Investigative Audit • Series 03

Statutory Rights Audit: How Health Trusts Use Flat PDFs to Hide Digital Medical Record Logs

Published by Independent Forensic Audit UnitUK GDPR Article 15 ComplianceICO Precedent & Access Rights

An examination of Subject Access Request (SAR) responses reveals how basic PDF printouts are used to withhold digital access logs and edit records, denying patients full transparency under UK GDPR Article 15.

1. Audit Trails Are Statutory Personal Data

Under established Information Commissioner’s Office (ICO) interpretations and binding case law, access logs and Change Data Capture (CDC) tables detailing who accessed a patient's medical file, when, and from which workstation constitute the personal data of that patient. Patients hold an explicit statutory right to know who processed their data.

2. The Three-Part Obfuscation Playbook

When applicants submit precise SARs demanding full digital telemetry (access logs, revision flags, deletion records), information governance departments frequently employ three standard avoidance tactics:

Tactic 1: Scope Narrowing

Supplying a flat PDF printout of a recent discharge summary and asserting that it constitutes the "complete medical record."

Tactic 2: Administrative Attrition

Citing "legacy system limitations" or claiming audit logs represent "system machine data" rather than disclosable personal medical records.

Tactic 3: Silent Severing

Exporting records where technical provenance has been severed, making it impossible to verify if unauthorized personnel viewed the file.

3. Statutory Enforcement & The 30-Day Clock

Under UK GDPR Article 12(3), controllers must respond to SARs without undue delay and at the latest within one calendar month. Refusing to disclose audit logs on the grounds of administrative inconvenience constitutes a reportable breach to the ICO.