Experts must therefore do more than keep documents secure. They must consider what information they need, who should have access to it, what belongs in the final report and how they will protect the information throughout the reporting process.
The GMC states that medical professionals have both ethical and legal duties to protect personal information against improper disclosure. Health information also qualifies as special category data under the UK GDPR and receives additional protection because of its sensitive nature.
Confidentiality Extends Beyond the Consultation.
Confidentiality does not begin when the claimant enters the examination room and end when they leave.
An expert may receive medical records weeks before an appointment and continue to hold reports, correspondence and supporting documentation after completing the assessment. Confidentiality therefore applies throughout the entire life of the case.
The GMC requires medical professionals to protect personal information against improper access, disclosure or loss and to understand the information-governance responsibilities relevant to their role.
Experts should consider how they receive records, where they store them, who can access them and how they eventually dispose of them. The same standards should apply whether the expert works from a clinic, office, home or temporary examination venue.
Convenience should never determine how sensitive information is handled.
Only Relevant Information Should Be Used.
A medico-legal expert may receive hundreds or even thousands of pages of medical records. Access to those records does not mean that every detail belongs in the final report.
The expert should identify information that is relevant to the questions they have been asked to address. Previous neck pain may clearly matter in a cervical injury claim. A completely unrelated medical condition from many years earlier may have no bearing on diagnosis, causation or prognosis.
The GMC advises medical professionals to use the minimum necessary personal information and to use anonymised information where this can achieve the required purpose. The UK GDPR also incorporates the principle of data minimisation.
This becomes particularly important where records contain highly personal information. Reproducing irrelevant psychiatric, sexual or family history simply because it appears in the records can cause unnecessary intrusion.
The expert should ask a straightforward question: does this information assist the medical opinion? If it does not, there may be no reason to reproduce it.
Sensitive Information May Still Be Relevant.
Data minimisation does not mean that experts should omit difficult information when it genuinely affects the opinion.
A previous psychiatric condition may be important where the claimant alleges psychological injury. Earlier episodes of back pain may influence an opinion on causation. Medication history may help establish whether symptoms existed before an accident.
The expert should therefore distinguish between information that is sensitive and information that is irrelevant. Sensitive information can still be clinically important.
Where the expert includes such material, they should explain it proportionately and professionally. A report rarely needs to reproduce extensive consultation notes word for word. A concise summary can often provide the necessary clinical context without unnecessarily repeating confidential information.
The expert should remain objective and ensure that the report contains the information necessary to support the opinion while avoiding unnecessary disclosure.
Understanding Consent and Disclosure.
Claimants should understand why their information is being obtained and how it will be used. However, experts should not assume that consent alone resolves every data-protection issue.
Health information falls within the UK GDPR definition of special category data. Organisations processing this information must identify an appropriate lawful basis for processing and satisfy an additional condition for processing special category data.
The GMC also emphasises that confidentiality has both ethical and legal dimensions. Where information is disclosed without consent, the professional must have an appropriate justification and meet the relevant legal and professional requirements.
Experts should understand the arrangements under which they receive and disclose claimant information rather than assuming that the instructing organisation has dealt with every confidentiality issue on their behalf.
Secure Transfer and Storage.
Medical records should move between organisations through appropriately secure systems.
Ordinary email can create risks if an expert sends a report to the wrong address, attaches the wrong claimant’s records or allows an unauthorised person to access an account. Experts should check recipient details carefully and use appropriate security measures when transferring sensitive documentation.
Devices containing medico-legal information should also receive suitable protection. Experts should control access to laptops, computers and cloud systems and prevent family members, colleagues or other unauthorised people from viewing claimant information.
The ICO requires organisations to implement appropriate security measures to protect personal data, while the GMC specifically requires professionals to keep records containing personal information secure and comply with data-protection law.
Remote working does not reduce these responsibilities. An expert reviewing records at home carries the same confidentiality obligations as an expert working within a clinical environment.
Administrative Staff and Third-Party Providers.
Experts often rely on secretaries, medical reporting organisations, transcription providers and report-writing systems. These arrangements may improve efficiency, but they also increase the number of people and systems that potentially handle claimant information.
Access should remain limited to those who genuinely require it.
Experts should understand how third-party systems process information, particularly where providers use cloud storage or external technology. They should also establish appropriate procedures for staff who handle records, prepare reports or arrange appointments.
The expert remains responsible for exercising appropriate professional judgment over the information included in the report. Outsourcing administrative work should never mean outsourcing responsibility for confidentiality.
Artificial Intelligence Creates Additional Risks.
Artificial intelligence can help experts organise information, summarise records or prepare initial drafts. However, entering identifiable medical information into an unsuitable AI system may result in data being processed or retained in ways that the expert does not fully understand.
The ICO’s current data-protection guidance specifically addresses artificial intelligence and requires organisations using AI to consider existing UK GDPR obligations, including requirements that apply to special category information.
Experts should therefore know what system they are using, what happens to the information entered into it and whether the system has been approved for processing sensitive medical data.
Removing the claimant’s name may not always make the information anonymous. A combination of age, accident date, occupation, unusual diagnosis and location might still make an individual identifiable.
Technology can assist an expert, but it should never encourage less careful handling of medical information.
What Happens When Information Is Sent Incorrectly?
Human error remains a significant confidentiality risk. An expert might send a report to the wrong solicitor, attach records belonging to another claimant or discover that an unauthorised person has accessed an email account.
The expert should act immediately rather than hoping the mistake will have no consequences.
The organisation responsible for the data should assess the nature of the breach, the information involved, who received it and the potential risk to the individual. Depending on the circumstances, notification to the ICO may be required. The ICO maintains specific procedures for reporting personal data breaches.
Experts should therefore have an incident procedure in place before a breach occurs. Quick containment can reduce the potential harm.
Protecting Confidentiality Without Weakening the Report.
Confidentiality should not prevent an expert from discussing relevant medical evidence. Equally, the requirement to prepare a comprehensive report does not justify reproducing every sensitive fact found within the records.
The expert must find the appropriate balance.
A good report includes enough medical history to explain the diagnosis, causation opinion and prognosis without unnecessarily exposing unrelated areas of the claimant’s private life.
The same principle applies to the wider handling of the case. Experts should collect only what they need, restrict access, use secure systems and retain information only for as long as there is a legitimate reason to do so.
Confidentiality is therefore not simply an administrative requirement. It forms part of professional medico-legal practice. Experts who handle sensitive information carefully protect the claimant while also protecting the reliability, integrity and professionalism of their own work.

