top of page

Primary Healthcare Derby

Patient Access to Medical Records Statement


The law states that NHS organisations must, when requested by an individual, give that person access to their personal health information, and occasionally, certain relevant information pertaining to others. In order to do this, they must have procedures in-place that allow for easy retrieval and assimilation of this information.


There are three main areas of legislation that allow the right of the individual to request such personal information, and they are:


  • The Data Protection Act 2018 (formerly DPA 1998) (DPA)

  • The UK General Data Protection Regulation 2016 (UK GDPR)

  • The Access to Health Records Act 1990

  • The Medical Reports Act 1988


Where the request for information by an individual falls under the legislation of any of these areas, access must be granted. Patients requesting information about their own personal medical records would usually have their request dealt with under the provisions of the Data Protection Act 2018 and UK GDPR 2016.


The GMS contract and PMS agreement contract 20202/21 (GP Contract commitment 5.10 (ii)) require practices to promote and offer their registered patients’ online access to all coded data in their GP records, referred to as their Detailed Coded Record.


Patients under the care of PHD must contact their own Practice in order to access their medical records.


The introduction of online patient access to services does not change the right that patients already have to request access to their medical records provided by the provisions of the Data Protection Act (DPA) and UK GDPR. The DPA principles and confidentiality requirements apply in the same way for online access as they do for paper copies of the record.

bottom of page