Can Posting Hospital Experiences Online Breach Medical Privacy?
Introduction
Sharing a hospital experience online may help inform the public, document poor service, or warn others about possible risks. However, a post may also expose medical records, diagnoses, photographs, names, or other details that identify a patient, nurse, doctor, or hospital employee.
Philippine law protects medical information and imposes duties on patients, healthcare workers, hospitals, employers, media organizations, and social-media users. Liability may arise when a post identifies a patient or healthcare worker, discloses private records, or uses confidential information to damage another person’s reputation.
What Medical Information Is Protected?
Health information is generally treated as sensitive personal information. This includes a person’s diagnosis, treatment, laboratory results, hospital admission, medical history, and other information that reveals the person’s health condition.
The Data Privacy Act also recognizes privileged information and permits personal information controllers to invoke privileged communication over privileged information that they lawfully control or process. Evidence gathered from such information may be inadmissible, subject to existing laws and regulations (R.A. No. 10173).
The Supreme Court has recognized that patients reasonably expect privacy regarding their identities and consultations with medical specialists. It also explained that information which appears harmless when viewed separately may reveal private patterns when combined with other details (Integrated Bar of the Philippines, et al. v. Purisima, et al., G.R. Nos. 211772 and 212178, 2023).
What Does the Data Privacy Act Require?
Processing sensitive personal information is generally prohibited unless a lawful exception applies. Section 13 of the Data Privacy Act allows processing in specific circumstances, including consent, compliance with law, medical treatment, protection of life and health, and the protection or exercise of lawful rights in court proceedings (R.A. No. 10173).
Consent is not the only possible legal basis, but it must be specific when consent is relied upon. A person’s decision to post about their own hospital experience does not automatically authorize the disclosure of another person’s medical information, name, image, or employment details.
All processing must also comply with the principles of transparency, legitimate purpose, and proportionality. Information should be collected, used, or disclosed only to the extent reasonably necessary for the stated purpose.
When Can a Hospital Disclose Medical Records?
The National Privacy Commission has held that attaching medical records to a cyber-libel complaint may be lawful when the records are necessary to protect legal rights, establish a claim, or defend against allegations in court or before a government authority. The lawful basis was Section 13(f) of the Data Privacy Act (NPC 22-201, 2024).
That exception is not unlimited. The word “necessary” requires proportionality. A hospital should disclose only records that are relevant and reasonably needed for the legal proceeding, rather than releasing an entire medical file without justification.
The National Privacy Commission also emphasized that ownership of the physical or digital copy of a medical record does not amount to ownership of the personal data contained in it. A hospital cannot use a patient’s data in any manner it chooses merely because the hospital maintains the record (NPC 22-201, 2024).
Can a Patient Post About a Hospital Experience?
Generally, a patient may describe their own experience, express an opinion, and report an event of public or personal concern. Nevertheless, the post should avoid revealing information about other patients, healthcare workers, or bystanders without a lawful basis.
A patient should be especially careful when uploading:
- Photographs showing medical charts, wristbands, laboratory results, prescriptions, or computer screens;
- Names, faces, telephone numbers, addresses, or employment details of nurses, doctors, and other staff;
- Details that identify another patient, even if that patient’s name is omitted;
- Audio or video recordings of consultations, procedures, or private conversations; and
- Claims based on records obtained from a hospital rather than personal observation.
Removing a person’s name may not be enough. A combination of the hospital, date, room, diagnosis, photograph, and other facts may allow readers to identify the person.
What Are the Risks for Nurses and Hospital Employees?
Nurses and other healthcare workers are bound by professional confidentiality. Information acquired in the course of patient care should not be posted on personal accounts, group chats, or private online communities merely because the account is restricted to selected viewers.
The confidentiality duty may apply to a person who obtains confidential information in an official capacity, including healthcare professionals, medical technologists, nurses, hospital personnel, and other persons involved in counseling, testing, or professional care (R.A. No. 11166).
A nurse may therefore incur liability for posting a patient’s diagnosis, photograph, room number, medical incident, or identifiable story, even if the post is intended as an anecdote or educational material. Permission from a colleague or supervisor does not necessarily replace the patient’s legally sufficient consent.
What Are the Risks Under the Philippine HIV and AIDS Policy Act?
HIV-related information receives heightened protection. The confidentiality of a person who has been tested for HIV, exposed to HIV, diagnosed with HIV infection, or treated for an HIV-related illness is guaranteed under the Philippine HIV and AIDS Policy Act.
Disclosing information that identifies a person as having AIDS, having undergone an HIV-related test, having HIV infection or illness, or having been exposed to HIV is unlawful without written consent, unless a statutory exception applies (R.A. No. 11166).
The law also prohibits media and social-media disclosure of the name, photograph, or information that would reasonably identify a person living with HIV or AIDS without prior written consent, subject to the exceptions recognized by law (R.A. No. 11166).
A breach of confidentiality by a health professional, employer, data custodian, or other covered person may result in imprisonment of five years and one day to seven years and a fine of P350,000 to P500,000, without prejudice to civil or administrative liability (R.A. No. 11166).
Can Medical Records Be Used in a Legal Complaint?
Yes, but the disclosure must have a lawful basis and must be proportionate to the legal purpose. Section 13(f) of the Data Privacy Act permits processing of information necessary for the protection of lawful rights and interests in court proceedings, the establishment, exercise, or defense of legal claims, or submission to a government or public authority (R.A. No. 10173).
In JPV v. Souley MD Services, Inc., the National Privacy Commission dismissed a complaint involving medical records attached to a cyber-libel complaint. The records were used to address allegations concerning the patient’s treatment and the hospital’s conduct, and the Commission found a lawful basis under Section 13(f) (NPC 22-201, 2024).
The decision does not mean that every disclosure in a complaint is permissible. The records must remain relevant to the claim, limited to what is reasonably necessary, and handled in a manner that protects the data subject from unnecessary exposure.
When May a Social-Media Disclosure Become Unauthorized?
Unauthorized disclosure under the Data Privacy Act may arise when a personal information controller or processor discloses personal or sensitive personal information to a third party without consent or another lawful basis. The disclosure must also satisfy the other statutory elements of the offense.
A post is more likely to create legal risk when it:
- Reveals identifiable medical information about another person;
- Shows a patient’s records, test results, or hospital forms;
- Names or depicts a nurse or doctor in connection with a private patient incident;
- Discloses HIV-related information without written consent; or
- Uses confidential information to malign, injure, or cause loss to another person.
The Data Privacy Act does not automatically prohibit criticism of a hospital or a personal account of treatment. The legal issue is whether the post contains protected personal information and whether the disclosure has a lawful basis.
Does Privacy Law Prohibit Criticism of Hospitals?
No. Privacy law does not give hospitals immunity from fair criticism, legitimate complaints, or truthful accounts based on a patient’s own experience. A person may report a concern to the hospital, Department of Health, professional regulator, law-enforcement agency, court, or other proper authority.
However, the method of disclosure matters. Publishing a complete medical chart or identifying a staff member to a large online audience may go beyond what is needed to report the concern. A complaint to the proper authority is ordinarily less intrusive than a public post containing identifiable medical details.
Separate liability may also arise from defamatory statements, threats, harassment, or unlawful recording. Privacy compliance does not by itself resolve every issue arising from online speech.
How Should Patients Post Safely?
Before posting, patients should separate the account of their own experience from information concerning other people. A safer post generally omits names, faces, medical records, room numbers, exact dates, and other details that can identify third parties.
Patients should also:
- Blur or remove all medical records, identification bands, prescriptions, and computer screens;
- Obtain written permission before posting another person’s image or medical information;
- Use private complaints and regulatory channels when disclosure of records is necessary;
- Distinguish personal observations from allegations about professional misconduct; and
- Preserve original records privately rather than uploading them publicly.
If a post has already disclosed private information, the person should promptly preserve evidence, remove unnecessary copies, notify the affected person or institution where appropriate, and seek legal advice before making further statements.
How Should Nurses and Hospitals Handle Online Content?
Healthcare institutions should maintain written social-media and confidentiality policies, limit access to patient records, train personnel on privacy duties, and establish procedures for responding to online disclosures.
Nurses and hospital workers should never assume that a post is safe because it contains no patient name. A unique story, unusual diagnosis, photograph, location, or combination of facts may identify the patient.
When a disclosure is necessary for patient care, institutional reporting, or legal proceedings, the institution should document the purpose, limit the information disclosed, restrict access, and use secure channels. The record should also show why the disclosure was necessary and proportionate.
What Penalties May Apply?
Possible consequences include administrative sanctions, professional discipline, civil damages, criminal prosecution under the Data Privacy Act or other applicable laws, and liability under special statutes such as the Philippine HIV and AIDS Policy Act.
For a lawyer, online disclosure of confidential information obtained from a client or during representation may also violate the Code of Professional Responsibility and Accountability, which prohibits direct or indirect disclosure of confidential information through online posts unless allowed by law or the Code of Professional Responsibility and Accountability (A.M. No. 22-9-1-SC).
Professional duties may therefore apply in addition to privacy legislation. The same conduct may raise separate issues involving confidentiality, ethics, defamation, unauthorized disclosure, or misuse of privileged information.
Practical Examples
Example 1: Photograph of a chart. A patient posts a photograph of a hospital chart to support a complaint about treatment. If the chart contains another patient’s name or medical information, the post may expose the patient and create privacy liability. The safer course is to crop or redact unrelated information and submit the complete record only to the proper authority.
Example 2: Nurse’s story post. A nurse describes an unusual case without naming the patient. If the hospital, date, diagnosis, and circumstances identify the patient, the post may still breach confidentiality.
Example 3: Cyber-libel complaint. A hospital attaches relevant portions of a patient’s record to a complaint to rebut specific allegations about treatment. The disclosure may fall under Section 13(f) of the Data Privacy Act if it is necessary, relevant, and proportionate.
Example 4: HIV disclosure. A healthcare worker posts that a named person tested positive for HIV. This may violate the confidentiality protections and penalties under the Philippine HIV and AIDS Policy Act, even if the worker believes the information is true.
Final Observations
Posting a hospital experience online is not automatically unlawful. The principal question is whether the post discloses identifiable personal or medical information about another person without consent or another lawful basis.
The safest approach is to disclose only what is necessary, remove identifying details, secure written consent when another person is involved, and use formal complaint channels when medical records are needed as evidence. Hospitals and healthcare workers should treat every patient story, image, record, and unusual clinical detail as potentially confidential.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

