16.5 Records, Information Governance & Regulation
Key Takeaways
- Health data is special category data under UK GDPR: the usual lawful bases in a clinical setting are Article 6(1) for the processing itself and Article 9(2)(h) for health and social care purposes, not patient consent
- A subject access request must normally be answered within one month and free of charge, and the practice cannot demand a reason for the request
- Retention periods differ across the UK: NHS England guidance for adults is now a minimum of 15 years, and for children until the 25th birthday (26th if the last entry was at 17), so always check the current schedule for your nation
- The Caldicott principles govern the use of confidential patient information, and the eighth principle requires that patients have clear expectations about how their data is used
- Enhanced CPD requires a dentist to complete 100 hours over the five-year cycle with a minimum of 10 hours in any consecutive two years, and to keep a personal development plan and a CPD log
Why Records Are a Regulatory Issue
Outcome A1.2 names regulatory issues relating to clinical practice including record keeping and information governance, and A1.5 names formal standards, guidelines and procedures, e.g. GDC requirements. Records are simultaneously a clinical tool, a legal document and personal data governed by statute. Most complaints and claims turn on what the record does or does not show.
Data Protection: UK GDPR and the Data Protection Act 2018
Health data is special category data, which needs a lawful basis under Article 6 and an additional condition under Article 9.
| Element | Position in dental practice |
|---|---|
| Lawful basis (Article 6) | Usually the performance of a task in the public interest for NHS care, or legitimate interests or contract for private care. Not normally consent — consent under GDPR must be freely given and withdrawable, which does not fit a clinical record you are obliged to keep |
| Article 9 condition | Article 9(2)(h) — processing necessary for the provision of health or social care by, or under the responsibility of, a professional subject to a duty of confidentiality |
| Consent to treatment | A separate concept entirely. Clinical consent and GDPR consent are not the same thing, and confusing them is a common examination distractor |
The data protection principles
Lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability — the practice must be able to demonstrate compliance, which is why a privacy notice, a record of processing activities and staff training are required.
Data subject rights that arise in practice
- Right of access (subject access request) — normally answered within one month, free of charge, and the patient does not have to give a reason. The period may be extended by two further months for complex or numerous requests, and a reasonable fee may be charged only for manifestly unfounded or excessive requests.
- Rectification — factual errors are corrected, but a clinical opinion recorded at the time is not deleted because the patient disagrees with it; an addendum is added instead.
- Erasure — very limited for health records, because there is a legal obligation to retain them.
- Restriction, portability and objection — apply in narrower circumstances.
- Access to Health Records Act 1990 governs access to the records of a deceased patient by the personal representative or by someone with a claim arising from the death.
Breaches
A personal data breach likely to result in a risk to individuals' rights must be reported to the Information Commissioner's Office within 72 hours of the practice becoming aware of it, and affected individuals must be told where the risk is high. Common dental examples are a lost unencrypted laptop, an email sent to the wrong patient list, and records left visible at reception.
Retention
Retention periods are set nationally and differ across the UK, so the correct examination answer is to check the current schedule for your nation rather than to quote a single number from memory. The direction of travel in England and Wales, under the NHS Records Management Code of Practice, is a minimum of 15 years for an adult's records and, for a child, until the 25th birthday (or the 26th where the last entry was made at 17), whichever is later. Scotland and Northern Ireland operate their own schedules. Records must be retained in a form that remains readable and that preserves the audit trail; destruction must be secure and logged.
The Caldicott Principles
The Caldicott principles govern the use of confidential patient information in health and care:
- Justify the purpose for using confidential information.
- Use confidential information only when it is necessary.
- Use the minimum necessary.
- Access should be on a strict need-to-know basis.
- Everyone with access must be aware of their responsibilities.
- Comply with the law.
- The duty to share information for individual care is as important as the duty to protect confidentiality.
- Inform patients about how their confidential information is used.
Principle 7 is the one candidates most often forget: failing to share information that is needed for a patient's care is as much a failing as sharing it inappropriately.
What Belongs in the Record
Beyond the clinical content covered in the treatment-planning section, the regulatory essentials are:
- Contemporaneous entries, made at the time or as soon as practicable afterwards.
- Attributable — who made the entry and when; electronic systems must maintain an audit trail.
- Unaltered — corrections to paper notes are made with a single strike-through, dated and initialled; the original must remain legible. Retrospective alteration of a record after a complaint is a serious professional offence.
- Radiographs, with the IR(ME)R justification recorded, and a clinical evaluation (report) of every image, including any incidental findings.
- Local anaesthetic type, dose and batch, materials used, and device or implant identifiers.
- What the patient was told, not merely that consent was obtained.
The Regulatory Framework a Dentist Works Within
| Body or instrument | What it governs |
|---|---|
| General Dental Council | Registration, Standards for the Dental Team (nine principles), Scope of Practice, enhanced CPD, fitness to practise |
| Enhanced CPD | 100 hours over the five-year cycle for dentists, with a minimum of 10 hours in any consecutive two years; dental nurses and dental technicians 50 hours, hygienists, therapists, orthodontic therapists and clinical dental technicians 75 hours; a personal development plan and a CPD log are required |
| Indemnity | A statutory requirement for all clinical registrants; practising without it is a registration offence |
| Care Quality Commission (England), Healthcare Improvement Scotland, Healthcare Inspectorate Wales, RQIA (Northern Ireland) | Registration and inspection of the provider, including the statutory duty of candour |
| IRR17 and IR(ME)R 2017 | Ionising radiation: employer procedures, justification, optimisation, clinical evaluation, training records |
| HTM 01-05 and equivalents | Decontamination and infection prevention |
| COSHH, RIDDOR, HASAWA 1974 | Hazardous substances, reportable incidents, general health and safety |
| Freedom of Information Act 2000 | Applies to public authorities; a private dental practice is not subject to it, though NHS bodies are |
A dental practice processes patient health records. Which lawful basis under UK GDPR normally applies to that processing?
A patient telephones asking for a copy of her complete dental record and refuses to say why she wants it. What is the correct response?
A practice laptop containing unencrypted patient records is stolen from a car. What is the practice's obligation?
Under the GDC's enhanced CPD scheme, what are the requirements for a dentist?