- Published
- 17 September 2026
- Last reviewed
- 17 September 2026
- Next review
- 17 September 2027
- Written for
- Pharmacy Assistant
- Topics
- Confidentiality, Data Protection, Professional Conduct
- Practice area
- Community pharmacy
- Level
- Foundation (Level 2)
- Outcome
- Managed by the employer: investigation, retraining and a written warning (within the scenario)
Introduction
Pharmacy teams hold some of the most private information there is. Most confidentiality breaches are not malicious. They start with curiosity or concern. This scenario looks at one of those moments.
What happened?
A dispensing assistant had worked in her local community pharmacy for two years. She noticed that an elderly neighbour, who usually collected his own prescriptions, had not been in for several weeks. She was worried about him.
During a quiet afternoon she opened his patient medication record to see whether anything had changed. She saw that a new medicine had been started and guessed what it was for. That evening she mentioned to another neighbour that he was 'on something for his memory now'.
The comment got back to the patient's daughter, who complained to the pharmacy. The pharmacy's system showed who had opened the record and when. There had been no prescription or query for him that day.
What was the concern?
- The record was opened without a work reason. Being able to open a record is not the same as being allowed to.
- Health information was shared outside the pharmacy with someone who had no right to it.
- The patient lost control of who knew about his health. That can damage trust in the whole pharmacy, and it can stop people being honest with their pharmacy team in future.
- Patient records are audited. Every access leaves a trace.
What was the outcome?
In this scenario the pharmacy investigated under its own procedures. The assistant was open about what she had done and why. The pharmacy recorded the incident, told the patient's family what had happened, considered whether it needed to be reported to the Information Commissioner's Office, and gave the assistant a written warning and refresher training on information governance.
Pharmacy assistants are not registered with the regulator, so matters like this are usually handled by the employer. For a registered pharmacy technician, the same behaviour could also be looked at by the regulator.
What can we learn?
- Only open a record when you need it for the task in front of you.
- Concern for someone is a reason to speak to the pharmacist, not a reason to look. The pharmacist can decide whether a welfare check or a call to the surgery is appropriate.
- Never discuss what you see at work outside work, even in general terms. In a small community, very little detail is needed to identify someone.
- Confidentiality applies to everyone in the pharmacy, registered or not. It is usually written into your contract.
- If you realise you have made a mistake with someone's information, tell the pharmacist straight away. Early reporting matters.
Relevant pharmacy practice
Patient information is protected by the UK General Data Protection Regulation and the Data Protection Act 2018, and by the common law duty of confidentiality. Health information is a special category of personal data and needs extra care. Knowingly obtaining or disclosing personal data without the consent of the organisation responsible for it can be a criminal offence under section 170 of the Data Protection Act 2018.
For registered professionals, Standard 7 of the GPhC standards for pharmacy professionals is to respect and maintain a person's confidentiality and privacy. Pharmacy owners must make sure the whole team, including unregistered staff, understands and follows this.
PPets learning connection
Confidentiality and information governance are core content in the Level 2 Certificate for pharmacy support staff. This scenario works well as the basis for a reflective account.
Reflection questions
- What counts as a work reason to open a patient's record in your role?
- The assistant was worried about her neighbour. What could she have done instead?
- How could a patient be identified from a comment that does not use their name?
- Who is responsible for data protection in your pharmacy, and how would you report a concern?
- How would you feel if you found out someone had looked at your record out of curiosity?
Record this as CPD
Registered pharmacy technicians can use this article towards GPhC revalidation, as an unplanned CPD entry or as the starting point for a reflective account. Pharmacy assistants and trainees can use it as evidence of reflective practice. Note down three things:
- What you learned from this article
- How you have applied it, or will apply it, in your own role
- The benefit to the people who use your pharmacy's services
Sources and further reading
- GPhC guidance on confidentiality
- GPhC standards for pharmacy professionals
- Data Protection Act 2018, section 170
- Information Commissioner's Office: guidance for organisations
Related from PPets
Become a registered pharmacy technician
The PPets Level 3 Diploma is an Open Awards qualification recognised by the GPhC. Study online around your shifts, with assessment in your own pharmacy and unlimited one-to-one support from tutors who are pharmacy technicians themselves.
See the Level 3 coursePractise real conversations before you have them
Pharmacy Counter lets you run over-the-counter consultations with AI customers across 64 scenarios. POM Counselling Trainer scores you against BNF and EMC guidance. Start free, no card needed.
Try the apps freeThis article is for general educational purposes only. It is not legal advice, professional regulatory advice or clinical advice about an individual patient. Always follow your pharmacy's SOPs and check current official guidance and product information.