The Advanced Electronic Signature (AES) system provides legally binding digital signatures for private electronic prescriptions. AES is a legal requirement under the Human Medicines Regulations 2012 (Regulation 219) for all private electronic prescriptions in the UK.
An Advanced Electronic Signature is a digital signature that is:
A standard email, password-protected PDF, scanned ink signature, or generic digital signature is legally invalid for private e-prescriptions in the UK. Only an AES meets the legal standard.
The signature uses PAdES-B-LTA (PDF Advanced Electronic Signature — Baseline — Long Term Availability), which is the EU/UK standard for long-term electronic signature validation.
| Component | Role |
|---|---|
| AES Portal | Centralised signing service; stores signature evidence; provides pharmacy list |
| AES Signer | Cryptographic signature creation service |
| AES PKI | Public Key Infrastructure — manages signing certificates |
| AES TSA | Time-Stamp Authority — provides legally valid timestamps |
| GP Booking App | Initiates signing requests; stores AES metadata with each prescription |
| Term | Meaning |
|---|---|
| AES | Advanced Electronic Signature |
| PAdES | PDF Advanced Electronic Signature |
| B-LTA | Baseline — Long Term Availability (signature remains valid for decades) |
| MFA | Multi-Factor Authentication — required to authorise each signature |
| dm+d | NHS Dictionary of Medicines and Devices — drug code reference |