Take the free IT Readiness Test and see where you stand, 10 quick questions.
If you work in an NHS trust in 2026, you've probably noticed something: paper is still everywhere, even though you have Microsoft 365. SharePoint is supposed to fix that. It doesn't, not automatically. The real problem isn't the software. It's that most NHS teams deploy SharePoint without understanding how to actually use it for document management. They end up with a dumping ground: folders within folders, duplicate files, versions nobody can track, and staff sending PDFs by email because SharePoint feels harder than the filing cabinet.
The stakes in healthcare are higher than anywhere else. Patient records, discharge summaries, risk assessments, and audit trails need to be findable, version-controlled, and compliant with GDPR, FHIR standards, and IG Toolkit requirements. When your document management fails in the NHS, people don't just waste time: compliance audits fail, confidentiality breaches happen, and patient safety can be compromised.
This guide walks you through what SharePoint document management actually looks like in an NHS trust, how to set it up properly, and how to stop it becoming a mess.
NHS organisations manage staggering amounts of information. A typical hospital trust might generate:
Before SharePoint, this lived in filing cabinets, network drives organised by department, and email inboxes. Those systems had one advantage: people understood them instinctively. SharePoint has features those systems never had (version history, retention policies, search, role-based access), but it requires discipline to work.
Most NHS trusts get SharePoint wrong because they treat it like a network drive: just chuck everything in and hope. That approach creates "digital filing cabinets" that are somehow even harder to navigate than the real thing.
A SharePoint site is a container. Inside, you build document libraries (folders, essentially, but with superpowers). For an NHS team, the structure might look like this:
Example for an outpatient clinic:
This is where SharePoint wins. Instead of relying on folder names, you tag every document with metadata: author, date created, document type, patient cohort, sensitivity level. When you search for "all safeguarding alerts from Q2 2026," SharePoint finds them instantly. A network drive can't.
For NHS use, essential metadata fields include:
NHS records have legal retention timescales. Patient notes might need to be kept for seven years after discharge. Incident reports often have statutory retention periods. SharePoint retention policies automate this: when a document hits its retention trigger, it gets moved to archive or deleted according to your IG policy.
Without this, you end up keeping everything forever (massive storage cost, compliance risk) or deleting things you shouldn't.
SharePoint allows granular access control. You can give a consultant full access to their clinic's documents, a manager read-only access to archived files, and completely hide sensitive records from staff who don't need them. This is critical for GDPR compliance and patient confidentiality in the NHS.
Common mistake: giving everyone access to everything for convenience, then worrying about confidentiality breaches later.
Before you build anything, walk around. Talk to your teams:
Write this down. Most NHS trusts skip this step and regret it a year later.
Create a single SharePoint site for your department or service line (not one per person, which defeats the purpose). Inside, create document libraries by function, not by person. Each library gets a consistent folder structure:
```
Patient Pathways
> Cardiology
> Respiratory
> Acute Medical
Policies and Guidelines
> Clinical
> Administrative
Audit and Compliance
> Incident Reports
> Audit Findings
```
Before anyone uploads a file, define your metadata fields. Keep them minimal: one extra field per document is fine, ten fields will be abandoned by staff. For NHS document management, these work:
Work with your Information Governance team. Define:
Make this visible to staff. A simple poster or one-pager explaining "patient notes: keep 7 years" stops confusion.
This is non-negotiable. SharePoint doesn't work unless people use it. Run a one-hour session for each team:
Mistake 1: Treating it like a network drive
SharePoint is powerful because of metadata and search, not folder depth. If your folder structure goes five levels deep, you've lost the plot. Aim for three, maximum four.
Mistake 2: Not involving Information Governance early
GDPR, patient confidentiality, and data retention aren't afterthoughts in healthcare. Involve your IG team from day one. They'll tell you what's legally mandatory, and it'll save you a compliance audit nightmare later.
Mistake 3: Not setting retention policies
You'll end up with petabytes of archived patient notes and no way to manage it. Define retention from the start.
Mistake 4: Letting everyone have different access levels
It's tempting to give people broad access "just in case." Don't. Role-based access (everyone in this team gets these documents, everyone in that team gets those) is clearer and more secure.
If you're considering a move into IT support or Microsoft 365 administration, understanding how healthcare organisations actually use SharePoint is a genuine advantage. NHS trusts are actively hiring people who can help them fix document management chaos. It's not glamorous, but it's real, valuable work with tangible impact.
The Microsoft 365 Administrator Programme at SmoothOps 365 teaches you exactly these scenarios: real deployments, compliance constraints, and how to troubleshoot when users can't find documents. We run sessions every month, and the waitlist is open now. [Book a free two-hour live session] (smoothops365.com/courses/it-helpdesk#free-session) where you'll work through a real NHS-style SharePoint setup from scratch, guided by someone who's done this in a live trust.
Clear folder names, a one-page guide printed and pinned in the office, and a quick demo for each team usually work. You can also restrict who can create new folders (only team leads, not everyone), which forces people to use the structure you've set up. After three months, most teams instinctively know where things go.
Retention policies should move older records to archive, not delete them. Archive libraries stay searchable and accessible, just separate from active work. Your IG team will define retention timescales (usually seven years for active records, then archive), and you'll manage it through SharePoint retention labels.
Yes, but in different libraries within the same site, with different access permissions and retention rules. Patient records are confidential and legally mandated retention; training materials might be public and shorter-lived. Separating them by library makes access control and compliance management much cleaner.
SharePoint is included in Microsoft 365 subscriptions (typically £7 to £12 per user per month depending on the plan). Storage is included; excess storage beyond the plan allotment costs extra, but most trusts stay well within included limits if retention policies are working.
Don't do it all at once. Start with active documents (things used in the last six months), upload them with correct metadata, then archive or dispose of old versions. Trying to migrate five years of cluttered network drives causes chaos. Parallel-run the old system and SharePoint for a month while staff get comfortable, then switch over.
SmoothOps 365 runs live instructor-led training every Saturday and Sunday. 3 months. 50 contact hours. Keep your job while you train.