Skip to main content

Doctor breached data rules in phone call in front of patient

A doctor who answered a phone call while examining a patient – and stayed in the room throughout the conversation – prompted a personal data breach report to the island’s data protection watchdog.

‘This report also reminds us that breaches are not just about records, but include overheard conversations,’ said data protection commissioner Brent Homan.
‘This report also reminds us that breaches are not just about records, but include overheard conversations,’ said data protection commissioner Brent Homan. / Sophie Rabey, Guernsey Press

Due to the volume of the call and how close others were, it was overheard by the patient being examined and by others in the room. During the conversation, identifying details and sensitive health information about a different person were disclosed to people who had no reason to hear them and no connection to that patient’s care.

The case, highlighted by the Office of the Data Protection Authority in its latest quarterly statistics, involved the unauthorised disclosure of special category data and created a risk of distress and loss of privacy for the person concerned.

The healthcare provider that reported it reminded the doctor of their data protection obligations and arranged for the lessons learned to be addressed urgently at an academic session for all its doctors. The authority has advised that such training should be repeated for new staff and refreshed each year.

Maintaining confidentiality was a fundamental part of handling personal data in every sector, the ODPA said, not only in healthcare, where the sensitivity of the information carried extra weight.

‘This report also reminds us that breaches are not just about records, but include overheard conversations,’ said data protection commissioner Brent Homan.

The case featured in the authority’s figures for the second quarter of the year, which showed reported breaches falling from 65, and high-risk incidents declining for the second quarter running.

The office received 49 breach reports between April and June, down on the previous three months. Only four were classed as high-risk, compared with seven in the previous period, while a further 10 reports were found not to meet the threshold of a reportable breach.

‘It is encouraging to see high-risk breach incident reports decline for a second quarter,’ said Mr Homan.

‘When organisations report breaches they not only fulfil an important legal obligation but can benefit from our office’s expertise in mitigating any harmful effects of a security incident.’

Emails sent to the wrong recipient were again the most common type of breach reported, with loss of confidentiality the most likely harm.

You need to be logged in to comment.