NHS England has instructed every trust in England to suspend immediately any member of staff suspected of accessing patient records without a legitimate reason and to remove their access to NHS systems while the facts are established, in a letter from chief executive Sir Jim Mackey announcing a zero-tolerance approach to what he called snooping.
The letter, sent to trusts on Friday 25 September, asks organisations to act at the point of suspicion rather than waiting for the outcome of an internal investigation. Mackey said patient records hold some of the most private information a person will ever share and that the NHS had seen too many cases of staff abusing that trust. Leaving a suspected individual in post with continued access while an investigation ran for days or weeks was, he said, no longer acceptable.
Trusts are asked to take three steps where unauthorised access is suspected: suspend the individual, cut off their access to NHS systems immediately, and, where the person is a registered healthcare professional such as a doctor or nurse, refer the case to the relevant professional regulator. Mackey warned that anyone looking at a record out of curiosity would be found out, could lose their career and could end up with a criminal record.
The letter describes unauthorised access by NHS employees as unlawful, damaging to public confidence and a serious failure of the duty to protect patient privacy. Mackey said the public outrage was understandable and that the conduct of a minority was tarnishing the reputation of colleagues who take pride in their work. He noted the incidents had continued despite new guidance and a communications toolkit on preventing and monitoring unlawful access, issued to NHS organisations in July.
Unauthorised access to patient records engages both the confidentiality obligations on NHS staff and data protection law. Knowingly or recklessly obtaining personal data without the controller's consent is a criminal offence under section 170 of the Data Protection Act 2018, prosecuted by the Information Commissioner's Office, while the trust as controller remains responsible under Article 5(1)(f) and Article 32 UK GDPR for access controls, monitoring and audit trails capable of detecting misuse. Confirmed incidents may also be reportable personal data breaches under Article 33.
NHS England's intervention follows a run of high-profile cases. Dozens of staff at University Hospitals of Liverpool Group were found in May to have viewed the records of victims of the 2024 Southport attack. In Nottingham, 11 staff were dismissed and 14 more disciplined after accessing the records of Barnaby Webber, Grace O'Malley-Kumar and Ian Coates, killed in 2023.
Around 40 hospital staff viewed the records of a three-year-old boy injured in a fall into a crocodile enclosure in Cambridgeshire in June. This week Southmead Hospital in Bristol confirmed an investigation into allegations that staff accessed the records of Oliver McGowan, who died in 2016, and the ICO recently issued a caution to a former private hospital worker who attempted to obtain and sell the medical records of the Princess of Wales.
A Health Service Journal investigation published this month found at least 214 NHS staff had lost their jobs and around 2,000 had been sanctioned for inappropriate access to patient data over the past five years.
Paula McGowan, Oliver's mother, welcomed the commitment but said it must be followed by meaningful action, describing access without a legitimate clinical or professional reason as a serious breach of trust that must have consequences.
NHS England's announcement can be viewed here: https://www.england.nhs.uk/2026/09/nhs-staff-suspected-snooping-patient-records-immediately-suspended/

