Data Breach: Access to Medical Records

A data breach reported has been reported after a doctor inappropriately accessed the medical records of a person who was not their patient. There was only and indirect personal link between them.

The doctor looked at both the patient’s hospital and GP records. They then used the information to share personal information about the patient and her family.

As a hospital consultant the doctor had access to the patient’s GP records through the interlink between primary and secondary healthcare IT systems. This is designed to facilitate information sharing and speed up patient care.

The Hospital Trust where the doctor worked was able to give the patient a detailed breakdown of who had accessed her medical records. This is what which any good record system should be able to do. That allowed the doctor to be identified. Although disciplinary action has been taken there is as yet no action by the Information Commissioner or the Police

You can read more about the incident here.

The incident, which as resulted in disciplinary action against the doctor, highlights the important of training. It is important that people understand what they are and are not allowed to do with personal data. They also need to know to speak up if they see something wrong. In our view enabling access to information, and linking systems to allow information sharing, is the right thing to do. However, this incident does highlight that the most complex part of any system is the people working in it. It also also show how difficult it is to protect systems and other people from malicious actions.

You can learn how to develop appropriate technical and organisational measures to prevent a data breach with GDPR and information governance training from WuDo Solutions – find out more about training opportunities for you here.