Council or Board notification · All 18 responsible authorities
Confidentiality in Healthcare Practice for Health Practitioners facing a Council or Board investigation, complaint or allegation
The allegation concerns patient information — shared, seen, sent or said where it should not have been.
- Overheard — a conversation in a corridor, a lift or a shared space
- Records — a record opened without a reason for it
- Shared — information given beyond the team, or without consent
- Whānau — a relative told without the patient’s agreement
- Misdirected — an email, a letter or a result sent to the wrong person
- Online — a photograph, a post or a message about a patient
- Small town — a detail that identified a patient, or a remark that travelled
- Any other — confidentiality or privacy concern, or allegation of a breach
Facing an allegation of a confidentiality breach or misconduct like these — from the Council or Board, a Professional Conduct Committee or the Health Practitioners Disciplinary Tribunal?
Help with a Council or Board investigation, complaint or allegation starts here. This CPD course helps you remediate — and demonstrate the remediation, with a dated certificate for your written response, your portfolio or a Committee or Tribunal direction.
Immediate access · certificate on completion · twelve months' access
- 2 CPD hours
- Self-paced
- Every registered profession
- CPD certificate
- Bulk buy: any 5 for NZ$850 · any 10 for NZ$1,400
At a glance
- Who it is for
- Any registered practitioner facing a Council or Board notification, complaint or allegation, an employer’s investigation, a privacy complaint or a Professional Conduct Committee investigation about patient information — a conversation, a record, a disclosure, an email, a post or a detail that identified a patient
- Authorities covered
- All 18 responsible authorities under the Health Practitioners Competence Assurance Act 2003, their Professional Conduct Committees and the Health Practitioners Disciplinary Tribunal
- Length
- 10 sections, 97 lessons, 2 CPD hours
- Format
- Self-paced, online, immediate access, twelve months from purchase
- Certificate
- Issued by Healthcare Ethics Courses on completion, dated, with the course title and 2 CPD hours
- Price
- NZ$200 · any 5 for NZ$850 · any 10 for NZ$1,400
Certificate issued by Healthcare Ethics CoursesRemediation courses for regulatory processes.
Who this course is for
Facing an allegation that patient information was shared
The letter says a conversation was overheard, a record was opened without a reason, information went beyond the team, a relative was told, an email went to the wrong address, something was posted. The Tribunal has censured and suspended a nurse for opening records she had no part in; this course is how you account for the breach — and show what now prevents the next one.
An access audit has found something
A record opened without a clinical reason — a neighbour, a colleague, a relative, a name in the news — and the system logged it. Say so before the audit does, with the reason given plainly and the access now controlled; the authorities read an access breach owned early very differently from one that was found, and the course covers appropriate access and what to do when the file has already been opened.
An employer has opened an investigation
A patient’s complaint to the practice, a misdirected result, a post reported by a colleague. The employer notifies your Council or Board in defined circumstances, and the privacy process can run alongside; the immediate response — contain, assess, tell the patient, notify where required, record — serves every process at once, and the course gives it a lesson of its own.
A privacy complaint, and your Council or Board
The patient has gone to the Privacy Commissioner, or the breach was notifiable under the Privacy Act, and the authority reads the same breach against its own standard as conduct. The course covers how the two routes interact and the one response that answers both.
A complaint with the Health and Disability Commissioner
A complaint about a patient’s care goes to the Commissioner first, and your Council or Board can act on public safety meanwhile. The Commissioner’s usual recommendations — an apology, an audit repeated after an interval, a written reflection, training — are the remediation this course is built for.
Before a Professional Conduct Committee
Members of your own profession and a layperson, with a legal adviser, investigate independently, read your response beside the record and every statement you have given, and usually meet you. They can recommend counselling or a review, decide on no further action or conciliation, or lay a charge before the Tribunal.
The concerns this course speaks to
A conversation in the wrong place
A handover in a corridor, a phone call in a waiting room, a case discussed in a lift, a video consultation from a shared space, a name said across a counter. The course opens with everyday practice because the breach is situational, and the remediation is concrete: the space changed, the habit changed, the team told.
A record opened without a reason
A neighbour, a colleague, a relative, a name in the news, your own family. Electronic systems log every access and employers audit them; a nurse who opened one patient’s records sixteen times without any part in her care was found guilty of professional misconduct, censured, suspended for three months and directed to privacy training. The course covers appropriate access, the need-to-know test and what to do when the file has already been opened.
Information shared beyond the team
A diagnosis mentioned to a colleague not involved in the care, a result given to an employer, a letter copied to someone who did not need it, a disclosure without consent that no exception covered. Implied consent reaches the care team and no further; the course sets out consent, disclosure and the exceptions — a serious threat, a legal requirement — and how each is justified in the record.
Whānau, family and friends
A relative who asked and was told, a partner updated without the patient asked, a friend of the family reassured. Partnership with whānau under Te Tiriti o Waitangi is a standard every authority sets, and it is not the same as disclosure: the patient decides what is shared and with whom. The course gives confidentiality and whānau involvement their own lesson.
A misdirected email, letter or result
The wrong address, the wrong patient’s result, the attachment that should not have been, the letter in the wrong envelope. The Privacy Act requires a breach likely to cause serious harm to be notified, and the immediate response — recall, retrieve, assess, tell the patient, notify, record — is the first thing every reader looks for.
Digital systems and social media
A photograph taken on a phone, a case described in a post a community could identify, a patient messaged from a personal account, a screen left open, a group chat. The course gives electronic records, digital systems and social media a section, because the record is permanent and the reach is unknown.
Small communities and recognisability
A detail — a role, a place, an event — that identified a patient without a name; a remark outside work that travelled; a patient who is also a neighbour. Confidentiality protects against recognition, not only against naming, and for many New Zealand practitioners this is where it is tested. The course gives small communities and recognisability a lesson.
Probity, intent and any other concern
Information disclosed deliberately, for gain or out of spite; a breach denied until the audit log was produced; an account of who was told that did not match the record. The Tribunal weighs the purpose of a disclosure, its reach and the practitioner’s insight into it, and has cancelled registration for the misuse of patient information. Any confidentiality allegation is measured against your own authority’s standard and the Health Information Privacy Code.
Facing a Council or Board investigation, complaint or allegation? This course helps you remediate — and demonstrate it.
Buy this course — NZ$200What the course covers
Ten sections and 97 lessons, with a reflective quiz closing each of the first nine and a post-course assessment at the end.
Introduction to Confidentiality in Healthcare
Ten lessons
What Information Is Confidential
Eleven lessons
Confidentiality in Everyday Clinical Practice
Eleven lessons
Sharing Information Within Healthcare Teams
Ten lessons
Confidentiality, Consent, and Disclosure
Ten lessons
Electronic Records, Digital Systems, and Social Media
Ten lessons
Confidentiality Breaches, Complaints, and Investigations
Eleven lessons
Regulatory Expectations and Fitness to Practise
Eleven lessons
Reflection, Insight, and Remediation After Confidentiality Breaches
Eleven lessons
Conclusion and Key Takeaways
Key takeaways and the post-course assessment
Show every lesson title
- Section 01 · Introduction to Confidentiality in Healthcare
- What Confidentiality Means in Healthcare Practice; Why Confidentiality Is Fundamental to Patient Trust; Confidentiality as a Professional, Not Just Legal, Duty; The Scope of Confidentiality Across Healthcare Settings; Intentional and Unintentional Breaches; Confidentiality, Power, and Vulnerability; Professional Expectations in New Zealand; Confidentiality in the Modern Healthcare Environment; Why Confidentiality Issues Escalate Quickly; The Purpose of This Course.
- Section 02 · What Information Is Confidential
- The Broad Scope of Confidential Information in Healthcare; Identifiable Patient Information; Clinical Information and Health Data; Administrative and Demographic Information; Verbal Information and Informal Communication; Visual Information and Observations; Information About Colleagues and Third Parties; Information Learned Outside Formal Care; Aggregated, Anonymised, and Educational Information; Regulatory Expectations in New Zealand; Consequences of Misunderstanding Confidentiality.
- Section 03 · Confidentiality in Everyday Clinical Practice
- Applying Confidentiality Principles in Day-to-Day Care; Conversations in Clinical and Non-Clinical Spaces; Telephone and Video Consultations; Accessing Patient Records Appropriately; Discussing Patients With Colleagues; Teaching, Training, and Case Discussions; Small Communities and Recognisability; Handling Information From Family, Friends, or Whānau; Managing Time Pressure and Workload; Responding Immediately to Near Misses; Professional Expectations in New Zealand.
- Section 04 · Sharing Information Within Healthcare Teams
- Why Information Sharing Is Necessary — and Risky; The "Need-to-Know" Principle; Multidisciplinary Team (MDT) Discussions; Informal Conversations Between Colleagues; Handovers and Transitions of Care; Sharing Information Across Services and Organisations; Seniority, Authority, and Information Requests; Access to Records by Non-Clinical Staff; Documenting Information Sharing; Regulatory Expectations in New Zealand.
- Section 05 · Confidentiality, Consent, and Disclosure
- The Relationship Between Confidentiality and Consent; What Valid Consent to Share Information Looks Like; Implied Consent in Healthcare Practice; When Consent Is Absent, Unclear, or Withdrawn; Disclosure Without Consent: Exceptional Circumstances; Safeguarding and Public Interest Disclosures; Confidentiality and Whānau Involvement; Disclosure to Employers, Agencies, or Third Parties; Documenting Consent and Disclosure Decisions; Regulatory Expectations in New Zealand.
- Section 06 · Electronic Records, Digital Systems, and Social Media
- Why Digital Confidentiality Requires Heightened Vigilance; Electronic Health Records and "Need-to-Know" Access; Working Remotely and Using Mobile Devices; Emails, Messaging, and Informal Digital Communication; Copying, Forwarding, and Sharing Digital Information; Social Media and Online Platforms; Photographs, Images, and Video; Data Breaches, Near Misses, and Immediate Action; Regulatory Expectations in New Zealand; Preventing Digital Confidentiality Breaches.
- Section 07 · Confidentiality Breaches, Complaints, and Investigations
- How Confidentiality Breaches Commonly Occur; Recognising What Counts as a Breach; Immediate Response to a Breach or Near Miss; Patient Complaints Arising From Confidentiality Issues; Employer Investigations Into Confidentiality Breaches; Regulatory Investigations and Confidentiality; Patterns, Severity, and Escalation; Documentation and Evidence in Investigations; Professional Behaviour During Investigations; Possible Outcomes Following Confidentiality Breaches; Learning From Confidentiality Incidents.
- Section 08 · Regulatory Expectations and Fitness to Practise
- Why Confidentiality Is a Core Regulatory Priority; Confidentiality and Public Confidence in Healthcare; When Confidentiality Issues Escalate to Regulators; What "Fitness to Practise" Means in Confidentiality Cases; How Regulators Assess Confidentiality in Practice; Insight as the Decisive Regulatory Factor; Professional Behaviour During Regulatory Processes; Confidentiality Breaches as Stand-Alone Conduct Issues; Possible Regulatory Outcomes in Confidentiality Cases; Early Action and Risk Reduction; Regulatory Expectations in New Zealand.
- Section 09 · Reflection, Insight, and Remediation After Confidentiality Breaches
- Why Reflection Is Essential After Confidentiality Breaches; What Regulators Mean by "Insight" in Confidentiality Cases; Reflecting on the Root Causes of the Breach; Reflecting on Patient and Whānau Impact; Linking the Breach to Professional Standards; From Reflection to Remediation: Why Action Is Required; Examples of Robust Remediation After Confidentiality Breaches; Demonstrating Remediation to Employers and Regulators; Timing and Proactivity in Remediation; Rebuilding Trust After Confidentiality Breaches; Reflection and Remediation as Ongoing Professional Skills.
- Section 10 · Conclusion and Key Takeaways
- Conclusion; Key Takeaways.
How to respond to a Council or Board notification, complaint or allegation
Every Council or Board, an employer, the privacy process, a Professional Conduct Committee and the Tribunal read a confidentiality response for the same four things, in the same order. The course teaches each.
What you did the moment you knew is read before what you knew.
- What was disclosed, to whom, how and whyIn order and in the first person: the information, the recipient, the medium, the basis you believed you had, and the standard you now know applied — named from your authority’s document and the Privacy Code.The course sets every authority’s confidentiality clause beside the Code’s rules.
- What you did the moment you knewContained, assessed, the patient told, notified where the Privacy Act required it, the employer told, all of it recorded with times — or, if not, why not and what has been done since.The course gives the immediate response a lesson in the everyday section and again in the breach section.
- The effect on the patient and whānauIn their terms: the exposure, the trust, the community that now knows, the decision taken out of their hands.The course shows how a breach reads from the patient’s side.
- What has changed, with evidenceAn access audit of your own records use, a protocol now followed, training on the Code, supervision where the breach was a pattern, near misses now reported.This course is the dated item you attach — and it names the other tools.
Confidentiality protects against recognition, not only against naming.
Take advice from your indemnity insurer, your union or a lawyer before you respond to anyone.
Facing a Council or Board investigation, complaint or allegation? This course helps you remediate — and demonstrate it.
Buy this course — NZ$200How this course helps with a Council or Board investigation
What is confidential, where it leaks, how it is shared safely, and the response and remediation that answer a breach.
It works through everyday practice and team sharing
Conversations in shared spaces, telephone and video consultations, records open on screens, the handover, the waiting room; the need-to-know test for sharing within a team; implied consent and its limits; and confidentiality and whānau involvement. The sections an overheard conversation, an access audit or a relative told are answered from.
It covers consent, disclosure and digital systems
The relationship between confidentiality and consent; valid and implied consent to share; absent, unclear or withdrawn consent; disclosure without consent in exceptional circumstances; safeguarding and public-interest disclosure; whānau involvement; disclosure to employers, agencies and third parties; and documenting the decision. Then electronic records and need-to-know access, remote working and mobile devices, email and messaging, copying and forwarding, social media, photographs and video, and the immediate response to a data breach or a near miss.
It explains the investigation and the authorities’ expectations
How breaches commonly occur, what counts as a breach, the immediate response, patient complaints, employer investigations, regulatory investigations, patterns and severity, documentation and evidence, conduct during an investigation, the possible outcomes, and learning from incidents. Then why confidentiality is a core regulatory priority, what fitness to practise means in a confidentiality case, how the authorities assess it, insight as the decisive factor, and early action.
It brings it to reflection and remediation
The reflection a confidentiality matter needs — who could hear, who was affected, what you did the moment you knew — and robust remediation: the disclosure to the patient, the access audit, the protocol, the training, the supervision, the near miss reported. Counts: the disclosure to the patient, made and recorded; an access audit of your own records use, repeated after an interval; a protocol for the space, the system or the conversation concerned, now followed; training on the Health Information Privacy Code with a reflection on what changed; this course’s dated certificate; supervision with reports where the breach was a pattern; near misses now reported. Counts for little: a statement that no harm was done, a breach explained by the system or the workload, a record of the conversation written up later, hours on another subject. For the stages from the first letter to the Tribunal, see the Council and Board investigation process, explained.
Read the primary sources
- Health Practitioners Competence Assurance Act 2003 — the Act
- Every Council and Board, in one place — Responsible authorities
- Privacy Act 2020 and the Health Information Privacy Code 2020
- Medical Council — Good medical practice
- Nursing Council — Code of Conduct
- Pharmacy Council — Code of Ethics 2018
- Health Practitioners Disciplinary Tribunal — decisions
Who wrote it
In short
Confidentiality in Healthcare Practice is a two-hour remediation course, self-paced, for any practitioner facing a notification, investigation, complaint or allegation before one of New Zealand’s 18 responsible authorities. It treats confidentiality as a professional duty governed alongside the Privacy Act 2020 and the Health Information Privacy Code, defines broadly what is confidential, and works through the places information leaks in everyday practice: conversations, records access, team sharing, whānau and family, small communities, and digital systems. It covers consent and disclosure, the immediate response to a breach or a near miss, patient complaints and employer and regulatory investigations, what fitness to practise means in a confidentiality case, and the reflection, insight and remediation that answer a breach. Ten sections with a reflective quiz after each of the first nine, a post-course assessment, and a dated certificate from Healthcare Ethics Courses for your recertification. Remediation, not advice: the course decides no matter, and your indemnity insurer, your union or association or a lawyer should read anything before it goes to your authority.
What New Zealand’s Councils and Boards mean by confidentiality
Confidentiality is governed twice over, and the two systems ask the same questions. Every authority’s standard of ethical conduct under section 118 of the Act requires a practitioner to keep patient information confidential and to share it only on a proper basis, and treats a breach as conduct. Alongside runs the Privacy Act 2020 and the Health Information Privacy Code 2020, which set the rules for collecting, holding, using and disclosing health information, require serious breaches to be notified, and give a patient a route of their own; the Privacy Commissioner reported breach notifications up 26.5% and serious-harm notifications up 43% between 2023/24 and 2024/25. A confidentiality concern can therefore arrive by either route, and the course treats both.
Two things are New Zealand-specific. The first is whānau and community: partnership with whānau under Te Tiriti o Waitangi is a standard every authority sets, and it is not the same as disclosure — the patient decides what is shared — while in a small community a detail can identify a patient and a remark can travel, so the course gives both their own lessons. The second is the notifiable breach: under the Privacy Act a breach likely to cause serious harm must be notified, and the immediate response to a breach or a near miss — contain, assess, tell the patient, notify where required, record — is the first thing every reader looks for.
The confidentiality clause in each code
Same duty, different numbering. Cite the one your own Council or Board uses.
What these words mean
The three terms that decide where a matter goes, and the other words the course uses.
- Professional Conduct Committee
- The committee the Council or Board appoints under s 71 of the Act to investigate a conduct concern: two members of the profession and a layperson with a legal adviser. It asks for your written response, may hear from you, and recommends anything from no further action, through counselling and a competence or health review, to a charge before the Tribunal (s 80).
- Professional misconduct
- The Tribunal’s ground under s 100 of the Act: malpractice or negligence in your scope of practice, or conduct that has brought or was likely to bring discredit to the profession. Dishonesty, a boundary breach and a breach of confidence are among the findings made under it.
- Health Information Privacy Code
- The code under the Privacy Act 2020 that sets the rules for collecting, holding, using and disclosing health information in New Zealand. The legal duty that runs beside the professional one, with its own route for a patient.
- The three routes under the HPCA Act
- Fitness to practise is the phrase practitioners use for the whole process. Under the Health Practitioners Competence Assurance Act 2003 the Council or Board takes one of three routes: a competence review (your practice against the required standard); the health process — the Act’s fitness to practise provisions, for impairment by a mental or physical condition; or a referral of your conduct to a Professional Conduct Committee, which can lay a charge of professional misconduct before the Tribunal. Which route your letter names tells you how the matter is being treated.
Need to know, implied consent, disclosure without consent, notifiable privacy breach, recognisability and the other terms the course uses
- Confidentiality
- The professional duty to keep patient information private and to share it only on a proper basis. Required by every authority’s standard, treated as conduct when breached, and running alongside the privacy law.
- Need to know
- The principle that information is shared with, and records are opened by, only those who need it for the patient’s care. The test for team sharing and for every access an electronic system logs.
- Implied consent
- The consent to share information within a care team that a patient gives by accepting care, limited to what that care requires. Not consent to share beyond the team, with whānau, or for another purpose.
- Disclosure without consent
- Sharing information where the law or the standard permits it without the patient’s agreement: a serious threat to someone’s safety, a legal requirement, safeguarding. Exceptional, justified in the record, and told to the patient where it can be.
- Notifiable privacy breach
- A breach that is likely to cause serious harm, which the Privacy Act requires to be notified. The step in an immediate response that a practitioner must know exists.
- Near miss
- A disclosure that nearly happened, or happened and was caught before harm — the wrong recipient noticed, the file closed, the conversation stopped. Reported and learned from, the simplest evidence of a confidential practice.
- Recognisability
- The way a patient can be identified from a detail rather than a name — a role, a place, an event — especially in a small community. Confidentiality protects against recognition, not only against naming.
- Remediation
- Change someone else can confirm: the disclosure to the patient, an access audit, a protocol now followed, training delivered, supervision with reports, and near misses now reported. What every review of a confidentiality matter reads for.
The provisions a confidentiality concern engages
Confidentiality in New Zealand is governed twice over: by each authority’s standards, which treat a breach as conduct, and by the Privacy Act 2020 and the Health Information Privacy Code 2020, which the Privacy Commissioner enforces. These are the provisions of the Health Practitioners Competence Assurance Act 2003 a confidentiality concern runs under, the privacy law, and the standards.
Privacy Act 2020 and the Health Information Privacy Code 2020
The Privacy Commissioner administers both; the Code sets the twelve rules for health information, from collection to disclosure and correction, requires a breach likely to cause serious harm to be notified, and gives a patient a route that runs alongside a Council or Board process rather than instead of it. Read it.
For this course: The Health Information Privacy Code is the law a confidentiality concern is measured against, and the course reads its rules on collection, use and disclosure one by one.
Section 71 — referral to a Professional Conduct Committee
Where the concern is about conduct the authority refers it to a Professional Conduct Committee — two members of the profession and a layperson, with a legal adviser — which investigates independently and asks for your written response. A confidentiality breach is a conduct concern, and the Committee reads what was disclosed, to whom, and on what authority. Read it.
For this course: A confidentiality breach is a conduct matter for a Committee, and the course explains what the Committee’s investigation will look at.
Section 100 — the grounds of discipline
The Tribunal may discipline for professional misconduct — malpractice or negligence, or conduct likely to bring discredit to the profession. A deliberate disclosure is charged on that ground; the Tribunal has cancelled registration for the misuse of patient information and suspended a nurse for records opened without a reason. Read it.
For this course: A serious or deliberate breach reaches the threshold of discipline, and the course explains how seriousness has been judged.
Section 101 — the penalties
Censure, conditions, suspension for up to three years, cancellation of registration, a fine of up to NZ$30,000 and costs. The Tribunal weighs the purpose of the disclosure, its reach and the practitioner’s insight into it when it chooses among them, and has directed training in ethics and patient privacy as a condition of return. Read it.
For this course: The Tribunal’s penalties in confidentiality cases weigh intent, reach and remedy, and the course teaches the remedy.
Also engaged: Section 118 — every authority’s standard contains a confidentiality duty and names the exceptions · Section 80 — counselling or a review where the breach was inadvertent and understood; a charge where it was deliberate · Medical Council — the statements on confidentiality and on patient records · Nursing Council — the Code’s confidentiality principle and the social media guidelines · Pharmacy Council — the Code of Ethics’ principle on confidentiality.
What happens after a confidentiality complaint reaches your Council or Board
The same stages under one Act, whichever authority registers you, with the privacy process alongside — and at every one the reader asks the same question: what did this practitioner do the moment they knew, and what now prevents the next one?
The patient, the employer, the audit or the privacy process: where it starts
A patient learns that their information was shared, an access audit flags a record opened without a reason, an email goes to the wrong address, a post is seen. A complaint goes to the practice, the employer, the Privacy Commissioner, the Health and Disability Commissioner or your Council or Board; the employer notifies the authority in defined circumstances, and the privacy process can run alongside.
The immediate response — and what the Registrar reads first
Contain it, assess who has what, tell the patient, notify where the Privacy Act requires it, tell your employer, record all of it with times. The Registrar or a delegated committee reads your response beside the patient’s account and the audit, and asks what you did the moment you knew. A breach contained, disclosed to the patient and remediated can end the matter with an educational letter.
A competence review
Where the breach reflects a practice in which information is not handled as the Code requires — records open on screens, conversations in shared spaces, results sent without a check — the authority may review your practice against the standards for your scope and order a programme, conditions or supervision, answered by a protocol and an audit.
The health route
Where a condition lay beneath the breach — the curiosity, the lapse, the message sent in distress — and was declared, the authority may deal with it under its health route, with support. A declaration made now, with a plan behind it, moves the matter toward it.
A Professional Conduct Committee
Members of your profession and a layperson, with a legal adviser, read what was disclosed, to whom, how and on what authority, beside the record, the audit log and your response, and meet you. They ask whether you understood who could hear and who was affected, whether the patient has been told, and what now prevents the next one. Counselling and a review are their options where the breach was inadvertent and understood; a charge follows a deliberate disclosure.
The Tribunal
A legally qualified chair, three members of your profession and a layperson hear the charge, usually in public. A nurse who opened the records of a patient she had no part in caring for sixteen times was censured, suspended for three months and directed to privacy training; the Tribunal weighs the purpose of a disclosure, its reach and the practitioner’s insight into it when it chooses a penalty, and any order is reviewed against what has changed.
Facing a Council or Board investigation, complaint or allegation? This course helps you remediate — and demonstrate it.
Buy this course — NZ$200This course is written for every registered profession under the Health Practitioners Competence Assurance Act 2003 — the process is the same for all. Ten professions also have Ethics and Professionalism courses written to their own Council or Board’s standard. Find the courses for your profession →
Frequently asked questions
What is the immediate response to a breach?
Contain it — recall the email, retrieve the letter, close the file; assess who has what and what harm could follow; tell the patient; notify where the Privacy Act requires it and tell your employer; and record all of it with times. The course treats the immediate response as the first thing every reader looks for, and gives it a lesson in the everyday-practice section and again in the breach section.
What should my written response contain?
What was disclosed, to whom, how and why, in order and in the first person; the basis you believed you had and the standard you now know applied, named from your authority’s own document and the Privacy Code; what you did the moment you knew; the effect on the patient and whānau in their terms; and what has changed — the access audit, the protocol, the training, the supervision — with dates. The course’s ninth section covers each part.
What does remediation look like after a breach — and will my Council or Board accept this course as part of it?
The disclosure to the patient, made and recorded; an access audit of your own records use, repeated; a protocol for the space, the system or the conversation concerned, now followed; training on the Health Information Privacy Code; supervision with reports where the breach was a pattern; and near misses reported from now on. Each is concrete, and the Tribunal has itself directed privacy training as a condition of return. No provider is accredited by any Council or Board, and no course decides a matter. What every authority, a Committee and the Tribunal weigh is dated, targeted remediation with reflection that engages your own code — and this course is written to the ground every authority’s standard shares on this subject, so the connection to yours is plain. The Tribunal has itself directed training in ethics and patient privacy as a condition of returning to practice. Check the wording of any direction with your indemnity insurer, union, professional association or lawyer before you rely on it.
Should I take advice before I respond?
Yes — before anything goes to the patient in writing, your employer, the privacy process, your Council or Board, a Professional Conduct Committee or the Tribunal. Your indemnity insurer, your union or professional association, or a lawyer will read a response before it is sent. Nothing on this page is legal advice, and no course determines the outcome of a matter.
I did not mean to share it. Does that matter to my Council or Board?
It matters to the reading and not to the duty. What the authorities read for is what you did the moment you knew — contained it, told the patient, notified where required, recorded it — and what now prevents the next one. An unintentional breach responded to at once is remediated at once; a deliberate one is charged. The course opens with intentional and unintentional breaches for that reason.
I opened a record I should not have. What happens now?
Say so, before the audit does, with the reason given plainly — curiosity, concern, convenience — and the access now controlled. Electronic systems log every access and employers audit them, so a breach of this kind is usually already known. The authorities read an access breach owned early very differently, and the course covers appropriate access and what to do when the file has already been opened.
A relative asked and I told them. Was that wrong?
Unless the patient had agreed, yes. Whānau involvement is expected and partnership is not the same as disclosure: the patient decides what is shared and with whom. The course gives confidentiality and whānau involvement their own lesson, and the remediation is the conversation with the patient about what they want shared, recorded.
The patient has gone to the Privacy route rather than my Council or Board. Is that different?
It runs alongside. The Privacy Act gives a patient a route of their own, and an employer or the privacy process may notify the authority; the authority reads the same breach against its own standard as conduct. The immediate response, the disclosure to the patient and the remediation serve both, and the course covers how the two interact.
How do I keep confidentiality in a small town where everyone knows everyone?
By protecting against recognition, not only against naming: no cases discussed where a detail could identify a patient, no remark outside work, whānau and friends who ask told that you cannot say, and the record of a patient who is also a neighbour treated like any other. The course gives small communities and recognisability a lesson because for many New Zealand practitioners this is where confidentiality is tested.
How is this different from the Privacy, Consent and Chaperone course?
This course is information: what is confidential, where it leaks, how it is shared, consent and disclosure, digital systems, and the breach. Privacy, Consent and Chaperone is the examination and the consultation: dignity in the room, consent as a process, the chaperone, and boundaries during sensitive care. A practitioner whose concern is a disclosure starts here; one whose concern is an examination takes the other.
Which Council or Board is this course written for?
All eighteen. Every authority under the Act requires confidentiality in its standard and treats a breach as conduct, and the Privacy Act and the Health Information Privacy Code apply to every practitioner. The course reads the Medical Council, Nursing Council, Pharmacy Council and Dental Council standards in their own words and the allied professions’ alongside.
How long does it take, and how long do I have access?
The course is 2 CPD hours, self-paced, with twelve months’ access from purchase. The certificate is issued on completion, dated, with the course title and the CPD hours, for a response, a portfolio or your recertification.
Courses that work alongside this one
Notifications rarely raise one issue. These are the courses that pair with this one.
Documentation for Healthcare Professionals
Clinical documentation and health records course for NZ health practitioners facing a notification about records, late entries or amendments. 2 CPD hours.
Social Media Professionalism and Boundaries for Healthcare Professionals
Social media course for NZ health practitioners facing a notification about a post, online contact with a patient, or advertising. 2 CPD hours, NZ$200.
Privacy, Consent and Chaperone in Healthcare Practice
Consent, privacy and the presence of another person during an examination: for NZ practitioners facing an allegation about an examination. 2 CPD hours.
Dealing with a Complaint or Investigation Professionally
Responding to a complaint, notification, competence review or conduct committee in NZ: the first letter, the meeting, what to write. 2 CPD hours.
Insight for Fitness to Practise
Asked to show insight after a notification? The staged model, the four components a Council or Tribunal assesses, and what undermines it. 2 CPD hours.
Remediation for Fitness to Practise
Remediation after a Council or Board notification: root cause not symptom, SMART goals, the seven parts of a written plan, evidence of change. 2 CPD hours.
Professional Boundaries Course
A boundary notification in NZ: where the risk comes from, dual relationships, another person in the room, colleagues and online conduct. 2 CPD hours.
Confidentiality in Healthcare Practice
This course. Conduct, boundaries, records, probity and communication under Good medical practice, and the evidenced remediation that answers a notification.
Start today, finish at your own pace
Immediate access on purchase. Twelve months' access, a dated certificate on completion, and 2 CPD hours issued by Healthcare Ethics Courses.
