Dataforge PMR Wiki · Operations

Electronic signatures for pharmacy consent: setup, legal validity and the audit trail

A signature on a consent form is not a formality, it is the evidence that a person agreed to something specific on a particular date, and most pharmacy services capture it in a way which cannot demonstrate either. It also has an audience services rarely design for, since patients return years later needing their records for insurance claims, employers and solicitors, and what they receive can decide whether a claim succeeds. This guide covers whether electronic signatures are legally valid in the UK, what a defensible signature record contains, why the document version matters most, where consent belongs in a pharmacy workflow, what patients and third parties will later ask for, how to handle version changes and withdrawal, retention, and what to check before relying on any e-signature arrangement.

Written by Saqib Kamili, Technical Lead. Last reviewed 16 May 2026 by Arham Jamaal, Superintendent Pharmacist.

For the documents a pharmacy uses, generally yes, and the position is more settled than the sector's caution suggests.

The Electronic Communications Act 2000 provides for the admissibility of electronic signatures in evidence, and the Law Commission's 2019 report concluded that an electronic signature is capable of satisfying a statutory requirement for a signature where the signatory intends to authenticate the document and any other formalities are met. Consent to treatment, agreement to service terms and permissions of the kind a private pharmacy service uses fall comfortably within that.

Two qualifications belong alongside it. Certain instruments, deeds most commonly, carry additional formalities including witnessing, and anything of that kind warrants specific legal advice rather than reliance on a general position. And validity is not the same as evidential weight, which is the distinction the rest of this article is concerned with. A signature which is legally capable of binding somebody is of limited use if the service cannot demonstrate who signed, when, and what they were shown.

What a defensible signature record contains

THE SIGNATURE IS THE LEAST IMPORTANT PART OF THE SIGNATURE RECORD

Services buying e-signature capability tend to evaluate how the signature looks, which is the part that matters least. What determines whether a consent record survives scrutiny is everything attached to it. Who signed, identified to the patient record rather than to an email address alone. When, to a timestamp rather than a date. What version of the document was displayed at the moment of signing, which is the element most commonly absent and the one that decides whether you can state what was agreed. The document as presented, retained rather than regenerated, since a consent form rebuilt from current templates shows today's wording rather than the wording signed. And evidence of integrity, meaning the record demonstrably has not been altered since. Technical context such as device, browser or address adds weight and is not essential. A record holding those five elements answers the question a dispute actually asks. A scanned image of a signature answers almost none of them, which is why digitising paper is not the same as capturing consent electronically.

Why the document version matters most

Consent wording changes, and it changes more often than services expect. A new medicine is added to a plan, a side effect warning is expanded following an MHRA communication, a data sharing arrangement is revised, or the service's own terms are updated.

Where the wording is stored as a single current document, every one of those revisions silently rewrites history. A patient who consented in March appears to have consented to the September wording, and the service cannot show otherwise. Where wording is versioned, with each revision released under a new identifier and an effective date, every signature continues to point at what was actually displayed.

The discipline is identical to the questionnaire versioning described in the consultation flow guide, and for the same reason. When something changes externally, the first question is which cohort was assessed or consented under which version, and a service that cannot answer it is reconstructing rather than reporting.

Where consent belongs in the workflow

Two placements, and choosing between them is a clinical judgement rather than a convenience one.

At booking for consent concerning the service the patient has chosen, comprising service terms, data handling, cancellation arrangements and permissions. The argument set out in the patient data capture guide applies with particular force here, since a patient signing at home can actually read what they are agreeing to, whilst a patient signing at the start of an appointment with a clinician waiting is performing a formality. Capturing it at booking improves the quality of the consent, not merely its timing.

At the consultation for consent which depends on the clinical discussion itself. Consent to a specific treatment, having understood its risks, cannot meaningfully be given before the conversation that conveys them. Signing it in advance produces a record which is evidentially neat and clinically hollow, and a reviewer will notice that the consent predates the discussion it purports to follow.

The distinction is worth writing into the service design rather than deciding case by case, because the default drift is toward putting everything at booking for operational convenience.

What a pharmacy actually needs signed

DocumentWhenSeparate or combined
Service terms and cancellationBookingSeparate, since it is contractual rather than clinical
Consent to treatmentConsultationSeparate, and per treatment where treatments differ materially
Data sharing with a GPBooking or consultationSeparate, since it is withdrawn independently
Disclosure to a named third party, comprising an insurer, employer or solicitorWhen the request arisesSeparate and specific to the recipient and the scope requested
Marketing permissionBooking, unbundledAlways separate and separately revocable, per the consent rules
Photography or imagingConsultationSeparate, and only where the service genuinely uses it

The recurring error is the combined agreement, in which treatment consent, service terms and marketing permission are signed as one document. It is quicker at the point of signing and it fails the moment a patient withdraws one of them, because the service cannot honour the withdrawal without appearing to unwind the others. Marketing in particular must be separately given and separately withdrawable, which is a requirement rather than good practice, as the PECR guide sets out.

Changing wording and withdrawing consent

Three situations arise and each has a correct handling.

Minor revision. Release a new version, leave existing signatures pointing at their own version, and apply the new wording to signatures taken from the effective date forward.

Material change. Where the substance of what a patient agreed to has altered, re-consent affected patients against the new version rather than assuming the previous signature carries. The judgement about materiality is the service's, and it should be recorded, because a reviewer will ask why a change was treated as one or the other.

Withdrawal. A withdrawal is recorded as an event on the timeline rather than by deleting the original consent. The original signature remains, because it evidences what was true at the time, and the withdrawal sits after it with its own date. Deleting a consent because it has been withdrawn destroys the record of a period during which treatment was properly given.

Records patients need for insurance and other third parties

THE PATIENT WILL EVENTUALLY NEED THIS FILE, AND SO WILL SOMEBODY ELSE

Private pharmacy services tend to design their records for the regulator and forget the audience which asks more often, which is the patient themselves needing to prove something to a third party. Private medical insurers require evidence before reimbursing a claim, and what they ask for is the treatment, its clinical justification and the patient's authorisation of it. Travel and life insurers ask patients to declare treatments and then verify the declaration. Employers and occupational health services request confirmation of ongoing treatment. Solicitors request records in personal injury and clinical negligence matters. Immigration and visa processes sometimes require evidence of prescribed treatment. In every one of those, a patient returns to the pharmacy asking for their file, frequently years afterwards, and what they receive determines whether their claim succeeds. A service holding a complete signed record produces it in an afternoon. A service holding a tickbox, a regenerated consent form showing today's wording and consultation notes spread across an inbox produces something the insurer will query, and the patient experiences that as the pharmacy having failed them rather than as a records design decision made three years earlier.

Two distinct obligations sit inside that, and services regularly conflate them.

Producing records to the patient is straightforward and is their right. A patient may request their own data, and a service which can assemble the consultation record, the clinical decisions, the consents and the supply history as a coherent file has discharged it properly. The practical test is whether the file reads as a chronology to somebody who was not there, which is the same test the patient data capture guide applies to the record generally.

Disclosing records to a third party is a different act requiring its own authority, and it should never be treated as implied by the patient having asked for something. An insurer, employer or solicitor requesting records directly should be met with a request for the patient's specific written authority, and the pharmacy should disclose the minimum the request genuinely requires rather than the whole file. That authorisation is itself a consent worth capturing as a signature, with the recipient and the scope named, so that a later question about why information was released has a documented answer.

What insurers most commonly query is worth designing for directly. They ask whether the treatment was clinically indicated, which the consultation record and the prescriber's reasoning answer. They ask whether the patient consented, which the signature answers only if it carries the version of what was explained. And they ask when it was authorised relative to when it was supplied, which the timeline answers. A record built to satisfy those three questions serves the patient's claim, the regulator's inspection and any subsequent dispute with the same material, which is the practical argument for building it properly once.

How long to keep signed consent

For as long as the record it supports, which in practice means the same retention schedule as the patient record rather than a shorter one.

Consent evidences a clinical or contractual event and its usefulness arrives late, frequently years after the treatment concluded, when a question is raised about whether something was agreed. The insurance and third-party requests described above are the most common form that question takes, and they arrive on no schedule the service controls. A service which retains treatment records for the applicable period but purges consent earlier has kept the half which describes what was done and discarded the half explaining why it was permitted.

One migration point deserves emphasis. Signed consent must survive a change of system, so it belongs in any export taken before a migration and should be verified as readable afterwards, per the data export guide. A signature which exists only inside a system the pharmacy has left is not evidence it can produce.

Capacity, carers and third parties

Electronic capture makes one thing easier to get wrong, which is knowing who actually signed.

Where a form is completed remotely, the service is relying on the person at the other end being the patient. For most private services that risk is acceptable and is mitigated by the identity verification the flow already performs. Where it is not, comprising services where a proxy has an incentive, the identity step should precede the signature rather than follow it.

Three situations require the record to show more than a signature. A carer or representative signing should be identified as such, with their relationship recorded, rather than appearing as the patient. Any question about capacity belongs in the clinical record and should be addressed before consent is taken rather than documented afterwards. And a patient who cannot use the electronic route requires an alternative, which is an accessibility obligation as well as a practical one, on the reasoning in the accessibility article.

What to check before you rely on it

Seven questions, applicable to any e-signature arrangement including one built into a pharmacy system.

Does the record identify the signer against the patient record rather than only an email address? Is the timestamp stored, not merely the date? Is the version of the document recorded, and is the document retained as presented rather than regenerated? Can the record demonstrate it has not been altered since signing? Can signed consent be exported, and does it remain readable outside the system? Are separate consents captured separately so one can be withdrawn without the others? Could you assemble a complete, chronological file for a patient who needs it for an insurance claim, and do you capture specific authority before releasing anything to a third party? And is there a documented alternative for patients who cannot sign electronically?

A service which can answer all seven has consent it can rely on. A service which can answer the first two has a signature, which is not the same thing.

Key takeaways

  • Electronic signatures are generally valid for the documents a pharmacy uses, with the Electronic Communications Act 2000 providing for admissibility and the Law Commission confirming capability to satisfy statutory signature requirements, subject to additional formalities for deeds.
  • The signature is the least important part of the record, since who signed, when, which version, the document as presented and evidence of integrity are what determine whether it survives scrutiny.
  • Version the consent wording, because storing a single current document silently rewrites what every previous patient appears to have agreed to.
  • Service terms and permissions belong at booking where a patient can read them, whilst consent to treatment belongs in the consultation, since it cannot precede the discussion that informs it.
  • Capture consents separately rather than as one combined agreement, because they are withdrawn independently and marketing permission must be separately revocable.
  • Handle revision, material change and withdrawal distinctly, and record a withdrawal as an event rather than by deleting the original signature.
  • Patients need these records for insurance claims, employers and solicitors, frequently years later, and insurers ask whether treatment was indicated, whether it was consented to and when it was authorised.
  • Disclosing to a third party is a separate act needing the patient\u2019s specific written authority, disclosed to the minimum scope, and that authorisation is itself worth signing.
  • Retain signed consent for as long as the record it supports, include it in any migration export, and provide a documented alternative for patients who cannot sign electronically.

FAQs

Frequently. Private medical insurers require evidence of the treatment, its clinical justification and the patient's authorisation before reimbursing, and travel and life insurers verify declared treatments. Employers, occupational health services and solicitors request records for their own purposes. Patients return to the pharmacy asking for the file, often years later, and the completeness of what they receive can determine whether their claim succeeds.
SK
WRITTEN BY
Saqib Kamili
Technical Lead
This article is general guidance for pharmacy professionals and does not constitute legal or regulatory advice. Standards and guidance change; always check the current GPhC publications and take professional advice on your specific circumstances. Last reviewed 16 May 2026.

Consent you can actually produce.

Bring your current consent wording and we will show what a versioned signature record looks like against it. See it working, then bring us your own case and we will walk through capture at booking, the audit trail and what you would send an insurer.

See Dataforge PMR

Keep reading