Skip to content

Sector guidance

Privacy for healthcare and life sciences

Health data is sensitive by default, shared across many organisations, and increasingly used for research and AI — a combination that leaves little room for informal practice.

Health data attracts additional conditions almost everywhere. The operational consequence is that the question is rarely whether you have a lawful basis; it is whether you can also satisfy the additional condition, restrict access appropriately, and evidence both.

Care is also inherently multi-party. Data moves between providers, laboratories, insurers, research partners and technology suppliers, and each hop needs a defined role, an agreement and a retention position.

Where personal data flows

Clinical records
Diagnoses, medication, notes and imaging held in electronic record systems with long retention obligations.
Referrals and sharing
Data exchanged with other providers, laboratories, pharmacies and funders, often through integration platforms.
Research and secondary use
Datasets reused for research, service improvement or model development, usually requiring a distinct basis and governance route.
Digital health products
App-collected symptoms, wearables and remote monitoring streams, frequently continuous and high-volume.
Administrative and workforce
Appointments, billing, occupational health and staff records with their own sensitivity.

Priority risks

Broad internal access
Clinical systems configured for availability during emergencies, resulting in far wider routine access than any role needs.
Undocumented secondary use
Research or product development using clinical data without an approved basis, governance review or participant transparency.
Weak de-identification
Datasets described as anonymised that remain re-identifiable through dates, rare conditions, postcodes or free text.
Sharing without agreements
Long-standing exchanges between organisations with no written allocation of roles or responsibilities.
AI in clinical pathways
Decision-support tools introduced without impact assessment, oversight, monitoring or a documented fallback.

Practical controls

  • Apply role-based access with break-glass procedures that are logged and reviewed rather than routinely used.
  • Require a governance review and documented condition for every secondary use of health data.
  • Test de-identification against realistic re-identification attempts before releasing a dataset.
  • Put written agreements in place for every recurring data exchange, defining roles, purposes, security and incident handling.
  • Assess clinical AI with a full impact assessment covering accuracy, oversight, monitoring and failure handling.
  • Extend retention schedules to imaging, communications and research datasets, not just the main record system.
  • Train frontline staff on free-text notes, which are the most common source of unnecessary sensitive detail.

Worth measuring

  • Break-glass access events reviewed within the target period.
  • Percentage of recurring data exchanges covered by a current written agreement.
  • Secondary-use projects with a completed governance review before data was accessed.

Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.