HCPC Patient Confidentiality & UK GDPR 1 — Questions and Answers
Question 1: What is the legal basis for processing patient health data under UK GDPR?
- Explicit consent, or another lawful basis under Article 9 (substantial public interest, vital interests, healthcare purposes, etc.) (Correct answer)
- Verbal consent alone is always sufficient
- Health data may be processed freely without any legal basis
- Only NHS organisations may process health data
Correct answer: Explicit consent, or another lawful basis under Article 9 (substantial public interest, vital interests, healthcare purposes, etc.)
Health data is 'special category' data under UK GDPR (Article 9). Processing requires both a standard lawful basis (Article 6) and a specific Article 9 condition, such as healthcare purposes or explicit consent.
Question 2: Under UK GDPR, what rights does a patient have regarding their personal health data?
- Right of access, rectification, erasure (in limited circumstances), restriction, data portability, and to object to processing (Correct answer)
- Only the right to access their records
- No rights — NHS controls all health data
- Only the right to erasure
Correct answer: Right of access, rectification, erasure (in limited circumstances), restriction, data portability, and to object to processing
UK GDPR grants data subjects multiple rights including: Subject Access Requests (within 1 month), correction of inaccurate data, erasure in limited circumstances, and restriction of processing.
Question 3: What is a 'Subject Access Request' (SAR) in the context of health records?
- A formal request by an individual for copies of all personal data held about them by an organisation (Correct answer)
- A request by a clinician to access a patient's records
- A request for a second clinical opinion
- A request from a solicitor for medical reports
Correct answer: A formal request by an individual for copies of all personal data held about them by an organisation
A SAR allows any individual to request copies of all personal data held about them. Healthcare organisations must respond within one calendar month and cannot usually charge a fee.
Question 4: How long do NHS organisations typically retain patient health records under Records Management Codes of Practice?
- 8 years after last treatment (adults); 8 years after 18th birthday for children; longer for certain specialties (Correct answer)
- 3 years only
- Indefinitely with no review
- 1 year post-treatment
Correct answer: 8 years after last treatment (adults); 8 years after 18th birthday for children; longer for certain specialties
NHS Records Management Codes specify minimum retention periods: adults' records are generally kept for 8 years after last treatment. Children's records must be kept until at least their 26th birthday.
Question 5: A patient requests that their GP does not share their records with the hospital they are being referred to. What should the healthcare professional advise?
- The patient has the right to restrict sharing; however, clinicians must explain that restriction may affect the quality and safety of care they receive (Correct answer)
- The patient has no right to restrict sharing between NHS organisations
- All NHS records sharing is automatic and patients cannot restrict it
- Only a court order can restrict record sharing
Correct answer: The patient has the right to restrict sharing; however, clinicians must explain that restriction may affect the quality and safety of care they receive
Patients can request restrictions on how their data is shared. However, they must be informed that restrictions may affect care quality. Clinicians may still share in genuine clinical emergencies to protect the patient's vital interests.
Question 6: What is the 'Caldicott Principles' framework and who does it apply to?
- Eight principles for protecting patient information across NHS and social care organisations, applicable to all staff handling patient data (Correct answer)
- A clinical coding framework for hospital records
- An information technology standard for NHS systems
- A framework for prescription management only
Correct answer: Eight principles for protecting patient information across NHS and social care organisations, applicable to all staff handling patient data
The Caldicott Principles (8 since 2020) provide a framework for protecting patient confidentiality in NHS and social care. All organisations must appoint a Caldicott Guardian and staff must follow these principles.
What is the legal basis for processing patient health data under UK GDPR?