Module 3 of 3 · 50 minutes
Confidentiality, bias and speaking up: using AI without breaking trust
By the end of this module you will be able to
- Say what counts as identifiable information and why a name is not the only thing
- Explain why an unapproved tool is not covered by your organisation's data protection
- Describe what to do if you have already shared identifiable information with a tool
- Give two ways bias can enter an AI tool and an example from clinical practice
- Know how and why to speak up, and how to use this learning for revalidation
Work through it
1 interactive for this module, built on the WAJD Teach engine. Nothing moves until you ask it to, and every one has a written version if you would rather read it.
Watch: Emma and George talk it through
4 minutes. Captions are on, and the same conversation is written out in full below. The voices are computer generated.
Emma George, I'll confess something. Last month I pasted a messy handover into a free AI tool to tidy it up. No names. Is that all right?
George I'm glad you said it, because you're far from alone. And no, probably not. Two questions. Had your organisation approved that tool for that use? And was it really anonymous?
Emma Not approved, as far as I know. And I took the name out.
George Take the first one. An approved tool has been assessed. There's an impact assessment, a contract saying what the supplier may do with the information, a safety case. A free tool you found yourself has none of that, and its terms may allow your input to be kept or used. Your organisation's data protection doesn't extend to it.
Emma People call that shadow AI, don't they?
George They do, and it's the risk that's growing fastest, mostly because the people doing it are conscientious, trying to save time, not careless.
Emma And the second question? I took the name out.
George A name is the obvious identifier, and far from the only one. Initials, a date of birth, an NHS number, an address, a ward plus an admission date, a rare diagnosis in a small community. Several together almost always identify someone.
Emma So taking the name out isn't enough.
George No. The test is whether somebody who knows the person, or has other information, could work out who it is. If they could, it's still personal data, the UK GDPR still applies, and so does clause 5 of the Code.
Emma Right. So what should I do about last month?
George Tell your manager and your information governance team now. Don't wait and don't quietly fix it. They have to assess whether it's reportable to the Information Commissioner, and where it is, the deadline is 72 hours from when the organisation became aware.
Emma So the clock starts when they know, not when I did it.
George Yes, which is exactly why telling them early matters. Every hour you wait comes off theirs. And prompt reporting is treated completely differently from concealment. If you're worried about the reaction, Freedom to Speak Up exists for that.
Emma Okay. Moving on, because I want to ask about bias. Isn't that a bit abstract?
George It can be, so let me give you a concrete one. The independent review of equity in medical devices, published in March 2024, found that pulse oximeters can overestimate oxygen levels in people with darker skin. And it warned AI-enabled devices carry a similar risk if they're built and tested on unrepresentative data.
Emma That's not an AI tool, though.
George No, which is why it's useful. It shows the mechanism. If a group was thin in the data, the tool works less well for them, and nobody has to have intended it. A tool that reassures you about a patient it measured badly is worse than no tool.
Emma Does it apply to scribes?
George Directly. If a scribe handles an accent or a second language less well, the notes for those patients will be worse and look just as confident. So ask of any tool who it was built and tested on, and whether it works as well for the patient in front of you.
Emma And if I think something's wrong?
George Say so. The Code asks you to raise concerns where people may be at risk. Tell your manager, report it as a patient safety event, or go to your Freedom to Speak Up Guardian. A concern raised early is the cheapest safety control an organisation has.
Emma And can I use all this for revalidation?
George Yes, carefully. This course alone is non-participatory CPD. If you then discuss it at a team meeting or journal club, that discussion is participatory. A reflective account might describe a draft that was wrong, what you changed in how you check, and the Code clause it links to. With no patient identifiable, ever.
The written material
The tool you chose is not the tool your employer approved
The commonest way for an AI tool to cause a data protection problem is not a hack. It is a conscientious person trying to save time. They paste a handover, a referral or a letter into a free tool to tidy it up, and the information has now left the organisation.
An approved tool has been assessed. There is a data protection impact assessment, a contract that says what the supplier may do with the information, and a safety case. A tool you found yourself has none of that, and its terms may allow your input to be kept or used. Your organisation's data protection arrangements do not extend to it. Using unapproved tools at work is sometimes called shadow AI, and it is the risk that grows fastest.
What counts as identifiable
A name is the obvious identifier, and it is far from the only one. Initials, a date of birth, a hospital or NHS number, an address, a ward combined with an admission date, a rare diagnosis in a small community, a distinctive family circumstance or a photograph can each identify somebody, and several together almost always do.
Removing the name is therefore not the same as making something anonymous. The test is whether someone who knows the person, or has other information, could work out who it is. If they could, it is still personal data and the UK GDPR and your duty of confidentiality under clause 5 of the Code still apply.
If you have already done it
It happens, and the response that matters is speed. Tell your manager and your information governance or data protection team as soon as you realise. Do not try to quietly fix it, and do not assume it does not count.
The organisation has to assess whether the incident must be reported to the Information Commissioner's Office, and where one is reportable the deadline is 72 hours from when the organisation became aware. Every hour you take to tell them is an hour off theirs. Reporting promptly is treated very differently from concealment, and Freedom to Speak Up is there if you fear the reaction.
Where bias comes from
An AI tool learns from data, and data reflects who was measured, who was written about and who was missing. If a group was thin in the data, the tool tends to work less well for them, and nobody needs to have intended that.
A real example is not even an AI example, which is why it is useful. The independent review of equity in medical devices, published by the UK Government in March 2024, found that pulse oximeters can overestimate oxygen levels in people with darker skin. It also warned that AI-enabled devices carry a risk of bias if they are built and tested on unrepresentative data. A tool that reassures you about a patient it has measured poorly is worse than no tool.
Bias can also enter in the words. A scribe that handles an accent, a dialect or a second language less well will produce worse notes for those patients, and the notes will look just as confident.
Speaking up, and using this for revalidation
If you think a tool is unsafe, producing worse results for some patients, or being used outside its approved purpose, say so. The Code asks you to raise concerns immediately where people may be at risk. Raise it with your manager, report it as a patient safety event, or go to your Freedom to Speak Up Guardian. A concern raised early is the cheapest safety control an organisation has.
For revalidation, completing this course alone is non-participatory CPD. If you discuss it with colleagues, at a team meeting or journal club, that discussion is participatory. A reflective account on digital practice might describe a time a draft was wrong, what you changed in how you check, and the Code clause it links to. It must not identify any patient.
Knowledge check
The knowledge check and your certificate need a free account, so that your progress and results can be saved as evidence.
The learning itself stays free and open. You are reading all of it right now without an account.
Was this module useful? Tell us in two minutes, it decides what we improve next.