This lesson comes first for a reason: everything else you learn here stops being useful the day you paste something into a chat that should never have left the pharmacy. And the line is not where most people think it is.
Why this is different from a web search
Searching "warfarin ibuprofen interaction" discloses nothing about anyone. Typing "my 78-year-old patient with atrial fibrillation on warfarin has just bought ibuprofen" does two things at once, and you only notice one: you ask a question, yes — but you also transfer health data to a company you do not control.
UK GDPR treats health data as special category (Article 9): processing is prohibited by default unless a specific condition applies. "I needed it to answer a question" is not one of them. On top of that sits your professional duty of confidentiality, which is yours regardless of what the service's small print says. If you practise elsewhere, the names change — EU GDPR, HIPAA, PIPEDA, the Australian Privacy Act — but the shape of the rule does not.
What never goes in
- Names, surnames, unusual initials or nicknames ("the lady from the corner shop").
- NHS number, hospital number, National Insurance number, or any local patient ID.
- Phone number, email, address or postcode.
- Exact date of birth. Age is usually fine, if it does not single anyone out.
- Specific dates of a visit, admission or dispensing.
- The GP's or the surgery's name, which narrows the circle almost as much as the patient's.
- Photos or screenshots of a prescription, a discharge letter or your PMR screen — that carries all of the above at once, and you never read it first.
What you can ask, and how
Almost every real question can be phrased without a single identifier. The question loses nothing; the only thing that disappears is what was never needed.
How it comes out naturally
"I've got Jane Smith, 78, NHS 943 476 5919, from the Baker Street surgery, on warfarin since 03/02/2024, asking for ibuprofen for her knee. What do I do?"
How it should come out
"An anticoagulated patient in her late 70s on warfarin asks for an NSAID for joint pain. What are the alternatives and what should I monitor?"
The second version actually answers better: with the noise gone, the model stays on the clinical question. Stripping identifiers is not a bureaucratic toll — it usually improves the answer.
The three-filter rule
- Does the answer need it? If the reply would be the same without that detail, drop it.
- Does it single anyone out? Think of your high street, not the country. If someone local would know who you mean, drop it.
- Would you say it out loud in the queue? If not, don't type it either.
Check it before you paste it
Paste the text you were about to send. It is checked in your browser: nothing is uploaded, nothing is stored, and it never reaches our servers.
Before you choose a tool
Services are not equivalent, and the difference matters even when no patient data is involved:
- Free personal account: what you type may be used to train models unless you turn that off. It is the worst place for any professional question.
- Paid or business account: usually no training on your data and bounded retention. Better — still a third party.
- Under a data processing agreement: the only arrangement that would let you process personal data properly, and it needs paperwork and a risk assessment. If your pharmacy has not signed one, you do not have it.
A full example, and what is wrong with it
This is a real counter question, written by someone who has already been careful: no name, no ID number, no phone. It passes the checker above clean. And there are still four things wrong with it, and none of the four shows up in the reply.
What gets pasted: "Woman, 84, from the village, on long-term lithium, admitted to the local hospital last week. Now she is asking me for ibuprofen for her back. What do I tell her?"
In an 84-year-old woman on lithium who has recently been admitted, ibuprofen is not a good option. NSAIDs reduce renal lithium clearance and can push lithium levels into the toxic range within days; the risk is higher in older people, with already compromised renal function, and higher still after a recent admission, where there may have been dehydration or medication changes.
The reasonable alternative for mild-to-moderate back pain would be paracetamol, watching the total daily dose. If the pain does not settle, her doctor should review it before any NSAID is introduced, with lithium level and renal function checks.
If you like, tell me her creatinine and how long she has been on lithium and I will refine the advice. I can keep remembering this patient for future questions.
And now, what is wrong with that reply:
- The reply is good, and that is why nothing goes off. Clinically it is right: NSAID + lithium is a textbook interaction and the alternative is the correct one. The failure had already happened before you pressed send, and from then on there is no signal at all: no warning, no colour, no flag. This is what makes this lesson different from every other one here — elsewhere the error is in the reply and you can catch it by reading. Here there is nothing to read.
- "From the village" does the job the name used to do. Woman + 84 + lithium + admitted last week + local hospital. In a village of 900 people that is not a description: it is an identification, and one anybody local resolves in two seconds. The checker does not see it because there is no pattern to look for — it is not an ID number, it is a combination. Four facts that say nothing apart and pin down one person together is the literal definition of identifiable in recital 26 of the GDPR.
- The reply repeats it, and so does the chat title. Look at how it opens: "In an 84-year-old woman on lithium who has recently been admitted…". The detail was there once and now it is there twice. And almost every service titles the conversation by itself with a summary of your first question, so the sidebar — and the browser tab on the counter computer, in full view of whoever is standing there — reads something like "Lithium and NSAIDs in 84-year-old admitted patient". Deleting your message deletes neither copy.
- And the last line is the one to read twice. "Tell me her creatinine and how long she has been on lithium" is a reasonable question that invites two more facts, and answering it is the natural thing to do. "I can keep remembering this patient" is worse: that is the account's persistent memory, and it takes the detail out of this conversation and into every future one — including the ones somebody else opens on the same account. The conversation ratchets upward on its own, and every single step looks harmless.
The clean version of that same question fits on one line: "elderly patient on long-term lithium asks for an NSAID for back pain; what alternatives and what do I watch?". The clinical answer is exactly the same — try it — and nothing is left anywhere.
And that is the test worth internalising: if removing the detail does not change the answer, the detail was not there for the answer.
And if your pharmacy is not like that
When it does not work first time
Before moving on
- I can name five identifiers I never type.
- I can rephrase a real question without a single identifier.
- I understand that removing the name is not anonymisation.
- I have checked whether my account trains on my conversations.
- I know no automated tool can certify that a text is clean.
Sources. UK GDPR, Articles 4(1), 5 and 9 and Recital 26 (reasonable identifiability) · Data Protection Act 2018 · ICO guidance on anonymisation and on AI and data protection · GPhC standards for pharmacy professionals (confidentiality). Outside the UK, check your own regulator and data protection authority.