1-20 of 2,662 results for subject:"Medical records"
Librarians' tools
- Search time
- 0.275 seconds
- Solr query time
- 0.011 seconds
- Search query
- subject:"Medical records"
- We searched for
- subject_t:"Medical records" OR subject_t:"Health records" OR subject_t:"NHS numbers" OR subject_ses:91972
Type
House
Session
More
Year
More
Department
More
Member
More
Primary member
More
Answering member
More
Legislative stage
Legislation
More
Subject
More
Publisher
To ask His Majesty's Government what plans they have to direct Cambridge University Hospitals NHS Foundation Trust to inform patients that their records were inappropriately accessed by staff members.
To ask His Majesty's Government what plans they have to direct Cambridge University Hospitals NHS Foundation Trust to inform patients that their records were inappropriately accessed by staff members.
To ask His Majesty's Government what assessment they have made of the risks to patient confidentiality of digital medical records being shared across multiple healthcare trusts.
To ask His Majesty's Government what assessment they have made of the risks to patient confidentiality of digital medical records being shared across multiple healthcare trusts.
Where medical records are shared across National Health Service organisations, such as the Shared Care Record program, organisations should complete a Data Protection Impact Assessment. This allows them to consider the data protection and confidentiality risks involved, and outlines what actions they can take to mitigate the risk to an acceptable level. NHS England has published guidance on this subject, Information Governance Framework: Shared Care Records, a copy of which is attached.
To ask His Majesty's Government, further to the Written Answer by Baroness Merron on 30 June (HL570), whether all the guidance referred to has now been published by NHS England; and whether that published guidance covers accesses for which NHS England, general practices, or pharmacies are the responsible employers.
To ask His Majesty's Government, further to the Written Answer by Baroness Merron on 30 June (HL570), whether all the guidance referred to has now been published by NHS England; and whether that published guidance covers accesses for which NHS England, general practices, or pharmacies are the responsible employers.
How can the upcoming Health Data Research Service simplify access to national health data for research opportunities, while addressing technical challenges, security, governance and public trust?
How can the upcoming Health Data Research Service simplify access to national health data for research opportunities, while addressing technical challenges, security, governance and public trust?
To ask His Majesty's Government whether the data described in the UK Biobank Data Statement on 28 April (HL Deb cols 1117–18) would be considered identifiable human genomic data under the Safeguarding UK human genomic data guidance, published on 2 July.
To ask His Majesty's Government whether the data described in the UK Biobank Data Statement on 28 April (HL Deb cols 1117–18) would be considered identifiable human genomic data under the Safeguarding UK human genomic data guidance, published on 2 July.
The Government understands that some of the data described in UK Biobank's statement from 28th April would be in scope of the Government's recent guidance on safeguarding UK human genomic data, however it is for the Information Commissioner's Office to determine if this may be potentially identifiable data. UK Biobank’s dataset is critical in supporting scientific discoveries that improve patient health, and we expect UK Biobank to remain one of the leading health research resources. Government continues to engage with Biobank to ensure that they are working to both protect the data of participants while ensuring that researchers who have a legitimate need to use the datasets can once again resume their research as soon as possible.
To ask His Majesty's Government, further to the Written Answer by Baroness Merron on 16 June (HL696), who authorised the sign-off and publication of National Data Integration Tenant Data Protection Impact Assessment.
To ask His Majesty's Government, further to the Written Answer by Baroness Merron on 16 June (HL696), who authorised the sign-off and publication of National Data Integration Tenant Data Protection Impact Assessment.
The NHS Federated Data Platform (NHS FDP) safely connects information from different systems across the National Health Service into a single, secure environment. This allows staff to co-ordinate care better to improve outcomes for patients.
In accordance with NHS England’s established information governance and assurance processes, the National Data Integration Tenant (NDIT) Data Protection Impact Assessment (DPIA) was reviewed and approved for sign off by the FDP Data Governance Group as well as senior Information Governance Professionals from NHS England.
For publication, the approved DPIA was reviewed by the Information Asset owner for NDIT and redacted in line with the Freedom of Information Act 2000 prior to approval for publication by the NDIT product owner, Programme Director and senior Information Governance Professionals from NHS England.
To ask the Secretary of State for Health and Social Care, pursuant to the HL1033, 6 July 2026, how many times the audit trail for access to data on the National Data Integration Tenant has been reviewed or audited since its implementation, and what the outcomes of those audits were.
To ask the Secretary of State for Health and Social Care, pursuant to the HL1033, 6 July 2026, how many times the audit trail for access to data on the National Data Integration Tenant has been reviewed or audited since its implementation, and what the outcomes of those audits were.
To ask the Secretary of State for Health and Social Care, what recent steps have been taken within the NHS to ensure compliance with the Records Management Code of Practice.
To ask the Secretary of State for Health and Social Care, what recent steps have been taken within the NHS to ensure compliance with the Records Management Code of Practice.
To ask His Majesty's Government what safeguards are in place to prevent patients’ medical records being accessed (1) inappropriately, and (2) illegally, in NHS Trusts in England where digital records are kept.
To ask His Majesty's Government what safeguards are in place to prevent patients’ medical records being accessed (1) inappropriately, and (2) illegally, in NHS Trusts in England where digital records are kept.
National Health Service trusts are required to maintain audit logs of access to patient information and have controls in place to prevent and identify unauthorised access. The Government is currently considering options for further action, and we will set out more detail in due course. In the meantime, NHS England will be launching a hard-hitting campaign telling staff Don’t let curiosity kill your career.
We expect the Single Patient Record to help strengthen ways to tackle this issue, including improving the audit trail for cases like this, so that trusts can take clear action when staff access records without due cause. Security and privacy of people’s health data are paramount, and as you’d expect we will build the strongest safeguards into the Single Patient Record. We’ll be confirming more on this as we develop the Single Patient Record in the coming months.
To ask His Majesty's Government how many instances of patients’ medical records being accessed (1) inappropriately, and (2) illegally, have been recorded in NHS Trusts in England where digital records are kept in the last two years for which figures exist.
To ask His Majesty's Government how many instances of patients’ medical records being accessed (1) inappropriately, and (2) illegally, have been recorded in NHS Trusts in England where digital records are kept in the last two years for which figures exist.
1,445 cases of inappropriate access have been reported to the Information Commissioner's Office (ICO) between 2019 to 2025. Medical records are accessed all the time by staff with a legitimate need to deliver the best possible care. Inappropriate access is rare, as the vast majority of staff take their duty of confidentiality extremely seriously. With that said, we agree with the ICO that there have clearly been too many incidents of National Health Service staff accessing patient records inappropriately. Any unauthorised access to a patient’s medical record is completely unacceptable and NHS organisations must take action where it occurs, including disciplinary measures and referrals to the police and professional regulators where appropriate.
New clause 6 debated and withdrawn. New clause 11, discussed with new clause 24, debated and withdrawn. New clause 12, discussed with new clauses 56 and 84, under consideration.
New clause 6 debated and withdrawn. New clause 11, discussed with new clause 24, debated and withdrawn. New clause 12, discussed with new clauses 56 and 84, under consideration.
To ask the Secretary of State for Health and Social Care, what steps he plans to take to ensure that patients can access audit logs of who has accessed their health records across (a) GP Connect, (b) the Summary Care Record and (c) other existing systems before the implementation of...
To ask the Secretary of State for Health and Social Care, what steps he plans to take to ensure that patients can access audit logs of who has accessed their health records across (a) GP Connect, (b) the Summary Care Record and (c) other existing systems before the implementation of...
Patients can make a request to the relevant organisation, such as their general practice or hospital, to see who has accessed their information in existing systems.
Audit logs will be a key safeguard for the Single Patient Record, helping to show who has accessed patient information and whether that access was appropriate. The detailed audit log arrangements are being developed as part of the technical design work and have not yet been finalised.
To ask the Secretary of State for Health and Social Care, whether the proposed Single Patient Record will have audit trails that are directly accessible to patients as a matter of course.
To ask the Secretary of State for Health and Social Care, whether the proposed Single Patient Record will have audit trails that are directly accessible to patients as a matter of course.
Patients can make a request to the relevant organisation, such as their general practice or hospital, to see who has accessed their information in existing systems.
Audit logs will be a key safeguard for the Single Patient Record, helping to show who has accessed patient information and whether that access was appropriate. The detailed audit log arrangements are being developed as part of the technical design work and have not yet been finalised.
To ask the Secretary of State for Health and Social Care, whether he plans to commission an updated Data Protection Impact Assessment for the NHS Federated Data Platform.
To ask the Secretary of State for Health and Social Care, whether he plans to commission an updated Data Protection Impact Assessment for the NHS Federated Data Platform.
The NHS Federated Data Platform (NHS FDP) safely connects information from different systems across the National Health Service into a single, secure environment. This allows staff to co-ordinate care better to improve outcomes for patients.
The NHS FDP is delivering for the NHS, helping people get the care they need quicker and more efficiently. Since March 2024, more than 100,000 additional patients have been supported to undergo procedures in theatres, partly by increasing theatre utilisation. Nearly 94,000 people have been supported on their cancer journey, with 7% seeing a reduction in the time it took to diagnose their cancer. There has been a 14% decrease in delays discharging patients staying in hospital for more than seven days, freeing up beds for those who need them most. NHS England publishes quarterly information on the benefits realised from the NHS FDP, which is available at the following link:
To date, 24 integrated care board clusters and 168 NHS trusts have signed up to the NHS FDP, including the Berkshire Healthcare NHS Foundation Trust.
The NHS FDP is underpinned by the NHS FDP Information Governance Framework which sets out the roles, responsibilities, and controls governing how data is accessed and used.
Access to data within the platform is subject to role-based and purpose-based access controls and is governed through a comprehensive set of information governance documentation, including Data Protection Impact Assessments (DPIA), data sharing agreements, and privacy notices.
Each product and use case within the platform is required to undergo appropriate information governance assessment and approval processes prior to deployment, with oversight provided through established governance arrangements, including the Federated Data Platform Data Governance Group.
NHS England has undertaken an urgent review of the current DPIA for the National Data Integration Tenant (NDIT), as the description of access to the directly identifiable layer within NDIT could be interpreted as indicating that non-NHS England staff have no access. This will be revised to make clear that some supplier staff, appropriately controlled, have access to patient data.
To ask the Secretary of State for Health and Social Care, what assessment he has made of whether the governance framework for the NHS Federated Data Platform reflects the data access arrangements currently in operation.
To ask the Secretary of State for Health and Social Care, what assessment he has made of whether the governance framework for the NHS Federated Data Platform reflects the data access arrangements currently in operation.
The NHS Federated Data Platform (NHS FDP) safely connects information from different systems across the National Health Service into a single, secure environment. This allows staff to co-ordinate care better to improve outcomes for patients.
The NHS FDP is delivering for the NHS, helping people get the care they need quicker and more efficiently. Since March 2024, more than 100,000 additional patients have been supported to undergo procedures in theatres, partly by increasing theatre utilisation. Nearly 94,000 people have been supported on their cancer journey, with 7% seeing a reduction in the time it took to diagnose their cancer. There has been a 14% decrease in delays discharging patients staying in hospital for more than seven days, freeing up beds for those who need them most. NHS England publishes quarterly information on the benefits realised from the NHS FDP, which is available at the following link:
To date, 24 integrated care board clusters and 168 NHS trusts have signed up to the NHS FDP, including the Berkshire Healthcare NHS Foundation Trust.
The NHS FDP is underpinned by the NHS FDP Information Governance Framework which sets out the roles, responsibilities, and controls governing how data is accessed and used.
Access to data within the platform is subject to role-based and purpose-based access controls and is governed through a comprehensive set of information governance documentation, including Data Protection Impact Assessments (DPIA), data sharing agreements, and privacy notices.
Each product and use case within the platform is required to undergo appropriate information governance assessment and approval processes prior to deployment, with oversight provided through established governance arrangements, including the Federated Data Platform Data Governance Group.
NHS England has undertaken an urgent review of the current DPIA for the National Data Integration Tenant (NDIT), as the description of access to the directly identifiable layer within NDIT could be interpreted as indicating that non-NHS England staff have no access. This will be revised to make clear that some supplier staff, appropriately controlled, have access to patient data.
To ask His Majesty's Government, further to the Written Answer by Baroness Merron on 16 June (HL696), whether the access of Palantir contractors to identifiable patient data was always part of the operational arrangements; and why the National Data Guardian was left unaware of this arrangement until it was exposed by...
To ask His Majesty's Government, further to the Written Answer by Baroness Merron on 16 June (HL696), whether the access of Palantir contractors to identifiable patient data was always part of the operational arrangements; and why the National Data Guardian was left unaware of this arrangement until it was exposed by...
The National Data Guardian (NDG) highlighted that the published Data Protection Impact Assessment (DPIA) for the National Data Integration Tenant (NDIT) was not fully reflective of current access arrangements, including limited administrative access by supplier staff.
Access by supplier staff has been part of the operational model for the NHS Federated Data Platform (NHS FDP) where necessary to support, maintain and assure the system. This access is strictly controlled, limited, and subject to contractual, technical and organisational safeguards.
The DPIA did include information on supplier data processing obligations and considered the risks associated with access to data. However, it was not sufficiently explicit about the nature and extent of limited administrative access by supplier staff. NHS England recognised this and has taken steps to improve transparency in how these arrangements are described. NHS England has also set out in its public communications that suppliers act only under the instructions of National Health Service organisations.
Whilst there is no statutory requirement for NHS England to notify the NDG of specific access arrangements to NDIT, NHS England engages regularly with the NDG through established governance routes as part of routine oversight of the NHS FDP Programme. This matter was discussed at the Data Transformation Check and Challenge Group; the NDG subsequently wrote to NHS England and has received an update in response. NHS England has also published an updated Privacy Notice on the NHS website in an online-only format.
NHS England acts as the data controller for the NHS FDP at the national level, including NDIT. NHS organisations using the platform act as data controllers for their own data and use of the system. Access to data is strictly controlled; any access by external contractors is limited, role-based and time-bound, requires appropriate security clearance and senior approval, and is fully logged and auditable. Data remains under the control of NHS organisations, and suppliers act only under the instruction of those organisations.
NHS England and the Department will continue to engage with the NDG through established governance routes on this matter.
Amendment 9 to Clause 43, discussed with new clauses 27, 33 and 34, negatived on division (1 to 7). Clauses 43 to 46 agreed to. Clause 47 under consideration.
Amendment 9 to Clause 43, discussed with new clauses 27, 33 and 34, negatived on division (1 to 7). Clauses 43 to 46 agreed to. Clause 47 under consideration.
Amendment 70 to clause 47 negatived on division (6 to 7). Amendment 48 to clause 47 negatived on division (6 to 7). Amendment 49 to clause 47 negatived on division (6 to 7). Clause 47, discussed with new clauses 7 and 8, agreed to. Clauses 48 to 50 agreed to. Amendment 6 to schedule 7 negatived on division (2 to 8). Schedule 7 agreed to. Clauses 51 to 57 agreed to. Written evidence reported to the House.
Amendment 70 to clause 47 negatived on division (6 to 7). Amendment 48 to clause 47 negatived on division (6 to 7). Amendment 49 to clause 47 negatived on division (6 to 7). Clause 47, discussed with new clauses 7 and 8, agreed to. Clauses 48 to 50 agreed to....
[This is a joint statement made with the Department for Science, Innovation and Technology.]
Human genomic data drives medical and scientific breakthroughs that benefit people by helping to identify some of the underlying factors in who will develop diseases and how they progress, leading to the development of new treatments. It...
[This is a joint statement made with the Department for Science, Innovation and Technology.]
Human genomic data drives medical and scientific breakthroughs that benefit people by helping to identify some of the underlying factors in who will develop diseases and how they progress, leading to the development of new treatments. It...
My Honourable Friend the Parliamentary Under-Secretary of State (Preet Kaur Gill MP) has made the following statement:
[This is a joint statement made with the Department for Science, Innovation and Technology.]
Human genomic data drives medical and scientific breakthroughs that benefit people by helping to identify some of the underlying factors in...
My Honourable Friend the Parliamentary Under-Secretary of State (Preet Kaur Gill MP) has made the following statement:
[This is a joint statement made with the Department for Science, Innovation and Technology.]
Human genomic data drives medical and scientific breakthroughs that benefit people by helping to identify some of the underlying factors in...