Sign up →
Data protection · Guide

Handling medical records under UK GDPR

A claimant’s medical records are about the most sensitive data a firm will ever hold. Processing them on a live matter is entirely lawful — but it sits under the special-category regime, and a few things are worth getting right from the start. Here is a practical checklist.

For PI & clinical-negligence fee-earners and their DPOs · ~5 min read

1. Treat it as special-category data

Health data is “special category” under Article 9 of the UK GDPR. That means two things must be in place at once: an ordinary lawful basis for processing (Article 6) and a separate Article 9 condition that permits handling health data. One without the other is not enough. For a firm running a claim, the everyday basis is usually legitimate interests, and the Article 9 condition is typically the one for the establishment, exercise or defence of legal claims. Record which you are relying on.

2. Write it down before you request records

Your privacy information and Article 30 record of processing should already cover claimant health data. In practice that means being able to answer, on any file: why you hold the records, the basis you rely on, who you share them with (counsel, experts, the defendant), and how long you will keep them. If a claimant asks, you should be able to give a straight answer.

3. Minimise — request what the claim needs

Data minimisation is a principle, not a nicety. Blanket “all records, all time” requests pull in decades of unrelated history you then have to hold, secure and eventually destroy. Where the injury and issues allow, scope the request to the relevant period and providers. A tighter record set is also a faster, cheaper bundle.

4. Keep it secure in transit and at rest

  • Move records over encrypted channels — secure portals or encrypted email, not an open attachment to a general inbox.
  • Restrict access to the people who actually need it on the matter.
  • If you use a third-party tool to summarise or paginate records, it is a processor: you need a processor agreement, and you should know where the data is processed and that it is not used to train anyone’s models.

5. Have a retention position

Health data should not be kept indefinitely “just in case”. Set a retention period tied to the limitation position and your regulatory obligations, and destroy securely at the end of it. A written schedule is far easier to defend than an ad-hoc decision years later.

6. Be ready for a subject access request

A claimant can ask for a copy of the personal data you hold about them. Knowing where the records live, who they have been shared with, and being able to produce them within a month is much easier when the file is organised — a paginated, indexed record set is a subject access response almost by itself.

Where Med-Legal fits. Records are processed only to produce your summary and bundle, on infrastructure under a processor agreement, and are never used to train models. The reading and assembly are automated; the file, and the judgement, stay with you.

Create a free account →

This is general information for legal professionals, not legal advice, and does not create a client relationship. Check your own obligations with your DPO or compliance lead.