Nottingham University Hospitals NHS Trust has reported a personal data breach to the Information Commissioner's Office after a script intended to copy a radiotherapy database was run against its legacy maternity system instead, overwriting records for women and babies treated between September 2011 and November 2022 and permanently destroying most of the audit trail showing who accessed them.
The trust said the error occurred on 18 August 2026 during routine technical work. Staff used a set of pre-written instructions that had previously been run against a different hospital system, but a setting that should have been changed before execution was missed. The process therefore ran on the maternity database, from the trust's former Medway system, rather than the radiotherapy database it was meant to copy.
Andy Callow, the trust's chief digital and information officer, apologised for the concern and distress the incident may cause to affected women and families, and said immediate action had been taken to investigate and recover the data. Working with external specialists and drawing on other sources, the trust says it has restored the clinical information needed for patient care, including notes, observations and test results.
It has not, however, been able to reconstruct the history of who viewed maternity records during the 11-year period, meaning that in most cases it may be unable to confirm whether a particular individual accessed a given record. Current maternity patients are unaffected and no patient information was accessed or used inappropriately as a result of the incident.
The period covered by the lost audit trail coincides with the maternity failings at Nottingham City Hospital and Queen's Medical Centre now under criminal investigation. Nottinghamshire Police launched Operation Perth in September 2023 and opened a corporate manslaughter investigation into the trust in June 2025, running alongside the Ockenden review, which reported in June 2026 that more than 500 mothers and babies suffered potentially avoidable harm or death as a result of systemic failures.
The trust has notified the force, which is assessing any impact on the investigation. Deputy Chief Constable Rob Griffin, gold commander for Operation Perth, said no crime had at present been identified and encouraged families with concerns to contact the investigation team.
The BBC reported that a separate police inquiry last year into a missing data file containing details of hundreds of maternity cases concluded it was most likely deleted intentionally or maliciously.
Under UK GDPR a personal data breach includes accidental destruction or loss of personal data as well as unauthorised disclosure, and article 33 requires controllers to notify the ICO within 72 hours of becoming aware unless the breach is unlikely to result in a risk to individuals. Article 5(1)(f) requires personal data to be processed in a manner that ensures its integrity and availability, and article 32 requires technical and organisational measures appropriate to the risk, including the ability to restore availability and access to personal data in a timely manner following an incident. The trust says the ICO was notified within the required timeframe.
The trust says the issue was escalated within minutes of being identified, that a full patient safety incident investigation has been completed, and that it has strengthened its technical controls and processes to prevent a recurrence. Its statement describes the incident as human error during a routine technical task.
The trust's statement is available here: https://www.nuh.nhs.uk/news/statement-nuh-data-loss-11205

