What a patient should have to prove before you show them a calendar
Ask a new patient to photograph a passport and record a video of their own face before you will show them an appointment calendar, and you have put a price on booking. Some of them close the tab and ring the surgery instead.
Patient identity verification is one of the few parts of onboarding where the product team decides how much to ask for. That decision usually gets made once and applied to everybody at the front door.
The NHS worked this out in public and published the answer. Ask for the least that will do for what the person is actually doing, and step up when they reach for more.
On NHS services in England, through NHS login, which has three verification levels. P0 confirms an email address and a phone number. P5 checks the details a patient gives against a Personal Demographics Service record. P9 compares the person against a photographic identity document. A private service that charges patients runs its own equivalent, sized to the action.
NHS login launched in September 2018 and had over 46 million users as at 11 June 2026. NHS England Digital’s integration toolkit states that “NHS login supports three levels of identity verification”.
Low, P0, is where “the user has verified ownership of an email address and mobile phone or landline number”. Medium, P5, is where the user has provided information “which has been checked to correspond to a record on the NHS Personal Demographics Service (PDS)”. High, P9, is where “physical comparison between the photographic identity and the person asserting their identity has occurred”.
NHS England Digital gives integrators a worked example. “Reading generic condition information may only require a P0, whereas viewing a medical record to order a repeat prescription will require a P9.” The instruction to integrators is plain: “You should not ask for more information than you need”, and a service “should request the lowest level of acceptable identity verification within the VoT set”. VoT is the Vector of Trust, the combination of verification level and authentication level a service asks for.
A service must meet all four of NHS England Digital’s criteria to apply. It has to serve patients registered at a GP practice in England or receiving NHS services in England, offer a health or social care benefit, be free to the patient at the point of delivery apart from NHS levied charges, and be commissioned or sponsored by an NHS organisation or local authority. A framework agreement “does not count as a commission or sponsorship”.
A privately funded service that charges the patient therefore builds its own patient identity verification. The published levels remain the best available template.
|
What the patient is trying to do |
Proof that is proportionate |
Source |
|---|---|---|
|
Read general health information, use a symptom checker, find a service |
No identity at all. An account is not needed. |
NHS, “Proving who you are to get full access”, reviewed 10 February 2026. NHS England Digital, Discovery, 24 June 2026 |
|
Create an account and receive messages |
Verified control of an email address and a mobile or landline number. NHS login calls this P0. |
NHS England Digital, “How NHS login works”, 3 February 2026 |
|
Contact a GP, receive notifications, use basic features tied to a real patient record |
Demographic details matched to a record on the Personal Demographics Service. NHS login calls this P5. It needs no document and no face comparison. |
“How NHS login works”, 3 February 2026. “Patient verification levels and proving identity”, 2 October 2025 |
|
View a health record, see test results, order a repeat prescription |
Identity proved to high level, with a comparison between the person and a photographic identity document or an equivalent NHS route. NHS login calls this P9. |
Discovery, 24 June 2026. “Introduction to Vectors of Trust” |
|
Reach that same high level without a passport or driving licence |
GP surgery online services registration details, used once, in England. Or the fast-track ID check route (IDVM). |
NHS login Help centre, “What to do if you do not have photo ID”. “How NHS login works”, 3 February 2026 |
|
Get online access as a patient the practice already knows |
Vouching by a member of staff who knows the patient, recorded with the name of the person vouching, the method and the date. Or confirmation against information already in the patient’s record. This is NHS England guidance for GP practices in England, not for private telehealth. |
NHS England, “Identity verification”, long read, updated 11 March 2025 |
|
Prove only that you are over 18, with no record access |
Age assurance rather than identity. Ofcom names seven methods capable of being highly effective and rules out self-declaration. |
Ofcom, “Age checks to protect children online”, 16 January 2025 |
|
Have a remote consultation where a prescription may follow |
An identity check adequate to the safeguards the service needs, with the clinician able to raise concerns where the system does not provide them. |
“High level principles for good practice in remote consultations and prescribing”, 8 November 2019, Principle 1 |
|
Decide what to ask for in the first place |
The lowest level that fits the action, escalated only when the patient reaches for something that needs more. |
“How NHS login works”, 3 February 2026. Developer documentation on offering P5 and P9. GPG45, 14 November 2024 |
The Personal Demographics Service is “the national master database of all NHS patients in England, Wales and the Isle of Man”. A match against it confirms that the details entered correspond to a real patient record. It does not confirm that the person entering them is that patient.
NHS login separates the two, which is why P5 sits below record access. P5 “does not provide access to health records or personal information”. Record access waits for P9 and the physical comparison. A product that treats an NHS number match as patient identity verification has confused a lookup with a check.
NHS England Digital documents the pattern for staging patient identity verification. A service “can only offer basic features to users with medium level verification (P5) at their initial login”. When that user goes for a feature backed by sensitive data, “the service then requires high verification and high authentication. The service prompts the user to undertake a verification step-up journey.”
For a product team that is a sequencing decision. Registration asks for what registration needs. The document capture and the face comparison arrive when someone is trying to see a result or order a repeat, at the point where they have a reason to finish. GPG45 allows the staging: “You do not have to do all parts of the identity checking process at once.”
Write down which action sits at which level and why. A data protection impact assessment will ask for exactly that.
No published UK figure measures how many patients abandon at the identity step. A 2023 study in the British Journal of General Practice found NHS App registrations were 25 per cent lower in the most deprived practices and 36 per cent higher in practices with the highest proportion of registered White patients, across data from January 2019 to May 2021. The study measured registration, not the identity step specifically.
NHS England’s inclusive digital healthcare framework, updated 1 March 2024, records that around 10 million adults lack foundation-level digital skills. The NHS designed around that. NHS login publishes a route in England for patients with no photo ID, using registration details from a GP surgery’s online services, and NHS England’s guidance of 11 March 2025 accepts vouching by a member of staff who knows the patient. Both are written for NHS services in England rather than for private providers. Restricting sign-up to a passport or a driving licence turns away the patients those routes were built for.
The data protection cost lands on the same decision. Article 9(1) of the UK GDPR places “data concerning health” and “biometric data for the purpose of uniquely identifying a natural person” in the same special category regime. A digital health service holds health data by definition. Adding a face comparison at sign-up creates a second special category dataset covering every patient, including the ones who only wanted an appointment. Article 5(1)(c) requires personal data to be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed”.
Regulation 12 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires that “care and treatment must be provided in a safe way for service users”, including “assessing the risks to the health and safety of service users of receiving the care or treatment” and “doing all that is reasonably practicable to mitigate any such risks”. It applies in England, and it names no identity method and no confidence level. The level follows the risk assessment, and the assessment has to exist on paper.
Principle 1 of the 2019 high level principles for remote consultations and prescribing, endorsed by the Care Quality Commission, the General Medical Council and twelve other bodies, asks clinicians to raise concerns where a service “does not have adequate patient safeguards including appropriate identity and verification checks”. Signatories include Healthcare Improvement Scotland, Healthcare Inspectorate Wales and the Regulation and Quality Improvement Authority, so it holds across the four nations.
GPG45, updated 14 November 2024, is the government’s method for choosing a level of confidence and evidencing the choice. It does not set levels by sector, and no law or regulator names a GPG45 level that an online health service must reach. No published mapping between GPG45 levels of confidence and NHS login verification levels could be found, so evidence each on its own terms.
DAPB3051, the Identity Verification and Authentication Standard for health and care, reached version 3.1 on 23 December 2025. It applies, in its own words, to “any NHS or non-NHS provider, organisation, company, or authority that provides individuals with access to digital, data, analytics and technologies for health or care services”, and sets a full conformance date of 31 December 2026.
It is published under section 250 of the Health and Social Care Act 2012 and states that persons subject to it must have due regard to it where it is relevant. Section 250 has since been amended so that mandatory information standards carry a duty to comply rather than a duty to have regard, and providers should check the standard’s current designation. NHS England Digital’s developer documentation maps P5 to medium verification and P9 to high verification within DAPB3051.
An age check confirms that someone is over a threshold, a narrower question than establishing who they are. Ofcom’s guidance of 16 January 2025 names seven methods capable of being highly effective and rules out self-declaration. Online pharmacy and prescribing services carry further rules, covered in the piece on age and identity checks when selling medicines online.
Staged verification is easier to run when the first check and the stronger one sit with the same supplier. Where the higher-level check means a second contract, the heaviest check tends to end up at the front door for everybody.
OneID runs several identity methods behind one integration. Those methods include bank-verified checks, international electronic identity schemes, digital wallets and document scanning, orchestrated with fallback so that a patient who cannot complete one route is offered another rather than dropped. OneID’s own figure for a bank-verified check is under 12 seconds. A service can therefore begin with a low-friction check and keep a heavier one in reserve without a second procurement.
OneID is listed on the public Digital Verification Services register as service ID 286, certified 12 June 2026 and valid to 21 June 2029. Certification is granted per check service, so confirm which service covers your use case. OneID supplies the verified identity. The risk assessment and the decision about which action sits at which level stay with the provider.
List every action your service offers, put each one at the lowest level that fits it, write down the reasoning, and test that the step-up path works without making the patient start again. That is patient identity verification sized to the job, and it is the version a clinical governance lead will sign off.
Can a private telehealth service use NHS login? Most cannot. NHS England Digital sets four conditions and an applicant has to meet every one, including free delivery to the patient and commissioning or sponsorship by an NHS organisation or a local authority. A framework agreement does not count. A subscription telehealth service funded by patient fees will fail on those two conditions and needs its own verification.
Is checking someone’s NHS number the same as verifying their identity? No. The Personal Demographics Service is a record lookup. A successful match shows only that the information supplied belongs to a real patient. Proof that the person at the keyboard is that patient needs a separate step, which is why NHS login caps its medium level, P5, below health record access.
What can a patient do without proving who they are? NHS App guidance for England, reviewed on 10 February 2026, says a person can use NHS 111 online and the NHS website, and find NHS services near them, without proving identity. Requesting repeat prescriptions and seeing test results require identity to be proved first.
Do we have to reach a particular GPG45 level of confidence? No. Nothing in health regulation names a level of confidence you have to hit. GPG45, updated 14 November 2024, gives you four levels and a method for choosing between them according to how exposed your service is to identity-related crime. Your own risk assessment produces the answer, and an auditor will ask to see it.
What happens to a patient with no passport or driving licence? In England, an NHS login account can be set up with three registration details issued by the patient’s GP surgery online services, and those details work once. NHS England’s guidance for GP practices also allows a member of staff who knows the patient to vouch for them, with the vouching recorded. Publish an equivalent route or you will turn people away.
When does DAPB3051 apply to us? The standard’s stated scope is “any NHS or non-NHS provider, organisation, company, or authority that provides individuals with access to digital, data, analytics and technologies for health or care services”. A private telehealth service sits inside that. Version 3.1 was implemented on 23 December 2025, with full conformance due on 31 December 2026. Its own page states a duty to have due regard.
The check that stops your bank nurse starting on Saturday
The staff you did not recruit are the ones you cannot evidence
Which age check are you actually asking your users to do?