You mention OH but mention a request to get a GP report, is it Oh requesting this? Or your manager.
For clarity, Occupational Health could speak to you first as a referral / discussion with an OH nurse, reviewing how you are, diagnosis, prognosis and recommendations, OR, Occ Health could be the ones to write to your GP, to gain an opinion on your health, diagnosis, prognosis etc. OR, it could be a combination of both of the above.
Consent to access medical records should only be “relevant”, so requesting ‘everything’ is unlikely, but more importantly, unnecessary.
Your information, as you rightly say, “sensitive data” (under GDPR, medical info is classified as sensitive therefore needs consent) must be protected carefully by the business and OH. Given that you have prior history and concerns, I would formally write back to the business stipulating what exactly you’re consenting to.
I would personally suggest:
-
request what specific information they would like from your GP. You may be able to provide them with that information. Might be requesting the form or referal letter they are providing your GP too. It’ll be useful to see this prior to you consenting.
-
consent only to the specific health issue that is relevant; eg. This illness, dating back no more than X years (2 maybe?), nothing more.
-
request that only an independent Occ Health company are allowed to request the report from your GP, not the business directly. This would add a layer of independence. OH should be pretty hot on GDPR etc and a decent OH would then receive the info from your GP, and can compile a report based on it (so the company wouldn’t then see the actual GP report)
-
finally, consent only with the option to view the report prior to the sending to the OH provider/business. The Medical Records Act gives you this option, many don’t utilise it but I would. You can then book an appointment with your GP and more or less stipulate what you want to be put into the report. A good GP (or medical secretary) will work with you to only put in what is required.
Summary, GP reports are normally not worth the paper they’re written on or the cost charged to a business. OH reports are far more useful for both the employee, and the business eg recommendations, advice etc It honestly depends on how good the HR team and OH work together. I’ve always worked well with our OH to ensure the employee is fully supported by OH, however I know of businesses who use OH to help them rather than the employee, and that’s where trust is questioned and things turn sour.