United Kingdom · Access to Health Records Act 1990

The one health-records regime UK GDPR does not cover

Data protection rights end at death. For NHS trusts, health boards, GP practices, and independent providers, the Access to Health Records Act 1990 governs applications for a deceased patient's records — on its own clocks, with its own limits.

United Kingdom — Access to Health Records Act 1990 at a glance

Who may apply
The patient's personal representative, and any person with a claim arising from the death
Deadline
21 days where the record was added to in the last 40 days; otherwise 40 days
Scope for claimants
Only information relevant to the claim
Limits
s.5 — serious harm, third-party identification, the patient's recorded objection
Fees
No fee for access itself; charges limited to what the Act permits
Languages
English

Built for United Kingdom — Access to Health Records Act 1990

One platform for the whole access-and-privacy mandate, pre-configured for this regime and running in your own Microsoft 365 tenant.

Applicant standing, checked first

The Act grants access to a personal representative and to a person with a claim arising from the death — and to nobody else. Capture and verify standing at intake, because the whole scope of the response depends on which of the two the applicant is.

The 21 and 40-day clocks

Which deadline applies depends on whether the record was added to in the preceding 40 days. AccessPoint asks the question at intake and sets the right clock, rather than defaulting everyone to 40 days.

Claim-relevance scoping

A claimant is entitled only to information relevant to their claim. Scope the release to that, and record what was excluded as irrelevant and why — a distinction generic SAR tooling does not make.

The s.5 limits

Serious harm, third-party identification, and the patient's own recorded objection each ship as a citable ground applied to specific passages, not to whole records.

Clinical review as a step

Serious-harm decisions need a clinician. Route the record for clinical review as a tracked stage with its own reviewer and recorded opinion, rather than an email to a consultant.

In your own tenant

Patient records stay inside your own Microsoft 365 and Azure tenant — no third-party cloud and no vendor access.

The request that falls between regimes

A bereaved family's request is the one your SAR process cannot handle.

UK GDPR gives living people rights over their own data, and those rights do not survive them. What replaces them is the Access to Health Records Act 1990 — a much older statute with a different applicant test, different clocks, a different scope, and a different set of limits. Requests under it arrive in the same inbox as subject access requests and look superficially similar, which is exactly why they go wrong: logged as a SAR, put on a one-month clock that does not apply, answered in full to someone entitled only to claim-relevant information, or refused by someone with no standing to decide. AccessPoint ships the 1990 Act as its own request type, so the regime is chosen at intake and everything downstream follows from it.

Standing first Representative or claimant — the answer sets the scope.
21 or 40 days Chosen from when the record was last added to.
Clinical review tracked Serious-harm opinions recorded, not emailed.

Configured out of the box

Installing the uk-health-records jurisdiction pack seeds your tenant with everything this regime needs — a starting point you can adjust, not a lock-in.

Related guide: FOI Workflow Quick Check
  • The Access to Health Records Act 1990 as the legal-authority spine
  • Applicant-standing capture for personal representatives and claim holders, with verification
  • The 21-day and 40-day clocks selected from when the record was last added to
  • Claim-relevance scoping for claimant applications, with exclusions recorded
  • The s.5 limits — serious harm, third-party identification, and the patient's recorded objection — as citable grounds
  • Clinical review as a tracked stage with reviewer and recorded opinion
  • Complaints tracking through the provider's procedure and beyond
  • Response templates carrying the Act's wording rather than UK GDPR wording

United Kingdom — Access to Health Records Act 1990 Questions

Why isn't this just a subject access request?

Because data protection rights do not survive the data subject. Once a patient has died, UK GDPR no longer provides a right of access to their records; the Access to Health Records Act 1990 does, on different terms — a narrower class of applicants, different deadlines, a claim-relevance limit, and its own withholding grounds. Running it as a SAR applies the wrong clock and usually the wrong scope.

Which deadline applies, 21 days or 40?

21 days where the record was added to during the 40 days preceding the application, and 40 days otherwise. AccessPoint puts the question at intake and sets the clock from the answer, so the shorter deadline is not missed by defaulting.

How is a claimant's access limited?

A person applying because they have a claim arising from the patient's death is entitled only to information relevant to that claim — not to the whole record. AccessPoint scopes the release accordingly and records what was excluded as not relevant, so the basis of the response is documented if it is later questioned.

Where do patient records reside?

Entirely within your own Microsoft 365 and Azure tenant. Records, requests, clinical review opinions, and audit history never leave your control — no third-party cloud, no vendor access, and no cross-border transfers.

Run the Access to Health Records Act in Your Own Tenant

Try AccessPoint free for 30 days, configured for deceased patients' records. No credit card required.

Start Free Trial