Some of your patients need someone else to manage their messages: a parent following a young child's vaccinations, or an adult son or daughter helping an elderly parent. Proxy access is how Nexus records that, safely and with an end date.
A proxy sees only what the patient's own account shows — messages from your practice, and how you contact them. Not their record, results, appointments or documents.
This is the part worth understanding before anything else. When someone opens a secure link and confirms a patient's date of birth, surname and postcode, that proves they *know the patient's details* — it does not prove they are the parent, or that the patient wants their help.
So a request from someone who cannot be checked by the patient themselves shows you nothing to the requester until you authorise it. It waits in Practice → Proxy access requests until one of your team looks at it.
| Who | Who decides | How long |
|---|---|---|
| Parent of a child under 11 | Your practice, on evidence of parental responsibility | Until the child's 11th birthday |
| Parent of a child aged 11–15 | The child, once they have their own account | Until their 16th birthday — no exceptions |
| Relative or carer of an adult who can decide for themselves | The patient, by answering a secure message | No end date; re-checked every year |
| Relative or carer of an adult who cannot decide | Your practice, on a documented ground | No end date; re-checked every year |
Each waiting request shows who is asking, for whom, and what they have offered as proof. Before you decide, the page also tells you two things that matter:
Authorise asks you to write down what you actually checked ("Birth certificate seen at reception"). That note and your name are kept with the grant permanently. Refuse asks for a reason, which the requester is told.
For an adult, use Ask the patient. Nexus emails *the patient* — never the person asking — with a plain question and an identity check. They say yes or no. If they do nothing, nothing happens.
Use They can't consent only where that is genuinely the case. You will be asked what the decision rests on — a lasting power of attorney, a court order, or a best-interests decision recorded at the practice — with a reference and a note of what you saw. This is a decision made on someone's behalf, so the record of it has to be solid.
Around three months before a child's 11th birthday, the parent, the child's own contact and your practice are all told what is coming. On the birthday the parent's access stops automatically — you don't have to do anything.
The child can then take over their own account and decide whether their parent carries on helping them, up to their 16th birthday. At 16 it ends for good.
One practical thing to plan for: a child can only be sent their own account link if you hold a contact for *them*. The Ending soon list flags any child with no email or mobile of their own so you can arrange it in person before the access stops.
Anyone can end it: the patient (or the young person) from their own account, and your practice at any time from the queue — instantly, at any age. Access stops the moment you revoke it. The record of the grant is kept, so you can always answer who had access and why it ended.
Adult grants come back to you once a year under Due for annual review. Confirm it is still appropriate, or end it.
Proxy access is off by default for every practice. Ask the Nexus team to enable it for you; we will confirm the information-governance position with you first, because you are the data controller for these decisions.