Sample policy · Independent specialist doctor

Clinical records and information governance policy (independent specialist doctor)

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). This policy also engages the UK GDPR, the Data Protection Act 2018 and the common law duty of confidentiality. · primary source

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) ... assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity. (Reg 17(2)(a) and (b): quality and risk)

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request.

3. Purpose

In a single-handed practice the doctor is usually the data controller, and the records sit in one place with one person responsible for them. Good records support safe care and are a legal and professional duty; poor security or a loss of records can harm patients and breach data protection law. This policy sets out how the practice keeps clear clinical records and protects patient information.

The practice must verify this policy against current GMC records guidance and data protection law before adoption.

4. Scope

This policy applies to:

5. Roles and responsibilities

6. Clinical records and information-governance procedure

The practice follows this procedure for every patient record and information-governance event:

  1. Create the record at the point of care. Record the consultation, assessment, decision, advice, consent discussion, prescription, referral, follow-up plan and safety-netting as soon as possible after the event.
  2. Check the record is usable by another clinician. The entry must be dated, attributable, clear, clinically complete and understandable if another clinician has to continue care.
  3. Protect the record. Store the record in the approved system or secure paper file. Do not keep live clinical records on unapproved personal devices, private email accounts or unencrypted storage.
  4. Control access. Give access only to people who need it for their role, remove access when work ends, and review user access on a stated cadence.
  5. Share information safely. Share only what is necessary, record the lawful basis or consent relied on, and use a secure route.
  6. Respond to patient rights requests. Log subject-access, rectification and objection requests on receipt, confirm identity, track the statutory response time, and record the outcome.
  7. Handle errors and breaches. If a record is wrong, correct it by dated amendment without hiding the original entry. If information is lost, exposed or accessed without authority, open a breach record and assess whether ICO or patient notification is required.
  8. Retain and dispose safely. Keep records for the current minimum retention period and record any secure disposal decision.
  9. Review system risks. Review backups, restore tests, processor arrangements, privacy notices, access logs and breach themes through governance.

7. Record standards

Records are:

8. The data controller and registration

9. Security

Because the records are concentrated in one place, security matters especially:

10. Sharing information

11. Patient access

The practice responds to a patient's request for access to their own records within the time the law allows, providing the information securely, and helps patients who wish to correct an inaccuracy.

12. Retention and disposal

Records are kept for the period the current guidance sets, stored securely throughout, and disposed of securely when that period ends, with the disposal recorded.

13. Continuity of the records

Because the records depend on one person, the practice plans for the doctor being unavailable: it is clear who can access the records in an emergency, how a patient would get their records or continue care, and what happens to the records if the practice closes (see the scope, indemnity and continuity policy).

14. Records and register links

The clinical-records and information-governance evidence trail should include:

Suspected data breaches are handled through the data-breach record and incident register. Repeated record-quality gaps, processor weaknesses, backup failures or overdue access requests are reviewed through the risk register and improvement-actions register.

15. Training and competence

Everyone who handles patient information must complete induction training before accessing records. Training covers record standards, confidentiality, secure sharing, patient access requests, breach reporting, device security, use of the clinical-records system and the practice's local privacy notice. The doctor or Information Governance Lead receives role-specific training on controller duties, breach assessment, retention and processor oversight.

Training records are held in the training matrix. Record-quality findings from audit, complaints, incidents or peer review are fed back through supervision, appraisal or continuing professional development.

16. Audit cadence

The practice checks, on a stated cadence, that:

The doctor and the Registered Manager review the results and record the improvement actions that follow.

17. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

18. Related reading

19. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

20. Document control

Version Date Author Changes
v1.1 2026-07-12 Verivius (sample) Added role ownership, records procedure, evidence fields, register links, training and competence controls, and related reading. Removed stray source artefact tags from the markdown.
v1 2026-06-10 Verivius (sample) Conformed to the Verivius policy standard: statutory anchor, verbatim Regulation 17 quotes and plain-English summary, standard sources and document-control blocks added; original sections preserved and renumbered.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

An independent specialist doctor usually sees a patient for a short private episode while the patient's continuing care sits elsewhere, most often with an NHS general practitioner the doctor may never speak to. The record is therefore the only thing carrying the diagnosis, the medicine started, the consent discussion and the follow-up plan across to whoever picks the patient up next, so a thin or late entry is a clinical gap for the next clinician rather than a paperwork gap. The second risk is concentration: one clinician, one laptop, one records system and often one person who knows the passwords, so a stolen device, a failed drive or an unplanned absence can put a whole patient list out of reach at the moment someone needs their results. Patients feel both of these directly. They come back months later expecting the doctor to know what was said, and they judge the service by whether their letter reached their general practitioner and whether their information stayed private. Records that are contemporaneous, attributable, restorable and reachable by a second person are what make this care safe and the practice well led, which is also why they are the part of it an inspector can see.

  1. Records are genuinely contemporaneous and attributable, and any change is made by a dated amendment that leaves the original entry visible, not quietly overwritten. In a single-handed practice the record is the only witness to the consultation, so the entries themselves are what the next clinician, and the patient, have to rely on.

    Strong evidence: Dated, attributable clinical record entries, and the amendment record showing the reason for each amendment with the original still visible (record-standards section and the records-and-register evidence trail).

    Weak evidence: Entries written up in a batch days after the clinic, or a run of consultations all reading "seen, all well, review as needed" with no history, examination, advice or safety-netting recorded. A shared login so no entry is attributable to a named clinician, and corrections typed straight over the original with no date and no reason, so nobody can reconstruct what the record said at the moment the decision was taken.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, reg 17(2)(c)

  2. Backups are actually restored and not merely run. The records sit in one place with one person, so what matters is a proven restore, not just evidence that a backup job exists. An untested backup is discovered to be unusable on the day a patient's record is needed.

    Strong evidence: The backup and restore-test record (security section and evidence trail).

    Weak evidence: A backup schedule, a supplier dashboard screenshot or a line in a contract offered as the proof, with no record that anyone has ever pulled a real patient record back out of a backup and checked it opened and was complete. A restore proven once at installation and never repeated since, or proven only for the clinical system while paper files and the mailbox nobody thinks of as clinical records sit outside the backup altogether.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  3. A loss or unauthorised disclosure is opened as a breach record, with the decision on reporting to the Information Commissioner's Office and the separate decision on telling the patient under Article 34 both written down, not judged in the moment and left undocumented. Reporting to the Information Commissioner does not discharge the decision about telling the patient, and telling the patient does not discharge the report.

    Strong evidence: The data-breach record carrying the Information Commissioner's Office decision and the patient-notification decision (sharing-information and evidence-trail sections).

    Weak evidence: A near miss handled by a quiet phone call: the letter went to the wrong address, the patient was rung, nothing was written down, so there is no breach record, no note of when the practice became aware and no reasoning about whether the Information Commissioner's Office or the patient should have been told. Or a breach log holding only the incidents that were reported, with no entry for those assessed as not reportable, so the decision not to report cannot be seen or defended later.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 33(5), with Articles 33(1) and 34(1)

  4. Information Commissioner's Office registration is current, and there is a documented lawful basis and privacy notice for processing special-category health data, not an assumption that consent covers everything. These duties fall on the practice as data controller whether the care is privately funded or NHS-commissioned, and the privacy notice is the patient's own route to understanding what happens to their health information.

    Strong evidence: The privacy-notice version, the Information Commissioner's Office registration record and the data map (data-controller and evidence-trail sections).

    Weak evidence: A registration with the Information Commissioner's Office that lapsed at the last renewal, or a privacy notice copied from another practice that names services this practice does not provide and points patients at a contact and a data protection officer who have nothing to do with it. A lawful basis recorded as consent for everything, with no separate condition recorded for special-category health data, no written agreement with the transcription supplier, and no data map showing where records, dictation, transcripts and correspondence actually sit, including the private mailbox.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    Data Protection (Charges and Information) Regulations 2018, reg 2; UK GDPR Articles 6(1), 9(2)(h) and 13

  5. Subject-access and rectification requests are logged on receipt and tracked to the statutory response time the law allows, not answered late or informally. A patient asking at reception for a copy of their notes has made the same request as one who writes in.

    Strong evidence: The subject-access and rectification request log (records procedure and evidence trail).

    Weak evidence: Requests answered from memory with no log, so there is no date the request arrived, no date identity was confirmed and no date the information was sent, and the practice cannot show it met the response time the law allows. Or a log holding only formal written requests, while a patient asking at reception for a copy of their notes, or asking for a wrong date of birth to be corrected, is dealt with informally and never counted, so rectification requests appear never to happen.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    UK GDPR Article 12(3), with Articles 15 and 16

Last verified 20 July 2026

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 10 June 2026