Please or to access all these features

AIBU?

Share your dilemmas and get honest opinions from other Mumsnetters.

What would you do if you got a copy of someone else’s confidential GP records

230 replies

Twinkletoesandspaghettios · 09/05/2026 23:09

No poll just wondering exactly what you would do?

The summary care report was in with mine and had name, address, DOB, full medical history including details on social services and CAMHS involvement

OP posts:
New posts on this thread. Refresh page
Holdonforsummer · 16/05/2026 17:56

Yes but you’re not the one whose data was breached? They will be following up with that person, not you.

weirdshape · 11/05/2026 06:40

AllTheChaos · 10/05/2026 22:45

They will have acted, they just may be not have done what you expected. It organisation had something like this happen the ICO would be looking at how and why the breach happened. If staff training was inadequate say, or the policies were poor or not followed properly, the ICO would expect us to detail what we were going to do to improve matters, and for us to then show within an agreed timescale that these changes had been made. You wouldn’t be aware of any of this though.

No, they havent acted. They logged it, gave me a reference number and that was it. They never followed up with me which is what they are SUPPOSED to do, never updated me, when I rang them multiple times they still said they hadn't processed it.

If they wont act on something as serious as this why are you so convinced they are massively efficient:

Statistics and court cases tell one side of the ICO’s decline. But behind every complaint or breach lies a human story – often one of profound harm made worse by the ICO’s inaction. Perhaps the most chilling example is an incident described in a previous Legal Lens report: a woman who was raped, and whose attack was captured on CCTV . Both the police and a car park owner held video evidence of her being dragged into a car by the attacker. Yet, disturbingly, this crucial footage was never turned over to the victim. When she exercised her data rights by filing a Subject Access Request (SAR) to obtain the CCTV of her own assault, her request was rejected. She then turned to the ICO – the very body tasked with enforcing individuals’ right to access their personal data. The ICO was presented with this blatant violation of the law and a plea for help in a situation with life-altering stakes. And it did nothing. The ICO failed to issue any enforcement order or sanction, effectively allowing authorities to suppress evidence of a rape and leaving the victim with no recourse . Justice was not just delayed; it was flat-out denied.

This is not an isolated anecdote. Every unresolved complaint of a data breach, every ignored subject access request, represents a person potentially denied their rights – sometimes in situations of serious wrongdoing or abuse. Whistleblowers have reported employer data deletions, victims of hacking have sought help, employees have faced blacklisting – and too often, the ICO’s response is a form letter or deafening silence. In that silence, wrongdoers find impunity. As I argued back in January, “the ICO isn’t just failing to protect the public; it’s actively enabling wrongdoing by refusing to act.” When organisations learn that Britain’s data regulator will likely do nothing even when faced with egregious violations, it creates a perverse incentive: break the law, ignore individuals’ rights, and chances are you’ll get away with it.

You can carry on believing the ICO are everyone's knights in shining armour but I sincerely hope you never need them one day because if you do, you're on your own!

LeftieRightsHoarder · 10/05/2026 23:16

I received a letter once from our local hospital, which I opened and read at once because I was expecting one. I soon realised it was for an elderly man who was having cancer treatment.

It was about his chemotherapy appointments so it needed urgent action.
I rang the hospital department and left a voicemail message, emailed them a copy of the letter, and rang the GP named in the letter. It had the patient’s address on it, so I think I also posted it to him — hope I did, but can’t remember all the details as this was years ago.

I’ve found that the NHS is often let down by its clerical staff. Apparently, at our hospital at least, it’s all contracted out, and subcontracted. Sneaky privatisation by the back door, at great expense and inconvenience to the NHS.

AllTheChaos · 10/05/2026 22:45

weirdshape · 10/05/2026 08:05

The ICO is useless and I dont even see the point of them. I reported a major breach of my father's data - the NHS "lost" the last 6 months of his medical notes before he died and I reported it to ICO. They did nothing. All they did was give me a reference number and I never heard anything from them again, despite me badgering them about it.

Ive also reported other things- never heard anything back.

I really dont see the point of them if they arent going to act.

They will have acted, they just may be not have done what you expected. It organisation had something like this happen the ICO would be looking at how and why the breach happened. If staff training was inadequate say, or the policies were poor or not followed properly, the ICO would expect us to detail what we were going to do to improve matters, and for us to then show within an agreed timescale that these changes had been made. You wouldn’t be aware of any of this though.

AllTheChaos · 10/05/2026 22:40

Su1rlie · 10/05/2026 07:42

I can’t believe I’m reading posts like this! It’s massive breech and they would be interested. Those working in education and public services do data training every year for this very reason. Things like this absolutely should not happen. I’d be beyond livid if those were my notes. The patient deserves to be told and it definitely needs to be reported.

Sorry to say but it’s really not a massive breach! It was one person, and no harm or disbenefit to them can be demonstrated. Now the time that the MoD left a load of old style computers in a decommissioned office, and they were nicked, and turned out to have the details of all the Muslim applicants to the armed forces (names,
home addresses etc), putting them at risk of attack, that was more in line with ‘major breach’ standards.

AllTheChaos · 10/05/2026 22:31

StrictlyCoffee · 10/05/2026 00:50

A £50k loan written off AND compensation!

Wonder what the other guy got?

The tale about them doing it because they’d have got hammered by ICO makes no sense as that could still have happened anyway. You can’t buy people off reporting data breaches.

Also if this really was in “pre-digital days” (which the reference to emails suggests was not the case!), if it was before the GDPR came into force the maximum fine was pocket change to the banks.

MrsBennetsPoorNervesAreBack · 10/05/2026 20:07

bigboykitty · 10/05/2026 20:07

Thanks, I haven't.

We can agree to differ.

bigboykitty · 10/05/2026 20:07

MrsBennetsPoorNervesAreBack · 10/05/2026 19:46

That's the section I was looking at. I think you've misunderstood it tbh.

Thanks, I haven't.

Sincerely24 · 10/05/2026 20:00

I had this once. It was important test results for someone else enclosed in a letter that was for me. I phoned the surgery to let them know I had received it and so they still needed to tell the correct person their test results (relating to cancer pathway so important). I shredded the letter. I don’t know if they reported themselves for gdpr breach or not.

5128gap · 10/05/2026 19:57

Well ideally I'd like to think once I saw someone else's name I'd not read any further, thus avoiding colluding with a GDPR breech. However, I'm human and in reality I suppose I'd have read more than I should have.
I'd contact the surgery straight away and tell them what had happened. They should then make arrangements to have the paperwork returned to them. As there is special category data they'd need to report to the OIC and there's a remote possibility you could be contacted as part of an investigation.

MrsBennetsPoorNervesAreBack · 10/05/2026 19:46

bigboykitty · 10/05/2026 19:25

It's regulation 20 of the Health and Social Care Act. It's not specific to data breaches and I didn't say it was. It's about responsibility to patients when things go wrong and it includes data and confidentiality breaches. If you have any more questions, please feel free to do some research of your own because I've done more than enough explaining.

That's the section I was looking at. I think you've misunderstood it tbh.

bigboykitty · 10/05/2026 19:25

It's regulation 20 of the Health and Social Care Act. It's not specific to data breaches and I didn't say it was. It's about responsibility to patients when things go wrong and it includes data and confidentiality breaches. If you have any more questions, please feel free to do some research of your own because I've done more than enough explaining.

MrsBennetsPoorNervesAreBack · 10/05/2026 19:14

bigboykitty · 10/05/2026 18:46

It's not just an NHS policy! It's a legal requirement under the Health and Social Care Act. GDPR is not the only legislation that's relevant here.

Can you quote the relevant legislation which states that all data breaches must be reported to the data subject regardless of the risk assessment? Because my quick Google states that the duty of candour would apply when a "notifiable safety incident" occurs, which includes serious data breaches causing or potentially causing significant harm. Which seems to imply that it would be dependant on the risk assessment, as previously stated.

Happy to be corrected if you can point to the relevant section in the legislation.

bigboykitty · 10/05/2026 18:46

MrsBennetsPoorNervesAreBack · 10/05/2026 18:19

That may well be NHS policy. However, a pp mentioned that it was a legal requirement to report the breach to the ICO and to inform the data subject. Some of us are merely clarifying that the legal position is more nuanced than this, and it would depend on the risk assessment in this particular case.

Of course, if NHS policy specifies requirements which are over and above what is required by the law, then NHS staff should obviously adhere to their employer's policies.

It's not just an NHS policy! It's a legal requirement under the Health and Social Care Act. GDPR is not the only legislation that's relevant here.

MrsBennetsPoorNervesAreBack · 10/05/2026 18:19

bigboykitty · 10/05/2026 18:10

It is an NHS requirement. It's obligatory to consider duty of candour. The example IS an NHS situation.

That may well be NHS policy. However, a pp mentioned that it was a legal requirement to report the breach to the ICO and to inform the data subject. Some of us are merely clarifying that the legal position is more nuanced than this, and it would depend on the risk assessment in this particular case.

Of course, if NHS policy specifies requirements which are over and above what is required by the law, then NHS staff should obviously adhere to their employer's policies.

bigboykitty · 10/05/2026 18:10

Dazedanddiscombobulated · 10/05/2026 17:18

It might be an NHS policy requirement, but it’s not an absolute requirement under GDPR law/regulation - it’s as @Snorerephron and @MrsBennetsPoorNervesAreBack say.

It is an NHS requirement. It's obligatory to consider duty of candour. The example IS an NHS situation.

Snorerephron · 10/05/2026 17:59

Doctor1988 · 10/05/2026 17:38

In this context, in an NHS GP surgery, they would have to tell the patient.

That's interesting. I know there are ICO decisions that make it clear, for instance, that a pharmacy wouldn't have to in these circumstances

MrsBennetsPoorNervesAreBack · 10/05/2026 17:55

Doctor1988 · 10/05/2026 17:38

In this context, in an NHS GP surgery, they would have to tell the patient.

That may well be NHS policy. The legal requirement to notify the data subject would depend on the risk assessment though.

Doctor1988 · 10/05/2026 17:38

Dazedanddiscombobulated · 10/05/2026 17:18

It might be an NHS policy requirement, but it’s not an absolute requirement under GDPR law/regulation - it’s as @Snorerephron and @MrsBennetsPoorNervesAreBack say.

In this context, in an NHS GP surgery, they would have to tell the patient.

Dazedanddiscombobulated · 10/05/2026 17:18

bigboykitty · 10/05/2026 17:08

No. They would need to tell the patient. It's a requirement in this specific situation.

It might be an NHS policy requirement, but it’s not an absolute requirement under GDPR law/regulation - it’s as @Snorerephron and @MrsBennetsPoorNervesAreBack say.

bigboykitty · 10/05/2026 17:08

MrsBennetsPoorNervesAreBack · 10/05/2026 16:31

Quite possibly, but it would depend on their assessment of the risk.

No. They would need to tell the patient. It's a requirement in this specific situation.

Snorerephron · 10/05/2026 17:06

bigboykitty · 10/05/2026 16:07

If you work in the NHS, this is completely unethical behaviour. There is a Duty of Candour and the patient absolutely has a right to know.

I don't work in the NHS. I am very familiar with the ICO guidance though

Snorerephron · 10/05/2026 17:04

Doctor1988 · 10/05/2026 16:29

In this context they will need to tell the patient.

Not necessarily no. The ICO guidance is clear that it should be an assessment balancing the harms before deciding whether or not to disclose.

WonsWoo · 10/05/2026 16:32

Twinkletoesandspaghettios · 09/05/2026 23:15

If something of this level of confidential information was given out from your team, would you report it to the Information Commissioner's office?

Where I work we would have to report ourselves to the ICO and we would also have to notify the person whose record had been shared. There would be a full significant event investigation, report and learning session.

MrsBennetsPoorNervesAreBack · 10/05/2026 16:31

Doctor1988 · 10/05/2026 16:29

In this context they will need to tell the patient.

Quite possibly, but it would depend on their assessment of the risk.

Swipe left for the next trending thread