“Your Information Is Confidential and Used for Your Care”
- Cindy Hansen

- Jul 19
- 5 min read

There’s a sentence nearly every clinician has said, in some form, thousands of times: your information is confidential, and it’s used for your care.
For most of the history of this profession, that sentence was simply true. The record stayed in the chart. The chart stayed in the clinic. Confidentiality had edges you could point to, and consent described something both people in the room understood. This post is about what’s happened to that sentence
What the sentence assumes when a client hears “used for your care,” they understand something specific: the information they share will be seen by the people helping them, for the purpose of helping them, for as long as helping them requires.
That consent is specific, ongoing, and tied to a therapeutic relationship.
It’s why clients tell you things they tell no one else.
What’s actually happening — and how often
Here’s the part I want to slow down on, because when I looked at the published
research, the scale surprised even me.
Training AI models on people’s linked health records isn’t an edge case, a pilot project,
or something on the horizon. It is now the standard method in the field. The published record reads like this: one widely cited model was trained on the longitudinal health histories of 1.6 million patients. Another, 3.4 million. Another, 28 million. A recent one: 55 million patient records. Not scattered anonymous data points —
sequences. A person’s encounters, diagnoses, medications, and outcomes, linked over
time. A compressed version of a clinical life. That’s exactly what makes these records valuable for training. It’s also exactly what makes them personal.
So the honest answer to “how often is this happening?” is: routinely, at population scale,
right now. Tens of millions of people’s clinical lives are already inside trained models.
Was consent obtained? In most cases, the question was never even required to be
asked. Under the prevailing research rules, once data is de-identified, it falls outside
research ethics review altogether — no research subject is considered present, so no
consent question arises. Notice what that means. Nobody broke a rule. The rules simply resolve the consent question before anyone examines what the data has become.
That’s the gap. Not misconduct — a category that no longer fits the object.
Why this is not on you
If you’re reading this with a sinking feeling — pause. You haven’t breached your ethical obligations by using digital tools. An obligation you can’t see and can’t verify isn’t one you can be said to have failed. Platforms generally comply carefully with what the law requires — but much of what happens after de-identification falls outside what the law requires anyone to explain. Most professional guidance doesn’t yet tell you what to ask. And most consent forms in use today were written before any of this existed.
But there is one place where this reality does reach directly into clinical work, and it
deserves naming plainly: consent accuracy.
Here is the part that is genuinely hard to see. Linking a client’s records across time,
adding notes, scores, and summaries — none of that breaches confidentiality or
consent. That is care working as promised. The promise comes apart one step later:
once that assembled record is de-identified, it can leave the care relationship entirely —
stored on servers elsewhere, moved across borders, accessed for analytics, eligible to
train models — because as “de-identified data,” it is no longer treated as the client’s
information at all. The words “confidential and used for your care” were true inside the
room. The infrastructure carries the record somewhere the words never covered.
Not through anyone’s bad faith. But the moment you know, something shifts.
Consent should travel as far as the data does. And where it can’t, consent language
should at least tell the truth about the journey.
If curiosity is stirring the Digital Clinical Data Governance Checklist was built for exactly this kind of looking. It’s not a compliance audit and it doesn’t require technical expertise — it’s a plain language way of exploring what your tools collect, where data travels, and whether your consent language matches reality. It’s free, and it’s an invitation to look, nothing more.
Canada is writing the rules right now
Here is why this moment matters more than most. The Digital Governance Standards
Institute has opened public consultation on a proposed National Standard of Canada for
patient-controlled verifiable health records. The model it describes is a genuine shift:
instead of records living only inside institutional systems, healthcare encounters would
be issued directly to patients as verified records, held in digital wallets under their own
control. Mental health records are explicitly in scope.
Notice how directly this speaks to everything above. The promise “confidential and used
for your care” came apart because the record’s journey became invisible — assembled,
de-identified, and travelling to places the words never covered. A patient-controlled
record is an attempt to make that journey visible again, and to put the person back at
the centre of it.
And the questions the standard will have to work through are the very ones this post has
been circling. When wallet-held records accumulate and link over a lifetime, what
governs the representation that forms — not just each individual exchange? Does consent cover only the moment of sharing, or also what the shared records become in analytics, research, and model training? Do AI-derived outputs — the summaries, the risk scores — inherit the consent and constraints of the records they came from? Whether the final standard answers these well depends on who shows up to the
consultation.
That is where you come in. The consultation is open until 29 August 2026, through dgc-
cgn.org, and healthcare providers are named among the stakeholders invited to
respond. Clinicians rarely think of standards development as their territory. It is.
The people who sit inside the therapeutic relationship know things about consent that no
technical committee can know without them.
The human in the room
The therapeutic relationship is still where trust is built — one encounter at a time.
Protecting it now includes understanding the systems underneath it. That’s not a burden
this profession asked for. But it’s one clinicians are unusually well equipped to carry —
you already know how to hold a promise carefully.
The sentence can be true again. It just has to be updated to match the world it’s spoken in.
Three doors, depending on where you are
Respond to the proposed standard. The public consultation on patient-controlled verifiable health records is open until 29 August 2026. Your perspective from inside the therapeutic relationship is exactly what a technical committee cannot supply for itself. Read the proposal and respond.
Look at your own systems. The Digital Clinical Data Governance Checklist is free, plain-language, and licensed CC BY 4.0 — an invitation to understand what your tools collect, where data travels, and whether your consent language matches reality. Download it here. https://zenodo.org/records/19765798
If you use it to start a conversation in your clinic, I’d genuinely like to hear how it goes.
Walk through it together. If you’d like company for the looking, I offer guided checklist consultations — working through the CDGC with you or your team, applied to your actual platforms and consent language.
.png)


