Confidentiality

Confidentiality is a fundamental principle of medical practice and a legal obligation, requiring that patient information is kept private and only shared with consent or when specific legal or ethical justifications apply, as outlined by the GMC, common law, and data protection legislation.

Key Facts

Confidentiality is a duty arising from common law, statute (Data Protection Act 2018/UK GDPR), professional regulation (GMC), and the Human Rights Act 1998 (Article 8 — right to private life) GMC guidance: patients have a right to expect that information about them will be held in confidence; disclosure without consent requires justification Confidentiality continues after death — GMC guidance applies to deceased patients Caldicott Principles: framework for handling patient-identifiable information in the NHS; Caldicott Guardian in every NHS organisation Common law duty of confidence: information given in circumstances where there is a reasonable expectation of confidentiality Patients can give explicit consent (specific) or implied consent (within the healthcare team for direct care) for information sharing Statutory obligations to disclose: notifiable diseases, court orders, terrorism (Section 19 Terrorism Act 2000), DVLA notification, Road Traffic Act Data Protection Act 2018 / UK GDPR: legal framework for processing personal data; health data is 'special category' requiring additional safeguards

Overview

Key Facts

Confidentiality is both a professional obligation and a legal duty. It underpins the trust necessary for patients to share sensitive information with healthcare professionals. Breaches require clear justification.

Legal Framework

  • Common law: duty of confidence; breach is actionable
  • Data Protection Act 2018 / UK GDPR: lawful basis for processing personal data; special category data requires additional condition
  • Human Rights Act 1998: Article 8 — right to respect for private and family life
  • NHS Act 2006 Section 251: allows Secretary of State to set aside common law duty of confidentiality for specific purposes (e.g. cancer registries, screening programmes)
  • Caldicott Principles (updated 2013): 7 principles governing use of patient-identifiable information

Caldicott Principles

  1. Justify the purpose of using confidential information
  2. Don't use personal data unless absolutely necessary
  3. Use the minimum necessary personal data
  4. Access to personal data on a strict need-to-know basis
  5. Everyone with access must understand their responsibilities
  6. Comply with the law
  7. The duty to share information can be as important as the duty to protect (added 2013)

Implied Consent for Information Sharing

  • Within the healthcare team providing direct care: implied consent assumed
  • Patients should be informed that information may be shared within the team
  • Opt-out should be available
  • For purposes other than direct care: explicit consent generally required

Clinical Presentation

Clinical Scenarios

  • Sharing information within the healthcare team: generally covered by implied consent for direct care
  • Referral letters: sharing relevant information with consent (implied for referrals the patient has agreed to)
  • Relatives requesting information: do not disclose without patient's consent unless patient lacks capacity (then best interests)
  • Police requesting information: do not disclose unless court order, statutory obligation, or serious crime/public interest
  • Insurance/employer reports: only with explicit written patient consent
  • Deceased patients: confidentiality generally maintained; disclosure if required by statute, court order, or compelling public interest

Common Exam Scenarios

  • Patient with epilepsy who continues to drive (DVLA notification duty)
  • Patient discloses domestic violence (support but respect confidentiality; may share if risk to children)
  • Patient with HIV who refuses to tell sexual partners (complex; exhaust other options before considering disclosure)
  • Patient's employer requests medical information (only with explicit consent)
  • Request from solicitor for medical records (only with patient consent or court order)

Differential Diagnosis

SituationConsent RequiredLegal Basis
Within healthcare team (direct care)ImpliedCommon law, UK GDPR
Referral to specialistImplied (patient agreed to referral)Common law
Insurance reportExplicit written consentAccess to Medical Reports Act 1988
Police request (no court order)Patient consent preferredDisclosure at discretion if serious crime
Court orderNo consent neededStatutory
Notifiable diseaseNo consent neededHealth Protection Regulations 2010
DVLA (patient refuses to stop driving)No consent needed (doctor may disclose)GMC guidance
Safeguarding childrenNo consent needed if child at riskChildren Act 2004

Diagnosis / Investigation

Information Governance Assessment

  • Is there a legal basis for processing the data? (UK GDPR)
  • Is there a condition for processing special category data?
  • Has the Caldicott Principles been applied?
  • Is the minimum necessary information being shared?
  • Has the patient been informed about how their data is used (privacy notice)?
  • Is there a lawful basis for any disclosure without consent?
  • Is the disclosure proportionate and necessary?

Management

Maintaining Confidentiality in Practice

  • Keep records secure (locked cabinets, password-protected systems)
  • Don't discuss patients in public areas
  • Use initials/patient numbers in teaching/research
  • Secure email and messaging (NHS Mail for patient-identifiable data)
  • Clear desk policy
  • Appropriate screen positioning
  • Anonymise data for audit, research, teaching where possible
  • Staff training on information governance

When Disclosure Without Consent May Be Justified

  1. Required by law: notifiable diseases, court orders, Terrorism Act, Road Traffic Act
  2. Statutory regulatory purposes: GMC/NMC investigations, child protection
  3. Public interest: serious crime prevention, safeguarding, serious risk to others
  4. With patient consent: explicit for non-care purposes

Referral Criteria

  • Caldicott Guardian advice for complex disclosure decisions
  • GMC confidentiality helpline
  • NHS legal team if legal obligation unclear
  • Information Commissioner's Office (ICO) for data protection queries
  • Court of Protection if patient lacks capacity and disclosure is disputed

Prognosis

  • Breaches of confidentiality erode patient trust and can deter people from seeking healthcare
  • Complaints about confidentiality are among the most common to the GMC
  • UK GDPR has strengthened data protection with significant penalties for breaches (up to £17.5 million or 4% of annual turnover)
  • Electronic records and digital communication increase both accessibility and risk
  • Good information governance protects patients and healthcare professionals

Other Relevant Information

Lawful Bases for Processing Health Data (UK GDPR)

Lawful BasisSpecial Category ConditionExample
ConsentExplicit consentResearch participation
Legal obligationEmployment, social security, social protectionOccupational health
Vital interestsUnconscious patient in emergency
Public interestHealthcare provision (Schedule 1, Part 1, Para 2)Direct patient care
Legitimate interestsSubstantial public interestPublic health surveillance

Key GMC Guidance on Confidentiality

TopicKey Principle
Sharing within the teamImplied consent for direct care
Sharing without consentOnly if required by law or justified in public interest
Deceased patientsDuty of confidentiality continues
ChildrenShare if necessary to protect child
DrivingCan disclose to DVLA if patient refuses to stop
Serious communicable diseaseConsider disclosure to protect identified at-risk individuals