In brief
- Outsourcing done carelessly moves clinical risk outside the building while leaving the liability inside it.
- Governance is checkable: registration, supervision, indemnity, data protection, audit and exit.
- NovaHS answers every one of these questions in the open, and any credible provider should too.
More practices than ever are using external teams for clinical and clinically adjacent work: correspondence, coding, medicines management, triage, clinics. Done well, it is one of the few genuine capacity releases available to general practice. Done carelessly, it moves clinical risk outside the building while leaving the liability inside it.
The difference is governance, and governance is checkable. These are the questions we believe every practice should put to any provider it considers. We answer them about ourselves below, and a credible provider should be happy to do the same.
Registration and accountability
Is the provider registered with the CQC for the regulated activities it performs? Registration means the provider is inspectable, accountable and operating under the same regulatory framework as the practice itself. Ask for the registration, not just the claim. Then ask who carries clinical responsibility day to day: is there genuine clinical leadership, and are clinicians supervising the work rather than lending their names to it?
Supervision, competence and indemnity
Ask how the people doing the work are trained, how their competence is assessed, and how often their output is audited. Ask what happens when they are unsure: is there a clear escalation route to a GP, and how quickly does it answer? And ask about professional indemnity, both the provider’s organisational cover and the arrangements for individual clinicians. If an error occurs, the practice should know in advance exactly where responsibility sits.
Data protection and access
Clinical work means patient data, so the provider is a data processor and the practice remains the controller. That demands a written processing agreement, compliance with UK GDPR, and the NHS-specific assurances: Data Security and Protection Toolkit standards met, Cyber Essentials in place, smartcard-equivalent access controls, and activity confined to the clinical system where it can be seen. Be wary of any workflow that takes patient data out of EMIS Web or SystmOne into places the practice cannot audit.
Evidence, audit and exit
Every item of work should leave a trail: who did it, when, under what protocol, and with what outcome. Ask to see a sample audit report before signing anything. Ask how quality is measured week to week, not just at annual review. And ask what happens if you leave: how is access revoked, what is handed back, and in what state. A provider confident in its service will make leaving easy, because it does not expect you to want to.
How NovaHS answers
NovaHS is CQC-registered and GP-led. Clinical work runs under GP supervision with defined escalation routes, professional indemnity is in place across the team, and we meet UK data standards including the DSP Toolkit and Cyber Essentials, working inside EMIS Web and SystmOne so every action is visible to the practice. Every document and clinical decision carries an audit trail, and regular clinical safety audits are part of how we operate, across NovaDoc, NovaClinic, NovaMed and NovaSummarise.
We support practices across 32 ICB areas in England, with over 10 million documents processed and an estimated 100,000 NHS clinical hours returned each year. Ask us these questions on a call. We enjoy them.
Frequently asked questions
Does outsourcing clinical work transfer the practice’s liability?
No. The practice remains accountable to its patients and its regulator, which is why the provider’s own registration, supervision and indemnity arrangements matter so much. Good governance means both organisations know exactly where responsibility sits for every task.
What should be in place before any patient data is shared?
A written data processing agreement, UK GDPR compliance, DSP Toolkit assurance, defined access controls, and a workflow that keeps the work inside the practice’s clinical system wherever possible.
How do we monitor an outsourced service once it is running?
Agree the audit and reporting cycle up front: regular quality reports, sample audits of processed work, error and escalation logs, and a named contact with the authority to fix problems quickly.
NHS GP and founder of NovaHS, leading its GP-led model of clinical support for practices across England.
More from the blog
Want to talk it through? Contact NovaHS for a free, no-pressure conversation about what support could look like for your practice, PCN or ICB.