Skip to content

How do private GPs store their consultation notes?

Where most private GPs keep their records, what the law expects of the storage, and the questions to settle on hosting, security, backups, retention and access.

  • England

The short answer

Most private GPs store consultation notes in a cloud-hosted electronic record system that the practice subscribes to, with the practice as data controller and the supplier as its processor under a written contract. Whatever system you use, the records must be secure, accurate, complete and contemporaneous under CQC Regulation 17 and UK GDPR, backed up, kept for a defined retention period and exportable if you change supplier or close.

Key points

  • Your practice is the data controller for its records. A cloud record supplier is your processor and needs a written contract.
  • CQC Regulation 17 requires secure, accurate, complete and contemporaneous records for every patient.
  • Check where data is hosted, how it is backed up, and how you would export it all if you left.
  • The NHS records management code is written for the NHS, but private providers can use it to set retention periods.
  • Patients can ask for a copy of their record, and you normally have one month to provide it.

What most private GPs do

Almost all private GPs now keep their notes in an electronic record, and most use a cloud-hosted system they reach through a browser. That lets you consult from different sites or remotely, send letters and prescriptions from the record, and avoid running your own servers. Systems private GPs use include Semble, Hero Health, EMIS, Cliniko, Meddbase, WriteUpp, Pabau and Jump EHR, and each answers the storage questions below differently. A few still use paper, which is allowed but harder to run well. See can I take paper notes?

If you work under practising privileges or as a sessional GP for another provider, you will normally write in their system and they are responsible for storage. This article is for GPs running their own service.

What the law and the CQC expect

  • CQC Regulation 17 requires you to maintain securely an accurate, complete and contemporaneous record for each patient, including the care provided and the decisions taken. Records must be kept secure, and created, stored and disposed of in line with legislation and national guidance.
  • UK GDPR and the Data Protection Act 2018 apply to health data as special category data. You need appropriate security, a lawful basis, a privacy notice and, in most cases, registration with the ICO. See ICO registration.
  • GMC guidance expects clear, accurate and legible records made at the time or as soon as possible afterwards.

You are the controller, the supplier is your processor

When you use a record system supplier, your practice decides why and how patient data is used, so it is the data controller. The supplier processes the data on your behalf. The ICO says that whenever a controller uses a processor, a written contract must be in place, covering matters such as security, sub-processors, help with patients’ rights requests and audits. Most suppliers provide a data processing agreement. Read it, and keep a copy.

Questions to ask about storage

QuestionWhy it matters
Where is the data hosted?Transfers outside the UK bring extra UK GDPR requirements. Many practices prefer UK hosting.
What security certifications does the supplier hold?Cyber Essentials Plus and an NHS Data Security and Protection Toolkit (DSPT) submission are useful signs, though not the whole picture.
How are backups made and tested?You must be able to restore access to data in a timely way after an incident.
Is there an audit trail?It shows who viewed or changed each record, which helps with complaints and CQC evidence.
Can you export everything?You need the full record, including letters and attachments, in a usable format if you change system or close.
What happens at the end of the contract?The supplier should return or delete data as you instruct.

The DSPT is compulsory for organisations with access to NHS patient data and systems. A purely private GP may not need to complete it, but a supplier that has done so has been through a recognised assessment.

Structure and coding

How you record matters as much as where. Coded entries, for example using SNOMED CT, make records searchable for recalls, audits and registers, and make letters to NHS GPs easier to code at the other end. Free text alone is harder to search and easier to miss. See how to choose a record system.

Day-to-day security

  • Use individual logins with multi-factor authentication. Never share accounts.
  • Lock screens and log out on shared devices.
  • Keep devices updated and encrypted, and use a secure network. See setting up your IT.
  • Do not store clinical notes in personal email, messaging apps or unencrypted documents.
  • Have a plan for downtime, such as a paper template that you add to the record afterwards.

How long to keep records

There is no retention period written specifically for private GPs. NHS England’s Records Management Code of Practice applies to NHS records but says private providers can use it for guidance. It says the NHS GP record should be kept for the life of the patient plus at least ten years after death. Many private GPs adopt a defined policy based on the code, and your medical defence organisation can advise on the periods it recommends. Write your policy down and apply it consistently, including confidential destruction at the end.

Patients’ access requests

Patients have the right to a copy of their record. The ICO says you must respond without undue delay and within one month, extendable by up to two months for complex requests. You cannot normally charge a fee. An electronic record that can export a patient’s full history makes this quick.

If you close or sell the practice

Decide early who will hold the records if you stop practising, how patients can get copies, and how long the records will be kept. Build this into your supplier contract and your business plan.

Outside England

UK GDPR applies across the UK. Scotland and Wales have their own records management codes, and independent clinics there are regulated by Healthcare Improvement Scotland and Healthcare Inspectorate Wales, and in Northern Ireland by the RQIA.

Tools that can help

Frequently asked questions

Can I store notes in a general cloud drive?

It is not a good idea. You would struggle to show a complete, contemporaneous record with audit trails, and you still need a processor contract and proper security.

Do I have to host records in the UK?

Not legally, but transfers outside the UK must meet UK GDPR rules. Most private GPs choose UK-hosted systems to keep this simple.

Who owns the records if I use a supplier’s system?

Your practice, as data controller, is responsible for them. The supplier processes them for you and should return or delete them when the contract ends.

Should I keep a separate copy of my records?

Check what backups your supplier makes and how quickly they can restore them. Some practices also take periodic exports, which must be stored as securely as the live record.

Sources

  1. Regulation 17: Good governanceCare Quality Commission · cqc.org.uk · Accessed
  2. What needs to be included in the contract?Information Commissioner’s Office · ico.org.uk · Accessed
  3. A guide to data securityInformation Commissioner’s Office · ico.org.uk · Accessed
  4. A guide to subject accessInformation Commissioner’s Office · ico.org.uk · Accessed
  5. Records Management Code of Practice: scope of the codeNHS England Digital · digital.nhs.uk · Accessed
  6. Records Management Code of Practice: Appendix III, how to deal with specific types of recordsNHS England Digital · digital.nhs.uk · Accessed
  7. Data Security and Protection ToolkitNHS England · dsptoolkit.nhs.uk · Accessed