Find a course

Data Protection in the Health Sector

Essential GDPR training for health sector staff.

Online / In Person
Half day: 9.30 to 12.30

About this course

Are your staff confident they understand their data protection obligations when handling patient records? Could your organisation withstand a Data Protection Commission investigation?

With the DPC actively focusing compliance efforts on the healthcare sector, understanding data protection requirements has never been more critical.

Given the immense sensitivity of medical records, it is imperative that professionals in this sector are clear about their use of patient data.

Discover the importance of data protection and how to ensure compliance with regulations.

Why choose this course

Nearly 75 data breach incidents have been reported by the Department of Health since 2018, with most attributed to human error. The DPC received 7,781 breach notifications in 2024, an 11% increase from 2023. Healthcare data breaches cost an average of €9.77 million per incident globally. The 2021 HSE ransomware attack remains Ireland's most significant cybercrime incident, causing widespread service disruption and compromising patient data.

This highly practical half day course is essential for those accessing, maintaining or creating medical records.

What you will learn:

Clear understanding of data protection regulations in healthcare contexts.

Practical approaches to handling patient records ethically and legally.

How to identify and prevent common breach scenarios.

Best practices for maintaining confidentiality in day-to-day operations.

Course syllabus

The confidentiality of patient records is central to the ethical tradition of health and social care and is in line with the requirements of the Data Protection Acts. La Touche Training’s Data Protection in the Health Sector course provides practical guidance on safeguarding patient information and maintaining compliance with GDPR and the Data Protection Acts.

Key Learning Points:

  • Data Protection and Freedom of Information – similarities and differences,
  • Access to records – Data Protection/Freedom of Information/Routine and Administrative Access,
  • Disclosure – particularly to third parties,
  • Data controllers/data processors – medical staff in private and public practice,
  • Restrictions on rights of access to documents,
  • Patient privacy,
  • Consent in the context of Data Protection legislation,
  • Records management,
  • Use of mobile telephones,
  • Encryption and protection of documents,
  • Retention of records,
  • The use of case studies specifically related to the medical setting.

Learning outcomes:

  • Understand your legal obligations under GDPR and the Data Protection Acts.
  • Identify common breach scenarios and how to prevent them.
  • Handle subject access requests correctly.
  • Implement practical safeguards for physical and electronic records.

Your Trainer – Niamh Flynn

Legal Programme Developer and Trainer

Niamh Flynn is a solicitor and now works as a full-time Legal Programme Developer and Trainer with La Touche Training.
...

Read Bio

Practical training with small groups to ensure quality.

Our training sessions are not lectures—they're practical, interactive experiences. The small group format allows every attendee to ask questions, take part in discussions involving practical exercises and role-plays.

This method of training allows attendees to put the skills learned into practice immediately. Course participants benefit from the focused attention and guidance of an independent expert.

Secure your place

# SELECTED
Course DatesLocationPriceSpaces LeftBook
20/11/26
i

20/11/2026 09:30 - 12:30

Zoom Online €245.00 12

Essential GDPR training for health sector staff

FAQs


Healthcare organisations process large volumes of sensitive personal and medical information. Strong data protection practices are essential to protect patient privacy, maintain trust, and comply with GDPR and Irish data protection legislation.


Healthcare providers in Ireland must comply with the EU General Data Protection Regulation (GDPR) and the Data Protection Act 2018, alongside professional confidentiality obligations and sector-specific guidance.

 


This course is suitable for healthcare professionals, practice managers, HR personnel, administrators, data protection officers, compliance staff, and public sector employees handling patient information.


Health data is classified as special category personal data under GDPR because it is particularly sensitive and requires enhanced protections when collected, processed, stored, or shared.


Key principles include lawful processing, transparency, data minimisation, accuracy, confidentiality, purpose limitation, storage limitation, and accountability in handling patient information.


Organisations can reduce risk through staff training, secure systems, clear data handling policies, access controls, encryption, regular audits, and prompt incident response procedures.


Staff should report the breach immediately through internal procedures so the organisation can assess the risk, contain the issue, and determine whether notification to the Data Protection Commission or affected individuals is required.


Confidentiality relates to the ethical and professional duty to keep patient information private, while data protection law governs how personal data is collected, processed, stored, and shared legally and securely.


Patient information may be shared where there is a lawful basis, a clear care-related purpose, and appropriate safeguards in place to protect confidentiality and comply with GDPR obligations.


Participants typically develop knowledge of GDPR compliance, handling special category data, breach management, confidentiality obligations, records management, and practical risk reduction strategies.