When I first started out as a health professional in occupational health, emailing health reports felt efficient — even considerate. We were doing our best in protecting patient data with the tools we had. Then came password protection (clunky, confusing, often ignored). Fast forward to today, and the stakes are higher.
With smartphones, cloud storage, and remote working now the norm, protecting patient confidentiality isn’t just good practice — it’s a legal and ethical must. If you’re still emailing sensitive reports, it’s time for a rethink.
Let’s break it down simply — no jargon, no judgment. Just practical steps to keep you (and your patients/clients) safe.
Common Pitfalls That Put Personal Health Data at Risk
Personal Devices
Using your own laptop or phone for work? If it’s lost, stolen, or hacked, patient data could be exposed.
Quick Fixes:
- Enable device encryption
- Use secure work-only apps
- Avoid saving files locally
Best Practices for Confidentiality
🔐 Secure Communication
- Encrypted email: Scrambles messages so only the intended recipient can read them
- Secure messaging apps: Use platforms designed for healthcare
- No public Wi-Fi: Ever. It’s a hacker’s playground
☁️ Data Storage & Backup
- Use encrypted cloud services
- Back up regularly (automated if possible)
- Lock up physical records — yes, paper still matters
🛡️ Device Security
- Strong, unique passwords
- Keep software updated
- Encrypt sensitive files
📉 Data Minimisation
- Only collect what you truly need
- Shred or securely delete outdated records
🧠 Staff Training
- Make data protection part of onboarding
- Run refreshers regularly — especially after tech updates
👀 What’s the Legal Angle?
Under the UK GDPR and Data Protection Act 2018, health professionals are data controllers. That means you’re responsible for how patient data is handled, stored, and shared. Emailing unencrypted reports? That’s a breach waiting to happen.
Final Thought
This isn’t about fear — it’s about confidence. When you know your systems are secure, you can focus on what really matters: patient care.
The checklist is designed to help you ensure you are meeting key data protection requirements when handling sensitive health information. Follow the links for clarification of technical safeguards
Health Data Protection Checklist for Health Professionals
Foundational Principles
[ ] I have a clear and documented reason for collecting and using health information.[ ] I only collect the minimum amount of data necessary for the intended purpose.[ ] I ensure that patient information is accurate and kept up to date.[ ] I do not keep patient information for longer than is necessary.[ ] I am transparent with patients about how their data is collected, used, and stored.Handling and Security
[ ] I have strong, unique passwords for all systems and devices.[ ] I use two-factor authentication (2FA) wherever possible.[ ] I do not leave patient records, either on paper or on a screen, unattended.[ ] I use secure methods (e.g., encryption) for storing and transmitting sensitive data (which includes memory sticks.)[ ] I only access patient information when I have a legitimate and documented reason to do so.[ ] I do not discuss patient information where others can be overheard.Patient Rights and Consent
[ ] I have a process to obtain explicit and informed consent for data processing, especially for non-standard uses like research.[ ] I have a clear procedure for handling patient requests to access their own data.[ ] I am aware of a patient’s right to withdraw their consent at any time.[ ] I have a process to verify the identity of a person requesting patient data.Reporting and Accountability
[ ] I know who the designated Data Protection Officer (DPO) is for my organisation.[ ] I have a clear plan for what to do in the event of a data breach.[ ] I am aware of the 72-hour deadline to report serious data breaches to the relevant authority (e.g., the ICO).[ ] I undergo regular training on data protection and information governance.[ ] I keep a record of my data processing activities.Third Parties
[ ] I ensure any third-party services I use (e.g., software, storage providers) are also GDPR compliant.[ ] I have a formal agreement or contract in place when sharing data with other organisations.Do you think these stipulations are enough, too much or outdated. Let me know in the comments.






