Using AI Tools With Patient Information: NHS England Guidance for Staff

NHS England's information governance guidance explains what must happen before AI tools use patient information. Here is what it says for care staff and managers.

Learnsignal Healthcare Education Team
7 min read
Updated

Health and care staff are being asked to work with AI tools in more and more settings. NHS England's information governance (IG) guidance on artificial intelligence sets out the data protection and confidentiality points that apply when those tools use patient information. This guide summarises that guidance for care staff, managers and IG leads. It explains what must happen before an AI tool is introduced, the legal bases that may apply, and what the guidance says individual health and care workers should do. For a specific example of a tool in use, see our guide to AI scribes in health and care settings.

A note on the source: the NHS England page says the guidance has been reviewed by the Health and Care Information Governance Working Group, including the Information Commissioner's Office and the National Data Guardian. The page we reviewed shows no publication or review date, so check the current version on the NHS England website before relying on any detail below.

Start with a data protection impact assessment

The guidance says a data protection impact assessment (DPIA) "must legally be completed prior to implementing AI-based technologies". It describes the DPIA as a way to manage and reduce potential harm, and to support accountability and data protection by design and by default. Our guide to DPIAs for care home technology explains how to carry one out.

Define the purpose and the lawful basis

The guidance says the purpose must be defined and agreed before any processing starts, because the purpose shapes the legal basis. It gives these examples under UK GDPR:

  • For individual care, condition 9(2)(h) (direct care) generally applies, and consent may be implied under common law.
  • For research, condition 9(2)(j) may apply.
  • For public health, condition 9(2)(i) may apply.

Where data is truly anonymous, no legal basis is needed, but staff must assess the risk of re-identification, including from linked datasets. If the purpose changes, the guidance says people must be told before the new processing starts, and a new legal basis, DPIA and privacy notice are needed.

Know who is the controller and who is the processor

The guidance says to establish who the controllers and processors are, and to put contracts and data processing agreements in place that state permitted uses and restrictions. It says health and care organisations should be the controller or joint controller when contracting with technology providers.

Be open with patients and service users

On transparency, the guidance says organisations should be open and honest about the purposes of AI and what will happen to data, and should tell people about new uses of their data before processing starts. It also says to explain the logic simply and clearly, use privacy notices, and provide materials directly where AI is part of a person's treatment.

Use the minimum data

The guidance says to use the minimum data needed for the purpose, and de-identified data where possible. It mentions synthetic data as a possible alternative in early stages of training, but says its use in the NHS is "in its infancy".

Accuracy, clinical safety and fairness

The guidance makes several points that matter for staff who use AI outputs:

  • An AI system does not need to be 100% accurate to comply with data protection law.
  • AI outputs should be recorded in the patient record as predictions, not facts.
  • Systems should be tested rigorously, a clinically acceptable accuracy level should be set, and organisations should check whether the system counts as a medical device under MHRA requirements.
  • Processing should be fair and avoid discrimination, supported by an equality impact assessment.

Security

The guidance lists access controls, audit logs, encryption and restrictions on downloading or exporting data as examples of appropriate measures. It says to record all movement and storage of personal data and to train staff in IG and cyber security.

Automated decisions and human review

Under Article 22 of the UK GDPR, people have the right not to be subject to automated decisions that have legal or similarly significant effects. The guidance says human review must be substantial, not a token gesture, and that a human decision option must always be available.

What the guidance says health and care workers should do

The guidance sets out responsibilities for individual workers:

  • Involve your IG lead, data protection officer and Caldicott Guardian in any decision to introduce AI or share data for AI development. You can also contact the NHS IG Policy Team.
  • Raise concerns about AI results, such as false or inconsistent outputs, through your clinical management route, because these may point to bias or inaccuracy.
  • Make the final care decision with the patient, using professional judgement.
  • Discuss a patient's questions about AI with them, or refer them to your IG lead, data protection officer or Caldicott Guardian.

For how this fits with wider governance in care settings, see our guide to AI in care homes governance.

What the guidance does not cover

The page we reviewed does not mention public generative AI tools, such as free online chatbots, or advise on entering identifiable information into them. If you are unsure whether a tool is approved, ask your IG lead or follow your organisation's own policy. That is our suggestion rather than something the guidance says.

Frequently asked questions

Do we always need a DPIA before using an AI tool?

The guidance says a DPIA must legally be completed before AI-based technologies are implemented.

Does an AI tool have to be perfectly accurate?

No. The guidance says an AI system does not need to be 100% accurate to comply with data protection law, but outputs should be recorded as predictions and systems should be tested against a clinically acceptable level of accuracy.

Who should I talk to if an AI tool gives odd results?

The guidance says to raise concerns through your clinical management route, and to involve your IG lead, data protection officer or Caldicott Guardian where decisions about the tool are being made.

Staff who work with AI and patient information may find our CPD courses useful for building their data protection knowledge. This article is a summary of NHS England guidance and is not legal advice.

This page was last updated:

Learnsignal Healthcare Education Team

The Learnsignal Healthcare Education Team creates CPD and compliance training content for nurses, allied health professionals, and care providers, drawing on current regulatory guidance from bodies including NMBI and equivalent professional regulators.

View all posts by Learnsignal Healthcare Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Learning Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans