2. Records, images and UK data protection
What a good record is for
Records support continuity of care, consent, complaints and, if needed, a GDC or court process. If it is not written down, it is hard to show it happened.
Contemporaneous and attributable
- Write at the time of the appointment, or as soon as possible afterwards, and say if the note is retrospective
- Every entry should show who wrote it
- Do not alter a note to make it “look better” after a complaint. If you need to correct an error, add a dated amendment — do not silently overwrite history
What to include (clinical)
History, examination, investigations, diagnosis or working diagnosis, options and consent discussion, treatment provided, materials and batch information where relevant, advice given, and the next plan. Negative findings matter (“soft tissues checked — no suspicious lesion”).
Photographs, scans and radiographs
These are personal data, and often special-category health data. Store them in the clinical system, not on a personal phone. If a phone must be used in a defined work process, it needs a written, secure workflow — not WhatsApp to a friend for a “quick opinion” with the patient’s face attached.
UK GDPR and the Data Protection Act 2018
You need a lawful basis to process health data, usually for the provision of health care and associated legal duties. Patients have rights of access to their records (subject access). Respond within the statutory timescale. Do not hide entries or charge an illegal fee. If you use a processor (cloud backup, laboratory portal, software vendor), there must be a contract and a clear idea of where data sit.
Retention
Follow the current records-retention schedule for your nation and organisation (NHS and private practices often follow national NHS / CQC-facing schedules). Do not shred a record because a complaint feels likely. When you do destroy records, do it securely.
Security basics
- Unique logins — no shared “nurse” password
- Lock screens when you walk away
- Encryption and backups that have been tested
- A process for lost devices and suspected breaches, including ICO notification where the law requires it