Sample policy · Independent specialist doctor

Clinical records and information governance policy (independent specialist doctor)

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). This policy also engages the UK GDPR, the Data Protection Act 2018 and the common law duty of confidentiality. · primary source

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) ... assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity. (Reg 17(2)(a) and (b): quality and risk)

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request.

3. Purpose

In a single-handed practice the doctor is usually the data controller, and the records sit in one place with one person responsible for them. Good records support safe care and are a legal and professional duty; poor security or a loss of records can harm patients and breach data protection law. This policy sets out how the practice keeps clear clinical records and protects patient information.

The practice must verify this policy against current GMC records guidance and data protection law before adoption.

4. Scope

This policy applies to:

5. Roles and responsibilities

6. Clinical records and information-governance procedure

The practice follows this procedure for every patient record and information-governance event:

  1. Create the record at the point of care. Record the consultation, assessment, decision, advice, consent discussion, prescription, referral, follow-up plan and safety-netting as soon as possible after the event.
  2. Check the record is usable by another clinician. The entry must be dated, attributable, clear, clinically complete and understandable if another clinician has to continue care.
  3. Protect the record. Store the record in the approved system or secure paper file. Do not keep live clinical records on unapproved personal devices, private email accounts or unencrypted storage.
  4. Control access. Give access only to people who need it for their role, remove access when work ends, and review user access on a stated cadence.
  5. Share information safely. Share only what is necessary, record the lawful basis or consent relied on, and use a secure route.
  6. Respond to patient rights requests. Log subject-access, rectification and objection requests on receipt, confirm identity, track the statutory response time, and record the outcome.
  7. Handle errors and breaches. If a record is wrong, correct it by dated amendment without hiding the original entry. If information is lost, exposed or accessed without authority, open a breach record and assess whether ICO or patient notification is required.
  8. Retain and dispose safely. Keep records for the current minimum retention period and record any secure disposal decision.
  9. Review system risks. Review backups, restore tests, processor arrangements, privacy notices, access logs and breach themes through governance.

7. Record standards

Records are:

8. The data controller and registration

9. Security

Because the records are concentrated in one place, security matters especially:

10. Sharing information

11. Patient access

The practice responds to a patient's request for access to their own records within the time the law allows, providing the information securely, and helps patients who wish to correct an inaccuracy.

12. Retention and disposal

Records are kept for the period the current guidance sets, stored securely throughout, and disposed of securely when that period ends, with the disposal recorded.

13. Continuity of the records

Because the records depend on one person, the practice plans for the doctor being unavailable: it is clear who can access the records in an emergency, how a patient would get their records or continue care, and what happens to the records if the practice closes (see the scope, indemnity and continuity policy).

14. Records and register links

The clinical-records and information-governance evidence trail should include:

Suspected data breaches are handled through the data-breach record and incident register. Repeated record-quality gaps, processor weaknesses, backup failures or overdue access requests are reviewed through the risk register and improvement-actions register.

15. Training and competence

Everyone who handles patient information must complete induction training before accessing records. Training covers record standards, confidentiality, secure sharing, patient access requests, breach reporting, device security, use of the clinical-records system and the practice's local privacy notice. The doctor or Information Governance Lead receives role-specific training on controller duties, breach assessment, retention and processor oversight.

Training records are held in the training matrix. Record-quality findings from audit, complaints, incidents or peer review are fed back through supervision, appraisal or continuing professional development.

16. Audit cadence

The practice checks, on a stated cadence, that:

The doctor and the Registered Manager review the results and record the improvement actions that follow.

17. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

18. Related reading

19. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

20. Document control

Version Date Author Changes
v1.1 2026-07-12 Verivius (sample) Added role ownership, records procedure, evidence fields, register links, training and competence controls, and related reading. Removed stray source artefact tags from the markdown.
v1 2026-06-10 Verivius (sample) Conformed to the Verivius policy standard: statutory anchor, verbatim Regulation 17 quotes and plain-English summary, standard sources and document-control blocks added; original sections preserved and renumbered.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 10 June 2026