Patient Audit Record Service (PARS)
A central service for recording, validating, storing and retrieving information about access to patient-related data.
Private beta
The Patient Audit Record Service (PARS) is currently in private beta.
We are onboarding services on a controlled, case-by-case basis while we test the service with real audit data and improve the onboarding, reporting and operational experience.
To discuss whether PARS is suitable for your service, email: [email protected].
About this service
PARS is a central service for recording, validating, storing and retrieving information about access to patient-related data.
Services submit structured patient access audit events to PARS. Approved users and services can then retrieve and query those events to support information governance, privacy, security, compliance and operational investigations.
PARS is intended to provide a consistent and reusable approach to patient access auditing, rather than each service creating its own audit store, data model and reporting capability.
Why would I use PARS?
If your service interacts with patient data, there is a legal obligation to maintain an audit trail of the interactions. PARS provides a centralised audit capability that services can use instead of developing their own audit store and reporting solution.
What PARS does not do
PARS does not:
- store the patient’s clinical record
- decide whether access to patient information was appropriate
- replace local information governance responsibilities
- automatically investigate suspicious access
- provide unrestricted access to patient audit information
- guarantee that incomplete source audit data can be reconstructed
- provide a patient-facing NHS App experience during private beta
Who this service is for
PARS is for NHS England services and other approved health and care organisations that need to:
- record access to patient-related data
- need a consistent way to store and retrieve patient access audit information
- investigate how patient data has been accessed
- support information governance, privacy, security and compliance activities
- need to produce reports based on patient access audit data
Typical users may include:
- information governance teams
- privacy and data protection teams
- cyber security and operational investigation teams
- service owners and technical teams responsible for systems that access patient data
- teams responding to Subject Access Requests and other access-related enquiries
Access to PARS is subject to onboarding, assurance and approval.
How to access this service
PARS is available through controlled private beta onboarding.
Contact the PARS team to discuss:
- whether your service is eligible
- technical integration
- audit-event requirements
- onboarding and assurance
- access to audit information
- reporting requirements
- documentation feedback
Email: [email protected]
More detailed technical guidance will be provided as part of onboarding.
How it works
1. A service creates an audit event
A service that performs an action involving patient-related data creates a structured FHIR AuditEvent.
The event should include enough information to explain:
- who performed or requested the action
- which organisation and system were involved
- which patient record was accessed
- what interaction took place
- when the action occurred
- how the event can be traced to the originating transaction
Services should create audit events at the point where the relevant action occurs.
Where several systems take part in processing a request, each system may need to record its own part of the interaction.
2. PARS validates the event
PARS checks the event against the agreed technical profile and business rules.
Events that do not meet the required standard may be rejected and returned to the submitting service for correction.
3. PARS stores the event
Accepted events are stored in the PARS structured audit datastore.
The information is retained in line with agreed retention, security and information-governance requirements.
4. Approved users retrieve audit information
Approved users and services can retrieve audit information through supported reporting and query mechanisms.
Access is restricted according to:
- the organisation
- the user or service
- the approved purpose
- the relevant dataset
- the agreed access-control model
5. The requesting organisation interprets the evidence
PARS provides the audit evidence.
The organisation using the information remains responsible for:
- deciding whether access was appropriate
- interpreting the results
- responding to an investigation or request
- taking any governance, security, disciplinary or operational action
Examples of use
Record patient access events
Services can submit structured audit events when a user, organisation or system performs an action involving patient-related data.
An audit event can record information such as:
- what action took place
- when it happened
- which patient record was involved
- who or which organisation initiated the action
- which service or system processed it
- the transaction or request identifier
- the interaction or endpoint used
Subject access requests
PARS can provide audit information to support Subject Access Requests, where an individual asks what information an organisation holds about them and how their information has been accessed.
User access requests
PARS can support checks into whether users are accessing patient information appropriately and in connection with their work.
This may include reviewing access:
- by a particular user
- during a defined period
- to a particular patient record
- linked to a team, organisation or work list
Organisation access reports
PARS can support reporting that helps organisations understand when another organisation last accessed a patient record. Reports may be based on an agreed list of product or interaction identifiers.
Governance, privacy and security investigations
PARS can provide evidence to support investigations into:
- inappropriate or unexpected access
- privacy complaints
- suspected data breaches
- security incidents
- operational incidents
- clinical incidents involving access to data
- access by particular organisations, users or systems
Ad hoc audit queries
Where approved, services can query structured audit data using SQL-on-FHIR. This can support more flexible analysis where a standard report does not meet the investigation or reporting need.
National usage policy
This service is strongly recommended for all audit capabilities and services that support NHS England.
We are working on an approach for other internal NHS services, particularly core services, where there is also considerable demand for using the service as their audit capability.
PARS principles
Audit by design
Services should consider patient access auditing as part of their design and delivery, rather than adding it after the service has gone live.
Consistent and structured audit data
Audit events should use an agreed structure and common definitions so that information can be reliably stored, understood, queried and reported.
Record actions where they occur
Each service involved in accessing or processing patient-related data is responsible for recording the actions it performs.
A service should not assume that another system will create a complete audit trail on its behalf.
Sufficient context
Audit events should contain enough information to understand:
- the patient involved
- the requester
- the organisation
- the system
- the interaction
- the transaction
- the outcome
Appropriate access
Patient access audit data may itself be sensitive. Access must be limited to authorised users, approved services and legitimate purposes.
Clear accountability
PARS is responsible for validating, storing and making audit information available. Submitting services remain responsible for the accuracy, completeness and timeliness of the audit events they provide.
Traceability
Audit events should support investigation from the original interaction through to the relevant user, organisation, service and patient record.
Reuse before building
Services should reuse the PARS audit standard, repository and reporting capability where it meets their need, rather than creating separate audit solutions.
Proportionate retention
Audit information should only be retained for an agreed period that meets legal, regulatory, operational and service requirements.
Continuous improvement
During private beta, evidence from onboarding, reporting and operational investigations will be used to improve the service, data model and guidance.
Roadmap
Find out what we're working on now and what we plan to do in the future:
- Complete the migration of agreed RIAK and Spine audit data into PARS.
- Validate the completeness and accuracy of migrated data.
- Provide priority query capability equivalent to existing Spine Reporting Service needs.
- Continue controlled onboarding of services.
- Improve the PARS FHIR AuditEvent profile and validation rules.
- Continue discovery into operational audit and investigation needs.
- Establish an organisational standard for patient access audit data.
- Create a reporting service that meets common organisational reporting needs.
- Develop reusable reports for Subject Access Requests, user access checks and organisation access reporting.
- Improve technical guidance and onboarding documentation.
- Reduce the amount of manual support required to onboard a service.
- Develop clearer data-quality reporting for submitting services.
- Explore how appropriate patient access audit information could be presented through the NHS App.
- Enable suitable services to self-onboard to production with minimal support from the PARS team.
- Expand the range of reusable organisational reports.
- Explore proactive identification of unusual or potentially inappropriate access patterns.
Status, service level and current usage
PARS is currently in private beta.
PARS is provided as a bronze service.
This includes:
- platform availability 24 hours a day, 7 days a week
- support Monday to Friday, 8am to 6pm
- no standard support coverage on bank holidays
Platform availability does not mean that support requests, reporting requests or onboarding queries will be handled outside the stated support hours.
PARS will become a platinum service in later phases to support more services and operationally critical use cases.
Reporting vulnerabilities and security concerns
To report a vulnerability or security concern, contact: [email protected].
Do not publicly disclose a potential vulnerability until the PARS development and security teams have had an opportunity to assess and address it.
For a live service incident, contact the National Service Desk.
Contact us
|
Enquiry |
Contact |
|---|---|
| Live service incident |
National Service Desk Email: [email protected] Report via our customer portal Telephone: 0300 303 5035 |
|
General enquiries and onboarding |
Email: [email protected] |
|
Strategic direction and escalations |
Shan Rahulan Email: [email protected] |
Last edited: 13 August 2026 3:29 pm