1. What the regulation says
Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)
assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) ... assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity. (Reg 17(2)(a) and (b): quality and risk)
maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)
The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. Where this policy and the regulation diverge, the regulation wins.
2. Plain-English summary
You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request.
3. Purpose
In a single-handed practice the doctor is usually the data controller, and the records sit in one place with one person responsible for them. Good records support safe care and are a legal and professional duty; poor security or a loss of records can harm patients and breach data protection law. This policy sets out how the practice keeps clear clinical records and protects patient information.
The practice must verify this policy against current GMC records guidance and data protection law before adoption.
4. Scope
This policy applies to:
- every clinical record the practice creates and holds, in any form
- the security, sharing, retention and disposal of patient information
- the doctor as data controller and anyone who handles patient information for the practice
5. Roles and responsibilities
- Doctor / Registered Manager: owns the clinical-records system, makes sure records support safe care, signs off the information-governance risk assessment, and reviews audit findings and improvement actions.
- Information Governance Lead: keeps the privacy notice, ICO registration, data map, processor agreements, breach process, subject-access process and retention schedule current. In a very small practice this may be the same person as the doctor, but the responsibility still needs to be named.
- Administrative or clinical support staff: record messages, referrals, results, correspondence and access requests accurately, protect patient information, and report any suspected breach or records error immediately.
- External processors: handle information only under a written agreement and only for the agreed purpose.
6. Clinical records and information-governance procedure
The practice follows this procedure for every patient record and information-governance event:
- Create the record at the point of care. Record the consultation, assessment, decision, advice, consent discussion, prescription, referral, follow-up plan and safety-netting as soon as possible after the event.
- Check the record is usable by another clinician. The entry must be dated, attributable, clear, clinically complete and understandable if another clinician has to continue care.
- Protect the record. Store the record in the approved system or secure paper file. Do not keep live clinical records on unapproved personal devices, private email accounts or unencrypted storage.
- Control access. Give access only to people who need it for their role, remove access when work ends, and review user access on a stated cadence.
- Share information safely. Share only what is necessary, record the lawful basis or consent relied on, and use a secure route.
- Respond to patient rights requests. Log subject-access, rectification and objection requests on receipt, confirm identity, track the statutory response time, and record the outcome.
- Handle errors and breaches. If a record is wrong, correct it by dated amendment without hiding the original entry. If information is lost, exposed or accessed without authority, open a breach record and assess whether ICO or patient notification is required.
- Retain and dispose safely. Keep records for the current minimum retention period and record any secure disposal decision.
- Review system risks. Review backups, restore tests, processor arrangements, privacy notices, access logs and breach themes through governance.
7. Record standards
Records are:
- made at the time of, or as soon as possible after, the consultation
- accurate, legible and clear, recording the history, examination, decisions, advice, consent and what was prescribed or done
- attributable, dated and not altered after the event except by a clear, dated amendment that leaves the original visible
- complete enough that another clinician taking over could understand the care
8. The data controller and registration
- the practice is registered with the Information Commissioner's Office as a data controller and keeps that registration current
- the practice has a lawful basis for processing health data and a clear privacy notice for patients
- where the practice uses any processor (for example a records system or a transcription service), there is a written agreement and the processor meets the required standards
9. Security
Because the records are concentrated in one place, security matters especially:
- access to records is limited to those who need it, controlled and, where possible, auditable
- records and devices are protected (for example by encryption and passwords), and not held on unprotected personal devices
- the practice takes regular, secure backups so records survive the loss, theft or failure of a device, and tests that they can be restored
- paper records are stored securely
10. Sharing information
- patient information is shared only with consent or where the law allows, and only to the extent needed (the Caldicott principle of using the minimum necessary)
- where the practice shares information with the patient's GP or another clinician for the patient's care, it does so securely and records what was shared
- a loss or unauthorised disclosure of patient information is treated as a data breach, contained, recorded, and reported to the Information Commissioner's Office and the patient where the law requires
11. Patient access
The practice responds to a patient's request for access to their own records within the time the law allows, providing the information securely, and helps patients who wish to correct an inaccuracy.
12. Retention and disposal
Records are kept for the period the current guidance sets, stored securely throughout, and disposed of securely when that period ends, with the disposal recorded.
13. Continuity of the records
Because the records depend on one person, the practice plans for the doctor being unavailable: it is clear who can access the records in an emergency, how a patient would get their records or continue care, and what happens to the records if the practice closes (see the scope, indemnity and continuity policy).
14. Records and register links
The clinical-records and information-governance evidence trail should include:
- clinical record entries, amendments and reasons for amendment
- consent, capacity, advice, referral, prescribing and follow-up entries
- privacy notice version, ICO registration record and data map
- processor due-diligence record and signed processor agreement
- access-control review and leavers access removal
- backup and restore-test record
- subject-access and rectification request log
- data-breach record, ICO decision and patient-notification decision
- retention and disposal decision
- audit findings, risk-register entries and improvement actions
Suspected data breaches are handled through the data-breach record and incident register. Repeated record-quality gaps, processor weaknesses, backup failures or overdue access requests are reviewed through the risk register and improvement-actions register.
15. Training and competence
Everyone who handles patient information must complete induction training before accessing records. Training covers record standards, confidentiality, secure sharing, patient access requests, breach reporting, device security, use of the clinical-records system and the practice's local privacy notice. The doctor or Information Governance Lead receives role-specific training on controller duties, breach assessment, retention and processor oversight.
Training records are held in the training matrix. Record-quality findings from audit, complaints, incidents or peer review are fed back through supervision, appraisal or continuing professional development.
16. Audit cadence
The practice checks, on a stated cadence, that:
- records meet the standards above and are contemporaneous and attributable
- ICO registration is current and a lawful basis and privacy notice are in place
- security, backups and tested restoration are in place, and access is controlled
- sharing follows consent and the Caldicott principles, and breaches are reported
- access requests are met on time and retention and disposal follow the guidance
The doctor and the Registered Manager review the results and record the improvement actions that follow.
17. Sources and further reading
This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.
- CQC Regulation 17: Good governance
- UK GDPR and the Data Protection Act 2018 (health data is special category): https://www.legislation.gov.uk/ukpga/2018/12/contents
- Information Commissioner's Office UK GDPR guidance, records and security guidance, data sharing code, and breach reporting tool: https://ico.org.uk/
- NHS Records Management Code of Practice where relevant
- NHS Data Security and Protection Toolkit where applicable
- The Caldicott Principles
- Professional record standards, especially GMC, Good medical practice: https://www.gmc-uk.org/professional-standards/professional-standards-for-doctors/good-medical-practice
- Sector-specific (independent specialist doctor): GMC Good medical practice; GMC remote prescribing and consent guidance; medical indemnity provider guidance; CQC Reg 12 and Reg 17
- Sector-specific (patient data and information governance): UK GDPR; Data Protection Act 2018; NHS Records Management Code of Practice; NHS Data Security and Protection Toolkit; Caldicott principles
- CQC assessment framework and sector-specific guidance, as updated by CQC from time to time
18. Related reading
- Related policy: Personal Data Breach Notification Policy
- Related policy: Record Keeping and Documentation Standards Policy
- Related policy: Good Governance Policy
- Related policy: Scope of practice, indemnity and continuity policy
19. When to seek further advice
Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.
20. Document control
| Version | Date | Author | Changes |
|---|---|---|---|
| v1.1 | 2026-07-12 | Verivius (sample) | Added role ownership, records procedure, evidence fields, register links, training and competence controls, and related reading. Removed stray source artefact tags from the markdown. |
| v1 | 2026-06-10 | Verivius (sample) | Conformed to the Verivius policy standard: statutory anchor, verbatim Regulation 17 quotes and plain-English summary, standard sources and document-control blocks added; original sections preserved and renumbered. |
This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.