1. What the regulation says
Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)
maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)
Regulation 12 also applies, because keeping sexual health information secure is part of safe care and treatment:
Care and treatment must be provided in a safe way for service users. (Reg 12(1), the headline duty)
The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17 and https://www.legislation.gov.uk/uksi/2014/2936/regulation/12. Where this policy and the regulation diverge, the regulation wins.
2. Plain-English summary
You have to run effective systems and processes to comply with everything else in Part 3, and that includes maintaining securely an accurate, complete and contemporaneous record for each person. In sexual health, the duty to keep information secure is heightened: the fact that someone attended, and what they were seen for, is private, and special-category data protection law applies on top of the common law duty of confidentiality and professional guidance. People will only come forward to be tested and treated if they trust that their attendance and their diagnosis stay private.
3. Purpose
Confidentiality matters in all of healthcare, but in sexual health it is the foundation of the service: people will only come forward to be tested and treated if they trust that their attendance and their diagnosis stay private. This policy sets out the heightened confidentiality the Service applies to sexual health, how it protects identity and records, and the narrow situations where information may be shared.
The Service must verify this policy against current BASHH and GMC confidentiality guidance and data protection law before adoption.
4. Scope
This policy applies to:
- all information about a person's attendance, testing, diagnosis and treatment in sexual health
- the records, the premises and the conversations of the Service
- everyone who works in or for the Service, clinical and non-clinical
5. Heightened confidentiality
The Service treats sexual health information with particular care:
- the fact that a person has attended, and what they were seen for, is not disclosed to anyone, including their GP, without the person's consent, except in the narrow situations in this policy
- the person is asked, not assumed, whether information may be shared with their GP or others, and that choice is recorded and respected
- staff do not discuss a patient where they can be overheard, and do not look at records they have no need to see
6. Protecting identity and records
- records are stored securely with access limited to those who need it for the person's care, and access is auditable
- the Service is careful with names in waiting and reception areas, with messages, and with any contact it makes, so that attendance is not revealed to family, partners or others
- the Service confirms how the person wishes to be contacted, and uses only that method
- the loss or exposure of sexual health information is treated as a serious data breach and reported at once
7. When information may be shared
Information may be shared without consent only in the narrow situations the law and professional guidance allow, and only to the extent needed. These include:
- a safeguarding concern about a child or an adult at risk (see the under-18s and safeguarding policy)
- a serious risk to the patient or another identifiable person, weighed in the public interest
- a legal requirement, such as a notifiable infection or a court order
Where the Service shares information in one of these situations, it records what was shared, with whom and why, and tells the patient unless doing so would increase a risk.
8. Partners and third parties
The Service does not reveal one patient's information to a partner. Partner notification is done in a way that protects the index patient's identity (see the partner notification policy). Where two people attend together, each is offered the chance to be seen alone, and neither is told the other's results without consent.
9. Young people
A young person's confidentiality is respected on the same basis as an adult's, subject to the safeguarding duties and the assessment of competence in the under-18s and safeguarding policy. A young person is told what confidentiality they can expect and the limits of it. Competence to consent to confidential treatment is assessed using Gillick competence and the Fraser guidelines, and any safeguarding concern is handled under Working Together to Safeguard Children 2026 and the local safeguarding children procedures.
Operational controls to adapt
Roles and responsibilities
- Registered Manager: owns confidentiality controls, makes sure staff complete training, and reviews confidentiality incidents, complaints and audit findings.
- Clinical lead: sets the clinical disclosure thresholds, supports difficult public-interest decisions, and checks that safeguarding disclosures are proportionate and recorded.
- Information governance lead or DPO: owns data-protection advice, breach triage, access controls, processor arrangements and ICO decision records.
- All staff: confirm contact preferences, protect conversations and records, and access only records they need for their role.
- Safeguarding lead: advises where confidentiality, under-18s, coercion, abuse, public interest or adult-at-risk concerns overlap.
Confidentiality procedure
- Confirm contact preferences at each relevant contact. Record the safe phone, email, text, portal or postal route and whether messages may mention the service.
- Ask before sharing with the GP or another service. Do not assume consent to share sexual health attendance, diagnosis or results. Record consent, refusal or the lawful reason for sharing without consent.
- Protect front-desk and waiting-area privacy. Use discreet calling, avoid diagnosis labels, and do not discuss sexual health details where others can hear.
- Control record access. Access is role-based, auditable and reviewed when staff join, change role or leave.
- Handle third-party requests through a named route. Requests from partners, relatives, employers, police, solicitors, insurers or other services are checked before anything is disclosed.
- Disclose without consent only when justified. The clinician records the legal or professional basis, what was shared, who received it, why less disclosure was not enough, and whether the patient was told.
- Treat accidental disclosure as a serious incident. Any lost message, wrong recipient, overheard disclosure, wrong portal upload or unauthorised access is logged, risk-assessed and escalated to information governance.
- Review repeat themes. Repeated contact-preference errors, reception risks, staff-access concerns or disclosure delays are added to the risk register or improvement-actions register.
Records and register links
The confidentiality record should include:
- contact preferences and any limits on voicemail, SMS, email, portal or postal communication
- GP-sharing consent, partner-sharing refusal or third-party-request decision
- lawful basis and public-interest or safeguarding rationale for disclosure without consent
- what was shared, with whom, by whom, when and by what route
- whether the patient was told about the disclosure, and if not, why not
- access-audit review where there is a concern about inappropriate record access
- breach triage, ICO decision, patient notification decision and mitigation where confidentiality failed
- linked incident, complaint, safeguarding, risk or improvement-action reference
Confidentiality concerns are logged as incidents even where no reportable data breach is confirmed, because the service still needs evidence that the risk was assessed and learned from.
10. Training
Everyone in the Service is trained in confidentiality, including the heightened expectation in sexual health and the narrow disclosure exceptions, at induction and on a refresher cadence. The Service records completion and the next refresher date.
11. Audit cadence
The Service checks, on a stated cadence, that:
- attendance and diagnosis are not disclosed (including to GPs) without recorded consent
- records are stored securely with auditable, need-to-know access
- contact and reception practice protects patients' identity
- any disclosure without consent fits an allowed exception and is recorded
- confidentiality breaches are reported and learned from
The Registered Manager and the clinical lead review the results and record the improvement actions that follow.
12. Sources and further reading
This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.
Original sources carried forward from this policy:
- British Association for Sexual Health and HIV (BASHH), standards and guidance: https://www.bashh.org/
- GMC, Confidentiality: good practice in handling patient information: https://www.gmc-uk.org/professional-standards/professional-standards-for-doctors/confidentiality
- Data Protection Act 2018 and the UK GDPR (health and sexual-life data are special category): https://www.legislation.gov.uk/ukpga/2018/12/contents
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, Regulation 12 (safe care and treatment): https://www.legislation.gov.uk/uksi/2014/2936/regulation/12
Source pack for sexual health confidentiality:
- CQC Regulation 17: Good governance (https://www.legislation.gov.uk/uksi/2014/2936/regulation/17)
- CQC Regulation 12: Safe care and treatment (https://www.legislation.gov.uk/uksi/2014/2936/regulation/12)
- Common law duty of confidentiality
- UK GDPR and Data Protection Act 2018 (health and sexual-life data are special category data); ICO UK GDPR guidance; ICO data sharing code
- GMC, Confidentiality: good practice in handling patient information
- British Association for Sexual Health and HIV (BASHH) standards and guidance
- Safeguarding exceptions: local safeguarding adults and children procedures; for under-18s, Fraser guidelines and Gillick competence, and Working Together to Safeguard Children 2026
- CQC Fundamental Standards
Related reading
- Related policy: Confidentiality and data protection policy
- Related policy: Data breach policy
- Related policy: Record keeping and documentation standards policy
- Related policy: Partner notification policy
- Related policy: Under-18s and safeguarding policy
13. When to seek further advice
Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.
14. Document control
| Version | Date | Author | Changes |
|---|---|---|---|
| v1.1 | 2026-07-14 | Verivius (sample) | Added role ownership, confidentiality controls, disclosure records, register links and related reading. |
| v1 | 2026-06-10 | Verivius (sample) | Initial sample template, conformed to the Verivius policy standard. |
This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.