Industry Insights

The Single Patient Record: National Ambition, Local Variation and System Risk

The Single Patient Record was announced as a costed government commitment on 1 June 2026. Three days earlier, the body that investigates NHS safety described the data infrastructure it depends on as inconsistent, unstandardised and inadequately assured. There is a stark distance between those two documents.

AUTHOR

Shoshana Bloom

PUBLISHED

June 8, 2026

ABOUT THE AUTHOR

Shoshana Bloom

Shoshana Bloom is Founder of Equiti Health and specialises in digital transformation, healthcare innovation, service redesign, and digital health equity.

View full biography →

PUBLISHED

June 8, 2026

Key Takeaways

  • The NHS's ambition for a single patient record faces significant variation in local implementation approaches, creating fragmentation risks at the system level.
  • Current digital health infrastructure struggles with interoperability between trusts, GP systems, and community care providers, undermining the vision of seamless care coordination.
  • Patient record consolidation raises critical questions about data governance, consent models, and who controls access to sensitive health information.
  • Successful single record implementation requires more than technical integration—it demands workflow redesign, clinician engagement, and patient trust-building.

On 1 June 2026, the Single Patient Record was announced as a costed government commitment.

The NHS Modernisation Bill reached its second reading, and this included the Department of Health and Social Care's numbers associated with its delivery; up to 20,000 fewer A&E visits a year, 6,000 fewer hospital admissions, more than £20 million saved annually through fewer medication errors, adverse drug reactions and duplicate prescribing, and around 500,000 clinician hours returned to care.

Three days earlier, the body that investigates NHS safety had described the NHS data infrastructure that those numbers depend on as inconsistent, unstandardised and inadequately assured.

There is a stark distance between those two documents and a lot of delivery risk.

What has changed

The Bill makes data-sharing mandatory for every NHS provider, hospital and GP practice alike, so that a patient's information can be joined up nationally for the first time. And it gives the Single Patient Record a public business case framed around safety and savings rather than technology.

On the same day, NHS Online was formally established as the Online NHS Trust, a digital-only provider projected to deliver up to 8.5 million appointments and assessments in its first three years.

This is a coherent direction: a shared record, an App-based front door, and a digital provider, all justified by an operational backdrop of falling but still substantial waiting lists. However the question now is whether the infrastructure beneath the business case can carry the weight the business case places on it.

Where the savings actually come from

Read the benefits case closely and most of the headline saving is generated at a single layer: medicines data. The £20 million figure is attributed specifically to reductions in medication errors, adverse drug reactions and duplicate prescribing, achieved by giving clinicians a complete and accurate view of a patient's medicines, allergies and prescribing history. This makes sense as medicines related savings deliver cashable benefits to the NHS.

Whether this is achievable depends on the underlying medicine-related systems that produce it. In hospitals, those systems are electronic prescribing and medicines administration platforms, known as ePMA, which clinicians use to prescribe and record every dose given during an inpatient stay.

This is the layer the Health Services Safety Investigations Body examined in the report it published on 28 May, the fourth report in its thematic review of medication-related harm. Its findings describe the precise mechanism by which the record is supposed to save money and prevent harm.

The assurance gap

HSSIB found that there are no core national patient safety standards governing how ePMA systems should be designed or procured. The result is what the report calls "unwarranted variation": different hospitals run systems that function very differently, which raises the cognitive burden on clinicians who move between organisations or work as locums, and introduces its own risks during prescribing and administration.

Legally mandated NHS standards for digital clinical safety and interoperability do exist, and they are applied to this software. But HSSIB found unwarranted variation in how trusts comply with them. With no national oversight or assurance in place, they are implemented inconsistently, and there is currently confusion between the Care Quality Commission and the Medicines and Healthcare products Regulatory Agency over who is responsible for assuring any of it. Safety learning about these systems is not reliably identified or shared across the system.

In the words of the report's lead investigator, Clare Crowley, "in the absence of national co-ordination, trusts are being left to assure themselves that the software they have chosen is safe."

The report concluded that the current framework does not adequately support safe adoption of digital technology at scale. Its recommendation is for national assurance mechanisms for digital clinical safety and interoperability, and active support for trusts to build the safety capability they currently lack.

None of this is new. A study published in late 2025 used freedom of information returns from NHS organisations in England, covering 14,747 deployed digital health technologies, to test compliance against mandatory clinical risk management standards: DCB0129 for manufacturers and DCB0160 for the organisations that deploy systems. It found that only 17.3% were fully assured against both, and 70.1% had no documented assurance at all.

Why it matters at three levels

At the level of the individual patient, the Single Patient Record will give clinicians earlier access from 2027 in two of the highest-risk areas: maternity and frailty care. These are exactly the cohorts where incomplete or inconsistent medicines data does the most damage, and exactly where the variation HSSIB describes is least tolerable.

At the level of the service, a national record multiplies the consequences of local variation. A medicines record assembled from systems that encode data differently, comply unevenly with interoperability standards, and are not adequately assured does not become safer by being shared more widely. It becomes a scaled opportunity for the same errors. The benefits case assumes interoperability as a property of the record; HSSIB describes it as an aspiration unevenly met by the systems feeding it. The same applies to the 500,000 clinician hours the government expects to save: that gain is real only if the joined-up data is usable at the point of care rather than another inconsistent feed to reconcile.

At the level of the system, the sequencing matters. Legislation can compel providers to share data. It cannot, by itself, make that data accurate, standardised or safe. The savings the government has announced are delivered, if at all, by the data-quality and assurance work that has to happen underneath it. Presenting the savings as a consequence of the legislation, rather than as a condition to be met, risks the most expensive error in digital transformation: mistaking the mandate for the outcome.

The equity dimension

There is a second assumption inside the benefits case, and it is about access. From 2028, patients are expected to view their record through the NHS App. The people who stand to gain most from a joined-up record — older patients and those living with frailty and multiple long-term conditions — are disproportionately those least likely to be confident online or able to reach an App-based service unaided. NHS England's own discovery work acknowledges users with accessibility needs and low digital confidence, and finds that public support for the record is conditional on safeguards such as role-based access and audit trails.

Data completeness is itself unequally distributed. The patients whose care is most fragmented — who move between services and fall through the gaps — are the patients whose records will be least complete when the record is built.

A Single Patient Record assembled from uneven data and access can widen the very gaps it is designed to close, unless inclusion is engineered into it from the start.

The governance questions that remain open

The question of who controls the record is unresolved: the British Medical Association has argued that GPs must retain control of GP data, while the intended data controller is the merged Department of Health and Social Care. Consent architecture, audit and the practical meaning of patient "choice over how their data is used" are still to be specified. In a model built on mandatory data-sharing, the legitimacy of the record depends on the clarity of its governance.

Conclusion

The Single Patient Record is absolutely the right policy. But we need to be careful about how its benefits case is read. The savings announced are not outcomes that will be delivered through legislation. They require accurate and standardised medicines data feeding the record into systems that comply with the safety and interoperability standards that already exist, and for that the record to reach the patients who need it most. The NHS's own safety investigator made it clear that those conditions are not yet in place consistently. Legislation can mandate the sharing. It cannot mandate the safety, the interoperability or the inclusion.


Shoshana Bloom is Founder and Principal Consultant at Equiti Health Ltd, specialising in digital health transformation and AI governance.

More from this category