Slides (PDF) · Student tasks · Български
Allow about 15 minutes to read and reflect. This material follows the presentation “Medical confidentiality: ethical foundations and legal liability”. Afterwards you should be able to name the grounds for disclosing health information without consent, apply the minimum-necessary rule, and distinguish the kinds of legal liability that a breach can create. The legal rules are Bulgarian; the English wording of statutes is a teaching translation.
What it covers and whom it binds
The Bulgarian Health Act uses the term health information (Art. 27). It means personal data on health status and on physical and mental development, and any information in prescriptions, orders, reports, certificates and other medical records. The fact of a visit, images, samples and data from medical devices are protected too. Protection does not depend on whether the patient called something a secret, or on the professional’s view that it is harmless.
Article 28c prohibits healthcare professionals and staff of healthcare establishments from disclosing information about a patient obtained in the course of their duties. The duty binds the whole team: doctors, nurses, midwives, laboratory staff, administrators, students and trainees. Members of the treating team share what they need. That is not free access for everyone in the hospital: a doctor from another ward who is not involved in the patient’s care is an outsider to the case.
The Code of Professional Ethics for Physicians in Bulgaria, Section IV, is stricter than the statutory minimum. Medical secrecy covers what the patient shared, what examination and tests revealed, and everything the doctor learned about the patient in practice (Art. 51(1)). It applies to the patient’s family and continues after death (Art. 51(2)–(3)). It extends to records, illustrative material and consultations (Art. 52). Doctors treating the same patient are released from secrecy among themselves unless the patient has a reasoned objection (Art. 53). Research and teaching may use the information only with guaranteed anonymity (Art. 54). Where the law requires reporting to an institution, the doctor is released from the duty of secrecy (Art. 55).
When information may be disclosed
The first basis is the patient’s own wish. A patient may authorise another person in writing to see their records and make copies (Art. 28b(2)). The authorisation should make clear who receives what information and for what purpose. A general “you can talk to my family” often needs clarifying.
Without consent, health information may be disclosed to third parties only in the situations listed in Article 28(1) of the Health Act:
- treatment continues in another healthcare establishment;
- there is a threat to the health or life of other persons;
- it is needed to identify a body or establish the cause of death;
- it is needed for state health control to prevent epidemics and the spread of communicable diseases;
- it is needed for medical expertise and social insurance;
- it is needed for medical statistics or research after the identifying data have been removed;
- it is needed by the Ministry of Health, the National Centre for Health Information, the National Health Insurance Fund, the regional health inspectorates or the National Statistical Institute;
- it is needed by specified insurers under the Insurance Code.
Where others are threatened, the patient must be notified before the information is disclosed (Art. 28(2)). Other laws create reporting duties. Under Article 7(2) of the Child Protection Act, anyone who learns through their profession that a child needs protection must report it immediately to social services, the State Agency for Child Protection or the police, even when bound by professional secrecy.
The minimum-necessary rule
A legal basis does not suspend the principle of minimum necessity. Before disclosing, the professional must answer four questions: who is the recipient, on what basis they receive the data, exactly which details are needed, and through which secure channel they will be sent. If any answer is unclear, disclosure stops until it has been checked. A regional health inspectorate investigating an outbreak does not receive unrelated psychiatric history. A team taking over care receives what it needs for safe continuity, not unlimited access.
A threat to a third party is among the hardest dilemmas. The assessment asks whether the harm is serious, likely and preventable, whether the person at risk can be identified, and whether a less intrusive way of reducing the risk exists. Talking with the patient, encouraging them to inform those affected, and consulting colleagues or a medical ethics committee usually come before disclosure. A genetic result raises a similar conflict because it also reveals a risk to relatives. The usual approach is to counsel the patient and support them in telling their relatives themselves.
Relatives, the deceased and children
A spouse, the parent of an adult patient, an adult child and a close friend are third parties unless the patient has authorised them. Kinship and good intentions do not create an automatic right to a diagnosis, prognosis or past treatment. A husband in the room is not permission to share every detail. Particular care is needed with a previous pregnancy or abortion, an infection, psychiatric treatment, a genetic result or abuse.
The ethical duty continues after death, but the records do not become completely inaccessible. Heirs and relatives in direct and collateral line up to the fourth degree may see the health information of the deceased and obtain copies (Art. 28b(3)). The information does not become public. It is released to the entitled person after their identity and basis have been checked.
With a child, the parent has access because of their responsibility for health decisions. An adolescent should know in advance how far the conversation will stay confidential. Absolute secrecy must not be promised where serious risk of abuse, self-harm or grave harm might emerge.
Degrees of breach and digital risks
The law sets no scale of breaches. For teaching purposes, four degrees are distinguished. The zero degree is lawful sharing for care. The first is careless disclosure with low identifiability. The second is disclosure to an unauthorised person, or access without a work-related need. The third is deliberate, public or large-scale spread of identifiable data. Identification does not require a name: a rare diagnosis, age, occupation, place and a photograph can together make a person recognisable. Lack of intent does not remove the breach. Intent affects the type and extent of liability.
Electronic records improve continuity but widen the circle of people who can reach the data. Access follows role and need, logins are never shared, and every opening of a record must be traceable. Work access does not allow looking up a relative, colleague or public figure. Personal messaging apps, photos of wounds or screens, and entering clinical data into external artificial-intelligence tools create unmanageable risk. After a breach, contain the incident, report it at once through internal channels, assess the data and the people affected, and notify the supervisory authority and the patient where required. Concealment increases the harm.
Legal liability
One act can give rise to several independent kinds of liability.
- Professional. A doctor answers for breaching the Code of Professional Ethics before the ethics committee of the regional college of the Bulgarian Medical Association (Professional Organisations of Physicians and Dentists Act, Arts. 37(1)(1) and 39). Penalties under Article 38 are a reprimand, a fine of one to five minimum monthly wages, and removal from the college register for three months to one year. Under Article 42(1), these penalties do not exclude criminal, civil or disciplinary liability.
- Employment-disciplinary. Culpable failure to perform work duties, including duties set by law and by internal rules, breaches labour discipline (Labour Code, Arts. 186 and 187(1)(10)). The penalties are a reprimand, a warning of dismissal and dismissal (Art. 188).
- Administrative. The Health Act provides a fine for breaching its provisions, including the prohibition in Article 28c (Art. 229), and a sanction for a healthcare establishment that violates patients’ rights (Art. 221). The person affected may complain to the Commission for Personal Data Protection within six months of learning of the breach (Personal Data Protection Act, Art. 38). The data controller faces sanctions under Article 83 of Regulation (EU) 2016/679.
- Civil. Everyone must repair harm they culpably cause to another, and fault is presumed (Obligations and Contracts Act, Art. 45). The healthcare establishment is liable for harm caused by staff in or in connection with their work (Art. 49). Non-pecuniary harm, such as shame and stigma, is assessed by the court on an equitable basis (Art. 52). Damages may also be claimed under Article 39(2) of the Personal Data Protection Act.
- Criminal. Anyone who unlawfully discloses another person’s secret that could damage someone’s good name, entrusted to them or learned in connection with their occupation, faces imprisonment of up to one year or a fine (Penal Code, Art. 145(1)). Prosecution begins on the victim’s complaint (Art. 161(1)). Not every disclosure is a crime, but it may still be a serious ethical and disciplinary breach.
Confidentiality cannot be used to hide a professional error, abuse or any other wrongdoing. It protects the patient, not the reputation of the department.
Before you open the student tasks, try to answer in three sentences: when you keep information, when you share it, and when you must report it. If you can name the legal basis and the recipient for each, you are ready for the cases.