HCPC Patient Confidentiality & UK GDPR 2 — Questions and Answers
Question 1: What is a 'Caldicott Guardian'?
- A senior NHS person responsible for protecting the confidentiality of patient information and enabling appropriate sharing (Correct answer)
- A data entry clerk
- A patient advocate employed by NHSX
- The HCPC's representative in an NHS trust
Correct answer: A senior NHS person responsible for protecting the confidentiality of patient information and enabling appropriate sharing
Every NHS organisation must appoint a Caldicott Guardian — usually a senior clinician or executive — to oversee and guide appropriate handling of patient information and enable justified sharing.
Question 2: Under what circumstances can patient identifiable information be shared without consent for public health purposes?
- Under specific statutory gateways such as Public Health (Control of Disease) Act 1984, Health Protection Regulations, or public health directions from Secretary of State (Correct answer)
- Never without explicit patient consent
- Only with an anonymised dataset
- Only by NHS England directly
Correct answer: Under specific statutory gateways such as Public Health (Control of Disease) Act 1984, Health Protection Regulations, or public health directions from Secretary of State
Statutory gateways (e.g., mandatory notification of infectious diseases, Public Health Act powers) allow sharing of identifiable patient data without consent to protect public health, provided disclosure is proportionate.
Question 3: A healthcare professional receives a phone call from someone claiming to be the patient's spouse requesting health information. What is the correct response?
- Do not disclose — verify the patient's identity and only share information with explicit patient consent or a valid legal basis (Correct answer)
- Disclose to the spouse as they are next of kin
- Ask the spouse to email their request
- Refer the spouse to the GP without any information
Correct answer: Do not disclose — verify the patient's identity and only share information with explicit patient consent or a valid legal basis
Being a relative does not automatically confer a right to patient information. UK GDPR requires a lawful basis for disclosure. Without patient consent or another legal gateway, sharing with relatives is a breach.
Question 4: What is 'pseudonymisation' in the context of health data?
- Replacing identifying fields with artificial identifiers so data cannot be attributed to a specific individual without additional information (Correct answer)
- Destroying all patient data after use
- Using only initials on patient records
- Removing dates of birth from records
Correct answer: Replacing identifying fields with artificial identifiers so data cannot be attributed to a specific individual without additional information
Pseudonymisation replaces direct identifiers (name, NHS number) with a code. The data can only be re-identified with the separately stored key. It reduces privacy risk but is not the same as full anonymisation.
Question 5: Which UK body oversees compliance with data protection law for healthcare organisations?
- The Information Commissioner's Office (ICO) (Correct answer)
- The Care Quality Commission (CQC)
- HCPC
- NHS England
Correct answer: The Information Commissioner's Office (ICO)
The ICO is the UK's independent authority for upholding information rights. It has powers to investigate data breaches, issue fines, and enforce UK GDPR compliance across all sectors including healthcare.
Question 6: What is a 'data breach' under UK GDPR?
- A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to personal data (Correct answer)
- Only a deliberate hacking event
- Only when physical records are lost
- Only when financial data is exposed
Correct answer: A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to personal data
A data breach includes any incident (accidental or deliberate) resulting in unauthorised access to, loss of, or destruction of personal data. Healthcare organisations must report serious breaches to the ICO within 72 hours.
What is a 'Caldicott Guardian'?