Health Bill (Eleventh sitting) Debate
Full Debate: Read Full DebateSojan Joseph
Main Page: Sojan Joseph (Labour - Ashford)Department Debates - View all Sojan Joseph's debates with the Department of Health and Social Care
(4 weeks, 2 days ago)
Public Bill Committees
Gregory Stafford
As we move towards a single patient record, we have to ensure that technological progress does not come at the expense of those who are least digitally connected. As others have said, I am particularly concerned about older patients and many disabled people, who often rely most on NHS services but can face the greatest barriers when healthcare systems—and all systems—become increasingly digital. For some elderly patients in my Farnham and Bordon constituency, navigating online platforms is challenging, and others may not have regular access to the internet at all. Unfortunately, my constituency has one of the worst full-fibre broadband roll-outs in the country, and it has extraordinarily poor mobile phone reception in the central rural parts of the constituency, despite my best efforts with BT Openreach and others.
Disabled people may also face accessibility barriers that these systems do not always anticipate in their design. Modernisation should never mean creating a two-tier NHS—one for those who are digitally confident and another for those who are not. The people at risk of being left behind are often those with the most complex healthcare needs and the greatest reliance on the continuity of care. A proper assessment of digital exclusion is therefore not just a bureaucratic exercise, as some may describe it; it is an essential safeguard. We need to understand how the single patient record will affect elderly patients, disabled people, carers, those with learning disabilities and those who may struggle to engage with digital services.
Sojan Joseph (Ashford) (Lab)
My understanding is that the single patient record is just a single place where all of a patient’s medical records will be kept. It will not necessarily change the ways in which they access healthcare services, such as A&E, the GP or a dentist. Those ways of accessing healthcare will stay the same, whether we have a single patient record or not.
Gregory Stafford
For me, the key thing is that we must have equity of access to the single patient record. If somebody wishes to see their own medical record, they should be able to do so, whether they are digitally savvy or not. As far as I can tell, that is the intention behind the Liberal Democrat amendment.
However, the hon. Gentleman raises an interesting point. We are seeing this already, but the more we go down the digital route—because it is more efficient and straightforward, and takes out the unnecessary bureaucracy of having a human interaction to book an appointment or whatever—the more likely it is that this will become the portal for all interactions. I am not saying that that is the Government’s intention, but he raises a point, perhaps inadvertently, that we need to think about.
To conclude on amendment 70, before we proceed any further, the Government should be able to demonstrate that no patient will receive a worse service, face greater barriers to care or lose access to information simply because they are older, disabled or less digitally connected than others—that goes to the heart of fairness and equity of access in our NHS. I am absolutely certain that the Minister does not wish that to happen, but it would be interesting to hear how she will ensure that it does not happen.
Amendment 49, in the name of my hon. Friend the Member for Sleaford and North Hykeham, would prevent the Secretary of State from making regulations to establish the single patient record unless a public awareness plan had first been published and laid before Parliament, and a minimum three-month public information campaign had been conducted before the system went live. That seems eminently sensible, and I hope it is something that would be not just welcomed by Ministers, but on their agenda already.
Patients clearly have a right to know what information is being held, who will have access to it, how it will be used, what safeguards are in place and what rights they have in relation to their own data before the system goes live. A three-month campaign to give them that opportunity would be appropriate, because the things that I have outlined are not technical details that need to be buried in some Government website or hidden in the small print of a privacy notice; they are fundamental questions that deserve proper public engagement.
I am especially supportive of amendment 49 because of the impact on older people, disabled people and those who are less digitally engaged. I do not think that most of my constituents spend their time reading NHS policy documents online—my notes say “most”, but I think none of them do, unless they are involved in the health world themselves—and they should not wake up one morning to discover that a major change to the management of their health information has already been implemented without their knowledge.
A public information campaign is not a bureaucratic hurdle; it is a democratic necessity. If Ministers are confident that the single patient record will improve care, strengthen efficiency and protect privacy, they should be eager to make that case to the public and should therefore welcome the scrutiny, transparency and informed debate that a three-month public information would bring.
I beg to move amendment 48, in clause 47, page 36, line 1, at end insert—
“(4A) Regulations may not be laid under this section unless the Secretary of State has published a plan setting out the measures to be taken to prevent clinicians and other persons involved in the provision of health care or social care from accessing patient information made available through the system otherwise than for the purposes of the care of the patient concerned (an ‘inappropriate access prevention plan’).
(4B) The inappropriate access prevention plan must include—
(a) a description of the technical controls to be applied to restrict access to patient information to those with a legitimate care relationship with the patient;
(b) the system of audit logging to be applied to record each instance of access to patient information, including the identity of the person accessing the information and the time and circumstances of access;
(c) the sanctions applicable to persons who access patient information without lawful authority or without a legitimate care relationship with the patient;
(d) the arrangements for detecting and investigating suspected cases of inappropriate access; and
(e) the role of the Care Quality Commission, the Information Commissioner and any other regulatory body in enforcing compliance with access controls.
(4C) The Secretary of State must lay the inappropriate access prevention plan before both Houses of Parliament.”
This amendment prevents the Secretary of State from making regulations to establish the single patient record unless a plan to prevent inappropriate access by clinicians and other care workers has first been published and laid before Parliament.
Amendment 48 would prevent the Secretary of State from
“making regulations to establish the single patient record unless a plan to prevent inappropriate access by clinicians and other care workers has first been published and laid before Parliament.”
This is about trust. It is about people being able to trust that the records that will now be more widely available will remain confidential and be looked at only by those who need to look at them.
We have seen that people can be uniquely nosey when it comes to accessing medical records. For example, 48 staff members at the University Hospitals of Liverpool Group were found to have looked at the records of those involved in the Southport attack without any medical basis to do so. Almost a dozen staff members were sacked from the Nottingham University Hospitals trust because they had looked at the records of the victims in Nottingham. It is important that we address this, because it is happening already and needs to be tackled.
Paul Arnold, the chief executive of the Information Commissioner’s Office, said that trust is being “jeopardised”. The amendment seeks to ensure that proper thought goes into making sure that people cannot access records they should not be able to look at—for example, those of the Prime Minister or members of the Royal family—before the single patient record is live and can be used. We have Public Department 1 for HMRC; is there an intention to have something similar to close off records to reduce their accessibility where the public may be particularly nosey, either because of the person’s job or because of an event such as a terrorist attack, where we have seen people look at records when they should not have? There were reports that staff at The London Clinic, a private clinic, had been trying to sell records of the Princess of Wales online, so there are examples where this has happened before.
In addition, it is important that people know what the penalties are for deliberately misusing these records. My final question for the Minister is this. If a record has been viewed and there is a data log of it having been viewed, how long will that data log last for? Will it last for six months or a year, or will I be able to look back in 10 years’ time and see who accessed my records today? It is a case of understanding the Minister’s intentions and pushing the Government to ensure that these records are truly private to those who need to see them, not accessible to anyone who just happens to be curious.
Sojan Joseph
I declare that I am a registered nurse. I have worked in the NHS for many years, and I have used patient records throughout my career. The Nursing and Midwifery Council code requires nurses, midwives and nursing associates to respect patient confidentiality, share information appropriately and ensure that patients are informed about how their information is used. That is the existing system, and every nurse, midwife and nursing associate has to follow the code of practice. A similar code is there for the General Medical Council for doctors, and all other registered professionals follow those codes.
On top of that, information governance in the NHS ensures that patient data is handled legally, securely and ethically, providing a framework for data protection and confidentiality. We have numerous different digital systems in the health system currently. Before anyone gets access to those digital systems and patient records, they all have to go through information governance and data protection training. They are then given access to patient records. That is the existing system.
The shadow Minister, the hon. Member for Sleaford and North Hykeham, has just mentioned the Nottingham incident, which is a good example. It is a clear example of where those who accessed the records were able to be identified. There is a clear audit trail, and I have my own experience of taking people through disciplinary proceedings for accessing patients’ notes when it was not relevant to those staff. The existing patient data systems do have provisions to safeguard and monitor who is accessing patient records.
I understand what the hon. Gentleman is saying, which is that there are processes in place already and that the fact that someone got sacked for looking at the records is a sign that the systems work to an extent. However, does the fact that they could look at them at all suggest that the systems are not working well enough? Because it is a computerised system, there are methods for identifying whether someone is likely to need to look at that record. By knowing the profession of the person looking at it, and the department they are in, the computer can help to limit the number of people who look at those records when they should not.
Sojan Joseph
I agree that we are never going to have 100% proof. There will always be people accessing records. What I am talking about is the existing system, which does have provisions. What we need to strengthen is the training and the audit trail. All staff who do the training are aware that they are not supposed to check patients’ records unless it is relevant to them. Those who access records inappropriately should be identified and action should be taken.
Just because we are moving to a single patient record system, it does not mean that everybody is going to access everything they want. People working in the healthcare system are given access based on their role. Not everybody is able to access everything. Systems are in place, and we need to strengthen those systems and the training. We should not be scaremongering by saying that, because we are moving to a single patient record, everybody will be able to see their records.
The hon. Member for Ashford made his point very clearly about what happens when something goes wrong and someone behaves inappropriately—the shadow Minister, my hon. Friend the Member for Sleaford and North Hykeham, has highlighted some very concerning recent incidents—and was right to highlight the ability to follow an audit trail and take action. He is also right to highlight the importance of training.
However, taking action once inappropriate access is known, and then following the audit trail, deals essentially with the consequences rather than preventing it from happening in the first place. That is why amendment 48, and particularly proposed new section 250E(4B)(a) of the National Health Service Act 2006, is important. It describes the technical controls. That goes beyond the audit process and what happens after something has gone wrong. It is about what can be done to build safeguards into the system to make it much harder for anyone to circumvent their obligations, and to build those technical safeguards into the overall design of the single patient record. That is a reasonable ask, because such incidents, while hopefully rare, as the hon. Member for Ashford alluded to, do happen and understandably cause concern.
The challenge is that there is potentially a lot more information in one place, rather than being held in different pots, trusts or GP surgeries. For those inclined to break their legal obligations and behave outside the rules, the potential opportunity to access a wider range of information is more significant. The design of the record needs to have those technical safeguards strengthened and built in.
Joe Robertson
That was a long intervention, but it was helpful. I disagree with the hon. Gentleman, because the legislation is not seeking to require technology companies or the providers of electronic record-keeping systems to be able to talk to each other. It is trying to create the concept of a single patient record, which is good, but it does not mandate a way to achieve that. I do not particularly want to name companies, but a big provider that is already in the health space and that provides electronic record-keeping systems might say, “We can already provide a single patient record. It is for other providers to adapt and feed into our record-keeping system,” and there is nothing in the Bill that says one technology company must adapt to another.
The technological issue is completely unaddressed. I am not even saying that it should be addressed in the Bill, because there are all sorts of issues around competition law and state support for particular companies. It is not a criticism per se of the way in which the Bill drafted, but this is an opportune moment to make the point that absolutely none of the clause will be delivered until a major issue that the Government have not yet addressed is dealt with. That issue is the interoperability of different electronic record-keeping systems provided by the private sector. They are all in competition with each other to get a bigger share of the market; unless and until that is addressed, the Government are not going to realise any of this. I do not want that to be the case. I want the single patient record to be realised, broadly speaking.
Sojan Joseph
I wish to speak in support of clause 47. I spoke on Second Reading about my strong support for the introduction of a single patient record. I am not a tech expert like my hon. Friend the Member for Lichfield—
Sojan Joseph
It really surprised me to hear my hon. Friend talk about his experience of 450 systems in the computer system in his local hospital. I was shocked, because as a clinician who previously worked in the NHS, I wanted a system that made patient records readily available so that we could care for patients.
My understanding is that the clause amends the National Health Service Act 2006 to enable the Secretary of State to make regulations to establish a system to make patient information readily available to patients and to those involved in providing health or social care in England. Under the current system, care and treatment across different parts of the NHS are not as co-ordinated as they could and should be. All too often, that means that patients have to repeat their medical history every time they see a different medical professional. The shadow Minister, the hon. Member for Sleaford and North Hykeham, talked about how that can sometimes be useful for getting the diagnosis right, but it can be very traumatising for someone to have to explain the same story again in such a short period of time.
Speaking in the Chamber, I previously gave the example of a mental health patient going to A&E on a Friday. They tell their story to the professionals there and they tell the same story later when a mental health professional comes to see them. When they are admitted into a mental health hospital, they have to explain the same story when going into the ward, and then again to the nurses. Having to repeat their story again and again is traumatising for most patients.
My point was that this can sometimes be beneficial. If a clinician sees a young lady who has collapsed at school, she might have fainted or had a fit. There are a lot of different potential causes, such as cardiac syncope, and lots of different potential diagnoses. A lot of the detail in making the diagnosis is in the history. The patient will probably already have been asked their story when they arrived at A&E, but it is still important for a senior clinician to ask for it again.
My caution was against presuming that we can, in all cases, prevent repeated asking of questions. There would clearly be a benefit when there are particularly sensitive pieces of information, about which we need not ask two, three or four times, but we cannot stop all cases in which a patient is asked for the same story.
Sojan Joseph
Absolutely; a single patient record will not stop professionals from asking the necessary questions of patients at any time. Each ward round, the doctors ask the patients how they are feeling. They will have that conversation; that will not stop. We are talking about repeatedly having to tell the story.
The point was highlighted when the Committee heard from Jacob Lant, the chief executive officer of National Voices, a coalition of health and social care charities. In his 15 years of patient and public engagement, the most consistent theme is patients’ frustration at constantly having to retell their story, and the fact that medical notes are not available across different healthcare settings. Not only is that frustrating for patients, but it can also be deeply distressing. Kath Abrahams, the chief executive of Tommy’s, told the Committee that
“Women report constantly having to retell their story—highly sensitive or traumatic experiences of loss—and that repetition can happen across the early pregnancy unit and maternity services.”––[Official Report, Health Public Bill Committee, 16 June 2026; c. 66, Q108.]
As medical professionals, we are taught the importance of empathy and understanding, but if the absence of a unified patient record system is aggravating traumatic experiences for patients, we need to address that. The absence of a national unified report can also compromise patient safety and lead to clinicians making decisions based on partial or incomplete information, significantly increasing the risk of error.
We heard evidence of that from the chair of Healthwatch England, who highlighted the risk posed to patients with multiple comorbidities. He said:
“Without a single patient record, we can find that a consultant or a GP has access to only one part of that multiple comorbidity…That can lead to all sorts of unforeseen errors.”
That can result in poor health outcomes, increased hospital admissions and reduced patient trust, which is why he went on to speak about
“the great advantage that we can get from a single patient record.”––[Official Report, Health Public Bill Committee, 16 June 2026; c. 49, Q79.]
Experienced mental health patients often move between A&E, GPs and mental health services and have to repeatedly go through that traumatic experience.
I have spoken in the House previously about my deep frustration that the digital records available to me in mental health services in Kent and Medway were incompatible with those used in other parts of the NHS, both locally and across the rest of England. I know that that frustration is shared, so in advance of the Committee’s consideration of clause 47 I spoke to some of my former colleagues, as well as other healthcare professionals in my constituency, to find out what systems are used to record patient information.
Joe Robertson
The hon. Gentleman is making the point that I have been trying to. He referred to a number of companies that each provide an electronic record-keeping system. The Bill does not mandate those companies to speak to each other and create a single patient record; there is no requirement on those private companies to do anything. As they are in competition with each other, their answer could be, “We can provide the single patient record—we are already doing it—if you just use more of our system and pay us more money.”
I am not suggesting that this is the hon. Gentleman’s responsibility, but does he have anything to say about the practicalities of a single patient record as a theory and the interoperability of electronic record keeping—a practical thing not dealt with in the Bill?
Sojan Joseph
My patient record is currently kept by different organisations or providers, which cannot see each other. If I speak to the GP about my blood sugar and then end up in A&E, they cannot see that record. If I go to the mental health service, they cannot see what medication I was taking. When I get discharged back to the GP, he will not get the information on my medication. That is the clinical aspect I am talking about, although I fully understand the hon. Gentleman’s concern. I hope the Minister will address some of those issues.
The responses I collected demonstrate how disparate and fragmented digital record systems are within just one local area. I do not think any of our constituents are aware that their data is kept in different places and that the services do not talk to each other. That is what the Bill is trying to address. All that information will be available for doctors, nurses and any other healthcare providers so that they can see patients’ history and medication and those patients will be more safe. Things will be more transparent. It will be easier for admission to discharge processes.
There is no detail in the Bill. As my hon. Friend the Member for Isle of Wight East said, there is nothing in the legislation requiring the computers in his local area to talk to the computers in my local area.
Sojan Joseph
I hope that would be the outcome of this legislation. I will give an example. My constituency is very close to Dover. Lots of travellers go through Ashford, my constituency. We often get patients from Scotland, Manchester or Liverpool, for whom doctors cannot start a treatment because they have to wait 24 hours to 48 hours to get the information from the hospital where the person comes from. I am not saying that the story is the same across the country, but that is what we are experiencing.
In the event that someone from Scotland comes into the hon. Gentleman’s hospital near Dover and a doctor wants to look at their healthcare record, does the hon. Gentleman envisage that the doctor will log on to their local system and see the records from Scotland, or that they will have access to the Scottish system to look at the records directly there?
Sojan Joseph
I do not know whether there will be the same system in Scotland, but my understanding is that in the north of England doctors will be able to see the same system. Again, we can hear more detail from the Minister.
A single patient report has the potential to transform patient experience and safety by ensuring continuity of care, by reducing unnecessary repetition, by enabling better informed clinical decisions and the smoother discharge of patients, and by creating a more efficient and joined up healthcare system.
Gregory Stafford
I thank all those who have spoken so far in this debate. I have never seen the hon. Member for Lichfield so animated—Data Dave is clearly alive and well.
As we have discussed, the clause creates the legal power for a single patient record in the UK. It is important to say, as others have, that the Bill does not create the system but gives the Secretary of State the power to create it later through regulation. That does not mean, however, that we should not have a debate about some of the issues that we have raised.
I should state at the start that I support better information sharing when that helps patients receive safer and better care, and I think that the single patient record could well do that. Anyone who has worked in healthcare, as I have, knows the frustration that results from the records not following patients between services. Clinicians can lose valuable time in searching for information, if they can get it at all. As others have said, patients are often asked to repeat the same details over and again—not, as my hon. Friend the Member for Isle of Wight East rightly said, because it gives a richer experience but simply because people do not have the information. Better joined up records have the potential to improve care.
We have, however, been here before. I was a lot younger—we all were—but back in 2002, the national programme for IT, under the last Labour Government, was a £10 billion unmitigated disaster, which the Public Accounts Committee described as
“one of the worst and most expensive contracting fiascos in the history of the public sector.”
I want to make sure that there are safeguards, from both a contracting and a data safety point of view, so that we do not go down that route again. As my hon. Friend the Member for Isle of Wight East clearly outlined, creating such a record is fiendishly complicated from both a technology and patient information point of view and from a data sharing and data protection point of view.
The record could contain some of the most sensitive information about people, so Parliament has the responsibility to make sure that the legal framework is right. We also know that the record will work only if the data in the single patient record is worth the electronic paper that it is electronically printed on. As I am sure the Minister knows from her time in the NHS, the information is getting better but continues to be patchy across the country. Different trusts and organisations record things in different ways. I take my hat off to those who work in clinical coding, as they do one of the most difficult jobs in a trust. Again, we need to make sure that the data is accurate. Someone mentioned AI earlier; I think AI could help with that, but we are still some way off.
I want to canter through my concerns about the breadth of the powers being given under the clause. The Bill allows the Secretary of State to make regulations establishing the system and to decide how it operates. Those regulations may require or authorise the sharing and processing of patient information, decide who can access the information and create enforcement powers and financial penalties. Some of those important questions are not answered in the Bill. Parliament is being asked to approve a broad framework before seeing some of the detail.
My second concern is that the Bill says little about patient choice. There is no clear statement about whether patients will have the right to opt in or out and no explanation of whether patients can restrict access to all or part of their records. There is no mention of whether someone could choose to limit access to particularly sensitive information, such as mental health records, sexual health information or information about substance dependence. There are major questions for public trust but those are left, I would say, entirely to future regulations. We need clarity about them now.
My third concern is the scope of the information that may be included. The definition of “patient information” is extraordinarily broad. It covers information about physical health, mental health, diagnosis, treatment and care, including social care. The definition of “patient” includes people receiving social care or having their care needs assessed. What we do not know from the Bill is exactly how that data will be presented. Will it use language that a patient can understand? Will it talk about having a heart attack, or will it use medical information that a medical professional will need to assess? Or will it include both, so that the patient knows that they have had a heart attack, for example, but the medic can see the precise detail on what sort of transient ischaemic attack it was. We need to understand what the data is recording and at what level of detail.