Healthcare professionals handle some of the most sensitive information people ever share. When concerns arise about patient confidentiality, information sharing, privacy or data handling, remediation means understanding both your professional duty and the legal framework, reflecting on what happened, closing the real learning gap and showing that you now handle information more safely.
Choose the closest situation. See what is likely to be considered, what to do now and where learning should focus.
Select a situation to see where to start.
Patient confidentiality is the duty to protect, and handle appropriately, information obtained through a professional relationship. It covers medical information, treatment and diagnoses, test results, photographs, appointment information, identifying details, what patients tell you during care, and any information that reveals something about a person's health.
The GMC's confidentiality guidance states that patients have a right to expect their personal information to be held in confidence by the professionals who care for them. Every UK healthcare regulator includes confidentiality in its core standards: for example, the NMC Code asks professionals to respect people's right to privacy and confidentiality (standard 5), and the HCPC's standards of conduct, performance and ethics include a standard on respecting confidentiality.
In law, the Information Commissioner's Office (ICO) confirms that health data is special category personal data under the UK GDPR, which means it receives additional protection. Health data is defined broadly and can include information about a person's past, current or future physical or mental health.
No. They overlap, but they are not interchangeable, and a healthcare professional usually needs to consider both.
| Concept | Main focus | Main source |
|---|---|---|
| Confidentiality | The duty to protect information entrusted to you as a professional | Professional standards and the common law duty of confidence |
| Data protection | The legal framework for processing personal data | UK GDPR and the Data Protection Act 2018; guidance from the ICO |
| Information governance | Organisational systems and controls for managing information | Your employer's policies and procedures |
| Privacy | The individual's interests and rights over their personal information | Law, standards and patient expectations |
| Cybersecurity | Protecting information and systems from unauthorised access or attack | Organisational security policies |
Diagnoses, treatment and medical history.
Notes, assessments and care plans.
Laboratory, imaging and other results.
Anything that identifies, or helps identify, a patient.
Clinical photographs and other identifiable images.
Even the fact of an appointment can reveal health information.
Emails, messages, letters and conversations about patients.
Details that are harmless alone can identify someone together.
Not necessarily. Many confidentiality incidents are accidental, are reported promptly and are resolved through local learning. The regulatory significance of a concern depends on the facts, the applicable professional standards and your regulator's processes.
The single most important distinction is usually between accidental disclosure, such as an email sent to the wrong address, and deliberate access or disclosure without a legitimate reason. Deliberately accessing records out of curiosity is treated very differently from a mis-addressed letter, and knowingly or recklessly obtaining or disclosing personal data without the controller's consent can be a criminal offence under the Data Protection Act 2018.
Patients share what they need to for safe care only if they believe it will be protected.
Healthcare involves some of the most personal information people have.
Appropriate sharing is often necessary for safe, coordinated care.
Professionals must understand their responsibilities for the information they handle.
Information sometimes needs to be shared for legitimate purposes, including direct care and other circumstances recognised by professional standards and law. The GMC's confidentiality guidance provides a framework for these decisions and distinguishes sharing for direct care from sharing for other purposes. Whatever your profession, the same questions sit behind a sound decision.
In England, the Caldicott Principles published by the National Data Guardian set out similar principles for health and care organisations. Always follow your organisation's information governance policies.
Consent, confidentiality and data protection are related but separate concepts, and confusing them is one of the most common misunderstandings in this area.
The ICO explains that consent to healthcare treatment is not the same as consent as a lawful basis for processing personal data, and that in healthcare another lawful basis will often be more appropriate, depending on the circumstances. Whether and how patients should be involved in decisions about sharing their information is also a matter of professional guidance, which may expect you to respect patient wishes even where sharing would be lawful.
Because health information is special category data, processing it generally requires both a lawful basis under Article 6 and a condition under Article 9 of the UK GDPR, with further requirements depending on the circumstances. In practice, most professionals rely on their organisation's established processes rather than making these decisions alone, so follow the information governance policies that apply to your role and seek advice from your information governance or data protection lead when unsure.
What happened, exactly?
What was involved, and how sensitive?
What your regulator expects.
What the law and your organisation require.
Why it happened, and your role.
Knowledge, habit or process.
How you now handle information.
Evidence, handled safely.
"I understand confidentiality now" is not insight. Specific understanding and changed practice are. Useful questions include:
Insight into impact matters particularly here. A patient whose information was disclosed may experience distress, stigma or loss of trust in their care, even when no clinical harm follows. Showing that you understand this from the patient's perspective is often central.
Remediation evidence must not create a new confidentiality problem. Case reflections, audits, clinical examples, documentation samples and incident reviews all risk including patient information. Follow your organisation's and your regulator's requirements for anonymisation, confidentiality and secure handling.
Removing a name is not enough. Identifiability often comes from combinations of details.
If you are unsure whether evidence is sufficiently anonymised, ask your information governance lead before using it, and prefer summaries or reviewer reports over copies of records.
Documentation asks whether the record is accurate, complete and appropriate. Confidentiality asks whether information is accessed, used and shared appropriately. Data protection asks whether personal data is processed lawfully.
Documentation remediationAn accidental incident is not a probity issue. A probity concern may arise from deliberately misleading others, concealment, knowingly accessing information without a legitimate purpose, falsifying information about access or disclosure, or misrepresenting what happened.
Probity remediationConfidentiality overlaps with professional responsibility, boundaries, communication, accountability, appropriate use of technology and respect for patient privacy, especially where concerns involve social media or personal devices.
Professionalism remediationRisk areas include patient stories, photographs, screenshots, clinical scenarios, workplace information, identifiable details, private messaging, closed groups and comments about patients. A patient may be identifiable even where their name is not included, particularly to people who know them. The aim is not to avoid discussing healthcare online, but to apply professional standards and appropriate information handling.
Common concerns include wrong email recipients, insecure messaging, screenshots, unauthorised system access, shared passwords, unlocked systems, information stored on unapproved devices, and personal accounts used for professional information. The exact requirements come from your employer's information governance policies and your professional standards.
A relevant confidentiality or information governance course can address an identified learning need and form part of a wider remediation plan. Course completion alone does not necessarily show that a confidentiality concern has been fully addressed. That is shown by how you now handle information.
Depending on the concern: patient confidentiality, data protection and UK GDPR, information governance, privacy, secure communication, record handling, social media professionalism, cyber awareness, appropriate information sharing, consent and information sharing, professional standards, and safeguarding and information sharing. Match the learning to the actual concern and your role, rather than taking generic GDPR training.
Targeted education on the specific issue.
Demonstrates understanding.
Learning and insight, fully anonymised.
Structured steps to prevent recurrence.
Supported development.
Evidence of changed practice from colleagues.
Where authorised, shows appropriate access over time.
Specific safeguards or process changes introduced.
Professional confidentiality requirements vary by profession and regulator, and your employer will also have its own information governance policies. For UK data protection law, the ICO is the authoritative source.
If your handling of confidential information is being considered by a regulator, employer or other formal body, this page provides general educational information rather than case-specific legal or regulatory advice. Where a concern could also involve a data protection offence, independent advice is particularly important.
Consider advice from a regulatory solicitor, your professional defence organisation, your trade union or another appropriate professional adviser.
IRR Practice is an independent education provider. Find your regulator.
Professional confidentiality and information-handling principles.
Targeted education for the identified learning need.
Consider what happened and what needs to change.
A certificate and learning record for your wider evidence.
Educational learning may form part of a wider remediation process. IRR Practice does not determine regulatory outcomes and cannot guarantee that a regulator, employer or panel will accept a particular course or form of evidence.
Depending on the concern, Documentation Professionalism, Probity or Professionalism for Healthcare Professionals may also be relevant.
Patient confidentiality is the duty to protect and appropriately handle information obtained through a professional relationship, including health information, results, images, appointments and identifying details. Every UK healthcare regulator includes it in its core standards.
It is the process of understanding a confidentiality or data handling concern, identifying the relevant professional and legal requirements, reflecting on why it happened, addressing the learning need, changing how you handle information and demonstrating that improvement safely.
Yes. The ICO confirms that health data is special category personal data under the UK GDPR, which gives it additional protection. Processing it generally requires both an Article 6 lawful basis and an Article 9 condition.
No. Confidentiality is a professional and common law duty to protect information entrusted to you. Data protection is the legal framework governing how personal data is processed. They overlap, but a professional usually needs to consider both.
Not always. Consent to treatment is not the same as consent as a lawful basis for processing data, and in healthcare another lawful basis often applies. Professional guidance also sets expectations about involving patients in decisions about sharing. Follow your organisation's policies and professional guidance.
No. Many incidents are accidental, reported promptly and resolved locally. The significance depends on what information was involved, who received it, whether it was accidental or deliberate, the impact and your response.
It can, particularly where access or disclosure was deliberate, repeated or without a legitimate purpose. Deliberately accessing records without a work reason is treated far more seriously than an accidental disclosure.
It means understanding specifically what information was involved, why it was confidential, why the incident happened, your responsibility, the potential impact on the patient, what should have happened and what safeguards you have introduced.
Work through what happened, the information involved, why the handling was inappropriate, the relevant requirements, your responsibility, the potential impact, what you have learned, what you will do differently and what evidence shows the change, without including identifiable patient details.
Yes, where it addresses the specific learning need. It is strongest when combined with reflection, changed practice and evidence such as an authorised access audit or feedback.
Only in line with your organisation's and regulator's requirements for anonymisation and information governance. Removing a name is not enough, as combinations of details can identify someone. If unsure, ask your information governance lead first.
Yes. Professional confidentiality standards vary by regulator, and employers have their own information governance policies. The ICO is the authoritative source for UK data protection law.
This guide draws on published professional standards and data protection guidance. Naming a regulator does not imply that it endorses IRR Practice or its courses.
Law and guidance change. Always check current guidance from your regulator, the ICO and your organisation.
Practical articles on fitness to practise, insight, reflection, remediation and each UK regulator.
Writes for IRR Practice on professional standards, fitness to practise, insight, reflection and remediation for UK healthcare professionals.
Last reviewed: September 2026