The NHS Single Patient Record: Ambitious reform or another digital transformation challenge?
Following the announcement of the NHS Modernisation Bill in May 2026, and as part of the Government’s 10-Year Health Plan for England, the NHS has embarked on one of its most ambitious digital transformation projects to date: the creation of a Single Patient Record (SPR).
While the potential benefits are significant, the proposal has already generated debate around data governance, patient trust, impact on existing medical practitioners, technology providers and, when facing government deadlines for roll out in 2028, and whether a programme of this scale can realistically be delivered.
What is the purpose of the proposal?
The SPR is being driven by NHS England and the Department of Health and Social Care (DHSC) as part of the Government’s wider plans to modernise the NHS. The SPR is intended to create a single, secure and authoritative source of patient information that can be accessed across health and social care settings, providing what NHS England has described as a “single version of the truth” for patient data.
Beyond improving continuity of care and patient safety, the SPR seeks to address a longstanding challenge within the NHS: fragmented patient information. Clinicians are frequently required to make decisions based on incomplete records held across multiple systems and organisations. By providing a more comprehensive view of an individual’s medical history, the SPR has the potential to improve clinical decision-making, reduce duplication of effort and enable more coordinated care.
Who is responsible for protecting the data?
Whilst the benefits of improved information sharing are clear, the SPR raises complex legal questions around responsibility and oversight.
Unsurprisingly, a headline concern is data governance and who is responsible for that. NHS England has indicated that patient information will remain within the organisation that originally created it, such as a GP practice or hospital, with responsibility for maintaining and securing that data remaining at source. On its face, this provides a clear line of accountability.
The practical challenge, however, lies in what happens once information is routinely accessed across organisational boundaries. As the SPR develops and more providers rely on centralised patient information, questions arise as to who is responsible for monitoring access, ensuring compliance with data protection legislation and responding where something goes wrong. Healthcare organisations may find themselves navigating increasingly complex governance obligations that extend well beyond traditional record-keeping responsibilities, particularly where misuse or unlawful disclosure could give rise to criminal, professional or financial consequences.
Ultimately, the success of the SPR will depend as much on the strength of its governance framework as on the technology itself.
Data access and patient confidentiality
Looking beyond the challenge of data protection responsibility and into the preservation of patient confidentiality.
Since the NHS’s inception in 1948, GPs have acted as custodians of patients’ confidential records. The concerns raised by the British Medical Association highlight an important governance question: if oversight of patient information by GPs is lost, who ultimately assumes responsibility for safeguarding confidentiality?
This issue goes directly to public trust. Even where information sharing is lawful and intended to improve patient care, patients must have confidence that their data will not be accessed or used in ways they would not reasonably expect. Whilst NHS England has emphasised that the SPR will be “secure by design”, the aggregation of large volumes of highly sensitive health data inevitably increases the potential impact of cyber incidents, security failures or inappropriate access.
The challenge is therefore not simply protecting information but maintaining public confidence that patient data remains both secure and respected. The detailed structure of any patient objection/opt-out mechanism also remains unclear.
Connecting records is easy. Building confidence is hard.
Beyond confidentiality concerns, the SPR also raises important questions of accountability.
A system designed to operate as a single source of truth is only as reliable as the information it contains. Whilst the SPR may reduce fragmentation, it will also bring together data from numerous organisations, creating uncertainty as to where responsibility lies when information is inaccurate.
If an error originates from a GP and is detrimentally relied upon by a paramedic, determining liability could be a complex issue. Does responsibility remain with the organisation that entered the information, or can accountability extend to those who subsequently access, rely upon or update it?
These issues go to the heart of the SPR’s credibility. Without clear lines of accountability for the accuracy of shared information, the ambition of creating a trusted and authoritative patient record may prove difficult to achieve.
Looking towards 2028
There is little doubt that the vision behind the SPR is attractive and could deliver meaningful benefits for both patients and healthcare professionals. However, the principal challenges are unlikely to be only technological. Rather, they lie in implementation, governance and accountability.
The SPR’s success will depend on whether policymakers can establish a framework that provides clarity around responsibility, protects patient confidentiality and maintains public trust. These are areas in which previous large-scale NHS digital initiatives have often encountered difficulty.
There is therefore still a significant amount of work to be done before the SPR can be implemented successfully, particularly while it remains in the “test and learn” phase. Much will depend on the lessons identified through that discovery process, and the extent to which those lessons inform the programme’s development. The key will be to avoid rushing implementation and to ensure that the legal, operational and technological risks associated with the SPR are properly addressed.