Privacy and confidentiality can lead to thorny issues
As a nurse, midwife or personal care worker, you have a duty to hold the health information of your patients in confidence.
Key points
- Accessing a patient’s health information is regulated by legislation and organisational policies.
- The Nursing and Midwifery Board of Australia’s nurses’ and midwives’ codes of conduct states you must ‘access records only when professionally involved in the care of the person and authorised to do so’.
- A breach of patient confidentiality may result in disciplinary action including the termination of your employment and/or a notification to the Australian Health Practitioner Regulation Agency (AHPRA).
- It may also attract a hefty fine in some situations 50 penalty units ($10,175.50) under section 141 Health Services Act 1988, 60 penalty units ($12,210.60) under section 92 Health Records Act 2001).
- Any information where a patient is able to be identified is confidential.
- You do not have to share, distribute or publish patient information to breach patient confidentiality – accessing the information of a patient not under your care is still a breach.
- In the past, when health records were paper-based, nurses and midwives in the hospital setting generally had access only to records of patients on their respective wards. This limited access to health records, and limited the risk of confidentiality breaches.
- Patients’ health information is nowadays much more vulnerable, with nurses and midwives having potential access to many thousands of records through digital health records systems used by health services.
- To protect patients’ information, electronic patient records systems generally log each time a file is accessed. Because records access requires a login, system administrators know who has accessed the records and when.
- Accessing the records of someone who you provided care to in the past is still a breach of patient confidentiality, unless you have proper reason and authorisation (for example, for approved research, quality control or legal proceedings).
Be familiar with the situations where a breach of patient confidentiality might occur and know how to reduce the risks of exposure to these situations: they may be happening without you even realising.
What information is confidential?
Health information includes progress notes, personal details, medical assessments and pathology results. Any information from which a patient can be identified is deemed confidential.
What is my duty?
It is your duty to protect the confidentiality of patients who are directly under your care, and those who are not directly under your care, but whose health information and records you have access to because of your employment and position as a health practitioner. Failing to do either of these things will result in a breach of patient confidentiality.
When does a breach occur?
A breach of patient confidentiality occurs when the health information of a patient is shared or distributed. A breach of patient confidentiality also occurs when patient information is accessed by someone who is not directly involved in the care of this patient.
Be certain you are authorised
Nurses, midwives and personal care workers are in a privileged position of having access to information about others that is often very sensitive and deeply personal. Accessing information about patients directly under your care is legitimate and indeed vital to providing appropriate care. You must familiarise yourself with your organisation’s policy in relation to accessing health information. Before you access health information for a purpose other than direct patient care you must be certain that you are authorised to do so.
Health practitioners should also ensure that after accessing health information, they logout of the system to ensure that others do not access information using their login credentials.
If you need further advice complete a ANMF Member Assistance inquiry form.
Case studies
A nurse who was involved in the care of a patient in the emergency department accessed the patient’s electronic medical records after they had been transferred to another unit, in order to follow up on the patient’s progress or outcome.
Outcome: It is human nature to want to know the outcome on a case you were involved with, but accessing the records of a patient no longer in your care is a breach of patient confidentiality and of the employer’s electronic access policy. The nurse was disciplined, given a first and final warning and put on a performance improvement plan with a requirement to undertake education.
A nurse accessed their partner’s electronic medical records multiple times throughout their hospital admission across different units. The nurse was not involved in the care of their partner.
Outcome: This scenario is unfortunately too frequent; it is also incredibly risky. A workplace investigation was carried out and the employer found that the nurse’s actions amounted to serious misconduct. The nurse received legal advice during the investigation process and received a first and final warning from her employer. The nurse was also required to disclose to their new employer that they had breached patient confidentiality.
In the days following the death of a patient, a nurse accessed the electronic medical records of the patient, who was a family friend. The nurse then shared some details regarding the circumstances of the admission with another friend, who was not next of kin. The nurse was not involved in the care of the patient.
Outcome: Allegations of serious and wilful misconduct were substantiated and the nurse was required to show cause as to why the employer should not terminate their employment. The nurse elected to resign instead and was later investigated by AHPRA.