NMC CBT·PROFESSIONAL-PRACTICE · Module 1: Professional Practice and the NMC Code·UnitPROFESSIONAL-PRACTICE · Unit 02Access: Premium
Unit 1.2: Legal and Ethical Frameworks
Prepare for Unit 1.2: Legal and Ethical Frameworks with NMC CBT practice questions covering 4 topics. Part of Module 1: Professional Practice and the NMC Code — build your knowledge and track your progress with NMC Prep.
What’s in it.
4 topics- Topic 01
Consent and Mental Capacity
45 questions - Topic 02
Confidentiality and Data Protection
45 questions - Topic 03
Negligence, Duty of Care and Liability
45 questions - Topic 04
Whistleblowing and Raising Concerns
45 questions
Sample questions
3 of manyA few questions from this unit, with the answer and a full explanation. The complete bank is available when you start practising.
An NHS trust shares a dataset with a university research team, describing it as 'anonymised.' The dataset includes patient age, postcode sector, diagnosis, treatment date, and length of stay. The university team identifies that certain combinations of these fields allow re-identification of specific patients. What are the information governance implications for the trust?
- The trust only has data protection obligations if the re-identification of patients is deliberate rather than accidental or incidental
- If re-identification is possible by reasonable means, this remains personal data, not anonymised data, and the sharing may need ICO notificationCorrect answer
- As long as no names or NHS numbers are included in the dataset, the data cannot constitute a data breach under UK GDPR or ICO guidance
- The university team bears sole responsibility for any re-identification that occurs — the trust's obligations end at the point of transfer
ExplanationUnder UK GDPR Recital 26, data is personal data if individuals are identifiable by 'reasonable means,' even if direct identifiers are absent. If a combination of quasi-identifiers (age, postcode sector, diagnosis, treatment date, length of stay) allows re-identification, the dataset is personal data, not truly anonymised data. The trust's disclosure was therefore the sharing of personal data without a lawful basis, potentially constituting a data breach. The ICO Information Commissioner has provided guidance on anonymisation (the Anonymisation Code of Practice) setting out the standard for achieving true anonymisation. The trust should review the data sharing agreement, notify the ICO if required, and take steps to prevent recurrence.
A nurse administers a clearly incorrect medication dose, causing a patient to experience a severe adverse reaction requiring admission to intensive care. The patient sues. The nurse argues the pharmacist who dispensed the drug bears sole responsibility. Which analysis of liability is most accurate?
- Only the NHS trust is liable — vicarious liability means individual clinicians bear no personal responsibility
- Both may be liable — the nurse for an unsafe dose, the pharmacist for a mislabelled dispenseCorrect answer
- No individual is liable — medication errors in complex systems are treated as system failures only
- The nurse is fully liable because they administered the drug, regardless of the pharmacist's role
ExplanationEach professional in the medication administration chain owes an independent duty of care. The nurse is responsible for verifying the drug, dose, patient, route, and time before administering — if a dose is clearly unsafe, the nurse has a professional duty to query it before proceeding. The pharmacist owes a duty to dispense and label correctly. Both may have independently breached their duty of care, and both may share liability for the harm. The NHS trust may be vicariously liable for the actions of its employed staff. Individual professional accountability under the NMC Code means that following instructions (from the pharmacy or the prescriber) does not remove the nurse's personal responsibility if an obvious error should have been challenged.
A patient undergoes a hip replacement and post-operatively is found to have a permanent nerve injury in an area unrelated to the operation site. Res ipsa loquitur is pleaded. The defendant argues this doctrine does not apply because nerve injuries can occur in the absence of negligence. How should this argument be resolved?
- The claimant wins automatically because the nerve damage was unforeseeable and therefore cannot have occurred in the absence of clinical error
- Res ipsa loquitur applies automatically because the patient was under general anaesthetic and therefore unable to prevent the injury from occurring
- Res ipsa loquitur applies only where the event does not ordinarily happen without negligence — if such injuries can occur without fault, it may not applyCorrect answer
- Res ipsa loquitur always applies to any injury discovered post-operatively, as the patient was unable to protect themselves while under general anaesthetic
ExplanationRes ipsa loquitur requires that three conditions are met: (1) the event was of a kind that does not ordinarily occur without negligence; (2) the event was caused by an agent within the defendant's control; and (3) there was no negligence by the claimant contributing to the event. If a nerve injury at an unrelated site can occur as an inherent risk of surgery — for example, due to positioning or an unusual anatomical variant — then it is not of a kind that does not happen without negligence, and res ipsa loquitur may not apply. The defendant's argument is legally sound, and the claimant may need to prove negligence through conventional expert evidence.