Back to BlogMicrosoft 365 Tips

SharePoint Document Management for NHS UK 2026: A Practical Setup Guide

3 October 2026 6 min read
Photo by Vitaly Gariev on Unsplash
Want to build a career in IT or Microsoft 365?

Take the free IT Readiness Test and see where you stand, 10 quick questions.

Take the free test

Why SharePoint matters in NHS environments right now

If you work in an NHS trust in 2026, you've probably noticed something: paper is still everywhere, even though you have Microsoft 365. SharePoint is supposed to fix that. It doesn't, not automatically. The real problem isn't the software. It's that most NHS teams deploy SharePoint without understanding how to actually use it for document management. They end up with a dumping ground: folders within folders, duplicate files, versions nobody can track, and staff sending PDFs by email because SharePoint feels harder than the filing cabinet.

The stakes in healthcare are higher than anywhere else. Patient records, discharge summaries, risk assessments, and audit trails need to be findable, version-controlled, and compliant with GDPR, FHIR standards, and IG Toolkit requirements. When your document management fails in the NHS, people don't just waste time: compliance audits fail, confidentiality breaches happen, and patient safety can be compromised.

This guide walks you through what SharePoint document management actually looks like in an NHS trust, how to set it up properly, and how to stop it becoming a mess.

The NHS document management challenge in 2026

NHS organisations manage staggering amounts of information. A typical hospital trust might generate:

  • Patient-specific records (clinic letters, test results, imaging reports)
  • Team documentation (guidelines, protocols, training materials)
  • Administrative records (rotas, contracts, procurement files)
  • Audit and compliance files (inspection reports, risk registers)
  • Before SharePoint, this lived in filing cabinets, network drives organised by department, and email inboxes. Those systems had one advantage: people understood them instinctively. SharePoint has features those systems never had (version history, retention policies, search, role-based access), but it requires discipline to work.

    Most NHS trusts get SharePoint wrong because they treat it like a network drive: just chuck everything in and hope. That approach creates "digital filing cabinets" that are somehow even harder to navigate than the real thing.

    Core SharePoint features NHS teams actually need

    1. Site structures and document libraries

    A SharePoint site is a container. Inside, you build document libraries (folders, essentially, but with superpowers). For an NHS team, the structure might look like this:

  • Main site: Whole department or service line
  • Document libraries: Separate for patient-facing documents, internal policies, training materials, audit records
  • Folders within libraries: Organised by process, patient cohort, or time period (never by person, which causes chaos when someone leaves)
  • Example for an outpatient clinic:

  • *Patient pathways* (subspecialised by condition)
  • *Staff training* (induction, competency records)
  • *Audit and compliance* (incident reports, patient feedback)
  • *Service development* (meeting notes, change logs)
  • 2. Metadata and searchability

    This is where SharePoint wins. Instead of relying on folder names, you tag every document with metadata: author, date created, document type, patient cohort, sensitivity level. When you search for "all safeguarding alerts from Q2 2026," SharePoint finds them instantly. A network drive can't.

    For NHS use, essential metadata fields include:

  • Document type (protocol, letter, incident report, training material)
  • Sensitivity level (public, internal, confidential, restricted)
  • Date created and date last modified
  • Author and approver
  • Related patient or service area (coded, not free text, to avoid data entry chaos)
  • 3. Retention and compliance

    NHS records have legal retention timescales. Patient notes might need to be kept for seven years after discharge. Incident reports often have statutory retention periods. SharePoint retention policies automate this: when a document hits its retention trigger, it gets moved to archive or deleted according to your IG policy.

    Without this, you end up keeping everything forever (massive storage cost, compliance risk) or deleting things you shouldn't.

    4. Access and permissions

    SharePoint allows granular access control. You can give a consultant full access to their clinic's documents, a manager read-only access to archived files, and completely hide sensitive records from staff who don't need them. This is critical for GDPR compliance and patient confidentiality in the NHS.

    Common mistake: giving everyone access to everything for convenience, then worrying about confidentiality breaches later.

    How to set up SharePoint document management properly in your NHS trust

    Step 1: Audit what you have now

    Before you build anything, walk around. Talk to your teams:

  • Where do they store documents now (network drive, email, paper)?
  • What types of documents matter most?
  • Who needs access to what, and why?
  • What compliance or retention rules apply?
  • Write this down. Most NHS trusts skip this step and regret it a year later.

    Step 2: Design your site structure

    Create a single SharePoint site for your department or service line (not one per person, which defeats the purpose). Inside, create document libraries by function, not by person. Each library gets a consistent folder structure:

    ```

    Patient Pathways

    > Cardiology

    > Respiratory

    > Acute Medical

    Policies and Guidelines

    > Clinical

    > Administrative

    Audit and Compliance

    > Incident Reports

    > Audit Findings

    ```

    Step 3: Configure metadata fields

    Before anyone uploads a file, define your metadata fields. Keep them minimal: one extra field per document is fine, ten fields will be abandoned by staff. For NHS document management, these work:

  • Document type (dropdown: Protocol, Letter, Report, Training Material)
  • Sensitivity (dropdown: Public, Internal, Confidential)
  • Date created (auto-populated)
  • Next review date (for protocols and guidelines)
  • Step 4: Set retention policies and access

    Work with your Information Governance team. Define:

  • How long each document type stays active
  • When it moves to archive (if it does)
  • Who can access what
  • Who can approve/publish documents
  • Make this visible to staff. A simple poster or one-pager explaining "patient notes: keep 7 years" stops confusion.

    Step 5: Train your teams

    This is non-negotiable. SharePoint doesn't work unless people use it. Run a one-hour session for each team:

  • Where to find documents in SharePoint
  • How to upload (and why you're not using email)
  • How to search using metadata
  • What retention policy means (not exciting, but important)
  • Common mistakes and how to avoid them

    Mistake 1: Treating it like a network drive

    SharePoint is powerful because of metadata and search, not folder depth. If your folder structure goes five levels deep, you've lost the plot. Aim for three, maximum four.

    Mistake 2: Not involving Information Governance early

    GDPR, patient confidentiality, and data retention aren't afterthoughts in healthcare. Involve your IG team from day one. They'll tell you what's legally mandatory, and it'll save you a compliance audit nightmare later.

    Mistake 3: Not setting retention policies

    You'll end up with petabytes of archived patient notes and no way to manage it. Define retention from the start.

    Mistake 4: Letting everyone have different access levels

    It's tempting to give people broad access "just in case." Don't. Role-based access (everyone in this team gets these documents, everyone in that team gets those) is clearer and more secure.

    Why this matters for your career in NHS IT

    If you're considering a move into IT support or Microsoft 365 administration, understanding how healthcare organisations actually use SharePoint is a genuine advantage. NHS trusts are actively hiring people who can help them fix document management chaos. It's not glamorous, but it's real, valuable work with tangible impact.

    The Microsoft 365 Administrator Programme at SmoothOps 365 teaches you exactly these scenarios: real deployments, compliance constraints, and how to troubleshoot when users can't find documents. We run sessions every month, and the waitlist is open now. [Book a free two-hour live session] (smoothops365.com/courses/it-helpdesk#free-session) where you'll work through a real NHS-style SharePoint setup from scratch, guided by someone who's done this in a live trust.

    Frequently asked questions

    How do I stop staff uploading documents to the wrong place in SharePoint?

    Clear folder names, a one-page guide printed and pinned in the office, and a quick demo for each team usually work. You can also restrict who can create new folders (only team leads, not everyone), which forces people to use the structure you've set up. After three months, most teams instinctively know where things go.

    What happens if a patient requests their records and they're archived in SharePoint?

    Retention policies should move older records to archive, not delete them. Archive libraries stay searchable and accessible, just separate from active work. Your IG team will define retention timescales (usually seven years for active records, then archive), and you'll manage it through SharePoint retention labels.

    Can I use SharePoint for both patient records and general staff training materials?

    Yes, but in different libraries within the same site, with different access permissions and retention rules. Patient records are confidential and legally mandated retention; training materials might be public and shorter-lived. Separating them by library makes access control and compliance management much cleaner.

    How much does SharePoint cost for an NHS trust?

    SharePoint is included in Microsoft 365 subscriptions (typically £7 to £12 per user per month depending on the plan). Storage is included; excess storage beyond the plan allotment costs extra, but most trusts stay well within included limits if retention policies are working.

    What's the best way to migrate existing NHS documents into SharePoint?

    Don't do it all at once. Start with active documents (things used in the last six months), upload them with correct metadata, then archive or dispose of old versions. Trying to migrate five years of cluttered network drives causes chaos. Parallel-run the old system and SharePoint for a month while staff get comfortable, then switch over.

    Ready to start your IT career?

    SmoothOps 365 runs live instructor-led training every Saturday and Sunday. 3 months. 50 contact hours. Keep your job while you train.