Information Governance and Data Protection
Estimated completion time: 40–50 minutes, including the knowledge check and practical reflection.
This module covers the safe handling of patient, family and staff information. Read it alongside the current WMI Information Governance, Data Protection, Confidentiality, Incident Reporting and Records Management policies, available in WMI Google Drive.
1. Introduction
Patients share information with WMI Psychiatry that they may find difficult to discuss with anyone else. This can include mental health difficulties, family relationships, school concerns, medication, trauma and safeguarding information.
Protecting this information is part of providing safe and respectful care. A confidentiality mistake can cause distress, damage trust or place someone at risk.
The admin team has an essential role in protecting information. Booking appointments, answering calls, sending reports and processing prescriptions all involve personal data. Even confirming that someone attends a psychiatric clinic can reveal something sensitive about them.
Information governance is the framework that helps us collect, use, store, share and dispose of information appropriately. Data protection concerns the lawful and fair handling of personal information. Confidentiality concerns our responsibility to protect information entrusted to us.
These responsibilities apply wherever you work, including clinic premises, shared office spaces and your home.
2. Learning Outcomes
By the end of this module, you should be able to:
Recognise personal data and sensitive health information.
Apply the main data protection principles to everyday admin work.
Check identity and authority before sharing information.
Handle emails, telephone calls, documents and electronic records safely.
Recognise information requests, complaints and potential data breaches.
Escalate concerns promptly through the WMI reporting process.
3. Understanding the Information We Handle
What is personal data?
Personal data is information relating to an identified or identifiable living person.
In the clinic, this includes names, addresses, dates of birth, telephone numbers, email addresses, appointment details, payment records and correspondence.
A person does not have to be named for information to identify them. A combination of their age, school, family circumstances and appointment date may be enough.
What is special category data?
Some personal data receives additional legal protection. Health information is special category data, including information about physical health, mental health, diagnoses and treatment. Other examples include ethnicity, religious beliefs and sexual orientation. ICO
An appointment list for a psychiatric clinic should therefore be treated as sensitive, even if it contains no clinical notes.
What about family members and staff?
Our responsibilities also extend to information about parents, carers, relatives, employees and applicants.
A patient’s record may contain personal information about other people. This matters when responding to requests for copies of records: the whole record cannot simply be forwarded without appropriate review.
Removing a name is not always enough
Replacing a patient’s name with initials or a reference number does not necessarily make the information anonymous.
If the person can still be identified, directly or indirectly, the information remains personal data. Do not assume that a case is safe to share because you have removed the name.
4. The Main Data Protection Principles
The UK GDPR and Data Protection Act 2018, as amended, provide the main legal framework for handling personal data.
The seven data protection principles can be translated into practical questions for everyday work:
1. Lawfulness, fairness and transparency
Are we handling the information for an authorised purpose, and is the person appropriately informed about its use?
Use the clinic’s approved processes and privacy information. Do not introduce a new use for patient information without approval.
2. Purpose limitation
Are we using the information for the purpose for which it was collected, or another properly authorised purpose?
An email address provided for appointment correspondence should not automatically be added to a promotional mailing list.
3. Data minimisation
Are we using only the information needed for the task?
An appointment reminder will rarely need to include a diagnosis, medication list or detailed clinical history.
4. Accuracy
Have we checked that the information is correct?
Incorrect contact details can cause both confidentiality breaches and delays in care. Check changes carefully and record them through the approved process.
5. Storage limitation
Are we keeping the information for the appropriate period?
Follow the clinic’s retention schedule. Do not keep personal copies indefinitely or delete clinical records because they appear old.
6. Integrity and confidentiality
Is the information protected against unauthorised access, loss, damage or disclosure?
Use approved systems, secure access controls and appropriate physical security.
7. Accountability
Can we demonstrate what we did and why?
Record relevant checks, authorisations, disclosures and concerns clearly enough for another member of the team to understand the decision.
Consent is not the only lawful basis
A common misunderstanding is that every use of patient information requires GDPR consent.
Healthcare organisations may use other lawful bases and conditions for providing care. Processing health information requires both an appropriate lawful basis and an additional special category condition. The clinic determines these arrangements; admin staff should follow the approved process rather than choose a legal basis themselves. ICO
Consent to treatment, permission to communicate with a relative and consent as a data protection lawful basis are related but different matters. If you are uncertain about what permission is required, seek advice.
5. Confidentiality and Appropriate Information Sharing
Access information only when your role requires it
Being able to open a record does not mean you are authorised to read it.
Access must relate to your work. It is inappropriate to look at the records of a friend, neighbour, colleague or public figure out of curiosity.
The same applies to browsing records simply because a case sounds interesting.
Apply the Caldicott Principles
The Caldicott Principles guide the use of confidential information in health and care. Their practical message is to justify information use, use the minimum necessary, restrict access to those who need it, understand your responsibilities and keep patients informed.
They also recognise that appropriate information sharing can be essential to safe care. Confidentiality must not become a reason to withhold information that needs to be shared lawfully for someone’s protection or treatment. GOV.UK
For admin staff, this means following approved sharing processes and escalating decisions that require clinical or safeguarding judgement.
Receiving information is different from disclosing information
You can listen to a relative’s concern without confirming that someone is a patient or sharing details about their care.
For example, a parent may telephone with concerns about an adult child. You can take the message and pass it to the appropriate clinician, while maintaining confidentiality.
You might say:
“Thank you for letting us know. I can take the information and pass it to the appropriate member of the team, but I cannot discuss another person’s care without the necessary authorisation.”
Do not promise absolute secrecy
If someone provides information about abuse, serious risk or a safeguarding concern, do not promise that it will remain secret.
Explain that it may need to be passed to an appropriate clinician or safeguarding lead to help protect the person involved.
Escalate urgent concerns immediately. If there is an immediate danger to life, follow the emergency procedure and call 999 where required.
6. Checking Identity and Authority
Before disclosing information, check two separate things:
Is this person who they say they are?
Are they entitled or authorised to receive this information?
Knowing a patient’s name and date of birth does not, by itself, establish authority to receive their records.
Telephone enquiries
Follow the clinic’s identity verification process. Avoid giving clues from the record to help a caller pass the checks.
Where necessary, call back using a verified number already held on the record. Do not rely solely on a new number supplied during the call.
If verification is unsuccessful, explain that you need to complete the checks before discussing confidential information.
Parents, carers and relatives
A relative’s involvement in booking appointments or paying fees does not automatically authorise access to clinical information.
For adult patients, check the recorded permission and its scope. Permission to discuss appointments may not include permission to disclose reports or medication information.
For children and young people, access can involve parental responsibility, the young person’s understanding and confidentiality rights, court restrictions and safeguarding considerations. Do not assume that every parent is entitled to the complete record.
Refer uncertain or disputed requests to the clinician or Data Protection Lead.
Separated parents
Do not change the main contact, remove an existing contact or send confidential reports solely because one parent requests it.
Check the recorded arrangements and any relevant restrictions. Escalate disagreements so the team can establish the appropriate authorisation and consent.
Requests from professionals
A caller saying they are from a GP practice, school, pharmacy or another healthcare service still needs appropriate verification.
Use independently verified contact details and follow the approved disclosure process. A professional job title does not automatically justify receiving the whole record.
7. Safe Email and Document Handling
Check before you send
Before sending patient information, check:
The correct patient record is open.
The recipient’s full address is correct.
The recipient is authorised to receive the information.
Every attachment belongs to the correct patient.
The information included is necessary.
The sending method meets the clinic’s security requirements.
Autocomplete can select the wrong address. Read the full address rather than relying on the displayed name.
Open attachments to check them. A filename alone is not sufficient verification.
Keep subject lines discreet
Email subject lines may appear on lock screens, shared devices and notifications.
Use the minimum information necessary. Avoid including diagnoses, sensitive symptoms or unnecessary identifiers.
Use approved systems
Use clinic-approved accounts and communication methods. Do not forward patient information to personal email accounts or transfer it through personal messaging services.
If a patient requests a different communication method, follow the clinic process and seek advice where needed. Their preference does not remove the clinic’s responsibility to use an appropriate method.
Group emails
Never expose patient email addresses to other patients through the “To” or “Cc” fields.
BCC hides addresses, but it does not make every group email appropriate. Use the approved mailing process and avoid placing individual patient information in group messages.
Shared document links
Check who can access a document before sending a link.
For confidential material, use the clinic’s approved restricted-access settings. Do not assume that a link is secure because it is difficult to guess.
Printing and post
Collect printing promptly, check all pages and place documents in secure storage.
Before posting, check the recipient, address and contents of the envelope. Follow the clinic’s process for sensitive correspondence and any required tracking.
Dispose of confidential paper through approved confidential waste arrangements.
Practical example
You are sending an assessment report to a parent. There are two patients with similar names, and the email software suggests an address automatically.
Pause and check the patient identifiers, recorded contact details and attachment contents. A brief check can prevent a serious disclosure.
8. Safe Telephone Calls, Messages and Conversations
Choose a private setting
Do not discuss patient details where visitors, other patients or members of your household can overhear.
In shared premises, be particularly careful in corridors, reception areas and communal offices.
Voicemail
Check the recorded communication preferences before leaving a message.
Use the minimum necessary information. Avoid mentioning diagnoses, medication or the reason for an appointment. Even naming a psychiatric clinic may reveal sensitive information, so follow the approved wording and any patient-specific restrictions.
Voice messages
Voice recordings are confidential information.
Access clinic voice messages through the approved system and listen privately, using headphones where appropriate. Do not play them aloud in shared spaces or copy them onto personal devices.
Record and escalate relevant information through the normal clinic process.
Social conversations
Do not discuss identifiable patients with friends or family, including after work.
Avoid saying things such as:
“You would never guess who has booked an assessment.”
Confidentiality continues outside working hours and after employment ends.
9. Electronic Records, Remote Working and AI Tools
Use your own account
Use your individual login and keep credentials private.
Do not share passwords or use another person’s account. Individual accounts help the clinic establish who accessed or changed information.
Secure your workspace
Lock your screen whenever you leave it unattended.
When working remotely, keep screens and documents away from household members and visitors. Use approved devices, connections and storage arrangements.
Do not photograph records with a personal phone or save patient information to a personal cloud account or unapproved USB drive.
Keep records accurate and professional
Admin entries should be factual, relevant and respectful.
Record what happened, what action you took and who you informed. Avoid speculation or judgemental language.
If you identify an error, follow the approved correction process and preserve the appropriate audit trail. Do not silently remove information to hide a mistake.
AI, transcription and online tools
Do not enter patient information into an AI assistant, online translator, transcription service or other external tool unless that specific tool and use have been approved by the clinic.
Removing a name may leave enough detail to identify the patient.
Before adopting a new tool, the clinic needs to assess privacy, security, access and contractual arrangements. Admin staff should not create an informal workaround.
10. Information Requests and Data Protection Complaints
Recognising a subject access request
A person may ask:
“Please send me all the information you hold about me.”
This may be a subject access request, even if they do not use that term. Requests can be verbal or written, and a particular form is not required.
Record the request and its date, then pass it promptly to the Data Protection Lead. Do not wait for the person to write to a different department before escalating it.
The usual response deadline is one month, with specific rules about identity checks, clarification and extensions. The responsible lead should assess these rather than admin staff promising a revised deadline independently. ICO
Do not release the whole record without review
Records may include third-party information or material requiring clinical review.
Follow the approved process for identity checks, authority, review and secure delivery. Do not delete or alter information to prevent it being disclosed.
Requests to correct or delete information
Patients may ask for an error to be corrected or for information to be deleted.
Record and escalate the request. A request for deletion does not automatically mean a clinical record can be erased: legal and clinical retention requirements may still apply.
Do not promise an outcome before the request has been assessed.
Complaints about information handling
Examples include:
“You sent my report to the wrong person.”
“My contact details are still wrong.”
“I am unhappy about who can access my records.”
Treat these as potential data protection complaints, even if they arrive informally. Record the concern and escalate it promptly. A complaint may also reveal a breach requiring immediate action.
Current requirements include providing a clear complaints route, acknowledging data protection complaints within 30 days, investigating appropriately and communicating the outcome. Admin staff should escalate immediately so the clinic can meet these requirements. ICO
11. Recognising and Responding to Data Breaches
What is a personal data breach?
A breach can involve loss, unauthorised access or disclosure, incorrect alteration, or loss of availability of personal information.
Examples include:
Sending a report to the wrong recipient.
Attaching another patient’s prescription or letter.
Losing a device or paper file.
Allowing unauthorised access to a shared folder.
Opening a record without a work-related reason.
Accidentally deleting information that cannot be recovered.
A breach does not have to involve a cyberattack.
What should you do?
Report suspected breaches immediately. Do not wait until you have investigated everything yourself.
Stop further exposure where safely possible. Pause further sending, secure papers or restrict an exposed link if you are authorised to do so.
Contact the Data Protection Lead or Registered Manager immediately. If one is unavailable, escalate to the other or the Nominated Individual.
Preserve the facts and evidence. Record what happened, when it happened, when you discovered it, what information was involved and any action taken.
Follow the incident reporting process. Ensure the concern reaches the normal WMI Incident Reporting System and, where applicable, the WMI Data Breach Log.
Follow instructions for containment and follow-up. Do not make independent promises about notification, liability or compensation.
An attempted email recall does not prove that the recipient has not read or saved the information.
Understanding the 72-hour rule
Where notification is required, the clinic must notify the Information Commissioner’s Office without undue delay and within 72 hours of becoming aware of the breach. This period includes weekends.
Not every breach requires ICO notification, but every breach must be documented. A breach likely to create a high risk to individuals also requires prompt notification to those affected.
The responsible lead assesses these requirements. For admin staff, the instruction is simple: escalate immediately, rather than treating 72 hours as time available to wait. ICO
Near misses
A near miss is an incident that could have caused a breach but was caught before disclosure or other harm occurred.
For example, you notice the wrong attachment before sending the email.
Report near misses through the clinic process so the team can improve systems and prevent recurrence.
12. Internal Escalation at WMI Psychiatry
Registered Manager: Caroline Lawrence
Nominated Individual: Dr James Glass
Data Protection Lead: Dr James Glass
Google Workspace administrator: Dr James Glass
Out-of-hours escalation: Registered Manager or Nominated Individual
Incident reporting system: Normal WMI Incident Reporting System
Data breach log: Normal WMI Data Breach Log
Location of current policies: WMI Google Drive
Business continuity information: WMI Business Continuity Policy
Use the current internal contact arrangements. For an urgent concern, make direct contact and seek acknowledgement rather than relying only on an unattended inbox.
13. Practical Scenarios
Scenario 1: A relative requests medication details
A woman calls asking what medication her adult brother takes. She knows his date of birth and says she pays his fees.
Appropriate response: Verify identity and check recorded authority. Payment and knowledge of personal details do not establish permission to receive clinical information. You can take a message without disclosing his treatment.
Scenario 2: A report goes to the wrong address
You discover that an assessment report was sent to an unrelated person because of an incorrect email address.
Appropriate response: Escalate immediately, preserve the details and follow instructions to contain the disclosure. Do not assume that recalling the email resolves the incident.
Scenario 3: A parent requests a child’s complete record
A parent says they have parental responsibility and wants the entire record immediately.
Appropriate response: Record and escalate the request. Appropriate checks and clinical review are needed, including consideration of the young person’s confidentiality, third-party information and any restrictions.
Scenario 4: A patient asks for records during a call
A patient says, “Can you send me everything you have about me?”
Appropriate response: Recognise a potential subject access request. Record the date and wording and refer it promptly to the Data Protection Lead.
Scenario 5: An urgent safeguarding concern
A caller gives information suggesting that a child may be at immediate risk.
Appropriate response: Take the necessary details and escalate immediately through the safeguarding and emergency procedures. Do not promise secrecy or delay because the information is confidential.
Scenario 6: A convenient online tool
You find a free website that summarises long documents and consider uploading a developmental history form.
Appropriate response: Do not upload it unless the specific tool and use are approved. Initials or removal of the name may not prevent identification.
14. Summary
Protecting information is part of safe patient care.
Access records only for an authorised work purpose. Verify identity and authority before sharing information, and use the minimum information necessary through approved systems.
Check recipients and attachments carefully. Keep records factual and secure, whether working in the clinic or remotely.
Recognise information requests and complaints, and pass them promptly to the responsible lead.
Report suspected breaches and near misses without delay. Early reporting gives the clinic the best opportunity to protect people and put things right.
15. Knowledge Check
Choose one answer for each question before reading the answer section.
Question 1
Which information should be treated as sensitive in a psychiatric clinic?
A. Only reports containing a confirmed diagnosis.
B. Appointment information linked to an identifiable patient.
C. Only information written by a clinician.
D. Only information marked “confidential”.
Question 2
A relative knows an adult patient’s date of birth and pays their fees. What should you do before discussing treatment?
A. Disclose the information because they pay.
B. Disclose only the medication name.
C. Verify identity and check authority to receive the information.
D. Ask them to promise not to tell anyone else.
Question 3
What does data minimisation mean?
A. Keeping as few patient records as possible.
B. Using only the personal information necessary for the purpose.
C. Deleting all correspondence after replying.
D. Never sharing information with another service.
Question 4
A colleague asks to use your login because their account is unavailable. What is the best response?
A. Share it if they are a clinic employee.
B. Share it for urgent work only.
C. Decline and help them obtain authorised access or support.
D. Share it and change the password later.
Question 5
You send a report to the wrong recipient. What should you do?
A. Wait to see whether they reply.
B. Recall the email and take no further action.
C. Report immediately and follow the breach response process.
D. Delete the sent email.
Question 6
What does the 72-hour breach rule mean?
A. Staff can wait 72 hours before reporting internally.
B. The clinic must notify every incident within 72 working hours.
C. Notifiable breaches must be reported to the ICO without undue delay and within 72 hours of awareness.
D. Only cyberattacks are subject to the rule.
Question 7
A patient verbally asks for all information held about them. What should you do?
A. Ask them to complete a form before recording the request.
B. Record and escalate it as a potential subject access request.
C. Immediately email the whole record.
D. Explain that requests must come from a solicitor.
Question 8
Which statement about children’s records is correct?
A. Every parent automatically has access to the whole record.
B. The person paying for care controls access.
C. Requests require appropriate checks and consideration of the child’s confidentiality and circumstances.
D. Children’s records can never be shared with parents.
Question 9
Can you upload a patient document to a free AI tool after removing the name?
A. Yes, because it is anonymous.
B. Yes, if it saves time.
C. Only if the specific tool and use are approved and the required safeguards are followed.
D. Yes, if the document is deleted afterwards.
Question 10
A caller provides information suggesting immediate risk to a child. What is the best response?
A. Promise not to share it.
B. Wait for the next routine team meeting.
C. Escalate immediately through safeguarding and emergency procedures.
D. Refuse to listen because it is confidential.
16. Answers and Explanations
Question 1: B
Appointment information can reveal that someone is receiving psychiatric care. A diagnosis, clinician author or confidentiality label is not required for information to need protection.
Question 2: C
Identity and authority are separate checks. Paying fees does not create access rights, and a medication name is itself clinical information. A promise of secrecy does not authorise disclosure.
Question 3: B
Use enough information to complete the authorised task, without unnecessary detail. Minimisation does not mean deleting required records or preventing appropriate sharing.
Question 4: C
Individual accounts support security and accountability. Employment status, urgency or a later password change does not make account sharing appropriate.
Question 5: C
Prompt reporting allows the clinic to contain and assess the incident. Waiting delays action, recall may fail, and deleting the sent email can remove useful evidence.
Question 6: C
The external notification deadline applies to notifiable breaches and includes weekends. Internal reporting must happen immediately, and breaches include more than cyberattacks.
Question 7: B
A verbal request can be valid. A form or solicitor is not required. The record needs appropriate verification and review before disclosure.
Question 8: C
Parental responsibility is relevant but does not settle every disclosure question. Payment does not determine access, and parents may appropriately receive information following the necessary assessment.
Question 9: C
The clinic must approve the tool and its use. Removing a name does not necessarily prevent identification, and later deletion does not undo an unauthorised disclosure.
Question 10: C
Confidential information may need to be shared appropriately to protect someone. Promising secrecy, delaying escalation or refusing to receive the concern could obstruct necessary action.
17. Practical Reflection and Completion Record
Before recording completion, confirm that you can answer these questions:
Where are the current WMI information governance policies?
How would you contact the Data Protection Lead urgently?
What checks would you make before sending a report?
How would you recognise and escalate a records request?
What would you do if you discovered a disclosure after office hours?
Record your name, completion date, knowledge check score and any further learning needs through the clinic’s training process.
Review incorrect answers before completing the module. Discuss any uncertainty with the Registered Manager or Data Protection Lead.
18. Further Reading
Current WMI policies and privacy notice.