Connect with us

NEWS

NHS Trusts Told to Lock Out Staff on Snooping Suspicion

NHS England told 205 trusts to suspend suspected record snoopers at once, after July’s campaign and weak audits failed to stop curiosity access.

Published

on

NHS England chief executive Sir Jim Mackey told all 205 trusts on 25 September to suspend staff at once if they are suspected of looking at patient records without a clinical reason. He said trusts must suspend staff and cut their computer access while the facts are established, and he called the stance zero tolerance.

The letter treats snooping as a discipline failure. The harder problem sits underneath it. Hospital computers still let a curious click through, most trusts do not hunt for that click, and patients often find out only if they ask.

Mackey Already Ran This Campaign in July

On 8 July, Mackey issued a July warning of sack or prison for staff who opened records out of curiosity. NHS England put posters and screensavers on wards with the line “let curiosity kill your career,” and it published new guidance on how to prevent and monitor unlawful access.

That pack already told employers they may report a case to the Information Commissioner’s Office and the police, both of which can bring a criminal case, and to professional regulators that can end a career. Newer electronic record systems, it said, may flag odd access in real time. Older ones still depend on someone pulling an audit log after the fact.

Patient records contain some of the most private information people will ever share. We have seen too many cases of people abusing that trust, and enough is enough.

Sir Jim Mackey, NHS England chief executive, 25 September 2026

He added that anyone who thinks they can satisfy curiosity by opening a file “will be found out, they may lose their career and could end up with a criminal record.” Immediate suspension while an inquiry runs is already supposed to be normal. In practice it has not been.

THE 2026 CRACKDOWN CALENDAR

  1. 22 June 2026: ICO chief executive Paul Arnold writes that curiosity is not an excuse, and that high-profile cases point to a trend the health service has to meet.
  2. 8 July 2026: NHS England launches the screensaver campaign and monitoring guidance for every trust.
  3. 7 September 2026: Freedom of information returns from trusts put hard numbers on sackings, warnings and how few organisations hunt for breaches.
  4. 24 September 2026: Bristol confirms staff opened Oliver McGowan’s records years after his death, including in 2026.
  5. 25 September 2026: Mackey’s lockout letter goes to 205 trusts, and Nottingham University Hospitals confirms its first sackings.

Two months of posters did not stop the next wave of cases. Friday’s letter is the HR version of the same warning, with a harder instruction: pull the person out first, then establish the facts.

54 of 134 Trusts Admit They Rarely Look

A joint FOI exercise completed in September found 214 staff dismissed for inappropriate access, three suspended and 540 given a final written warning. About 2,000 people were sanctioned in some form since 2020, a wider net that includes the lesser penalties. One worker had opened up to 179 people’s files. Another had opened a spouse’s record in a potential domestic violence situation. Others had passed what they found into WhatsApp groups.

Those sackings sit inside a larger pile of data-breach work. Trusts investigated 2,914 data-breach cases since 2021 and sent 409 of them to the ICO. Some 67% of the breach cases ended in a minor sanction such as an informal or written warning, or in no further action. Health minister Gillian Merron said health bodies reported 1,445 cases of inappropriate access to the ICO between 2019 and 2025, a longer window and a different count from the 409 FOI referrals since 2021.

THE FOI TALLY

What the returns showed Figure
Staff dismissed for inappropriate access 214
Final written warnings 540
Staff suspended 3
Data-breach cases investigated since 2021 2,914
Those cases sent to the ICO 409
Share of breach cases ending in a minor sanction or none 67%
Trusts that said they routinely hunt for breaches 54 of 134

Only 54 of 134 trusts that answered the audit question said they routinely look for potential breaches. The rest are waiting for a complaint, a journalist, or a famous name on a ward list. Liberal Democrat MP Layla Moran, who chairs the health and social care select committee, has called official Data Protection Act counts “canaries in the coal mine.”

Patients Are Left to Discover the Breach Themselves

NHS England’s July pack included a note for patients on how records should be used and what to do if they think someone opened them without a reason. That still puts the burden on the patient. There is no automatic ping when a staff login hits a file that has nothing to do with their care.

Southport attack survivor Leanne Lucas, a teacher injured in the July 2024 stabbings, was not told her records had been opened until 2026, two years after the breach. The ICO had been told in August 2024. She learned as the story was about to appear in print. After Mackey’s letter she said she was “really pleased to see that people in these positions have listened to us and they’re taking it seriously.”

Paula and Tom McGowan found the same gap by filing paperwork. Their son Oliver, who was autistic and had epilepsy, died in 2016 at Southmead Hospital in Bristol, aged 18, after antipsychotic drugs his family had warned against. A subject access request showed 38 people had opened his records since his death, with 637 items viewed and 67 printed, some of that access as recently as 2026.

Of 22 staff still at the trust, 15 had a legitimate reason, such as care at the time or later inquiries. Five did not. Three nurses are under formal investigation. A doctor who has left the trust opened the file in March 2026 and self-referred to the General Medical Council. The trust has referred itself to the ICO. Tom McGowan said the family wants Mackey “to actually take action,” and that Oliver’s case is not isolated.

HOW FAMILIES FOUND OUT

  • Leanne Lucas: The trust knew in 2024 and told the ICO that August; she was told in 2026, as the breach was about to become public.
  • Paula and Tom McGowan: They learned through a subject access request, not a prompt from the hospital, that 38 people had opened Oliver’s file after he died.
  • The standard route: NHS guidance still tells people to request a log of who looked by making a subject access request, then to report anything that looks wrong.

If the deterrent is “you will be found out,” it currently means found out by a trust that chooses to audit, or by a family that knows to ask. Most patients will do neither.

Eleven Dismissals in Nottingham, Zero in Liverpool

High-profile files keep drawing staff. On the same day as Mackey’s letter, Nottingham University Hospitals published the first outcomes of the Nottingham investigations into the records of Ian Coates, Grace O’Malley-Kumar and Barnaby Webber, who were murdered by Valdo Calocane in June 2023.

The trust, which began the work in early 2025, dismissed 11 staff and took action against a further 14: two first written warnings and 12 final written warnings. That is 25 people in the first completed wave, including doctors, nurses, other registered staff, and admin and clerical colleagues. Families were being told that week. The ICO and Nottinghamshire Police have been informed. More files, including those of surviving victims Wayne Birkett, Sharon Miller and Marcin Gawronski, are still under review.

The families of Ian, Grace and Barnaby have had to endure much pain and heartache, and I am truly sorry that the actions of some of our staff have added to that.

Dr Manjeet Shehmar, medical director, Nottingham University Hospitals NHS Trust

Liverpool’s numbers landed differently. University Hospitals of Liverpool Group admitted in May 2026 that nearly 50 staff had inappropriately opened records of Southport attack victims treated at Aintree, including Lucas and a 13-year-old girl. The trust called the breach inexcusable. Nobody had been sacked at the point that admission was made.

Cambridge University Hospitals asked the ICO to look at a separate pile: 40 staff had opened the records of a three-year-old boy hurt after falling into a crocodile enclosure in Cambridgeshire in June. NUH is now installing a system that it says will monitor access, spot odd behaviour, and generate alerts. That work is still underway.

HIGH-PROFILE FILES

Case Staff identified What followed
Nottingham murder victims (attacks in 2023) 11 dismissed, 14 other actions in the first wave ICO and police told; more files still open
Southport attack victims (2024, revealed May 2026) Nearly 50 at Liverpool Trust called it inexcusable; no sackings as of May
Cambridgeshire crocodile-pit boy (2026) 40 staff ICO investigation requested
Oliver McGowan’s records after his 2016 death 38 people accessed the file; 5 without a clear reason GMC self-referral; trust referred itself to the ICO

Curiosity clusters around names already in the news. Arnold said as much in June: when a local incident becomes national news, the risk rises that staff will open records they have no reason to view. The July posters were aimed at that reflex. The September letter is aimed at the colleague still on the ward while HR takes “days or weeks.”

Paul Arnold Still Calls Inappropriate Access Rare

On 22 June, Arnold wrote that inappropriate access is rare and “does not represent the behaviour of the vast majority of healthcare staff who take their duty of confidentiality extremely seriously.” He also said recent famous cases were not isolated, and that this is “primarily a cultural challenge.”

His practical advice was blunt and cheap. When a serious incident is about to fill the news, a fast note from the top reminding staff of confidentiality has been “a genuinely effective deterrent.” Role-specific training, access limits and audit logs should sit behind that note. He asked every healthcare leader “whether your organisation is doing enough to prevent unauthorised access before it happens.”

WHERE EXPERTS DISAGREE

  • Paul Arnold, ICO: Inappropriate access is rare, the majority of staff keep the confidence, and the main job is culture plus a fast warning when a story breaks.
  • Layla Moran MP: The official Data Protection Act counts are likely “canaries in the coal mine,” not a full map of the harm.
  • Sam Smith, Med Confidential: Staff can often see records across parts of the service; “the protection is that you shouldn’t, not that you can’t,” and patients should get an NHS App notice when a file is opened.

Both things can sit in the same building. Most logins are legitimate, because care does not work if a nurse cannot open a record at speed. The FOI returns show that when a trust does look, it finds enough to sack 214 people and warn hundreds more, while 80 of the 134 trusts in that audit set did not say they routinely look at all.

The Computer Still Lets Curiosity Through

There is no single NHS-wide record that every worker can open. GPs, hospitals and clinics keep their own systems and set their own permissions. Staff still need fast access in an emergency. The legal line is simple: a login is not a licence. Arnold’s phrase is the cleanest version. Having the ability to view a record is not the same as having a legitimate need to do so.

Electronic systems keep a log of who opened what, and when. NHS England’s July guidance told information-governance teams to run routine manual audits if they have no automatic monitor, to check logs when a patient complains, and to watch for odd patterns such as night-time views or inactive files. It also told them to consider telling the people affected when a breach has occurred. That “consider” is doing a lot of work, given Lucas’s two-year wait and the McGowans’ paperwork trail.

Role-Based Access Still Depends on Trusts Switching It On

The July note asked trusts to use role-based controls so that only people who need a sensitive field can see it, and to use multi-factor logins. Some newer record systems can raise an alert flag as a suspicious open happens. Many organisations are not on those systems. NUH is still building one. NHS England’s planned Single Patient Record, in design through 2026 to 2028, is being sold in part as a better way to spot unusual access. That is an admission that today’s local logs are a poor hunter.

A Subject Access Request Is Still the Patient’s Main Tool

Guidance for staff is clear that people can ask who has opened and added to their record. In practice that means a formal request, a wait, and a family already worried enough to file one. Smith has argued that an automatic NHS App notice would do more to deter misuse than another poster, because “the only way to prevent abuse is to stop the secrecy that facilitates it.” Friday’s letter does not create that notice.

The same log that can show a snoop can show who changed, backdated or printed a file after a death. Families still have to fight for that evidence. If a system can suspend a nurse for opening a celebrity file, it can also show a bereaved parent who touched the notes after the funeral. That second use is not in the letter.

What Immediate Suspension Does Not Fix

Mackey’s instruction closes a narrow gap. A worker under suspicion will not keep a live login while HR takes a fortnight. Remote access goes with the ward terminal. That is a real change if trusts obey it.

It does not tell a trust how to treat an honest mis-click, the search for a common name that opens the wrong person. Replies to NHS England’s own announcement already flagged that risk and asked for a proper look at the log before a nurse is sent home. The letter’s sequence is the other way round: suspend, cut access, then establish the facts.

It also does not make a trust hunt. Fifty-four of 134 respondents already said they routinely look. The others will now have a harsher playbook for the cases they happen to catch. It does not give patients a ping, a dashboard, or a new right to the audit trail. Lucas still had to wait until the story was about to run. The McGowans still had to ask.

NUH is still working through surviving victims’ files in Nottingham. Bristol is still investigating Oliver’s. The 205 chief executives have the letter. The next test is whether the first staff member pulled off a shift is named because a live alert fired, or because a family, a journalist, or a famous case forced the log open.

Harry is the editor of REMEDIES HEALTH, an independent health title that he owns and runs, covering fitness, nutrition, food, mental health, public health and home remedies. He has been in journalism for ten years, a reporter before he was an editor, with most of that time on health and science, where the gap between a headline and the study behind it is usually the story. Articles are built from peer-reviewed trials, systematic reviews and meta-analyses, trial registry records, and the guidance published by public health bodies, with each study reported alongside its size, duration, comparator and funding source. Remedies are covered by what the evidence actually shows, including when it shows nothing, and fitness guidance is checked against training research rather than gym folklore. Nutrition numbers are verified against food composition databases before publication. Mistakes are handled under a public corrections policy, and a corrected article carries a note explaining the change. Nothing on the site replaces a clinician; readers with symptoms or on medication should seek proper medical care before changing what they do. Harry answers reader mail at support@remedieshealthfitness.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending