In the era of digital healthcare, enabling patients to have online access to GP records brings enormous benefits for engagement and patient care. Online platforms such as the NHS app or the Patient Access app allow patients to book and manage appointments, order repeat prescriptions, and access their medical records.

At the same time, the need for robust cyber security for patient online access in general practice has never been greater. This article explores the key elements that GP practices must consider — and act upon to secure access, protect patient data, safeguard information security, and maintain trust.

 

Cyber security for patient online access

When a practice enables patients to view their records online (for example via the NHS App), it opens new access to data that must be carefully managed. The national guidance from NHS England highlights that protecting patient data, preventing unauthorised access, and ensuring operational resilience are central to the cyber and data security agenda.

Key factors include:

  • Strong authentication of users (both patients and staff)
  • Role-based access control (ensuring staff only see what they need)
  • Endpoint and network security (as remote access and mobile devices increase)
  • Monitoring and incident response (so that any breach or misuse is rapidly detected)
  • Staff training and awareness (phishing remains a top risk)

NHS App, GP records security, and readiness

Making record access available via the NHS App and GP systems brings specific controls. Firstly, the guidance “GP health records in the App” published by NHS Digital is a critical resource.

It includes information and links to topics such as:

  • Policies & processes
  • Staff training: all staff (including locums)
  • Systems & configuration
  • Patient communication
  • Safeguarding & young people
  • Data quality and record readiness

Online access GP record security checklist

Using the readiness guidance above, here is a tailored security-checklist for GP practices enabling patient online access:

1. Identity registration and verification – ensure patient identities are properly verified before enabling access; consider proofing and matching.

2. Access controls – configure what parts of the record are visible, apply redaction where needed (e.g., sensitive third-party notes).

3. Audit logs – ensure registers/logs record when and by whom patient record access is given, and when patients view their records.

4. Role-based access for staff – ensure that staff logging into the GP system have only the minimum required access (see next section below for smartcards & RBAC).

5. Secure systems and endpoints – ensure workstations, laptops, tablets used by staff are patched, encrypted, protected by endpoint security and managed.

6. Remote access and MFA – ensure staff remote access (and ideally patient portals) are protected by multi-factor authentication (MFA).

7. Incident response and training – have a policy for handling cyber incident or data breach; provide staff training on phishing and password hygiene.

8. Robust Cyber Cover – implement the appropriate level of Cyber Insurance which includes a 24/7 incident response helpline

9. Patient communication and opt-out/safeguarding handling – communicate clearly with patients about how their online access works and identify patients for whom full access may not be appropriate.

10. Data quality review – ensure notes and records are accurate, legible, and written with the understanding that patients may view them.

11. Toolkit compliance – ensure the practice’s submission to the NHS DSP Toolkit covers patient online services and associated security controls.

CIS2 smartcards & RBAC for GP systems

For staff accessing GP systems, national guidance from NHS England states that smartcards (and broader identity/authentication solutions) must be used alongside role-based access control (RBAC) to protect patient records and audit access.

The move to the CIS2 Authentication platform (part of the NHS Digital “Care Identity Service”) offers modern authentication options including smartcards, security keys, biometrics, and virtual smartcards.

 

NHSmail MFA policy for staff

Email systems remain a critical access point and one of the highest risks for phishing, credential reuse and compromise. The national MFA policy for health and care, published by NHS England, requires that organisations enforce multi-factor authentication (MFA) on all remote access and on all privileged user access.

For the NHSmail platform this is applied via an MFA rollout: from 5 October 2023 all new accounts were enabled automatically.


 Key take-aways for GP practices:

  • Ensure that any staff (clinical, administrative) using NHSmail have MFA enabled – ideally via authenticator app, push notification, hardware token.
  • Where exceptions are made (for example a user cannot use MFA due to accessibility reasons), document and risk-assess the exception; ensure compensating controls.
  • Regularly review staff accounts, privileged accounts, shared mailboxes and ensure reviewing of conditional access policies.
  • Link the practice’s MFA status and compliance into your DSP Toolkit submission (see next section).

 

 

DSP Toolkit for patient online services (dsptoolkit.nhs.uk)

The Data Security and Protection Toolkit (DSP Toolkit) is the UK health-sector’s core self-assessment tool for data security and information governance. All organisations with access to NHS patient data must use it.

For GP practices enabling patient online access, this means:

  • Selecting relevant standards and evidence under the toolkit’s domains (identity check, access control, incident management, governance, data quality)
  • Ensuring that the security measures applied (smartcards/RBAC, MFA, audit logs, training, redaction processes) are documented and mapped to the toolkit requirements
  • Demonstrating readiness for patient online access via the checklist, and evidencing that the practice has policies/processes and training in place

 

Cyber Insurance

With the rapid expansion of patient online access and digital GP systems, the risk of cyber incidents in primary care has never been greater. Data breaches, ransomware, or email compromise can disrupt services, damage patient trust, and lead to significant financial and regulatory costs.

Arranging Cyber Insurance through Lloyd & Whyte provides GP practices with specialist protection tailored to the healthcare sector, covering data recovery, business interruption, legal support, and regulatory defence. Backed by deep understanding of NHS frameworks and the DSP Toolkit, Cyber Insurance through us helps practices build resilience and recover swiftly from digital threats.

 

To obtain a new quote or to discuss the tailored Cyber Insurance your GP practice needs, contact our team of specialist insurance experts today.

Contact Us

Call us

Book an appointment

30-minute consultation

Lloyd & Whyte® Ltd are authorised and regulated by the Financial Conduct Authority. Registered in England No. 03686765. Registered office: Affinity House, Bindon Road, Taunton, Somerset, TA2 6AA. Calls may be recorded for use in quality management, training and customer support.