Information Governance and Data Protection

Who this module is for: All administrative staff, including temporary staff and anyone handling patient information.

Estimated completion time: 40–50 minutes.

How to complete this module: Read the teaching material, consider the practical scenarios and complete the knowledge check. Record your completion through WMI’s staff training process.

This module should be read alongside the current WMI policies on confidentiality, data protection, information security, records management and incident reporting.

1. Introduction

Patients trust WMI Psychiatry with information that is often deeply personal. This may include mental health difficulties, medication, family relationships, school experiences, safeguarding concerns and financial information.

Protecting that information is part of providing safe care. A report sent to the wrong person, a conversation overheard in a public place or a change to a patient’s contact details without appropriate checks can have significant consequences.

Administrative staff play an essential role in information governance. You may receive assessment forms, arrange appointments, send clinical letters, process payments and answer enquiries from relatives, schools, pharmacies and GP practices. Each of these tasks involves decisions about how information should be collected, recorded, used or shared.

You do not need to make complex legal or clinical decisions independently. You do need to recognise when information is sensitive, follow the correct process and seek advice when something is unclear.

2. Learning Outcomes

By the end of this module, you should be able to:

  • Recognise personal data and sensitive health information.

  • Apply the main data protection principles to everyday administrative work.

  • Check identity and authority before sharing patient information.

  • Handle emails, documents, telephone calls and voice messages securely.

  • Recognise requests for access, correction or deletion of information.

  • Respond promptly to a suspected data breach or confidentiality concern.

3. What Is Information Governance?

Information governance is the framework for managing information safely, appropriately and effectively.

It includes:

  • Keeping information confidential.

  • Maintaining accurate and useful records.

  • Controlling who can access information.

  • Sharing information appropriately.

  • Storing and disposing of records securely.

  • Recognising and responding to incidents.

  • Respecting people’s rights over their personal information.

Good information governance also ensures that authorised staff can access the information they need to provide care. A record that is unavailable, incorrectly filed or accidentally deleted can create a patient safety problem.

Personal data

Personal data is information relating to an identifiable living person.

Examples include:

  • Names, addresses and dates of birth.

  • Telephone numbers and email addresses.

  • Appointment details.

  • Payment records.

  • Assessment forms and clinical letters.

  • Emails, recordings and voice messages.

  • Information about relatives or members of staff.

A person does not have to be named for information to identify them. A combination of details, such as their school, age and unusual family circumstances, may be enough.

Special category data

Health information receives additional protection under data protection law. This includes information about mental health, diagnoses, symptoms, medication and treatment.

Other special categories include information about ethnicity, religious beliefs and sexual orientation. These details may also appear in psychiatric assessment records.

An administrative record can reveal health information. For example, an appointment confirmation identifying someone as attending an ADHD assessment may disclose something about their healthcare. ICO

Practical rule: Treat patient-related information as confidential, even when it appears to be routine administration.

4. The Legal and Professional Framework

The main UK data protection framework includes the UK General Data Protection Regulation, known as the UK GDPR, and the Data Protection Act 2018, as amended by subsequent legislation.

Healthcare information is also subject to confidentiality obligations. Data protection and confidentiality are related, but they are not identical. Having a data protection basis for using information does not automatically settle every question about disclosing confidential patient information.

WMI is responsible for identifying and documenting the appropriate legal basis for its activities. Admin staff should follow the clinic’s approved procedures rather than select a legal basis themselves.

Consent is not the answer to every data protection question

Healthcare organisations do not necessarily rely on UK GDPR consent to process information needed for treatment. However, patient consent and confidentiality remain important when deciding who may receive information.

For example, a patient’s partner paying an invoice does not automatically authorise the clinic to send that partner a clinical report.

If you are uncertain about a disclosure, pause and seek advice before sending the information.

5. The Seven Data Protection Principles

The UK GDPR sets out seven core principles. The table below explains how they apply to administrative work. ICO

PrincipleWhat it means in practiceLawfulness, fairness and transparencyUse information through approved processes and explain its use honestly.Purpose limitationUse information for the purpose for which it was collected, unless another use has been properly authorised.Data minimisationCollect, access and share only what is needed for the task.AccuracyCheck important details and correct errors through the appropriate process.Storage limitationFollow the retention policy rather than keeping information indefinitely.Integrity and confidentialityProtect information against unauthorised access, loss, alteration and disclosure.AccountabilityKeep appropriate records showing that the correct process was followed.

Example: data minimisation

A school requests confirmation that a child attended an appointment.

If the request is authorised, an attendance confirmation may be sufficient. Sending the full diagnostic report would disclose much more information than the task requires.

Example: accuracy

A patient provides a new email address.

Check their identity, update the appropriate record and establish whether the change affects any scheduled correspondence. Do not assume that changing one contact field updates every system or existing email thread.

Example: accountability

A clinician authorises a particular letter to be sent to a school.

Record the authorisation and recipient through the approved process so that there is a clear record of what was shared and why.

6. Confidentiality and the Caldicott Principles

The Caldicott Principles provide a framework for handling confidential information in health and care.

Their practical messages include:

  • Be clear about why confidential information is needed.

  • Use identifiable information only when necessary.

  • Use the minimum information required.

  • Restrict access to people who need it for their work.

  • Understand your responsibilities and follow the law.

  • Recognise that appropriate sharing can be essential for safe care.

  • Help patients understand how their information is used.

Confidentiality should support safe care. If information may need to be shared urgently for safeguarding or another serious safety concern, escalate promptly to a clinician or senior lead. Do not delay escalation because you are unsure about consent. GOV.UK

Access must have a work-related purpose

You may only access records needed for your authorised duties.

You must not open a record because:

  • You recognise the patient’s name.

  • The patient is a friend, neighbour or relative.

  • You are curious about their diagnosis.

  • Someone outside the clinic has asked what is happening.

Technical access to a record does not give permission to view it.

7. Checking Identity and Authority

Before disclosing information, consider two separate questions:

  1. Is this person who they say they are?

  2. Are they entitled or authorised to receive this information?

Someone may pass an identity check and still have no authority to receive a patient’s records.

Telephone enquiries

Follow WMI’s identity-checking procedure. Use the information already held in the record and the approved verification process.

Avoid giving the caller information as part of checking their identity. For example, do not ask, “Is your address still 12 Example Road?” before establishing who they are.

If a caller claims to be from a GP practice, pharmacy or another organisation, verify the request through an established or independently checked contact route where needed.

Urgency, confidence or familiarity with clinical terminology does not establish authority.

Relatives and carers

Being a spouse, parent, sibling, carer or emergency contact does not automatically authorise unrestricted access.

Check:

  • The patient’s recorded preferences and consent.

  • The scope of any existing authorisation.

  • Any relevant restrictions or safety concerns.

  • Whether clinical or senior review is needed.

An emergency contact is not automatically a person who may receive routine clinical information.

Receiving information is different from disclosing information

You can listen to a relative’s concerns and pass relevant information to the clinical team without giving them information about the patient.

A suitable response is:

“I can pass your concerns to the clinical team, but I’m unable to discuss the patient’s care without the appropriate authorisation.”

8. Children, Young People and Separated Parents

Requests involving children can require particular care.

Do not assume that:

  • The parent who pays has greater access rights.

  • The parent who arranged the appointment is the only person who may receive information.

  • A parent is entitled to every part of a young person’s record.

  • Parental responsibility automatically resolves every confidentiality question.

Decisions may depend on the child’s understanding, confidentiality interests, parental responsibility, court orders, safeguarding concerns and the particular information requested.

Admin staff should refer disputed or unclear requests to the clinical team or Data Protection Lead.

Changing the primary contact

A request to change a child’s primary contact may affect who receives appointment information, reports and clinical correspondence.

Follow WMI’s consent and verification process. Check existing arrangements and escalate any disagreement before making changes that could disclose information or exclude an authorised person.

Example

A parent says:

“We have separated. Please remove the other parent and send all future reports only to me.”

Record the request and refer it for review. Do not make the requested changes solely on the basis of that telephone call.

9. Sending Emails, Letters and Reports

Many confidentiality incidents arise from routine correspondence.

Before sending

Check:

  • The correct patient record is open.

  • The recipient is authorised to receive the information.

  • The address is correct and current.

  • The attachment belongs to the correct patient.

  • The document is the correct version and approved for release.

  • The message contains only the information needed.

  • The delivery method follows WMI policy.

Open and check the actual attachment. A correct filename does not guarantee that the contents are correct.

Be particularly careful with similar names, autocomplete suggestions and documents saved beside one another.

Email subject lines

Keep subject lines discreet. Avoid including diagnoses, medication details or sensitive family information unless necessary.

A subject line such as “WMI appointment information” will often be sufficient.

Email threads

Review the full thread before adding another recipient or forwarding a message. Previous messages may contain information that the new recipient should not receive.

Group emails

Do not expose patients’ email addresses to other recipients.

Use the approved mailing process. BCC can hide recipient addresses, but it does not make an otherwise inappropriate disclosure safe.

Postal correspondence

Check the recipient, address, document and envelope together. Keep papers for different patients separate while preparing letters.

Follow the approved postage and tracking process where required.

10. Telephone Calls, Voicemail and Voice Messages

Confidentiality applies to spoken and recorded information as well as written records.

Telephone conversations

Discuss patient information where you cannot reasonably be overheard by unauthorised people.

Avoid discussing identifiable information in reception areas, shared venues, corridors or public places.

Leaving voicemail

Check the patient’s recorded contact preferences and any restrictions.

Unless authorised otherwise, keep messages neutral. For example:

“This is WMI Psychiatry. Please contact the clinic when convenient.”

Even naming the clinic may be sensitive for some patients, so follow any recorded instructions.

Voice messages

Patient voice messages may contain health information, safeguarding disclosures or details about other people.

Use the approved WMI system and follow its handling procedures. Do not copy recordings into personal messaging applications, personal email accounts or unapproved transcription services.

Record relevant information in the appropriate patient record according to WMI procedure. Do not assume that information will remain available indefinitely within a messaging system.

If a message raises an urgent clinical or safeguarding concern, escalate promptly through the appropriate route.

11. Secure Working Practices

Electronic records

  • Use your own authorised account.

  • Do not share passwords or verification codes.

  • Lock your screen whenever you leave it.

  • Use approved devices and systems.

  • Check sharing permissions before providing access.

  • Avoid unnecessary downloads or duplicate copies.

A document stored in Google Drive is not automatically safe to share. Its permissions and recipients still need to be checked.

Paper records

Keep confidential papers secure and retrieve printouts promptly.

Use approved confidential disposal arrangements. Do not put patient information into ordinary rubbish or recycling.

Working remotely

Use the approved working arrangement. Prevent household members or visitors from viewing screens, hearing calls or accessing documents.

Do not transfer patient information to a personal account simply because it is more convenient.

Artificial intelligence and other online tools

Do not enter patient information into AI tools, online converters, transcription services or other applications unless WMI has specifically approved that use.

Removing a name does not necessarily anonymise a document. Dates, schools, family circumstances and unusual events may still identify someone.

Approval to use a tool for general administrative work does not automatically cover uploading identifiable clinical records.

12. Accurate Records, Retention and Disposal

Write records clearly, factually and respectfully.

Distinguish between:

  • What a person said.

  • What you observed.

  • What action you took.

  • What remains to be checked.

For example:

“Patient telephoned to request a repeat prescription and asked whether it could be processed today. Explained the usual processing timescale and passed the request to the prescribing team.”

This is more useful than writing:

“Patient was demanding.”

Correcting errors

Use the approved correction process and preserve the audit trail.

Do not silently rewrite clinical information or delete an entry to conceal a mistake. Refer clinical corrections to the appropriate clinician.

Retention and disposal

Different records may have different retention requirements. Follow WMI’s retention schedule and authorised disposal process.

Do not delete a clinical record simply because:

  • The patient has left the clinic.

  • The record is old.

  • The patient requests deletion.

  • You need to free storage space.

Escalate deletion requests for review.

13. Patient Rights and Requests for Records

People have rights over their personal information. These include rights to access information and request correction, and qualified rights to erasure, restriction or objection.

Not every right applies in every situation.

Recognising a subject access request

A patient does not need to use legal wording or complete a particular form to make a subject access request.

Examples include:

  • “Please send me all the information you hold about me.”

  • “I would like a copy of my records.”

  • “Can I have the emails relating to my assessment?”

Requests can be made verbally or in writing.

Record the request, date received and scope, then pass it promptly to the Data Protection Lead.

The usual response period is without undue delay and within one month. Specific rules may affect the calculation or allow an extension in appropriate cases; the responsible lead should manage these. Do not delay forwarding the request while trying to decide whether it is valid. ICO

Do not release an entire record without review

Records may contain information about other people, material requiring clinical review or information subject to an exemption.

Follow the authorised disclosure process.

Requests for correction or deletion

Acknowledge and escalate these requests. Do not promise that a clinical entry will be removed.

An accurate record of a clinical opinion at a particular time may need to remain even when the patient disagrees with it. The appropriate response may include recording the disagreement or adding clarification.

14. Recognising and Reporting Data Breaches

A personal data breach can involve unauthorised disclosure, access, loss, destruction or alteration of personal information.

Examples include:

  • Sending a report to the wrong address.

  • Attaching another patient’s letter.

  • Losing paperwork or a device.

  • Giving an unauthorised person access to a folder.

  • Accidentally deleting records.

  • Opening a patient’s record without a work-related reason.

  • Sharing login details.

A near miss should also be reported through WMI’s incident process.

What to do immediately

  1. Stop further disclosure where possible. For example, stop sending messages or revoke an incorrect sharing permission.

  2. Inform the Data Protection Lead or Registered Manager immediately. Do not wait until the end of the day.

  3. Preserve the evidence. Keep relevant emails, times, recipient details and other information needed to understand what happened.

  4. Follow instructions to contain the incident. This may include contacting the unintended recipient through an agreed process.

  5. Record the incident through WMI’s reporting system.

  6. Support the investigation and learning.

An email recall is not proof that information was not accessed. A recipient’s assurance that they deleted a document does not remove the need to report the incident.

The 72-hour rule

Certain breaches must be reported to the ICO without undue delay and, where feasible, within 72 hours of the organisation becoming aware of them. Breaches likely to create a high risk for individuals also require notification to those individuals without undue delay.

Not every breach requires ICO notification. The responsible lead must assess and document the decision. Your responsibility is to report internally immediately; 72 hours is not a waiting period for staff. ICO

15. WMI Internal Escalation

Data Protection Lead: Dr James Glass.

Registered Manager: Caroline Lawrence.

Nominated Individual: Dr James Glass.

Google Workspace administrator: Dr James Glass.

Incident reporting: Normal WMI Incident Reporting System.

Data breach recording: Normal WMI Data Breach Log.

Current policies: WMI Google Drive.

Business continuity guidance: WMI Business Continuity Policy.

For an urgent information governance incident outside normal office hours, contact the Registered Manager or Nominated Individual through the established internal escalation route.

A technical support provider may help resolve a system problem, but internal reporting is still required.

16. Practical Scenarios

Scenario 1: A partner requests a report

A patient’s partner calls and says:

“I paid for the assessment. Please email me the report.”

Appropriate response: Check the patient’s recorded authorisation. Payment does not establish permission to receive clinical information. If authority is unclear, refer the request for review.

Scenario 2: A report goes to the wrong person

You realise that autocomplete selected the wrong email address after you sent a diagnostic report.

Appropriate response: Report the incident immediately, preserve the details and follow containment instructions. Do not rely on recall or quietly ask the recipient to delete it without informing the responsible lead.

Scenario 3: A school requests information

A teacher requests a child’s diagnosis and medication details to help with classroom planning.

Appropriate response: Verify the request, check authorisation and refer it for appropriate review. Share only the agreed information needed for the purpose.

Scenario 4: A patient requests every record

A patient says:

“Please send me everything you hold about me, including emails.”

Appropriate response: Record and forward the request promptly. Do not insist that they use the phrase “subject access request” or complete a form before it is recognised.

Scenario 5: A relative raises a safety concern

A relative says the patient has been talking about suicide and asks whether the patient has attended appointments.

Appropriate response: Receive the concern and escalate urgently through the clinical safety process. Do not disclose attendance information automatically. Decisions about necessary disclosure should be made by the appropriate clinician or lead.

Scenario 6: A colleague suggests an online shortcut

A colleague suggests uploading a patient’s report to a free online tool to improve its formatting.

Appropriate response: Use an approved alternative. Patient information must not be uploaded unless WMI has approved that specific use.

17. Knowledge Check

Choose the single best answer before reading the explanation.

Question 1

Which of the following may reveal confidential health information?

A. A diagnostic report only.
B. A prescription only.
C. An appointment email identifying a person as attending an ADHD assessment.
D. Only documents marked “confidential”.

Correct answer: C.

Routine correspondence can reveal healthcare information. Reports and prescriptions are also confidential, but protection is not limited to those documents or to information carrying a confidentiality label.

Question 2

A patient’s spouse pays the assessment fee. What does this mean?

A. They can receive the full report.
B. They can receive medication details.
C. They automatically become the primary contact.
D. Payment alone does not authorise access to clinical information.

Correct answer: D.

Financial involvement does not establish disclosure authority. Report access, medication information and contact arrangements require the appropriate checks.

Question 3

You recognise a patient’s name as someone from your neighbourhood. What should you do?

A. Open the record to confirm their identity.
B. Access the record only if required for your authorised work.
C. Ask a colleague about their diagnosis.
D. Read the record but keep it confidential.

Correct answer: B.

Access must have a legitimate work-related purpose. Curiosity is not an authorised reason, even if you do not share what you read.

Question 4

A patient asks by telephone for all their records. What is the best response?

A. Tell them requests must be in writing.
B. Ask them to use legal wording.
C. Record the request and forward it promptly.
D. Immediately email the complete record.

Correct answer: C.

Verbal requests can qualify. The request needs prompt handling, but disclosure must follow the approved verification and review process.

Question 5

You send a clinical letter to the wrong recipient. What should you do first?

A. Wait to see whether they open it.
B. Report it immediately and start appropriate containment.
C. Delete the email from your sent folder.
D. Wait until the next team meeting.

Correct answer: B.

Prompt reporting allows containment and assessment. Deleting evidence or waiting may make the situation worse.

Question 6

What does the 72-hour breach notification rule mean for admin staff?

A. Staff have 72 hours to report internally.
B. Every error must be reported personally to the ICO.
C. Staff should report internally immediately so the responsible lead can assess notification requirements.
D. Only cybersecurity incidents need reporting.

Correct answer: C.

The deadline concerns certain external notifications. Internal reporting must be immediate, and breaches can involve paper, spoken information or administrative errors as well as technology.

Question 7

A separated parent asks you to remove the other parent’s contact details. What should you do?

A. Make the change immediately.
B. Follow the verification and consent process and escalate any uncertainty.
C. Refuse every request involving separated parents.
D. Give priority to the parent who pays.

Correct answer: B.

These requests require individual review. Neither automatic acceptance nor blanket refusal is appropriate, and payment does not determine authority.

Question 8

Which approach best demonstrates data minimisation?

A. Sending a full report with every attendance confirmation.
B. Sharing the information necessary for an authorised purpose.
C. Deleting all patient records after each appointment.
D. Collecting extra details in case they are useful later.

Correct answer: B.

Data minimisation means limiting information to what is needed. It does not justify deleting necessary records or collecting speculative information.

Question 9

A patient requests deletion of their entire clinical record. What should you do?

A. Delete it immediately.
B. Promise deletion within one month.
C. Ignore the request.
D. Record and escalate it for review.

Correct answer: D.

The request must be considered, but erasure rights are qualified and clinical retention obligations may apply. Admin staff should neither delete the record nor dismiss the request.

Question 10

Which use of an online AI or document tool is appropriate?

A. Uploading a report after removing only the name.
B. Uploading it because the tool is free.
C. Using it only where WMI has approved that specific handling of patient information.
D. Uploading it through a personal account.

Correct answer: C.

Approval must cover the relevant information and purpose. Removing a name may leave identifying details, and convenience or personal account access does not establish approval.

18. Summary

Information governance is part of safe patient care and applies to every format: records, emails, paper documents, telephone conversations and recordings.

Before accessing or sharing information, establish the purpose, check authority and use only what is necessary. Keep records accurate, use approved systems and follow retention procedures.

Recognise requests for personal information and forward them promptly. If a mistake or suspected breach occurs, report it immediately so that the clinic can contain the incident and protect the people affected.

When uncertain, pause the disclosure and seek advice. When there is an urgent safety concern, escalate promptly.

19. Further Reading

Previous
Previous

Information Governance and Data Protection

Next
Next

Infection Prevention and Control Awareness