us

216.73.216.229

Back
Blogs

Know Your Patient Process Explained [Under the GPhC’s guidance]

Know Your Patient Process Explained [Under the GPhC’s guidance]
Richard M. AUGUST 28, 2020 9 minutes read

How do you make sure that a patient qualifies to buy a restricted medicine? Or that someone requesting the results of a blood test online is who they claim to be?

Know Your Patient (KYP) is the process that verifies the identity of patients. This article covers how your business can carry it out, and the use cases that may apply to your healthcare business.

What is Know Your Patient (KYP)?

Ever wondered why doctors and medical offices ask patients to show identification?

Know Your Patient is identity verification applied to healthcare, confirming that the person ordering a restricted medicine or requesting a test result is who they claim to be. This also makes sure that only the right person has access to sensitive medical records and avoids unauthorized personnel from knowing about vulnerabilities of a person.

Medical staff need to know who they are treating, much as a bank runs know your customer checks when someone applies for a loan or opens an account.

Hospitals require credentials from patients for several reasons, including securing medical data, preventing health insurance fraud and protecting the patient’s identity.

Digital identity verification in healthcare does real work here.

The General Pharmaceutical Council (GPhC) of the UK publishes guidance for registered pharmacies providing pharmacy services at a distance, including on the internet. The current version was issued in February 2025, replacing the 2019 edition. It was updated in response to concerns about inappropriate supplies of medicines, including those used for weight management.

The 2025 update focuses on the consultation rather than on the checkout. Pharmacies are expected to verify the information a person provides in an initial questionnaire rather than accept it at face value, and to enable two-way communication between that person and the prescriber. Identity is part of that picture, because verifying what someone has told you is difficult if you cannot establish who they are.

So how do you confirm that an online order for diabetes medicine was placed by someone holding an authentic prescription from a qualified doctor? Online identity verification addresses that problem. KYP looks like a restriction on drug stores, but it also benefits healthcare providers by protecting patient data.

KYP protects both patients and healthcare providers. It is not only patients who need to demonstrate credentials before buying. ID verification for pharmaceutical businesses is also required. Identity theft is not confined to financial services and ecommerce. Healthcare is a primary target too.

Requirements for ID verification in pharmaceuticals are getting stricter worldwide as a result.

KYC, KYP and Age Assurance are not the Same Check

The three get used interchangeably, and they answer different questions. Confusing them is how a pharmacy ends up with a check that satisfies nobody.

KYC KYP Age Assurance
Question it answers Who is this customer, and are they a financial crime risk? Is this the patient the record belongs to? Is this person old enough?
What triggers it Opening an account or crossing a transaction threshold Requesting a restricted medicine, a prescription or a test result Access to an age restricted product or service
Who sets the rule Financial regulators and AML law Health and pharmacy regulators, in the UK the GPhC Sector rules, plus online safety regulation for online content
Data collected Identity, address, source of funds, screening results Identity, and the link between the person and the clinical record The minimum needed to establish age, often nothing more
Re-verification Periodically, on a risk-based cycle At each request for a restricted supply or sensitive record Per session or per purchase
Cost of failure Fines and enforcement action Patient harm, data breach, fitness-to-practise consequences Regulatory penalty and reputational damage


One point on the third column. The standard the UK now expects of an age check has moved. Ofcom’s highly effective age assurance duties came into force on 25 July 2025 under the Online Safety Act, with penalties reaching £18 million or 10 per cent of global turnover. Those duties apply to services carrying pornographic and other harmful content, not to online pharmacies, so they are not what obliges a pharmacy to check age. What they have done is settle the question of whether a self-declared date of birth counts as an age check. It does not.

Digital ID Verification for Pharmaceuticals in the United Kingdom

Pharmaceutical services hold extremely personal and sensitive data, which is what makes identity verification necessary rather than optional.

Pharmacy services need to confirm patient identity before supplying medicines that health regulators have restricted.

Verifying customers can look like a burden on a hospital dispensary. In practice a digital check returns in under three seconds, though not every provider delivers the same quality.

Healthcare providers need trusted identity data for real-time verification.

How to Verify Patient Identity?

Patient identifiers support the KYP process. With tools such as face verification or document verification, pharmacies can capture unique features and patient data. That confirms the person is who they claim to be, and establishes a legitimate request for medicine or for test results.

Verifying patient identity also prevents fraud and the misuse of stolen medical data.

ID verification for Pharmacies

Pharmacists need a licence to operate and sell medicine, so this runs in both directions. A genuine patient who arrives at an unlicensed pharmacy can have their data misused. Age verification is often the first step.

Verifying patient age works much like the age verification used by online gaming and other age-sensitive sectors. Depending on the region, there are several ways patient verification helps pharmacies meet their compliance requirements.

Use Cases

KYP has several use cases that protect patient identity and help healthcare businesses confirm they are releasing medical test results to the rightful owner of that information.

Age Verification for Online Prescriptions

How do you establish the age of a person standing in a pharmacy, or ordering online? The GPhC guidance expects pharmacies supplying at a distance to satisfy themselves about who they are dealing with and to verify what that person has told them, rather than relying on the answers alone. Where a medicine carries an age restriction, checking age against a government-issued identity document is the practical way to do that.

Preventing Insurance Fraud

When a patient’s data is compromised, an identity thief can claim falsely using the health insurance ID. The fraudster takes the benefit, and the real claimant is left trying to prove they did not.

What are the Procedures to Verify Patient Identity?

The Know Your Patient process resembles standard identity verification. Businesses use it to open an account or to confirm the identity of someone who has ordered medicine online.

The KYP steps are:

  1. The patient uploads a picture of a government-issued identity document such as a driving licence, passport or national ID card, using a smartphone or webcam.
  2. They then capture a live selfie. Liveness checks confirm a real person is present rather than a photograph, a replayed video or a generated face, which is what makes the rest of the check meaningful.
  3. Verify that the ID document is real, valid and unaltered, and match the person in the selfie against the picture on the document.
  4. Confirm the patient meets the minimum age requirement. A background check on the document can also show whether it has been involved in fraudulent activity.
  5. Using the results of the four steps above, hospitals, pharmacies and medical offices accept or reject the request for a new online account and any supply order.

Everything collected in those five steps is health-adjacent personal data, so UK GDPR applies to all of it. Lawful basis, retention period and processing location are part of the same design decision as the check itself, and a verification flow that keeps document images indefinitely creates a new liability while closing an old one.

Ongoing KYP with Biometric Authentication

After the initial screening, pharmacies and clinics can accept or reject future requests for online purchases from a selfie alone.

The process is straightforward. At account creation, a biometric template of the person’s face is captured through face verification.

Every time the patient requests an online purchase or a set of test results, they send a live selfie.

That selfie is matched against the template captured at enrolment, with liveness and presentation attack detection running on the new capture. The match is what identifies the patient. The liveness check is what stops a photograph or a generated face from standing in for them, and it is the part worth asking any vendor about, along with the independent testing they have been through.

Regulation for medical facilities and pharmacies continues to tighten, and remote supply is where the scrutiny concentrates. Getting identity right is what lets a pharmacy operate at a distance without lowering the standard of care it would apply across a counter.

How patient verification would fit your dispensing flow in a 20-minute demo.

Frequently Asked Questions

Is Know Your Patient a legal requirement in the UK?

There is no statute called Know Your Patient. What exists is regulatory guidance, and for pharmacies supplying at a distance that is the GPhC's guidance, updated in February 2025. It expects a pharmacy to satisfy itself about who it is dealing with and to verify the information a person supplies rather than accept it. KYP is the industry's name for how that gets done in practice.

What ID documents can a patient use?

A government-issued photo document, usually a passport, driving licence or national ID card. Coverage extends to more than 10,000 document types across 240+ countries and territories, though the accepted list for any given service is set by the pharmacy or provider, not by the verification vendor.

How long does patient identity verification take?

Under three seconds for the automated check, covering document authenticity, data extraction and the biometric match against a live selfie. Cases the system flags go to manual review and take longer, which is the intended behaviour rather than a failure.

How is patient data protected under UK GDPR?

Identity data collected in a healthcare context sits close to health data, which carries additional protection. The practical requirements are a lawful basis for processing, collecting no more than the check needs, a defined retention period rather than indefinite storage, and knowing where the data is processed. A verification provider should be able to answer all four in writing.

Can a patient be verified without a document?

Sometimes. Database and registry checks can confirm an identity without a document image, and a returning patient can be authenticated biometrically against the template captured at enrolment. The first verification usually still needs a document, because that is what establishes the identity everything afterwards is matched against.

Disclaimer: The views and opinions expressed on this webpage or weblink are those of the author only, and are not necessarily the views or opinions of Shufti Pro Limited. The material and information on this weblink is solely for general information purposes. You should not rely upon the material or information on the website as a basis for making any business or legal decision.

While we endeavor to keep the information up-to-date and/or correct, we make no representations or warranties of any kind, express or implied, or for any purpose about the completeness, accuracy, reliability, suitability, or availability of the contents or information herein. Any reliance on its content is thus entirely at your own risk.

For the avoidance of doubt, Shufti Pro Limited will not be liable for any false, inaccurate, inappropriate, or incomplete information presented herein, and all liabilities with respect to actions taken, or not taken, based on the contents or information herein, or for any loss sustained by you as a consequence are hereby expressly disclaimed by us.

Join the
Shufti Sphere Newsletter

Get the latest trends, insights, and expert opinions on KYC, AML, fraud prevention, and more, straight to your inbox.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.