Demographics API Useful Information
Information on the how NDP Demographics API allows to retrieve demographics data.
Information on the how NDP Demographics API allows to retrieve demographics data.
The NDP Demographics API allows to retrieve demographics data for individuals registered with NHS Scotland.
Demographics data includes:
The system allows users to:
The accuracy of the demographics data depends on:
There are two environments available externally
1. Staging Environment
This environment is designed for development and integration testing. It contains test patient data.
Credentials for this environment are available on request. For more information, go to the 'Onboarding and Getting Access' section at the end of this document.
Support for this environment is available Monday to Friday, 7am to 6pm.
2. Production Environment
This environment contains live patient data.
Credentials for this environment are issued following information governance approval. If you require production access, notify us at least 4 weeks in advance.
There are no IP restrictions in place for any of the environments.
Authentication
The API uses OAuth 2.0 access token authentication. Clients must obtain access tokens from the NDP Identity and Access Management service.
Authorization
The client must include access token in the 'Authorization' header of every API request.
Scopes
The client will be registered with the appropriate scope or scopes for the operations they need depending on if they want to:
Access
The NDP Demographics Service supports 2 access patterns:
User-level
This is the access pattern for any application that has end users using the system.
The application makes requests using the authenticated user's identity. This means, each API call is attributed to a specific user rather than the application itself. This process allows for more granular access to data as well as auditing of user actions. The user will normally use the Authorization Code Flow to obtain the Bearer token.
In production, users of NHS Scotland EntraID will be able to sign in with the NHS Scotland credentials.
Application-level
This access is only granted in special cases when an application is trusted and it’s not possible to provide user-level access. The application will use the Client Credentials Flow to obtain the access token.
In this case, the application makes requests using its own identity. This means, API calls are attributed to the application rather than any individuals. Under these circumstances, there is no way to provide more granular access or auditing.
All accesses to the NDP Demographics Service are fully audited. Each record includes
Client Responsibility
Applications must be able to demonstrate that they capture, maintain and retain full user level audit logs of all API usage. These logs must be retained following the clinical data user activity policies in effect at the time of access.
Find the OpenAPI 3.0 documentation in the NDP Demographics Service Docs .
The following items are typically included in the returned FHIR Patient resource . These are standard fields and are always available in the National CHI Database.
Health Board Cyphers
In certain circumstances, the user will have the disbanded board 'C' (NHS Argyll & Clyde) returned. This board has been split between NHS Highland and NHS Greater Glasgow & Clyde.
During the onboarding process, users will receive the mapping of the GP Practice to the new Health Board along with other test data.
If you’re part of NHS Scotland
To start the onboarding process, complete the Technical Triage Form.
After review, we'll issue staging credentials and we’ll be in touch with any required information governance steps.
In reference to question 12 within the Technical Triage Form, you need to attach in your application response:
If you’re not part of NHS Scotland
You need permission from the CHI Management Board (CHIMB).
To get this, apply using the Health and Social Care Public Benefit and Privacy Panel (HSC-PBPP) application form . To do this:
Once you complete the application, send it to nss.committee@nhs.scot stating it’s for approval by CHIMB.
The NDP Demographics Service team does not have the ability to influence or accelerate the board’s decision-making processes.
For any issues, please log a ticket in the NDP Service Desk.