HCPC Patient Confidentiality & UK GDPR 4 — Questions and Answers
Question 1: How does UK GDPR apply to deceased patients' records?
- UK GDPR does not apply to deceased persons' data, but common law duty of confidentiality and Access to Health Records Act 1990 still offer some protection (Correct answer)
- UK GDPR applies fully to all records including deceased patients
- Deceased patients have no information rights whatsoever
- Deceased patients' records can be freely shared after 6 months
Correct answer: UK GDPR does not apply to deceased persons' data, but common law duty of confidentiality and Access to Health Records Act 1990 still offer some protection
UK GDPR only protects living individuals. However, a common law duty of confidentiality persists after death, and the Access to Health Records Act 1990 gives limited rights to certain representatives to access deceased patients' records.
Question 2: What is 'consent' as a lawful basis for processing health data under UK GDPR?
- Freely given, specific, informed, and unambiguous agreement by the patient to their data being processed for a specific purpose — and withdrawable at any time (Correct answer)
- A general agreement to treatment that covers all data uses
- A form signed on hospital admission
- NHS data is always processed under an implied consent model
Correct answer: Freely given, specific, informed, and unambiguous agreement by the patient to their data being processed for a specific purpose — and withdrawable at any time
UK GDPR consent must be active, specific, informed, and freely given. It must be as easy to withdraw as to give. Pre-ticked boxes or bundled consent for multiple purposes do not meet the standard.
Question 3: A physiotherapist discovers their colleague has accessed a celebrity patient's records without clinical justification. What should they do?
- Report as a data breach through the organisation's information governance team and line management; this may also be a conduct concern (Correct answer)
- Inform only the celebrity patient
- Ignore it as it is between the colleague and the patient
- Report directly to the ICO without internal reporting first
Correct answer: Report as a data breach through the organisation's information governance team and line management; this may also be a conduct concern
Unauthorised access to patient records is a data breach and a professional conduct concern. It must be reported internally through information governance and escalated to management. ICO reporting follows if required.
Question 4: What is a 'fair processing notice' (privacy notice) in the context of NHS health data?
- Information provided to patients explaining how their data will be used, who it may be shared with, and their data rights — required under UK GDPR transparency obligations (Correct answer)
- A clinical consent form
- A leaflet about hospital visiting times
- An internal IT security document
Correct answer: Information provided to patients explaining how their data will be used, who it may be shared with, and their data rights — required under UK GDPR transparency obligations
UK GDPR's transparency principle (Article 13/14) requires organisations to provide clear, accessible privacy notices explaining how patient data is collected, used, stored, and shared, and patients' rights.
Question 5: Under the Data Protection Act 2018, which organisation can access identifiable patient data without consent for approved medical research?
- Organisations with approval from the Health Research Authority (HRA) and a legal gateway under DPA 2018 Schedule 2/3 (substantial public interest) (Correct answer)
- Any academic institution with ethical approval
- All NHS trusts freely for any research purpose
- Only NICE and NHS England
Correct answer: Organisations with approval from the Health Research Authority (HRA) and a legal gateway under DPA 2018 Schedule 2/3 (substantial public interest)
Research access to identifiable data without consent requires HRA approval, a robust legal gateway under DPA 2018, and adherence to Caldicott Principles and data minimisation standards.
Question 6: What is 'data minimisation' in the context of health data processing?
- Only collecting and processing personal data that is adequate, relevant, and limited to what is necessary for the specified purpose (Correct answer)
- Deleting patient data as quickly as possible
- Using only electronic rather than paper records
- Limiting access to the electronic patient record system to one user
Correct answer: Only collecting and processing personal data that is adequate, relevant, and limited to what is necessary for the specified purpose
Data minimisation (UK GDPR Article 5(1)(c)) requires that only data strictly necessary for the legitimate purpose is collected and processed. Collecting excessive patient data beyond clinical need violates this principle.
How does UK GDPR apply to deceased patients' records?