Whenever we go to a doctor or a hospital, they collect data about us, our health and our lifestyle. This is recorded and stored in our patient record. It may include our height and weight, whether we smoke, how much we drink, detail of any allergies, what aches, pains or infections we’ve got, and what medications we are taking. It may also include the results of blood tests, images from MRI scans, and any procedures we’ve had, together with contact information, date of birth, and next of kin information.  

Other specialists we see, for example dentists, physiotherapists and psychologists, will also create records. 

The NHS uses this information to help provide the best clinical care for us. Because a patient record contains sensitive information about our health, it must be handled very carefully and accessed safely and securely, to protect confidentiality.

Other types of health data include information collected during clinical trials and cohort studies or data generated by you; for example, health apps, fitness trackers or patient surveys.

Everyone in England should be able to access summary information from their GP records online. However, the number of people using this system is low, and the information that is available varies between different GP practices. If you want to access your health records online, speak to reception at your GP practice.

At the moment, very few people have online access to hospital records. The Government has committed that by April 2018 everyone will have access to an online personal health record that includes information from all of their health and care interactions. This is an important goal that will help us feel empowered to manage our care better.

Read how patient access to their medical records has transformed care from a patient's perspective and GP's perspective

You can find out more here:

The most important information in your patient record is also stored in a central ‘Summary Care Record’ (SCR). This means that if anything happens to you when you’re away from your usual GP surgery, for example in an emergency or when you’re on holiday, other healthcare professionals can access vital information so they can give you better and safer care.

The SCR includes data about:

  • current medicines
  • allergies and details of any previous bad reactions to medicines
  • your name, address, date of birth and NHS number.

You can also choose to include additional information in your SCR, including any long-term conditions, like diabetes or dementia; details of your carer; and your treatment preferences.

NHS staff have to ask your permission to look at your SCR for your individual care (except in an emergency where you are unconscious, for example).  Most pharmacists can also now access SCRs, but again only if you say it’s OK.

Find out more about Summary Care Records.

Good quality information is essential to inform our clinical care. Everyone should have access to information about their own healthcare, to check the information is accurate and to help manage any condition. Your whole care team, whether in a GP practice, a hospital or a care home, needs to have access to up-to-date information about you to inform your treatment, and to provide the best care.

In addition, if small amounts of data from many patients are linked up and pooled, researchers and doctors can look for patterns in the data, helping them develop new ways of predicting or diagnosing illness, and identify ways to improve clinical care. The information from patient records is really valuable to help understand more about disease, to develop new treatments, to monitor safety, to plan services and to evaluate NHS policy. 

Find out more about why patient data is used

Do the benefits of using patient data outweigh the risks? Could something go wrong, and what would be the impact? What are the consequences of not using data? 

Sharing patient data will never be totally risk-free, but there must be appropriate measures in place to make any risks as low as reasonably possible. Data is anonymised wherever possible. There are audit processes to check who is accessing data, and there are robust penalties where data is misused.

Currently, most of the ‘data breaches’ in the health sector occur when information is accidentally posted, faxed or emailed to the wrong person. Surveys suggest that there are three main things people are concerned about:

  • invasion of privacy, or information about medical history being revealed to others;
  • loss of control if data is passed outside the NHS;
  • the possibility of cyberattacks or hacking.

Find out more about each of these issues, and what is being done to reduce the risks and protect data here.

It is essential that patient data is kept safe and secure, to protect your confidential information. 

There are four ways that privacy is protected:

  • by removing identifying information, particularly your name and contact details
  • using an independent review process to make sure the reason for using patient data is appropriate
  • ensuring strict legal contracts are in place before data is transferred
  • implementing robust IT security.​​​​​​

Safeguards explainer

People want to know whether they could be identified when data about them is used. There are different levels of identifiability which sit on a spectrum.  

Full spectrum

At one end of the spectrum, a person is fully identifiable. As you remove or encrypt information, you blur the image more and more, and it becomes more difficult to identify who that person is. At the other end of the spectrum, it is not possible to identify who someone is — they are effectively anonymous. Different controls are needed at different points along the spectrum depending on the risk of re-identification. The controls that are taken to protect the data are just as important as the data itself. It may also be possible to work out who someone is by joining together information from different sources — like joining together different pieces of a jigsaw puzzle.

Identifiability explainer

This data glossary, produced by Connected Health Cities, also clarifies other technical terms around patient data. 

There are strict rules on what’s allowed and not allowed depending on how identifiable the data is.

Personally identifiable information: you will usually be asked to give explicit consent for personally identifiable data to be used for purposes other than your individual care. For example, you would have to give consent for personally identifiable data to be used in a specific research or cohort study.

Personally identifiable information will always be stored in a highly secure way and there are sanctions under the Data Protection Act if personally identifiable data is misused. It can only be used if you give your permission or where required by law, and then only with robust safeguards. There are some occasions where the law allows the data to be used without consent, for example:

  • Notification of infectious diseases and food poisoning.
  • NHS fraud investigations.
  • Investigations by regulators of professionals (eg General Medical Council investigating a registered doctor’s fitness to practice).
  • Information must be provided to the police for road traffic offences and to prevent an act of terrorism.
  • Termination of pregnancy must be notified to the Chief Medical Officer (reference number, date of birth and postcode).
  • Notification of cancer to cancer registries.
  • NHS Digital (which has responsibility for collecting and publishing data and information from across the health and social care system in England) has the power to collect information from health and social care organisations as set out in the Health and Social Care Act 2012.
  • Section 251 of the NHS Act 2006 allows identifiable information to be used for research and other medical purposes without consent where the use is in the public interest but it would not be practical to seek consent because of very large numbers of people involved or where it may cause harm and distress. In these unusual cases, the research must first be approved by the Confidentiality Advisory Group of the Health Research Authority.

You can find out more here:

De-personalised information: there are strict safeguards on how de-personalised information can be used, because there is the potential that it might be possible to re-identify someone. The higher the possibility of re-identification, the greater the level of control needed. Provided the data is anonymised in line with the ICO code of anonymisation, it can be used without consent.

Anonymous information: because it would not be possible to identify someone, anonymous information does not need special protection and can be published openly. Provided the data is anonymised in line with the ICO code of anonymisation, it can be used without consent.

A new national data opt-out was introduced in May 2018, following recommendations from the National Data Guardian. People can opt out of having their confidential patient information shared for reasons beyond their individual care, for example for research and planning.

Find out more about the national data opt-out.

Researchers use patient data to help us to understand more about disease, develop new treatments, monitor safety, plan services and evaluate NHS policies. This kind of research is vital to improve health and care for everyone.

Data about patients is held in many datasets, including:

  • GP records
  • Clinical audits eg National diabetes audit
  • Disease registers eg Cancer register
  • Hospital Episode Statistics
  • Diagnostic imaging datasets
  • Prescribing databases
  • Commission reporting and evaluation
  • Patient surveys eg Patient Reported Outcome Measures (PROMs).

Researchers apply to access data from several sources, including the Clinical Practice Research DatalinkNHS Digital and Public Health England. There are also tools available, such as the Health Data Finder for research, which help researchers look for relevant datasets.   

Before a researcher is granted access, their study must be assessed by an independent review committee, who check that the reason for using the data is appropriate. Wherever possible data will be anonymised, and researchers should only be given the minimum amount necessary to answer a question. Data must be stored securely, and a legal contract must be signed before data can be transferred.

Often a study will need to use data about an individual that is held in more than one dataset. When this happens, a trusted third party, usually NHS Digital, links the data using a unique identifier (such as NHS number which is then removed) to make sure the researcher cannot re-identify individuals.

You can find more examples of what data is used by researchers in our case studies. The video below answers questions about how patient data is used by university researchers. 

 Video produced by Connected Health Cities and The Farr Institute. 

Many people are uncomfortable with the idea of companies accessing health information. Find out why commercial organisations might need to use data, how the NHS works in partnership with companies, and the safeguards that are in place to protect your privacy.

  • Companies are involved in many ways in the delivery of care and research across the NHS, but there are strict controls on how companies can use patient data, to protect your privacy.
  • Personally identifiable patient data can only be used if there is a health benefit.
  • The NHS will never share your personally identifiable data for marketing or insurance purposes (unless you specifically say that it is OK).

Find out more about companies accessing patient data.

NHS Digital is responsible for collecting data from across the health and social care system, including from GPs and hospitals. NHS Digital also provides specialist skills and expertise to analyse the information, and publish insights to inform NHS services and research. NHS Digital helps support national IT services, and is the central access point for data across the NHS.

NHS Digital collects and stores data from a wide range of providers across England including hospitals and general practices. Information includes:

  • Information from General Practice collected under the Quality and Outcomes Framework
  • Clinical audits
  • Hospital Episode Statistics
  • NHS Blood and Organ Donor Register system
  • Prescribing databases
  • Information about vaccination programmes
  • Maternity datasets.

NHS Digital, the central repository of NHS information, is not allowed to sell data for profit but operates on a cost recovery basis. It is allowed to charge for the cost of processing and delivering the service, but not for data itself. The charge depends on the type of application, amount of data requested, and the amount of work that NHS Digital will need to do.

Individual NHS Trusts will enter into different arrangements when working in partnership with companies, depending on their requirements and the services that are offered.  

As new digital technologies develop, we are beginning to understand more about the value of data. While people may feel uncomfortable with the idea of the NHS ‘selling’ data, there would also be concerns if valuable data is given away to companies for free. There needs to be much more discussion about how the NHS and patients can benefit from the unique resource of NHS data. For example, if patient data is used to develop a new algorithm, should the NHS get access to that service at a reduced rate? Should the NHS be able to make a profit from commercial access to data? 

Information from every hospital is collected by NHS Digital each month, and added to the Hospital Episode Statistics (HES). HES is a database that includes records of all patients admitted to NHS hospitals in England. It contains details of inpatient care, outpatient appointments and A&E attendance records. HES data can be used to monitor trends and patterns in hospital activity, assess the delivery of care and support local service planning.  The information is also used to pay hospitals for the care they provide.

An HES record is created for each ‘episode’ of care a patient receives in an NHS hospital (or delivered in the independent sector but commissioned by the NHS). It will include a range of information about you, including:

  • clinical information about diagnoses and operations
  • demographic information, for example age group, gender and ethnicity
  • administrative information, for example time waited, date of admission and discharge
  • geographical information, for example the area where the patient lives.

Last year, 125 million records were added to the HES database.

The National Cancer Registration and Analysis Service, which is part of Public Health England, collects information about every cancer patient in England.  This is important to help understand cancer better, and to make sure that people living with cancer receive the best possible care and support.

The Cancer Registry includes information about the numbers and types of cancers across England, how this varies and is changing over time. Collecting data on all cancers across England helps the NHS to plan cancer services; track cancer rates; to make decisions about NHS facilities and services; compare survival statistics with other countries; improve and ensure the safety of the national cancer screening programmes; and help doctors find the most effective treatments. 

The information includes data about the patient and their tumour, collected from screening clinics, X-rays and pathology labs and from the patient’s care team. 

In May 2018, three regions were awarded national investment to become best practice exemplars for integrated local health and care records (LCHRE). LHCRE will demonstrate how information can be shared safely and securely, and for what purposes, across different places of care within a region but for a large number of people (in the millions).

The exemplars are focusing on sharing health and care records to improve individual care for those living in their area. So regardless of where an individual is receiving care and support (at their GP, hospital, community hospital or even at home), the health and care professionals looking after then can access the right information, at the right time. The exemplars will help create better data sharing between:

  • different places of care (healthcare, mental health, social care services etc)
  • health and care professionals supporting an individual (eg GPs, nurses, social care workers, pharmacists etc)
  • individuals and those involved in their care.

Find out more here.