Personal Mobile Phone and Recording Devices Policy
- Home
- Personal Mobile Phone and Recording Devices Policy
First Contact Physiotherapists and MSK Outpatient Physiotherapist
| Author Reviewer |
Ravi Shanker, Operational Lead Chandrasekhar Dekka, Clinical Director |
Version | 1.0 |
| Effective date | August 2026 | Review date | August 2027 |
| Applies to | FCPs, physiotherapists, locums, and contractors | Status | Approved by: Ravi Shanker |
1. Purpose
2. Core Standard
- Phones must be placed on silent/do-not-disturb and kept securely away, preferably in a bag, locker, drawer or pocket.
- Personal phones should not be placed on the clinical desk or examination area.
- Clinicians should not check calls, messages, social media or other personal content during a consultation without prior permission from patient if expecting an emergency.
- Where a host practice/PCN has a stricter policy, the local policy must also be followed rather than Nexus Policy.
3. Photography, Video and Audio Recording
Clinicians must not photograph, video-record or audio-record a patient, clinical record, computer screen or patient-identifiable information using a personal device. Photograph of part of body with consent from patient for education purpose can be taken and advisable to show patient what picture has been taken. Eg knee swelling, deformity of body part or etc.
Where clinical photography or recording is genuinely required, valid and documented consent and information-governance process must be used. Routine consent to examination or treatment does not constitute consent to recording. Document that patient has been consented for recording or photography of body part of movement for educational purpose and video or photography has been shown to patient.
4. Legitimate Clinical or Emergency Use
5. Patient Information and Confidentiality
- Do not photograph clinical notes with identifiable data, referral letters or EMIS/SystmOne screens with identifiable data.
- Do not store patient-identifiable information in personal notes, photo galleries, cloud storage or personal applications with identifiable data.
- Do not send patient-identifiable information through personal WhatsApp, SMS, personal email or social-media accounts.
- Any personal device including smart phones, camera, or laptops use must comply with Nexus Health and host-practice information-governance requirements.
6. Suspected Unauthorised Recording or Data Incident
- Potentially relevant information must not be deleted, altered, transferred or reset.
- The clinician must cooperate with a fair and proportionate investigation.
- Any device review must respect privacy and data-protection requirements. Intrusive searches of a personal device should not be undertaken without appropriate HR, information-governance and/or legal advice.
- Potential personal-data breaches must be escalated to the appropriate Information Governance/DPO lead.
7. Responsibilities and Non-Compliance
8. Training and Review
9. Key References
- NHS England – Primary Medical Services Policy and Guidance Manual: Data Security and Protection.
- NHS England – Information Governance and Data Protection.
- NHS England – Records Management Policy / Records Management Code of Practice.
- NHS England – Primary Care GP Digital Services Operating Model (including personal device).
- Care Quality Commission (CQC) – Regulation 11: Need for Consent and guidance on use of technology in care.
- UK GDPR and Data Protection Act 2018.
Staff Acknowledgement
Signature of Clinician: _______________________