Online accounts, messaging and digital identity risks

Digital routes introduce new identity risks. Online forms, SMS, email, app messages and proxy profiles can make access easier, but they can also send information to the wrong person or expose sensitive details when someone else controls the account or device.
Check the route as well as the person
When a request arrives digitally, staff may assume the identity has already been checked. That assumption may not be sufficient. The practice must confirm the request matches the patient record, that the message route is secure, and whether the requested action requires further verification.
Digital identity can change over time. Phone numbers, email addresses, proxy users and app permissions may be out of date. Patients may have separated from a partner, lost a phone, changed carers or be concerned that someone is monitoring their messages.
Digital checks to consider
- Does the message match the correct patient record?
- Is the phone number or email already verified in the practice system?
- Is the request sensitive enough to need stronger checks?
- Could a proxy, parent, partner or shared account be involved?
- Are there safe-contact or safeguarding notes before replying?
Patient Online: Safe access to online GP records
A digital message is not automatically safe just because it appears to come from the patient.

