Data Protection and Patient Records
Key Takeaways
- The UK GDPR and Data Protection Act 2018 mandate how personal and sensitive health data must be processed, stored, and protected.
- Patients have the right to access their dental records via a Subject Access Request (SAR), which must typically be fulfilled within one month.
- Clinical records must be retained for specific periods: adults for 11 years after the last entry, and children until age 25.
Data Protection and Patient Records
Modern dental practices handle, store, and transmit vast amounts of highly sensitive personal and clinical data on a daily basis. Ensuring the strict confidentiality, integrity, and continuous availability of this data is not merely a professional courtesy or an ethical aspiration; it is a strict legal requirement governed by robust, heavily enforced legislation. Breaches can lead to severe financial penalties, regulatory action by the GDC, and a devastating loss of patient trust.
UK GDPR and the Data Protection Act 2018
Following Brexit, the processing of personal data in the United Kingdom is governed by the UK General Data Protection Regulation (UK GDPR), which sits alongside the updated Data Protection Act (DPA) 2018. These extensive regulations set out the fundamental legal framework and key principles for data processing that all dental practices must rigorously follow.
Within the framework of the UK GDPR, health data (including dental records, medical histories, and radiographs) is specifically classified as 'special category data'. Because of its highly sensitive nature, processing this data requires a higher level of protection and specific lawful conditions.
The core principles of the UK GDPR dictate that personal data must be:
- Processed lawfully, fairly, and transparently: Patients must know exactly what you are doing with their data. This is typically achieved by providing a clear, accessible Privacy Notice in the practice waiting room and on the website.
- Collected for specified, explicit, and legitimate purposes: You cannot collect data for dental care and then sell it to a third-party marketing company without explicit consent.
- Adequate, relevant, and limited to what is necessary: This is the principle of data minimisation. You should not collect personal information that is not strictly required for providing dental care.
- Accurate and kept up to date: Practices have a duty to ensure records are correct. Medical histories must be regularly checked and updated at every recall appointment.
- Kept in a form which permits identification of data subjects for no longer than is necessary: Records must not be hoarded indefinitely and must be securely destroyed when they reach the end of their statutory retention period.
- Processed in a manner that ensures appropriate security: This includes protection against unauthorised or unlawful processing, and against accidental loss, destruction, or damage. Practices must use appropriate technical and organisational measures, such as strong passwords, encrypted drives, secure clinical software, locked filing cabinets, and comprehensive staff training.
Every practice should designate a Data Protection Officer (DPO) or a specific individual responsible for overseeing data protection compliance. All members of the dental team must receive regular, documented training on data protection. Human error—such as sending a referral email to the wrong recipient, leaving computer screens unlocked, or discussing a patient in a public area like reception—remains the leading cause of data breaches in healthcare.
Data Breaches and Reporting
A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Examples include a stolen unencrypted practice laptop, a cyber-attack (like ransomware), or posting records to the wrong address.
If a data breach occurs and is likely to result in a risk to the rights and freedoms of individuals, the practice is legally required to notify the Information Commissioner's Office (ICO) no later than 72 hours after becoming aware of it. If the breach is likely to result in a high risk to the individuals (for example, leading to identity theft or significant distress), those individuals must also be informed directly without undue delay.
Subject Access Requests (SARs)
Under the UK GDPR, patients have a powerful right known as the "Right of Access." They can legally request a copy of all their personal data held by the practice. This includes their full clinical notes, radiographs, referral letters, and financial correspondence. This is formally known as a Subject Access Request (SAR).
When a practice receives a SAR, there are strict rules to follow:
- Timeframe: The practice must provide the requested information typically within one calendar month of receipt of the request.
- Fees: The practice must provide this information entirely free of charge. The historical £50 fee under the old Data Protection Act is abolished. You can only charge a reasonable fee for administrative costs if a request is manifestly unfounded, excessive, or repetitive.
- Verification: It is absolutely crucial that the identity of the person making the request is verified before releasing any sensitive health data, to prevent fraudulent access.
- Third-Party Redaction: Before releasing notes, the practice must carefully review them and redact (black out) any information relating to third parties who have not consented to disclosure, unless it is reasonable to disclose it without their consent.
Clinical Record Keeping Standards and Retention
Accurate, detailed, and contemporaneous clinical records are the foundation of safe patient care. They also serve as the primary, and often only, defense for a clinician in the event of a patient complaint, a GDC fitness to practise investigation, or a clinical negligence claim. As the legal maxim goes: "Good records, good defence; poor records, poor defence; no records, no defence."
According to the Faculty of General Dental Practice (FGDP) and the College of General Dentistry (CGDent), records should be written as soon as practically possible after the appointment. They must be clear, legible, entirely objective, and free from derogatory remarks. A complete record should include the updated medical history, detailed clinical findings (including negative findings), diagnoses, all treatment options discussed (including risks and costs), the actual treatment provided, the materials used (including batch numbers), and any post-operative instructions or warnings given to the patient.
Records must be securely retained for legally mandated minimum periods, even if a patient leaves the practice to go elsewhere or passes away. The standard recommended retention periods in the UK are:
- Adult records: Must be retained for a minimum of 11 years after the date of the last entry.
- Child records: Must be retained for 11 years after the last entry OR until the patient reaches the age of 25, whichever is the longer period.
When records finally reach the end of their required statutory retention period, they cannot simply be thrown in the general waste. They must be securely and permanently destroyed. This means rigorous cross-shredding or incineration for paper records, and secure digital deletion or physical destruction of hard drives for electronic files, ensuring the data cannot ever be recovered or reconstructed.
Under the UK GDPR, what is the standard timeframe within which a dental practice must respond to a patient's Subject Access Request (SAR)?
How long must the clinical records of an adult patient be retained after the last entry in their notes?