3.3 Patient Confidentiality, Data Protection & Duty of Candour
Key Takeaways
- The Data Protection Act 2018 and UK GDPR govern the lawful processing of health data, classifying medical records as special category data requiring strict safeguards.
- The Caldicott Principles (expanded to 8 principles) dictate that patient-identifiable information must only be shared on a need-to-know basis for justified, lawful purposes.
- Confidentiality can be lawfully breached under three explicit exceptions: explicit patient consent, overriding public interest (e.g., severe harm prevention, terrorism, safeguarding), or statutory requirement/court order.
- The statutory Duty of Candour (Regulation 20 of the Health and Social Care Act 2008 Regulations 2014) mandates openness, a timely notification, written explanation, and a formal apology when a patient safety incident causes moderate or severe harm or death.
3.3 Patient Confidentiality, Data Protection & Duty of Candour
Patient confidentiality is both a common law duty and a core mandate of the NMC Code. Patients share sensitive personal information with healthcare staff under the expectation of privacy. Breaching confidentiality breaches trust, deters patients from seeking medical care, and violates UK data protection law.
Data Protection Act 2018 & UK GDPR
The Data Protection Act 2018 (DPA 2018) incorporates the UK General Data Protection Regulation (UK GDPR) into national law. In healthcare, personal health data is legally classified as special category data (sensitive data), requiring explicit lawful bases for processing under Article 6 and Article 9 of the UK GDPR.
Key Data Protection Principles for Nurses
- Lawfulness, Fairness, and Transparency: Personal data must be processed lawfully and transparently.
- Purpose Limitation: Data collected for direct clinical care cannot be repurposed without authorization.
- Data Minimisation: Only record and share information that is strictly necessary for the clinical purpose.
- Accuracy: Medical records must be accurate, clear, contemporaneous, and kept up to date.
- Storage Limitation: Records must be retained only as long as permitted under the NHS Records Management Code of Practice.
- Integrity and Confidentiality: Data must be stored securely (e.g., password-protected electronic systems, locked paper records).
- Accountability: Organizations and practitioners must demonstrate compliance with data protection laws.
The Caldicott Principles
First established in 1997 following a review chaired by Dame Fiona Caldicott, the Caldicott Principles guide the handling of patient-identifiable information across the NHS and social care. The framework was updated in 2013 and expanded in 2020 to 8 core principles:
| Principle | Rule Description |
|---|---|
| 1. Justify the purpose(s) | Every proposed use or transfer of confidential patient information must be clearly defined and justified. |
| 2. Use only when necessary | Confidential patient-identifiable information should not be included unless it is essential. |
| 3. Use the minimum necessary | Where use of confidential information is necessary, only the exact minimum required details must be shared. |
| 4. Access on a strict need-to-know basis | Only those individuals who need access to confidential patient information should have access. |
| 5. Everyone must understand responsibilities | Action must be taken to ensure those handling confidential information are aware of their legal duties. |
| 6. Comply with the law | Every use of confidential patient information must be lawful under DPA 2018, UK GDPR, and common law. |
| 7. Duty to share can be as important as duty to protect | Health and care professionals should share information in the best interests of patients for direct care or safeguarding. |
| 8. Inform patients about how data is used | Transparency requires informing patients how their confidential data will be processed and shared. |
Every NHS Trust employs a Caldicott Guardian—a senior healthcare professional responsible for protecting patient data and authorizing complex data-sharing decisions.
Lawful Exceptions & Breaching Confidentiality
While confidentiality is fundamental, it is not absolute. A nurse may lawfully disclose confidential patient information without consent under three specific circumstances:
- Explicit Patient Consent: The patient freely gives clear, informed permission for their data to be shared with named third parties (e.g., insurance companies, solicitors, or family members).
- Overriding Public Interest: Disclosure is justified if the public interest in disclosing the information outweighs the duty of confidentiality. Examples include:
- Preventing or detecting serious crime (e.g., murder, manslaughter, rape, terrorism).
- Protecting public safety from imminent threats of serious physical harm or death.
- Urgent safeguarding concerns involving vulnerable children or adults at risk of severe abuse or neglect.
- Statutory Requirement or Court Order: Disclosure is mandated by law or a judge's order:
- Notification of specific infectious diseases under the Public Health (Control of Disease) Act 1984.
- Statutory notifications to the DVLA regarding medical unfitness to drive.
- Express court orders directing the release of medical records.
[Confidential Patient Info]
|
Is there Explicit Consent? ---> YES ---> Share Safely
| NO
Is there a Statutory Duty / Court Order? ---> YES ---> Disclose Lawfully
| NO
Is there Overriding Public Interest / Safeguarding Risk?
| YES ---> Consult Caldicott Guardian & Document Rationale ---> Disclose
| NO ---> MAINTAIN CONFIDENTIALITY
The Statutory Duty of Candour
The Duty of Candour was enacted into law under Regulation 20 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 following the Francis Inquiry into failures of care at Mid Staffordshire NHS Foundation Trust. It imposes a legal obligation on healthcare providers to be open and transparent with service users when safety incidents occur.
Harm Threshold for Statutory Duty of Candour
The statutory Duty of Candour is triggered when a notifiable safety incident occurs during care that results in, or could result in:
- Death (directly linked to the incident rather than natural disease progression).
- Severe harm (permanent brain damage, permanent loss of bodily function/limb, or severe disfigurement).
- Moderate harm (harm requiring moderate clinical intervention such as surgical repair, additional hospital stay, or permanent minor impairment).
- Prolonged psychological harm (continuous psychological trauma lasting at least 28 days).
Mandatory Steps Required Under Regulation 20
- Prompt Notification: Notify the patient (or their representative if the patient lacks capacity or has died) as soon as reasonably practicable after the incident is discovered.
- Verbal Explanation & Formal Apology: Provide a clear, truthful verbal explanation of the facts known at the time and offer a sincere, formal apology ("we are sorry for the harm caused"). Under Section 2 of the Compensation Act 2006, an apology does not constitute an admission of legal liability.
- Written Follow-Up: Provide written confirmation detailing the verbal explanation, apology, and outline of the formal investigation steps within Trust policy timescales (typically within 10 working days).
- Investigation Results: Share the final written investigation report and action plan with the patient or family upon completion.
Professional vs. Statutory Duty of Candour
- Statutory Duty (Regulation 20): Applies to healthcare organizations for incidents resulting in moderate/severe harm or death.
- Professional Duty (NMC Code): Applies directly to individual registered nurses for ALL incidents, near-misses, or errors, regardless of whether harm actually occurred.
Which Caldicott Principle explicitly highlights that sharing confidential information for direct patient care can be as vital as maintaining secrecy?
What harm threshold triggers the statutory Duty of Candour under Regulation 20 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014?
Which circumstance provides a valid legal justification for breaching patient confidentiality without explicit consent or a court order?
What is a mandatory requirement of the statutory Duty of Candour when a notifiable patient safety incident occurs?