Health data attracts additional conditions almost everywhere. The operational consequence is that the question is rarely whether you have a lawful basis; it is whether you can also satisfy the additional condition, restrict access appropriately, and evidence both.
Care is also inherently multi-party. Data moves between providers, laboratories, insurers, research partners and technology suppliers, and each hop needs a defined role, an agreement and a retention position.
Where personal data flows
- Clinical records
- Diagnoses, medication, notes and imaging held in electronic record systems with long retention obligations.
- Referrals and sharing
- Data exchanged with other providers, laboratories, pharmacies and funders, often through integration platforms.
- Research and secondary use
- Datasets reused for research, service improvement or model development, usually requiring a distinct basis and governance route.
- Digital health products
- App-collected symptoms, wearables and remote monitoring streams, frequently continuous and high-volume.
- Administrative and workforce
- Appointments, billing, occupational health and staff records with their own sensitivity.
Priority risks
- Broad internal access
- Clinical systems configured for availability during emergencies, resulting in far wider routine access than any role needs.
- Undocumented secondary use
- Research or product development using clinical data without an approved basis, governance review or participant transparency.
- Weak de-identification
- Datasets described as anonymised that remain re-identifiable through dates, rare conditions, postcodes or free text.
- Sharing without agreements
- Long-standing exchanges between organisations with no written allocation of roles or responsibilities.
- AI in clinical pathways
- Decision-support tools introduced without impact assessment, oversight, monitoring or a documented fallback.
Practical controls
- Apply role-based access with break-glass procedures that are logged and reviewed rather than routinely used.
- Require a governance review and documented condition for every secondary use of health data.
- Test de-identification against realistic re-identification attempts before releasing a dataset.
- Put written agreements in place for every recurring data exchange, defining roles, purposes, security and incident handling.
- Assess clinical AI with a full impact assessment covering accuracy, oversight, monitoring and failure handling.
- Extend retention schedules to imaging, communications and research datasets, not just the main record system.
- Train frontline staff on free-text notes, which are the most common source of unnecessary sensitive detail.
Worth measuring
- Break-glass access events reviewed within the target period.
- Percentage of recurring data exchanges covered by a current written agreement.
- Secondary-use projects with a completed governance review before data was accessed.
Privacy Practice Lab publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.