Confidentiality
Reviewed by Dr C. J. Odike, MRCGP · June 2026
People need confidence that health information will be handled respectfully. Safe care also depends on relevant information reaching the right people. Confidentiality therefore requires both protection and appropriate sharing.
Confidentiality protects trust and safe care Confidentiality means protecting information that people reasonably expect health and care services to keep private. This includes diagnoses, conversations, appointments, prescriptions, test results, images and information about family or social circumstances. The duty can apply even when a name is absent if the person could still be identified. It also continues after a person has died, although lawful disclosures may still occur. Confidentiality is not the same as total secrecy. Safe care can fail when relevant information does not reach people providing treatment or support. The duty to share for individual care can be as important as the duty to protect information. Several rules work together The common law duty of confidentiality governs information received in circumstances where privacy is reasonably expected. It usually requires consent, legal authority or a sufficiently strong public interest reason before confidential information is disclosed outside expected use. Data protection law governs how personal information is collected, recorded, used, stored, shared and deleted. Health data receives extra protection. Organisations need a lawful basis, must be transparent and must use proportionate security. Professional standards and organisational policies add further duties. The Caldicott Principles guide health and social care organisations in England. They emphasise justified purposes, necessity, data minimisation and need to know access. Consent to treatment, consent to disclose confidential information and consent under data protection law are related but different concepts. One does not automatically provide the others. Direct care usually involves appropriate sharing Direct care includes activities that directly contribute to one person's diagnosis, treatment, care or support. It can involve clinicians, social care professionals and administrative staff who directly support that care. Relevant confidential patient information can usually be shared within the direct care team on the basis of implied consent. This applies when people are informed about expected sharing, the recipient needs the information for care and there is no known objection. Implied consent means agreement is reasonably inferred from the circumstances. It is not the same as using consent as the lawful basis under the UK General Data Protection Regulation. Explicit consent means the person actively agrees, verbally or in writing. It is usually needed when sharing would be unexpected or is for a purpose beyond direct care, unless another legal route applies. Shared information should be accurate, relevant and limited to what the recipient needs. Sending a complete record is not automatically justified when a short referral summary is sufficient. People can object to direct care sharing A person with capacity can object to particular information being shared for their care. The professional should explore the concern, explain possible consequences and consider whether a workable compromise exists. The objection should usually be respected. Disclosure may still be justified by law, a strong public interest reason or the overall benefit of a person who lacks capacity. Sometimes a referral or treatment cannot be arranged safely without essential information. The professional should explain this rather than secretly sending the information or pretending safe care is possible without it. The National Data Opt Out in England concerns uses of confidential patient information for research and planning. It does not stop information being used or shared for a person's own care. Family and carers do not have automatic access Being a spouse, partner, parent of an adult, adult child or named next of kin does not create a general right to health information. Professionals should establish what the person wants shared, with whom and in what circumstances. Family members and carers can still give information to a healthcare team. Listening to their concern does not require the professional to reveal confidential details in return. Professionals can often provide general information about a condition or available support without confirming private facts about the person. Specific disclosure needs permission or another valid justification. If an adult lacks capacity for the disclosure decision, information may be shared when it is of overall benefit and the relevant legal framework is followed. Relatives can provide valuable evidence about wishes and values, but they do not automatically gain access to the full record. Children and young people also have confidentiality rights Confidentiality applies to children and young people as well as adults. A young person who can understand the disclosure decision should usually be involved and asked for consent. Parents may need information to support care, especially for a younger child. However, parental responsibility does not justify unnecessary access to every confidential detail in all circumstances. Information may be shared without consent when required by law or when necessary to protect a child or another person from serious harm. Seeking consent should not delay action when delay could increase danger. Disclosure without consent needs a clear justification Confidentiality is not absolute. Disclosure without consent may be required by law, directed by a court, permitted through a statutory process or justified in the public interest. A public interest disclosure may be justified when failure to share would expose a person or society to a risk of death or serious harm. A vague concern or general curiosity is not enough. Safeguarding can require information sharing about a child or an adult at risk. Professionals should seek consent when safe and practicable, but they should not allow confidentiality fears to prevent necessary protection. The decision should consider the likely harm from sharing, the harm from not sharing and whether the purpose can be achieved another way. Only relevant information should go to an appropriate person or authority. When practicable, professionals should seek advice from a Caldicott Guardian, data protection lead, safeguarding lead or experienced colleague. They should record the reasoning and what was shared. The person should usually be told about the disclosure. This may be delayed or omitted when informing them would increase risk, undermine a serious investigation or defeat the purpose of sharing. Police, employers, insurers, schools and solicitors do not automatically have access to health records. Disclosure usually needs explicit consent, a legal requirement, a court order or a justified public interest basis. Uses beyond individual care follow different routes Health information can support research, planning, public health, service evaluation, education and clinical audit. These uses do not all follow the same rules. Anonymised information should be used when the purpose can be achieved without identifying people. Anonymised information is no longer personal information when identification is not reasonably possible. Identifiable information beyond direct care may require explicit consent, legal authority, statutory approval or another recognised route. People should receive clear information about how data is used and any choices available. Security supports confidentiality but does not replace it Secure systems, strong passwords, access controls and identity checks reduce the risk of loss or unauthorised access. Staff should verify recipients, avoid discussing patients where they can be overheard and use authorised communication systems. Security alone is not enough. An encrypted record is still misused if someone opens it from curiosity or sends more information than the purpose requires. A data breach can involve loss, unauthorised access, accidental disclosure or inappropriate alteration. Concerns should be reported promptly through the organisation's process so risks can be contained and assessed. People can ask how their information is used, request access to much of their record and ask for inaccurate information to be corrected. Some rights have legal limits, including restrictions protecting other people or preventing serious harm. A person who believes their information was mishandled can complain to the organisation. They may also raise a data protection concern with the Information Commissioner's Office. This lesson explains general UK principles. Exact legal routes differ between UK nations and between clinical situations. It does not decide whether information should be shared in an individual case.
Confidentiality requires both protection and appropriate sharing. Direct care often relies on expected, need to know sharing. Unexpected or wider disclosure needs explicit consent, legal authority or a justified public interest reason.
Medical words made simple
- Confidentiality
- The duty to protect information that a person reasonably expects health and care services to keep private and to disclose it only appropriately.
- Confidential patient information
- Information that identifies or could identify a person and reveals something about their health, care or treatment.
- Common law duty of confidentiality
- A legal duty arising from court decisions that protects information given or received in circumstances where privacy is reasonably expected.
- Data protection
- Law and practice governing how personal information is collected, used, stored, shared, secured and handled when people exercise their rights.
- Direct care
- Activities that directly contribute to one person's diagnosis, treatment, care or support.
- Implied consent
- Agreement reasonably inferred from the circumstances. In direct care, it can support expected sharing when the person is informed and has not objected.
- Explicit consent
- Active spoken or written agreement to a clearly explained use or disclosure of information.
- Need-to-know
- Access limited to people who need particular information for a legitimate role or purpose.
- Data minimisation
- Using or sharing only the personal information that is necessary for a defined purpose.
- Public interest
- A wider benefit or protection that can sometimes justify disclosure without consent, such as preventing death or serious harm.
- Safeguarding
- Action to protect a child or an adult at risk from abuse, neglect or other harm. It may require appropriate information sharing.
- Anonymised information
- Information changed so that no person can reasonably be identified from it or other available information.
- National Data Opt-Out
- An England choice limiting many uses of confidential patient information for research and planning. It does not apply to information used for individual care.
- Data breach
- A security incident involving personal information that is lost, altered, destroyed, accessed or disclosed without proper authority.
Quick recap
- Confidentiality protects information but also permits relevant sharing for safe individual care.
- Implied consent for expected direct care sharing is different from consent as a data protection lawful basis.
- Family members and next of kin do not automatically have access to an adult's health information.
- Disclosure without consent needs law, an appropriate capacity decision or a strong public interest justification.
- Safeguarding information should be relevant, proportionate and shared promptly when delay could increase serious harm.
- Security, need to know access, data minimisation and clear patient rights all support confidentiality.