Sample policy · Sexual health

Confidentiality in sexual health policy (sexual health)

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). This policy also engages Regulation 12 (safe care and treatment), and rests on the common law duty of confidentiality, the UK GDPR and the Data Protection Act 2018 (under which health and sexual-life data are special category data). · primary source

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

Regulation 12 also applies, because keeping sexual health information secure is part of safe care and treatment:

Care and treatment must be provided in a safe way for service users. (Reg 12(1), the headline duty)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17 and https://www.legislation.gov.uk/uksi/2014/2936/regulation/12. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3, and that includes maintaining securely an accurate, complete and contemporaneous record for each person. In sexual health, the duty to keep information secure is heightened: the fact that someone attended, and what they were seen for, is private, and special-category data protection law applies on top of the common law duty of confidentiality and professional guidance. People will only come forward to be tested and treated if they trust that their attendance and their diagnosis stay private.

3. Purpose

Confidentiality matters in all of healthcare, but in sexual health it is the foundation of the service: people will only come forward to be tested and treated if they trust that their attendance and their diagnosis stay private. This policy sets out the heightened confidentiality the Service applies to sexual health, how it protects identity and records, and the narrow situations where information may be shared.

The Service must verify this policy against current BASHH and GMC confidentiality guidance and data protection law before adoption.

4. Scope

This policy applies to:

5. Heightened confidentiality

The Service treats sexual health information with particular care:

6. Protecting identity and records

7. When information may be shared

Information may be shared without consent only in the narrow situations the law and professional guidance allow, and only to the extent needed. These include:

Where the Service shares information in one of these situations, it records what was shared, with whom and why, and tells the patient unless doing so would increase a risk.

8. Partners and third parties

The Service does not reveal one patient's information to a partner. Partner notification is done in a way that protects the index patient's identity (see the partner notification policy). Where two people attend together, each is offered the chance to be seen alone, and neither is told the other's results without consent.

9. Young people

A young person's confidentiality is respected on the same basis as an adult's, subject to the safeguarding duties and the assessment of competence in the under-18s and safeguarding policy. A young person is told what confidentiality they can expect and the limits of it. Competence to consent to confidential treatment is assessed using Gillick competence and the Fraser guidelines, and any safeguarding concern is handled under Working Together to Safeguard Children 2026 and the local safeguarding children procedures.

Operational controls to adapt

Roles and responsibilities

Confidentiality procedure

  1. Confirm contact preferences at each relevant contact. Record the safe phone, email, text, portal or postal route and whether messages may mention the service.
  2. Ask before sharing with the GP or another service. Do not assume consent to share sexual health attendance, diagnosis or results. Record consent, refusal or the lawful reason for sharing without consent.
  3. Protect front-desk and waiting-area privacy. Use discreet calling, avoid diagnosis labels, and do not discuss sexual health details where others can hear.
  4. Control record access. Access is role-based, auditable and reviewed when staff join, change role or leave.
  5. Handle third-party requests through a named route. Requests from partners, relatives, employers, police, solicitors, insurers or other services are checked before anything is disclosed.
  6. Disclose without consent only when justified. The clinician records the legal or professional basis, what was shared, who received it, why less disclosure was not enough, and whether the patient was told.
  7. Treat accidental disclosure as a serious incident. Any lost message, wrong recipient, overheard disclosure, wrong portal upload or unauthorised access is logged, risk-assessed and escalated to information governance.
  8. Review repeat themes. Repeated contact-preference errors, reception risks, staff-access concerns or disclosure delays are added to the risk register or improvement-actions register.

Records and register links

The confidentiality record should include:

Confidentiality concerns are logged as incidents even where no reportable data breach is confirmed, because the service still needs evidence that the risk was assessed and learned from.

10. Training

Everyone in the Service is trained in confidentiality, including the heightened expectation in sexual health and the narrow disclosure exceptions, at induction and on a refresher cadence. The Service records completion and the next refresher date.

11. Audit cadence

The Service checks, on a stated cadence, that:

The Registered Manager and the clinical lead review the results and record the improvement actions that follow.

12. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

Original sources carried forward from this policy:

Source pack for sexual health confidentiality:

Related reading

13. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

14. Document control

Version Date Author Changes
v1.1 2026-07-14 Verivius (sample) Added role ownership, confidentiality controls, disclosure records, register links and related reading.
v1 2026-06-10 Verivius (sample) Initial sample template, conformed to the Verivius policy standard.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 10 June 2026