Good medical records are the backbone of safe care and the main evidence of what was done and why, and the personal information they contain is protected by law. For the sport and exercise medicine (SEM) doctor, records raise particular questions: who holds them, how they are shared with a club or with performance staff, and what happens when an athlete moves on. This page sets out what good record-keeping looks like, the data protection framework that governs health information, and how both apply in the sporting setting. It builds on the material on confidentiality and on duty of care, consent and records.
Good Records and the Law
A good clinical record is made at the time or as soon as possible afterwards, is clear, factual and legible, and includes the relevant history, findings, decisions, the information given to the patient, and the reasons for the plan. Records should be accurate and should not be altered after the event, and if a correction is needed the original entry should remain visible alongside it. Beyond their clinical value, records are also personal data, and information about a person's health is special category data under the Data Protection Act 2018 and the UK General Data Protection Regulation, which means it is given a higher level of protection.
Handling health records under the Data Protection Act 2018 and UK GDPR: a lawful basis and condition, purpose limitation, data minimisation, accuracy, secure storage and retention, and the right of access.
The law requires a lawful basis for processing personal data and, for health data, an additional condition for handling this more sensitive category. The core principles are that data is used lawfully, fairly and transparently, is collected for specified purposes and not used in ways incompatible with them, is limited to what is necessary, is accurate and kept up to date, is kept no longer than needed, and is held securely. People also have rights over their own information, including the right to be told how it is used and, through a subject access request, the right to a copy of the personal data held about them, subject to limited exemptions and usually within one month. A subject access request is handled by the data controller, which may be the club, clinic or employer rather than the individual doctor, and it provides a copy of the person's personal data rather than necessarily an unredacted copy of every original document, since third-party information and other limited exemptions may apply. For the doctor, this also means holding only what is needed, keeping it secure, sharing it only with a proper basis, and supporting an athlete's access to their own information.
Records in the Sporting Setting
The sporting setting complicates records in ways the doctor must handle carefully. Clinical records made by the medical team should be kept distinct from the operational information a club holds, so that sensitive clinical detail is not freely available to coaching or management staff. This is about purpose limitation and role-based access rather than necessarily storing the two physically apart: a secure system may hold both, provided coaching and management staff cannot see clinical detail they do not need. Sharing clinical information with performance staff, or with anyone outside the treating team, generally needs the athlete's consent or another clear legal basis, and only the information that is necessary should be shared, a theme developed in the material on confidentiality. When an athlete moves between clubs, their medical records should be handled with the same care: the athlete is entitled to their information, and transfer of records should happen with their consent and by secure means, not through informal channels. Electronic systems bring convenience but also risk, so access should be limited to those who need it, and security measures such as controlled access and secure storage matter. Retention should follow recognised guidance rather than keeping everything indefinitely or discarding records too soon.
Consider an athlete who transfers to a new club and asks for a copy of their medical records, and whose new club also wants the records transferred. The athlete has a right to their own information, so a copy should be provided to them securely. The records should be shared with the new club's medical team only with the athlete's consent, limited to what is relevant, and sent by a secure route, rather than emailed informally or handed to non-medical staff. If the athlete wanted only certain information shared, that wish should be respected within what is clinically safe.
Key Principles
•Records are special category data; hold only what is needed and keep it secure.
•Keep clinical records distinct from a club's operational information.
•Share clinical information outside the treating team only with consent or a clear legal basis.
•An athlete has a right to a copy of their own records; transfer records securely and with consent.
Common Pitfalls
A common failing is a poor record itself: not contemporaneous, vague, or missing the reasoning behind a decision, which weakens both care and any later account of it. Altering a record after the event, rather than adding a dated correction, is a serious error. On data protection, a frequent problem is merging clinical detail into club systems so that sensitive information is seen by people who have no need for it, or sharing information with coaching staff without consent. Sending records by insecure means, or handing them to non-medical staff during a transfer, risks a breach. Keeping records for too long, or destroying them too soon, both cause problems, as does failing to recognise an athlete's right to access their own information. Treating a well-known athlete's information with any less care than anyone else's is a mistake.
Exam Tips
•Good records are contemporaneous, clear, factual, and explain the reasoning behind decisions.
•Do not alter records after the event; add a dated correction and keep the original visible.
•Health information is special category data under the Data Protection Act 2018 and UK GDPR.
•Hold only what is necessary, keep it secure, and share it only with a proper basis.
•Keep clinical records distinct from a club's operational information.
•An athlete has a right to access their own records through a subject access request.