Raise the concern through your employer's process or a prescribed regulator, and share the least patient information needed for someone to investigate. Describe the risk and give a way to find the records, such as dates and a shared reference, rather than copying records. Do not take patient records home or send them to a personal email account, even to prove a point.
Key facts
- Your duty of confidence
- Comes from the common law, the UK GDPR, the Data Protection Act 2018 and your regulator's standards
- NDAs
- Do not create or remove the duty to patients
- Whistleblowing law
- Protects you from detriment for a protected disclosure, but gives no general right to remove records
- Data offence
- Obtaining or disclosing personal data without the controller's consent can be an offence under section 170 of the Data Protection Act 2018, subject to defences
- Regulators
- The GPhC, GMC, NMC and CQC are prescribed bodies and have their own powers to request records
Two duties at once
As a registered professional you hold a duty to raise concerns about patient safety. You also hold a duty to keep patient information confidential. The two rarely clash in practice. Most concerns can be reported in a form which tells the reader what went wrong, when, and where to look, without naming a patient in the first message. The person investigating then reads the records through proper access.
Whistleblowing law protects you from detriment for a protected disclosure. The law does not give a blanket right to collect or share patient data. When a case reaches a tribunal, the judge looks at how you gathered and passed on information as well as what you said.
What to share and what to hold back
- Share: the type of risk, dates, the ward, pharmacy or clinic, the system or log where the evidence sits, and record numbers or prescription references your employer can look up internally.
- Hold back: names, addresses, NHS numbers and clinical details in a first report to anyone outside your organisation, unless a regulator asks for them through their own process.
- Never share: patient details with the media, on social media, in a peer support group or in a public AI tool.
Keep your own private timeline of what you reported and when. Write the timeline without patient identifiers. For record-keeping tips, read keeping safe records.
What regulators say
The GMC guidance on raising a concern (opens another website) tells doctors to raise concerns where patient safety or care is compromised. The guidance also says a doctor considering a public disclosure must not breach patient confidentiality and should get advice first. The GPhC guidance on raising concerns (opens another website) says pharmacy professionals should, where possible, keep information confidential and not disclose without consent. The NMC publishes raising concerns guidance (opens another website) for nurses, midwives and nursing associates. If you are unsure whether to share an identifiable detail, ask your regulator's advice service or your organisation's data protection officer.
Mistakes to avoid
- Photographing a prescription, chart or screen on your own phone.
- Forwarding records to a personal email address to keep as evidence.
- Printing records and taking them home.
- Naming patients in a complaint to a newspaper, MP or online forum.
- Accessing records you have no clinical reason to view, to build a case.
Each of these can lead to a disciplinary process or a fitness to practise referral, and can weaken a whistleblowing claim. If you think evidence will be destroyed, tell Protect or the regulator what exists and where, and let them decide how to secure the evidence.
A GP practice example
Say a practice pharmacist notices repeat prescriptions for a high-risk medicine issued for months without the required blood tests. A safe first report to the practice lead would say: "On 12 dates between March and June, repeat prescriptions for [medicine] were issued without the monitoring the protocol requires. I can give the record references on the clinical system. I am worried patients face harm." The report names no patient and still gives enough to investigate. If the practice does nothing, the pharmacist can take the same information to the CQC or GPhC.
Questions to ask an adviser
- How much patient detail do I need in this report for the concern to be taken seriously?
- Can I keep any copy of evidence, and if so where and how?
- Does an NDA or contract clause affect what I can tell a regulator?
- Should I involve the data protection officer or Caldicott guardian?
- What should I do if I have already shared something I should not have?
Where to get advice
- Protect: 020 3117 2520, free and confidential, with experience of health service concerns. See Protect.
- Your regulator: the GMC has a confidential helpline, and the GPhC and NMC publish guidance on raising concerns.
- Professional body or union: PDA (opens another website), BMA (opens another website), RCN (opens another website) or your defence organisation.
- Acas: 0300 123 1100 for the employment side.
- Citizens Advice or a solicitor: for help if you face disciplinary action.
- Northern Ireland: Labour Relations Agency, 03300 555 300.
Common questions
Can I share patient records when whistleblowing?
Share the least information needed and let the investigator access records through proper channels. Whistleblowing law gives no general right to remove or copy patient records.
Can I take copies of records as evidence?
Taking records without authority risks a disciplinary process and may be an offence under the Data Protection Act 2018. Tell Protect or the regulator where the evidence sits instead.
Do I need patient consent to report a safety concern?
Not for an internal report which names no patient. For identifiable details shared outside your organisation, follow your regulator's confidentiality guidance and get advice first.
