Skip to main content

Restricting access to patient records

You can restrict staff members from accessing patient records stored in this service.

Only restrict access to a record if it’s necessary to protect the patient. Ensure your actions follow your organisation’s information governance policies and the Records Management Code of Practice. 

To add a restriction, you’ll need the staff member’s NHS smartcard number. Some staff members may have more than one NHS smartcard number, for example, if they’ve moved practice and have been given a new one. You can check a staff member's NHS smartcard details in Care Identity Management.


Add a restriction to patient record

You can only add restrictions for staff members who work at your practice. You cannot add a restriction for your own NHS smartcard. If you need to restrict yourself from patient records, ask another member of staff to do this for you.  

To add a restriction:  

1. In the home page, select the Admin hub

2. In the Admin hub, select Add and manage restrictions on accessing patient records.

3. In the next page, select Add a restriction.

4. Enter the NHS number of the patient you want to restrict a staff member from accessing the record of.  

5. Confirm the patient details and continue. 

6. You'll be shown the existing restrictions on accessing the patient record, if there are any. Check if the staff member you need to add a restriction for is already listed. Select Continue to add a restriction if you need to.

7. Enter the NHS smartcard number of the staff member you want to restrict from accessing the patient record. The details you enter will be validated against Care Identity Service (CIS) data.    

8. Check and confirm the NHS smartcard details. The details displayed have come from CIS data.

9. Check and confirm the details of the restriction, then select Continue to add this restriction. You can cancel without adding the restriction if the details are incorrect.

If you cancel, you’ll be asked ‘Are you sure you want to cancel adding this restriction.’ If you continue to cancel, you’ll go back to the ‘Restrict staff from accessing patient records’ page.

10. You’ll see a page confirming that the restriction has been added.  

You cannot add a restriction for your own NHS smartcard. If you need to restrict yourself from patient records, ask another member of staff to do this for you. You can only add a restrictions for staff members who work at your practice.


Manage restrictions on access to patient records

You can view and remove restrictions from the ‘Manage restrictions on access to patient records’ page. This page shows restrictions for all staff linked to your patients with active restrictions on their record in the service. You may see staff members listed who do not work at your practice.

To view a restriction:

1. In the home page, select the Admin hub.

2. In the Admin hub, select Add and mange restrictions on accessing patient records.

3. In the next page, select View and remove a restriction.

4. In the ‘Manage restrictions on access to patient records’ page you’ll see a list of all the restrictions for your practice. 

5. Select View next to the restriction. 

6. Check and confirm the patient details to continue. 

7. You’ll go to a page displaying all the staff members restricted from accessing that patient record.  

To remove a restriction:

1. In the same page, select Remove next to the staff member you want to remove a restriction for.  

2. You’ll be asked ‘Are you sure you want to remove this restriction?’ Choose Remove this restriction, or Cancel to stop removing the restriction.  

3. If you continue, you’ll see a page confirming that you’ve removed the restriction for that staff member. They will now be able to access the patient record in this service.


After you’ve added a restriction

The restriction will stay with a patient record until it is removed. If a patient moves practice, the new practice will see the name and NHS smartcard number of the staff member you’ve restricted. 

This service is not linked to the clinical systems. Any restrictions you’ve added will not appear in the clinical system.


Errors and messages when adding a restriction

Adding restrictions for staff who do not work at your practice 

If you try to add a restriction on an NHS smartcard number of a staff member who does not work at your practice, you’ll see the message: ‘You cannot add a restriction on this NHS smartcard number’.   

Accessing records you’re restricted from 

If you try to access a patient record that you’re restricted from, you’ll see the message ‘You cannot access this patient’s record or documents.’ If you think you’ve been restricted by mistake, speak to your practice manager. 

You will see the message: ‘You are restricted from reassigning these pages to this patient’ if you try to reassign pages in scanned paper notes to a patient whose record you are restricted from accessing. You’ll need to ask another member of staff to reassign the pages. 

For auditing purposes, the service will log when a user tries to access a patient record they’re restricted from. 

Errors when a restriction already exists

You may see an error message ‘A restriction on this record already exists for this NHS smartcard number’ if you enter an NHS smartcard number which is already restricted from accessing the patient record.  

You can check what restrictions already exist for a patient record in the ‘Manage restrictions on access to patient records’ page. You’ll also be shown the existing restrictions for a patient record before you add a new restriction.

Last edited: 31 March 2026 3:15 pm