Can we share patient records with insurers and TPAs?
Short answer: Yes for the patient's claim; only what it needs
Yes, for a claim the patient has asked for, because that is part of the purpose. Share only what the claim needs, through the TPA portal or a secure channel, and keep a record of what was sent. Sharing for anything else, such as an insurer's own marketing, needs consent.
What the law says
Section 7(a) covers the claim purpose; Section 8(1) and 8(5) apply to how data is sent.
Section 7: Some uses need no consent: data a person gave voluntarily for a specified purpose, duties under law, medical emergencies involving a threat to life, health services during an epidemic, safety during a disaster, and purposes of employment.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Sections 11–14 · Rule 14: People can ask for a summary of their data and who it was shared with, ask for correction, completion, updating or erasure, complain, and nominate someone to act for them. You must publish how to do this.
Steps
Use TPA portals, not email.
Send only claim documents.
Log what was sent, to whom, when.
Answer patient questions about sharing.
Check TPA agreements.
Evidence to keep
Sharing log
TPA agreement
Common mistakes
Full case files by email
No record of what was sent
Insurer representatives reading records on wards
From each seat
DPO / Privacy lead: Patients often ask who received their data; this log answers it.
CEO / MD: Fast cashless and privacy can both work through portals.
Chief risk officer: TPA flows are a vendor risk line.
Finance department: Billing owns this flow.
What a good answer from management sounds like
“Claims go through portals with only the needed documents, and every transfer is logged.” Effort and time: Light to medium.