Home / Safety, Ethics & Governance
Confidentiality and Privacy
Confidentiality concerns duties around entrusted information, while information privacy covers the wider handling of personal data.
#Entrusted information needs protection
The UK General Medical Council's confidentiality principles call for protecting patient information against improper access, disclosure and loss. They also emphasize using the minimum personal information necessary and understanding responsibilities appropriate to a professional's role.
Confidentiality concerns how entrusted information is handled. The source is professional guidance in a UK legal context, not a rule that every health system uses unchanged. Read which duties and organizational policies apply before assuming that an available record may be shared.
#Privacy includes uses, disclosures and rights
HHS describes the US HIPAA Privacy Rule as protecting specified medical records and other identifiable health information. It sets limits and conditions on uses and disclosures and gives individuals rights to access records and request corrections.
Its scope includes health plans, clearinghouses and certain healthcare providers. This is an example of how privacy rules govern more than secrecy; it is not proof that every health-related app or dataset falls under HIPAA. Local law, the organization and the information involved matter.
Evidence: HHS: scope of the HIPAA Privacy Rule
#The purpose of disclosure matters
The GMC distinguishes sharing for direct care from other purposes and describes consent, legal requirements and other grounds that can apply to disclosure. Its framework also calls for minimum necessary disclosure and records of decisions.
Confidentiality is not an absolute ban on sharing, but a useful purpose alone does not settle whether disclosure is appropriate. Read the relevant legal and professional basis, the recipient and the amount of information needed. This summary is not a decision rule for disclosing a particular patient's information.
Evidence: GMC: framework for disclosing patient information / GMC: principles for handling patient information
#Security supports privacy but does not decide permission
HHS describes the HIPAA Security Rule as requiring administrative, physical and technical safeguards for electronic protected health information within its scope. These safeguards concern confidentiality, integrity and availability.
Protecting a file from unauthorized access is different from deciding whether its use or disclosure is permitted. Read both the access protections and the applicable purpose and disclosure rules. This page does not describe Mynd as holding patient records or certify its compliance with a health-data law.
Evidence: HHS: scope of the HIPAA Security Rule / HHS: scope of the HIPAA Privacy Rule
Source note
The sections above were checked against the linked sources. No clinical review has been performed. This is general research education, not a clinical guideline.