Whether you're working in a familiar department or supporting a new NHS organisation, patients have the same expectation every time – that their personal information will be handled with care, respect and professionalism.
Following the launch of NHS England's 'Don't let curiosity kill your career' campaign, we'd like to remind everyone working with Bank Partners that confidential patient information should only be accessed when there's a clear, legitimate and work-related reason.
No matter where you're working, protecting confidentiality is an essential part of delivering safe, high-quality care.
The same standards apply in every setting
Working across different NHS organisations means adapting to different teams and environments, but the principles of confidentiality never change.
Patient records should only be accessed when they are needed to carry out your role.
It isn't acceptable to access the records of:
- Friends
- Family members
- Colleagues
- Yourself
- High-profile individuals
- Patients you are no longer directly involved in caring for
Remember, having access to a clinical system doesn't automatically give you permission to view every record. Even if someone asks you to access their information, you must still have a legitimate work-related reason for doing so.
Every patient deserves the same level of confidentiality
Patients place enormous trust in the people caring for them, regardless of where that care is delivered.
Confidentiality is both a legal requirement and a professional duty. Accessing information without a valid reason can cause distress to patients, damage public trust and undermine confidence in NHS services.
Protecting confidential information is one of the simplest but most important ways to demonstrate respect for every patient you support.
Consistent practice protects patients and professionals
Wherever your work takes you, good information governance should remain part of your everyday practice.
Please remember to:
- Access records only when there is a legitimate professional reason.
- Use patient information only for approved work purposes.
- Keep passwords, smartcards and system access secure.
- Log out of systems when they are not in use.
- Share information only through approved, secure channels.
- Report any suspected or accidental inappropriate access immediately in line with Bank Partners incident reporting procedures.
- Speak to your line manager, Information Governance, Data Protection, Clinical Governance, or use the Freedom to Speak Up route if you are unsure or have concerns.
Access records only when there is a legitimate professional reason.
Accountability follows every access
Electronic patient records are auditable and every access can be reviewed.
Inappropriate access may result in disciplinary action, dismissal, referral to a professional regulator, reporting to the Information Commissioner's Office or police, and potential criminal prosecution.
Making the right decision before opening a record protects both the patient and your own professional accountability.
One commitment, wherever you work
Every NHS organisation relies on healthcare professionals who understand the importance of handling confidential information appropriately.
Please continue to follow Bank Partners policies, professional standards, the UK GDPR, the Data Protection Act 2018 and the common law duty of confidentiality whenever you access, use or share patient information.
By applying the same high standards in every placement, you help protect patients, support NHS organisations and reinforce the confidence that people place in healthcare professionals every day.
Thank you for playing your part in keeping patient information safe.