Reading List

A curated Reading List to support and extend learning from Handling Third-Party Requests for Patient Information.
The sources below cover confidentiality, proxy access, data sharing, third-party disclosure, safeguarding-sensitive information and information governance in general practice.
1. Confidentiality and Caldicott
National Data Guardian - The Caldicott Principles
The eight principles for using confidential patient information appropriately, including the duty to share when appropriate and the need to inform patients about information use.
https://www.gov.uk/government/publications/the-caldicott-principlesGMC - Confidentiality: good practice in handling patient information
Professional guidance on ethical and legal duties, disclosure decisions and protecting patients and others.
https://www.gmc-uk.org/professional-standards/the-professional-standards/confidentialityGMC - Disclosing patients' personal information: a framework
A practical framework for deciding when to disclose patient information, including consent, lack of capacity and public interest scenarios.
https://www.gmc-uk.org/professional-standards/the-professional-standards/confidentiality/disclosing-patients-personal-information-a-frameworkGMC - Sharing information with family members
Case-based material on balancing confidentiality with sensitive communication and support for those close to the patient.
https://www.gmc-uk.org/professional-standards/learning-materials/sharing-information-with-family-members
2. Proxy Access and Online Records
NHS - Accessing GP services for someone else, with proxy access
Patient-facing information explaining proxy access and how someone may help another person manage GP services.
https://www.nhs.uk/nhs-services/gps/gp-services-for-someone-else-proxy-access/NHS England - Proxy access
Guidance on proxy access levels, permissions, consent forms and recording agreed access in GP systems.
https://www.england.nhs.uk/long-read/proxy-access/NHS England Digital - Safeguarding your patients
Guidance on vulnerable patients, safeguarding risks and when to refuse, review or revoke proxy access.
https://digital.nhs.uk/services/proxy-application-service/safeguarding-your-patients
3. Data Sharing and Special Category Data
ICO - Data sharing: a code of practice
Practical advice on sharing data lawfully and protecting privacy while meeting accountability duties.
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/data-sharing-a-code-of-practice/ICO - Special category data
Guidance explaining that health data is special category data and requires additional protection under UK GDPR.
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/a-guide-to-lawful-basis/special-category-data/
4. Safeguarding and Protection
GMC - Disclosures for the protection of patients and others
Guidance on disclosure when patients or others face a risk of serious harm, including adults who lack capacity and safeguarding concerns.
https://www.gmc-uk.org/professional-standards/the-professional-standards/confidentiality/disclosures-for-the-protection-of-patients-and-others

