Medical confidentiality: when to keep, share or report

A 15-minute reading before the third class: the concept and ethical foundations of medical confidentiality, health information and permitted disclosure under the Bulgarian Health Act, degrees of breach, digital confidentiality and the physician’s legal liability.
English
Medical Ethics
Medicine | 2nd year
Dental Medicine
2026/2027
Author

Kostadin Kostadinov

Published

September 26, 2026

Slides (PDF) · Student tasks · Български

Allow about 15 minutes to read and reflect. This material follows the presentation “Medical confidentiality: ethical foundations and legal liability”. Afterwards you should be able to name the grounds for disclosing health information without consent, apply the minimum-necessary rule, and distinguish the kinds of legal liability that a breach can create. The legal rules are Bulgarian; the English wording of statutes is a teaching translation.

What it covers and whom it binds

The Bulgarian Health Act uses the term health information (Art. 27). It means personal data on health status and on physical and mental development, and any information in prescriptions, orders, reports, certificates and other medical records. The fact of a visit, images, samples and data from medical devices are protected too. Protection does not depend on whether the patient called something a secret, or on the professional’s view that it is harmless.

Article 28c prohibits healthcare professionals and staff of healthcare establishments from disclosing information about a patient obtained in the course of their duties. The duty binds the whole team: doctors, nurses, midwives, laboratory staff, administrators, students and trainees. Members of the treating team share what they need. That is not free access for everyone in the hospital: a doctor from another ward who is not involved in the patient’s care is an outsider to the case.

The Code of Professional Ethics for Physicians in Bulgaria, Section IV, is stricter than the statutory minimum. Medical secrecy covers what the patient shared, what examination and tests revealed, and everything the doctor learned about the patient in practice (Art. 51(1)). It applies to the patient’s family and continues after death (Art. 51(2)–(3)). It extends to records, illustrative material and consultations (Art. 52). Doctors treating the same patient are released from secrecy among themselves unless the patient has a reasoned objection (Art. 53). Research and teaching may use the information only with guaranteed anonymity (Art. 54). Where the law requires reporting to an institution, the doctor is released from the duty of secrecy (Art. 55).

When information may be disclosed

The first basis is the patient’s own wish. A patient may authorise another person in writing to see their records and make copies (Art. 28b(2)). The authorisation should make clear who receives what information and for what purpose. A general “you can talk to my family” often needs clarifying.

Without consent, health information may be disclosed to third parties only in the situations listed in Article 28(1) of the Health Act:

  1. treatment continues in another healthcare establishment;
  2. there is a threat to the health or life of other persons;
  3. it is needed to identify a body or establish the cause of death;
  4. it is needed for state health control to prevent epidemics and the spread of communicable diseases;
  5. it is needed for medical expertise and social insurance;
  6. it is needed for medical statistics or research after the identifying data have been removed;
  7. it is needed by the Ministry of Health, the National Centre for Health Information, the National Health Insurance Fund, the regional health inspectorates or the National Statistical Institute;
  8. it is needed by specified insurers under the Insurance Code.

Where others are threatened, the patient must be notified before the information is disclosed (Art. 28(2)). Other laws create reporting duties. Under Article 7(2) of the Child Protection Act, anyone who learns through their profession that a child needs protection must report it immediately to social services, the State Agency for Child Protection or the police, even when bound by professional secrecy.

The minimum-necessary rule

A legal basis does not suspend the principle of minimum necessity. Before disclosing, the professional must answer four questions: who is the recipient, on what basis they receive the data, exactly which details are needed, and through which secure channel they will be sent. If any answer is unclear, disclosure stops until it has been checked. A regional health inspectorate investigating an outbreak does not receive unrelated psychiatric history. A team taking over care receives what it needs for safe continuity, not unlimited access.

A threat to a third party is among the hardest dilemmas. The assessment asks whether the harm is serious, likely and preventable, whether the person at risk can be identified, and whether a less intrusive way of reducing the risk exists. Talking with the patient, encouraging them to inform those affected, and consulting colleagues or a medical ethics committee usually come before disclosure. A genetic result raises a similar conflict because it also reveals a risk to relatives. The usual approach is to counsel the patient and support them in telling their relatives themselves.

Relatives, the deceased and children

A spouse, the parent of an adult patient, an adult child and a close friend are third parties unless the patient has authorised them. Kinship and good intentions do not create an automatic right to a diagnosis, prognosis or past treatment. A husband in the room is not permission to share every detail. Particular care is needed with a previous pregnancy or abortion, an infection, psychiatric treatment, a genetic result or abuse.

The ethical duty continues after death, but the records do not become completely inaccessible. Heirs and relatives in direct and collateral line up to the fourth degree may see the health information of the deceased and obtain copies (Art. 28b(3)). The information does not become public. It is released to the entitled person after their identity and basis have been checked.

With a child, the parent has access because of their responsibility for health decisions. An adolescent should know in advance how far the conversation will stay confidential. Absolute secrecy must not be promised where serious risk of abuse, self-harm or grave harm might emerge.

Degrees of breach and digital risks

The law sets no scale of breaches. For teaching purposes, four degrees are distinguished. The zero degree is lawful sharing for care. The first is careless disclosure with low identifiability. The second is disclosure to an unauthorised person, or access without a work-related need. The third is deliberate, public or large-scale spread of identifiable data. Identification does not require a name: a rare diagnosis, age, occupation, place and a photograph can together make a person recognisable. Lack of intent does not remove the breach. Intent affects the type and extent of liability.

Electronic records improve continuity but widen the circle of people who can reach the data. Access follows role and need, logins are never shared, and every opening of a record must be traceable. Work access does not allow looking up a relative, colleague or public figure. Personal messaging apps, photos of wounds or screens, and entering clinical data into external artificial-intelligence tools create unmanageable risk. After a breach, contain the incident, report it at once through internal channels, assess the data and the people affected, and notify the supervisory authority and the patient where required. Concealment increases the harm.