Ensuring Confidentiality in Healthcare Practice
The CPD Certification Service, UK
Remediation · All UK healthcare regulators CPD Certified
Ensuring Confidentiality in Healthcare Practice
Facing a complaint or allegation about patient confidentiality? Start here.
A CPD-certified remediation course for Doctors, Dentists, Nurses, Midwives, Pharmacists
and all other Healthcare Professionals responding to a concern
raised with the GMC, GDC, NMC, GPhC, HCPC, GOC, GCC, GOsC or Social Work England. Written
for allegations about accessing records without a reason, disclosure without a basis, conversations
and records left exposed, third-party requests, and data protection breaches.
Bulk buy — any 10 courses
Instant access · certificate on completion · CPD certified
Who this course is for
For healthcare professionals whose handling of patient information has been questioned —
or who would rather check their habits before someone else does.
A complaint, investigation or allegation of a confidentiality breach
Something has been raised about how you accessed, discussed or disclosed patient information, and you are being asked to account for it — by your employer, by your regulator, or by both.
An access audit has flagged you
A record you opened without a care-related reason, sometimes months or years ago, has been picked up in a routine or triggered review.
Information reached the wrong person
An email or letter sent in error, a conversation overheard, a document left visible, or details shared with a relative who turned out not to be authorised.
You are under fitness to practice investigation
A case is open with the GMC, GDC, NMC, GPhC, HCPC, GOC, GCC, GOsC or Social Work England and you need documented CPD and written reflection to put behind your response.
An information governance investigation has started
Your employer is asking for an account of an access or a disclosure, sometimes before your regulator has heard anything about it at all.
You handle third-party requests
Police, insurers, employers, solicitors or family. You want to know what to check and what to ask for in writing before you answer, not after.
You lead a team or a service
You set the culture around access, conversations and records, and you want the habits right before an audit examines them.
The concerns this course speaks to
Confidentiality allegations are rarely about deliberate disclosure. Most begin with kindness,
curiosity or haste.
Access without a reason
Records opened out of concern or curiosity, with nothing shared and nothing intended — and an audit trail that says otherwise.
Talking where you can be heard
Corridors, lifts, receptions, open-plan offices and shared workspaces. The commonest breach of all and the least recorded.
Records left exposed
Screens unlocked, notes on a desk, documents taken home, and devices or paperwork lost in transit.
Sharing with family
Answering a distressed relative without establishing what the patient agreed to, including after the patient has died.
Third-party requests
Police, insurers, employers and solicitors — answered helpfully and promptly, but without a basis being established first.
Online and in writing
Posts, photographs and case discussions where indirect identification does the damage that no name would have done.
What the course covers
Seven sections and 15 lessons, with reflective exercises closing each of the first six sections
and a post-course assessment at the finish.
Overview of confidentiality
The key concepts in patient confidentiality, and why it underpins the trust that makes disclosure to a healthcare professional possible at all.
The rules that apply
Data protection law as it applies in UK healthcare, including GDPR and the Data Protection Act 2018, alongside the confidentiality guidance issued by the healthcare regulators.
Confidentiality in clinical practice
Practical protection of patient information day to day, and how confidentiality works within multidisciplinary and team settings where information is legitimately shared.
The difficult situations
Three lessons: handling requests for information from third parties, managing confidentiality during transitions of care, and the challenges created by electronic records and data sharing.
Breaches and consequences
The common causes of confidentiality breaches, most of them unintended, and what follows for the patient, the professional and the organisation.
Remediation
Three lessons: practical approaches to strengthening confidentiality, integrating them into daily practice, and structured reflection on your own current habits.
Conclusion and assessment
Takeaways, followed by a post-course assessment. Your certificate is issued on completion.
How this helps if a concern has been raised
Naming the basis is what a written response has to do
Almost every confidentiality response begins in the same place: that no harm was intended, that the
information went no further, that anyone would have done the same for a worried relative. Those things are
usually true. None of them is a basis, and a panel reading a response that offers good
intentions where a justification should be is reading an absence of insight rather than an explanation.
The productive route is to work out what the basis actually was, or to acknowledge plainly that there was
not one. Consent, legal requirement, public interest, or care of the patient on a need-to-know footing
— naming which applied, or conceding that none did, is what turns an account into an analysis. It
also points straight at evidence a case examiner can verify: information governance training
completed, a documented change to how you access, discuss and record, a check of your own recent access,
and supervision or countersigning where appropriate. Section 6 is built to produce exactly
that.
On completion you receive a certificate recording the course title, the CPD hours and the date —
which, with your own written reflection, is suitable for inclusion in a remediation
portfolio, an appraisal folder, a revalidation submission or a response to your regulator. For
courses written to your own regulator’s standards, see courses by regulator.
Read the guidance yourself
GMC: confidentiality and handling patient information ↗
HCPC: respect confidentiality ↗
The eight principles, in full ↗
GCC: Code of Professional Practice ↗
Ready to start?
Written for professionals answering a confidentiality concern. Instant access, 2 CPD hours, certificate on completion.
Who wrote it
Is it a breach of confidentiality if you only looked?
Yes. Accessing a patient’s information without a legitimate reason connected to their care
is a breach in itself, whether or not you shared anything with anyone. Looking up your own record,
a relative’s, a colleague’s, a former partner’s, or someone whose name you recognised
from the news are all common examples. Every modern system keeps an audit trail, so they are routinely
detected months afterwards.
The wider duty is not absolute. Disclosure can be justified where the patient consents, where the law or a
court requires it, or where it is in the public interest — and sharing with colleagues directly
involved in that patient’s care is expected, on a need-to-know basis. So the question
in a case is never whether you may ever share information. It is whether you had a basis for
this disclosure, to this person, at this time.
What these words mean
The terms a regulator will use about a confidentiality concern, and what each one means in
practice.
Patient confidentiality
The duty to protect information a patient shares in the course of their care, and to disclose it only where there is a proper basis. It exists because without it people would not disclose what clinicians need to know.
Need-to-know
The principle that access to patient information should be limited to what your role in that patient’s care actually requires. It applies within a clinical team as well as outside it.
Inappropriate access
Opening or viewing a record without a legitimate reason connected to that patient’s care. It is a breach in itself, whether or not anything is shared, and system audit trails make it detectable long afterwards.
Implied consent for direct care
The basis on which information is shared with colleagues involved in a patient’s care without asking each time: the patient has been told how their information will be used and has not objected. It covers direct care, and it does not stretch to anything else.
Indirect identification
Where details that seem harmless individually — condition, timing, department, location, an image of a setting — combine to make a patient identifiable, even though no name was used.
Public interest disclosure
Disclosure without consent that can be justified because the benefit to an individual or to society outweighs the patient’s and the public’s interest in keeping the information confidential, for example to protect someone from serious harm.
Anonymised information
Information from which a patient cannot reasonably be identified, whether directly or by combining it with something else. Where anonymised information will serve the purpose, the expectation is that you use it rather than identifiable information — which is what makes anonymisation the safest answer to most teaching, audit and research questions.
Information governance
The framework of policies, training and audit an organisation uses to control how patient information is held, accessed and shared. It is the process that generates the access log, runs the investigation and, in a serious case, makes the report to the Information Commissioner’s Office.
Remediation
The concrete steps taken so the same thing does not happen again — information governance training, changes to how you access, discuss and record, supervision, and systems fixed — with evidence they were sustained.
Looking is a breach, even if you tell nobody
The most misunderstood point in this whole subject, and one of the most frequent routes to a
referral. No disclosure is required for it to be a breach.
Access must have a reason
A reason connected to your role in that patient’s care. The system permitting you to open a record is not the same as your being entitled to.
The usual examples
Your own record. A family member’s. A colleague who was admitted. A former partner. A neighbour. Someone in the news. Almost always curiosity or concern rather than malice.
Audit trails do not forget
Access is logged, and reviews are often triggered long after the event by an unrelated complaint. A single look years ago can surface in an audit today.
Need-to-know applies inside the team too
Being part of a service does not entitle you to every record in it. The staff-room conversation about an interesting case is where a lot of careful people come unstuck.
Confidentiality is not absolute, but you need a basis
Most registrants know disclosure is sometimes permitted. Far fewer can name which basis they
were relying on, which is exactly what a written response has to do.
Consent
The patient agrees, having understood what will be shared and with whom. The most common basis and the one most often assumed rather than obtained.
Required by law
A statutory requirement or a court order. Being asked by someone official is not the same as being legally required, which is why written confirmation matters.
Public interest
Where the benefit of disclosing outweighs the patient’s and the public’s interest in confidentiality — typically to protect someone from serious harm. A judgement to be recorded at the time.
Care of the patient
Sharing with colleagues directly involved in their care, on a need-to-know basis, and consistent with what the patient has been told and has not objected to.
What the guidance actually asks of you
The GMC guidance rests on eight principles, aligned with the Caldicott principles for
information governance. Named plainly, they are the checklist a written response can be measured against.
Use the minimum you need
No more personal information than the purpose requires, and anonymised information wherever that would do the job just as well.
Protect what you hold
Personal information has to be effectively protected at all times against improper access, disclosure or loss — screens, papers, devices and conversations alike.
Know your own responsibilities
Understand information governance to the level your role actually requires. Not knowing the local rule is not treated as an answer to having broken it.
Handle information lawfully
Satisfy yourself that what you are doing has a lawful basis, rather than assuming that a system permitting it makes it lawful.
Share for direct care
Relevant information should be shared with those involved in the patient’s care, unless the patient has objected. The duty to share can matter as much as the duty to protect.
Ask for explicit consent beyond care
For anything other than the patient’s care or local clinical audit, ask for explicit consent — unless the disclosure is required by law or can be justified in the public interest.
Tell patients, and record the decision
Tell patients about disclosures they would not reasonably expect, or check they have been told. Record your decision either way, including a decision not to disclose.
Support access to their own records
Respect and help patients exercise their rights to know how their information is used and to obtain access to, or copies of, their health records.
A breach can be examined in three places at once
This is the practical thing to understand early, and the reason to take advice before
writing an account for anyone.
Your employer
An information governance or disciplinary investigation, usually the fastest moving of the three and
normally the first to ask you for an account of what you accessed and why.
Your regulator
A fitness to practice process asking whether your fitness is currently impaired — a different
question, on a different timescale, from the employer’s.
Possibly the Information Commissioner
Where a personal data breach is reportable, the organisation makes that report. It looks at the
handling of data rather than at your fitness, and it can run alongside both of the others.
And being open with the patient
Telling the person affected is a professional duty in its own right, and it runs through your
employer’s process rather than around it. What you say in one process can surface in another.
Frequently asked questions
Is it a breach if I looked at a record but never told anyone?
Yes. Accessing a patient’s information without a legitimate reason connected to their care is itself a breach, whether or not you shared anything. Looking up your own record, a relative’s, a colleague’s, a former partner’s, or someone whose name you recognised from the news are all common examples — and every modern system keeps an audit trail, so they are routinely detected months later. This is one of the most frequent confidentiality referrals and one of the most misunderstood.
I only looked at my own record, or a family member’s. Is that different?
It is not a defence, and it is one of the most common versions of this concern. Your own record is patient information held by your employer, and there is a route for requesting it that does not involve opening it yourself. A relative’s record is someone else’s information however worried you were, and their being family does not supply a reason connected to your role in their care. Employers treat self-access and family access as flags precisely because they are so frequent, and the fact that nothing was shared and no harm followed goes to seriousness rather than to whether it happened.
Which professions is this remediation course for?
All UK healthcare professionals. It is written for doctors regulated by the GMC, dentists and the dental team regulated by the GDC, nurses, midwives and nursing associates regulated by the NMC, pharmacists and pharmacy technicians regulated by the GPhC, HCPC-registered professionals, optometrists and dispensing opticians regulated by the GOC, chiropractors regulated by the GCC, osteopaths regulated by the GOsC, and social workers. Confidentiality duties are common to every regulator’s standards.
When am I allowed to disclose patient information?
Confidentiality is not absolute. Broadly, disclosure can be justified where the patient consents, where you are required to do so by law or a court order, or where it is in the public interest — for example to protect someone from a risk of serious harm. Sharing with colleagues directly involved in the patient’s care is also expected, on a need-to-know basis. The question in a case is never whether you may ever share; it is whether you had a basis for this disclosure, to this person, at this time.
Does being part of the team entitle me to see everything?
No. The need-to-know principle applies within teams as well as outside them. Access should be connected to your role in that patient’s care, and the fact that a system lets you open a record does not mean you were entitled to. Curiosity about a colleague’s admission or a case being discussed in the staff room is where a lot of otherwise careful people come unstuck.
I did not name the patient. Is that enough?
Often not. Details that look harmless on their own — the condition, the timing, the department, the location, a photograph of a setting, or the fact that people know where you work — can combine to identify someone. Indirect identification is one of the most common findings and one of the least intended, and it is the point where confidentiality and social media concerns usually meet.
Does confidentiality end when a patient dies?
No. The duty continues after death. Requests from relatives, insurers or others after a patient has died still need a basis, and the fact that someone is next of kin does not by itself entitle them to clinical information. This catches people out precisely because the situation is usually a sympathetic one.
A family member is asking me about a patient’s care. What should I do?
Establish what the patient has agreed to before you say anything, and check whether they have expressed any wishes about who should be told. Acting kindly under pressure from a distressed relative is a very common route to a breach. Where the patient lacks capacity or the situation is urgent, different considerations apply — which is exactly the kind of judgement Section 4 works through.
What about police, employers, insurers and solicitors?
Third-party requests need their own basis, and being asked by someone official is not itself one. Section 4 covers how to handle requests from third parties: what to check, what to ask for in writing, when consent is needed, when a legal requirement applies, and when to take advice before responding rather than after.
Can I use a case for teaching, an exam, a portfolio or research?
Yes, with care, and the safe route is nearly always anonymisation. Where anonymised information will serve the purpose, that is what you are expected to use. Where the material has to be identifiable, and the purpose is something other than the patient’s own care or local clinical audit, you need explicit consent unless the law requires the disclosure or it can be justified in the public interest. The trap is indirect identification: a case that carries the condition, the timing, the setting and your own workplace can identify someone to a reader who knows them, however carefully the name was left out.
Do I have to disclose to protect someone else?
Sometimes, and this is the hardest judgement on the subject. Confidentiality can be outweighed where disclosure would protect an individual or society from serious harm, and the guidance sets out a framework for disclosures made to protect patients and others. Several situations have their own detailed guidance, including a patient’s fitness to drive and reporting to the DVLA or DVA, serious communicable diseases, and gunshot and knife wounds. What matters in a case is that you identified the risk, weighed it against the patient’s interest in confidentiality, disclosed no more than was necessary, and recorded the reasoning at the time. Take advice from your indemnity provider or Caldicott Guardian where there is time to.
Should the patient be told, and does the breach have to be reported?
Usually yes to the first, and often yes to the second, but neither is a decision to take alone. Being open when something has gone wrong is a professional duty in its own right, and organisations have their own process for telling the person affected. Reporting runs through your employer’s information governance route, which is what assesses whether a personal data breach has to go to the Information Commissioner’s Office. Tell your information governance lead promptly, say what you know rather than what you have concluded, and take advice from your indemnity provider or union before you write an account for anyone.
An information governance investigation has also started. How do these fit together?
A confidentiality breach can be looked at in more than one place at once: your employer’s information governance or disciplinary process, your regulator’s fitness to practice process, and in some cases the Information Commissioner’s Office. They ask different questions on different timescales, and what you say in one can surface in another. Take advice from your indemnity provider, union or professional body before responding to any of them.
Will completing this course resolve my fitness to practice case?
No. No course, from us or from anyone else, determines the outcome of a fitness to practice matter. What a course can do is help you build the insight and reflection your response needs, and give you a verifiable certificate to evidence it. In a confidentiality case it sits alongside practical steps such as information governance training, changes to how you access and record, and supervision.
How long does it take, and is it CPD certified?
It runs to 2 CPD hours across seven sections and 15 lessons, with reflective exercises closing each of the first six sections and a post-course assessment at the end. The certificate is CPD certified by The CPD Certification Service and records the course title, the hours and the date, which is what makes it usable in an appraisal folder, a revalidation submission or a remediation portfolio. It is self-paced, and you can stop and resume.
Courses that work alongside this one
Where indirect identification does the damage. The online half of the same duty.
Privacy and consent in the consultation itself, alongside the information duty this course covers.
What you record, how you correct it, and who can see it — the other half of handling patient information.
The element assessed in almost every case, whatever the allegation, and the one most often described as lacking.
How to write reflection that reads as understanding rather than regret, in your own words.
Turning insight into concrete, evidenced change that a panel can see actually happened.
What fitness to practice means, how the process works, and what is being assessed at each stage.
Restoring confidence after a concern — with patients, with colleagues and with the regulator.
This course. Access, disclosure, third-party requests and data protection — and the evidenced
remediation that answers a confidentiality concern.
You are here
Find courses written to your own regulator’s standards →
Start your remediation today, finish at your own pace
Instant access on purchase. Certificate on completion, CPD certified by The CPD Certification Service.
by any UK healthcare regulator. This course covers professional standards and the handling of patient
information. No course determines the outcome of a fitness to practice case. This is not legal, data
protection or regulatory advice — if a confidentiality concern has been raised about you, and
particularly where an information governance investigation or a data protection matter may also be involved,
take advice from your indemnity provider, defence organisation, union or professional body before responding
to anyone.