Standard 6 — Data Privacy & Patient Confidentiality
Criteria in this standard
6.2 — A Third Party Present But Unseen Is Genuinely Disclosed and Consented To
6.3 — Session Recording Follows a Clear, Specific Policy
6.4 — The Provider's Own Home Office Meets the Same Privacy Standard
6.5 — Substance Use Disorder Records Follow the Heightened, Distinct Confidentiality Standard
The Patient's Session Environment Is Actively Addressed
Non-Negotiable
In plain terms: At the start of care, the patient is told how to make their session private — a room with a door, headphones, no one listening — and the provider checks each time.
| Facility category | Crisis | Transition | Small | Standard |
|---|---|---|---|---|
| Applicability | Full | Full | Full | Full |
Why this matters
The patient joins from the kitchen with children present. From the car park at work. From a shared bedroom. A mental health session, a discussion of an STI, a domestic violence disclosure — none can happen safely in those settings. The service must give guidance at intake (a private room, a closed door, headphones, a signal if someone enters) and the provider must check at each session ('Are you somewhere private? Can anyone hear?'). If not, the session is deferred or limited to non-sensitive content. Privacy is the patient's right and the provider's responsibility to protect.
What good looks like
- Patients are genuinely, proactively guided on finding a private location.
- Concrete alternatives are offered when home isn't private or quiet.
- Attention to environment is genuinely calibrated to visit sensitivity.
Common failure modes
- Environment privacy is assumed adequate without any active guidance.
- No alternatives are offered for patients without a private home space.
- Environment receives the same minimal attention regardless of topic sensitivity.
Worked example
If you are starting from zero — do this first
- Write a one-page privacy guide for patients.
- Script the check: 'Are you somewhere private?'
- Record the answer every session.
- Reschedule if not private.
Self-assessment questions
Evidence: Patient environment guidance materials
Evidence: N/A — tested directly
Evidence: N/A — tested directly
Common reasons for a PARTIAL answer
- Guidance exists in intake materials but isn't reinforced verbally at the start of an actual session. — Real, active reinforcement at the point of use is more reliable than guidance provided once and easily forgotten.
- Alternatives are suggested generally but not tailored to what's realistically available to a specific patient's circumstances. — Genuine, practical guidance should reflect what's actually feasible for the individual patient, not a generic list.
- Environment is addressed for new patients but not consistently revisited for established, ongoing patients.
Implementation plan
| When | What |
|---|---|
| Week 1 | Review current patient environment guidance for genuine specificity and practicality. |
| Week 2 | Build concrete alternative suggestions for patients without a private home space. |
| Week 3 | Reinforce environment guidance verbally at the start of sessions, not intake materials alone. |
| Ongoing | Revisit environment guidance periodically for established patients. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Guidance materials review | Reviews actual patient-facing materials for genuine, specific environment guidance. |
| OBSERVE | Session opening observation | Observes whether environment is genuinely addressed at the start of an actual session. |
| DOCUMENT | Sensitivity calibration review | Reviews whether environment attention is genuinely calibrated to the sensitivity of the visit. |
Supervisor tips
- Ask a patient whether they were given any specific guidance on finding a private location. — A specific, real answer reveals genuine practice, not an assumption of adequate guidance.
- Observe an actual session opening for genuine environment discussion. — Direct observation reveals whether this happens in practice, not just in intake documentation.
Evidence base
ASF training courses on GMJ Academy →
Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.
A Third Party Present But Unseen Is Genuinely Disclosed and Consented To
Non-Negotiable
In plain terms: If anyone other than the patient is in the room — visible or not — the provider knows, the patient has agreed, and it is recorded. No hidden listeners.
| Facility category | Crisis | Transition | Small | Standard |
|---|---|---|---|---|
| Applicability | Full | Full | Full | Full |
Why this matters
A family member sitting off-camera, a partner in the next room, a carer 'just helping' — each is a third party to a confidential consultation. The patient may not feel free to speak; the provider may not know who is listening; consent is compromised. The rule: the provider asks who is present at the start of every session; anyone present is named and the patient confirms consent to their presence; the presence and consent are recorded; the patient can ask them to leave at any point. For sensitive topics, the provider may ask to speak to the patient alone. A hidden listener is a breach the patient did not agree to.
What good looks like
- Providers genuinely, actively ask whether anyone else is present.
- Specific, documented consent is genuinely obtained when a third party is present.
- Public location risk is genuinely, actively addressed before continuing.
Common failure modes
- Providers assume the patient is alone based only on what's visible on screen.
- Consent for third-party presence isn't genuinely obtained or documented.
- A patient's apparently public location isn't addressed before continuing with sensitive topics.
Worked example
If you are starting from zero — do this first
- Add 'Who else is present?' to the session opening script.
- Record every third party and the patient's consent.
- Train providers to ask for a private word when needed.
- Tell patients the rule at intake.
Self-assessment questions
Evidence: Provider training on third-party presence inquiry
Evidence: Third-party presence consent documentation
Evidence: N/A — tested directly
Common reasons for a PARTIAL answer
- Inquiry happens for new patients but isn't consistently repeated for established, ongoing patients. — An established patient's actual circumstances at a given session can genuinely differ from prior visits.
- Consent is obtained verbally but not consistently documented in a genuinely retrievable way. — Documented consent provides more reliable, real evidence than a verbal exchange alone.
- Public location risk is addressed when obviously apparent but not consistently for more ambiguous settings.
Implementation plan
| When | What |
|---|---|
| Week 1 | Review current practice for genuine inquiry about third-party presence at session start. |
| Week 2 | Train providers to actively ask and document consent when a third party is present. |
| Week 3 | Build specific guidance for addressing apparently public patient locations. |
| Ongoing | Extend genuine, repeated inquiry to established, ongoing patients. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| OBSERVE | Third-party inquiry observation | Observes an actual session opening for genuine, active inquiry about anyone else present. |
| DOCUMENT | Consent documentation review | Reviews records for genuine, documented consent when a third party is present. |
| OBSERVE | Public location handling observation | Observes how a provider genuinely addresses a patient joining from an apparently public location. |
Supervisor tips
- Observe an actual session opening for genuine inquiry about who else might be present. — Direct observation reveals whether this genuinely happens, not an assumption based on stated policy.
- Ask to see documented consent for a real case where a third party was present. — A real, specific record reveals genuine practice, not policy language alone.
Evidence base
ASF training courses on GMJ Academy →
Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.
Session Recording Follows a Clear, Specific Policy
Non-Negotiable
In plain terms: There is a written policy on whether sessions are ever recorded, when, by whom, with what consent, how stored, and who can access — and it is followed. Patients are told.
| Facility category | Crisis | Transition | Small | Standard |
|---|---|---|---|---|
| Applicability | Full | Full | Full | Full |
Why this matters
A recorded consultation is a permanent record of the most private conversation a person may have. Recording without consent is illegal in many jurisdictions and unethical everywhere. Recording with consent creates obligations: secure storage, defined retention, controlled access, and the patient's right to a copy or deletion. The policy may be 'never'; that is legitimate and simple. If recording is permitted for any purpose — quality, training, clinical — every element must be specified, consent must be explicit and revocable, and the platform's own recording settings must match the policy. Patients must also be told that they may not record without consent.
What good looks like
- A clear, specific, documented recording policy genuinely exists.
- The policy specifically addresses storage location and retention duration.
- Patients are genuinely, specifically informed about recording before it happens.
Common failure modes
- No clear policy exists; practice is left to individual provider discretion.
- The policy is silent on storage location or retention duration.
- Recording occurs without the patient's genuine, prior knowledge.
Worked example
If you are starting from zero — do this first
- Check your platform's recording settings right now.
- Decide: never, or under what exact conditions?
- Write the policy and configure the platform to match.
- Tell patients.
Self-assessment questions
Evidence: Session recording policy documentation
Evidence: N/A — tested directly
Evidence: Patient recording notification record
Common reasons for a PARTIAL answer
- A policy exists for standard consultations but isn't specifically addressed for group or family sessions. — Every session type deserves the same genuine policy clarity, not standard consultations alone.
- Storage location is specified but retention duration isn't clearly, specifically defined. — Both elements genuinely matter to a patient's real understanding of what happens to their recorded information.
- Notification happens but isn't consistently documented as genuinely occurring before recording begins.
Implementation plan
| When | What |
|---|---|
| Week 1 | Review current recording practice for genuine, specific policy clarity. |
| Week 2 | Build a clear, documented policy addressing whether, when, storage, and retention. |
| Week 3 | Establish consistent, documented patient notification before any recording. |
| Ongoing | Extend policy clarity to all session types, not standard consultations alone. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Policy documentation review | Reviews the actual, specific, documented recording policy. |
| DOCUMENT | Storage and retention review | Reviews whether the policy specifically addresses storage location and retention duration. |
| OBSERVE | Patient notification observation | Observes whether patients are genuinely, specifically informed about recording before it occurs. |
Supervisor tips
- Ask to see the actual, written recording policy, not a general assurance recording is handled appropriately. — A specific, real document reveals genuine clarity, not assumed adequacy.
- Ask a provider directly what the specific retention period is for a session recording. — A specific, confident answer reveals genuine, clear policy, not individual discretion.
Evidence base
ASF training courses on GMJ Academy →
Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.
The Provider's Own Home Office Meets the Same Privacy Standard
Non-Negotiable
In plain terms: A provider working from home has a private room, a secure device, a secure network, no one who can overhear, and the same data protection as an office — verified, not assumed.
| Facility category | Crisis | Transition | Small | Standard |
|---|---|---|---|---|
| Applicability | Adapted | Full | Full | Full |
Why this matters
The provider joins from the kitchen table while family passes through. Their laptop is shared with a teenager. The Wi-Fi is the neighbour's. Papers with patient names are on the desk. The home office is the weakest link in telemedicine security and the least examined. The standard is the same as a clinical office: a private room with a closed door; a work-only device with encryption and MFA; a secure network (not public Wi-Fi, ideally VPN); no patient information visible or audible to others; a clean desk; a screen lock. The service verifies this — by attestation at minimum, by inspection where practical — and provides what the provider needs.
What good looks like
- Provider devices are genuinely, verifiably encrypted.
- Home network security is genuinely, specifically verified.
- Providers genuinely have real physical privacy during sessions.
Common failure modes
- Device encryption is assumed adequate without genuine verification.
- Home network security is unexamined, not specifically verified.
- Physical privacy is assumed from a designated space without genuine confirmation.
Worked example
If you are starting from zero — do this first
- Ask each provider: private room? Work-only device? Secure network? Anyone who can overhear?
- Write the home office standard.
- Issue managed devices and require VPN.
- Verify each setup by video walkthrough.
Self-assessment questions
Evidence: Provider device encryption verification
Evidence: Home network security verification
Evidence: N/A — tested directly
Common reasons for a PARTIAL answer
- Device encryption is verified for provider-issued equipment but not for personally owned devices also used for sessions. — Every device genuinely used to access patient information deserves the same verification, regardless of ownership.
- Network security is addressed at initial setup but not periodically reconfirmed as home network configurations can change. — A home network's real security can change over time, and periodic reconfirmation reflects this reality.
- Physical privacy is generally adequate but hasn't been specifically confirmed for providers sharing a household with others working or studying at home.
Implementation plan
| When | What |
|---|---|
| Week 1 | Review current home office privacy and security for genuine verification versus assumed adequacy. |
| Week 2 | Verify encryption for every device genuinely used to conduct sessions, regardless of ownership. |
| Week 3 | Confirm home network security and genuine physical privacy for every provider. |
| Ongoing | Periodically reconfirm home office security as configurations may change. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | Device encryption review | Reviews evidence of genuine, verified encryption for devices used to conduct sessions. |
| DOCUMENT | Network security review | Reviews evidence of genuine, verified home network security. |
| ASK | Physical privacy interview | Asks a provider to describe their actual physical privacy setup during sessions. |
Supervisor tips
- Ask a provider to describe their actual home office setup, including device and network security. — A specific, confident answer reveals genuine attention, not an assumption of adequacy.
- Ask specifically about physical privacy for a provider sharing a household with others. — This reveals whether genuine privacy has been confirmed, not assumed from a general home office description.
Evidence base
ASF training courses on GMJ Academy →
Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.
Substance Use Disorder Records Follow the Heightened, Distinct Confidentiality Standard
Non-Negotiable
In plain terms: Records of substance use disorder treatment follow the separate, stricter confidentiality rules that apply to them — separate consent, restricted sharing, no disclosure without specific authorisation.
| Facility category | Crisis | Transition | Small | Standard |
|---|---|---|---|---|
| Applicability | Full | Full | Adapted | Full |
Why this matters
In many jurisdictions, substance use disorder treatment records have a higher confidentiality standard than general health records (42 CFR Part 2 in the US, equivalents elsewhere): they cannot be shared even with other treating providers without specific written consent; they cannot be used in legal proceedings without a court order; they must be segregated or flagged; breaches carry distinct penalties. A telemedicine service that stores SUD records alongside general records with the same access and sharing rules is violating the higher standard. The service must know the rule, identify SUD records, and apply the stricter regime.
What good looks like
- Substance use disorder records genuinely follow the specific, heightened standard.
- Disclosure is genuinely based on the patient's own specific written consent.
- Staff are specifically trained on this distinct standard, not assuming general practice suffices.
Common failure modes
- These records are treated identically to general health information.
- Disclosure relies on a general release, not specific written consent for this category.
- Staff aren't specifically trained; general health privacy knowledge is assumed sufficient.
Worked example
If you are starting from zero — do this first
- Find the SUD confidentiality regulation for your jurisdiction.
- Identify and flag every SUD treatment record.
- Introduce a separate SUD disclosure consent.
- Train staff on the difference.
Self-assessment questions
Evidence: SUD-specific confidentiality protocol documentation
Evidence: Patient written consent for SUD record disclosure
Evidence: Staff training on substance use disorder confidentiality standard
Common reasons for a PARTIAL answer
- The distinct standard is understood by clinical staff but not consistently by administrative staff who may handle these records. — Every staff member with access to these specific records deserves the same genuine understanding of this heightened standard.
- Written consent is obtained but doesn't specifically distinguish this category from general information release consent. — Genuine compliance requires consent language specifically reflecting this distinct, heightened requirement.
- The standard is applied for direct SUD treatment records but not consistently for related information in a broader clinical note.
Implementation plan
| When | What |
|---|---|
| Week 1 | Review current handling of substance use disorder records for genuine adherence to the distinct standard. |
| Week 2 | Establish specific written consent language distinguishing this category from general release. |
| Week 3 | Train all staff with potential record access, not clinical staff alone, on this heightened standard. |
| Ongoing | Audit handling of related information within broader clinical notes for consistent application. |
How the Monitor verifies this
| Method | What | Detail |
|---|---|---|
| DOCUMENT | SUD protocol review | Reviews evidence that substance use disorder records genuinely follow the distinct, heightened standard. |
| DOCUMENT | Written consent review | Reviews documentation confirming disclosure is based on genuine, specific patient written consent. |
| DOCUMENT | Staff training review | Reviews training records confirming staff are specifically educated on this distinct standard. |
Supervisor tips
- Ask an administrative staff member whether they're aware of the distinct standard for these specific records. — This reveals whether genuine understanding extends beyond clinical staff alone.
- Ask to see the actual, specific written consent language used for this category of disclosure. — A real, specific document reveals genuine compliance, not an assumption general consent suffices.
Evidence base
ASF training courses on GMJ Academy →
Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.