openapi: 3.0.0 info: title: gp-connect-access-record-structured-fhir Appointment Patient API version: Computed and injected at build time by `scripts/set_version.py` description: "## Overview\nUse this API to access structured information from a patient's registered GP practice record. Structured information is patient data in a coded format that a consuming system can import and process.\n\nThe API accesses GP principal supplier systems, provides a consistent interface and data model, and is brokered through [Spine](https://digital.nhs.uk/services/spine). Refer to [Spine terminology](https://digital.nhs.uk/developer/api-catalogue/gp-connect-general-pages/spine-terminology), used throughout these pages, for further details.\n\n![GP Connect Ecosystem Overview](https://raw.githubusercontent.com/NHSDigital/gp-connect-access-record-structured-fhir/master/specification/images/gpconnect-ecosystem.svg)\n\nYou can retrieve data from GP practice records for the following areas:\n\n- medications\n- allergies\n\nData is available for the following clinical areas:\n\n- immunizations\n- consultations\n- problems\n- investigations\n- outbound referrals\n- diary entries\n- uncategorised data (other clinically coded items that are present in the record)\n\nThese clinical areas are still in development; there is enough data to test, but it is subject to change as GP systems suppliers go through the development process.\n\nIt does not include:\n\n- extended demographics information - for example, about carers\n- flags and alerts\n- templates\n- test requests\n\nCommon use cases include:\n\n- access GP medications on admission to secondary care, reducing transcription errors\n- active checking of a patient's prescription in unscheduled care\n- out-of-hours GP accesses patient's medications, allergies and problems\n- midwife views patient record before visiting a patient\n- community cardiac nurse accesses GP record before visiting a patient\n\n\nFor more details, see the [GP Connect Access Record: Structured specification](https://developer.nhs.uk/apis/gpconnect-1-5-1/accessrecord_structured.html), and for a description of terms and standards used in this guide, please see the [General API Guidance page](https://digital.nhs.uk/developer/api-catalogue/gp-connect-general-pages/general-api-guidance).\n\nYou cannot currently use this API to:\n\n- create patient-facing views of a medical record\n- create reports for secondary use, such as care planning\n- write back to the GP record\n\n\n### Retrieving documents\n\nTo retrieve documents from a patient's registered GP practice, use [GP Connect Access Document - FHIR API](https://digital.nhs.uk/developer/api-catalogue/gp-connect-access-document-fhir). After you've found the relevant document references within Access Record returns, use GP Connect Access Document to retrieve the documents. All documents can be requested separately.\n\n\n## Who can use this API\nThis API can be used by developers of clinical systems that support clinicians delivering direct care.\n\nBefore you start development, read the [GP Connect API 1.5.1-beta](https://developer.nhs.uk/apis/gpconnect-1-5-1/) specification and the prerequisites listed below. \n\nBecome an API consumer\nIf you're planning on consuming data using GP Connect APIs then you're a consumer system.\n\nBecome an API provider\nIf you're planning on providing data using GP Connect APIs then you're a provider system.\n\n### Prerequisites\n#### Technical\nThe technical prerequisites are as follows:\n\n- you must have access to the [Health and Social Care Network (HSCN)](https://digital.nhs.uk/services/health-and-social-care-network)\n- you must be [Personal Demographics Service (PDS)](https://digital.nhs.uk/Demographics)-compliant or capable of performing a PDS search via NHS Digital or a third-party provider\n#### Information governance (IG)\nThe IG prerequisites are as follows:\n\n- your organisation must be compliant with the [GP Connect Direct Care API Information Governance Model](https://github.com/nhsconnect/gpc-consumer-support/wiki/Information-Governance-(IG))\n- you must manage access to your system locally using local role-based access control (RBAC) (this does not need to be compliant with the national RBAC model and GP Connect products do not require smartcards to control access, though they can be used if already implemented)\n\n- the GP Connect APIs are for direct care purposes for NHS patients in England\n### Clinical safety\nThe clinical safety prerequisites are as follows:\n\n- you must have a clinical safety officer (CSO) who is responsible for [DCB0129](https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections/dcb0129-clinical-risk-management-its-application-in-the-manufacture-of-health-it-systems) and, if necessary, [DCB0160](https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections/dcb0160-clinical-risk-management-its-application-in-the-deployment-and-use-of-health-it-systems) (for more on clinical risk management, visit [Clinical risk management standards](https://digital.nhs.uk/services/clinical-safety/clinical-risk-management-standards))\nIf you are confident that you can meet the prerequisites, please express an interest with the GP Connect team (see 'Onboarding' below).\n\n## Related APIs\nThe following APIs are also related to this API:\n\n- GP Connect Access Document - FHIR API - use this API to retrieve unstructured documents from a patient's GP practice record\n- Personal Demographics Service - FHIR API - use this API to search for patients, retrieve patients by NHS number and update patients\n- Personal Demographics Service - HL7 V3 API - use this if you want to use functions that are not yet available on the FHIR API\n- Spine Directory Service (SDS) - FHIR API - access accredited system information and messaging endpoint details\n\n## Integration with Spine\nFor guidance on how to integrate with the Spine systems required to use this API, please see the [integrate with spine](https://digital.nhs.uk/developer/api-catalogue/gp-connect-general-pages/spine-integration) page.\n\nFor guidance on querying and using the Spine Directory Service (SDS) [please see the Spine Directory Service page](https://digital.nhs.uk/developer/api-catalogue/gp-connect-general-pages/spine-directory-service).\n## API status and roadmap\nThe current working version is 1.5.1. The API status is:\n\n- in production (out of beta) for medications and allergies - there will be no breaking changes\n- in production, beta for other aspects of the clinical record - there might be breaking changes, but we will let you know in advance\nIt may not be fully supported by all providing systems. See [GP Connect supplier progress](https://digital.nhs.uk/services/gp-connect/supplier-progress) for details of provider rollout.\n\nThe previous version ([1.5.0](https://developer.nhs.uk/apis/gpconnect-1-5-0/)) does not include the ability to access deceased patients' documents, but is available for system suppliers who have started to develop against it.\n\nRoadmap\n\nThe next planned version is [1.6.0](https://developer.nhs.uk/apis/gpconnect-1-6-0/), which is currently [in production, beta](http://digital.nhs.uk/developer/guides-and-documentation/reference-guide#statuses). The 1.6.0 specification contains the full scope of 1.5.1, but additionally it introduces a new message to support GP2GP transactions. It is important to understand that the GP2GP transactions do not affect the consumer build. 1.6.0 will be backward compatible with the 1.5.1 specification.\n## Service level\nThis API is a silver service, meaning it is operational 24 hours a day, 365 days a year but only supported during business hours (8am to 6pm), Monday to Friday excluding bank holidays.\n\nFor more details, see [service levels](https://digital.nhs.uk/developer/guides-and-documentation/reference-guide#service-levels).\n## Technology\nThis is a synchronous API. It conforms to the [FHIR](https://digital.nhs.uk/developer/guides-and-documentation/api-technologies-at-nhs-digital#fhir) global standard for health care data exchange. Specifically, it is aligned with [FHIR UK Core](https://digital.nhs.uk/services/fhir-uk-core), which is built on FHIR Release 3. \n\nIt uses a FHIR Operation that requires you to make a HTTP POST of a FHIR Parameters resource to the provider endpoint. The resource contains parameters that correspond to the requested clinical information - for example, medications, allergies or problems.\n\nWe use this approach instead of a resource-based RESTful API in the interests of clinical safety. The provider system constructs a response that contains all clinical information relating to the request to ensure that the clinical information is interpreted safely.\n\n\n## Network access\nYou can access this API via the [Health and Social Care Network (HSCN)](https://digital.nhs.uk/services/health-and-social-care-network).\n\nThe API is not currently available over the internet, but we plan to enable public internet access in the future.\n\nFor more details, see [Network access for APIs](https://digital.nhs.uk/developer/guides-and-documentation/network-access-for-apis).\n## Security and authorisation\n### Security\nAccess to the GP Connect APIs is controlled and protected by the [Spine Secure Proxy (SSP)](https://digital.nhs.uk/developer/guides-and-documentation/api-technologies-at-nhs-digital#spine-security-proxy-ssp-), a forward HTTP proxy.\n\nIt provides a single security point for both authentication and authorisation for consuming systems. Additional responsibilities include auditing of requests, checking data sharing agreements and transaction logging, and its use and examples are described at the [Spine Secure Proxy page](https://digital.nhs.uk/developer/api-catalogue/gp-connect-general-pages/spine-secure-proxy).\n\nFor a breakdown of cross-organisation audit and provenance, please see the related page [here](https://digital.nhs.uk/developer/api-catalogue/gp-connect-general-pages/cross-organisation-audit-and-provenance).\n\nAll HTTP communications are secured using TLS MA. This includes both legs of the request, from consumer system to the proxy and then from the proxy to provider system.\n\n### Authorisation\nAuthorisation takes place in two locations: \n\n- the consumer system\n- the SSP\nThe consumer system must have local RBAC in place and restrict GP Connect APIs to authorised users. With each request, a JSON Web Token (JWT) must be included with the following information:\n\n- details of users, including role\n- where smartcards are used in the consumer system, including SDS user and role IDs\n- details of the consumer system\n- details of the consumer's organisation, including ODS code\nThe information in the JWT is retained for audit purposes.\n\nProvider systems:\n- SHALL only accept connections from the [Spine Secure Proxy](https://developer.nhs.uk/apis/gpconnect-1-5-0/integration_spine_secure_proxy.html) (SSP)\n- SHALL authenticate the SSP prior to responding to any requests using its [client certificate](https://developer.nhs.uk/apis/gpconnect-1-5-0/development_api_security_guidance.html#client-certificates-tlsma)\n- SHALL only accept encrypted connections and drop connection attempts presented over insecure protocols\n- SHALL only accept requests for its allocated address space identifier (ASID), as specified by the Ssp-To header on its matching endpoint URL\n- SHALL check that the Ssp-InteractionID value is consistent with the endpoint being requested\n- SHALL check for the presence of all [SSP headers](https://developer.nhs.uk/apis/spine-core-1-0/ssp_implementation_guide.html#consumer)\n- SHALL check that an [authorization bearer token](https://developer.nhs.uk/apis/gpconnect-1-5-0/integration_cross_organisation_audit_and_provenance.html#json-web-tokens-jwt) is present and correctly formed\n- MAY authorise access to API endpoints through examining acceptable values in the JSON Web Tokens (JWT) requested_scope claim\n- SHALL risk-manage the security of the endpoints of the Transport Layer Security (TLS) communications, so as to prevent inappropriate risks (for example, audit logging of the GET parameters into an unprotected audit log)\n\nProvider systems should support only the following ciphers, ordered by preference (that is, the first item being the most preferred):\n- AESGCM+EECDH\n- AESGCM+EDH\n- AES256+EECDH\n- AES256+EDH\n\nThe SSP checks data-sharing agreements to ensure that the consumer system is authorised to communicate with the provider system.\n\nMore details of both the ciphers and TLS approach, as well as headers and certificates, can be found on the [Security page](https://digital.nhs.uk/developer/api-catalogue/gp-connect-general-pages/security).\n\n## Error Handling\nA full breakdown of errors, including examples, can be found on the [Error Handling page](https://digital.nhs.uk/developer/api-catalogue/gp-connect-general-pages/error-handling).\n\n## Environments and testing\n| Environment\t | URL |\n| ----------- | --- |\n| Internet-facing demonstrator | \t[https://orange.testlab.nhs.uk/](https://orange.testlab.nhs.uk/) |\n| OpenTest environment\t | [https://orange.testlab.nhs.uk/opentest.html](https://orange.testlab.nhs.uk/opentest.html) |\n| Integration | (INT)\tProvided during onboarding process |\nWe have 2 testing streams:\n\n- clinical testing\n- technical testing\nEach stream is complicated in its own right and we've designed them to run in parallel to help you to work with us more easily and to consider your system design in a holistic way, rather than having to complete one stream before the other.\n\n### Clinical testing\nThe aim of clinical testing is to ensure the safe interoperability of information exported from GP systems and then processed or displayed in a consuming system. \n\nTo help you test that your consuming system is clinically safe, we have created the following resources:\n\n- a patient record or, for some more complex areas, 2 records that can be requested from the GP Connect demonstrator\n- a description of each of the data items, what it is intending to test and the hazards that it is intended to mitigate\n- notes and guidance about each clinical area that describe how to process and display the data that it contains in a safe way\nSee [Clinical test data](https://digital.nhs.uk/developer/api-catalogue/gp-connect-access-record-structured-fhir/clinical-test-data).\n\n### Technical testing\nThe purpose of technical testing is to help you assure the messaging capability of your system via the Spine with GP Connect provider FHIR endpoints. It ensures the consumer requests conform to FHIR standards as per the specification. In addition, it maintains the integrity of the data displayed to the user and assures pertinent functional requirements. It does not assure the message payload, which is covered in clinical assurance.\n\nAn automated provider test harness has been made publicly available to allow standardised testing of the FHIR® APIs prior to any formal assurance activities being undertaken. This approach aims to streamline the end-to-end assurance process by ensuring that a common baseline level of technical conformance has been achieved and, thus, fewer issues are surfaced during formal assurance.\n\nDownload the [GP Connect automated test suite for API providers](https://github.com/nhsconnect/gpconnect-provider-testing) to help validate the technical conformance of your provider API implementation.\n\nSee [Consumer Supplier Test Assurance for achieving Technical Conformance](https://github.com/nhsconnect/gpc-consumer-support/wiki/Document-library#consumer-supplier-test-assurance-for-achieving-technical-conformance) (PDF) for full details of the technical conformance process and relevant artefacts.\n## Onboarding\nExpressing an interest\nIf you meet the prerequisites and have a product that can integrate with GP Connect, you should express an interest with us by submitting a use case.\n\nThe main purpose of the use case is to help us understand how you plan to use GP Connect APIs and the business issue you are looking to address. You should email your use case to the [GP Connect team](mailto:gpconnect@nhs.net).\n\nYour use case should include the following information as a minimum:\n\n- the business problem you are intending to solve using GP Connect\n- how GP Connect will be used in practice to benefit patients and staff\n- which of the GP Connect products you will use to benefit patients and staff\n- any end-user organisations you are currently working with\n- who your clinical safety officer is and, where available, your clinical risk management process documentation\nOnce we receive your use case, we'll respond within 14 days.\n\nConsumer assurance process\nOn approval of a use case, we will support you through the assurance process through to go live. We will discuss the [assurance process](https://github.com/nhsconnect/gpc-consumer-support/wiki/Assurance-Process-Overview) and artefacts with you to help you understand the requirements.\n\n![Access Record Structured Consumer Assurance Process](https://raw.githubusercontent.com/NHSDigital/gp-connect-access-record-structured-fhir/master/specification/images/access-record-structured-consumer-assurance-process.svg)\n\nStart your development work within 6 months of use case approval. If you miss this date, a review or new submission of the use case will be required. Changes or additional development will also require a review or new use case submission. For full details of the technical conformance process, see [GP Connect Consumer Supplier Test Assurance for achieving Technical Conformance](https://github.com/nhsconnect/gpc-consumer-support/wiki/Document-library#consumer-supplier-test-assurance-for-achieving-technical-conformance) (PDF).\n\nClinical assurance process\nWe are here to support you to develop clinically safe systems in line with your responsibility to achieve the relevant [DCB0129](https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections/dcb0129-clinical-risk-management-its-application-in-the-manufacture-of-health-it-systems) or [DCB0160](https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections/dcb0160-clinical-risk-management-its-application-in-the-deployment-and-use-of-health-it-systems) clinical safety standards. \n\n![Access Record Structured Clinicals Assurance Process](https://raw.githubusercontent.com/NHSDigital/gp-connect-access-record-structured-fhir/master/specification/images/gpc2-structured-consumer-clinical-assurance-process.svg)\n\nThe three stages of the clinical assurance process for GP Connect Access Record: Structured consumers\n\nWe host a series of meetings to help you develop clinically safe systems:\n\n- initial meeting\n- clinical safety process readiness review meeting\n- clinical evaluation of readiness for deployment meeting\nFor more information, see [Clinical assurance process details](https://digital.nhs.uk/developer/api-catalogue/gp-connect-access-record-structured-fhir/clinical-assurance-process-details).\n\n## Interactions\nFor a full list of interactions for this API, see [GP Connect Interaction IDs](https://digital.nhs.uk/developer/api-catalogue/gp-connect-general-pages/interaction-ids), which contains Access Record: Structured.\n\nFor details on the general structure of the interactions, see [FHIR](https://digital.nhs.uk/developer/guides-and-documentation/api-technologies-at-nhs-digital#fhir).\n \n## Additional guidance: Clinical safety and hazard log\n### Clinical safety approach\nYour organisation must have a clinical safety officer. Information standards underpin national healthcare initiatives from the Department of Health, NHS England, the Care Quality Commission, and other national health organisations. They provide the mechanism for introducing requirements to which the NHS, those with whom it commissions services and its IT system suppliers, must conform.\n\nThe following two standards relating to clinical safety are accepted for publication under section 250 of the Health and Social Care Act 2012 by the Data Coordination Board (DCB). In line with current DCB practice, each standard comprises:\n\n- a specification, which defines the requirements and conformance criteria to be met by the user of the standard - how these requirements are met is the responsibility of the user\n- implementation guidance, which provides an interpretation of the requirements and, where appropriate, defines possible approaches to achieving them\nCompliance with [DCB0129](https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections/dcb0129-clinical-risk-management-its-application-in-the-manufacture-of-health-it-systems) and [DCB0160](https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections/dcb0160-clinical-risk-management-its-application-in-the-deployment-and-use-of-health-it-systems) is mandatory under the Health and Social Care Act 2012 ([Clinical risk management standards - NHS Digital](https://digital.nhs.uk/services/clinical-safety/clinical-risk-management-standards)).\n\n### Clinical safety guidance \nThe [Guide for Access Record: Structured](https://github.com/nhsconnect/gpc-consumer-support/blob/master/Clinical%20Safety%20Officer%20Guidance%20for%20GP%20Connect%20V0.6%20Structured.pdf) helps clinical safety officers assure GP Connect consumer systems into their own organisations. It includes details of the clinical safety standards that consumer suppliers and their commissioning organisations must be compliant with ([DCB0129](https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections/dcb0129-clinical-risk-management-its-application-in-the-manufacture-of-health-it-systems) and [DCB0160](https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections/dcb0160-clinical-risk-management-its-application-in-the-deployment-and-use-of-health-it-systems)).\n\n[Clinical safety principles](https://github.com/nhsconnect/gpc-consumer-support/wiki/Clinical-Safety-Principles) shows you who is responsible for the clinical safety of GP Connect specifications and consumer systems.\n\n### Hazard log\nThe GP Connect Access Record: Structured generic [hazard log](http://github.com/nhsconnect/gpc-consumer-support/raw/master/test_data_files/GP_Connect_Hazard_Log_Consumers_v1.0.xlsx) shows you the clinical risks of using GP Connect functionality through a consumer system. Use it to identify the clinical risks of consuming clinical data and presenting it in your system, and record these in your own system-specific hazard log. If necessary, take mitigating action to ensure clinical safety.\n \n" contact: name: gp-connect-access-record-structured-fhir API Support url: https://simplifier.net/guide/gp-connect-access-record-structured/Home/Help-and-Support/Enquiries.page.md?version=current email: gpconnect@nhs.net tags: - name: Patient paths: /Patient/$gpc.getstructuredrecord: post: summary: Access a structured record relating to a patient. description: "## Overview \nThis end point returns a patient's record in structured format using FHIR Operations. It returns a Bundle.\nThe request body must be a Parameters resource.\n" parameters: - $ref: '#/components/parameters/ProviderASID' - $ref: '#/components/parameters/ConsumerASID' - $ref: '#/components/parameters/InteractionID' - $ref: '#/components/parameters/TraceID' requestBody: required: true description: Valid request for the entire record. content: application/fhir+json: schema: type: object description: 'TODO: Add in description with link to Simplifier ' example: resourceType: Parameters parameter: - name: patientNHSNumber valueIdentifier: system: https://fhir.nhs.uk/Id/nhs-number value: '9000000009' - name: includeAllergies part: - name: includeResolvedAllergies valueBoolean: true - name: includeMedication part: - name: includePrescriptionIssues valueBoolean: true - name: medicationSearchFromDate value: '2019-12-21' - name: includeConsultations part: - name: consultationSearchPeriod valuePeriod: start: '2019-12-21' end: '2020-02-21' - name: includeNumberOfMostRecent value: 5 - name: includeProblems part: - name: filterStatus valueCode: active - name: filterSignificance valueCode: major - name: includeImmunisations part: - name: includeNotGiven valueBoolean: true - name: includeStatus valueBoolean: true - name: includeUncategorisedData part: - name: uncategorisedDataSearchPeriod valuePeriod: start: '2019-12-21' end: '2020-02-21' - name: includeInvestigations part: - name: investigationSearchPeriod valuePeriod: start: '2019-12-21' end: '2020-02-21' - name: includeReferrals part: - name: referralSearchPeriod valuePeriod: start: '2019-12-21' end: '2020-02-21' - name: includeDiaryEntries part: - name: diaryEntriesSearchDate value: '2019-12-21' responses: '200': description: Returned with the response body which will be a [GPConnect-StructuredRecord-Bundle-1](https://fhir.nhs.uk/STU3/StructureDefinition/GPConnect-StructuredRecord-Bundle-1/_history/1.3) resource tags: - Patient /Patient/{id}/Appointment: get: summary: Read a patient's appointments description: Retrieve all appointments for the patient within a defined time-frame. parameters: - $ref: '#/components/parameters/BearerAuthorization' - $ref: '#/components/parameters/CorrelationID' - $ref: '#/components/parameters/RequestID' - name: id in: path description: The patient's NHS number. The primary identifier of a patient, unique within NHS England and Wales. Always 10 digits and must be a [valid NHS number](https://www.datadictionary.nhs.uk/attributes/nhs_number.html). required: true schema: type: string example: '9000000009' - name: start in: query description: Appointment start/end dates. Default values show a query for appointments on or after 2020-05-09 and on or before 2020-05-19. required: true style: form explode: true schema: type: array items: type: string default: - ge2020-05-09 - le2020-05-19 - in: query name: _include:recurse description: 'Appointment:actor:Practitioner Include Practitioner resources referenced in Appointment:actor Appointment:actor:Location Include Location resources referenced in Appointment:actor ' schema: type: array items: type: string enum: - Appointment:actor:Practitioner - Appointment:actor:Location - name: past-appt-limit in: query description: Number of past appointments to return in query, starting at the date given in the "le" portion of the start parameter and working backwards. Parameter is optional, if no value supplied then no limits are applied. required: false schema: type: string example: '5' - name: status in: query description: 'The type of status to search: you can find valid values [here](https://simplifier.net/packages/hl7.fhir.r4.core/4.0.1/files/83480) ' required: false schema: type: string example: proposed responses: 200: description: OK content: application/fhir+json: schema: type: object description: Link to Profile--GPConnect-Appointment-1 resource population guidance [here](https://simplifier.net/guide/gpconnect-data-model/Home/FHIR-Assets/All-assets/Profiles/Profile--GPConnect-Appointment-1?version=current). examples: example: $ref: components/examples/PatientAppointment.yaml 4XX: description: 'An error occurred as follows: | HTTP status | Error code | Description | | ----------- | ---------- | ----------- | | 400 | INVALID_IDENTIFIER_VA | Invalid identifier value | | 400 | BAD_REQUEST | Submitted request is malformed/invalid | | 400 | VALIDATION_ERROR | This is the "default" error thrown when no others are applicable | | 400 | UNSUPPORTED_VALUE | There was an unsupported value in the request | | 400 | NO_ORGANISATION_CONSENT | Organisation has not provided consent to share data | | 400 | BAD_REQUEST | Submitted request is malformed/invalid | | 403 | ACCESS_DENIED | Access denied | | 404 | NO_RECORD_FOUND | No record found | ' content: application/fhir+json: schema: type: object description: Link to GPConnect-OperationOutcome-1 resource population guidance [here](https://simplifier.net/guide/gpconnect-data-model/Home/FHIR-Assets/All-assets/Profiles/Profile--GPConnect-OperationOutcome-1?version=current). examples: example: value: resourceType: OperationOutcome meta: profile: - https://fhir.nhs.uk/STU3/StructureDefinition/GPConnect-OperationOutcome-1 issue: - severity: error code: not-found details: coding: - system: https://fhir.nhs.uk/STU3/ValueSet/Spine-ErrorOrWarningCode-1 code: NO_RECORD_FOUND display: No record found tags: - Patient /Patient/{id}/DocumentReference: get: operationId: search-document summary: Search for a patients documents description: 'Use this endpoint to search for a patients documents from a GP Practice. Use the patient id obtained from the /documents/Patient/{id} endpoint (NOT NHS Number). The NHS number of the patient is also required as a query string parameter. Details on the included parameters can be found below. These parameters must be used to reduce the number of API calls. ' parameters: - $ref: '#/components/parameters/BearerAuthorization' - $ref: '#/components/parameters/CorrelationID' - $ref: '#/components/parameters/RequestID_2' - in: path name: id description: The id of the patient obtained by using the /documents/Patient/{id} endpoint using their NHS Number. This can vary depending on GP provider system. schema: type: string example: 9d43831b-b2c7-4f8f-b5b5-1d9429acf5fb required: true - in: query name: patientNHSNumber description: The NHS number of the patient for whom documents are being searched. required: true schema: type: string example: '9000000009' - in: query name: _include description: 'DocumentReference:subject:Patient - Include Patient resources referenced within the returned DocumentReference resources DocumentReference:custodian:Organization - Details of organisations that are custodians for the documents that are returned in DocumentReference resources DocumentReference:author:Organization - Details of organisations that authored the documents that are returned in DocumentReference resources DocumentReference:author:Practitioner - Details of who/what authored the documents that are returned in DocumentReference resources ' required: false schema: type: array items: type: string enum: - DocumentReference:subject:Patient - DocumentReference:custodian:Organization - DocumentReference:author:Organization - DocumentReference:author:Practitioner - in: query name: _revinclude:recurse description: PractitionerRole:practitioner Include PractitionerRole resources referenced from matching Practitioner resources schema: type: array items: type: string enum: - PractitionerRole:practitioner required: false - in: query name: created description: 'The created date yyyy-mm-dd. To use a range use authored-on=geyyyy-mm-dd&authored-on=leyyyy-mm-dd ' required: false schema: type: string examples: exact date: value: eq2010-10-22 description: Exact match date greater than or equals: value: g2022-01-15 description: Greater than or equals which matches 2022-01-15 or 2022-01-16 less than or equals: value: le2022-01-15 description: Less than or equals which matches 2022-01-15 or 2022-01-14 - in: query name: author description: 'Who/what authored the documents that are returned ' required: false schema: type: string example: https://fhir.nhs.uk/Id/sds-user-id|G13579135 - in: query name: description description: 'The description of the document that is returned ' required: false schema: type: string example: Discharge Summary responses: '200': description: 'This endpoint returns a bundle containing relevant documents. ' content: application/fhir+json: schema: type: object description: The response will be a populated Binary resource. example: resourceType: Bundle meta: profile: - https://fhir.nhs.uk/STU3/StructureDefinition/GPConnect-Searchset-Bundle-1 type: searchset entry: - fullUrl: http://exampleGPSystem.co.uk/GP0001/STU3/1/gpconnect-documents/Patient/04603d77-1a4e-4d63-b246-d7504f8bd833 resource: resourceType: Patient id: 04603d77-1a4e-4d63-b246-d7504f8bd833 meta: versionId: '1469448000000' profile: - https://fhir.nhs.uk/STU3/StructureDefinition/CareConnect-GPC-Patient-1 extension: - url: https://fhir.nhs.uk/STU3/StructureDefinition/Extension-CareConnect-GPC-RegistrationDetails-1 extension: - url: registrationPeriod valuePeriod: start: '1962-07-13T00:00:00+00:00' identifier: - extension: - url: https://fhir.nhs.uk/STU3/StructureDefinition/Extension-CareConnect-GPC-NHSNumberVerificationStatus-1 valueCodeableConcept: coding: - system: https://fhir.nhs.uk/CareConnect-NHSNumberVerificationStatus-1 code: '01' display: Number present and verified system: https://fhir.nhs.uk/Id/nhs-number value: '9999999999' active: true name: - use: official text: JACKSON Jane (Miss) family: Jackson given: - Jane prefix: - Miss telecom: - system: phone value: 01454587554 use: home gender: female birthDate: '1952-05-31' address: - use: home type: physical line: - Cable Place - Roundhay city: Leeds district: West Yorkshire postalCode: LS1 5HT generalPractitioner: - reference: Practitioner/6c41ebfd-57c3-4162-9d7b-208c171a2fd7 managingOrganization: reference: Organization/db67f447-b30d-442a-8e31-6918d1367eeb - fullUrl: http://exampleGPSystem.co.uk/GP0001/STU3/1/gpconnect-documents/DocumentReference/27863182736 resource: resourceType: DocumentReference id: '27863182736' meta: profile: - https://fhir.nhs.uk/STU3/StructureDefinition/CareConnect-GPC-DocumentReference-1 masterIdentifier: system: LocalSystem/1 value: bb2374e2-dde2-11e9-9d36-2a2ae2dbcce4 identifier: - system: https://fhir.nhs.uk/Id/cross-care-setting-identifier value: bb237762-dde2-11e9-9d36-2a2ae2dbcce4 status: current type: coding: - system: http://snomed.info/sct code: '824331000000106' display: Inpatient final discharge letter subject: reference: Patient/04603d77-1a4e-4d63-b246-d7504f8bd833 created: '2019-06-24T09:35:00+11:00' indexed: '2019-07-02T09:43:41+11:00' author: - reference: Practitioner/6c41ebfd-57c3-4162-9d7b-208c171a2fd7 description: Discharge Summary content: - attachment: contentType: application/msword url: http://exampleGPSystem.co.uk/GP0001/STU3/1/gpconnect-documents/Binary/07a6483f-732b-461e-86b6-edb665c45510 size: 3654 context: practiceSetting: coding: - system: http://snomed.info/sct code: '1060971000000108' display: General practice service encounter: reference: Encounter/4 - fullUrl: http://exampleGPSystem.co.uk/GP0001/STU3/1/gpconnect-documents/Organization/db67f447-b30d-442a-8e31-6918d1367eeb resource: resourceType: Organization id: db67f447-b30d-442a-8e31-6918d1367eeb meta: versionId: '636064088098730113' profile: - https://fhir.nhs.uk/STU3/StructureDefinition/CareConnect-GPC-Organization-1 identifier: - system: https://fhir.nhs.uk/Id/ods-organization-code value: O001 name: The Trevelyan Practice address: - line: - Trevelyan Square - Boar Ln city: Leeds district: West Yorkshire postalCode: LS1 6AE telecom: - system: phone value: 03003035678 use: work - fullUrl: http://exampleGPSystem.co.uk/GP0001/STU3/1/gpconnect-documents/Practitioner/6c41ebfd-57c3-4162-9d7b-208c171a2fd7 resource: resourceType: Practitioner id: 6c41ebfd-57c3-4162-9d7b-208c171a2fd7 meta: versionId: '1469448000000' lastUpdated: '2016-07-25T12:00:00.000+00:00' profile: - https://fhir.nhs.uk/STU3/StructureDefinition/CareConnect-GPC-Practitioner-1 identifier: - system: https://fhir.nhs.uk/Id/sds-user-id value: G13579135 name: - use: usual family: Gilbert given: - Nichole prefix: - Miss gender: female - fullUrl: http://exampleGPSystem.co.uk/GP0001/STU3/1/gpconnect-documents/PractitionerRole/e0244de8-07ef-4274-9f7a-d7067bcc8d21 resource: resourceType: PractitionerRole id: e0244de8-07ef-4274-9f7a-d7067bcc8d21 meta: profile: - https://fhir.nhs.uk/STU3/StructureDefinition/CareConnect-GPC-PractitionerRole-1 practitioner: reference: Practitioner/6c41ebfd-57c3-4162-9d7b-208c171a2fd7 organization: reference: Organization/db67f447-b30d-442a-8e31-6918d1367eeb code: - coding: - system: https://fhir.hl7.org.uk/STU3/CodeSystem/CareConnect-SDSJobRoleName-1 code: R0260 display: General Medical Practitioner 4XX: description: 'An error occured as follows: | HTTP Status | Spine error code | Description | | ----------- | ---------------- | ----------- | | 400 | INVALID_PARAMETER | The author query parameter contains an identifier other than an ODS code | | 400 | INVALID_PARAMETER | The request does not contain the mandatory _include parameters | | 400 | INVALID_NHS_NUMBER | The NHS number provided is invalid, for example it fails format or check digit tests | | 404 | PATIENT_NOT_FOUND | A patient could not be found with the patient id provided | | 404 | PATIENT_NOT_FOUND | The request is for the record of an inactive or deceased patient | | 404 | PATIENT_NOT_FOUND | The request is for the record of a non-Regular/GMS patient (i.e. the patient''s registered practice is somewhere else) | | 404 | PATIENT_NOT_FOUND | The patient''s NHS number in the provider system is not associated with a NHS number status indicator code of ''Number present and verified'' | | 404 | PATIENT_NOT_FOUND | The request is for a sensitive Patient | | 422 | INVALID_PARAMETER | The patientNHSNumber parameter is not provided | ' content: application/fhir+json: schema: type: object description: Link to GPConnect-OperationOutcome-1 resource population guidance [here](https://simplifier.net/guide/gpconnect-data-model/Home/FHIR-Assets/All-assets/Profiles/Profile--GPConnect-OperationOutcome-1?version=current). examples: example: value: resourceType: OperationOutcome meta: profile: - https://fhir.nhs.uk/STU3/StructureDefinition/GPConnect-OperationOutcome-1 issue: - severity: error code: not-found details: coding: - system: https://fhir.nhs.uk/STU3/ValueSet/Spine-ErrorOrWarningCode-1 code: PATIENT_NOT_FOUND display: No patient found tags: - Patient /Patient/{id}/MedicationRequest: get: operationId: get-ordered-medicationrequest summary: Get prescription issue details description: '## Overview Use this endpoint to get details of previous prescription issues. The request must include the following parameter: * patient The request can optionally include include one of following parameters: * authoredon * identifier * intent * status Each MedicationRequest with intent of order must reference a MedicationRequest with intent plan within the basedOn element. ## Use cases Use cases covered by this endpoint include: * to get information about previously prescribed medication to display to the patient * present previously prescribed repeat medications available to reorder ' parameters: - $ref: '#/components/parameters/BearerAuthorization' - $ref: '#/components/parameters/CorrelationID' - $ref: '#/components/parameters/RequestID_3' - in: path name: id description: 'The NHS number of the patient whose requests you are searching for ' required: true schema: type: string example: '9912003489' - in: query name: authoredon description: 'Date the prescription was requested, format: YYYY-MM-DD. To use a range use authoredon=geYYYY-MM-DD&authoredon=leYYYY-MM-DD ' required: false schema: type: string examples: exact date: value: eq2010-10-22 description: Exact match date greater than or equals: value: ge2022-01-15 description: Greater than or equals which matches 2022-01-15 or 2022-01-16 less than or equals: value: le2022-01-15 description: Less than or equals which matches 2022-01-15 or 2022-01-14 - in: query name: identifier description: 'This will either be a uuid OR an EPS prescription identifier, this should only be used to obtain specific EPS orders using their identifier. EPS prescription Identifier for the prescription. Searches for EPS prescriptions need to provide a data type of `https://fhir.nhs.uk/Id/prescription-order-number` in the format `|` ' required: false schema: type: string examples: eps-prescription: value: https://fhir.nhs.uk/Id/prescription-order-number|CDT38E-Y765968-4FG3BQ - in: query name: intent description: 'Intent of the MedicationRequest, will either be plan or order. If plan is selected only MedicationRequest''s with intent of plan will be returned. ' required: false schema: type: string examples: intent: value: plan - in: query name: status description: 'The type of status to search: you can find valid values [here](https://simplifier.net/guide/gp-connect--patient-facing-services--prescriptions/Home/FHIR-Assets/All-Assets/Profiles/UKCore-MedicationRequest?version=0.1.1-private-beta#status) ' required: false schema: type: string example: active responses: '200': description: Successful request to view previous prescription issue details content: application/fhir+json: schema: type: object description: Information surrounding how the resource is populated can be found [here](https://simplifier.net/guide/gp-connect--patient-facing-services--prescriptions/Home/FHIR-Assets/All-Assets/Profiles/UKCore-MedicationRequest?version=0.1.1-private-beta). examples: GetResponsePreviousPrescriptionDetailed: $ref: '#/components/examples/GetResponsePreviousPrescriptionDetailed' GetResponseMultiplePrescriptions: $ref: '#/components/examples/GetResponseMultiplePrescriptions' GetResponseMethotrexate: $ref: '#/components/examples/GetResponseMethotrexate' 4XX: description: 'An error occurred as follows: | HTTP Status | Spine error code | Description |-------------|--------------------|------------ | 404 | RESOURCE_NOT_FOUND | The request is for a MedicationRequest that doesn''t exist | 422 | INVALID_PARAMETER | The MedicationRequest id supplied is invalid | 422 | INVALID_PARAMETER | The date is invalid or in future | 422 | INVALID_PARAMETER | The identifier value is invalid ' content: application/fhir+json: schema: type: object description: Link to UKCore-OperationOutcome resource population guidance [here](https://simplifier.net/guide/gp-connect--patient-facing-services--prescriptions/Home/FHIR-Assets/All-Assets/Profiles/UKCore-OperationOutcome?version=0.1.1-private-beta). examples: InvalidRequestError: $ref: '#/components/examples/InvalidRequestError' tags: - Patient components: parameters: RequestID: in: header name: X-Request-ID required: true description: 'A globally unique identifier (GUID) for the request, which we use to de-duplicate repeated requests and to trace the request if you contact our helpdesk. Must be a universally unique identifier (UUID) (ideally version 4). Mirrored back in a response header. If you re-send a failed request, use the same value in this header. Required in all environments except sandbox. ' schema: type: string pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ example: 60E0B220-8136-4CA5-AE46-1D97EF59D068 BearerAuthorization: in: header name: Authorization description: 'An [OAuth 2.0 bearer token](https://digital.nhs.uk/developer/guides-and-documentation/security-and-authorisation#user-restricted-apis). Required in all environments except sandbox. ' required: true schema: type: string format: ^Bearer\ [[:ascii:]]+$ example: Bearer g1112R_ccQ1Ebbb4gtHBP1aaaNM InteractionID: in: header name: Ssp-InteractionID description: "\tSpine Interaction ID, likely to be \turn:nhs:names:services:gpconnect:fhir:operation:gpc.getstructuredrecord-1\n" required: true schema: type: string example: urn:nhs:names:services:gpconnect:fhir:operation:gpc.getstructuredrecord-1 TraceID: in: header name: Ssp-TraceID description: "\tConsumer's Trace ID (a GUID or UUID), generated per request\n" required: true schema: type: string example: 09a01679-2564-0fb4-5129-aecc81ea2706 CorrelationID: in: header name: X-Correlation-ID required: false description: 'An optional ID which you can use to track transactions across multiple systems. It can have any value, but we recommend avoiding `.` characters. Mirrored back in a response header. ' schema: type: string example: 11C46F5F-CDEF-4865-94B2-0EE0EDCC26DA ConsumerASID: in: header name: Ssp-From description: "\tConsumer's ASID - that of the requesting organisation\n" required: true schema: type: string example: '200000000359' RequestID_3: in: header name: X-Request-ID required: true description: 'A globally unique identifier (GUID) for the request, which we use to de-duplicate repeated requests and to trace the request if you contact our helpdesk. Must be a universally unique identifier (UUID) (ideally version 4). Mirrored back in a response header. If you re-send a failed request, use the same value in this header. Required in all environments except sandbox. ' schema: type: string pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ example: 60E0B220-8136-4CA5-AE46-1D97EF59D068 RequestID_2: in: header name: X-Request-ID required: true description: 'A globally unique identifier (GUID) for the request, which we use to de-duplicate repeated requests and to trace the request if you contact our helpdesk. Must be a universally unique identifier (UUID) (ideally version 4). In the use case of accessing a patient''s record, this UUID must be used as the id of the bundle returned. Mirrored back in a response header. If you re-send a failed request, use the same value in this header. Required in all environments except sandbox. ' schema: type: string pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ example: 60E0B220-8136-4CA5-AE46-1D97EF59D068 ProviderASID: in: header name: Ssp-To description: "\tProvider's ASID - identified by use of SDS\n" required: true schema: type: string example: '918999198738' examples: GetResponsePreviousPrescriptionDetailed: $ref: components/examples/GetResponsePreviousPrescriptionDetailed.yaml GetResponseMultiplePrescriptions: $ref: components/examples/GetResponseMultiplePrescriptions.yaml GetResponseMethotrexate: $ref: components/examples/GetResponseMethotrexate.yaml InvalidRequestError: $ref: components/examples/InvalidRequestError.yaml