Sample policy · Sexual health

Confidentiality in sexual health policy (sexual health)

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). This policy also engages Regulation 12 (safe care and treatment), and rests on the common law duty of confidentiality, the UK GDPR and the Data Protection Act 2018 (under which health and sexual-life data are special category data). · primary source

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

Regulation 12 also applies, because keeping sexual health information secure is part of safe care and treatment:

Care and treatment must be provided in a safe way for service users. (Reg 12(1), the headline duty)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17 and https://www.legislation.gov.uk/uksi/2014/2936/regulation/12. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3, and that includes maintaining securely an accurate, complete and contemporaneous record for each person. In sexual health, the duty to keep information secure is heightened: the fact that someone attended, and what they were seen for, is private, and special-category data protection law applies on top of the common law duty of confidentiality and professional guidance. People will only come forward to be tested and treated if they trust that their attendance and their diagnosis stay private.

3. Purpose

Confidentiality matters in all of healthcare, but in sexual health it is the foundation of the service: people will only come forward to be tested and treated if they trust that their attendance and their diagnosis stay private. This policy sets out the heightened confidentiality the Service applies to sexual health, how it protects identity and records, and the narrow situations where information may be shared.

The Service must verify this policy against current BASHH and GMC confidentiality guidance and data protection law before adoption.

4. Scope

This policy applies to:

5. Heightened confidentiality

The Service treats sexual health information with particular care:

6. Protecting identity and records

7. When information may be shared

Information may be shared without consent only in the narrow situations the law and professional guidance allow, and only to the extent needed. These include:

Where the Service shares information in one of these situations, it records what was shared, with whom and why, and tells the patient unless doing so would increase a risk.

8. Partners and third parties

The Service does not reveal one patient's information to a partner. Partner notification is done in a way that protects the index patient's identity (see the partner notification policy). Where two people attend together, each is offered the chance to be seen alone, and neither is told the other's results without consent.

9. Young people

A young person's confidentiality is respected on the same basis as an adult's, subject to the safeguarding duties and the assessment of competence in the under-18s and safeguarding policy. A young person is told what confidentiality they can expect and the limits of it. Competence to consent to confidential treatment is assessed using Gillick competence and the Fraser guidelines, and any safeguarding concern is handled under Working Together to Safeguard Children 2026 and the local safeguarding children procedures.

Operational controls to adapt

Roles and responsibilities

Confidentiality procedure

  1. Confirm contact preferences at each relevant contact. Record the safe phone, email, text, portal or postal route and whether messages may mention the service.
  2. Ask before sharing with the GP or another service. Do not assume consent to share sexual health attendance, diagnosis or results. Record consent, refusal or the lawful reason for sharing without consent.
  3. Protect front-desk and waiting-area privacy. Use discreet calling, avoid diagnosis labels, and do not discuss sexual health details where others can hear.
  4. Control record access. Access is role-based, auditable and reviewed when staff join, change role or leave.
  5. Handle third-party requests through a named route. Requests from partners, relatives, employers, police, solicitors, insurers or other services are checked before anything is disclosed.
  6. Disclose without consent only when justified. The clinician records the legal or professional basis, what was shared, who received it, why less disclosure was not enough, and whether the patient was told.
  7. Treat accidental disclosure as a serious incident. Any lost message, wrong recipient, overheard disclosure, wrong portal upload or unauthorised access is logged, risk-assessed and escalated to information governance.
  8. Review repeat themes. Repeated contact-preference errors, reception risks, staff-access concerns or disclosure delays are added to the risk register or improvement-actions register.

Records and register links

The confidentiality record should include:

Confidentiality concerns are logged as incidents even where no reportable data breach is confirmed, because the service still needs evidence that the risk was assessed and learned from.

10. Training

Everyone in the Service is trained in confidentiality, including the heightened expectation in sexual health and the narrow disclosure exceptions, at induction and on a refresher cadence. The Service records completion and the next refresher date.

11. Audit cadence

The Service checks, on a stated cadence, that:

The Registered Manager and the clinical lead review the results and record the improvement actions that follow.

12. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

Original sources carried forward from this policy:

Source pack for sexual health confidentiality:

Related reading

13. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

14. Document control

Version Date Author Changes
v1.1 2026-07-14 Verivius (sample) Added role ownership, confidentiality controls, disclosure records, register links and related reading.
v1 2026-06-10 Verivius (sample) Initial sample template, conformed to the Verivius policy standard.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

In sexual health, the sensitive fact is often not the diagnosis but the attendance itself. A voicemail naming the clinic, a full name called across an open waiting area, or a routine letter to a general practitioner can expose someone to a controlling partner, to family, or to consequences at work, and once it has happened the person has no way to undo it. That is why the consent entry and the confirmed contact route in the record are clinical safety information rather than administrative housekeeping: they are the instruction on how to reach this person without causing them harm. There is a public-health edge too, because people who do not trust a service to keep attendance private simply stay away, and infection that is never tested for is never treated. A service that can show who consented to what, which route was actually used, and why any disclosure without consent was justified is a service people can safely come back to.

  1. Attendance and diagnosis reach a GP only on recorded consent that was asked for, not assumed. The failure that matters is a GP letter or summary going out by default, so a person finds out their sexual health attendance reached their practice when nobody ever asked them.

    Strong evidence: Section 5 (attendance and what a person was seen for is not disclosed to anyone, including their GP, without consent, and the person is asked, not assumed); the records field for GP-sharing consent; and the audit-cadence check that attendance and diagnosis are not disclosed, including to GPs, without recorded consent.

    Weak evidence: Weak evidence is a tick-box "general practitioner (GP) sharing: yes" captured by reception on a registration form before the person has spoken to a clinician, or a records system that generates a GP letter by default unless someone actively suppresses it. It is also weak when a run of notes carries identical "consent given" wording, or when a GP summary clearly went out and the consent field is blank.

    The recognised standard from a professional or clinical body, such as NICE or a royal college. Not a legal duty, but the accepted mark of safe practice, and a departure needs a documented reason.
  2. Each disclosure made without consent fits one of the narrow allowed exceptions, and its lawful or professional basis is written down, including why less disclosure would not have been enough and whether the patient was told. The failure that matters is a disclosure with no recorded basis, so the person cannot be told what left the service or why, and the colleague who picks the record up next cannot tell a justified disclosure from a careless one.

    Strong evidence: Procedure step 6 (record the legal or professional basis, what was shared, who received it, why less disclosure was not enough, and whether the patient was told) and the records fields for the lawful basis and public-interest or safeguarding rationale, and whether the patient was told about the disclosure.

    Weak evidence: Weak evidence is a disclosure entry that reads "shared with police" or "safeguarding referral made" and stops there, with no lawful or professional basis named, nothing on why a narrower disclosure would not have been enough, and no note of whether the patient was told or why not. A safeguarding referral to the local authority and a disclosure to the police are separate decisions, and one entry covering both leaves neither basis recorded. It is also weak when the public-interest reasoning appears only later in a supervision note or an email thread rather than in the record at the time of the decision, or when a request from a partner, employer, solicitor or insurer was answered at the front desk without going through the named checking route.

    The recognised standard from a professional or clinical body, such as NICE or a royal college. Not a legal duty, but the accepted mark of safe practice, and a departure needs a documented reason.
  3. Record access is genuinely role-based, auditable and reviewed when staff join, change role or leave, and an access audit is actually run where inappropriate access is suspected. The failure that matters is any member of staff being able to open any record with no trail, so a person who lives or works near the service cannot be told who has seen their notes.

    Strong evidence: Procedure step 4 (access is role-based, auditable and reviewed when staff join, change role or leave); the records field for an access-audit review where there is a concern about inappropriate record access; and the audit-cadence check that records are stored securely with auditable, need-to-know access.

    Weak evidence: Weak evidence is a shared clinical login or a generic reception account that makes the access log meaningless, leavers still active in the system months after their last shift, and no one able to produce a list of who opened a named record when asked. It is also weak when a suspicion of inappropriate access was resolved by asking the staff member rather than by pulling and reviewing the audit trail.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  4. The confirmed safe contact route is the one actually used, and reception practice does not reveal that a person has attended, not just that a policy says so. The failure that matters is a voicemail or text naming the service left on a shared or unsafe route, which can reveal a person's attendance to a partner or a family member at home.

    Strong evidence: Procedure steps 1 and 3 (confirm the safe route and whether messages may mention the service; use discreet calling and avoid diagnosis labels); the records field for contact preferences and any limits on voicemail, text message, email, portal or postal communication; and the audit-cadence check that contact and reception practice protects patients' identity.

    Weak evidence: Weak evidence is a contact preference captured once at registration and never revisited, or a note saying "happy for texts" with nothing on whether a message may name the service. It is also weak when the record shows the preference but not which route was actually used, when results messages come from a number or sender name that identifies the clinic, or when reception calls people by full name and reason for attendance across an open waiting area.

    The recognised standard from a professional or clinical body, such as NICE or a royal college. Not a legal duty, but the accepted mark of safe practice, and a departure needs a documented reason.
  5. Accidental disclosures are logged as incidents and risk-assessed even where no reportable data breach is confirmed, with breach triage recorded and the decision on reporting to the Information Commissioner's Office (ICO) kept distinct from the decision on telling the person affected, because neither stands in for the other. The failure that matters is an overheard disclosure or wrong-recipient message that was never logged, so nobody can show the risk to that person was ever assessed.

    Strong evidence: Procedure step 7 and the policy's note that confidentiality concerns are logged as incidents even where no reportable data breach is confirmed, plus the records field for breach triage, ICO decision, patient-notification decision and mitigation.

    Weak evidence: Weak evidence is an overheard conversation, a wrong-recipient message or a results letter to an old address that was dealt with by an apology at the time and never reached the incident log, so there is no trail that the risk was assessed. It is also weak when "not reportable" is written with no record of who decided, on what facts, whether the Information Commissioner's Office threshold was considered, or whether the patient was told.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.

Last verified 20 July 2026

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 10 June 2026