Overview
This lecture (MED3 Medical Law #3) covers privacy and confidentiality in healthcare in four parts: why they matter ethically and professionally, New Zealand’s privacy law framework (the Privacy Act 2020 and Health Information Privacy Code 2020), the lawful use of health information, and the lawful disclosure of health information. Three running case studies (Sana’s ankle injury, pregnancy and hepatitis C status; a nurse browsing an unrelated patient’s notes; and a doctor sharing details in an international group chat) test whether a given use or disclosure is legitimate, alongside real NZ news stories about breaches.
Why Privacy and Confidentiality Matter in Healthcare
- Privacy: the desire, expectation, or right of an individual to control how their information is collected, used, and disclosed.
- Confidentiality: a provider’s duty to maintain patients’ privacy. Basic rule: health information is personal (private), and providers must keep it secret (confidential), with limited exceptions.
- Reasons privacy and confidentiality matter, each tied to an ethical/professional principle:
- Most people expect control over who sees their body and personal information -> Respect for Autonomy, Dignity.
- Some information can be harmful if mishandled -> Non-maleficence, Trust, Kaitiakitanga.
- Information can also help protect or assist someone -> Beneficence, Justice.
- Responsible use of information maintains relationships -> Trust, Duty of Care, Manaakitanga.
- It is the law -> professional standard and legal obligation.
- Hippocratic Oath: “Whatsoever things I see or hear concerning the lives of men, in my attendance on the sick, or even apart therefrom, which ought not to be noised abroad, I will keep silence thereon, counting such things to be as sacred secrets.”
- Declaration of Geneva (Physician’s Pledge): “I will respect the secrets that are confided in me, even after the patient has died.”
- Code of Health and Disability Services Consumers’ Rights, Right 1 (Right to be Treated with Respect): every consumer has the right to have their privacy respected.
The reasons list above, the Hippocratic Oath and Declaration of Geneva quotes, and the Right 1 text were all recovered from the PDF's text layer rather than confirmed on the rendered slide images (slides 9-11 showed blank/solid-colour blocks or hidden text in the render).
- Right 4 (Right to services of an appropriate standard) includes care provided “in a manner consistent with…needs”, complying with legal, professional, ethical and other relevant standards, minimising harm and optimising quality of life, and a right to cooperation among providers.
- Medical Council of NZ, Good Medical Practice: establish a relationship of trust with patients; be aware of cultural diversity and safety; treat patients as individuals, respecting dignity by treating them respectfully and respecting their right to confidentiality and privacy; treat all information about patients as confidential and sensitive.
- Code of Professional Conduct for Medical Students (Auckland and Otago), clause 6 - maintaining patient confidentiality: disclosure without permission or legal justification is inconsistent with the trust required in medical practice and has the potential to cause harm or distress. As a medical student:
- Hold all patient information in confidence, including after treatment ends or the patient dies.
- Respect patients’ right to determine who receives their personal information.
- Not remove or copy patient-related material without specific permission.
- Ensure documents/images containing patient information are de-identified, securely stored, and securely destroyed when no longer required.
- Be aware of the limited circumstances where breaches of confidentiality may be justified or required.
- Not access patient information unless involved in their care, or with a legitimate reason and permission from those authorised to give it.
New Zealand’s Privacy Law
- The Privacy Act 2020 (Public Act 2020 No 31, date of assent 30 June 2020) is the overarching legislation.
- The Health Information Privacy Code 2020 is a Code of Practice made under section 32 of the Privacy Act 2020 by the Privacy Commissioner, and applies specifically to health information.
- The Code applies to information about an identifiable individual (clause 4(1)).
The list of information classes covered by clause 4(1) rendered as an unreadable block in the slide image, and pdftotext captured no further text for it, so its specific contents are not available from this transcript.
- A “health agency” (who must comply with the Code) includes a hospital, medical practice, medical school, and the people who work or study there.
The Health Information Privacy Code: 13 Rules
Health agencies (including health professionals and students) must:
- Only collect information about a patient that is really needed.
- Get the information from the patient wherever possible.
- Be open with the patient about what will be done with the information (3A: if the information is instead collected from someone else, let the patient know).
- Be fair and lawful about how the information is obtained.
- Keep the information secure.
- Let patients see the information if they want to - limited reasons for refusal exist, e.g. if release would endanger a person or damage their health; “patient” includes their representative (e.g. parent, welfare guardian).
- Fix the information if it is wrong - if you know it’s wrong, correct it; patients can also request correction, and if you disagree you must attach a statement showing that correction was requested.
- Make sure the information is accurate before using it.
- Dispose of the information as soon as it is no longer needed.
- Use the information only for the purpose it was collected for, unless the patient gives permission, the new purpose is directly related to the original collection, or the information is de-identified.
- Only disclose the information if there is a good reason (detailed under “Lawful Disclosure” below).
- Make sure the information is adequately protected before sending it overseas.
- Only use the National Health Index (NHI) number for health reasons.
Illustrative real-world failures:
- Rule 5 (security): confidential Otago School of Dentistry patient files, including HIV status and mental state, were found fluttering around a Dunedin street and marked “Confidential. Not to be removed from the building” (2010 news story).
- Rule 8 (accuracy): a UK NHS patient found his medical record incorrectly included treatment for drug addiction; a 2024 survey separately found 45% of respondents had found inaccuracies in their records (most often personal information, allergies, or treatment history), usually corrected by phone call or document verification.
- A study across four Australian/NZ hospitals found at least one simple prescribing error on the medication charts of 672 of 715 patients, with more errors as more medications were prescribed (r=0.571, p<0.001); pharmacist review was linked to fewer allergy-documentation errors (13.5% vs 29.4% inadequate documentation, p<0.001).
Lawful Use of Health Information
Rule 10 requires information to be used only for the purpose it was collected for (or with consent, a directly related purpose, or de-identification).
- Case 2: a nurse not involved in a patient’s care browses her notes (which include a detailed mental-illness history) out of curiosity during a quiet night. This is not a legitimate use: under the Code of Professional Conduct (6.6), information may only be accessed if you are involved in the patient’s care or have a legitimate reason and permission.
- Case 3: a doctor treating a patient with a very rare condition posts patient information to an international expert group chat while co-writing a practice guideline. This is not automatically legitimate; de-identifying the information, or obtaining the patient’s consent, could make the use acceptable.
- Real breach: a doctor was fined $30,000 for accessing the medical records of dozens of patients not under her care, including friends and acquaintances.
- Real breach: 33 staff at Auckland City Hospital were disciplined (sackings, verbal/written/final written warnings) after a six-month investigation found no legitimate reason for them to access a patient’s radiology images, blood test results and discharge summary; the breach extended to distributing information to the public and media.
- Real breach: Waikato Hospital recorded 12 confirmed privacy/confidentiality breaches since 2012, ranging from unauthorised snooping on records to misdirected emails; two staff were sacked and two resigned. High-profile patients’ records are checked afterwards for unauthorised access.
One news excerpt states a doctor's colleagues accessed his records "with good reason", which appears to be a transcription of a negated phrase in the original headline/body ("without good reason"); flagged rather than silently corrected.
Lawful Disclosure of Health Information
Rule 11 only allows disclosure for a good reason. Two routes are given:
- Disclosure is permitted to:
- The individual or their representative.
- Others involved in the patient’s care, as needed.
- Someone else, with the patient’s consent.
- General information about the patient’s presence, location and condition in hospital, if not contrary to their wishes (can include the fact of death to whānau).
- An audit, or de-identified for research.
- OR, if there are reasonable grounds to believe patient consent cannot or should not be obtained, disclosure is allowed when:
- The information is de-identified (including for statistics or research), or
- Disclosure is necessary to prevent or lessen a serious threat to public health or safety, or to the life or health of the individual or another individual, or
- Disclosure is required by law.
- Example of lawful (permissible) disclosure: a doctor told Police about a suicidal patient’s gun after the patient withdrew from treatment rather than give it up; the doctor consulted several colleagues involved in the patient’s care, all agreed it was appropriate, and Police visited the man the same day.
- Examples of legally required disclosure: notifying a notifiable disease; notifying the NZ Transport Agency if a patient’s physical or mental condition means they “should not be permitted to drive” yet intend to.
- Case 1 variation: Sana discloses she has hepatitis C and consents to her ankle details being shared but asks that her hepatitis C status not be disclosed. Guidance given: counsel her to disclose to sexual partners and clinicians herself, and only breach her confidentiality if the case meets the Rule 11 “serious threat” standard.
Self-test
- Distinguish privacy from confidentiality as defined in this lecture.
- List the five reasons given for why privacy and confidentiality matter in healthcare, and the ethical/professional principle linked to each.
- Name the two historical professional pledges quoted in the lecture that commit clinicians to confidentiality, and summarise what each says.
- List three specific obligations a medical student has under clause 6 of the Code of Professional Conduct for Medical Students.
- What two pieces of NZ law/codes form the legal framework for health information privacy, and how does one relate to the other?
- List the first four (plus 3A) collection rules of the Health Information Privacy Code.
- What does Rule 5 require, and which real NZ case illustrates a failure to meet it?
- Describe what Rules 6 to 8 of the Code require, including when access to information can be refused.
- What must happen to information under Rule 9, and what limits how it may be used under Rule 10?
- In Case 2, is a nurse’s out-of-care browsing of a patient’s file a legitimate use of the information? Explain why or why not.
- In Case 3, what would need to be true for the doctor’s group-chat disclosure to become acceptable?
- List the categories under which Rule 11 permits disclosure without needing to establish “reasonable grounds”.
- Under Rule 11, when may information be disclosed on the basis of “reasonable grounds” that consent cannot or should not be obtained?
- Give two examples from the lecture of disclosures that are legally required, and state who must be told in each case.
- In the Case 1 variation, what standard must be met before Sana’s doctor can disclose her hepatitis C status without her consent?
- Distinguish an unlawful use of health information from an unlawful disclosure of it, using one example of each from the lecture.
Answers
Reveal answers
- Privacy is the individual’s desire, expectation, or right to control how their information is collected, used and disclosed. Confidentiality is the provider’s duty to maintain that privacy - health information is personal and must be kept secret, with limited exceptions.
- Control over body/personal information -> Autonomy, Dignity; harm if mishandled -> Non-maleficence, Trust, Kaitiakitanga; information can help/protect -> Beneficence, Justice; responsible use maintains relationships -> Trust, Duty of Care, Manaakitanga; it is legally required -> professional standard and legal obligation.
- The Hippocratic Oath: to keep silent about what is seen or heard in attending the sick, treating it as a sacred secret. The Declaration of Geneva (Physician’s Pledge): to respect the secrets confided by a patient, even after their death.
- Any three of: hold all patient information in confidence, including after treatment ends or death; respect the patient’s right to determine who receives their information; not remove or copy patient material without permission; ensure documents/images are de-identified, securely stored and securely destroyed; be aware of the limited circumstances justifying a breach; not access information unless involved in care or with a legitimate reason and permission.
- The Privacy Act 2020 is the overarching legislation; the Health Information Privacy Code 2020 is a Code of Practice made under section 32 of the Privacy Act by the Privacy Commissioner, applying specifically to health information.
- 1: only collect information really needed; 2: get it from the patient wherever possible; 3: be open with the patient about what will be done with it; 3A: if collected from someone else, let the patient know; 4: be fair and lawful about how it is obtained.
- Rule 5 requires keeping information secure. Illustrated by confidential Otago School of Dentistry patient files (including HIV status and mental state) being found blowing around a Dunedin street.
- Rule 6: let patients see their information, with limited refusal grounds (e.g. risk of endangering someone or harming their health); “patient” includes a representative. Rule 7: correct information known to be wrong, or attach a statement if a requested correction is disputed. Rule 8: ensure information is accurate before using it.
- Rule 9: dispose of information as soon as it is no longer needed. Rule 10: use information only for the purpose it was collected for, unless the patient permits otherwise, the new purpose is directly related to the original one, or the information is de-identified.
- No - the nurse is not involved in the patient’s care and is browsing out of curiosity, which is not a legitimate reason to access information under the Code of Professional Conduct (6.6) and would breach Rule 10’s purpose limitation.
- The disclosure would need to be de-identified, or the patient’s consent would need to be obtained, for it to be acceptable.
- Disclosure to the individual or their representative; to others involved in the patient’s care, as needed; to someone else with the patient’s consent; general information about presence, location and condition in hospital if not contrary to the patient’s wishes (including fact of death to whānau); for an audit, or de-identified for research.
- When there are reasonable grounds to believe consent cannot or should not be obtained, and either the information is de-identified, or disclosure is necessary to prevent or lessen a serious threat to public health/safety or to the life/health of the individual or another person, or disclosure is required by law.
- Notifying a notifiable disease (to the relevant authority), and notifying the NZ Transport Agency when a patient’s physical or mental condition means they should not be driving but intend to.
- The disclosure must meet the Health Information Privacy Code Rule 11 “serious threat” standard; otherwise Sana should be counselled to disclose to sexual partners and clinicians herself.
- Unlawful use (Rule 10): the doctor fined $30,000 for accessing the medical records of patients not under her care, including friends and acquaintances - not a legitimate purpose. Unlawful disclosure (Rule 11): the Auckland City Hospital case, where the breach extended to distributing a patient’s information to the public and media without a legitimate reason.