top of page
Search
All Posts


They wrote it. You hold it. Is it still in scope of the SAR?
An individual's right of access applies to the personal information that the organisation is processing. The fact that some of that information originated somewhere else does not, by itself, take it outside the scope of the request. We find that there is a surprisingly persistent misunderstanding when our customers respond to subject access requests: “We didn't create that document, so we don't need to disclose it.” But that isn't how subject access works because a patient's
2 days ago4 min read


Do patients need to show ID every time they ask for their information?
It is important to remember that obtaining an ID document is not the objective here, it is to be reasonably satisfied that the person requesting information is who they claim to be. Protecting patient information is fundamental to healthcare, and so before confidential information is disclosed, a provider needs to be satisfied that it is giving that information to the right person. But that does not mean every patient requesting information must automatically produce a passpo
3 days ago6 min read


Microsoft 365 Copilot has arrived for the NHS but what does this mean for providers?
The NHS's procurement and deployment of Microsoft 365 Copilot provides significant central assurance about the product. It does not necessarily tell a provider whether its particular way of using Copilot is appropriate. Microsoft 365 Copilot is beginning to become a much more familiar part of NHS working life. In June 2026, NHS England announced that more than 500,000 NHS staff would be given access to Microsoft 365 Copilot, following a trial involving more than 30,000 staff
Sep 74 min read


Transparency Notices: More Information Does Not Always Mean More Transparency
The aim is not simply to publish a large amount of legal information. It is to help people understand, in a meaningful way, what is happening with their information. A transparency notice, often called a privacy notice, is there to explain, in clear and accessible terms, what an organisation does with personal information. For our customers, this is an important part of UK GDPR compliance. Service users, staff and applicants should be able to understand what information is co
Sep 34 min read


Parental Responsibility Is Not a Right to the Record: Ask What Access Does for the Child
If the parent is not providing care, is not involved in treatment decisions and has no current healthcare role, the benefit to the child may be limited. Parents often assume that if they have parental responsibility, they have a right to see their child’s medical record, which is understandable. . Parental responsibility gives a parent important legal rights and duties in relation to their child. But it does not create an automatic entitlement to information held about that c
Aug 265 min read


When Can a Parent Access Their Child’s Medical Information? Young Person Consent, Gillick Competence and the Grey Area in Between
A parent who has managed every aspect of their child’s healthcare for years does not necessarily become an inappropriate person to deal with simply because the child has reached a particular age. Parents are usually closely involved in their children’s healthcare. They book appointments, request prescriptions, speak to clinicians, manage referrals and, quite often, submit requests for copies of medical records. For younger children, this will rarely cause problems but as chil
Aug 267 min read


When Speech Recognition Becomes a Clinical Safety Risk
A transcription error can become a clinical hazard AI-powered speech recognition is increasingly being used across healthcare in the form ambient voice technology, clinical documentation to triage, call handling and patient-facing tools. Our customers are learning that converting spoken language into structured or written information can save considerable time and reduce administrative burden. But from a clinical safety perspective, we support our customers to ask Who does it
Aug 215 min read


The Children's Wellbeing and Schools Act 2026 – What Does It Mean for Healthcare Providers?
One of the most important safeguards within the legislation is that information should not be shared if the person making the decision reasonably believes that doing so would be more detrimental to the child than not sharing it. If you've spoken to us recently, you'll know this new legislation has been a regular topic of conversation. We've had some fantastic discussions with GP practices, safeguarding teams, DPOs and healthcare professionals, all asking very similar question
Aug 44 min read


Deepfakes: An Increasing Risk for our customers
The strongest protections are controls that prevent a single convincing communication from causing harm. We have written on this topic before but it warrants revisitng. I think deepfakes should now be treated as a medium and increasing risk for sectors like healthcare, finance or IT. The technology is becoming more accessible, convincing and much easier to use. These are not always sophisticated fake videos. In many cases, a cloned voice, manipulated image or impersonation ca
Jul 214 min read


AI Assurance for Clinical Safety Officers - Online Training
While the webinar is designed with Clinical Safety Officers in mind, it is also valuable for CCIOs, CNIOs, Digital Leads, Information Governance professionals, AI Leads and anyone responsible for assuring AI technologies within healthcare. A practical session exploring the governance, legal and information risks associated with AI in healthcare, designed for CSOs 18th August 2026, 12pm to 2pm Online via Teams For Clinical Safety Officers, AI presents new challenges. Traditi
Jul 22 min read


Managing Subject Access Requests in Health and Care
Applying the 'serious harm - health' exemption It is important to remember that the harm exemption is time limited. This article relates only to subject access requests (SARs) made under UK GDPR and the Data Protection Act 2018. It does not cover disclosures made under court orders, police investigations, safeguarding processes, litigation, insurance requests, statutory powers, or any other legal basis for sharing information. A SAR is a request by an individual, or someone
Jul 14 min read


Managing Subject Access Requests in Health and Care
Applying the 'third party confidential ' exemption The ICO makes clear that you should not automatically redact information simply because it mentions another person. This article relates only to subject access requests (SARs) made under UK GDPR and the Data Protection Act 2018. It does not cover disclosures made under court orders, police investigations, safeguarding processes, litigation, insurance requests, statutory powers, or any other legal basis for sharing information
Jun 304 min read


Human Oversight in AI: Why “A Human Reviews It” Is Not Enough
This is the paradox. The more carefully every AI output is reviewed, the less productivity the AI may deliver. The more productivity the AI delivers, the less likely it is that every output is being carefully reviewed. From AI scribes and service user triage to decision support and administrative automation, AI has the potential to reduce workload and improve efficiency for all our customers. However, a very common phrase in supplier materials is: “A human reviews every AI ou
Jun 294 min read


Why Good Suppliers Still Lose Public Sector Tenders
One consequence of widespread AI use is that many tender responses are beginning to sound very similar. Many suppliers assume that if they have a strong product, competitive pricing and relevant experience, they should perform well in public sector procurement exercises. In practice, good suppliers score poorly for reasons that have little to do with the quality of their service. At Kafico, we regularly support organisations assessing suppliers, reviewing governance arrangeme
Jun 203 min read


Preparing Your HealthTech Product for the UK Market: What International Suppliers Need to Know
NHS procurement and healthcare procurement processes place significant emphasis on assurance and governance. For a decade now we have supported our NHS and charity customers to assess HealthTech products before adoption, reviewing supplier assurances, data protection arrangements, AI governance, DPIAs, risk assessments, clinical safety considerations and wider compliance evidence. For many HealthTech and AI suppliers, the UK healthcare market can appear highly attractive. The
Jun 204 min read


What Our Customers Look For When Assessing AI Systems
Many suppliers spend effort trying to prove their AI is accurate, powerful or innovative but in our experience, customers understand that no system is perfect. We support around 150 healthcare, charity and tech customers as their DPO or AI Compliance Lead and perform AI governance assessments routinely. Over the last few years we've worked on both sides of the procurement journey; with organisations developing AI products and trying to bring them to market and with organisati
Jun 204 min read


Lasting Power of Attorney: What Should Care Providers Check?
For healthcare providers, the important point is that not every LPA gives the attorney the same rights. Healthcare providers are often contacted by relatives, carers or attorneys asking for access to a patient / service user information. Sometimes this is straightforward. Sometimes it is not. A Lasting Power of Attorney, often called an LPA, is a legal document that allows someone to make decisions on behalf of another person if they are unable to make those decisions themsel
Jun 194 min read


Health or Care Subject Access Requests from Solicitors: How do we treat them?
A solicitor acting on behalf of a patient is exercising the patient's right of access. The solicitor effectively stands in the patient's shoes. It is common for GP practices or care homes to receive Subject Access Requests (SARs) from solicitors acting on behalf of patients / residents. These requests are often linked to personal injury claims, clinical negligence cases, employment disputes, insurance claims or family court proceedings. A common question we hear is: "Do we pr
Jun 195 min read


The Rise of Digital Coercive Control
"The world in which domestic abuse is perpetrated is changing, but domestic abuse persists at worrying levels. Perpetrators of domestic abuse now routinely use technology and social media to control and instil fear in those they victimise." All-Party Parliamentary Group on Domestic Violence Safeguarding professionals have long been trained to recognise physical abuse, emotional abuse, financial exploitation and coercive control, but digital coercise control is a rapidly growi
Jun 174 min read


Medical Records Are Not Personal Health Records: Managing Increasing Requests to Rewrite Clinical Records
The EHR is not a personal health record, it is a professional record containing personal data We have noticed a big increase in requests to amend, remove or add information to clinical records since the expansion of patient access to online medical records, and while some requests relate to genuine inaccuracies and should be corrected, others are not appropriate and can be tricky to manage for customers. Practices report patients asking for large sections of narrative to be a
Jun 53 min read
bottom of page