Healthcare Records
Healthcare records law in the UK is the body of statute and regulatory guidance, principally UK GDPR, the Data Protection Act 2018, the common law duty of confidentiality, and the NHS Records Management Code of Practice 2021, that governs the creation, retention, access, and disclosure of information held about patients and service users. Healthcare records carry special-category personal data of the highest sensitivity: GP letters, hospital discharge summaries, mental-health assessments, and clinical-research datasets identify patients alongside diagnoses, medication, and treatment outcomes. anonym.legal will offer en-GB workflows that pseudonymise these identifiers in line with UK GDPR, the Data Protection Act 2018, and the retention and sharing expectations of the NHS Records Management Code of Practice, preserving the clinical narrative while protecting patient identities across audit, research, subject-access response, and external review. Task-specific healthcare guidance lands in US-012.
By the numbers
The health sector recorded the highest number of self-reported personal data breaches of any UK sector — 3,820 cases between 2023 and Q1 2025 — out of nearly 22,000 total breach reports received by the ICO in that period.
The NHS Records Management Code of Practice 2021 mandates a minimum retention period of 8 years for general medical records after last treatment, creating large volumes of personally identifiable health data that must be securely managed during that period.
NHS England Digital, Records Management Code of Practice (digital.nhs.uk)
When this doesn't apply
- Does not provide clinical decision support, interpret diagnoses, or assess clinical coding — pseudonymisation applies to patient identifiers only; clinical content, SNOMED codes, and ICD codes are preserved and remain the clinician's responsibility.
- Does not satisfy a subject access request under UK GDPR Article 15 in itself — a formal SAR response requires a qualified Caldicott Guardian or data protection officer to review and approve the scope of the disclosure before release.
Tasks
Anonymising NHS Patient Electronic Health Record Extracts
UK GDPR Art. 9Pseudonymising GP Medical Notes and Referral Letters
UK GDPR Art. 9Anonymising Hospital Discharge Summaries for Clinical Audit
NHS Records Management Code of Practice 2021Pseudonymising Mental Health Detention Papers
Mental Health Act 1983Anonymising Outpatient Clinic Letters for Peer Review
UK GDPR Art. 9Pseudonymising Pathology, Radiology, and Imaging Reports
UK GDPR Art. 9Anonymising NHS SAR Responses Before Release
UK GDPR Art. 9Pseudonymising Clinical Trial Data: Consent Forms & CRFs
Medicines for Human Use (Clinical Trials) Regulations 2004Anonymising Research-Cohort Datasets for HRA Studies
Health Research Authority guidancePseudonymising NHS Continuing Healthcare Assessment Packs
DPA 2018 Sch.1 Pt.1Anonymising Clinical Input to Coroners' Inquest Records
Common Law Duty of ConfidentialityPseudonymising Adult Safeguarding Case Files
DPA 2018 Sch.1 Pt.1Pseudonymising Child Safeguarding Referrals
DPA 2018 Sch.1 Pt.1Anonymising Whistleblowing & FTSU Disclosures
Common Law Duty of ConfidentialityPseudonymising NHS Significant-Event Audit Reports
Common Law Duty of ConfidentialityPseudonymising Multidisciplinary Team Meeting Minutes
UK GDPR Art. 9Pseudonymising NHS Staff Occupational Health Records
DPA 2018 Sch.1 Pt.1