Governance

What a superintendent should check before approving remote consultations

A practical, source-checked checklist for the superintendent signing off a remote-consultation provider, from pharmacist registration and indemnity to data residency, clinical-safety standards and the Responsible Pharmacist boundary.

Published 14 July 2026 · 7 min read · Checked against official sources 14 July 2026

Start with the people: registration and indemnity

Before anything else, verify the pharmacists who will deliver consultations. Each should be checked against the GPhC register, hold current professional indemnity cover appropriate to remote clinical work, and have their identity and named accountability confirmed. Ask how the provider evidences this on an ongoing basis rather than at onboarding only, and how a registrant is stood down if their status lapses.

It is worth being clear on what registration does and does not cover. The GPhC registers pharmacists, pharmacy technicians and pharmacies or premises. It does not register or approve software. Any claim that a platform is "GPhC registered" or "GPhC approved" is a red flag, and assurance about the technology should be evidenced through the standards covered below, not a regulator's badge.

Map remote suitability pathway by pathway

Do not accept a blanket "delivered remotely" claim. Six of the seven Pharmacy First clinical pathways (sinusitis, sore throat, infected insect bites, impetigo, shingles and uncomplicated UTI in women aged 16 to 64) can be delivered by video, provided the video is good enough to examine what needs examining, such as a rash or a urine sample. Acute otitis media (earache) requires an otoscope and therefore remains an in-person service.

Telephone or audio-only delivery is not permitted for the clinical pathways; only the minor-illness and urgent-medicine-supply referral consultations may be handled by phone or video. Confirm too where the delivering pharmacist physically sits: NHS terms require any pharmacist providing a remote consultation to be at registered pharmacy premises when they deliver it. You can see how this maps to each pathway on our what can be delivered remotely page.

Insist on a written convert-to-face-to-face protocol

The GPhC's February 2025 guidance on providing pharmacy services at a distance is risk-based professional judgement, not a ban. For higher-risk requests the prescriber must not rely on a questionnaire alone; they must independently verify the information, and where it cannot be verified or it is not safe to prescribe, the patient is redirected to an appropriate care provider. That escalation route is exactly what you are approving.

Ask to see the protocol written down: the thresholds at which a remote consultation is paused, what independent verification looks like in practice (for weight-management medicines, for example, verifying weight, height and BMI, where a phone call alone is not adequate), and precisely where the patient is directed next. A provider that cannot show you a documented convert-to-face-to-face pathway has not met the guidance.

Check how consent is captured and recorded for each consultation, and how recording is controlled. Recording should be off by default and only enabled with consent, with access restricted, for example through short-lived signed URLs rather than open links. Clinical notes should be pathway-aligned and written contemporaneously into your NHS-assured Pharmacy First IT system, which is also where NHS claims flow.

Underpinning all of this, look for an append-only, hash-chained audit trail so that who did what, and when, cannot be altered after the fact, alongside role-based access and multi-factor authentication. These are the controls that let you reconstruct a consultation if it is ever questioned, and they are reasonable to expect as standard.

Where the data lives, and the clinical-safety standards

Establish where patient data is stored and processed and confirm UK data residency. Then work through the assurance position rather than taking a summary claim at face value. The NHS Data Security and Protection Toolkit (DSPT) is an annual self-assessment against the National Data Guardian's ten standards, due by 30 June each year. It is a contractual requirement, not a third-party certificate. ICO data-protection-fee registration is a legal duty for any controller. Cyber Essentials covers five NCSC technical controls, with Cyber Essentials Plus adding independent testing.

On clinical safety, DCB0129 is the clinical-risk-management standard the software manufacturer must meet, evidenced by a named Clinical Safety Officer, a hazard log and a clinical safety case. DCB0160 is the equivalent standard for your organisation as the deploying provider, and part of your duty under it is to confirm your supplier meets DCB0129. A pre-launch provider may honestly show some of these as in progress; what matters is that each position is stated plainly and given to you in writing. Our clinical safety and assurance page sets out how we present ours.

Hold the Responsible Pharmacist boundary

Finally, protect the line that a remote model must never cross. The on-site Responsible Pharmacist always stays on the premises and is never replaced, and the platform must not provide remote supervision of dispensing, which is not permitted. The remote pharmacist adds NHS Pharmacy First and private-consultation capacity; they do not stand in for on-site presence.

In practice the patient should never be left alone with a screen: on-site staff greet them and start the call, and dispensing continues under the on-site Responsible Pharmacist exactly as before. If a provider's model implies operating without an on-site Responsible Pharmacist, or remote oversight of the dispensing process, it should not pass your review. See how it works for how the on-site and remote roles sit together.

Frequently asked questions

Can a Pharmacy First clinical consultation be done over the phone?

No. The seven clinical pathways cannot be delivered audio-only. Six can be delivered by good-quality video that is clear enough to examine, for example, a rash or a urine sample; acute otitis media (earache) needs an otoscope and remains in person. Only minor-illness and urgent-medicine-supply referral consultations may be by phone or video.

Does the remote pharmacist need to be in a pharmacy?

Yes. NHS terms require any pharmacist providing a remote Pharmacy First consultation to be physically at registered pharmacy premises when they deliver it. The consultation room must have the IT to record contemporaneously in the NHS-assured Pharmacy First IT system.

Can I describe the software as GPhC approved once we are satisfied with it?

No. The GPhC registers pharmacists, pharmacy technicians and pharmacies or premises, not software, so no product can be GPhC registered or GPhC approved. Technology assurance is evidenced through the DSPT, DCB0129 and DCB0160, ICO registration and Cyber Essentials instead.

What is the difference between DCB0129 and DCB0160?

DCB0129 is the clinical-risk-management standard the software manufacturer must meet, with a named Clinical Safety Officer, a hazard log and a clinical safety case. DCB0160 is the equivalent standard for your organisation as the deploying provider, and part of your duty under it is to confirm your supplier meets DCB0129.

Does remote consultation let one pharmacist supervise dispensing at another site?

No. Remote supervision of dispensing is not permitted, and the on-site Responsible Pharmacist always remains on the premises. The model adds consultation capacity; it does not provide remote oversight of the dispensing process.

See the governance controls in a live walkthrough

Book a demo and we will take you through the registration checks, the convert-to-face-to-face route, the audit trail and our current DSPT, DCB0129 and Cyber Essentials position, including what is still in progress.