NEWS
NHS Trusts Told to Lock Out Staff on Snooping Suspicion
NHS England told 205 trusts to suspend suspected record snoopers at once, after July’s campaign and weak audits failed to stop curiosity access.
NHS England chief executive Sir Jim Mackey told all 205 trusts on 25 September to suspend staff at once if they are suspected of looking at patient records without a clinical reason. He said trusts must suspend staff and cut their computer access while the facts are established, and he called the stance zero tolerance.
The letter treats snooping as a discipline failure. The harder problem sits underneath it. Hospital computers still let a curious click through, most trusts do not hunt for that click, and patients often find out only if they ask.
Mackey Already Ran This Campaign in July
On 8 July, Mackey issued a July warning of sack or prison for staff who opened records out of curiosity. NHS England put posters and screensavers on wards with the line “let curiosity kill your career,” and it published new guidance on how to prevent and monitor unlawful access.
That pack already told employers they may report a case to the Information Commissioner’s Office and the police, both of which can bring a criminal case, and to professional regulators that can end a career. Newer electronic record systems, it said, may flag odd access in real time. Older ones still depend on someone pulling an audit log after the fact.
Patient records contain some of the most private information people will ever share. We have seen too many cases of people abusing that trust, and enough is enough.
Sir Jim Mackey, NHS England chief executive, 25 September 2026
He added that anyone who thinks they can satisfy curiosity by opening a file “will be found out, they may lose their career and could end up with a criminal record.” Immediate suspension while an inquiry runs is already supposed to be normal. In practice it has not been.
NHS staff suspected of improperly and unlawfully accessing patients’ medical records will face immediate suspension and have their access to NHS computer systems cut off, under a zero-tolerance crackdown on “snooping staff”.
Learn more ➡️ https://t.co/UL7veOBIk2 pic.twitter.com/ij86Ftvqk4
— NHS England (@NHSEngland) September 25, 2026
THE 2026 CRACKDOWN CALENDAR
- 22 June 2026: ICO chief executive Paul Arnold writes that curiosity is not an excuse, and that high-profile cases point to a trend the health service has to meet.
- 8 July 2026: NHS England launches the screensaver campaign and monitoring guidance for every trust.
- 7 September 2026: Freedom of information returns from trusts put hard numbers on sackings, warnings and how few organisations hunt for breaches.
- 24 September 2026: Bristol confirms staff opened Oliver McGowan’s records years after his death, including in 2026.
- 25 September 2026: Mackey’s lockout letter goes to 205 trusts, and Nottingham University Hospitals confirms its first sackings.
Two months of posters did not stop the next wave of cases. Friday’s letter is the HR version of the same warning, with a harder instruction: pull the person out first, then establish the facts.
54 of 134 Trusts Admit They Rarely Look
A joint FOI exercise completed in September found 214 staff dismissed for inappropriate access, three suspended and 540 given a final written warning. About 2,000 people were sanctioned in some form since 2020, a wider net that includes the lesser penalties. One worker had opened up to 179 people’s files. Another had opened a spouse’s record in a potential domestic violence situation. Others had passed what they found into WhatsApp groups.
Those sackings sit inside a larger pile of data-breach work. Trusts investigated 2,914 data-breach cases since 2021 and sent 409 of them to the ICO. Some 67% of the breach cases ended in a minor sanction such as an informal or written warning, or in no further action. Health minister Gillian Merron said health bodies reported 1,445 cases of inappropriate access to the ICO between 2019 and 2025, a longer window and a different count from the 409 FOI referrals since 2021.
THE FOI TALLY
| What the returns showed | Figure |
|---|---|
| Staff dismissed for inappropriate access | 214 |
| Final written warnings | 540 |
| Staff suspended | 3 |
| Data-breach cases investigated since 2021 | 2,914 |
| Those cases sent to the ICO | 409 |
| Share of breach cases ending in a minor sanction or none | 67% |
| Trusts that said they routinely hunt for breaches | 54 of 134 |
Only 54 of 134 trusts that answered the audit question said they routinely look for potential breaches. The rest are waiting for a complaint, a journalist, or a famous name on a ward list. Liberal Democrat MP Layla Moran, who chairs the health and social care select committee, has called official Data Protection Act counts “canaries in the coal mine.”
Patients Are Left to Discover the Breach Themselves
NHS England’s July pack included a note for patients on how records should be used and what to do if they think someone opened them without a reason. That still puts the burden on the patient. There is no automatic ping when a staff login hits a file that has nothing to do with their care.
Southport attack survivor Leanne Lucas, a teacher injured in the July 2024 stabbings, was not told her records had been opened until 2026, two years after the breach. The ICO had been told in August 2024. She learned as the story was about to appear in print. After Mackey’s letter she said she was “really pleased to see that people in these positions have listened to us and they’re taking it seriously.”
Paula and Tom McGowan found the same gap by filing paperwork. Their son Oliver, who was autistic and had epilepsy, died in 2016 at Southmead Hospital in Bristol, aged 18, after antipsychotic drugs his family had warned against. A subject access request showed 38 people had opened his records since his death, with 637 items viewed and 67 printed, some of that access as recently as 2026.
Of 22 staff still at the trust, 15 had a legitimate reason, such as care at the time or later inquiries. Five did not. Three nurses are under formal investigation. A doctor who has left the trust opened the file in March 2026 and self-referred to the General Medical Council. The trust has referred itself to the ICO. Tom McGowan said the family wants Mackey “to actually take action,” and that Oliver’s case is not isolated.
HOW FAMILIES FOUND OUT
- Leanne Lucas: The trust knew in 2024 and told the ICO that August; she was told in 2026, as the breach was about to become public.
- Paula and Tom McGowan: They learned through a subject access request, not a prompt from the hospital, that 38 people had opened Oliver’s file after he died.
- The standard route: NHS guidance still tells people to request a log of who looked by making a subject access request, then to report anything that looks wrong.
If the deterrent is “you will be found out,” it currently means found out by a trust that chooses to audit, or by a family that knows to ask. Most patients will do neither.
Eleven Dismissals in Nottingham, Zero in Liverpool
High-profile files keep drawing staff. On the same day as Mackey’s letter, Nottingham University Hospitals published the first outcomes of the Nottingham investigations into the records of Ian Coates, Grace O’Malley-Kumar and Barnaby Webber, who were murdered by Valdo Calocane in June 2023.
The trust, which began the work in early 2025, dismissed 11 staff and took action against a further 14: two first written warnings and 12 final written warnings. That is 25 people in the first completed wave, including doctors, nurses, other registered staff, and admin and clerical colleagues. Families were being told that week. The ICO and Nottinghamshire Police have been informed. More files, including those of surviving victims Wayne Birkett, Sharon Miller and Marcin Gawronski, are still under review.
The families of Ian, Grace and Barnaby have had to endure much pain and heartache, and I am truly sorry that the actions of some of our staff have added to that.
Dr Manjeet Shehmar, medical director, Nottingham University Hospitals NHS Trust
Liverpool’s numbers landed differently. University Hospitals of Liverpool Group admitted in May 2026 that nearly 50 staff had inappropriately opened records of Southport attack victims treated at Aintree, including Lucas and a 13-year-old girl. The trust called the breach inexcusable. Nobody had been sacked at the point that admission was made.
Cambridge University Hospitals asked the ICO to look at a separate pile: 40 staff had opened the records of a three-year-old boy hurt after falling into a crocodile enclosure in Cambridgeshire in June. NUH is now installing a system that it says will monitor access, spot odd behaviour, and generate alerts. That work is still underway.
HIGH-PROFILE FILES
| Case | Staff identified | What followed |
|---|---|---|
| Nottingham murder victims (attacks in 2023) | 11 dismissed, 14 other actions in the first wave | ICO and police told; more files still open |
| Southport attack victims (2024, revealed May 2026) | Nearly 50 at Liverpool | Trust called it inexcusable; no sackings as of May |
| Cambridgeshire crocodile-pit boy (2026) | 40 staff | ICO investigation requested |
| Oliver McGowan’s records after his 2016 death | 38 people accessed the file; 5 without a clear reason | GMC self-referral; trust referred itself to the ICO |
Curiosity clusters around names already in the news. Arnold said as much in June: when a local incident becomes national news, the risk rises that staff will open records they have no reason to view. The July posters were aimed at that reflex. The September letter is aimed at the colleague still on the ward while HR takes “days or weeks.”
Paul Arnold Still Calls Inappropriate Access Rare
On 22 June, Arnold wrote that inappropriate access is rare and “does not represent the behaviour of the vast majority of healthcare staff who take their duty of confidentiality extremely seriously.” He also said recent famous cases were not isolated, and that this is “primarily a cultural challenge.”
His practical advice was blunt and cheap. When a serious incident is about to fill the news, a fast note from the top reminding staff of confidentiality has been “a genuinely effective deterrent.” Role-specific training, access limits and audit logs should sit behind that note. He asked every healthcare leader “whether your organisation is doing enough to prevent unauthorised access before it happens.”
WHERE EXPERTS DISAGREE
- Paul Arnold, ICO: Inappropriate access is rare, the majority of staff keep the confidence, and the main job is culture plus a fast warning when a story breaks.
- Layla Moran MP: The official Data Protection Act counts are likely “canaries in the coal mine,” not a full map of the harm.
- Sam Smith, Med Confidential: Staff can often see records across parts of the service; “the protection is that you shouldn’t, not that you can’t,” and patients should get an NHS App notice when a file is opened.
Both things can sit in the same building. Most logins are legitimate, because care does not work if a nurse cannot open a record at speed. The FOI returns show that when a trust does look, it finds enough to sack 214 people and warn hundreds more, while 80 of the 134 trusts in that audit set did not say they routinely look at all.
The Computer Still Lets Curiosity Through
There is no single NHS-wide record that every worker can open. GPs, hospitals and clinics keep their own systems and set their own permissions. Staff still need fast access in an emergency. The legal line is simple: a login is not a licence. Arnold’s phrase is the cleanest version. Having the ability to view a record is not the same as having a legitimate need to do so.
Electronic systems keep a log of who opened what, and when. NHS England’s July guidance told information-governance teams to run routine manual audits if they have no automatic monitor, to check logs when a patient complains, and to watch for odd patterns such as night-time views or inactive files. It also told them to consider telling the people affected when a breach has occurred. That “consider” is doing a lot of work, given Lucas’s two-year wait and the McGowans’ paperwork trail.
Role-Based Access Still Depends on Trusts Switching It On
The July note asked trusts to use role-based controls so that only people who need a sensitive field can see it, and to use multi-factor logins. Some newer record systems can raise an alert flag as a suspicious open happens. Many organisations are not on those systems. NUH is still building one. NHS England’s planned Single Patient Record, in design through 2026 to 2028, is being sold in part as a better way to spot unusual access. That is an admission that today’s local logs are a poor hunter.
A Subject Access Request Is Still the Patient’s Main Tool
Guidance for staff is clear that people can ask who has opened and added to their record. In practice that means a formal request, a wait, and a family already worried enough to file one. Smith has argued that an automatic NHS App notice would do more to deter misuse than another poster, because “the only way to prevent abuse is to stop the secrecy that facilitates it.” Friday’s letter does not create that notice.
The same log that can show a snoop can show who changed, backdated or printed a file after a death. Families still have to fight for that evidence. If a system can suspend a nurse for opening a celebrity file, it can also show a bereaved parent who touched the notes after the funeral. That second use is not in the letter.
What Immediate Suspension Does Not Fix
Mackey’s instruction closes a narrow gap. A worker under suspicion will not keep a live login while HR takes a fortnight. Remote access goes with the ward terminal. That is a real change if trusts obey it.
It does not tell a trust how to treat an honest mis-click, the search for a common name that opens the wrong person. Replies to NHS England’s own announcement already flagged that risk and asked for a proper look at the log before a nurse is sent home. The letter’s sequence is the other way round: suspend, cut access, then establish the facts.
It also does not make a trust hunt. Fifty-four of 134 respondents already said they routinely look. The others will now have a harsher playbook for the cases they happen to catch. It does not give patients a ping, a dashboard, or a new right to the audit trail. Lucas still had to wait until the story was about to run. The McGowans still had to ask.
NUH is still working through surviving victims’ files in Nottingham. Bristol is still investigating Oliver’s. The 205 chief executives have the letter. The next test is whether the first staff member pulled off a shift is named because a live alert fired, or because a family, a journalist, or a famous case forced the log open.
-
FITNESS1 month agoMuscle-Boosting Drugs Near Approval for Children With SMA
-
NEWS4 weeks agoThe New Heart Attack Definition Recodes Women’s Missed Cases
-
NEWS1 month agoPennsylvania’s Two Measles Deaths Follow a Long Coverage Slide
-
NEWS2 months agoProgranulin and JAK2 Split the Macrophages That Heal
-
NEWS1 month agoRoche and Lilly Wager Alzheimer’s Care on a Blood Test
-
NEWS1 month agoPennsylvania Measles Deaths Collide With Falling MMR Coverage
-
MENTAL HEALTH1 month agoAfter the ADHD Invoice, GPs and Waiters Carry the Cost
-
NEWS1 month agoFDA Flagged This Sprout Plant 16 Months Before the Outbreak
