We are a supplier integrating GP Connect Access Record: HTML, and we retrieve a single patient from PDS by NHS number to confirm the number before the GP Connect call. We never search on demographics and we never write.
NHS England have told us that healthcare worker access mode with CIS2 is required for our use case, since the user triggers the retrieval and reads the result. We have implemented CIS2 authentication and are currently having Integration test users provisioned, with role code R8015. Before those accounts are bound we would like to get the role right, because amending it afterwards is harder.
1. Which RBAC activity codes does the user need for a retrieve-by-NHS-number in healthcare worker access mode?
Our reading of the conformance guidance is that no additional business function code is required for a read of a single patient, because the National RBAC requirement attaches to multi-patient searches and to updates. But the Path to Live smartcard request form lists DSA codes such as B0089, and we would rather be told than infer. Is B0089 — or any other B code — expected on a user who only ever performs this retrieval?
2. What is the calling system expected to enforce, given the codes CIS2 actually returns?
The guidance says PDS does not perform the authorisation check itself and that the calling system is expected to apply the rules in the national RBAC database. We also understand from Activity codes in UserInfo response that CIS2 does not return baseline activity codes — an integrator has to know them already.
So if a baseline code covers this retrieval, we would not see it in the userinfo response, and we would have no way to check for it. Should we be checking for a specific code before making the call, or is the presence of an authenticated healthcare worker with an appropriate job role sufficient here?
Happy to give more detail on the flow if that helps.
The requirement to use CIS2 Auth is part of a shift to improve the overall security of the access and use of PDS data. The documentation has not yet been fully updated to reflect this - the final decisions and updates are in progress.
There is no fixed requirement for the National RBAC for a single retrieve at this time, however it is available for your use using CIS2 Auth. I will try get a confirmation of the expected activities if you are to use it.
Regarding Baseline Activity Codes - basically, a Role Code (Rxxxx) comes with some baseline activities, defined by the National RBAC Baseline Activities. These are not returned in the CIS2 userinfo at this time. However, they are pretty much fixed and have been for a long time - any change to these would be a large undertaking, so it is unlikely to happen, to you can hardcode these, essentially.
Thank you — that is exactly what we needed, and it corrects our question as well as answering it.
B0089 came from the Path to Live smartcard request form, where it appears as an access DSA code. We carried it into the question because the form lists it; B0825 and B0264 are clearly the right ones.
On that basis we will not build an activity check for now. We retrieve a single patient by NHS number and never write, so with no fixed National RBAC requirement for a retrieve there is nothing for us to gate on — and the note that baseline activities may be hardcoded resolves what looked like an impasse, since we had established that CIS2 does not return them.
One follow-up, and it is the specific version of the confirmation you offered. Our two Integration test accounts were created with role code R8015. Does that role’s baseline include B0825 and B0264? It matters mainly for timing: if it does not, amending the role through ITOC is much easier now, while the accounts are new, than after a requirement lands.
Noted also that the documentation is mid-update — that is useful context and will save us second-guessing anything that looks contradictory in the meantime.
A generic role to cover staff who provide support to systems, but have no baseline activities although it is envisaged that at least one of the systems activities will be allocated to this role