Confidentiality is to keep secret


“Confidentiality” is to keep secret about something that has been spoken, heard or written in confidence.

The term “confidentiality” has been used by various organisations and departments in many ways, such as ‘Privacy', ‘Secrecy', ‘Restricted', ‘Security' and ‘Official Secret', etc. “Preservation of confidentiality is the only way of securing public health otherwise doctors will be discredited ... future individual patients will not come forward if doctors are going to squeal on them.”

There is a well established and well understood presumption in favour of confidentiality.

Therefore compelling reasons are necessary to justify disclosure of information acquired in practice by a health care professional. What constitutes ‘good reason', however, is not so well understood and health care professionals encounter moral dilemmas and intellectual puzzlement.

Delivery of health care system in the UK is rapidly changing and doctors are faced with legal and ethical obligations relating to their professional practice. There is an emerging trend towards the use of statutes to protect and enforce patient rights resulting in alteration and limitations to professional practice.

Confidentiality has been regarded as ‘indispensible' under good medical practice otherwise best treatment cannot be offered to patient. Equally this duty of confidentiality could itself cause greater damage to the patient's rights and interests if the information about individual's physical and mental health is not shared with relevant professionals.

Doctors and health care providers are faced with the dilemma of finding a balance between protecting patient's confidentiality and allowing physicians to meet appropriate care needs of a patient.

The aim of this essay is to critically explore whether an unmitigated duty of confidence would prevent a physician sharing information with other health care professionals to treat a patient effectively.

The way to approach the question is to understand; (a) the origin, (b) recognition of the duty of confidence (c) the regulatory bodies guidelines and to look at the case laws, before looking into the (d) exceptions to this duty, prior to (e) drawing a conclusion.

  1. Origin Of The Duty Of Confidence:

A doctor's duty about patient's confidentiality has its origin from the first Medical ethics codes,

The Hippocratic Oath that states:

“Whatsoever things I see or hear concerning the life of men, in my attendance on the sick or even apart therefrom, which ought not to noised abroad, I will keep silence thereon, counting such things to be as sacred secrets.”

Patient confidentiality also receives unqualified protection in the modern version of the Oath, the Declaration of Geneva: “I will respect the secrets which are confined in me, even after the patient has died.”

In October 2009 General Medical Council, published an up to date guidance for doctors on “Confidentiality”, emphasising the point of making patient care a first concern, along with showing respect to patient's right to confidentiality. This further holds a doctor personally responsible for his professional practice and should be able to justify his actions.

  1. Recognition Of The Duty Of Confidence:

The Department of Health, recognises duty of confidence in patient-clinician relationship by holding this as a legal obligation that is derived from case law. It also establishes this as a requirement within professional codes of conduct within NHS employment contracts as a specific requirement linked to disciplinary procedures.

There is a significant burden of confidentiality on medical profession, where the responsibility of keeping patient's medical information safe can be quite diffuse due to multidisciplinary structure. Subsequently, there is a need to understand the duty of confidentiality ethically as well.

“As Jackson describes this on the deontological (duty-based) that states ‘respect for person's rights importance for its own sake' and teleological (consequences-based), ‘judging the actions by its consequences' basis of reasoning.”

Patient's confidentiality, autonomy and to recognise the duty of care that a doctor owes are three main duties of a doctor. Although these three main duties are professional, but there are legal implications in the event of a breach of such duties. These are also legal duties and ethical consideration often arises while contemplating such duties.

Doctor-patient confidentiality starts when a patient seeks the advice, care, and/or treatment from a doctor. It is usually implied by the patient seeking medical consultation. The patient should not be hindered by doubts that their medical concern(s) or condition(s) will be disclosed to others.

The general expectation is that a doctor will hold such knowledge in confidence and will only use it exclusively for patient's benefit.

The professional duty of confidentiality covers not only what patients may or have revealed to doctors, but also what doctors may independently conclude or form a clinical opinion about, on the basis of examination, further investigations and tests (including x-rays, lab-reports, etc.) and/or assessment of patients. Beside communications between patient and doctor, and it also includes communications between the patient and other professional staff working alongside the doctor.

There has to be a lawful "doctor-patient relationship" between patient and a doctor before any duty of confidentiality is developed. Generally speaking, a patient must voluntarily seek consultation from the doctor, and only then can expect that the information will be held in confidence. This does not need to be expressed and is implied from the circumstances.

Meeting a doctor at a party, and during a “general conversation”, asking the doctor a medical opinion relating to them, the doctor's advice under these circumstances most likely would not be regarded as confidential. Further, the doctor will not be considered “the individual's doctor.”

Similarly, if patients are examined by a doctor following a third party request (such as an insurance company or their employer), no “Doctor-Patient relationship” is considered and no duty of confidentiality is owed by the doctor, irrespective of the extensive nature the examination or friendly attitude of the doctor. This is simply because patient has not sought the doctor's advice or treatment.

  1. Regulatory Bodies Guidelines & Case Laws:

There is an obligation to obtain guidance on the duty of confidentiality from regulatory and statutory bodies. A ‘duty of confidentiality' exists in the UK under Common Law based upon societal customs but not recognized by statute. This is further recognized, enforced and developed through the judgments in case laws but can make interpretation difficult.

In AG v Guardian Newspapers (No. 2) also known as spycatcher case, Lord Bingham explained that the duty of confidence arises from an obligation of conscience, and Lord Goff laid out the necessary conditions that relates to the circumstances for the existence of a duty of confidence with the effect that it would be just in all the circumstances for a doctor to avoid disclosing patients' information to others.

General Medical Council recognises “Confidentiality” as fundamental for patients to confide in doctors otherwise, patients may be hesitant to provide information or seek medical attention that is essential for good care.

The Medical Research Council's guidance on confidentiality reflects upon respect to private life as a human right and considers confidentiality as fundamental when holding extremely sensitive information. Keeping control over facts about one's self can have an insignificant role in person's sense of security, freedom of action and self-confidence.

The Human Rights Act 1998, Article 8, Right to respect for private and family life, also protects patient's interest in confidentiality. However Article 8 is not an absolute right and is qualified by Article 8(2).

There are number of cases where patients have relied on Article 8 of Human Rights Act 1998 about the breach of confidentiality. For example, the judgment of ECtHR in Z v Finland, court held that there was no violation of Article 8 on the basis of good reasons for acquiring information, as the legitimate aims being pursued and no disproportionate measures were taken.

In the case of Campbell v MGN Ltd, Baroness Hale said “Blundering in when matters are acknowledged to be at ‘fragile' stage may do great harm.” Here the House of Lords recognises and obligation of existence of confidentiality due to the nature of treatment for Ms Campbell's drug addiction.

In May 2002, Information Commissioner Office published guidelines on “Use and Disclosure of Health Data” The Data Protection Act 1998 gives effect in UK law to EC Directive 95/46/EC.

It introduces Eight Data Protection Principles that set out standards on personal data handling and processing ‘fairly and lawfully.' However it is worth noting from British Medical Association's guidelines that The Data Protection Act governs access to the health records of living people only in both NHS and private health sector. It is also applicable to employers holding data about physical or mental health of their employees if the record has been made by, or on behalf of, a health professional in connection with the care of the employee..

Does the duty of confidentiality end with the death of a patient? The Department of Health and GMC both agree over the lack of clarity about legal obligations of confidentiality applying to deceased patient. Both suggest that ethical obligation of confidentiality must continue to apply according to the guidelines.'

General Medical Council explains that, “Your duty of confidentiality continues after a patient has died”.

GMC further suggest that the level of disclosure after a patient's death will depend on the circumstances. Doctor should usually respect patient's wishes and must consider the reasons for such disclosure while balancing the distress or benefits to the patient's spouse or family. Further such disclosures could disclose information about the patient's family or anyone else and if the information is not already in public knowledge then consider anonymisation or coding.

  1. Exceptions To The Duty Of Confidentiality:

GMC advice is to regard confidentiality as an important but not an absolute duty under exceptional circumstances e.g. if required by law, implicit or explicit consent by patient and when justifiable public interests are involved.

It is worth noting that breaches of confidentiality are not deliberate acts of the doctor, but are commonly unintentional breaches of confidentiality. Physical privacy of the patient can be prevented to a degree by curtains on NHS inpatient wards, but there is no guarantee that confidential discussion at the patient's bedside will not be overheard by others.

Where appropriate consent has been obtained from the patient the information can be shared with others such as, health care workers, medical reports to Benefit Agencies, Employers or Police. Also to administrative staff for anonymisation of research data and Publication of case histories.

Disclosure is also appropriate without patient consent due to withheld consent and impracticalities in patient's best interest e.g. medical emergencies, in the case of individual's mental incapacity and in the case of child abuse where statutory authorities must be informed.

Also to DVLA where patient continues to drive despite attempts to persuade them otherwise, where a person is unable to comprehend that they are unfit to drive e.g. in case of dementia.

Public interest is probably the most important exception and disclosure can be made without patient's permission. This arises in such cases; if ordered by a judge, a person has a serious communicable disease continues to put close contacts at risk, to act quickly in the event of an outbreak of some communicable disease and there is insufficient time to obtain patient's consent and to assist in the prevention, detection and prosecution of a serious crime and reporting ‘gunshot and knife injuries.' There may be exceptional circumstances of fitness to practice where a health professional is a risk to the public but does not give consent to disclosure. Also included are Statutory notifications (birth, death, abortion, and notifiable diseases), information regarding serious communicable diseases to the relevant authorities, reporting death to a coroner in connection with inquest or fatal accident inquiry.

The Courts handle the duty of confidentiality in a flexible way leading to ongoing changes in the UK legal system. Indeed, Courts are faced with a balancing act when deciding cases on confidentiality and disclosure. There are several circumstances when the doctor may legitimately disclose information regarding a patient. Both legal and medical experts would argue that the duty of confidentiality is relative, not absolute; and the matter is principally for the professional judgement of the contemplating health practitioner to decide in the individual case whether public interests take precedence over the duty of confidentiality.

In the case of W v Egdell (1990), considering the Doctrine of Judicial precedence, the court held that the balance of public interests (i.e. confidentiality against public safety) was in favour of disclosure because of the seriousness of the offences that the patient had committed and the need for the authorities to have relevant information about his medical condition before making decisions about his release.

In Hunter v. Mann, the doctor refused to disclose identities of two patients he treated in a ‘hit and run' accident. This doctor was convicted and fined under the Road Traffic Act 1972 (which preceded the 1988 Act).

Similarly, judgments in the cases of X v Y and Palmer v Tees Health Authority is also examples of court's balancing act with different rulings.


The duty of confidentiality is regarded “sacred” by almost all medical practitioners, however the legal duty of confidence remained somewhat opaque. Privacy and confidentiality are similar but not synonymous. The Human Rights Act prevents privacy but the duty of confidentiality simply prevents the redisclosure of previously disclosed information in a confidential doctor-patient relationship. The General Medical Council's guidance is the most useful tool for the doctors, when faced with the dilemma to justify breaching patient confidentiality. Failure to follow General Medical Council guidelines could lead to disciplinary and professional misconduct proceedings against the doctor. If found guilty the doctor can be struck off from medical register.

Disclosure may be legal under certain circumstances (mainly under the public interest exception, and certain cases where the patient mental capacity has been affected). But certain requirements must be met before any disclosure is acceptable under these circumstances. There are a wide range of circumstances where duty to respect confidentiality is either suspended or modified. For example when sharing patients` notes among health care professionals.

The doctor exists for patient, not the other way round. The doctor must act independently or in collaboration with other medical colleagues and must always consider the best for the patient's physical and mental health. Therefore a blanket and absolute duty of confidence would prevent a doctor from disclosing information that is necessary for other health professionals to treat the patient effectively.

In my view duty of confidentiality should be regarded as relative, not absolute as there is no single collection of ethical guidelines or laws, clarifying every aspect of ethical or legal issue arising from the duty confidentiality. Breach of confidences can have deleterious consequences;

particularly for the doctor-patient relationship, but, failure to disclose in some situations could have serious implications for the well-being of the patient or the wider society.

While keeping the balanced view, significant majority of clinicians would regard the duty of confidentiality as a “Double-edged sword”. The problem arises due to the broad and somewhat vague exception of ‘public interests' along with confusing legal rules governing the duty of confidentiality.