Skip to content
Independent remediation education for UK healthcare and social care professionals
IRR Practice
WelcomeLog in to access your courses and certificates
Log in My Courses Create an account
Get Started
GMCDoctors, PAs & AAs
NMCNurses & midwives
GDCDentists & DCPs
GPhCPharmacists & technicians
HCPCAllied health professions
GOCOptometrists & opticians
Social Work EnglandSocial workers, England
SSSCSocial services, Scotland
Contact Cart
Get Started

Confidentiality & Data Protection Remediation

Healthcare professionals handle some of the most sensitive information people ever share. When concerns arise about patient confidentiality, information sharing, privacy or data handling, remediation means understanding both your professional duty and the legal framework, reflecting on what happened, closing the real learning gap and showing that you now handle information more safely.

  • UK healthcare focused
  • Regulator-aware
  • Evidence-led learning
  • Independent provider

What happened with the information?

Choose the closest situation. See what is likely to be considered, what to do now and where learning should focus.

Select a situation to see where to start.

What is patient confidentiality?

Patient confidentiality is the duty to protect, and handle appropriately, information obtained through a professional relationship. It covers medical information, treatment and diagnoses, test results, photographs, appointment information, identifying details, what patients tell you during care, and any information that reveals something about a person's health.

The GMC's confidentiality guidance states that patients have a right to expect their personal information to be held in confidence by the professionals who care for them. Every UK healthcare regulator includes confidentiality in its core standards: for example, the NMC Code asks professionals to respect people's right to privacy and confidentiality (standard 5), and the HCPC's standards of conduct, performance and ethics include a standard on respecting confidentiality.

In law, the Information Commissioner's Office (ICO) confirms that health data is special category personal data under the UK GDPR, which means it receives additional protection. Health data is defined broadly and can include information about a person's past, current or future physical or mental health.

Are confidentiality and data protection the same thing?

No. They overlap, but they are not interchangeable, and a healthcare professional usually needs to consider both.

ConceptMain focusMain source
ConfidentialityThe duty to protect information entrusted to you as a professionalProfessional standards and the common law duty of confidence
Data protectionThe legal framework for processing personal dataUK GDPR and the Data Protection Act 2018; guidance from the ICO
Information governanceOrganisational systems and controls for managing informationYour employer's policies and procedures
PrivacyThe individual's interests and rights over their personal informationLaw, standards and patient expectations
CybersecurityProtecting information and systems from unauthorised access or attackOrganisational security policies

What types of healthcare information are sensitive?

Health information

Diagnoses, treatment and medical history.

Clinical records

Notes, assessments and care plans.

Test results

Laboratory, imaging and other results.

Identifiers

Anything that identifies, or helps identify, a patient.

Images

Clinical photographs and other identifiable images.

Appointment information

Even the fact of an appointment can reveal health information.

Communication

Emails, messages, letters and conversations about patients.

Combinations

Details that are harmless alone can identify someone together.

What can lead to a confidentiality concern?

Disclosure

  • Unauthorised disclosureSharing with someone not entitled to the information.
  • Incorrect recipientLetters, emails or results sent to the wrong person.
  • Workplace conversationsDiscussing patients where others can hear.

Access

  • Inappropriate accessViewing records without a legitimate professional reason, including those of family, friends, colleagues or yourself.
  • Shared loginsUsing or allowing others to use your access.

Handling and technology

  • Insecure communicationPersonal email or unapproved messaging apps.
  • Physical recordsDocuments left where others can see them.
  • Digital recordsUnlocked screens, personal devices, screenshots.
  • Social media and photographyPosts or images that could identify a patient.

Does a confidentiality breach automatically mean misconduct?

Not necessarily. Many confidentiality incidents are accidental, are reported promptly and are resolved through local learning. The regulatory significance of a concern depends on the facts, the applicable professional standards and your regulator's processes.

The single most important distinction is usually between accidental disclosure, such as an email sent to the wrong address, and deliberate access or disclosure without a legitimate reason. Deliberately accessing records out of curiosity is treated very differently from a mis-addressed letter, and knowingly or recklessly obtaining or disclosing personal data without the controller's consent can be a criminal offence under the Data Protection Act 2018.

Factors that are likely to be considered

  • what information was involved
  • who received or accessed it
  • whether the patient was identifiable
  • why it was accessed or disclosed
  • whether there was a legitimate purpose
  • accidental or deliberate
  • the scale of the disclosure
  • actual or potential impact
  • whether it was repeated
  • how you responded and reported it
  • what now prevents recurrence

Why is confidentiality a professional responsibility?

Trust

Patients share what they need to for safe care only if they believe it will be protected.

Privacy

Healthcare involves some of the most personal information people have.

Patient safety

Appropriate sharing is often necessary for safe, coordinated care.

Accountability

Professionals must understand their responsibilities for the information they handle.

When can healthcare information be shared?

Information sometimes needs to be shared for legitimate purposes, including direct care and other circumstances recognised by professional standards and law. The GMC's confidentiality guidance provides a framework for these decisions and distinguishes sharing for direct care from sharing for other purposes. Whatever your profession, the same questions sit behind a sound decision.

  1. PurposeWhy is the information being shared?
  2. NecessityIs sharing actually needed?
  3. ProportionalityWhat is the minimum necessary?
  4. RecipientWho needs it, and are they entitled to it?
  5. BasisWhat professional, legal or organisational basis permits it?
  6. SecurityHow will it be protected in transit and at rest?

In England, the Caldicott Principles published by the National Data Guardian set out similar principles for health and care organisations. Always follow your organisation's information governance policies.

What does confidentiality remediation involve?

  1. 1

    Understand the concern

    What happened, exactly?

  2. 2

    Identify the information

    What was involved, and how sensitive?

  3. 3

    Professional standard

    What your regulator expects.

  4. 4

    Data protection requirements

    What the law and your organisation require.

  5. 5

    Reflect

    Why it happened, and your role.

  6. 6

    Identify the learning need

    Knowledge, habit or process.

  7. 7

    Change practice

    How you now handle information.

  8. 8

    Demonstrate improvement

    Evidence, handled safely.

What does insight mean in a confidentiality case?

"I understand confidentiality now" is not insight. Specific understanding and changed practice are. Useful questions include:

  • What information was involved?
  • Why was it confidential?
  • Who received or accessed it?
  • Why did the incident occur?
  • What responsibility applied?
  • What impact could it have had?
  • What should have happened?
  • What have I learned?
  • What safeguards are now in place?
  • How will similar incidents be avoided?

Insight into impact matters particularly here. A patient whose information was disclosed may experience distress, stigma or loss of trust in their care, even when no clinical harm follows. Showing that you understand this from the patient's perspective is often central.

How to reflect on a confidentiality concern

  1. What happened?
  2. What information was involved?
  3. Why was the handling inappropriate or concerning?
  4. What professional and legal requirements were relevant?
  5. What was my responsibility?
  6. What was the potential impact?
  7. What have I learned?
  8. What will I do differently?
  9. What evidence demonstrates the change?

Be careful when using patient information as evidence

Remediation evidence must not create a new confidentiality problem. Case reflections, audits, clinical examples, documentation samples and incident reviews all risk including patient information. Follow your organisation's and your regulator's requirements for anonymisation, confidentiality and secure handling.

Removing a name is not enough. Identifiability often comes from combinations of details.

AgeWard or clinicDate of admissionRare conditionOccupationTown
Potentially identifiableEach detail is harmless alone. Together, they may point to one person, especially to colleagues or people in the same community.

If you are unsure whether evidence is sufficiently anonymised, ask your information governance lead before using it, and prefer summaries or reviewer reports over copies of records.

How confidentiality overlaps with other concerns

Documentation

Documentation asks whether the record is accurate, complete and appropriate. Confidentiality asks whether information is accessed, used and shared appropriately. Data protection asks whether personal data is processed lawfully.

Documentation remediation

Probity

An accidental incident is not a probity issue. A probity concern may arise from deliberately misleading others, concealment, knowingly accessing information without a legitimate purpose, falsifying information about access or disclosure, or misrepresenting what happened.

Probity remediation

Professionalism

Confidentiality overlaps with professional responsibility, boundaries, communication, accountability, appropriate use of technology and respect for patient privacy, especially where concerns involve social media or personal devices.

Professionalism remediation

Social media and patient confidentiality

Risk areas include patient stories, photographs, screenshots, clinical scenarios, workplace information, identifiable details, private messaging, closed groups and comments about patients. A patient may be identifiable even where their name is not included, particularly to people who know them. The aim is not to avoid discussing healthcare online, but to apply professional standards and appropriate information handling.

Electronic records, email and digital communication

Common concerns include wrong email recipients, insecure messaging, screenshots, unauthorised system access, shared passwords, unlocked systems, information stored on unapproved devices, and personal accounts used for professional information. The exact requirements come from your employer's information governance policies and your professional standards.

Can confidentiality training help with remediation?

A relevant confidentiality or information governance course can address an identified learning need and form part of a wider remediation plan. Course completion alone does not necessarily show that a confidentiality concern has been fully addressed. That is shown by how you now handle information.

LearningUnderstanding
ReflectionInsight
Practice changeSafer handling
EvidenceDemonstrated improvement

Learning that may be relevant

Depending on the concern: patient confidentiality, data protection and UK GDPR, information governance, privacy, secure communication, record handling, social media professionalism, cyber awareness, appropriate information sharing, consent and information sharing, professional standards, and safeguarding and information sharing. Match the learning to the actual concern and your role, rather than taking generic GDPR training.

What evidence may demonstrate improvement?

Relevant training

Targeted education on the specific issue.

Assessment

Demonstrates understanding.

Reflection

Learning and insight, fully anonymised.

Action plan

Structured steps to prevent recurrence.

Supervision

Supported development.

Feedback

Evidence of changed practice from colleagues.

Access audit or review

Where authorised, shows appropriate access over time.

Updated practice

Specific safeguards or process changes introduced.

Specific
Addresses the actual information-handling issue.
Relevant
Matches your role and the systems you use.
Practical
Changes how information is handled day to day.
Proportionate
Targets the actual risk.
Evidence-based
Supported by appropriate, anonymised evidence.
Sustained
Improvement continues over time.

Common confidentiality remediation mistakes

  • "Never share information". Appropriate sharing is often essential.
  • Consent as the only basis. Other lawful bases often apply in healthcare.
  • Generic GDPR training. Unrelated to the specific concern.
  • Certificates without changed practice. No evidence of safer handling.
  • Identifiable information in reflections. Creating a new breach.
  • Assuming no name means anonymous. Combinations identify people.
  • Ignoring local policies. Information governance rules apply to you.
  • Not reflecting on why it happened. Only on what happened.
  • Disclosure, not process. The underlying process left unchanged.
  • Treating an accident as deliberate. Or the reverse.
  • No safeguards shown. Nothing demonstrates reduced risk.
  • One framework for all regulators. Standards differ.

If a confidentiality concern has become a regulatory issue

If your handling of confidential information is being considered by a regulator, employer or other formal body, this page provides general educational information rather than case-specific legal or regulatory advice. Where a concern could also involve a data protection offence, independent advice is particularly important.

Consider advice from a regulatory solicitor, your professional defence organisation, your trade union or another appropriate professional adviser.

IRR Practice is an independent education provider. Find your regulator.

How IRR Practice can support confidentiality learning

Understand

Professional confidentiality and information-handling principles.

Learn

Targeted education for the identified learning need.

Reflect

Consider what happened and what needs to change.

Evidence

A certificate and learning record for your wider evidence.

Educational learning may form part of a wider remediation process. IRR Practice does not determine regulatory outcomes and cannot guarantee that a regulator, employer or panel will accept a particular course or form of evidence.

Related learning

IRR pillar

Insight

  • Impact of disclosure on patients
  • Understanding responsibility
  • Expressing insight specifically
CPDStructured CPD · 1.5 CPD pts
Enrol Now
IRR pillar

Reflection and Reflective Practice

  • Reflecting without identifying patients
  • Analysing why an incident happened
  • Linking reflection to safeguards
CPDStructured CPD · 1.5 CPD pts
Enrol Now
IRR pillar

Remediation

  • Building a confidentiality action plan
  • Evidencing safer information handling
  • Presenting evidence safely
CPDStructured CPD · 1.5 CPD pts
Enrol Now
Core

Confidentiality

  • The professional duty of confidentiality
  • Appropriate information sharing
  • Data protection principles in practice
CPDStructured CPD · 1.5 CPD pts
Enrol Now
Digital

Social Media Professionalism

  • Identifiability and online posting
  • Messaging, groups and screenshots
  • Professional standards online
CPDStructured CPD · 2 CPD pts
Enrol Now
Privacy

Privacy, Consent and Chaperone

  • Privacy and dignity in care
  • Consent and its limits
  • Chaperones and intimate examinations
CPDStructured CPD · 1.5 CPD pts
Enrol Now

Depending on the concern, Documentation Professionalism, Probity or Professionalism for Healthcare Professionals may also be relevant.

Confidentiality remediation: FAQs

What is patient confidentiality?

Patient confidentiality is the duty to protect and appropriately handle information obtained through a professional relationship, including health information, results, images, appointments and identifying details. Every UK healthcare regulator includes it in its core standards.

What is confidentiality remediation?

It is the process of understanding a confidentiality or data handling concern, identifying the relevant professional and legal requirements, reflecting on why it happened, addressing the learning need, changing how you handle information and demonstrating that improvement safely.

Is health information protected under UK GDPR?

Yes. The ICO confirms that health data is special category personal data under the UK GDPR, which gives it additional protection. Processing it generally requires both an Article 6 lawful basis and an Article 9 condition.

Is confidentiality the same as data protection?

No. Confidentiality is a professional and common law duty to protect information entrusted to you. Data protection is the legal framework governing how personal data is processed. They overlap, but a professional usually needs to consider both.

Is patient consent always required to share information?

Not always. Consent to treatment is not the same as consent as a lawful basis for processing data, and in healthcare another lawful basis often applies. Professional guidance also sets expectations about involving patients in decisions about sharing. Follow your organisation's policies and professional guidance.

Is a confidentiality breach automatically misconduct?

No. Many incidents are accidental, reported promptly and resolved locally. The significance depends on what information was involved, who received it, whether it was accidental or deliberate, the impact and your response.

Can a confidentiality breach affect fitness to practise?

It can, particularly where access or disclosure was deliberate, repeated or without a legitimate purpose. Deliberately accessing records without a work reason is treated far more seriously than an accidental disclosure.

What does insight mean after a confidentiality concern?

It means understanding specifically what information was involved, why it was confidential, why the incident happened, your responsibility, the potential impact on the patient, what should have happened and what safeguards you have introduced.

How should I reflect on a confidentiality incident?

Work through what happened, the information involved, why the handling was inappropriate, the relevant requirements, your responsibility, the potential impact, what you have learned, what you will do differently and what evidence shows the change, without including identifiable patient details.

Can confidentiality training form part of remediation?

Yes, where it addresses the specific learning need. It is strongest when combined with reflection, changed practice and evidence such as an authorised access audit or feedback.

Can I use patient cases in my remediation evidence?

Only in line with your organisation's and regulator's requirements for anonymisation and information governance. Removing a name is not enough, as combinations of details can identify someone. If unsure, ask your information governance lead first.

Does confidentiality remediation differ between UK regulators?

Yes. Professional confidentiality standards vary by regulator, and employers have their own information governance policies. The ICO is the authoritative source for UK data protection law.

Sources for this guide

This guide draws on published professional standards and data protection guidance. Naming a regulator does not imply that it endorses IRR Practice or its courses.

Law and guidance change. Always check current guidance from your regulator, the ICO and your organisation.

  • ICO Guidance on special category data and lawful basis under the UK GDPRAuthoritative source for UK data protection law
  • GMC Confidentiality: good practice in handling patient informationCurrent published version
  • NMC The Code, standard 5Current published version
  • HCPC Standards of conduct, performance and ethicsCurrent published version
  • National Data Guardian The Caldicott PrinciplesHealth and care in England

More from the IRR Practice blog

Practical articles on fitness to practise, insight, reflection, remediation and each UK regulator.

Read the blog
Dr Anthony Whitfield

Dr Anthony Whitfield

Writes for IRR Practice on professional standards, fitness to practise, insight, reflection and remediation for UK healthcare professionals.

Last reviewed: September 2026