Proxy access — when someone acts for a patient

Proxy access — when someone acts for a patient

Some of your patients need someone else to manage their messages: a parent following a young child's vaccinations, or an adult son or daughter helping an elderly parent. Proxy access is how Nexus records that, safely and with an end date.

A proxy sees only what the patient's own account shows — messages from your practice, and how you contact them. Not their record, results, appointments or documents.

Nobody gets access by asking

This is the part worth understanding before anything else. When someone opens a secure link and confirms a patient's date of birth, surname and postcode, that proves they *know the patient's details* — it does not prove they are the parent, or that the patient wants their help.

So a request from someone who cannot be checked by the patient themselves shows you nothing to the requester until you authorise it. It waits in Practice → Proxy access requests until one of your team looks at it.

The four situations

WhoWho decidesHow long
Parent of a child under 11Your practice, on evidence of parental responsibilityUntil the child's 11th birthday
Parent of a child aged 11–15The child, once they have their own accountUntil their 16th birthday — no exceptions
Relative or carer of an adult who can decide for themselvesThe patient, by answering a secure messageNo end date; re-checked every year
Relative or carer of an adult who cannot decideYour practice, on a documented groundNo end date; re-checked every year

Working through the queue

Each waiting request shows who is asking, for whom, and what they have offered as proof. Before you decide, the page also tells you two things that matter:

  • if this access was refused or revoked before, and why — shown in red, because a safeguarding decision must not be undone by someone who never saw it;
  • if they held an authorised grant at the patient's previous practice, with the dates. That is a helpful signal when a family moves, but it is not a substitute for your own check — you did not see the evidence the other practice saw, and you will not be told why it ended.

Authorise asks you to write down what you actually checked ("Birth certificate seen at reception"). That note and your name are kept with the grant permanently. Refuse asks for a reason, which the requester is told.

When the patient can decide for themselves

For an adult, use Ask the patient. Nexus emails *the patient* — never the person asking — with a plain question and an identity check. They say yes or no. If they do nothing, nothing happens.

When the patient cannot decide

Use They can't consent only where that is genuinely the case. You will be asked what the decision rests on — a lasting power of attorney, a court order, or a best-interests decision recorded at the practice — with a reference and a note of what you saw. This is a decision made on someone's behalf, so the record of it has to be solid.

What happens as a child grows up

Around three months before a child's 11th birthday, the parent, the child's own contact and your practice are all told what is coming. On the birthday the parent's access stops automatically — you don't have to do anything.

The child can then take over their own account and decide whether their parent carries on helping them, up to their 16th birthday. At 16 it ends for good.

One practical thing to plan for: a child can only be sent their own account link if you hold a contact for *them*. The Ending soon list flags any child with no email or mobile of their own so you can arrange it in person before the access stops.

Ending access

Anyone can end it: the patient (or the young person) from their own account, and your practice at any time from the queue — instantly, at any age. Access stops the moment you revoke it. The record of the grant is kept, so you can always answer who had access and why it ended.

Annual re-checks

Adult grants come back to you once a year under Due for annual review. Confirm it is still appropriate, or end it.

Turning it on

Proxy access is off by default for every practice. Ask the Nexus team to enable it for you; we will confirm the information-governance position with you first, because you are the data controller for these decisions.

Related articles

  • What happens when a child turns 11
  • Childhood immunisations (Local data)
    • Related Articles

    • What happens when a child turns 11

      A parent can follow their child's messages from your practice until the child's 11th birthday. On that day it stops on its own. The child can then take over their own account and decide whether their parent carries on helping them — and at 16 it ends ...
    • CQC performance and CQC actions (Local data)

      The Ardens CQC search set, run against your practice's own clinical data and grouped under the five CQC key questions (Safe, Effective, Caring, Responsive, Well-led). It is delivered as two dashboards, sold separately, which link to each other when ...
    • Childhood immunisations (Local data)

      Dashboards → Local data → Childhood immunisations shows every child under 5 registered at your practice against the QOF childhood vaccination schedule — who has had each vaccination, whose is due or overdue, whether an appointment is already booked, ...
    • Why can't I see a feature?

      Nexus shows you only the features you can actually use. If a menu item or page someone else has is missing for you, it's almost always one of these: 1. Your organisation doesn't hold the package Menus are driven by your organisation's packages. If ...
    • Free NHS data access

      Anyone with an NHS email address can use the Nexus benchmark dashboards for free — no card details, no trial clock, and no need to register your organisation or involve anyone else at your practice. This is not a taster of the paid product that ...