top of page
Search

Do patients need to show ID every time they ask for their information?

4 hours ago
6 min read
It is important to remember that obtaining an ID document is not the objective here, it is to be reasonably satisfied that the person requesting information is who they claim to be.
It is important to remember that obtaining an ID document is not the objective here, it is to be reasonably satisfied that the person requesting information is who they claim to be.

Protecting patient information is fundamental to healthcare, and so before confidential information is disclosed, a provider needs to be satisfied that it is giving that information to the right person.


But that does not mean every patient requesting information must automatically produce a passport, driving licence or other physical ID.


NHS England's guidance on identity verification confirms that verification is an important part of protecting patient information, but it expressly recognises different ways in which identity can be established, including documentation, personal vouching and confirmation using information already held within the patient record.


The Information Commissioner's Office (ICO) takes a similarly proportionate approach to subject access requests. Its current guidance states that organisations should be reasonable and proportionate about what they ask for and should only request formal identification documents if necessary.


A useful way for providers to think about the process is therefore to separate two questions:


  1. Does this identity exist?

  2. Are we satisfied that the person making the request is actually that person?


That distinction is also reflected in the Government's current Good Practice Guide 45 (GPG45) on checking identity.


1. Does this identity exist?

When somebody contacts the provider, they are effectively claiming an identity, so they may provide a name, date of birth, address, NHS number or other identifying details.


GPG45 describes this as the claimed identity: the combination of information representing the person somebody is claiming to be. The guidance then distinguishes obtaining evidence about that identity from the later task of checking that the identity actually belongs to the person making the claim.


In healthcare, the clinical record will often help with this first stage.

If somebody gives the provider the name Jane Smith, a date of birth and an address, and those details correspond with an existing patient record, the provider has good evidence that the claimed identity exists.


But that does not necessarily establish that the person standing at reception, sending an email or speaking on the telephone is Jane Smith. This is why simply asking someone to quote a name, date of birth and address may not always be sufficient.


But it is also why the answer is not automatically: "ask everybody for photographic ID."


The next question is whether there is sufficient assurance that the requester is the person represented by that record.


2. Is this actually that person?

This is the part of the process where the provider establishes that the claimed identity belongs to the individual making the request.

GPG45 specifically identifies this as part of the identity-checking process: checking that the identity belongs to the person claiming it.

In healthcare, there may already be several sources of assurance available.


Personal recognition and vouching

NHS England specifically recognises personal vouching as an acceptable means of confirming identity.

Its guidance says staff can personally vouch for a patient whom they know, provided they are confident of that person's identity. The method and person vouching should be recorded appropriately.


Our own Kafico protocol takes the same pragmatic approach and includes the example of a patient who does not have ID with them but is recognised by a member of staff, allowing that member of staff to vouch for their identity.


This is an important practical safeguard against identity checking becoming a paperwork exercise, because if a receptionist has known a patient for many years and is confident who they are, requiring that individual to go home and fetch a passport may add very little genuine assurance.


Information already held by the provider

NHS England also says that where a patient is registered but is not personally known to staff, identity can be confirmed using additional security information taken from the patient's record.

Examples given by NHS England include information such as current medication or details of a recent hospital visit or procedure. Staff must, of course, take care not to reveal information from the record while asking the questions.

These are known as knowledge-based checks, using existing provider-held information as potential methods of strengthening confidence in someone's identity.


Established communication routes

Existing contact routes can also contribute to the overall level of assurance so, rather than relying solely upon an unfamiliar email address from which a request has arrived, the provider might contact the patient using a telephone number already recorded within the clinical record.


The important principle is that providers can use the relationships, records and communication mechanisms they already have rather than treating a physical identity document as the only possible evidence.


Physical ID is one method, not the objective

There will certainly be situations in which asking for formal identification is appropriate.


For example:

  • a request arrives from an unfamiliar email address;

  • the patient is not known to staff;

  • details provided by the requester do not correspond comfortably with the clinical record;

  • there are two patients with very similar identifying information;

  • the circumstances create a particular concern about impersonation or inappropriate access; or

  • other attempts to authenticate the requester have not provided sufficient confidence.


In those circumstances documentary evidence may be a sensible way to obtain additional assurance.


It is important to remember that obtaining an ID document is not the objective here, it is to be reasonably satisfied that the person requesting information is who they claim to be.


The ICO is particularly helpful here. Its guidance on subject access requests states that organisations should be reasonable and proportionate about identity checks and should only request formal identification documents where necessary.


It also says that existing verification measures can be used and that, where the requester's identity is obvious, further information is unlikely to be required — particularly where there is an ongoing relationship with the individual.


Use the least intrusive check that gives sufficient assurance

A proportionate process might therefore work like this.


First: establish the claimed identity

Ask the requester for sufficient information to identify the relevant patient record.



Second: consider the assurance you already have

Ask:

  • Is the patient personally known to staff?

  • Are they using an established communication route?

  • Can the provider independently contact them using details already held?

  • Is there other reliable information already available which supports their identity?


If the answer is yes and staff are sufficiently confident, further documentation may add little.


Third: obtain additional assurance where needed

Where there is uncertainty, additional checks can be used.

These might include appropriate knowledge-based questions, independent contact using existing provider-held information, or another suitable authentication method.


Finally: ask for documentary ID where it is necessary

If the provider still cannot obtain sufficient assurance, formal documentary evidence may then be appropriate.


This reflects both the ICO's requirement for proportionality and NHS England's recognition of vouching and record-based authentication as legitimate methods of identity confirmation.


Examples in practice


Scenario 1: a patient known to the provider

A patient comes to reception and asks for a copy of a recent hospital letter.

The receptionist recognises her. She has attended the provider for many years and the details she provides correspond with the correct clinical record.

The provider can therefore answer both questions:


Does this identity exist? Yes — the patient record establishes that.

Are we satisfied this is that person? Yes — a member of staff who knows the patient can personally vouch for her.


NHS England expressly recognises personal vouching as an acceptable method of confirming patient identity.

Requiring that patient to return home and bring back a passport purely because she has requested information is unlikely to provide meaningful additional assurance.


Scenario 2: an unfamiliar email request

An email arrives from an address the provider has never previously recorded.

The sender provides a patient's name, date of birth and address and requests a complete copy of the medical record.


Those details match a patient.

So:

Does the identity exist? Yes.

But:

Do we yet know that the sender is actually that patient? No.


Additional authentication is therefore appropriate.

The provider could, for example, contact the patient through a telephone number already held in the clinical record and ask some questions related to information held in the record.


If that does not provide sufficient assurance, asking for documentary evidence may then be appropriate.

The important point is that the level of checking responds to the risk and uncertainty in the particular situation, rather than being identical for every request.


Identity and authority are not the same thing

There is one further distinction providers should keep in mind.

Even where the provider knows exactly who the requester is, that does not automatically mean the person is entitled to receive the information they are requesting - for example, Power of Attorney or consent from the patient.


Why we would not recommend a blanket "physical ID required" notice

Against this background, we would advise providers against insisting on ID for all requests for information as this goes beyond what the current guidance requires.


A blanket requirement could also create an unnecessary obstacle for patients who do not routinely carry photographic ID or who do not have a passport or driving licence.

Interestingly, the NHS does not require patients to produce ID even when registering with a GP practice.

It would therefore be difficult to justify treating possession of a physical identity document as the universal gateway to subsequently exercising information rights.


Sources




Emma Cooper, Healthcare Privacy Nerd
Emma Cooper, Healthcare Privacy Nerd

 
 
 

Comments


00011-2939233035.png

DID YOU FIND THIS USEFUL?

Join our mailing list to get practical insights on ISO 27001, AI, and data protection; No fluff, just useful stuff.

You can unsubscribe at any time. You are welcome to read our Privacy Policy

bottom of page