HCPC Patient Confidentiality & UK GDPR 3 — Questions and Answers
Question 1: A healthcare professional is asked by the police to provide patient information relating to a violent crime investigation. What should they do?
- Balance public interest against patient confidentiality; disclose only what is necessary under a relevant statutory gateway or court order, or where there is serious ongoing risk (Correct answer)
- Always provide all requested information to police
- Refuse all police requests on confidentiality grounds
- Ask the patient to go to the police themselves
Correct answer: Balance public interest against patient confidentiality; disclose only what is necessary under a relevant statutory gateway or court order, or where there is serious ongoing risk
Police requests for patient data require a legal basis. Disclosure is permitted under specific statutory gateways, court orders, or where there is serious risk of harm. Routine disclosure on request without legal basis is a breach.
Question 2: What is the purpose of an NHS Data Security and Protection Toolkit?
- An annual self-assessment for NHS and social care organisations to demonstrate compliance with data security and protection standards (Correct answer)
- A checklist for individual clinicians only
- A tool for patients to assess their own data rights
- A software programme for encrypting patient records
Correct answer: An annual self-assessment for NHS and social care organisations to demonstrate compliance with data security and protection standards
The NHS Data Security and Protection (DSP) Toolkit is an annual online self-assessment that NHS and social care organisations must complete to demonstrate they meet data security and information governance standards.
Question 3: Under UK GDPR, what is the maximum fine that can be imposed on an organisation for a serious data protection breach?
- Up to £17.5 million or 4% of global annual turnover, whichever is higher (equivalent of EU GDPR €20m/4% rule) (Correct answer)
- £500 maximum
- £1 million only
- Fines are not applicable to NHS organisations
Correct answer: Up to £17.5 million or 4% of global annual turnover, whichever is higher (equivalent of EU GDPR €20m/4% rule)
UK GDPR (post-Brexit retained EU law) maintains the maximum fine of up to £17.5 million or 4% of global annual turnover for the most serious violations — equivalent to the EU's €20 million cap.
Question 4: What does the 'right to erasure' (right to be forgotten) allow a patient to request?
- Deletion of their data where it is no longer necessary, consent is withdrawn, or processing is unlawful — subject to exceptions for health records retained for legal or safety purposes (Correct answer)
- Deletion of any data at any time for any reason
- Only deletion of online accounts, not clinical records
- Deletion of records within 7 days of request in all cases
Correct answer: Deletion of their data where it is no longer necessary, consent is withdrawn, or processing is unlawful — subject to exceptions for health records retained for legal or safety purposes
The right to erasure applies in specific circumstances. Clinical records often cannot be erased due to legal obligations (retention policies) and patient safety considerations. Healthcare organisations can refuse erasure on these grounds.
Question 5: A care home asks a community occupational therapist for a patient's full clinical records. What must happen before sharing?
- Verify the care home has a legitimate need, a data sharing agreement is in place, and share only relevant information proportionately (Correct answer)
- Share all records immediately as they are a care provider
- Refuse all sharing between health and social care
- Only share if the patient's family has consented
Correct answer: Verify the care home has a legitimate need, a data sharing agreement is in place, and share only relevant information proportionately
Data sharing with care homes requires a legitimate basis (direct care), proportionality (only necessary information), and ideally a formal data sharing agreement. Sharing more than necessary is a breach.
Question 6: What is a 'data protection impact assessment' (DPIA) and when must one be completed?
- A systematic assessment of risks to individuals' privacy from new data processing activities — mandatory before introducing processing likely to result in high risk (Correct answer)
- An optional voluntary assessment
- A financial audit of data storage costs
- Only required when sharing data with third parties
Correct answer: A systematic assessment of risks to individuals' privacy from new data processing activities — mandatory before introducing processing likely to result in high risk
A DPIA (under UK GDPR Article 35) is mandatory before implementing any new processing that is likely to result in high risk to individuals — including new health IT systems, large-scale processing, or systematic monitoring.
A healthcare professional is asked by the police to provide patient information relating to a violent crime investigation.
What should they do?