Skip to content

November 10, 2024

Ensuring Confidentiality in Healthcare Practice

Current Status
Not Enrolled
Price
£79.00
Get Started


 

The CPD Certification Service member logoCPD-AccreditedCertified by
The CPD Certification Service, UK

Remediation · All UK healthcare regulators CPD Certified

Ensuring Confidentiality in Healthcare Practice

Facing a complaint or allegation about patient confidentiality? Start here.
A CPD-certified remediation course for Doctors, Dentists, Nurses, Midwives, Pharmacists
and all other Healthcare Professionals responding to a concern
raised with the GMC, GDC, NMC, GPhC, HCPC, GOC, GCC, GOsC or Social Work England. Written
for allegations about accessing records without a reason, disclosure without a basis, conversations
and records left exposed, third-party requests, and data protection breaches
.

2CPD hours
7Sections
15Lessons
£79One-off
Buy this course — £79
Bulk buy — any 10 courses
Instant access · certificate on completion · CPD certified
Instant access
Certificate on completion
CPD certified
CPD Provider No. 13197

Who this course is for

For healthcare professionals whose handling of patient information has been questioned —
or who would rather check their habits before someone else does.

A complaint, investigation or allegation of a confidentiality breach

Something has been raised about how you accessed, discussed or disclosed patient information, and you are being asked to account for it — by your employer, by your regulator, or by both.

An access audit has flagged you

A record you opened without a care-related reason, sometimes months or years ago, has been picked up in a routine or triggered review.

Information reached the wrong person

An email or letter sent in error, a conversation overheard, a document left visible, or details shared with a relative who turned out not to be authorised.

You are under fitness to practice investigation

A case is open with the GMC, GDC, NMC, GPhC, HCPC, GOC, GCC, GOsC or Social Work England and you need documented CPD and written reflection to put behind your response.

An information governance investigation has started

Your employer is asking for an account of an access or a disclosure, sometimes before your regulator has heard anything about it at all.

You handle third-party requests

Police, insurers, employers, solicitors or family. You want to know what to check and what to ask for in writing before you answer, not after.

You lead a team or a service

You set the culture around access, conversations and records, and you want the habits right before an audit examines them.

The concerns this course speaks to

Confidentiality allegations are rarely about deliberate disclosure. Most begin with kindness,
curiosity or haste.

Access without a reason

Records opened out of concern or curiosity, with nothing shared and nothing intended — and an audit trail that says otherwise.

Talking where you can be heard

Corridors, lifts, receptions, open-plan offices and shared workspaces. The commonest breach of all and the least recorded.

Records left exposed

Screens unlocked, notes on a desk, documents taken home, and devices or paperwork lost in transit.

Sharing with family

Answering a distressed relative without establishing what the patient agreed to, including after the patient has died.

Third-party requests

Police, insurers, employers and solicitors — answered helpfully and promptly, but without a basis being established first.

Online and in writing

Posts, photographs and case discussions where indirect identification does the damage that no name would have done.

What the course covers

Seven sections and 15 lessons, with reflective exercises closing each of the first six sections
and a post-course assessment at the finish.

01

Overview of confidentiality

The key concepts in patient confidentiality, and why it underpins the trust that makes disclosure to a healthcare professional possible at all.

02

The rules that apply

Data protection law as it applies in UK healthcare, including GDPR and the Data Protection Act 2018, alongside the confidentiality guidance issued by the healthcare regulators.

03

Confidentiality in clinical practice

Practical protection of patient information day to day, and how confidentiality works within multidisciplinary and team settings where information is legitimately shared.

04

The difficult situations

Three lessons: handling requests for information from third parties, managing confidentiality during transitions of care, and the challenges created by electronic records and data sharing.

05

Breaches and consequences

The common causes of confidentiality breaches, most of them unintended, and what follows for the patient, the professional and the organisation.

06

Remediation

Three lessons: practical approaches to strengthening confidentiality, integrating them into daily practice, and structured reflection on your own current habits.

07

Conclusion and assessment

Takeaways, followed by a post-course assessment. Your certificate is issued on completion.

How this helps if a concern has been raised

Naming the basis is what a written response has to do

Almost every confidentiality response begins in the same place: that no harm was intended, that the
information went no further, that anyone would have done the same for a worried relative. Those things are
usually true. None of them is a basis, and a panel reading a response that offers good
intentions where a justification should be is reading an absence of insight rather than an explanation.

The productive route is to work out what the basis actually was, or to acknowledge plainly that there was
not one. Consent, legal requirement, public interest, or care of the patient on a need-to-know footing
— naming which applied, or conceding that none did, is what turns an account into an analysis. It
also points straight at evidence a case examiner can verify: information governance training
completed, a documented change to how you access, discuss and record, a check of your own recent access,
and supervision or countersigning where appropriate
. Section 6 is built to produce exactly
that.

On completion you receive a certificate recording the course title, the CPD hours and the date —
which, with your own written reflection, is suitable for inclusion in a remediation
portfolio
, an appraisal folder, a revalidation submission or a response to your regulator. For
courses written to your own regulator’s standards, see courses by regulator.

Read the guidance yourself
GMC: confidentiality and handling patient information ↗
HCPC: respect confidentiality ↗
The eight principles, in full ↗
GCC: Code of Professional Practice ↗

Ready to start?
Written for professionals answering a confidentiality concern. Instant access, 2 CPD hours, certificate on completion.

Buy this course — £79

Who wrote it

Dr Shehzad Iqbal, course facilitator and author at Probity & Ethics

Dr Shehzad Iqbal

Course facilitator and author, Probity & Ethics

Dr Iqbal has designed and delivered ethics, probity and professionalism training for UK healthcare
professionals since 2020, working with registrants of all nine UK healthcare regulators, online and face
to face. He combines clinical practice with formal postgraduate training in healthcare law and
ethics.

MBBS · MRCS · MRCGP · Postgraduate Certificate in Healthcare Law and
Ethics, University of Dundee

Written and reviewed by Dr Shehzad Iqbal. Last reviewed
.

Is it a breach of confidentiality if you only looked?

Yes. Accessing a patient’s information without a legitimate reason connected to their care
is a breach in itself
, whether or not you shared anything with anyone. Looking up your own record,
a relative’s, a colleague’s, a former partner’s, or someone whose name you recognised
from the news are all common examples. Every modern system keeps an audit trail, so they are routinely
detected months afterwards.

The wider duty is not absolute. Disclosure can be justified where the patient consents, where the law or a
court requires it, or where it is in the public interest — and sharing with colleagues directly
involved in that patient’s care is expected, on a need-to-know basis. So the question
in a case is never whether you may ever share information. It is whether you had a basis for
this disclosure, to this person, at this time.

What these words mean

The terms a regulator will use about a confidentiality concern, and what each one means in
practice.

Patient confidentiality

The duty to protect information a patient shares in the course of their care, and to disclose it only where there is a proper basis. It exists because without it people would not disclose what clinicians need to know.

Need-to-know

The principle that access to patient information should be limited to what your role in that patient’s care actually requires. It applies within a clinical team as well as outside it.

Inappropriate access

Opening or viewing a record without a legitimate reason connected to that patient’s care. It is a breach in itself, whether or not anything is shared, and system audit trails make it detectable long afterwards.

Implied consent for direct care

The basis on which information is shared with colleagues involved in a patient’s care without asking each time: the patient has been told how their information will be used and has not objected. It covers direct care, and it does not stretch to anything else.

Indirect identification

Where details that seem harmless individually — condition, timing, department, location, an image of a setting — combine to make a patient identifiable, even though no name was used.

Public interest disclosure

Disclosure without consent that can be justified because the benefit to an individual or to society outweighs the patient’s and the public’s interest in keeping the information confidential, for example to protect someone from serious harm.

Anonymised information

Information from which a patient cannot reasonably be identified, whether directly or by combining it with something else. Where anonymised information will serve the purpose, the expectation is that you use it rather than identifiable information — which is what makes anonymisation the safest answer to most teaching, audit and research questions.

Information governance

The framework of policies, training and audit an organisation uses to control how patient information is held, accessed and shared. It is the process that generates the access log, runs the investigation and, in a serious case, makes the report to the Information Commissioner’s Office.

Remediation

The concrete steps taken so the same thing does not happen again — information governance training, changes to how you access, discuss and record, supervision, and systems fixed — with evidence they were sustained.

Looking is a breach, even if you tell nobody

The most misunderstood point in this whole subject, and one of the most frequent routes to a
referral. No disclosure is required for it to be a breach.

Access must have a reason

A reason connected to your role in that patient’s care. The system permitting you to open a record is not the same as your being entitled to.

The usual examples

Your own record. A family member’s. A colleague who was admitted. A former partner. A neighbour. Someone in the news. Almost always curiosity or concern rather than malice.

Audit trails do not forget

Access is logged, and reviews are often triggered long after the event by an unrelated complaint. A single look years ago can surface in an audit today.

Need-to-know applies inside the team too

Being part of a service does not entitle you to every record in it. The staff-room conversation about an interesting case is where a lot of careful people come unstuck.

Confidentiality is not absolute, but you need a basis

Most registrants know disclosure is sometimes permitted. Far fewer can name which basis they
were relying on, which is exactly what a written response has to do.

Consent

The patient agrees, having understood what will be shared and with whom. The most common basis and the one most often assumed rather than obtained.

Required by law

A statutory requirement or a court order. Being asked by someone official is not the same as being legally required, which is why written confirmation matters.

Public interest

Where the benefit of disclosing outweighs the patient’s and the public’s interest in confidentiality — typically to protect someone from serious harm. A judgement to be recorded at the time.

Care of the patient

Sharing with colleagues directly involved in their care, on a need-to-know basis, and consistent with what the patient has been told and has not objected to.

What the guidance actually asks of you

The GMC guidance rests on eight principles, aligned with the Caldicott principles for
information governance. Named plainly, they are the checklist a written response can be measured against.

01

Use the minimum you need

No more personal information than the purpose requires, and anonymised information wherever that would do the job just as well.

02

Protect what you hold

Personal information has to be effectively protected at all times against improper access, disclosure or loss — screens, papers, devices and conversations alike.

03

Know your own responsibilities

Understand information governance to the level your role actually requires. Not knowing the local rule is not treated as an answer to having broken it.

04

Handle information lawfully

Satisfy yourself that what you are doing has a lawful basis, rather than assuming that a system permitting it makes it lawful.

05

Share for direct care

Relevant information should be shared with those involved in the patient’s care, unless the patient has objected. The duty to share can matter as much as the duty to protect.

06

Ask for explicit consent beyond care

For anything other than the patient’s care or local clinical audit, ask for explicit consent — unless the disclosure is required by law or can be justified in the public interest.

07

Tell patients, and record the decision

Tell patients about disclosures they would not reasonably expect, or check they have been told. Record your decision either way, including a decision not to disclose.

08

Support access to their own records

Respect and help patients exercise their rights to know how their information is used and to obtain access to, or copies of, their health records.

A breach can be examined in three places at once

This is the practical thing to understand early, and the reason to take advice before
writing an account for anyone.

01

Your employer

An information governance or disciplinary investigation, usually the fastest moving of the three and
normally the first to ask you for an account of what you accessed and why.

02

Your regulator

A fitness to practice process asking whether your fitness is currently impaired — a different
question, on a different timescale, from the employer’s.

03

Possibly the Information Commissioner

Where a personal data breach is reportable, the organisation makes that report. It looks at the
handling of data rather than at your fitness, and it can run alongside both of the others.

04

And being open with the patient

Telling the person affected is a professional duty in its own right, and it runs through your
employer’s process rather than around it. What you say in one process can surface in another.

Frequently asked questions

Is it a breach if I looked at a record but never told anyone?

Yes. Accessing a patient’s information without a legitimate reason connected to their care is itself a breach, whether or not you shared anything. Looking up your own record, a relative’s, a colleague’s, a former partner’s, or someone whose name you recognised from the news are all common examples — and every modern system keeps an audit trail, so they are routinely detected months later. This is one of the most frequent confidentiality referrals and one of the most misunderstood.

I only looked at my own record, or a family member’s. Is that different?

It is not a defence, and it is one of the most common versions of this concern. Your own record is patient information held by your employer, and there is a route for requesting it that does not involve opening it yourself. A relative’s record is someone else’s information however worried you were, and their being family does not supply a reason connected to your role in their care. Employers treat self-access and family access as flags precisely because they are so frequent, and the fact that nothing was shared and no harm followed goes to seriousness rather than to whether it happened.

Which professions is this remediation course for?

All UK healthcare professionals. It is written for doctors regulated by the GMC, dentists and the dental team regulated by the GDC, nurses, midwives and nursing associates regulated by the NMC, pharmacists and pharmacy technicians regulated by the GPhC, HCPC-registered professionals, optometrists and dispensing opticians regulated by the GOC, chiropractors regulated by the GCC, osteopaths regulated by the GOsC, and social workers. Confidentiality duties are common to every regulator’s standards.

When am I allowed to disclose patient information?

Confidentiality is not absolute. Broadly, disclosure can be justified where the patient consents, where you are required to do so by law or a court order, or where it is in the public interest — for example to protect someone from a risk of serious harm. Sharing with colleagues directly involved in the patient’s care is also expected, on a need-to-know basis. The question in a case is never whether you may ever share; it is whether you had a basis for this disclosure, to this person, at this time.

Does being part of the team entitle me to see everything?

No. The need-to-know principle applies within teams as well as outside them. Access should be connected to your role in that patient’s care, and the fact that a system lets you open a record does not mean you were entitled to. Curiosity about a colleague’s admission or a case being discussed in the staff room is where a lot of otherwise careful people come unstuck.

I did not name the patient. Is that enough?

Often not. Details that look harmless on their own — the condition, the timing, the department, the location, a photograph of a setting, or the fact that people know where you work — can combine to identify someone. Indirect identification is one of the most common findings and one of the least intended, and it is the point where confidentiality and social media concerns usually meet.

Does confidentiality end when a patient dies?

No. The duty continues after death. Requests from relatives, insurers or others after a patient has died still need a basis, and the fact that someone is next of kin does not by itself entitle them to clinical information. This catches people out precisely because the situation is usually a sympathetic one.

A family member is asking me about a patient’s care. What should I do?

Establish what the patient has agreed to before you say anything, and check whether they have expressed any wishes about who should be told. Acting kindly under pressure from a distressed relative is a very common route to a breach. Where the patient lacks capacity or the situation is urgent, different considerations apply — which is exactly the kind of judgement Section 4 works through.

What about police, employers, insurers and solicitors?

Third-party requests need their own basis, and being asked by someone official is not itself one. Section 4 covers how to handle requests from third parties: what to check, what to ask for in writing, when consent is needed, when a legal requirement applies, and when to take advice before responding rather than after.

Can I use a case for teaching, an exam, a portfolio or research?

Yes, with care, and the safe route is nearly always anonymisation. Where anonymised information will serve the purpose, that is what you are expected to use. Where the material has to be identifiable, and the purpose is something other than the patient’s own care or local clinical audit, you need explicit consent unless the law requires the disclosure or it can be justified in the public interest. The trap is indirect identification: a case that carries the condition, the timing, the setting and your own workplace can identify someone to a reader who knows them, however carefully the name was left out.

Do I have to disclose to protect someone else?

Sometimes, and this is the hardest judgement on the subject. Confidentiality can be outweighed where disclosure would protect an individual or society from serious harm, and the guidance sets out a framework for disclosures made to protect patients and others. Several situations have their own detailed guidance, including a patient’s fitness to drive and reporting to the DVLA or DVA, serious communicable diseases, and gunshot and knife wounds. What matters in a case is that you identified the risk, weighed it against the patient’s interest in confidentiality, disclosed no more than was necessary, and recorded the reasoning at the time. Take advice from your indemnity provider or Caldicott Guardian where there is time to.

Should the patient be told, and does the breach have to be reported?

Usually yes to the first, and often yes to the second, but neither is a decision to take alone. Being open when something has gone wrong is a professional duty in its own right, and organisations have their own process for telling the person affected. Reporting runs through your employer’s information governance route, which is what assesses whether a personal data breach has to go to the Information Commissioner’s Office. Tell your information governance lead promptly, say what you know rather than what you have concluded, and take advice from your indemnity provider or union before you write an account for anyone.

An information governance investigation has also started. How do these fit together?

A confidentiality breach can be looked at in more than one place at once: your employer’s information governance or disciplinary process, your regulator’s fitness to practice process, and in some cases the Information Commissioner’s Office. They ask different questions on different timescales, and what you say in one can surface in another. Take advice from your indemnity provider, union or professional body before responding to any of them.

Will completing this course resolve my fitness to practice case?

No. No course, from us or from anyone else, determines the outcome of a fitness to practice matter. What a course can do is help you build the insight and reflection your response needs, and give you a verifiable certificate to evidence it. In a confidentiality case it sits alongside practical steps such as information governance training, changes to how you access and record, and supervision.

How long does it take, and is it CPD certified?

It runs to 2 CPD hours across seven sections and 15 lessons, with reflective exercises closing each of the first six sections and a post-course assessment at the end. The certificate is CPD certified by The CPD Certification Service and records the course title, the hours and the date, which is what makes it usable in an appraisal folder, a revalidation submission or a remediation portfolio. It is self-paced, and you can stop and resume.

Professionalism & Boundaries in Use of Social Media

Where indirect identification does the damage. The online half of the same duty.

2 CPD hours · £79
Add to basket
Privacy, Consent, and Chaperone in Healthcare Practice

Privacy and consent in the consultation itself, alongside the information duty this course covers.

2 CPD hours · £79
Add to basket
Professionalism in Documentation

What you record, how you correct it, and who can see it — the other half of handling patient information.

2 CPD hours · £79
Add to basket
Module on Insight

The element assessed in almost every case, whatever the allegation, and the one most often described as lacking.

1.5 CPD hours · £49
Add to basket
Module on Reflection

How to write reflection that reads as understanding rather than regret, in your own words.

1.5 CPD hours · £49
Add to basket
Module on Remediation

Turning insight into concrete, evidenced change that a panel can see actually happened.

1.5 CPD hours · £49
Add to basket
Fitness to Practice for Healthcare Professionals

What fitness to practice means, how the process works, and what is being assessed at each stage.

2 CPD hours · £79
Add to basket
Rebuilding Trust of Patients, Public, and Healthcare Regulator

Restoring confidence after a concern — with patients, with colleagues and with the regulator.

2 CPD hours · £79
Add to basket
Ensuring Confidentiality in Healthcare Practice

This course. Access, disclosure, third-party requests and data protection — and the evidenced
remediation that answers a confidentiality concern.

2 CPD hours · £79
You are here

Find courses written to your own regulator’s standards →

Start your remediation today, finish at your own pace

Instant access on purchase. Certificate on completion, CPD certified by The CPD Certification Service.

Buy this course — £79
Bulk buy — any 10 courses

Probity & Ethics is an independent CPD provider. We are not affiliated with, accredited by, or endorsed
by any UK healthcare regulator. This course covers professional standards and the handling of patient
information. No course determines the outcome of a fitness to practice case. This is not legal, data
protection or regulatory advice — if a confidentiality concern has been raised about you, and
particularly where an information governance investigation or a data protection matter may also be involved,
take advice from your indemnity provider, defence organisation, union or professional body before responding
to anyone.

Course Content