PogoWasRight.org

Menu
  • About
  • Privacy
Menu

UK: Insurers using subject access requests to see medical information

Posted on July 31, 2015June 26, 2025 by Dissent

The Information Commissioner has been considering the emerging practice of insurance companies obtaining medical records by using patients’ subject access rights.

We recognise that insurance companies may have a genuine need to review medical information about its customers when providing policies like life and critical illness cover.

To enable this, the Access to Medical Reports Act 1988 gives insurance companies a clear and established legal route to access medical information. The Act also gives appropriate safeguards to patients and respects the confidential relationship between a GP and their patient. Under the Act, a GP can provide a tailored report to an insurer, with their patient’s consent, setting out only the information the insurer needs.

However, some insurance companies have instead been looking to rely on the subject access right given to consumers under the Data Protection Act in order to obtain medical records, rather than a tailored GP’s report.

A subject access request gives an individual the right to ask for all of the personal information an organisation holds about them. This is a powerful right, designed to ensure individuals can access information held about them within a specified time period and at a nominal cost. This right was not designed to underpin the commercial processes of insurers.

By making a subject access request on a patient’s behalf, an insurance company may be provided with a patient’s entire medical record, including information that is not relevant for the purpose of underwriting a policy.

The ICO has recently written to the insurance industry to explain that we consider that the use of subject access rights in this way is inappropriate and an abuse of that right.

We also have concerns that the processing of medical records by insurers once received from GPs is likely to breach the Data Protection Act.

We will be speaking to the insurance sector further to ensure that future use of medical records is in line with the law.

Patients continue to be able to make subject access requests to their GP.

GPs have ethical obligations around how patient records are shared, and we advise GPs to explain to patients, in broad terms, the implications of making a subject access request so they can make a more informed decision on whether they wish to exercise their rights under the Data Protection Act. We also recommend GPs share any responses to subject access requests directly with patients, rather than to insurance companies.

Contrary to comments made by the British Medical Association, GPs must still respond to subject access requests, in accordance with the guidance published on our website. The right to see personal information held about you by an organisation is an important one, and one from which GPs are not exempt. We will be speaking with the British Medical Association again to further clarify this.

SOURCE: U.K. Information Commissioner’s Office Blog

Related posts:

  • California fines hospitals for breaches of medical privacy
Category: BusinessHealthcareNon-U.S.

Post navigation

← Texas to require cameras in some special ed classes
Feds Hand Out Funds To Be Used For ‘Traffic Safety;’ Local Agencies Buy License Plate Readers Instead →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map
  • EPIC Publishes New Whitepaper Detailing Privacy Risks of Government Data Mining Programs
  • Modern cars are spying on you. Here’s what you can do about it.

RSS Recent Posts at DataBreaches.net

  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
©2025 PogoWasRight.org. All rights reserved.