Skip to main content

Order Management transparency notice

This transparency notice for the Genomics Order Management project explains: 

  • why we collect information about you (we call this 'personal data') 
  • what we do with it, including who we share it with 
  • how long we keep it for and where we store it 
  • our legal basis for using it 
  • what your data protection rights are

To read more about how NHS England uses personal data to improve health and care, see NHS England's privacy notice.


About the Order Management project 

The National Genomics Order Management Interoperability Project is focused on allowing genomic tests to be ordered through a single electronic system nationally. Currently, each region within the Genomics Medicine Service has their own process for ordering tests which can vary depending on the region and organisations involved. To standardise the test requesting, it uses a standardised master data set, which provides all data fields required by both the requester of the test and the lab completing the test. This is used to accept and progress the genomic test request and support the report being provided back to the requestor.  

Ultimately, the project is aiming to make the ordering and management of Genomic Test orders more simple, efficient and effective by allowing electronic ordering and communication across organisations to be smoother. 

The key parts of the project include:   

Central broker: to coordinate the electronic communication required between organisations and allow for genomic testing, genomic test reports and updates between given organisations and systems. This includes storage of data for these activities centrally.  

Genomic Test Order portal: to provide a generic way for requestors to create and manage genomic test orders access the national order management system, where their local systems do not have capabilities or integration to the national broker is not available (for example, lab system isn’t able to communicate to the central broker).  

Integrated Trust and Lab Genomic Test ordering: to enable the use of an existing system (electronic patient record systems (EPRs) and Laboratory Information Management Systems (LIMS)) to connect to the central broker and to allow for end-to-end communication of the test across organisations.

Introduction of the national Order Management infrastructure will drive the following key, fundamental benefits:  

Data quality and consistency – Electronic ordering will improve the completeness and accuracy of information passed between the requestors of tests and laboratories fulfilling the order. 

Time and resource savings – Electronic ordering will remove the need for manual transcription of current paper-based order forms.  

Order and sample tracking – A way of providing and querying status updates for the order and the whereabouts of related samples will address the current lack of visibility for both clinicians and laboratory personnel. 

Strategic alignment - to the 'Accelerating genomic medicine in the NHS' strategic ambitions within the NHS (for example, NHS Long Term Plan), to improve and align with NHS ambitions to improve interoperability and use of standardised data within the Genomic Medicines Service (GMS).  

Equity of access –This work adds a scalable, interoperable capability to the GMS ecosystem. Once expanded, it will help ensure fair access to test ordering and improve communication of the tasks needed to complete an order. 

Turnaround times for test – Faster communications and reduced manual tasks will improve how quickly a test can be turned around from request to a report being completed and received.

Process improvements and standardisation – Use of the solution will mean more specialities are working in the same way.  

Scalability and integration opportunities – it is likely that there are further opportunities to collaborate and share data between systems or organisations will be realised in future. The Order Management infrastructure is the enabler for introduction of the Unified Genomic Record (UGR) and introduction of structured reporting data to standardise the way genomic test reports are shared. 

Each of the above listed items can be considered as either directly or indirectly benefitting patients. 


Our role

Under data protection law, NHS England is the 'controller' for the Order Management project. This means that we make decisions about what personal data we need to collect and how we will use your data to deliver the service.


What data we collect 

The personal data to be processed within the scope of the Order Management project relates to both patients and NHS personnel. In addition to the areas mentioned below, a PDF of the test report will also be shared through the broker from the testing lab to the clinician.  

To provide the Order Management Service we need to collect and process your: 

Genomic test data [Category] – such as your: 

  • demographics information Name, date of birth, ethnicity and sex, gender identity, NHS number [data item]
  • patient information: Personal and Personal-Sensitive (special category) information for patients (relatives of patient for certain test)  
  • test request data – Test ID, test type, clinical details, pregnancy status 
  • record of your consent choice in relation to research [data item] 
  • information in relation to your biopsy or specimen [data item] 
  • previous genomic reports 
  • patient clinical information (see table below) 
  • relevant previous non-genomic diagnostic reports (for example, pathology) 
  • healthcare professionals – names, contact details and organisations     

Genomic test reports as an attached PDF file, including genomic test results, variants of interest, patient and clinician information.

In some circumstances we may perform diagnostic requests on groups rather than single individuals, such as testing a family (mother, father and child) or testing a pregnant mother and her feotus. In these events, we collect relevant Genomic test data and test reports for each individual. We also link these records so that the group can be reviewed together. 

The data being either used or generated has been documented formally within a Master Data Set (MDS), the data groups contained within this are found below:

MDS data groups

Data group Short description
Healthcare professional Name, contact and organisational information
Patients

Personal and Personal-Sensitive (special category) information for patients (patient and/or relatives of the patient). Broad examples range from name and other personal identifiers such as DOB, ethnicity, sex, gender identity.  

Foetus detail is recorded (identifier, sex, status at time of test, pregnancy ID) for relevant tests.

Record of Discussion (RoD) or (NGRL) Consent for Research Incorporating clinical staff name and patient demographics (or patient representative) as relating to the consent. 
Test request Information associating test request to patient.
Primary sample (raw specimen or biopsy)  Information associating a specimen to patient or relatives' identifiers.
Other relevant clinical document (attachable file)  Comparable data to 'Patients' data group, (PDF), clinical personnel identifiers present in report files.
Patient clinical information Personal and Personal-Sensitive data, for example, phenotypic information, and genomic ethnicity for the patient and various elements relating to specifics of the disease and subject of the testing. 
Further supporting information Information associating clinical encounter or speciality to patient

Where we get your data from

Data will be collected about individual patients, from clinicians requesting a test and from related IT systems used at the requesting organisation – which will be a hospital or other care setting. For example, information relating to the test request, or to the patient themselves such as name, date of birth, ethnicity and gender. This will be provided by National NHS systems (Personal Demographics Service) that are already in place. 

Data will in some circumstances be collected directly from the patient by the relevant treatment provider and it is expected that the patient will be registered locally with the patient electronic record prior to being referred for a genomic test.  

Data will in some circumstances be entered manually by clinicians and health care professionals when dealing with patients or their family members as part of the test ordering consultation process. At the stage of test requesting, the following types of data may be collected:  

Patient Demographics  

Organisation or clinician Details  

Reason for testing  

Relevant clinical information to support testing  

Record of Discussion (consent for WGS research)  

Sample type information   

Data held within the central broker will be managed through secure communication infrastructure standards (Application Programming Interfaces Management (APIM) and Apigee) to ensure appropriate levels of security and authenticated access.


How we use your data

Use and management of genomic test data 

This section explains how data is used, transferred, and stored as part of the Genomics Order Management project, delivered under a Ministerial Direction. It outlines the key processes that support the ordering, fulfilment, and reporting of genomic tests across the NHS, and the measures in place to ensure data is managed securely, responsibly, and in accordance with national standards. 

Overview of the genomic testing process 

Data referenced within this notice supports a range of NHS systems and activities involved in the genomic testing pathway - from the initial test request through to sample processing, analysis, and the generation of a final report. 

At a high level, the process includes: 

  1. Test request: A hospital, laboratory, or healthcare organisation requests a specific genomic test. 
  2. Sample processing: The request may involve preparing and sequencing a DNA sample, followed by analysis and interpretation of the results. 
  3. Reporting: A final report is created and shared securely with the requesting organisation. 

Data underpins each of these stages; for example, sample quality information supports laboratory preparation, and patient details are used by scientists to interpret results accurately. 

Order Management and data exchange 

The Genomics Order Management System enables secure, standardised communication between NHS organisations and Genomic Laboratory Hubs (GLHs). Its core features include: 

Test status updates: Real-time notifications showing when a test request has been received, is in progress, or is awaiting a sample. 

Sample tracking: Updates confirming when a sample has been sent or received, including transfers between organisations or GLHs. 

Request processing: Validation of request details and matching to available samples, with routing to the appropriate testing location. 

Result reporting: Creation and storage of final test reports in secure PDF format, accessible only to authorised users. 

Data security and storage 

All patient and test request information is transmitted and stored securely using modern encryption standards (HTTPS/AES-256). The Order Management solution, including the central broker and national genomics portal, is hosted in line with NHS England’s security and interoperability standards.  

Access and authentication are managed through Apigee and API Management (APIM), ensuring that only authorised systems and users can exchange data. 

Data such as test requests, sample updates, and reports may be held within a patient’s Electronic Patient Record (EPR) or within the National Genomics Portal, depending on the system used to place the request. 

Organisations submitting electronic requests must comply with NHS and international standards - FHIR UK Core R4 and Open API (APIM) standards - to ensure secure interoperability. Where existing systems use a different standard, HL7 V2, NHS England provides guidance to support message transformation to the FHIR and Open API standards mentioned and support safe data exchange. 

Further detail is available in the FHIR Genomics Implementation Guide, which outlines technical specifications for connecting local systems to the national broker. 

Access and authentication 

Access to the National Genomics Portal requires secure authentication, either through Care Identity Service 2 (CIS2) or locally managed multi-factor authentication within NHS organisations. 

Where genomic test requests are submitted via an Electronic Patient Record, authentication follows NHS Smartcard processes and local governance policies to ensure appropriate access controls. 

Hosting and cloud infrastructure 

The programme follows a cloud-first approach, with data hosted securely within the UK using Amazon Web Services (AWS) and NHS England-approved services (for example, Patient Data Manager). 

All data storage and processing comply with UK data protection legislation and NHS information governance standards, ensuring patient information is safeguarded throughout the testing process. 



Who we share data with

We share identifiable data with the following organisations to support the completion of genomic test requests:

Organisation ordering entities Country of operation Data to be shared
GMS Genomics Laboratories England All groups from the Test Request Reference Set (MDS) 
Pathology laboratories England All groups from the Test Request Reference Set (MDS) 
CPCGC Laboratories (Cellular Pathology Genomic Centres)  England All groups from the Test Request Reference Set (MDS) 
SIHMDS (Specialist Integrated Haematological Malignancy Diagnostic Service)  England All groups from the Test Request Reference Set (MDS) 
Primary care settings – various – as ordering entities  England All groups from the Test Request Reference Set (MDS) 
Secondary care settings – various – as ordering entities  England All groups from the Test Request Reference Set (MDS) 
Tertiary care settings – various – as ordering entities  England All groups from the Test Request Reference Set (MDS) 
Order processing (wet and dry lab tasks)    
GMS/Genomics Laboratories England All groups from the Test Request Reference Set (MDS) 
Pathology laboratories England All groups from the Test Request Reference Set (MDS) 
CPCG Laboratories (Cellular Pathology Genomic Centres)  England All groups from the Test Request Reference Set (MDS) 
Genomics England (GEL) England  All groups from the Test Request Reference Set (MDS) 
Technology suppliers England Intersystems Healthcare Connect have been procured to provide the technology platform for the broker. Kainos have been procured to be the development and support partner, however they will not process personal data. The web portal is yet to be selected. The DPIA and transparency notice will be updated once the supplier is confirmed

Processors

We also share some data with our data processor Intersystems Healthcare Connect who provide a broker service which will deliver electronic communication required in order to process each test request under a contract. They can only use, store and keep the data in accordance with our instructions and cannot use the data for any other purposes.


How long we keep data for  

NHS England shall retain data in line with The Records Management Code of Practice 2021 and organisational policy.

Data item or category

Records (as defined in the Genomics FHIR IG) covering orders, results, consent, clinical structured observations.

How long we keep it for

30 years.

Why

Records Management Code of Practice retention schedule and Royal College of Pathology and BSGM guidelines.

We keep your data in accordance with The Records Management Code of Practice 2021.


Where we store data  

We securely store your data on our servers in the United Kingdom (UK), on NHS England AWS cloud infrastructure that is conformant to United Kingdom (UK) boundary needs for data capture. 

All patient and test request information is transmitted and stored securely using modern encryption standards (HTTPS/AES-256). The Order Management solution, including the central broker and national genomics portal, is hosted in line with NHS England’s security and interoperability standards. 

Access and authentication are managed through Apigee and API Management (APIM), ensuring that only authorised systems and users can exchange data. 

Data such as test requests, sample updates, and reports may be held within a patient’s Electronic Patient Record (EPR) or within the National Genomics Portal, depending on the system used to place the request. 

Organisations submitting electronic requests must comply with NHS and international standards -  FHIR UK Core R4 and Open API (APIM) standards - to ensure secure interoperability. Where existing systems use a different standard, HL7 V2, NHS England provides guidance to support message transformation to the FHIR and Open API standards mentioned, and support safe data exchange. 

Further detail is available in the FHIR Genomics Implementation Guide, which outlines technical specifications for connecting local systems to the national broker.


Your data protection rights 

Under data protection law, you have the following rights over your data for this service: 

Your right to be informed – You have the right to be told how and why we are using your personal data. We have published this transparency notice to provide you with this information.  

Your right to get copies of your data – You have the right to ask us for copies of your personal data (right of access). For more information, see how to make a subject access request.

Your right to get your data corrected – You have the right to ask us to correct (rectify) your personal data if you think it is inaccurate or incomplete. 

Your right to limit how we use your data – You have the right to ask us to limit the way we use your personal data (restrict processing) in certain circumstances.

To make a rights request, email us at [email protected].


Opt outs

National Data Opt-Out 

When NHS England collects the Order Management data from healthcare providers 

If you have registered a National Data Opt-Out, NHS England can still collect your data under the Genomics Services Directions. This is because the National Data Opt-Out does not apply where NHS England has a legal obligation to collect the data (see section 6.4 of the National Data Opt-Out Operational Policy Guidance for more information). 

When NHS England shares Genomics Order Management data 

For any data we share with other organisations through our Data Access Request Service, we will apply the national data opt-out in line with the National Data Opt-Out Operational Policy Guidance. 

You can find out more about and register a national data opt-out or change your choice on the NHS.uk website.


Your right to complain 

We take our responsibility to look after your data very seriously. If you have any questions or concerns about how NHS England uses your data, please contact our Data Protection Officer at: [email protected].

If you are not happy with our response, you have the right to make a complaint about how we are using your data to the Information Commissioner’s Office by calling 0303 123 1113 or through their website.


Changes to this notice 

We may make changes to this notice. If we do, the 'last edited' date on this page will also change. Any changes to this notice will apply immediately from the date of any change.


Appendix A

Right to be informed Right to get copies (access) Right to get data corrected (rectification) Right to get data deleted (erasure) Right to limit how data is used (restrict processing) Right to object Right to data portability Right not to be subject to automated decision making Right to withdraw consent
Consent Yes Yes Yes Yes Yes No Yes No Yes
Contract Yes Yes Yes Yes Yes No Yes No No
Legal obligation Yes Yes Yes No Yes No No No No
Vital interests Yes Yes Yes No Yes No No Yes No
Public task Yes Yes Yes No Yes Yes No Yes No
Legitimate interests Yes Yes Yes Yes Yes Yes No Yes No

 

Last edited: 1 October 2026 11:09 am