A fine gets an appeal. A child gets ‘have regard to.’

ADVOCACY · 18 July 2026

Advocacy — Health Bill

The Health Bill creates a single patient record for England. It sets out in detail how information will be compelled into that record, and how failure to comply will be punished. It says almost nothing about who may look at it, or what a patient can do about it.

There are two halves to the clause that creates the single patient record. Read them next to each other.

The first deals with the record itself. It allows regulations to provide that the processing of information “does not breach any obligation of confidence owed by the person processing the information”. It allows information to be made available “to people other than a patient on the patient’s behalf” — and says nothing at all about who those people are, how they come to hold that access, or how a patient might limit or end it.

The safeguard attached to all of this is that the Secretary of State, in making the regulations, must “have regard to the need to ensure that adequate safeguards are in place to prevent the improper use of information”.

The second deals with money. Where a financial penalty is to be imposed for failing to comply, the regulations must provide for a written notice of intent, an opportunity to make representations, a decision, a final notice, and a right of appeal to the First-tier Tribunal. Every step is specified. Every one of them is mandatory. And the person on the receiving end can enforce them.

The person facing a fine is given a procedure. The patient facing disclosure is given a state of mind.

This is not a rhetorical trick, and it is not a comparison drawn from opposite ends of the statute book. Both provisions sit in the same clause of the same Bill, inserted into the same Act, drafted by the same hand in the same week. One assumes that the person affected is owed enforceable procedural protection. The other assumes that ministerial judgement is enough.

The record is a good idea

It is worth being plain about this, because the argument that follows is not an argument against the single patient record.

Fragmented records kill people. A clinician who cannot see what a patient has been prescribed, or what they were treated for last year, or what they are allergic to, makes worse decisions — and makes them faster and under more pressure than anyone would choose. The case for a record that follows the patient is a strong one, and it is a clinical case, not an administrative one.

Nothing here asks for information to be deleted, hidden from a treating clinician who needs it, or withheld where a patient’s safety depends on it being seen. The request is narrower and more ordinary than that: that the same care taken over notices and appeals for those facing penalties be taken over access and restriction for patients. Not concealment. Differentiated access — which is what every clinical record system already does, and what the Department has said it intends to build.

What is missing

The clause does not require role-based access, so nothing on the face of the Bill limits what any given professional can see to what their involvement in a patient’s care actually requires. It does not require an audit trail, so nothing guarantees that a record is kept of who looked, still less that a patient can ever see it. And it gives a patient no mechanism at all to restrict routine access to information they have particular reason to protect.

These things may well appear in the regulations. Ministers have said, in terms, that the record is expected to operate role-based access control with an audit trail, that clinicians will be able to redact information too sensitive to share, and that access by someone acting on a patient’s behalf will be set out in regulations, on the patient’s consent and involvement.

Every one of those statements is welcome. Not one of them is in the Bill.

An assurance given at the despatch box binds the minister who gives it for as long as they hold the office. A provision in a statute binds whoever comes next.

And these safeguards were not merely left out. On 2 July the committee divided on an amendment that would have required, before any regulations could be made, a published plan setting out technical controls limiting access to those with a legitimate care relationship, audit logging of every access, sanctions for accessing a record without lawful authority, and an enforcement role for the Care Quality Commission and the Information Commissioner. It was defeated. A second amendment, requiring patients to be told what the record is, who could see it, how to object to or restrict access, and how to view a record of who had looked at their data, was defeated too. The clause was then agreed unchanged.

The gap for children is specific

The words child, young person, competence and capacity do not appear anywhere in the clause. The word “child” appears once within it — as part of “childbirth”, in the definition of social care.

This matters because the clause permits information to be made available to people other than the patient, on the patient’s behalf. For most children, most of the time, the person exercising that access will be a parent, and that is exactly right and entirely unremarkable. Parents should be able to manage their children’s healthcare.

But the law has understood for decades that a young person’s confidence is sometimes owed to the young person themselves. A sixteen-year-old seeking contraception, a fourteen-year-old disclosing what happens at home, a young person being treated for an eating disorder or self-harm, a teenager asking about drugs or alcohol or a sexually transmitted infection — in each of these cases, confidentiality is not a courtesy extended to the patient. It is the condition on which they come through the door at all.

The Bill does not say what happens to any of them. It does not say at what age or in what circumstances access on a patient’s behalf is reviewed or withdrawn. It does not say whether a competent young person can ask for anything to be restricted, or to whom they would ask, or on what grounds it could be refused. It does not say whether they could make that request privately, without it travelling through the very household it concerns.

The question of whether a patient can consent to part of the record being shared but not the whole was put directly to the Minister during the Bill’s committee stage. The answer was that this is an enabling power, and the detail will be brought forward in regulations. The question was asked. The Bill does not answer it.

Silence is not neutral

There is a particular failure mode worth naming, because it is the one that catches people who have done nothing wrong and taken every precaution.

A record does not have to state something for it to be disclosed. Appointment histories, clinic names, prescribing data, correspondence headers and referral routes all carry information, and often carry it more legibly than the notes themselves. A restriction that hides a diagnosis but leaves the pathway visible has protected no one. Nor has a system that announces, to the person a patient is protecting themselves from, that a restriction has been applied.

None of this is exotic. It is the ordinary design problem of any system that holds sensitive information about people who are not always safe. It has known solutions, and they work — but only if someone is required to build them.

The clause requires nobody to build them.

The statutory guardian said so first

This is not a point invented from outside. The National Data Guardian — the statutory office-holder responsible for patient confidentiality in the health and care system — told the committee that the power to set aside the duty of confidence should be removed, warning that lifting that duty wholesale from the Government’s flagship record risks eroding the culture of confidentiality within care relationships. She added that she would also support replacing it with a much narrower provision, lifting the duty solely for the supply of information into the record and leaving everything that happens afterwards subject to the ordinary law of confidence.

The amendment to remove the provision was tabled. It was not moved. Her narrower alternative was never tabled by anyone, and the clause left committee unchanged.

What would fix it

Rather less than the length of this argument might suggest.

A new clause would require the regulations under the single patient record power to provide for access limited to what is necessary and proportionate for a professional’s involvement in a patient’s care; for an auditable record of access, with intelligible information from it ordinarily available to the patient; for a mechanism by which a patient can seek restriction of routine access to sensitive information, exercisable personally and confidentially by a young person able to exercise it; and for access on a patient’s behalf to be granted, scoped, reviewed and withdrawn according to stated criteria. It would preserve access where necessary for safe care, safeguarding or the prevention of serious harm, and would not touch disclosures required by law or by a court.

It would not delay the record. It would not require the Department to abandon a single stated policy. Where a safeguard is already the Government’s intention, putting it in the Bill cannot frustrate that intention — it secures it.

The drafted text is set out at paragraph 17 of our written evidence to the Public Bill Committee, published on the parliamentary record as HB130. It is available to any member who wishes to use it, and we will provide it in whatever form is useful.

A record that patients do not trust does not become a smaller record. It becomes an incomplete one that still looks comprehensive — which is more dangerous to the clinician reading it than an obvious gap would be. Confidentiality is not a constraint on the single patient record. For some patients, it is the condition of the record working at all.

Eden Openly’s written evidence on the single patient record is published by Parliament as HB130. The statutory text quoted here is from the Health Bill as amended in Committee (Bill 131), at new sections 250E and 250F of the National Health Service Act 2006. Eden Openly receives no funding from, and has no commercial relationship with, any provider of gender-related healthcare, any pharmaceutical company, or any supplier of NHS digital systems.

Version history. v1.0, 18 July 2026 — first published. v1.1, 20 July 2026 — now records that amendments requiring access controls and audit logging were put to a division on 2 July 2026 and defeated; and corrects the account of the National Data Guardian’s position, which was that the provision should be removed, her narrower alternative being a replacement she said she would also support and which was never tabled by anyone. The argument is unchanged.

More Advocacy

View all →