houses of Parliament.”
This amendment prevents the Secretary of State from making regulations to establish the single patient record unless a plan to prevent inappropriate access by clinicians and other care workers has first been published and laid before Parliament.
Amendment 48 would prevent the Secretary of State from
“making regulations to establish the single patient record unless a plan to prevent inappropriate access by clinicians and other care workers has first been published and laid before Parliament.”
This is about trust. It is about people being able to trust that the records that will now be more widely available will remain confidential and be looked at only by those who need to look at them.
We have seen that people can be uniquely nosey when it comes to accessing medical records. For example, 48 staff members at the University Hospitals of Liverpool Group were found to have looked at the records of those involved in the Southport attack without any medical basis to do so. Almost a dozen staff members were sacked from the Nottingham University Hospitals trust because they had looked at the records of the victims in Nottingham. It is important that we address this, because it is happening already and needs to be tackled.
Paul Arnold, the chief executive of the Information Commissioner’s Office, said that trust is being “jeopardised”. The amendment seeks to ensure that proper thought goes into making sure that people cannot access records they should not be able to look at—for example, those of the Prime Minister or members of the Royal family—before the single patient record is live and can be used. We have Public Department 1 for HMRC; is there an intention to have something similar to close off records to reduce their accessibility where the public may be particularly nosey, either because of the person’s job or because of an event such as a terrorist attack, where we have seen people look at records when they should not have? There were reports that staff at The London Clinic, a private clinic, had been trying to sell records of the Princess of Wales online, so there are examples where this has happened before.
In addition, it is important that people know what the penalties are for deliberately misusing these records. My final question for the Minister is this. If a record has been viewed and there is a data log of it having been viewed, how long will that data log last for? Will it last for six months or a year, or will I be able to look back in 10 years’ time and see who accessed my records today? It is a case of understanding the Minister’s intentions and pushing the Government to ensure that these records are truly private to those who need to see them, not accessible to anyone who just happens to be curious.
Sojan Joseph
I declare that I am a registered nurse. I have worked in the NHS for many years, and I have used patient records throughout my career. The Nursing and Midwifery Council code requires nurses, midwives and nursing associates to respect patient confidentiality, share information appropriately and ensure that patients are informed about how their information is used. That is the existing system, and every nurse, midwife and nursing associate has to follow the code of practice. A similar code is there for the General Medical Council for doctors, and all other registered professionals follow those codes.
On top of that, information governance in the NHS ensures that patient data is handled legally, securely and ethically, providing a framework for data protection and confidentiality. We have numerous different digital systems in the health system currently. Before anyone gets access to those digital systems and patient records, they all have to go through information governance and data protection training. They are then given access to patient records. That is the existing system.
The shadow Minister, the hon. Member for Sleaford and North Hykeham, has just mentioned the Nottingham incident, which is a good example. It is a clear example of where those who accessed the records were able to be identified. There is a clear audit trail, and I have my own experience of taking people through disciplinary proceedings for accessing patients’ notes when it was not relevant to those staff. The existing patient data systems do have provisions to safeguard and monitor who is accessing patient records.
I understand what the hon. Gentleman is saying, which is that there are processes in place already and that the fact that someone got sacked for looking at the records is a sign that the systems work to an extent. However, does the fact that they could look at them at all suggest that the systems are not working well enough? Because it is a computerised system, there are methods for identifying whether someone is likely to need to look at that record. By knowing the profession of the person looking at it, and the department they are in, the computer can help to limit the number of people who look at those records when they should not.
Sojan Joseph
I agree that we are never going to have 100% proof. There will always be people accessing records. What I am talking about is the existing system, which does have provisions. What we need to strengthen is the training and the audit trail. All staff who do the training are aware that they are not supposed to check patients’ records unless it is relevant to them. Those who access records inappropriately should be identified and action should be taken.
Just because we are moving to a single patient record system, it does not mean that everybody is going to access everything they want. People working in the healthcare system are given access based on their role. Not everybody is able to access everything. Systems are in place, and we need to strengthen those systems and the training. We should not be scaremongering by saying that, because we are moving to a single patient record, everybody will be able to see their records.
The hon. Member for Ashford made his point very clearly about what happens when something goes wrong and someone behaves inappropriately—the shadow Minister, my hon. Friend the Member for Sleaford and North Hykeham, has highlighted some very concerning recent incidents—and was right to highlight the ability to follow an audit trail and take action. He is also right to highlight the importance of training.
However, taking action once inappropriate access is known, and then following the audit trail, deals essentially with the consequences rather than preventing it from happening in the first place. That is why amendment 48, and particularly proposed new section 250E(4B)(a) of the National Health Service Act 2006, is important. It describes the technical controls. That goes beyond the audit process and what happens after something has gone wrong. It is about what can be done to build safeguards into the system to make it much harder for anyone to circumvent their obligations, and to build those technical safeguards into the overall design of the single patient record. That is a reasonable ask, because such incidents, while hopefully rare, as the hon. Member for Ashford alluded to, do happen and understandably cause concern.
The challenge is that there is potentially a lot more information in one place, rather than being held in different pots, trusts or GP surgeries. For those inclined to break their legal obligations and behave outside the rules, the potential opportunity to access a wider range of information is more significant. The design of the record needs to have those technical safeguards strengthened and built in.
If we use the example of Southport, the people who could access those records worked in the Liverpool trust, because that is where the records were stored. With the single patient record, as planned, people would be able to access those records from across the country, if they had a clinical reason to do so. However, someone behaving badly could also potentially do so, even if they did not have a reason.
That is the challenge. The Minister knows her brief very well—if I may say, I hope that whatever happens in a few weeks’ time, she retains it. She is that rare thing among Ministers in Government: someone who comes to their position with a hinterland of knowledge, experience and interest, which she has demonstrated through her period in office thus far. I hope that she retains her role, because continuity of Ministers in Government is a good thing.
Can the Minister reassure us on the shadow Minister’s point, which is one that I have been seeking to make? Can she reassure us that the system will include barriers to prevent whoever builds and operates it—whether a third party or someone internal—from having inappropriate access to the records? The data must be ringfenced and protected, so that it does not go out of the country and cannot be accessed by those who are technically running or providing the platform. Even within the social care system, there must be very clear and technical restrictions on who can access the records for legitimate purposes, as the hon. Member for Ashford has highlighted. I think that would just reassure people.
As I said in response to previous amendments, I think the potential of the single patient record to improve clinical outcomes in care is very significant, but we need to bring people with us. I suspect that if anyone can reassure us on those points, it is the Minister.
Gregory Stafford
Before I was rudely interrupted by the fire alarm—I am not taking it as a hint, much to the Minister’s disappointment—I was saying that this is a unique system and that with the unique benefits come unique risks. I was trying to answer the points made by the hon. Member for Ashford.
As my hon. Friend the Member for Sleaford and North Hykeham and my right hon. Friend the Member for Melton and Syston have mentioned, we already know that despite the regulations, whether they are from professional regulators or the ICO, people will get round the system. One of the biggest concerns that patients will raise is not simply whether patient records will be accessed by nefarious people from outside, such as cyber-hackers, hostile states and so on, but whether they are secure from inappropriate access by people who have access to the system. As my hon. Friend the Member for Sleaford and North Hykeham pointed out, those people could be situated anywhere across the country. Patient records should be accessed only where there is a clear clinical, professional need. The public rightly expect robust safeguards, strong audit trails and meaningful consequences where the rules are breached. Amendment 48 raises that important issue. The Minister should explain how inappropriate access will be prevented, how misuse will be detected and what sanctions will apply when the standards are not met.
My hon. Friends have already mentioned a number of cases and I pick another one: the unfortunate case of the three-year-old boy who was hospitalised after being attacked by a crocodile at a zoo. Cambridge University Hospitals trust is currently investigating 40 members of staff who appear to have accessed that boy’s medical records inappropriately.
While we would always hope that that would not happen, unfortunately it clearly does. This single patient record means that someone will potentially be able to look at patients’ records regarding anything and from anywhere in the country. My hon. Friend the Member for Sleaford and North Hykeham slightly generously described some people as “nosey”. Along with those who have an actual ulterior motive, that presents a real challenge. I say to the hon. Member for Ashford that just because the current system is in place to protect patient records as they currently exist, that should not be a bar to making sure that we make the system even more robust given its potential risks.
It goes directly to proposed new section 250F(4B)(b) of the National Health Service Act 2006, which is the system of audit logging to be applied to each record, so that every time someone accesses a patient record or part of that patient record, the identity of the person obtaining that information should be recorded. I believe that the patient should be able to easily see, hopefully in real time, who has been accessing their record and at what time.
We on this side have mentioned a number of big events: that poor boy with the crocodile, terrorist attacks in Southport and so on. I suspect that those data breaches have been identified because they were big events. People have gone out to check that nobody has been inappropriately accessing those records. I worry that every patient record will potentially be available to every single person, and I doubt that there will be an ability to check every single person proactively rather than reactively. That means patients need access themselves to look at their record and see who has been accessing it. If the name of the person who has accessed the record, or the organisation they belong to is available, patients can say, “Well, there is Mr Smith, my child’s paediatrician, and that is fine. However, who is this guy from elsewhere in the country who has looked at the record?” They can then raise that. That is absolutely vital.
My hon. Friend is making a very important point. Does he also think that it is possible for the system to have some designs built into it that identify that someone from another area of the country, or from another department or different profession is unexpectedly looking at results? Perhaps AI could help with this.
Gregory Stafford
My hon. Friend is right. I will not sit here and propose a solution to this problem, but what her amendment does is ensure that the Government look at this and present a plan before both Houses of Parliament, before we get to a single patient record.
I have now touched on the nefarious and the nosey. I think there is also a case of inadvertent access. With this new system, despite what the professional regulators might think, and despite the best training from the Information Commissioner’s Office, there will be occasions in a new system where people do not understand the limits of what they are allowed to look at or the appropriateness of access. There could well be inadvertent access to these systems. Again, the Government need to have a plan and system in place to ensure that there is not inadvertent, non-nefarious access to patient records as well. That is why I am very supportive of amendment 48.
To make sure that this system is trusted by patients, we need to have the highest level of safeguarding possible, both from external attacks and from internal misuse. My hon. Friend’s amendment goes a long way to putting some of that trust in place.
This is another important discussion to have on the record to give patients and the public confidence as we introduce the vital single patient record. I start by stating that the security and privacy of people’s health data is paramount, and we will build the strongest safeguards possible into the record. Members from across the House have asked how those safeguards will be built into how the system is designed and operated, which is what we are doing.
It will operate on a roles-based access control model, similar to other NHS patient record systems where access to patient information is restricted to the authorised user only. The single patient record will go a step further by applying advanced cloud-based audit and oversight capabilities, enabling near real-time monitoring of system access and detection of unusual or inappropriate patterns. That will allow NHS security teams to track and detect access patterns, and to quickly intervene if specific records are accessed by staff who have no clinical relationship with the patient in question.
The single patient record will ensure that just because a clinician has permission to view a specific patient record, that does not mean they are authorised to do so without a clinical need. The security and access arrangements will be set out in the regulations themselves, which will be debated, rightly, in Parliament. Therefore, it is not necessary to set them out in a plan beforehand.
Furthermore, there are already existing enforcement arrangements that provide sanctions for inappropriate access to patient data, which will also include accessing the single patient record. I commend my hon. Friend the Member for Ashford for his extremely helpful intervention, in which he highlighted his own experience in this field. Some of the examples that we heard again today, including Southport, Nottingham, the recent case in Cambridge and others, are truly shocking to people. Clearly, that should never happen, but sadly it has. As my hon. Friend rightly outlined, there are provisions in place for training people on information governance and tracking when that happens.
Additionally, I want to be clear that the Computer Misuse Act 1990 makes it an offence to use a computer to access information in an unauthorised manner, such as a person accessing information without a legitimate reason. Inappropriate or unauthorised access to health records—often referred to as snooping—is a serious offence that can lead to severe penalties, including dismissal, criminal prosecution and financial penalties. Regulated healthcare professionals, such as doctors, nurses and pharmacies, can be reported to their respective professional bodies, which can result in them being struck off in serious cases.
The information commissioner also has powers to investigate and take action against infringements of data protection legislation, which can include monetary penalties, enforcement notices, undertakings, prosecutions and reprimands. Furthermore, patients have a right to access data that is held about them under the data protection legislation, and those rights will continue to apply to the single patient record. For those reasons, I ask the hon. Member for Sleaford and North Hykeham to withdraw her amendment.
We think this is an important issue, so we would like to divide the Committee.
Question put, That the amendment be made.
Clause 47 amends the existing legislation to facilitate the single patient record. We have heard about the many benefits that it may bring, for example for patients who find themselves telling the same story again and again and having to repeat themselves because caregivers cannot see the records that they need to see. That can be frustrating and sometimes very distressing for patients.
I caution the Minister against saying that the single patient record will completely fix that issue, because from a clinical perspective, particularly in certain presentations, hearing the story again from the individual can be helpful for a diagnosis, but the principle is a good one, and it will make things easier for clinicians, particularly if the patient is in an area away from home. Records may be kept in a particular geographical location or hospital, and if someone is away on holiday and they come in, we may not have access to their records. In paediatrics, we often give the parents of children with complex problems letters to carry that have the necessary information in them. That would not be necessary if the record were more accessible, so there are benefits to the single patient record.
There are, however, a lot of questions about it. One problem is that the single patient record has not really been designed yet, so we are being asked to approve something that is a hazy vision in the distance. On 1 June, the Minister said that
“although the Bill establishes the legal framework for the SPR, much of the detail will be in secondary legislation.”—[Official Report, 1 June 2026; Vol. 786, c. 957.]
I appreciate that it will be subject to the affirmative procedure, but we are being asked to make a decision now on something that is unfortunately very woolly.
Will the Minister reassure us that she will address the following questions in the secondary legislation? Who will have permission to edit the information in the single patient record? When will they have access to it? Will it tell us who has edited it—will there be a record of who, when and where? If the record is not accurate when it is edited, how will that be addressed? How will people know that it is inaccurate, and how will it be improved? In 2025, Healthwatch reported that 23% of adults who had seen their medical records reported inaccuracies or missing details, 12% said they had been refused treatment because of inaccurate information, and 10% said they had received inappropriate medication as a result. This is important. In recent years, there have been several incidents of patients dying after doctors used incorrect medical histories and prescribed medication that they should not have. This information needs to be available, but also accurate. I am interested in what the Minister has to say about that.
The other question is: what is going to happen to the records people have now? I am 48. I am sure the Minister is much younger than that, but we have records: our vaccination records, our childhood records, and records of any admissions or treatment we have had. Will those be added to the single patient record, or will the SPR start from day zero and go forwards? If it does, how will people access their historical records? If it goes backwards, what provision has been made to ensure that the data that is input is accurate, and for the cost and personnel required to do it?
Is the intention that the SPR will be one-size-fits-all? The Secretary of State talked about people not being asked to have a one-size-fits-all but being able to access the various systems around the country, but there are so many different systems. In my own practice, if I want to look at the notes of somebody I am caring for, I go to Evolve, where the notes are scanned in and I can look at the pages one at a time. If I want to look at blood results, I go to ICE, which is a different system where I can see the test results. If I want to look at the films of an X-ray, they are on a different computer system again. If I want to follow the patient’s pathway through the hospital, see when their next appointment is with me or see who is next in my clinic, I go on to e-Track. There is a different system for maternity, and there is Symphony in A&E.
Each hospital trust has a lot of different computer systems and information, and they do not all use the same systems, as I know having rotated through a number of hospitals during my training. How will the single patient record work with that? Will people be able to access all those different systems, and will they need to be trained to use them, or will there be a homogeneous system—and if so, what does the Minister envisage that looking like?
The Government say the single patient record will be more efficient, reduce the number of A&E attendances and hospital admissions, and make £20 million in annual savings to the NHS. Those are quite small margins compared with the scale of the project. Is the Minister satisfied that the savings will not be obliterated by the cost of the project running away?
The other thing is the public view of this. Polling published in January 2025 by the Tony Blair Institute found that 69% of people are willing for their anonymised data to be used to help plan NHS delivery, 71% are willing for it to be used for research into drugs and new treatments, and 75% are willing for it to be used for speeding up and making better diagnoses. There is an amendment—amendment 11—that make data available only for patient care, but patient audit and research can be quite important. Does the Minister have any comments on how audits and patient research might be used in a clinical context to improve care using anonymised or non-anonymised data?
Proposed new section 250E(3) of the National Health Service Act 2006 says:
“The regulations may provide that the processing of information in accordance with the regulations does not breach any obligation of confidence owed by the person processing the information.”
As one of my hon. Friends said earlier this afternoon, if the Government put a clause into a Bill, they normally have a reason for wanting to use it. Can the Minister expand on the circumstances in which they might want, in essence, to bypass patient confidentiality in pursuit of that provision?
In addition, the regulations may make information
“available to people involved in the provision to patients of health care or social care anywhere in the British Islands,”
which means it will not all be provided in England, and it will not necessarily all be provided within the United Kingdom. Will there be reciprocal arrangements with the self-governing territories? If not, how will the Government ensure that the data is properly protected once it has been shared?
I also want to mention cyber-security. On 30 June—just earlier this week—it was reported that the UK healthcare sector experienced a tenfold increase in attacks during January to May 2026 compared with the whole of 2025, recording 264,000 individual events compared with just 27,000 in 2025. In June 2026, Bedfordshire hospitals NHS foundation trust revealed that data relating to 33,000 hospital patients was stolen and shared online two years ago. Mid and South Essex NHS foundation trust reported the theft of 2,380 records in the same attack. The Secretary of State said earlier in June that
“the situation with the single patient record is…different from that of the federated data platform, because it is likely that we will let a series of contracts to de-risk the delivery of the single patient record.”—[Official Report, 1 June 2026; Vol. 786, c. 891.]
That suggests that the Government are aware of the problem but have not yet nailed down the detail of how to contract the delivery of the single patient record or worked out how they are going to keep data safe once they have. How can patients have confidence when their health data—their most personal data—is on the line and the Government have not yet made the key decisions for protecting it? Does the Minister have any comments on that?
What will happen to private providers? The Government are increasingly using private healthcare providers to try to improve the waiting lists, but will they have access to the single patient record? If they will, will they have to contribute to it financially or get it for free? How will the data be protected if it is not in NHS hands and not necessarily under the same regulation? What plans do the Government have to monetise the data? In December 2025, the then Under-Secretary of State for Health, Innovation and Safety, the hon. Member for Glasgow South West (Dr Ahmed), was reported in the Financial Times as having said that the UK should make money from patient data for the
“benefit of the Treasury coffers”.
Can the Minister expand on her Department’s plans to monetise patient data? Can she guarantee that personal data will not be exposed or leaked?
Can the Minister give assurances that the tendering process for contracts to set up and run the single patient record will be fair and transparent? It has been said that companies that donated to Labour before the general election were awarded contracts worth almost £138 million during this Government’s first year. It has also been reported that Peter Mandelson had links to Palantir, which secured a £240 million deal with the Ministry of Defence. It is important that people have confidence in the contracts. Does the first person to get a contract get locked in? Once the system is set up with one provider, will it be prohibitively difficult to change provider? Will the contracts become more and more expensive as time goes on because of the difficulties in redesigning a system? Who will own the intellectual property of the system that is designed? Will it be the Government or the private company? If it is the private company, how will that work going forwards?
The other question is: can we trust this Labour Government to deliver this? In 2005, the previous Labour Government launched a digitisation project called the NHS national programme for IT. In 2007, the Public Accounts Committee found that the Government had not sought to keep a detailed record of expenditure and there was no evidence that officials had carried out an examination to see whether the benefits exceeded the cost. The Father of the House, my right hon. Friend the Member for Gainsborough (Sir Edward Leigh), described the project as
“one of the biggest IT disasters of all time”.
Costs ballooned to more than £9 billion, leading a member of the PAC to say in 2013 that it was one of the
“worst and most expensive contracting fiascos”
in the history of the public sector. How will the Minister convince the House and the public that the contract is being provided fairly, that it will be useful, that it will deliver what it said it would at the prices it said it would, that the data will be held securely once it is delivered, and that provisions will be in place to record access, decide who gets access and limit access?
Who gets access to sexual health records is particularly important. At the moment, sexual health records are kept separate. If someone attends a sexual health clinic specifically for sexual health screening, those records do not appear in their general medical record, in order not to disincentivise people from attending those sorts of appointments. If everything will be in one single patient care record, will sexual health records appear within that record? That is an important issue; indeed, it was raised during the Committee’s evidence sessions, when it seemed that the Government had not yet made a decision.
Dave Robertson (Lichfield) (Lab)
As ever, it is a pleasure to see you in the Chair, Ms Lewell. I have listened very carefully to people’s speeches, and it is important to say that we are debating that clause 47 stand part of the Bill. The clause creates the single patient record and, while many Opposition Members have justifiably and understandably asked how we will do this right and what safeguards we will have, it is important that what we are debating is that the clause stand part of the Bill.
The clause creates the single patient record, and it creates the overarching ability for the NHS to use data better than it currently does. I am not a data scientist. I am a physicist by training, and I taught physics and worked in trade unions for a long time. Because of my training and my use of data, every group of people I have ever worked with invariably came up with nicknames for me, which usually boil down to “Data Dave”. There is something so valuable about being able to use aggregated values to tell us something that we do not already know.
One of the most valuable things we may get from this is that, when a clinician talks to a patient and they say or present something that does not match what is on the single patient record, it will raise a red flag that leads the clinician to realise something they would not have realised if they did not have access to notes previously taken elsewhere. I genuinely think that is one of the most valuable things that will come from this.
On a wider stage, the ability to aggregate data and properly track what is going on within the health service, and for people to be able to track what is going on with their care, with a wider view of what is going on, will be so valuable to clinicians and wider afield.
I am interested in what the hon. Gentleman is saying. Does he agree that, in many ways, the NHS dataset will be one of the most valuable datasets in the world, not only to patients themselves—in terms of the value to them and their privacy—but in the ability to analyse it and perhaps understand parts of medicine that we do not understand at the moment and so improve patient care?
Dave Robertson
I am not entirely certain that I want to agree with “one of” the most valuable datasets in the world; I think it could potentially be the most valuable dataset in the world.
We know that the NHS is the largest healthcare provider in the world. We know that the data is potentially very valuable. Creating this will allow our NHS to be at the forefront of managing how it works, in a way that no other health system will be able to, and certainly to a scale that no other health system anywhere in the world will be able to. That obviously comes with risks.
I have been listening carefully, and it is important that we tease out those risks and make sure that we stay as red hot as we can on all the issues that hon. Members have raised. I go back to the salient point of whether this clause should stand part. I fully support that this measure should be part of the Bill and that we should be moving in this direction.
I have spoken about the more global ideas and the reasons why, intellectually, I think this is a good idea, but let me take an example from my home county of Staffordshire up in the west midlands. There are reports that one hospital in Staffordshire uses 450 different electronic systems, which is absolutely bananas.
For so long, we have not had a single patient record. We have not had one unifying system. Over a cup of tea with the Minister a couple of days ago, I got very excited and started talking about primary keys because, although I am not a data scientist, I like the use of data. I do not think we need to get into a situation where there is a single primary key that is instantly recognisable to everybody and where we are necessarily using some machine learning to assess that. That could potentially come later down the line. That is not what the clause is doing, and it would need a much wider discussion than we are currently having.
If we take the example of Staffordshire and its 450 different data systems in one hospital—I do not know that number for certain, although it has been reported to me by two or three colleagues—I cannot imagine the difficulties that the IT team has in trying to get that number of systems to talk to each other. It will be nigh on impossible. All it leads to is delays. All it leads to is people having to reproduce data from one system to another manually. By creating an overarching single patient record, we will force it to happen.
Sojan Joseph
It really surprised me to hear my hon. Friend talk about his experience of 450 systems in the computer system in his local hospital. I was shocked, because as a clinician who previously worked in the NHS, I wanted a system that made patient records readily available so that we could care for patients.
My understanding is that the clause amends the National Health Service Act 2006 to enable the Secretary of State to make regulations to establish a system to make patient information readily available to patients and to those involved in providing health or social care in England. Under the current system, care and treatment across different parts of the NHS are not as co-ordinated as they could and should be. All too often, that means that patients have to repeat their medical history every time they see a different medical professional. The shadow Minister, the hon. Member for Sleaford and North Hykeham, talked about how that can sometimes be useful for getting the diagnosis right, but it can be very traumatising for someone to have to explain the same story again in such a short period of time.
Speaking in the Chamber, I previously gave the example of a mental health patient going to A&E on a Friday. They tell their story to the professionals there and they tell the same story later when a mental health professional comes to see them. When they are admitted into a mental health hospital, they have to explain the same story when going into the ward, and then again to the nurses. Having to repeat their story again and again is traumatising for most patients.
My point was that this can sometimes be beneficial. If a clinician sees a young lady who has collapsed at school, she might have fainted or had a fit. There are a lot of different potential causes, such as cardiac syncope, and lots of different potential diagnoses. A lot of the detail in making the diagnosis is in the history. The patient will probably already have been asked their story when they arrived at A&E, but it is still important for a senior clinician to ask for it again.
My caution was against presuming that we can, in all cases, prevent repeated asking of questions. There would clearly be a benefit when there are particularly sensitive pieces of information, about which we need not ask two, three or four times, but we cannot stop all cases in which a patient is asked for the same story.
Sojan Joseph
Absolutely; a single patient record will not stop professionals from asking the necessary questions of patients at any time. Each ward round, the doctors ask the patients how they are feeling. They will have that conversation; that will not stop. We are talking about repeatedly having to tell the story.
The point was highlighted when the Committee heard from Jacob Lant, the chief executive officer of National Voices, a coalition of health and social care charities. In his 15 years of patient and public engagement, the most consistent theme is patients’ frustration at constantly having to retell their story, and the fact that medical notes are not available across different healthcare settings. Not only is that frustrating for patients, but it can also be deeply distressing. Kath Abrahams, the chief executive of Tommy’s, told the Committee that
“Women report constantly having to retell their story—highly sensitive or traumatic experiences of loss—and that repetition can happen across the early pregnancy unit and maternity services.”––[Official Report, Health Public Bill Committee, 16 June 2026; c. 66, Q108.]
As medical professionals, we are taught the importance of empathy and understanding, but if the absence of a unified patient record system is aggravating traumatic experiences for patients, we need to address that. The absence of a national unified report can also compromise patient safety and lead to clinicians making decisions based on partial or incomplete information, significantly increasing the risk of error.
We heard evidence of that from the chair of Healthwatch England, who highlighted the risk posed to patients with multiple comorbidities. He said:
“Without a single patient record, we can find that a consultant or a GP has access to only one part of that multiple comorbidity…That can lead to all sorts of unforeseen errors.”
That can result in poor health outcomes, increased hospital admissions and reduced patient trust, which is why he went on to speak about
“the great advantage that we can get from a single patient record.”––[Official Report, Health Public Bill Committee, 16 June 2026; c. 49, Q79.]
Experienced mental health patients often move between A&E, GPs and mental health services and have to repeatedly go through that traumatic experience.
I have spoken in the House previously about my deep frustration that the digital records available to me in mental health services in Kent and Medway were incompatible with those used in other parts of the NHS, both locally and across the rest of England. I know that that frustration is shared, so in advance of the Committee’s consideration of clause 47 I spoke to some of my former colleagues, as well as other healthcare professionals in my constituency, to find out what systems are used to record patient information.
Sojan Joseph
My patient record is currently kept by different organisations or providers, which cannot see each other. If I speak to the GP about my blood sugar and then end up in A&E, they cannot see that record. If I go to the mental health service, they cannot see what medication I was taking. When I get discharged back to the GP, he will not get the information on my medication. That is the clinical aspect I am talking about, although I fully understand the hon. Gentleman’s concern. I hope the Minister will address some of those issues.
The responses I collected demonstrate how disparate and fragmented digital record systems are within just one local area. I do not think any of our constituents are aware that their data is kept in different places and that the services do not talk to each other. That is what the Bill is trying to address. All that information will be available for doctors, nurses and any other healthcare providers so that they can see patients’ history and medication and those patients will be more safe. Things will be more transparent. It will be easier for admission to discharge processes.
There is no detail in the Bill. As my hon. Friend the Member for Isle of Wight East said, there is nothing in the legislation requiring the computers in his local area to talk to the computers in my local area.
Sojan Joseph
I hope that would be the outcome of this legislation. I will give an example. My constituency is very close to Dover. Lots of travellers go through Ashford, my constituency. We often get patients from Scotland, Manchester or Liverpool, for whom doctors cannot start a treatment because they have to wait 24 hours to 48 hours to get the information from the hospital where the person comes from. I am not saying that the story is the same across the country, but that is what we are experiencing.
In the event that someone from Scotland comes into the hon. Gentleman’s hospital near Dover and a doctor wants to look at their healthcare record, does the hon. Gentleman envisage that the doctor will log on to their local system and see the records from Scotland, or that they will have access to the Scottish system to look at the records directly there?
Sojan Joseph
I do not know whether there will be the same system in Scotland, but my understanding is that in the north of England doctors will be able to see the same system. Again, we can hear more detail from the Minister.
A single patient report has the potential to transform patient experience and safety by ensuring continuity of care, by reducing unnecessary repetition, by enabling better informed clinical decisions and the smoother discharge of patients, and by creating a more efficient and joined up healthcare system.
Gregory Stafford
I thank all those who have spoken so far in this debate. I have never seen the hon. Member for Lichfield so animated—Data Dave is clearly alive and well.
As we have discussed, the clause creates the legal power for a single patient record in the UK. It is important to say, as others have, that the Bill does not create the system but gives the Secretary of State the power to create it later through regulation. That does not mean, however, that we should not have a debate about some of the issues that we have raised.
I should state at the start that I support better information sharing when that helps patients receive safer and better care, and I think that the single patient record could well do that. Anyone who has worked in healthcare, as I have, knows the frustration that results from the records not following patients between services. Clinicians can lose valuable time in searching for information, if they can get it at all. As others have said, patients are often asked to repeat the same details over and again—not, as my hon. Friend the Member for Isle of Wight East rightly said, because it gives a richer experience but simply because people do not have the information. Better joined up records have the potential to improve care.
We have, however, been here before. I was a lot younger—we all were—but back in 2002, the national programme for IT, under the last Labour Government, was a £10 billion unmitigated disaster, which the Public Accounts Committee described as
“one of the worst and most expensive contracting fiascos in the history of the public sector.”
I want to make sure that there are safeguards, from both a contracting and a data safety point of view, so that we do not go down that route again. As my hon. Friend the Member for Isle of Wight East clearly outlined, creating such a record is fiendishly complicated from both a technology and patient information point of view and from a data sharing and data protection point of view.
The record could contain some of the most sensitive information about people, so Parliament has the responsibility to make sure that the legal framework is right. We also know that the record will work only if the data in the single patient record is worth the electronic paper that it is electronically printed on. As I am sure the Minister knows from her time in the NHS, the information is getting better but continues to be patchy across the country. Different trusts and organisations record things in different ways. I take my hat off to those who work in clinical coding, as they do one of the most difficult jobs in a trust. Again, we need to make sure that the data is accurate. Someone mentioned AI earlier; I think AI could help with that, but we are still some way off.
I want to canter through my concerns about the breadth of the powers being given under the clause. The Bill allows the Secretary of State to make regulations establishing the system and to decide how it operates. Those regulations may require or authorise the sharing and processing of patient information, decide who can access the information and create enforcement powers and financial penalties. Some of those important questions are not answered in the Bill. Parliament is being asked to approve a broad framework before seeing some of the detail.
My second concern is that the Bill says little about patient choice. There is no clear statement about whether patients will have the right to opt in or out and no explanation of whether patients can restrict access to all or part of their records. There is no mention of whether someone could choose to limit access to particularly sensitive information, such as mental health records, sexual health information or information about substance dependence. There are major questions for public trust but those are left, I would say, entirely to future regulations. We need clarity about them now.
My third concern is the scope of the information that may be included. The definition of “patient information” is extraordinarily broad. It covers information about physical health, mental health, diagnosis, treatment and care, including social care. The definition of “patient” includes people receiving social care or having their care needs assessed. What we do not know from the Bill is exactly how that data will be presented. Will it use language that a patient can understand? Will it talk about having a heart attack, or will it use medical information that a medical professional will need to assess? Or will it include both, so that the patient knows that they have had a heart attack, for example, but the medic can see the precise detail on what sort of transient ischaemic attack it was. We need to understand what the data is recording and at what level of detail.
If it is to include both, who will translate it into the simplest form and how much will that cost?
Gregory Stafford
Precisely. These questions need to be thought about when the Government are creating this system.
As hon. Members have described in their speeches and in their amendments, the system could contain much wider information, including highly sensitive information about disability, safeguarding, care assessments, addiction, pregnancy, military service, caring responsibilities and many other personal matters. This is not simply about a hospital record; it is about bringing together health and social care information. That makes it even more important—indeed, essential—that safeguards be clear and robust.
That leads me on to my fourth issue, which is confidentiality. The Bill says that where information is processed under the regulations, doing so will not breach any duty of confidence. I think that that is a significant legal challenge and change. Confidentiality has been one of the foundations of healthcare. Of course there are already situations in which information can and should be shared, but where Parliament is creating a new legal basis for disclosure, it is reasonable to expect strong safeguards alongside it.
That brings me to my next concern. The Bill says that the Secretary of State must have regard to the need for “adequate safeguards”. That is welcome, of course, but the Bill does not say what those safeguards are. There is nothing in it about role-based access controls, audit logs or whether patients would be able to see who had looked at their records. There is nothing about minimum cyber-security standards, about how inappropriate access will be detected or about independent oversight. Those matters may appear later in regulations or in guidance, but they are not guaranteed in the Bill.
The clause says that information could be made available
“to people involved in the provision to patients of health care or social care anywhere in the British Islands”.
That implies that the English system will be used to share information with people outside England—in the Isle of Man, the Channel Islands, Scotland, Wales or Northern Ireland—but it does not imply that those areas will necessarily have the same systems to share information with us.
Gregory Stafford
That is an interesting question. I do not know the answer, but perhaps the Minister can pick that up.
The Bill also creates powers for financial penalties. It sets out a process for notices and opportunities to make representations and a right of appeal. Those procedural protections are sensible, but the Bill does not tell us who might be fined or what conduct would trigger a penalty, and it does not set out a maximum penalty level. Those decisions, again, are left to regulations.
It is also important to remember that the Bill does not replace existing data protection law, as I think the Minister outlined in her opening remarks. Organisations will still have to comply with the Data Protection Act and other UK data protection rules. However, the Bill would provide a new statutory basis for processing information through the single patient record. That makes the wording of the Bill especially important. Ultimately, public confidence will determine whether the system succeeds. People are generally willing for information to be shared when it improves their care, but they also expect transparency, security and accountability and expect to know who can see their information and why. Those expectations are entirely reasonable.
There are several questions that I believe the Committee should ask before these powers are granted. Will patients have a genuine choice about participation? Will they be able to restrict access to particularly sensitive parts of their records? Who exactly will be able to access the system? Will patients be able to see a record of who has viewed their information? What minimum standards will apply? How will misuse be identified and punished? What independent oversight will exist? Those are not technical details; they are central to public confidence.
In conclusion, the clause will create a legal framework rather than a system itself. It will give broad powers to establish the single patient record while leaving many of the most important questions to future regulations. Clearly most people support the goal of improving patient care, but because the system will involve some of the most personal information that people have, Parliament should ensure that patient rights, safeguards, transparency and accountability are clearly built into the framework from the beginning. It should ensure that questions are asked now rather than decided on later.
Clauses 49 and 50 explain our approach to the transfer of NHS England’s existing data and information functions to the Secretary of State. Slightly counterintuitively, I will start with clause 50 before turning to clause 49.
Clause 50 inserts schedule 7, which takes existing NHS England information functions and transfers them to the Secretary of State for Health and Social Care, as part of a single centre for data and digital policy in the NHS. The schedule also includes changes to existing information functions. This will support the shift from analogue to digital and allow us to make the most of opportunities from data and AI, as set out in the 10-year health plan. The changes will not weaken the fundamental safeguards in place to protect health and care data, nor fundamentally change rules relating to how confidential patient information can be used.
I will now outline some key changes made by the clause. It will ensure that information systems for the NHS are set up, where appropriate, not just for the collection and analysis of data but for processing more generally. This will make it easier to support machine learning and artificial intelligence activities, among other uses of data.
The clause extends the extent of chapter 2 of part 9 of the Health and Social Care Act 2012 to the whole of the UK, and provides for the Secretary of State to establish information systems in the interests of the health service or adult social care in England, or in connection with the provision of care across the British Isles, as NHS England currently can.
The clause enables the Secretary of State to issue guidance to health and social care bodies on the processing of information. It transfers to the Secretary of State NHS England’s powers to require and request information, and such requests will be able specify the form, manner and time within which the information requested is to be provided.
The clause also allows the Secretary of State to publish information obtained in the operation of an information system, including information about service providers. Where NHS England had a duty to publish such information, it is right that the Secretary of State should retain discretion in that regard. Obviously, there may be circumstances in which the publication of data would not be appropriate, and the clause does not give the Secretary of State complete freedom to publish personal information. The Secretary of State may publish personal information without patient consent only where it is for the protection of life or health, or for the protection of public safety or security. It is possible that there could be circumstances—for example, in relation to infectious disease—in which information is published that could lead to an individual being identified. None the less, the change simplifies the process of publication while maintaining a high bar for the publication of personal information.
The Secretary of State’s power to disclose information—for example, to health bodies—other than by publication will be slightly different from NHS England’s current power. The grounds for disclosing personal information will largely mirror the current grounds, with a few additions, including in respect of facilitating clinical trials or other research. This will help to address barriers to data access for research while preserving existing rules on confidentiality. As with his powers of publication, the Secretary of State will also be able to disclose information for the protection of life or health, or for the protection of public safety or security.
The Secretary of State will be bound by certain existing duties on NHS England, including a duty to have regard to any relevant advice from the Confidentiality Advisory Group when publishing or disclosing information in accordance with his data functions. The Secretary of State will retain the regulation-making power to establish an accreditation scheme for information service providers, which will now include a broader range of providers, including public bodies.
Clause 49 permits the Secretary of State to delegate certain functions relating to health and care information. Currently, some of those functions can be delegated by NHSE via arrangements with third parties or under regulations. The clause will insert new section 251ZF, which allows the Secretary of State, by arrangement, to delegate to persons specified in regulations functions relating to information standards.
Information standards help to reduce fragmentation in digital and data services. They include mandatory requirements for how information is recorded, shared, governed and supported by IT. Increasing interoperability and consistency in digital and data is essential to increasing value for money, reducing the burden on staff and, ultimately, improving the quality of care. The continued use of information standards is key to the 10-year health plan’s aim of improving the interoperability of digital and data services across the health and care system. This will provide the Secretary of State with the flexibility to delegate such functions to persons who have the required technical expertise, where necessary.
Clause 49 will also insert new section 277G, which enables the Secretary of State to direct public bodies to exercise a wider range of his information functions, defined as “relevant information functions”. This includes not only information standards but other information functions, such as the Secretary of State’s duty to establish and operate information systems. The measures will provide the Secretary of State with important flexibility to delegate such functions to persons who have the required technical expertise, where necessary.
In all, the changes are necessary not just to effect the transfer of data functions to the Secretary of State but to enable better data use for the benefit of the NHS now and into the future.
I have a couple of questions. In lots of ways the provisions derive from clause 1 and the abolition of NHS England. Schedule 7 refers to operating a system in the interests of the health service, which is not the same as operating it in the interests of the patients. Does the Minister have any comments on that? The Nuffield Trust has pointed out that schedule 7 would not pass over to the Secretary of State NHSE’s duty to report to Parliament. Is that because the Minister thinks that duty is duplicated elsewhere and is therefore not necessary?
Under the previous legislation, the Care Quality Commission was slightly stronger and could make a mandatory request that NHS England establish a system, and NHS England had to comply with that unless it related to an existing exception. Now if the CQC makes a request, it goes to the Secretary of State, and whether it is agreed to is then somewhat more optional. Will the Minister say why she needs to change that power?
I want to speak to amendment 6, which is tabled in my name, and amendment 7, which is consequential upon it. Amendment 6 would ensure that the CQC and NICE can
“continue to make mandatory requests to the Secretary of State to establish an information system”,
as they currently can with NHS England. At the moment, NHS England has a duty to co-operate with the CQC and NICE, and that is often enough for a collaborative approach that allows the CQC to access the data it needs.
But the duty that applies to NHS England is not being passed on to the Department of Health and Social Care. The CQC raised the issue in written evidence to the Committee, saying that the duty
“has been an important mechanism”
that has
“supported receipt of patient safety incident reports…information sharing between regional teams, and the development of central data sharing solutions.”
The CQC went on:
“Without an equivalent duty, we would be reliant on there being sufficient capacity and willingness within DHSC to share information, with no statutory backstop. This could inhibit our ability to receive the information”
needed
“to keep people who use services safe. Challenges in this area are often cultural and rely on the subjective judgment of individual data controllers as to whether particular data sets can be shared, how these should be used and what the timeliness of sharing should be, leading to protracted piecemeal conversations and delays.”
As we have harrowingly heard over the past week, there is often reluctance to share data, particularly when there is a defensive culture in certain NHS institutions. Our amendment seeks to address the gap. I hope that what I have outlined is an oversight from the Government, not a deliberate attempt to reduce transparency or reduce regulator access to key data. The wider changes in schedule 11 will omit section 288 of the Health and Social Care Act 2012. The Government are dropping this key wider duty in a schedule entitled “Minor and consequential amendments”. We do not think it is minor. It holds major implications for patient safety and transparency.
On a wider note, it seems counterintuitive that the CQC, as regulator, does not have easy access to the data collected nationally in the health service.