Lesson 8 - Confidentiality and Information Governance

1. Lesson Overview

Patients and families provide sensitive personal information during structured appointments. They must be able to trust that this information will be accessed, recorded, stored and shared appropriately.

Confidentiality means protecting information entrusted to the service. Information governance is the wider system used to ensure that information is accurate, secure, available when needed and handled lawfully.

The assistant practitioner must use only approved systems and access only the information required for their work. Any actual or suspected information governance incident must be reported immediately.

Suggested duration: 75 minutes
Delivery method: Self-directed learning followed by case discussion
Practical requirement: Completion of an information-handling exercise
Additional requirement: Completion of WMI Psychiatry information governance and cybersecurity training

2. Learning Outcomes

By the end of this lesson learners should be able to:

  • Explain confidentiality and information governance.

  • Recognise health information as particularly sensitive personal information.

  • Access only the information needed for an authorised work purpose.

  • Verify identity before discussing or sharing patient information.

  • Use approved systems to record, store and communicate information.

  • Maintain privacy during in-person and remote appointments.

  • Recognise when information may need to be shared for safety or safeguarding.

  • Respond appropriately to requests from parents, carers and other professionals.

  • Recognise common information governance incidents.

  • Take immediate action following an actual or suspected breach.

3. The Lecture

What is confidentiality?

Confidentiality means protecting information learned through a professional role.

Patient information should not be disclosed to another person unless:

  • The patient has agreed where consent is required.

  • Sharing is necessary for the person’s care.

  • Sharing is required by law.

  • Sharing is necessary to protect the patient or another person from serious harm.

  • Another lawful and appropriate basis applies.

  • The disclosure has been authorised through the correct WMI Psychiatry process.

Confidentiality applies to:

  • Spoken information.

  • Written records.

  • Emails.

  • Forms.

  • Questionnaires.

  • Photographs.

  • Video recordings.

  • Audio recordings.

  • Screenshots.

  • Appointment details.

  • Contact details.

  • Financial information.

  • Information about whether somebody is a patient.

  • Information learned informally during work.

Even confirming that a person is receiving care from WMI Psychiatry may disclose confidential information.

What is information governance?

Information governance describes the systems and responsibilities used to manage information safely.

It includes:

  • Confidentiality.

  • Data protection.

  • Cybersecurity.

  • Accurate record keeping.

  • Appropriate access.

  • Secure storage.

  • Safe communication.

  • Retention and disposal.

  • Information sharing.

  • Responding to data breaches.

  • Patient rights.

  • Staff training and accountability.

Information governance is not only an administrative responsibility. Every staff member who handles patient information has a part to play.

Why health information requires particular care

Health information can reveal highly personal details about:

  • Mental health.

  • Diagnoses.

  • Medication.

  • Family circumstances.

  • Development.

  • Education.

  • Relationships.

  • Risk.

  • Abuse.

  • Substance use.

  • Physical health.

  • Disability.

  • Religious or cultural background.

  • Sexuality.

  • Financial circumstances.

The UK GDPR identifies health information as special category data. It requires additional protection and an appropriate legal basis for processing. ICO: Special category data

The assistant practitioner does not need to determine the service’s legal basis each time they complete an authorised task. They do need to follow WMI Psychiatry procedures and avoid using information for any unauthorised purpose.

The main principles in practice

The practitioner should follow these practical principles:

  • Use information only for an authorised purpose.

  • Collect only information that is relevant.

  • Keep information accurate.

  • Store information securely.

  • Access only records needed for work.

  • Share only what is necessary.

  • Confirm who will receive the information.

  • Retain information only through approved systems.

  • Report incidents immediately.

  • Be open with patients about how their information is used.

Need-to-know access

Access to a clinical system does not mean that the practitioner may open any record.

The practitioner should access a patient’s record only when:

  • They are involved in an authorised appointment or task.

  • The information is needed for that work.

  • Their level of access is appropriate to their role.

  • There is a legitimate professional reason.

The practitioner must not access a record because:

  • They know the patient socially.

  • The person is well known.

  • They are curious.

  • A friend asks them to look.

  • They want to check whether a colleague is receiving treatment.

  • They are concerned about a relative but are not involved in their care.

  • They want to practise using the system.

Access may be audited. Inappropriate access is a serious confidentiality breach even if no information is shared.

Accessing the correct record

Before reading or entering information the practitioner should confirm the correct patient.

They should check approved identifiers such as:

  • Full name.

  • Date of birth.

  • Address or postcode.

  • Zanda identification number where appropriate.

People may have similar names. The practitioner should never rely on name alone.

Only one patient record should be open where possible. Unrelated records should be closed.

Discussing patients with colleagues

Patient information may be discussed with colleagues who require it for the patient’s care or the safe operation of the service.

Discussions should take place:

  • Through approved communication systems.

  • In a private environment.

  • With appropriate members of the team.

  • Using only the information needed.

  • For a clear professional purpose.

Patient information should not be discussed:

  • In corridors.

  • In waiting areas.

  • In cafés.

  • On public transport.

  • In lifts.

  • In social settings.

  • With family or friends.

  • With staff who are not involved.

  • Through personal messaging groups.

Removing the patient’s name may not be enough if other details could identify them.

Privacy during appointments

The appointment should take place in a private environment.

For an in-person appointment the practitioner should:

  • Use an appropriate room.

  • Close the door where possible.

  • Ensure conversations cannot easily be overheard.

  • Position screens away from public view.

  • Remove documents relating to other patients.

  • Lock the computer when leaving the room.

  • Avoid leaving forms unattended.

  • Dispose of confidential waste securely.

For a remote appointment the practitioner should:

  • Work from a private location.

  • Use an approved platform.

  • Wear headphones where needed.

  • Check who else can hear the conversation.

  • Avoid using a speakerphone in a shared space.

  • Avoid displaying information about other patients.

  • Use an appropriate private background.

  • Prevent household members from entering.

  • Close unrelated applications and notifications.

The practitioner should not conduct confidential appointments from a public place.

Confirming who is present

At the beginning of a remote appointment the practitioner should ask:

“Could you confirm who is in the room or able to hear the conversation?”

Someone may be present but outside the camera view.

The practitioner should record who attended and whether anyone joined or left.

If privacy cannot be established the practitioner should consider whether the appointment can continue safely.

Confidentiality when parents or carers attend

A parent or carer may attend to provide information. Their presence does not automatically mean that every item of patient information can be disclosed to them.

The practitioner should understand:

  • Who has been invited.

  • Who is providing the information.

  • Whether the patient has agreed to their involvement where required.

  • Whether the clinical team has given instructions.

  • Whether any restriction is recorded.

  • Whether there is a safeguarding concern.

Children and young people have confidentiality rights. A young person’s understanding, wishes and circumstances may affect what can be shared. NHS: Information for under-16s about parent and guardian access

The assistant practitioner should not independently make a complex decision about a young person’s capacity, parental responsibility or access to records. They should seek advice from a qualified clinician.

Separated parents

A parent may ask the service to:

  • Change the primary email address.

  • Remove another parent’s contact details.

  • Send copies of reports.

  • Prevent another parent from receiving information.

  • Discuss the child’s assessment.

  • Cancel an appointment arranged by another parent.

The practitioner should not make these changes based only on one person’s request.

They should:

  1. Verify the identity of the person making the request.

  2. Record the request accurately.

  3. Avoid disclosing information during the initial contact.

  4. Check the clinical record for existing instructions.

  5. Refer the matter to the appropriate clinician or manager.

  6. Follow the WMI Psychiatry parental responsibility and information-sharing procedure.

  7. Avoid taking sides in a parental dispute.

Parental separation does not by itself determine who may receive information. Each request must be considered through the proper process.

Telephone enquiries

Before discussing patient information by telephone the practitioner should verify the caller’s identity using the approved procedure.

The practitioner should not rely only on:

  • The caller knowing the patient’s name.

  • The telephone number displayed.

  • The caller sounding familiar.

  • The caller stating that they are a parent.

  • The caller knowing the appointment date.

If identity or authority is uncertain the practitioner should:

  • Avoid disclosing information.

  • Take a message.

  • Explain that the service needs to complete appropriate checks.

  • Seek advice from a manager or clinician.

A safe response is:

“I am unable to discuss the record until the required identity and authority checks have been completed. I can take your details and ask the appropriate person to review the request.”

Emails

Before sending an email containing patient information the practitioner should check:

  • The recipient’s address.

  • Whether the recipient is authorised.

  • Whether the patient has agreed where required.

  • Whether the email contains only necessary information.

  • Whether the correct attachment is included.

  • Whether another patient’s information is visible.

  • Whether the approved clinic account is being used.

  • Whether encryption or another secure method is required.

  • Whether the subject line reveals unnecessary information.

  • Whether copied recipients need the information.

The practitioner should pause before pressing send.

Email address autofill can select the wrong recipient. The full address should be checked manually.

Patient information must not be sent through a personal email account.

Attachments

Attachments create particular risk.

Before sending an attachment the practitioner should:

  1. Open the file.

  2. Confirm the patient’s identity.

  3. Check that it is the correct version.

  4. Review the full document.

  5. Check for information about another person.

  6. Remove unnecessary hidden information where required.

  7. Confirm the recipient.

  8. Use the approved secure process.

A filename alone is not enough to confirm the contents.

Group emails

Patient email addresses should not be exposed to other patients or families.

If a message must be sent to several unrelated recipients the approved bulk communication process should be used.

The practitioner should not place unrelated patient addresses in the “To” or “CC” field.

Messaging services

Patient information must not be shared through personal messaging accounts.

This includes:

  • Personal WhatsApp.

  • Personal text messages.

  • Facebook Messenger.

  • Instagram.

  • Telegram.

  • Personal Slack workspaces.

  • Other unapproved applications.

If an approved clinical messaging system is available it should be used only according to WMI Psychiatry procedure.

Messages relevant to care may need to be transferred into the clinical record.

Passwords and account security

The practitioner should:

  • Use a strong and unique password.

  • Keep passwords private.

  • Use multi-factor authentication where provided.

  • Lock the screen when leaving a device.

  • Sign out of shared devices.

  • Report unexpected login prompts.

  • Report suspected account compromise.

  • Keep recovery details secure.

  • Complete software updates as instructed.

The practitioner should not:

  • Share passwords.

  • Write a password where others can see it.

  • Allow another person to work through their account.

  • Approve an unexpected multi-factor authentication request.

  • Reuse a personal password for a work account.

  • Leave a device unlocked.

Activity completed through the practitioner’s account may be attributed to them.

Phishing and suspicious messages

A phishing message may attempt to persuade the practitioner to:

  • Enter a password.

  • Open an attachment.

  • Follow a link.

  • Approve a login.

  • Transfer money.

  • Send patient information.

  • Download software.

  • Change account details.

Possible warning signs include:

  • Unexpected urgency.

  • A slightly altered email address.

  • An unusual request from a senior colleague.

  • Poor formatting.

  • An unexpected attachment.

  • A request to bypass normal procedure.

  • A login page reached through an email link.

  • A request for passwords or verification codes.

The practitioner should not respond through the suspicious message. They should verify the request using a known contact route and report it according to the cybersecurity procedure.

Paper records

Where paper documentation is authorised the practitioner should:

  • Keep it in their possession.

  • Avoid leaving it in a car.

  • Store it in an approved locked location.

  • Prevent other people from viewing it.

  • Transfer it to the approved record promptly.

  • Dispose of it through confidential waste.

  • Record any loss immediately.

Paper containing patient information must not be placed in ordinary household or office waste.

Working away from clinic premises

When working remotely the practitioner should:

  • Use an authorised device.

  • Use a secure internet connection.

  • Avoid public Wi-Fi unless an approved secure method is used.

  • Prevent family members from accessing the device.

  • Store no patient information in a personal folder.

  • Avoid printing unless authorised.

  • Keep the work area private.

  • Lock the screen when away.

  • Follow the clear-desk procedure.

  • Return any authorised paper records securely.

Patient information should not be stored permanently at a room-hire location unless this has been specifically authorised.

Approved storage

Patient information should be saved only in a system or location approved for that type of information.

The practitioner should not assume that every organisational account or shared folder is suitable for clinical information.

They should not save identifiable patient information in:

  • Personal cloud storage.

  • A personal computer folder.

  • A personal email account.

  • An ordinary shared folder that is not approved for clinical records.

  • An unencrypted removable drive.

  • A personal mobile telephone.

  • An unauthorised notes application.

  • A temporary download folder beyond the authorised task.

If uncertain the practitioner should ask before saving the file.

Downloads and temporary files

Opening an attachment may create a local downloaded copy.

The practitioner should:

  • Use approved devices.

  • Avoid downloading unless required.

  • Save files directly to the approved location where possible.

  • Remove temporary copies through the approved secure process.

  • Empty authorised temporary storage where required.

  • Check that files have not synchronised to a personal account.

  • Report any accidental unauthorised storage.

Deleting a file may not remove every copy if it has synchronised elsewhere. Advice should be obtained following an accidental upload or download.

Screenshots, photographs and recordings

The practitioner must not make a screenshot, photograph, audio recording or video recording of patient information unless this is explicitly authorised.

They should not:

  • Photograph a form with a personal telephone.

  • Record an appointment for note-taking.

  • Use automatic transcription without approval.

  • Screenshot the clinical record.

  • Ask a patient to send sensitive information through an unapproved method.

If an authorised recording is required the consent, storage and access process must be followed.

Artificial intelligence tools

Patient information must not be entered into an artificial intelligence system unless WMI Psychiatry has specifically approved the system and the exact use.

The practitioner should not enter:

  • Names.

  • Dates of birth.

  • Contact details.

  • Zanda identification numbers.

  • Clinical histories.

  • Appointment transcripts.

  • Reports.

  • Questionnaire responses.

  • Risk information.

  • Details that could indirectly identify the person.

Removing the name may not make a detailed clinical account anonymous.

The practitioner should seek advice before using any automated transcription, summarisation or drafting tool.

Sharing information for care

Relevant information may be shared with members of the clinical team when needed for the patient’s assessment or care.

The practitioner should share:

  • Only information needed for the purpose.

  • Through an approved channel.

  • With an authorised person.

  • At the appropriate time.

  • With clear identification of the patient and source.

The practitioner should not withhold relevant information from the clinical team because a patient asks them to keep it “off the record”.

They should explain the limits of confidentiality before sensitive information is discussed.

Sharing information for safeguarding

Confidential information may need to be shared to protect a child, an adult at risk, the patient or another person.

The practitioner should not delay urgent safeguarding action because they are uncertain about confidentiality.

They should:

  1. Contact the supervising clinician or Safeguarding Lead.

  2. Share the concern through an approved route.

  3. Share only relevant information.

  4. Record what was shared.

  5. Record who authorised or received the disclosure.

  6. Explain the sharing to the patient where safe and appropriate.

  7. Follow the safeguarding procedure.

The ICO’s Data Sharing Code supports fair, safe and transparent sharing while protecting privacy. ICO: Data Sharing Code of Practice

Requests from schools, GPs or other services

An outside professional may request information.

The practitioner should not assume that a professional title automatically permits disclosure.

They should:

  • Verify the requester.

  • Confirm the purpose.

  • Check whether appropriate consent or another authority exists.

  • Refer the request through the approved process.

  • Share only authorised information.

  • Record the disclosure.

The assistant practitioner should not independently decide what parts of a clinical report should be released.

Subject access and requests for records

Patients may ask for copies of their records. Parents may request information about a child.

The practitioner should not send records immediately in response to an informal request.

They should:

  • Record the request.

  • Confirm the requester’s identity.

  • Pass it to the person responsible for information requests.

  • Follow the WMI Psychiatry subject access procedure.

  • Avoid altering or deleting the record.

The relevant lead will consider identity, authority, third-party information and any applicable exemptions.

Requests to correct or delete information

A patient may state that information is wrong.

The practitioner should:

  • Listen to the concern.

  • Record what correction is requested.

  • Identify the exact record.

  • Avoid deleting information themselves.

  • Refer the request through the approved process.

  • Correct straightforward demographic information only where authorised.

  • Preserve the original clinical record where required.

A difference of opinion is not always the same as a factual error.

What is a personal data breach?

A personal data breach is a security incident involving the accidental or unlawful:

  • Loss of personal information.

  • Destruction of information.

  • Alteration of information.

  • Unauthorised disclosure.

  • Unauthorised access.

  • Loss of availability.

Examples include:

  • Sending an email to the wrong person.

  • Attaching the wrong patient’s report.

  • Losing a paper form.

  • Uploading a patient document to an unauthorised folder.

  • Discussing a patient where others can hear.

  • Accessing a record without a work reason.

  • Leaving a computer unlocked.

  • Losing a work device.

  • Sharing a password.

  • Clicking a phishing link and entering work credentials.

  • Photographing a form on a personal telephone.

  • Including patient addresses in a group email.

  • Giving information to an unverified caller.

  • Being unable to access records because of a cyberattack.

Responding to a breach

If an incident occurs the practitioner should:

  1. Take immediate safe steps to contain it.

  2. Do not conceal the incident.

  3. Inform the WMI Psychiatry Data Protection Lead or appropriate manager immediately.

  4. Preserve relevant evidence.

  5. Record what happened.

  6. Follow instructions about recovery or notification.

  7. Complete the incident reporting process.

  8. Avoid contacting affected people unless instructed.

  9. Reflect on the incident and any required learning.

Containment may include:

  • Asking an unintended recipient not to open an email.

  • Recalling an email if the system allows it.

  • Locking or disabling a lost device.

  • Changing a compromised password through the approved process.

  • Removing access to an incorrectly shared file.

  • Disconnecting a compromised device from the network where instructed.

The practitioner should not decide that an incident is too minor to report. The Data Protection Lead assesses the level of risk and whether any external notification is required.

Near misses

A near miss is an event that could have caused a breach but was identified before information was exposed.

Examples include:

  • Noticing the wrong attachment before sending.

  • Identifying an incorrect email address before pressing send.

  • Finding a confidential document left near a shared printer before anyone else sees it.

  • Opening the wrong patient record but recognising this before viewing further information or making an entry.

Near misses should be reported according to WMI Psychiatry procedure. They help the service improve its systems.

Clear desk and clear screen

At the end of work the practitioner should:

  • Close patient records.

  • Sign out where required.

  • Lock the device.

  • Remove confidential paper.

  • Check printers and scanners.

  • Close email attachments.

  • Secure any authorised notes.

  • Remove patient details from visible calendars or reminders.

  • Confirm that documents are saved in the correct place.

The practitioner should not leave information visible for the next person using the room.

A final information governance check

Before accessing, recording or sharing information the practitioner should ask:

  • Do I need this information for my role?

  • Am I in the correct patient record?

  • Is this an approved system?

  • Is the person authorised to receive it?

  • Have I verified their identity?

  • Am I sharing only what is necessary?

  • Is the environment private?

  • Have I checked the attachment and recipient?

  • Will the action be recorded where required?

  • Do I need advice before proceeding?

If uncertain the practitioner should pause and seek guidance.

4. Clinical Perspective

Clinical pearl: Access is not permission

Being able to open a record does not mean there is a legitimate reason to do so.

Clinical pearl: Confirm identity before discussing the patient

A familiar voice, telephone number or email address is not always enough.

Clinical pearl: Check the contents rather than the filename

A file may have the correct name but contain another patient’s information.

Clinical pearl: Report quickly rather than trying to hide a mistake

Prompt reporting gives the service the best opportunity to contain an incident and reduce harm.

Clinical pearl: Confidentiality does not prevent necessary safeguarding action

Relevant information can be shared through the appropriate process when needed to protect someone from harm.

Common pitfall: Using autofill without checking the email address

Always read the complete recipient address before sending.

Common pitfall: Assuming a parent can access everything

A child or young person has confidentiality rights. Complex requests should be reviewed by a clinician or appropriate manager.

Common pitfall: Discussing a memorable case without using the name

A person may still be identifiable from age, location, circumstances or other details.

Common pitfall: Saving a file temporarily on a personal device

Temporary storage can still create a data breach or unauthorised copy.

Common pitfall: Trying to resolve an incident alone

The practitioner should contain the incident where possible and report it immediately.

When to escalate

The practitioner should seek immediate advice if:

  • Information has been sent to the wrong person.

  • The wrong patient record has been accessed.

  • Information has been entered into the wrong record.

  • A device or paper document is missing.

  • A password may have been compromised.

  • A patient document has been placed in an unauthorised folder.

  • An unverified person requests information.

  • Parents disagree about access to a child’s information.

  • A young person requests that information is withheld from a parent.

  • A patient requests deletion of a clinical record.

  • Safeguarding information may need to be shared.

  • The practitioner is uncertain whether a system is approved.

  • Any information governance incident or near miss occurs.

5. Case Examples

Case Example 1: Incorrect email attachment

The practitioner prepares an email to a parent and notices that the attachment relates to another patient.

They should remove the attachment and check whether it was sent or opened. The near miss or breach should be reported according to WMI Psychiatry procedure.

They should not simply replace the attachment without considering whether any information was exposed.

Case Example 2: A request from a separated parent

A mother asks the practitioner to remove the father’s email address and make her the only contact.

The practitioner should verify her identity and record the request. They should not change the record immediately or disclose existing communications. The request should be reviewed through the appropriate process.

Case Example 3: A familiar patient

The practitioner notices that a neighbour is receiving an assessment and opens the record out of curiosity.

This is an unauthorised access and must be reported. The practitioner had no work-related reason to view the record.

Case Example 4: A public appointment

A patient joins a video appointment from a busy café.

The practitioner should explain that sensitive information cannot be discussed safely in that environment. They should ask whether the patient can move to a private location or arrange for the appointment to be rescheduled.

Case Example 5: A safeguarding disclosure

A young person asks the practitioner not to tell anyone about abuse at home.

The practitioner should explain that they cannot keep safety information secret. They should share the concern promptly through the safeguarding procedure and record what was disclosed.

Case Example 6: Accidental cloud storage

A patient document is accidentally saved to an unauthorised shared folder.

The practitioner should restrict or remove access where possible and immediately inform the Data Protection Lead. They should not assume that deleting the file resolves the incident.

Case Example 7: An unverified caller

A caller states that he is the patient’s father and asks for the assessment outcome.

The practitioner should complete the approved identity and authority checks. If these cannot be completed they should not disclose information.

Case Example 8: Personal artificial intelligence use

A practitioner copies an appointment transcript into a public artificial intelligence service to produce a summary.

This is not permitted unless the exact system and purpose have been approved by WMI Psychiatry. Removing the patient’s name may not remove the risk of identification.

6. Summary

The assistant practitioner must:

  • Protect patient confidentiality.

  • Access records only for an authorised purpose.

  • Confirm the correct patient.

  • Verify identity and authority before disclosure.

  • Use approved systems and devices.

  • Keep appointments private.

  • Check email recipients and attachments.

  • Share only necessary information.

  • Follow the correct process for parent and carer requests.

  • Seek advice about children’s confidentiality.

  • Share safety information through appropriate channels.

  • Report incidents and near misses immediately.

  • Maintain clear desk and clear screen standards.

  • Avoid unapproved artificial intelligence or transcription tools.

The assistant practitioner must not:

  • Access records out of curiosity.

  • Discuss patients casually.

  • Use personal email or messaging accounts.

  • Save patient information in unauthorised locations.

  • Photograph or record patient information without approval.

  • Share information with an unverified caller.

  • Assume that any parent may access a child’s full record.

  • Change contact details during a parental dispute without review.

  • Hide a data breach.

  • Decide alone whether an incident is serious enough to report.

7. Further Reading

8. Reflective Exercise

The learner should consider:

  1. What information could reveal that somebody is a WMI Psychiatry patient?

  2. When would you have a legitimate reason to open a patient record?

  3. How would you verify a telephone caller’s identity and authority?

  4. What checks would you complete before sending an attachment?

  5. How would you respond if separated parents gave conflicting instructions?

  6. What would you do if a young person asked for information to be withheld from a parent?

  7. Why might removing a patient’s name not make a clinical account anonymous?

  8. What would you do after entering information into the wrong patient record?

  9. What is the difference between containing an incident and concealing it?

  10. Who is the WMI Psychiatry Data Protection Lead and how would you contact them?

The learner should discuss their responses with their supervisor.

9. Practical Competency Activity

The learner should complete a supervised information-handling exercise involving:

  • Two patients with similar names.

  • An email with an incorrect attachment.

  • A telephone request from a parent.

  • Conflicting requests from separated parents.

  • A young person asking for confidentiality.

  • A remote appointment where another person is listening.

  • An accidental upload to an unauthorised folder.

  • A suspicious login request.

  • A request from an outside professional.

  • A potential safeguarding disclosure.

The learner should demonstrate that they can:

  1. Select the correct patient record.

  2. Verify identity and authority.

  3. Maintain privacy.

  4. Use only approved systems.

  5. Check recipients and attachments.

  6. Recognise a confidentiality concern.

  7. Respond appropriately to a parental request.

  8. Explain the limits of confidentiality.

  9. Share safeguarding information through the correct route.

  10. Contain and report a data breach.

  11. Identify a near miss.

  12. Complete the relevant documentation.

Competency should not be signed off until the learner can explain the immediate steps required after an information governance incident.

10. Knowledge Check

Complete the short knowledge check below to consolidate your learning and check your understanding of the key principles covered in this lesson. You can review the lesson content again before submitting your answers.

Link to Knowledge Check

Previous
Previous

Lesson 9 - Managing Common Difficulties During Appointments

Next
Next

Lesson 7 - Risk and Safeguarding