Skip to main content

Operations

The Operations team is responsible for the ongoing maintenance and support of operational services.

We ensure the health and social care products under NHS England's remit are delivered from a programme environment into an operational environment, where they can be managed on a day to day basis in line with agreed product roadmaps and strategies.

At the appropriate point in a programme's delivery the run and maintain elements of a service are transitioned into operations. 

IT Operations aims to bring efficiencies and economies of scale by taking products into a maintenance and improvement environment, right through to product retirement. It aims to standardise the management of products which the NHS and NHS IT suppliers interface in a controlled and secure manner.

What we do

As IT operations, we support the maintain aspects of live service management. We work with three main parties: 

  • NHS England, (this includes programmes, projects, subject matter experts and directorates)
  • our technology partners, such as third-party system developers and suppliers and NHS England development teams
  • health and social care organisations 

Our two core roles are transition and business as usual operations. 

The primary role of the operations function is to provide a permanent home for products and services after they have been developed by programmes, projects or development teams and are ready to be made available to our external customers. Moving home involves a process called transition (to ops).

Our second role is to put products, services and applications in the hands of health and care professionals, 'to transform the NHS and social care'. There are various business as usual operations processes to achieve this, depending on the type of data or service and the external organisations involved. These include the following processes.

Onboarding

This process involves a technology partner requesting access to an NHS England dataset or service so that they can integrate it with their health and social care application or system. The onboarding process has a risk management and assurance focus to ensure that we, our partners and health and social care organisations take appropriate responsibility for using data safely to provide health and social care services.

Monitoring

Once an NHS England product, service or application is being used by an health and social care organisation, IT operations continues to monitor partners and the organisations using their products, for compliance with core requirements, standards and specifications (these vary with the data, product or service and cover technical/functional, clinical safety, information governance and security). As with the onboarding process, the emphasis is upon self-assurance by our partners and deploying organisations. IT Operations provides an oversight and governance role.

Product management

As the demand on NHS England’s services changes, our products, services and applications need to evolve to meet those changing demands. Our product management role is to assess changes and developments and implement them based on impact and urgency. These changes may be mandated or imposed because of statutory changes or needed to improve functionality.


Onboarding

Onboarding is NHS England's process for allowing connecting systems to integrate with national services. Connecting systems are developed by technology partners to provide healthcare organisations and individuals with access to national services, in support of the provision of direct care.

There are three main approaches to onboarding and NHS England is working towards standardising these. GPIT, IM1 and full integration approaches are separate to the following self-declared compliance approach, which uses a Supplier Conformance Assessment List (SCAL) and Connection Agreement (CA). The Digital Onboarding Service is a digitised version of the SCAL. We reference the SCAL documentation as conformance documentation within the connection agreement.

The NHS England services and APIs that currently follow this onboarding approach include:
  • Ambulance Data Submission - FHIR API
  • Booking and Referral Standard (BARS) 
  • Care Identity Service 2 (CIS2) - formerly NHS Identity 
  • Child Protection Information Sharing (CP-IS) HL7 API
  • Directory of Services - Urgent and Emergency Care - REST API
  • Directory of Services - Urgent and Emergency Care - SOAP API

  • Directory of Services - Urgent and Emergency Care - Electronic Prescription Service (EPS)

  • Directory of Services - Search API

  • Electronic Prescription Service (EPS) Prescription Tracker API
  • Electronic Prescription Service (EPS) Prescription Tracker FHIR API
  • Electronic Prescription Service (EPS) HL7 and FHIR APIs
  • Electronic Prescription Service (EPS) Prescriptions for Patients FHIR API
  • Electronic Prescription Service (EPS) Prescription Status Update FHIR API
  • Electronic Prescription Service (EPS) Custom Prescription Status Update FHIR API
  • e-Referral Service (e-RS) FHIR API Application-restricted, unattended access
  • e-Referral Service (e-RS) FHIR API Healthcare worker, user-restricted access

  • GP Connect Products such as Access Document, Access Record: HTML and Structured, Appointment Management, Send Document and Update Record.
  • Healthcare Worker API

  • HomeTest Platform FHIR API

  • Immunisation History - FHIR API (Application & User Restricted Access for COVID19 and FLU vaccination history)
  • Immunisation FHIR API - consumer (Application restricted and User Restricted (CIS2))

  • Immunisation FHIR API - provider (Application restricted and User Restricted (CIS2))

  • Message Exchange for Social Care and Health (MESH) API
  • National Care Record Service (NCRS) 
  • National Data Opt-Out 
  • National Event Management Services (NEMS) with PDS data 
  • National Event Management Services with Digital Child Health (NEMS-DCH)
  • National Imaging Registry API
  • National Record Locator (NRL)
  • NHS App
  • NHS App Notification and Messaging
  • NHS login
  • NHS Notify
  • Patient Care Aggregator FHIR API (Appointments; Documents; Questionnaires and MIv2)
  • Patient Data Manager FHIR API
  • Patient Flag Service FHIR API– Female Genital Mutilation Digital Flag; Reasonable Adjustment Flag and Child Protection Information Sharing (CPIS) Service
  • PDS FHIR API - Application Restricted Access; Health Worker Access; Health Worker Access with Update and Patient Access
  • Proxy Service FHIR API - IM1 Auth Proxy Service
  • Proxy Service FHIR API - Validated Relationship Service (Non Patient Facing)
  • Register with a GP Surgery API
  • Summary Care Record (SCR) FHIR API
  • Urgent and Emergency Care (UEC) Appointment Booking

The onboarding process

The onboarding process is risk-based and:

  • assesses the technical conformance of the connecting system with the integration standards and requirements of the service
  • requires self-declared compliance with specified standards for data protection, clinical safety, information governance and security

The aim of the onboarding process is for all parties to work together to ensure the safe and secure transmission and/or sharing of data for healthcare purposes.

The parties involved in onboarding are:

  • NHS England the owner of the national service
  • the connecting party an individual or organisation that develops, owns, and maintains the connecting system that connects to one or more national service or services - this is sometimes called a partner or supplier
  • the end user organisation, the recipient or commissioning body wishing to use or commission a connecting system to access a national service or services - the end user organisation often represents individual end users for example, healthcare professionals or patients

Each party is responsible for their own information governance, data protection, information security, clinical risk management and incident management. The connection agreement explains the responsibilities, obligations and terms of use and is signed by the connecting party. The end user acceptable use policy explains the responsibilities, obligations, and terms of use for every end user organisation. 

Each national service also has a web page or portal, that contains the technical, functional, and non-functional standards and requirements that a connecting system must meet to integrate to the national service. Search the API catalogue for more information.


The SCAL (conformance documentation)

The Supplier Conformance Assessment List (SCAL) is currently presented as a workbook. This needs to be completed by the connecting party to create a record of the technical conformance of its connecting system with the technical requirements of the national service being integrated. It also contains declarations of organisational compliance with standards, regulations, and policies. 

The Digital Onboarding Service (a digitised version of the SCAL) now manages assurance for many of our APIs. Once a developer account has been set up, the connecting party must register their organisation, to which they may register multiple products, each product may onboard with multiple APIs within the one record.

When an organisation, product and its associated APIs are added, the supplier will be presented with the appropriate question set for the APIs they are onboarding too and may commence completion of the assurance questions.

Users can upload documents and evidence as directed by the question sets and the onboarding teams. The NHS England will review, request more information, and approve the question sets.

This sample sets out the assurance questions that applies to all NHS England service listed to demonstrate that your organisation and product has processes in place to handle data securely, manage clinical risk and use our production environments. Each of the NHS England services will contain service specific technical conformance question which will be on the service specific SCAL.

The form includes a section for you to provide details about your organisation and product. For some APIs you must also demonstrate you are eligible or have an appropriate use case.


The end user organisation acceptable use policy (EUO AUP)

The end user organisation acceptable use policy (EUO AUP) explains the responsibilities, obligations, and terms of use for every end user organisation. This may be updated from time to time. The latest copy is published below.

The connecting party shall incorporate or otherwise alert the end user organisations to the end user organisation AUP as updated and published on this web page.

If you are an end user organisation and have any questions about this End User Organisation AUP, email: [email protected].


Connection agreement

Entering into a connection agreement

As part of our ongoing efforts to improve our service and streamline our processes, we have moved to a fully digital system for managing connection agreements effective from 1 August 2025. This supported by our ServiceNow customer portal.

Signatures have been replaced with an acceptance state of 'Active' and date 'Accepted on' and will contain the registered onboarding contact name who has accepted the terms and conditions under 'Accepted by'.  

You must have a registered account to view your connection agreement through the customer portal. If you do not currently have access to the portal, please use the self-registration link to create an account and gain access. Or read our customer portal account guidance for more information on how to use the portal if you have registered. 

To accept a connection agreement, you must be registered as an 'Onboarding Contact'. This can be done by completing the Supplier Onboarding Contact Nomination Form, available on the customer portal by searching for 'Supplier Onboarding Contact Nomination Form'.

NHS England will normally assign the 'Onboarding Contact' responsibility to the authorised signatory contacts provided during onboarding. However, this form can also be used to nominate additional contacts who require access to view and accept connection agreements on behalf of your organisation.

Once the form has been submitted, the nominated user will automatically be assigned the 'Onboarding Contact' responsibility without requiring any further approval.

When your connection agreement is ready, you will receive an email notification issued from [email protected] containing a link to the customer portal. 

Further guidance can be found in the user guide for acceptance of a digitised connection agreement through the ServiceNow customer portal.

Current version of the Connection Agreement 

This webpage serves as the 'Onboarding Web Page' as defined in the Connection Agreement. NHS England publishes on this page the current operative version of the Connection Agreement together with details of changes and their effective dates in accordance with clause 8 of the Connection Agreement.

Connection Agreement version published on 22 September 2026 and effective from 21 October 2026.

The connection agreement constitutes:

  • Standard Terms, applicable to all NHS England services
  • Appendix 1A - The End User Organisation Acceptable Use policy (EUO AUP) explains the responsibilities, obligations, and terms of use for every end user organisation. If you are an end user organisation developing software for your own use, this policy applies to your own organisation. You must note and share the contents of the End User Organisation Acceptable Use Policy (Appendix 1A,) with all your customers who will use your Product(s) to access any of NHS England Services. You will also need a business-as-usual process for sharing this Policy with new customers. A standalone copy of this Policy is available on this webpage above
  • Appendix 2A - Data Processing Special Terms. These data processing Special Terms apply where the Connecting Party is a Processor for and on behalf of NHS England as the Controller in respect of Personal Data it Processes pursuant to this Connection Agreement. This is not applicable to all NHSE services but will be clearly stated in the applicable Appendix 3
  • Appendix 3 – Service specific Special Terms. An appendix 3 (labelled 3A, 3B, 3C etc) applies to each NHS England service, detailing Data Protection Status (that is, if Appendix 2A applies) and any applicable Special Terms
  • All other documents and items referred to or linked from the Standard Terms or applicable Special Terms, whether by URL or otherwise, including but not limited to the Requirements and Conformance Documentation

Changes to the Connection Agreement 

Connection agreement activity that generates an email notification are:

  • new contract - contract awaiting acceptance containing new Services applicable or removal of some Services previously applicable due to offboarding
  • terms change - new contract version because terms have been updated
  • contract termination - due to offboarding of all Services previously applicable

Where reasonably practicable, NHS England will provide notice between publication and the effective date of a Change to the Connection Agreement. We publish a Change log giving details pursuant to clause 8.5 of Changes to the connection agreement. The publication date and effective date for each Change are set out in the published changes log.

We maintain copies of previous versions for reference purposes. Superseded versions are not effective once replaced by a subsequent version in accordance with clause 8. Copies are available on request.

If you have any questions about the published changes, contact [email protected]. 


Guidance on assurance and connection agreement requirements for middleware Integrations

The assurance and connection agreement requirements for a middleware integration depend on which organisation hosts the endpoint that connects directly to the NHS England API.

Scenario 1: Middleware supplier hosts the endpoint

Where a middleware supplier hosts and manages the endpoint connecting to the NHS England API, and customer organisations consume the middleware service without hosting their own endpoint:

A single SCAL/DOS onboarding submission is required.

A single Connection Agreement is required.

The middleware supplier is responsible for completing all onboarding and assurance requirements.

The middleware supplier must provide responses to all applicable onboarding questions, including those relating to data use, information governance, and security requirements.

These responsibilities cannot be delegated to customer organisations using the middleware service.

The onboarding submission should accurately reflect the intended use case at the time of onboarding. Any future changes to the service, data processing activities, or scope of use may require further review through the applicable NHS England change process.

Scenario 2: Customer organisation hosts its own endpoint

Where a customer organisation hosts its own endpoint and connects directly to the NHS England API, even when using middleware software or services:

The customer organisation must complete its own SCAL/DOS onboarding submission.

The customer organisation must meet all applicable assurance requirements, including any information governance, security, or technical controls relevant to the integration.

The customer organisation must enter into its own Connection Agreement with NHS England.

Additional considerations

Some assurance evidence produced by a middleware supplier may be relevant across multiple implementations. However, the extent to which existing evidence can be reused will be determined on a case-by-case basis as part of the onboarding and assurance process.

In particular, functional and non-functional testing requirements are assessed in the context of the specific NHS England API or service being accessed and the implementation model being used.

Further advice

If you are unsure which onboarding model applies to your implementation, contact the National service desk before progressing with your onboarding request.

Tel: 0300 303 5035

Email: [email protected] 

Early engagement helps ensure the correct assurance and contractual requirements are in place from the start.

Last edited: 6 October 2026 1:07 pm