How to migrate your private GP clinical system safely
Export, coding, audit trails, patient communication and parallel running: a step-by-step plan for changing record system without losing data or safety.
The short answer
Plan the move before you give notice. Get a written description of exactly what your current supplier will export and in what format. Update your data protection paperwork, test an import on a sample and have a clinician check it. Then switch on a set date, keep read-only access to the old system and its audit trail, and tell patients what changes for them. Allow at least six to eight weeks.
Key points
- Before you sign anything, ask your current supplier in writing what a full export contains, the file formats, the cost and the timescale.
- Structured data such as problems, medicines, allergies and results is what keeps patients safe. Check how it maps into the new system, not just that the notes arrive.
- Your old supplier’s processor contract should require it to return or delete your data when the contract ends. Agree which, and get it confirmed.
- Audit trails rarely move across. Keep read-only access or an archive export for as long as your retention policy requires.
- Test on a sample, have a clinician check it, set a cut-over date and run the old system read-only in parallel.
Start with a plan, not a notice period
Most migration problems come from starting too late. Once you have chosen a new system (see what to compare), work backwards from your contract end date.
| When | What |
|---|---|
| 8 or more weeks before | Request an export specification. Check the contract notice period. Name one person to own the migration, and a clinician to check it. |
| 6 weeks before | Review your data protection impact assessment and privacy notice. Sign the new processor contract. Map the data fields. |
| 4 weeks before | Run a test export and import on a sample. The clinician checks it. Fix the mapping. |
| 2 weeks before | Train staff. Tell patients. Set the cut-over date and plan how to handle open tasks. |
| Cut-over | Final export and import, a check, then go live. The old system becomes read-only. |
| After go-live | Keep the old system or an archive accessible. Reconcile results and tasks. Review after a month. |
What to ask your current supplier for
Ask in writing for a full export, and for the answer in writing too. Cover:
- Demographics and contact details, including NHS GP details and consent to share
- Coded data: problems, diagnoses, allergies and medications, with their codes, not just the text
- Consultation notes, with dates and the author of each entry
- Documents and letters, as files you can attach to the right patient
- Results, both structured values and the lab reports
- Prescriptions and repeat templates
- Appointments, invoices and payments, for continuity and your accounts
- The audit trail, or confirmation of how you can access it after you leave
Suppliers differ. Cliniko documents an export of all your data as CSV files, with attachments as a ZIP. Semble lets you export an individual patient’s data from their record, so ask its team what a whole-account export includes and in what format. For EMIS Web, ask the supplier or partner who manages your licence. If the answer is a set of PDFs per patient, expect to re-enter key coded data by hand.
Contracts and data protection
- The old processor contract. Under UK GDPR, your contract with a processor must require it to delete or return all the personal data when the service ends. Tell the old supplier which you want, and get written confirmation once the migration is verified.
- The new processor contract. Check it covers UK hosting, security, sub-processors, breach notification and exit terms.
- A DPIA. The ICO requires a data protection impact assessment where processing is likely to be high risk, and health records are special category data. Update yours for the new system.
- Records of processing and privacy notice. Name the new supplier. See UK GDPR for private practices.
- Clinical safety. NHS organisations must manage the clinical risk of deploying a new system under the DCB0160 standard. It is written for the NHS, but its approach is a sound model for a private practice: a named clinical lead, a list of hazards such as missing allergies, and a record of how you controlled them.
Coding and structured data
SNOMED CT is the clinical terminology all GP systems in England use. If both systems code in SNOMED CT, problems and allergies should map cleanly. Medicines should map to dm+d. Check that:
- active problems arrive as active problems, not as history
- allergies and adverse reactions arrive as coded allergies, not buried in free text
- current medications and repeats arrive with dose and quantity
- recalls, registers and monitoring dates (for example for high-risk drugs) are rebuilt in the new system
If your old system held mostly free text, agree which items you will code by hand for active patients, starting with allergies, long-term conditions and current medications.
Audit trails and retention
The CQC expects records that are accurate, complete, contemporaneous and accessible to authorised people when needed. That applies to records you created in the old system as well. Imported notes usually show the import date, not the original edit history, so keep:
- read-only access to the old system for an agreed period, or
- a complete archive export, including the audit trail, stored securely and searchable
Keep them for as long as your retention policy requires. NHS England’s Records Management Code of Practice sets NHS retention periods, and private providers may use it as guidance. Agree your policy with your indemnity provider.
Test, cut over and run in parallel
- Import a test sample that includes complex patients: several problems, repeat medicines, documents and recent results.
- A clinician compares a set of records side by side, field by field, and signs off or lists the fixes.
- Freeze bookings and data entry in the old system at the cut-over time, then run the final export.
- Check totals (number of patients, documents and appointments) and spot-check again.
- Carry over open work by hand: outstanding results, referrals, unsent letters and unpaid invoices.
- Keep the old system read-only and check it for anything that arrives late, such as lab results.
Tell patients
Tell patients before the switch if anything they see changes, such as booking links, the patient app or portal, payment or appointment reminders. Saved card details may not transfer between payment providers, so warn patients who pay by stored card. Update your privacy notice and website on the same day.
Suppliers that help with migration
Many suppliers will import data for you, and some charge for it. Ask what they have imported before, from which systems, and what they check afterwards. For example, Jump has a structured import for moving from Semble, which brings coded data across rather than only documents. Whichever supplier you choose, ask them to show you a migrated test record before you commit.
Migration checklist
- Written export specification and cost from the current supplier
- Contract notice period and end date confirmed
- DPIA, privacy notice and records of processing updated
- New processor contract signed
- Field mapping agreed, including coded problems, allergies and medicines
- Test import checked and signed off by a clinician
- Staff trained and patients told
- Cut-over done, totals reconciled and open tasks carried over
- Old system read-only or archived, with the audit trail, for the retention period
- Old supplier confirms return or deletion of the data in writing
Tools that can help
Frequently asked questions
Can I migrate from paper notes to an electronic system?
Yes. Most practices scan paper records into the new system and code active problems, allergies and medications by hand. Keep the paper originals securely until you have checked the scans against your retention policy.
Who owns the data when I leave a supplier?
You do, as the data controller. The supplier processes it for you and must return or delete it at the end of the contract. Check the exit terms for format and cost before you sign.
Should I tell the CQC I have changed record system?
Changing software is not usually a notifiable event. But inspectors may ask how you kept records safe during the change, so keep your migration plan, checks and sign-off as evidence.
How long should I run the old system in parallel?
Keep it read-only for at least a few months, until late results and queries have stopped. Then keep an archive export or read-only access for your full retention period.
