NHS sites give monitors access to the electronic patient record (EPR) without breaching UK GDPR by putting three permissions in place before the first login: a lawful basis for the processing, explicit consent that releases the record from the common law duty of confidentiality, and a named read-only account the trust itself issues, scopes and audits. Each comes from a different body of law, and a different person at the trust grants it.
This guide sits in our series on eSource in clinical trials. It covers what makes the access lawful, the models the MHRA recognises, the trust approval chain, what the Caldicott principles ask, how the access is audited, and where it fails.
Consent releases the record. The trust grants the account.
What Makes a Monitor’s Access to an NHS EPR Lawful?
Four requirements have to be satisfied at once. A site holding only the sponsor’s paperwork has an arrangement that fails an information governance review.
| Requirement | Where it comes from | What satisfies it at an NHS site |
| A lawful basis for processing | UK GDPR | A task in the public interest for NHS organisations, and legitimate interests for commercial sponsors |
| Release from the duty of confidentiality | The common law duty of confidentiality | Explicit participant consent, recorded in the information sheet and consent form |
| A duty to permit direct access | ICH E6(R3), section 2.12.14 | The investigator makes requested trial-related records available for direct access to the monitor, auditor, ethics committee or regulatory authority |
| Contractual information governance terms | The clinical trial agreement | The sponsor’s obligations on training, device security, breach reporting and permitted locations |
Consent does different work in the first two rows. The HRA guidance on consent in research states that consent is not the legal basis for processing personal data under UK GDPR in health and care research. It also states that consent is still needed for people outside the care team to access confidential patient information, which is the common law requirement a monitor clears.
Controllership stays split. The HRA states that the sponsor acts as the controller in relation to the research data and the care organisation acts as the controller in relation to the data provided for care purposes, so one set of information can have two controllers for two purposes. The trust keeps its EPR controller duties whatever the trial agreement says.
ICH E6(R3) ties the consent wording to the access. Section 2.8.10(o) requires the participant to be told that taking part allows direct access to source records, on the understanding that the confidentiality of their medical record will be safeguarded.
Which EPR Access Models Does the MHRA Recognise?
The MHRA recognises log-in access, guided access and upload to a portal, and treats printouts as a fallback. Its guidance on access to electronic health records by sponsor representatives states that log-in access requires far less investigator site personnel involvement during the review, so it is preferable.
| Access model | How the monitor reads the record | What the site has to provide | Where it falls short |
| Log-in access, on site | A named read-only account at the site | An account, a role, a desk and an escort | Research space and staff time |
| Log-in access, remote | The same account from the monitor’s own location | The account, two-factor authentication and review windows | Permitted only from the UK, an EEA state or a state under a UK adequacy decision |
| Guided access | Site staff share a screen and navigate | A delegated staff member throughout | Site effort runs through the visit, and the records opened are evidenced only where the site logs them |
| Upload to a portal | The site exports documents to a secure portal | Export and upload effort for each participant | Direct access only where it holds a complete, certified copy of the EHR system |
| Printouts | Paper or PDF extracts handed over at the visit | Printing, checking and filing | The MHRA reports printouts arriving incomplete, with gaps where a report runs date to date |

Two conditions apply to every log-in model. The guidance states that log-in access must not be provided where the monitor can edit, add, change or delete information. It also states that sharing user accounts and log-in information with another person is strictly forbidden.
The record a monitor reaches is the source only where the site has declared it as such. Our guide to which record is the source when data sits in both the EPR and the trial system covers that declaration.
How Does an NHS Trust Approve a Monitor’s Access?
Approval runs through eight steps, and the trust owns most of them.
- The clinical trial agreement sets the information governance terms, the sponsor’s training duty and the conditions of access.
- The trust’s research and development office confirms the study locally and records the agreed access arrangement.
- The site verifies the monitor’s identity when creating the read-only account, using government issued photographic identification that is documented rather than retained.
- A monitor who is not employed by an NHS organisation obtains a letter of access or an honorary research contract. The HRA research passport is the mechanism for non-NHS staff to obtain either one, and a person already employed by an NHS organisation needs neither.
- The Caldicott Guardian and the information governance team decide whether the disclosure meets the trust’s confidentiality standards.
- The Registration Authority issues the account. NHS England states that smartcards are issued only to individuals whose identity has been verified to national identity check standards, and that role-based access control restricts a user to the data items their role requires.
- The sponsor trains the monitor on the trust’s information governance obligations and on where a session may be opened.
- The site deactivates the account at close-out, or on the day the monitor leaves the study.
Six of those eight steps belong to the trust, which is why the timetable follows NHS research governance rather than the monitoring plan.
The chain produces documents for the site file. The letter of access, the access agreement, the identity verification record and the training certificate are filed in the investigator site file.
Also Read: How Should Monitors Do Remote Source Data Verification with eSource?
What Do the Caldicott Principles Require of an EPR Access Decision?
The Caldicott principles are eight principles published by the National Data Guardian and last updated in December 2020. Health service bodies in England handling confidential patient information appoint a Caldicott Guardian to apply them, under guidance issued in August 2021 using the statutory power in the Health and Social Care (National Data Guardian) Act 2018.
| Principle | The question it puts to a monitor access request |
| 1. Justify the purpose | Which study, sponsor and monitoring plan clause requires this access? |
| 2. Use confidential information only when necessary | Does verification of the trial data require sight of the record itself? |
| 3. Use the minimum necessary | Can the account be limited to the participants the study covers? |
| 4. Access on a strict need-to-know basis | Is the account held by one named monitor, for one study, at one site, read-only? |
| 5. Everyone aware of their responsibilities | Has the monitor completed documented governance training before the first login? |
| 6. Comply with the law | Are the lawful basis and the consent recorded and current? |
| 8. Inform patients about how their information is used | Does the participant information sheet state that sponsor and regulatory personnel can read the record? |

Principle 7 concerns the duty to share information for an individual’s own care, so it governs clinical use rather than a research disclosure. Each answer above is evidence the trust can produce later.
How Is a Monitor’s Access to the EPR Audited?
The trust audits the access on two levels: the account and the reading. Both produce evidence an inspector or a governance review can request.
- The system logs user additions, deactivations and permission changes, which shows who held access on any past date.
- Every access to patient data is traceable back to the smartcard holder, which attributes each read to one person.
- The site runs a risk-based audit trail review of the monitor’s activity, which detects inappropriate activity and triggers corrective and preventive action.
- An automatic time-out ends an inactive session, which closes a login left open on an unattended device.
- Two-factor authentication applies to remote log-in, which ties a session to something the monitor holds.
- The read-only role restricts printing, copying and downloading, which keeps the record inside the trust.
- A scheduled account review identifies dormant logins, which stops access accumulating past the point of need.

A finding from that review runs through the site’s own quality process. A monitor who opened a record outside the study cohort produces a data breach assessment and a corrective action in the quality management system.
Also Read: What MHRA Expects from Electronic Source Systems Under the 2026 UK Regulations
Where Does EPR Access Break Down at NHS Sites?
Six failures account for most of the difficulty, and each is a condition set before the monitor arrives.
| Failure | What it looks like | Condition behind it |
| The EPR cannot restrict to trial participants | The only account available reaches the whole ward | Permissions are built around clinical roles. MHRA inspectors have reported a system that did not allow access limited to trial patients for external monitors |
| No audit trail to review | The trust cannot show which records were opened | MHRA inspectors have reported records with no audit trail, or no ability to access it |
| Access granted to the sponsor rather than a person | Read events attribute to an organisation | Provisioning treated the monitoring team as one user |
| Printouts substituted for access | The monitor verifies against paper extracts | The printout was never certified, so it stands as an uncontrolled copy |
| Access exercised outside the permitted territory | A monitor logs in from outside the agreed states | The access agreement never named permitted locations |
| The account outlives the study | A login still works a year after close-out | Deactivation depends on memory rather than a scheduled review |
Consider a hypothetical respiratory study at an NHS trust. A quarterly account review finds the monitor’s remote read-only account still active eight months after the last participant completed. The access log shows four logins in that period, all against consented participants. The finding is the provisioning procedure rather than the monitor’s conduct, because nothing in the process closed the account when the study closed. The corrective action attaches deactivation to the close-out checklist.
An account nobody closed is an access nobody authorised.
Monitor access to an NHS EPR holds together where the lawful basis, the trust approval and the audit of the reading sit alongside the study record. AQ is launching eSource soon as part of the AQ platform, so the access a site grants and the source record a monitor reads are held on one footing. Book a live demo to see the AQ platform today.
