The NHS is undergoing a vital transformation towards Neighbourhood healthcare. Through Integrated Neighbourhood Teams (INTs), the goal is to break down the traditional walls between primary, secondary, community, and social care to deliver proactive, holistic care for local populations.
Remote clinical service providers like Medacy will be central to this vision. By integrating highly skilled clinicians into these local teams, we help expand capacity and ensure patients get timely interventions. We are already embedded in primary care workflows, seamlessly accessing SystmOne and EMIS.
But, as with any big change, there is a problem on the horizon for this new integrated model: fragmented access to pathology results. Even when we have 90% of the clinical picture, the remaining 10% (the pathology data) is often trapped behind secondary care firewalls and bureaucratic red tape.
A System-Wide Infrastructure Gap
While remote providers are often the first to hit these walls, it is vital to recognise that this is not just a remote provider problem. It is a fundamental infrastructure gap that threatens the entire vision of the Single Neighbourhood Provider (SNP) and integrated working.
The success of Neighbourhood healthcare relies on clinicians moving fluidly between primary, secondary, and community settings. However, the moment a community nurse, a mobile multidisciplinary team member, or a remote clinician steps outside a specific Trust’s physical network, they become ‘external’ in the eyes of the IT firewall.
By treating anyone not physically tethered to the hospital as a security threat, we aren’t just slowing down remote partners; we are handicapping the very local teams—both internal and external—meant to deliver holistic care. At Medacy, we see this bottleneck daily, but we also see it as the canary in the coal mine for the wider shift toward integrated working.
The Bottleneck: IP Ranges and Misunderstood Red Tape
To make safe and effective clinical decisions, clinicians need to view blood test results or order necessary panels via systems like webICE. Instead of seamless interoperability, we are met with two major roadblocks:
- Technical Bureaucracy: Clinicians are frequently forced to rely on localised IT workarounds. This usually means submitting requests to secondary care IT departments to whitelist specific IP ranges for secure networks (like Redcentric). This delays onboarding and treats vetted clinical partners like external security threats.
- Information Governance (IG) Misunderstandings: We frequently see large NHS Foundation Trusts refuse pathology access because a remote or partner provider does not hold a direct commercial contract with the Integrated Care Board (ICB).
This is a fundamental misunderstanding of data-sharing legislation. It confuses the flow of money with the legal basis for clinical care.
Clearing the Confusion: The Data Controller Argument
When a Trust blocks webICE access due to a lack of an ICB contract, it inadvertently prevents the Primary Care Network (PCN) from doing its job. Here is the reality of the legal framework:
- The PCN is the Data Controller: The GP practices within the PCN are the data controllers for their patients.
- The Provider is the Data Processor: Whether it is a mobile internal team or an external partner like Medacy, the provider holds a direct, legally binding contract with the PCN to provide clinical services. This makes them an authorised Data Processor, acting on the PCN’s explicit instructions for direct patient care.
- The Duty to Share: Under Caldicott Principle 7, “The duty to share information can be as important as the duty to protect patient confidentiality.” If the Data Controller (the PCN) authorises a provider to manage their patients, secondary care partners have a duty to facilitate the secure sharing of that pathology data.
We don’t need a commercial contract with the ICB to look at a blood test; we need a secure, standardised mechanism that respects the PCN’s clinical mandate.
The Solution: A ‘ick-Box Access Passport and Supplier Framework
Patient data security is paramount. But security should not come at the expense of silos. If the NHS is serious about Neighbourhood healthcare, we need to move away from localised IT battles and adopt standardised access models.
Here are two solutions that ICBs and Trusts can implement right now:
1. The Short-Term Fix: System-Wide Information Sharing Agreements (ISAs)
Instead of using the lack of a commercial contract as a roadblock, Trusts and ICBs should utilise Information Sharing Agreements (ISAs) or Memorandums of Understanding (MoUs). These documents formally acknowledge that a clinician—whether remote or part of a mobile neighbourhood team—is an approved clinical partner of the PCN, legally clearing them for cross-system data access without a financial contract.
2. The Long-Term Fix: An ICB Accredited Digital Supplier Framework
Think of this as a “Performers List” for digital and remote suppliers. Instead of negotiating with individual IT departments over IP ranges or IG checks, there should be a straightforward, system-wide framework: If you tick all the compliance boxes, you are granted access.
To get on this approved list, a provider must demonstrate:
- IG Compliance: A “Standards Met” status on the Data Security and Protection Toolkit (DSPT).
- Secure Infrastructure: Use of approved, secure clinical networks (e.g., HSCN).
- Verified Identity: Clinicians are authenticated using the NHS Care Identity Service (Smartcards or secure alternatives) with clear Role-Based Access Control (RBAC).
Once a provider is on the ICB’s Accredited Supplier List, Foundation Trusts can automatically grant webICE or pathology portal access. This will save hundreds of hours of duplicated IT and IG checks across the system.
True Integration Requires True Interoperability
We cannot build integrated Neighbourhood teams on a fragmented IT infrastructure and misunderstood IG rules.
By replacing outdated technical barriers with a standardised, compliance-based access model, we can empower every clinician—remote, mobile, or community-based—to work at the top of their license. At Medacy, we have navigated these hurdles many times, but for the Neighbourhood model to succeed at scale, we must clear these roadblocks for everyone. It is time to deliver the faster, safer, and more efficient care that this new era of healthcare promises.
If you are looking for a pharmacy provider with the highest data transparency and security standards for the transition to the future – talk to Medacy. We are ISO 9001 certified, Cyber Secure, and compliant with Data Security and Protections Toolkit standards.