top of page

6-Month Data Protection in Health Wrap-Up

  • Writer: Joe Stock
    Joe Stock
  • Jun 25
  • 4 min read

It's been a busy first half of the year for data protection in health. From alleged inappropriate access to patient records, to questions around de-identified health datasets and continued scrutiny of the NHS Federated Data Platform, a few clear themes are emerging.


Just because you have access, doesn’t mean you should access.

In May, we saw the news that two hospitals had taken action against their staff for accessing Personal Data in relation to local tragedies for which they had no legitimate reason to access. Nottingham University Hospitals NHS Trust dismissed 11 staff members and issued written warning to 14 others in relation to the Nottingham attack in 2023, whilst at NHS University Hospitals of Liverpool Group, nearly 50 staff members were found to have inappropriately accessed records in relation to the Southport attack, although none were dismissed.


In June, the ICO issued a formal caution to a former healthcare professional at The London Clinic following a criminal investigation into the unlawful obtaining and disclosure of medical information to a third party without the data controller’s consent, contrary to section 170(5) of the Data Protection Act 2018.


Takeaway: Staff are accountable for their actions. Controls can help reduce this risk in some cases, but staff need to be aware of their obligations when it comes to accessing records. Breaching these obligations is serious and can result in job losses, and, in scenarios such as further disclosure, criminal action.


Understand your data

It hasn’t been the best year so far for Biobank, which has gained unwanted attention from both publication of data on Github and Alibaba. This raised two important points. 1. Organisations need to ensure appropriate disclosure controls in relation to health databases such as this; and 2. Organisations need to have a clear and documented determination of the status of their data in relation to data protection law. BioBank have continually stressed that the data published online ‘did not contain any personally identifying information’ and that the data was ‘de-identified’ - some commentators have disagreed. BioBank has referred itself to the ICO, with the National Data Guardian also issuing statements, so it will be interesting to see the outcome of their determination which could have implications for health research organisations.


In a similar vein, over the channel in France life sciences company IQVIA were fined €5million by CNIL, France’s data protection regulator.* There are many facets to this judgement, but one circled around whether the data held in two databases subject to investigation was anonymous or not, to which IQVIA were of the  view it was, and as such, outside scope of data protection law. CNIL, however, found that whilst data minimisation and technical controls were in place to reduce risk of identifiability, the data was pseudonymised, rather than anonymised, and as such it was still within scope of data protection law. Because of this, the rest of the investigation around areas such as control and transparency were in play.


Takeaway: Understanding the status of your data is a fundamental concept but in health can be one of the most difficult. Decisions need to be documented, consistent and appropriately reviewed and managed. I wrote about some of the challenges when it comes to terms in more detail here


Transparency takes all forms

In the IQVIA case, CNIL found that although the original providers of the data (in this case Pharmacists) were contractually responsible for providing transparency information, this did not absolve IQVIA of responsibility for ensuring that this information was being provided to data subjects under their own Controller Article 14 obligations. Where Health Research companies are receiving data from third parties such as the NHS for their own purpose of creating their own commercialised datasets, the CNIL judgement is an important reminder that you likely are a Controller given the whole processing operation, and that you have an obligation to ensure your Article 14 requirements are being discharged, and a contract with the other party does not override this.


Transparency in data breaches has also emerged as a theme, with one of the victims from the Southport attack stating “The decision to keep this from me for almost two years is a new low. .. I'm also angry that the Information Commissioner's Office was told about it in August 2024, and I've only be

en told now because I was about to read about it in a paper."


In June we also saw Mid and South Essex NHS Foundation Trust, Bedfordshire Hospitals NHS Foundation Trust and Norfolk and Norwich University Hospitals Foundation Trust put out statements to say they were affected by the Synnovis incident in 2024 and will be trying to contact impacted individuals once they can.


Takeaway: Transparency will always be more than a privacy notice. Whether data is collected directly, received from another organisation, or affected by a breach, health organisations need to be able to show that individuals are given clear, timely and meaningful information about how their data is being used and what has happened when things go wrong.


Federated Data Platform

The other big story has been that of the Federated Data Platform. This is currently subject to a lot of (mainly negative) press and pressure from various groups. The disputed issues are complex and bigger than data protection alone, which I’ll be following up on as they deserve a post on their own.


Conclusion

None of these themes are new in health data protection. But the first half of the year has shown how quickly familiar issues can become high-profile, high-impact problems, even for large and well-resourced organisations.


The common thread is trust. Access controls matter, but so does staff judgement. Data classification matters, but so does documenting and reviewing the rationale. Transparency matters, not only because the law requires it, but because people rightly expect to understand how their health data is being used.


For health organisations, healthtech companies and research bodies, these challenges will not disappear overnight, but learning from incidents like these reduces the risk going forward for all.

*It should be noted that this case was therefore under EU data protection laws rather than UK, but the learning is still important for those in the UK.

bottom of page