A GP practice must respond to a subject access request for patient records within one month of receipt, and in most cases cannot charge a fee to do so, but health records carry additional rules that do not apply to a typical business responding to a data request. The “serious harm test” and the requirement to involve an appropriate health professional before disclosure are specific to health information, and getting them wrong, in either direction, creates real risk.

We advise GP practices on data protection compliance, including where a subject access request has become contentious because it touches on safeguarding concerns, family disputes, or information about someone other than the patient. This post sets out the practical mechanics of handling a DSAR correctly.

The Basic Timetable and What Counts as a Request

A subject access request does not need to use any particular wording, refer to legislation, or be made in writing. A patient can make a valid SAR verbally, at reception, over the phone, or via social media, provided it is clear they are asking for their own personal data. Practices should have a process for recording verbal requests so the clock isn’t missed simply because nothing was put in writing.

The response deadline is one month from receipt, and this can be extended by a further two months if the request is complex or the same individual has made a number of requests. If an extension is needed, the practice must tell the patient within the original one-month period and explain why. A request is not automatically complex just because it involves a large volume of records; complexity has to be assessed on the actual circumstances, though needing to consult an appropriate health professional (see below) is itself recognised by the ICO as a legitimate reason to treat a request as complex.

In most circumstances a practice cannot charge a fee to comply with a SAR for health information. A reasonable administrative fee is only available where the request is manifestly unfounded or excessive, or where the patient is asking for further copies of information already provided.

The Serious Harm Test: What Makes Health Records Different

Health information is exempt from disclosure to the extent that providing it would be likely to cause serious harm to the physical or mental health of the patient or another person. This is a genuinely narrow exemption, not a general discretion to withhold anything sensitive, and it works differently depending on who is handling the request.

  • If a health professional (for example, a GP) is handling the request themselves, they can rely on the exemption directly, based on their own clinical judgement.
  • If the request is being handled by someone who is not a health professional, such as a practice manager or administrator, they cannot withhold information on serious harm grounds unless they have obtained an opinion from the “appropriate health professional” within the last six months confirming the test applies, and that opinion must be reconsulted if it would be reasonable to do so given how much time has passed or how the patient’s circumstances may have changed.

The “appropriate health professional” is the clinician currently or most recently responsible for the patient’s diagnosis, care or treatment in connection with the matter in question. Where more than one clinician has been responsible, it is whoever is best placed to give an opinion on the specific issue. If no such clinician is available, the practice can appoint another suitably qualified and experienced health professional to give the opinion.

The same logic works in reverse for disclosure. A non-health-professional handling a SAR must not disclose health information unless they are satisfied the patient already knows it, or they have obtained a recent opinion from the appropriate health professional confirming that the serious harm test is not met. If a practice cannot get that opinion within the response deadline, the ICO’s position is clear: the information must be withheld rather than disclosed by default, and the practice should keep a record of the efforts it made to consult the clinician.

Third-Party Information Within a Patient’s Record

GP records routinely reference other people: family members mentioned in a social history, a partner referenced in a safeguarding note, or a carer named in correspondence. Where a record contains identifiable information about someone other than the requesting patient, that information must be considered separately from the rest of the request. It should not be disclosed unless the third party consents, or it is reasonable to disclose it without their consent, taking into account factors such as any duty of confidentiality owed to them and whether they have expressly refused consent.

It is normally reasonable to disclose information that simply identifies a health professional carrying out their clinical duties (for example, naming the GP or nurse who made an entry), which is treated differently from information identifying another patient or a family member.

Requests Made on Someone Else’s Behalf

A solicitor, relative, or advocate can make a SAR on a patient’s behalf, but the practice needs to be satisfied that the third party is actually entitled to act for the patient, and it is the third party’s responsibility to provide evidence of that authority, not the practice’s job to assume it. For requests concerning a child, the practice should consider whether the child is mature enough to understand their own rights (broadly, whether they are Gillick competent) before automatically routing the request through a parent.

A SAR cannot be used to obtain a deceased patient’s records; that sits under the separate Access to Health Records Act 1990, which has its own rules about who can apply and what can be withheld. Practices should not process a request for a deceased patient as though it were a live SAR.

It is also worth flagging to reception and administrative staff that pressuring someone to make a SAR so that the information can be used for another purpose, for example, requiring a job applicant to submit a SAR to their own GP to disclose their health records to a prospective employer, is a criminal offence. Practices are not usually the ones doing the pressuring, but staff should recognise the signs of an enforced request and query it rather than simply processing it.

Enforcement Risk if It Goes Wrong

Failing to respond within the deadline, disclosing third-party information without proper consideration, or releasing health information without appropriate clinical sign-off where the serious harm test may apply, are all matters the ICO can act on, and a patient can also apply to the court for an order requiring compliance or seek compensation. Getting DSAR handling wrong is also the kind of process failure that tends to surface in a wider information governance review, whether that is an ICO investigation or a CQC well-led assessment, which we cover in our post on CQC registration and compliance for GP practices. Consistent, well-documented DSAR handling is also one of the practical things a properly resourced Data Protection Officer should be actively overseeing, something we cover in more detail in our post on the risks of getting the GP practice DPO role wrong.

DSAR Handling Checklist for GP Practices

StepWhat to check
Recognise the requestAny clear request for a patient’s own data counts, verbal or written, however it is worded
Log the date receivedThe one-month clock starts on receipt, not when it reaches the right member of staff
Verify identity and authorityConfirm the requester’s identity, and any third party’s authority to act, before the substantive work begins
Assess complexityDecide early whether an appropriate health professional needs to be consulted, and extend the deadline (with notice to the patient) if so
Apply the serious harm test correctlyNon-clinical staff must not withhold or disclose on serious harm grounds without a recent opinion from the appropriate health professional
Review for third-party informationRedact or withhold identifiable information about other people unless consent is given or disclosure is reasonable without it
Respond and documentKeep a record of what was disclosed, what was withheld, why, and the clinical input obtained

What This Means for Your Practice

DSARs involving health records are more procedurally demanding than a standard business SAR, and the serious harm test in particular is easy to apply too cautiously or not cautiously enough if the process isn’t clear to whoever picks up the request. A written procedure that tells reception and administrative staff exactly when to involve a clinician, and how quickly, closes the most common gap we see.

If your practice would like its DSAR process reviewed, or needs advice on a specific request that has become contentious, get in touch with our healthcare team or call us on +44 207 566 1188. You can also reach us at info@gurvelegal.com. Our data protection team supports GP practices with DSAR procedures, training and individual case advice.