Statement of Guidance
Guidance Note: Protecting Personal Information in the Medical Field
In forceView on PRIVCOM's website Source document
Summary
This is an updated PrivCom guidance note explaining how the Personal Information Protection Act 2016 (PIPA), in effect since 1 January 2025, applies to the handling of personal information in the medical field. It is non-binding guidance issued under PrivCom's general powers to comment on PIPA's application, aimed at health service providers and medical professionals who collect, use, share, and transfer patient information.
- Sensitive personal information: Physical and mental health information, and related data often found in medical records, is classed as sensitive personal information under section 7 and requires enhanced protection.
- Privacy programme: Organisations must adopt suitable policies and measures (a privacy programme) under section 5 to meet PIPA obligations and individuals' rights.
- Consent versus lawful conditions: Consent to use personal information (section 6(1)(a)) is distinct from consent to medical treatment; consent is not required in emergencies or when needed to treat a patient, and organisations may instead rely on other lawful conditions such as emergency or contractual necessity.
- Proportionality and purpose limitation: Personal information collected must be adequate, relevant, and not excessive for its purpose (section 11), and organisations must be transparent about purposes in privacy notices (section 9).
- Security safeguards: Appropriate security safeguards, such as encryption, must be implemented under section 13 to protect personal information from loss, unauthorised access, or misuse.
- Sharing and transferring records: When sharing or transferring medical records, including overseas, organisations must identify a purpose and lawful condition, notify individuals via privacy notice, conduct due diligence on transfer risks, and implement risk-based controls.
- Retention and deletion: Once information is no longer needed for its original purpose, organisations should erase or securely destroy it unless another legal provision requires retention.
- Email communications and marketing: Organisations should maintain privacy in email communications, obtain patient consent before sending general email announcements, and be mindful of privacy risks (data collection, tracking, sharing, security, consent, and policy changes) when using email marketing tools.
The guidance reiterates that individuals retain rights to access their personal and medical information and to request correction, blocking, erasure or destruction, though these rights are not absolute and may be refused in certain circumstances.
Key obligations
- Organisations must adopt suitable policies and measures (a privacy programme) under section 5 of PIPA to give effect to their obligations and individuals' rights.
- Organisations must implement enhanced protections for sensitive personal information such as health data.
- Organisations must identify a lawful condition (consent or otherwise) for using personal information, with sensitive personal information requiring conditions beyond consent alone under section 6(1)(b).
- Organisations must ensure personal information collected is adequate, relevant, and not excessive relative to its purpose (proportionality, section 11).
- Organisations must provide individuals with transparent privacy notices explaining the purpose and lawful condition for using their personal information (section 9).
- Organisations must implement appropriate security safeguards, such as encryption, to protect personal information against loss, unauthorised access, or misuse (section 13).
- When sharing or transferring patient records (including overseas), organisations must identify a purpose and condition, notify individuals, assess and mitigate risk, and implement appropriate controls.
- Organisations must conduct due diligence, including risk assessment, when transferring personal information to overseas third parties.
- Organisations must erase or securely destroy personal information once no longer necessary for its purpose, unless another legal provision requires retention.
- Organisations must obtain patient consent before sending general email marketing announcements and manage individual patient communications separately.
- Organisations must honour individuals' rights to request access to their personal information and medical records, and to request correction, blocking, erasure or destruction, subject to permitted exceptions.
Applies to
health service providers, medical professionals, healthcare practitioners, organisations handling patient personal information