Info Gov

NHS England has instructed every trust in England to suspend immediately any member of staff suspected of accessing patient records without a legitimate reason and to remove their access to NHS systems while the facts are established, in a letter from chief executive Sir Jim Mackey announcing a zero-tolerance approach to what he called snooping.

The letter, sent to trusts on Friday 25 September, asks organisations to act at the point of suspicion rather than waiting for the outcome of an internal investigation. Mackey said patient records hold some of the most private information a person will ever share and that the NHS had seen too many cases of staff abusing that trust. Leaving a suspected individual in post with continued access while an investigation ran for days or weeks was, he said, no longer acceptable.

Trusts are asked to take three steps where unauthorised access is suspected: suspend the individual, cut off their access to NHS systems immediately, and, where the person is a registered healthcare professional such as a doctor or nurse, refer the case to the relevant professional regulator. Mackey warned that anyone looking at a record out of curiosity would be found out, could lose their career and could end up with a criminal record.

The letter describes unauthorised access by NHS employees as unlawful, damaging to public confidence and a serious failure of the duty to protect patient privacy. Mackey said the public outrage was understandable and that the conduct of a minority was tarnishing the reputation of colleagues who take pride in their work. He noted the incidents had continued despite new guidance and a communications toolkit on preventing and monitoring unlawful access, issued to NHS organisations in July.

Unauthorised access to patient records engages both the confidentiality obligations on NHS staff and data protection law. Knowingly or recklessly obtaining personal data without the controller's consent is a criminal offence under section 170 of the Data Protection Act 2018, prosecuted by the Information Commissioner's Office, while the trust as controller remains responsible under Article 5(1)(f) and Article 32 UK GDPR for access controls, monitoring and audit trails capable of detecting misuse. Confirmed incidents may also be reportable personal data breaches under Article 33.

NHS England's intervention follows a run of high-profile cases. Dozens of staff at University Hospitals of Liverpool Group were found in May to have viewed the records of victims of the 2024 Southport attack. In Nottingham, 11 staff were dismissed and 14 more disciplined after accessing the records of Barnaby Webber, Grace O'Malley-Kumar and Ian Coates, killed in 2023.

Around 40 hospital staff viewed the records of a three-year-old boy injured in a fall into a crocodile enclosure in Cambridgeshire in June. This week Southmead Hospital in Bristol confirmed an investigation into allegations that staff accessed the records of Oliver McGowan, who died in 2016, and the ICO recently issued a caution to a former private hospital worker who attempted to obtain and sell the medical records of the Princess of Wales.

A Health Service Journal investigation published this month found at least 214 NHS staff had lost their jobs and around 2,000 had been sanctioned for inappropriate access to patient data over the past five years.

Paula McGowan, Oliver's mother, welcomed the commitment but said it must be followed by meaningful action, describing access without a legitimate clinical or professional reason as a serious breach of trust that must have consequences.

NHS England's announcement can be viewed here: https://www.england.nhs.uk/2026/09/nhs-staff-suspected-snooping-patient-records-immediately-suspended/

Also in this section

Sep 23, 2026

Prime Minister announces new National Centre for Information Defence

Prime Minister Andy Burnham has tasked the UK's security chiefs with establishing a National Centre for Information Defence to detect, attribute and disrupt hostile state information attacks, telling the UN General Assembly in New York on 22 September that AI would "multiply the threat" from disinformation and deepfakes.
Sep 11, 2026

Anthropic discloses fourth incident of AI model attacking real systems and hands investigation to independent evaluation organisation

Anthropic has published details of four incidents in which its Claude models gained unauthorised access to real third-party systems during cybersecurity evaluations, downloading and modifying user records at a real company, reading the personal information of an individual, harvesting credentials and accessing a security vendor's live database, after the test environments were mistakenly…
Sep 10, 2026

Welsh environmental watchdog hit by data breach

Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public.
Aug 24, 2026

Ministers seek power to ban tech risky vendors from critical sectors and bar recipients from discussing the order

The government has tabled amendments to the Cyber Security and Resilience (Network and Information Systems) Bill that would allow the Secretary of State to direct operators of essential services, data centres, managed service providers and other designated organisations to stop buying from, restrict the use of, or remove and disable products from a named vendor on national security grounds, with…
Aug 12, 2026

ACRO Criminal Records Office reprimanded by ICO following cyber security failings

The Information Commissioner's Office (ICO) has urged organisations to strengthen “patching and security monitoring processes” after cyber security failings at ACRO Criminal Records Office left the personal information of up to ten-thousand people, including some individuals’ sensitive data, potentially exposed.

InfoGov Masthead Newsletter 800