Health Records Access Check: UK Compliance Guide
Ensure GDPR & DPA compliance with a health records access review—avoid fines and protect patient data.
Every week, UK GP surgeries, private clinics, and care homes handle thousands of requests from patients who want to see their own medical notes. Many of these organisations rely on template policies or outdated forms to manage access. When those documents don’t match the Data Protection Act 2018 (DPA2018), the result is often a rejected Subject Access Request (SAR), a complaint to the Information Commissioner’s Office (ICO), or even a regulatory fine. For small practices and solo practitioners, the cost isn’t just financial—it’s the hours spent untangling paperwork and the risk of losing patient trust.
This guide explains how to check whether your health records access check document is legally sound. You’ll learn the five key checks that matter most, the common mistakes that trip people up, and how an automated review can give you confidence in minutes.
Why data-protection paperwork matters under UK GDPR
Health records are among the most sensitive personal data UK organisations hold. A single GP practice can receive dozens of Subject Access Requests each month—from patients checking test results, solicitors gathering evidence for personal-injury claims, or family members acting on behalf of a vulnerable adult. If your access policy or internal checklist doesn’t reflect the current rules, you risk:
- Rejected requests: The ICO reports that incomplete or incorrect SAR responses are a top reason for complaints. When a patient’s request is turned down because your document doesn’t cover third-party data or confidentiality exemptions, you may have to start again—wasting staff time and risking a formal investigation.
- Breach of confidentiality: Many practices still use blanket consent forms that don’t distinguish between the patient’s own data and information about family members or carers. If you release third-party details without proper safeguards, you could face a complaint under Article 5(1)(f) DPA2018 (integrity and confidentiality).
- Regulatory scrutiny: The ICO has issued fines for repeated failures to respond to SARs within the 30-day deadline. While most penalties target larger organisations, small clinics and care homes are not exempt. A single complaint can trigger an audit that disrupts your operations for weeks.
- Reputational damage: Patients who feel their rights are ignored often share their experiences online or with local media. In an era where trust is a competitive advantage, even a minor misstep can lead to lost referrals and lower patient retention.
This isn’t just about compliance—it’s about operational resilience. A well-drafted health records access check document acts as a safeguard, ensuring your team knows exactly what to look for, what to redact, and when to seek legal advice.
Is your document complete and internally consistent?
A “good” document does three things:
- Maps to the law: It reflects the exact requirements of the DPA2018, including the right of access (Article 15 UK GDPR), exemptions for confidentiality, and rules on third-party data.
- Guides action: It gives your team clear, step-by-step instructions—what to verify, what to redact, and when to escalate to a manager or solicitor.
- Protects you: It creates an audit trail, showing regulators that you took reasonable steps to comply.
If your current document is a generic template or hasn’t been updated since 2018, it’s time for a review.
UK GDPR and the Data Protection Act 2018 — plain English
The Data Protection Act 2018 (DPA2018) is the UK’s main data protection law. It sits alongside the UK General Data Protection Regulation (UK GDPR), which is the retained version of the EU GDPR after Brexit. Together, they set the rules for how organisations collect, store, and share personal data—including health records.
Key principles for health records access
- Right of access (Article 15 UK GDPR): Patients have the right to ask for a copy of their personal data. This includes medical notes, test results, referral letters, and even internal emails about their care. You must respond within one month (extendable by two months for complex requests).
- Confidentiality exemptions (Schedule 2, Part 3, DPA2018): You can refuse a request if disclosing the data would reveal information about another person (a “third party”), unless that person has given consent or it’s reasonable to disclose without it. This is common in family medicine, where records often include details about spouses, children, or carers.
- Manifestly unfounded or excessive requests (Article 12 UK GDPR): If a request is clearly unreasonable—such as repeated requests for the same data in a short period—you can charge a fee or refuse to act. However, you must be able to justify your decision.
- Data minimisation (Article 5 UK GDPR): You should only provide the data that’s relevant to the request. For example, if a patient asks for their blood test results, you don’t need to include their entire medical history unless they specifically ask for it.
What counts as a “health record”?
Under the DPA2018, a health record is any record relating to the physical or mental health of an individual, made by or on behalf of a health professional. This includes:
- GP notes
- Hospital discharge summaries
- Physiotherapy reports
- Mental health assessments
- Even handwritten notes in a patient’s file
It doesn’t matter whether the record is digital or paper-based—both are covered.
Who can request access?
- The patient themselves
- A person with parental responsibility (for children under 13)
- A person appointed by a court (e.g., a deputy or guardian)
- A solicitor acting on the patient’s behalf (with written authority)
If the request comes from someone other than the patient, you must verify their authority before releasing any data.
Five privacy-document checks organisations miss
1. Does your document cover third-party data?
Why it matters: Health records often include information about people other than the patient—such as family members, carers, or other healthcare professionals. Under Schedule 2, Part 3, DPA2018, you must not disclose third-party data unless:
- The third party has given explicit consent, or
- It’s reasonable to disclose without consent (e.g., the information is about a healthcare professional acting in their professional capacity).
Practical tip: Your document should include a checklist for identifying third-party data. For example:
- Names of family members mentioned in consultation notes
- Details of carers or support workers
- Information about other patients (e.g., in a shared ward)
- Opinions of healthcare professionals that could identify them
VetroCheck tip: Use our Health Records Access Check to flag sections of your document that don’t address third-party data. We’ll highlight gaps and suggest wording to bring you into compliance.
2. Are confidentiality exemptions clearly explained?
Why it matters: The DPA2018 allows you to refuse a SAR if disclosing the data would breach confidentiality. However, you must apply this exemption carefully. For example:
- You can’t refuse a request just because the data is “sensitive”—you must show that disclosure would cause harm or reveal information about someone else.
- You must balance the patient’s right of access against the third party’s right to privacy.
Practical tip: Your document should include a decision tree for confidentiality exemptions. For example:
- Does the data include information about a third party?
- Has the third party given consent?
- If not, is it reasonable to disclose without consent? (Consider the nature of the data, the relationship between the parties, and any duty of confidentiality.)
- If you refuse, have you documented your reasons?
VetroCheck tip: Our tool cross-references your document against the DPA2018’s confidentiality rules. We’ll flag any language that’s too vague or overly restrictive.
3. Does it set out the 30-day deadline?
Why it matters: Under Article 12 UK GDPR, you must respond to a SAR “without undue delay” and at the latest within one month of receiving it. This clock starts ticking the day after you receive the request (or the day after you receive any requested fees or identification).
Practical tip: Your document should include:
- A clear statement of the deadline (e.g., “You must respond within 30 calendar days”).
- Steps for calculating the deadline (e.g., “If the request is received on 15 March, the deadline is 14 April”).
- Guidance on when and how to extend the deadline (e.g., for complex requests, you can extend by two months, but you must inform the patient within the first month).
VetroCheck tip: We’ll check whether your document includes the correct timescales and whether it explains how to handle extensions. Missing this detail is a common reason for ICO complaints.
4. Does it explain how to verify the requester’s identity?
Why it matters: Releasing health records to the wrong person is a serious breach of confidentiality. Under Article 12 UK GDPR, you can ask for proof of identity before processing a SAR. However, you must not impose excessive requirements (e.g., asking for a passport if a driving licence would suffice).
Practical tip: Your document should include:
- A list of acceptable forms of ID (e.g., passport, driving licence, utility bill).
- Guidance on what to do if the requester can’t provide ID (e.g., ask for alternative evidence, such as a letter from their GP).
- Steps for verifying requests from solicitors or other representatives (e.g., check for written authority from the patient).
VetroCheck tip: Our review will highlight any gaps in your identity-verification process. We’ll suggest wording to ensure you’re not asking for more information than necessary.
5. Does it address manifestly unfounded or excessive requests?
Why it matters: Some patients (or their representatives) make repeated or unreasonable requests. Under Article 12 UK GDPR, you can refuse to act on a request if it’s “manifestly unfounded or excessive.” However, you must be able to justify your decision and offer an alternative (e.g., charging a fee).
Practical tip: Your document should include:
- Examples of unfounded or excessive requests (e.g., repeated requests for the same data within a short period, requests that are clearly intended to harass).
- Steps for assessing whether a request is unfounded or excessive (e.g., consider the context, the frequency of requests, and the burden on your organisation).
- Guidance on how to respond (e.g., refuse the request, charge a fee, or offer a more limited response).
VetroCheck tip: We’ll check whether your document includes clear criteria for assessing unfounded or excessive requests. Vague language here can lead to disputes with patients or the ICO.
Data-protection mistakes that create complaint risk
1. Ignoring third-party data
What goes wrong: Many practices assume that if a patient requests their records, they’re entitled to everything in their file. This often leads to the accidental disclosure of third-party data—such as details about a family member’s health or a carer’s personal circumstances.
Consequence: The third party may complain to the ICO, leading to an investigation and potential enforcement action. Even if no fine is issued, you’ll spend hours responding to the complaint and may have to pay compensation to the affected individual.
Example: A GP practice released a patient’s full medical history to their solicitor, including notes about the patient’s spouse’s mental health. The spouse complained to the ICO, which found the practice in breach of confidentiality rules. The practice had to review its SAR process and provide staff training.
2. Missing the 30-day deadline
What goes wrong: Practices often underestimate how long it takes to gather and redact records. If you don’t start the clock on day one, you risk missing the deadline—especially if the request arrives just before a bank holiday or busy period.
Consequence: The patient may complain to the ICO, which will ask for evidence of your process. If you can’t show that you acted promptly, the ICO may issue a reprimand or order you to comply. This can damage your reputation and lead to further scrutiny.
Example: A private clinic received a SAR on 20 December but didn’t start processing it until after the Christmas break. The deadline passed, and the patient complained. The ICO found the clinic in breach of Article 12 UK GDPR and ordered it to respond within 14 days.
3. Over-reliance on blanket consent forms
What goes wrong: Some practices use a single consent form for all SARs, regardless of whether the request involves third-party data. This can lead to the release of confidential information without proper safeguards.
Consequence: If a third party complains, the ICO may find that you failed to apply the confidentiality exemption correctly. You may have to recall the records, issue an apology, and review your process—all of which take time and resources.
Example: A care home released a resident’s records to their family, including details about another resident mentioned in the notes. The second resident complained, and the ICO found the care home in breach of confidentiality rules. The home had to implement a new SAR process and provide staff training.
FAQ
What does the Health Records Access Check: compliance and gap review review?
The Health Records Access Check is an information-only audit of your data health records access check document. It focuses on four key areas:
- Health records: Does your document cover all types of health data (e.g., GP notes, test results, referral letters)?
- Subject access: Does it explain how to handle Subject Access Requests, including deadlines and exemptions?
- Confidentiality: Does it address the rules on third-party data and confidentiality exemptions?
- Third-party data: Does it include clear guidance on when and how to disclose information about other people?
Each finding is backed by a citation from your document, so you can see exactly where improvements are needed.
Which legal sources are used in the review?
The analysis is based on the Data Protection Act 2018 (DPA2018) and the UK General Data Protection Regulation (UK GDPR). These are the primary laws governing data protection in the UK, including the right of access to health records.
Which specific points are checked?
The agent checks the following points in your data health records access check document:
- Third-party data: Does your document explain how to identify and handle information about other people?
- Confidentiality exemptions: Does it set out the rules for refusing a request on confidentiality grounds?
- Deadlines: Does it include the correct timescales for responding to SARs (e.g., 30 days)?
- Identity verification: Does it explain how to verify the requester’s identity?
- Unfounded or excessive requests: Does it address how to handle unreasonable requests?
Each finding is linked to a specific part of your document, so you can see exactly what needs to change.
Which documents can I upload?
The Health Records Access Check accepts PDF files up to 20 MB. It’s designed for data health records access check documents, such as:
- Internal policies for handling SARs
- Checklists for reviewing health records
- Template letters for responding to requests
- Guidance notes for staff
If your document is in another format (e.g., Word), you can convert it to PDF before uploading.
How much does the review cost and how long does it take?
The full analysis costs £12.99. Results are usually ready within a few minutes as a PDF download. You’ll receive a detailed report highlighting any gaps in your document and suggesting improvements to bring it into compliance with the DPA2018.
Check your privacy paperwork — £12.99
Checklist: Before you upload your document
- Gather your document: Locate your current health records access check document (e.g., policy, checklist, or guidance notes).
- Check the format: Ensure it’s a PDF file under 20 MB. If not, convert it or split it into smaller files.
- Review the basics: Make sure it covers the five key areas (third-party data, confidentiality, deadlines, identity verification, and unfounded requests).
- Note any concerns: Jot down any sections you’re unsure about—our report will help you address them.
How VetroCheck helps
VetroCheck’s Health Records Access Check gives you a fast, affordable way to review your document against the DPA2018. Here’s what you get:
- Instant feedback: A detailed report highlighting gaps and suggesting improvements.
- Clear citations: Each finding is linked to a specific part of your document, so you know exactly what to fix.
- Peace of mind: Confidence that your document reflects the latest legal requirements.
**Ready to check? Upload your document for a structured PDF review — £12.99. ---
Important note: VetroCheck is not a law firm and is not regulated by the Solicitors Regulation Authority. Our tools provide information-only audits and do not constitute legal advice. For specific legal questions, consult a qualified solicitor.
Check your document now — £12.99
Also see the agent topic page for statute themes and related checks.
Check your document now — £12.99
Upload your PDF for a structured review. One-time analysis from £12.99 — not legal advice.