"We have seen too many cases of people abusing that trust"
NHS staff in England suspected of accessing patient records without a valid reason will be immediately suspended under a new “zero-tolerance crackdown” on snooping.
Those under suspicion will also be locked out of NHS computer systems, preventing them from accessing confidential records, including when working from home.
NHS England chief executive Sir Jim Mackey has ordered every trust to introduce the measures immediately as part of efforts to strengthen protections against unlawful access to patient data.
The move follows several high-profile incidents involving the records of Nottingham patients, victims of the Southport attack and a child injured in a crocodile enclosure in Cambridgeshire.
The NHS said the “hardline” approach is part of a wider crackdown on inappropriate access to medical records.
This includes a national campaign reminding staff of their responsibilities and the serious consequences of unlawful access.
NHS England’s chief executive Sir Jim Mackey said:
“Patient records contain some of the most private information people will ever share.
“We have seen too many cases of people abusing that trust, and enough is enough.
“Anyone who thinks they can satisfy their curiosity by looking at a patient’s record should know this: they will be found out, they may lose their career and could end up with a criminal record.”
The announcement comes after an investigation by the Health Services Journal found that at least 214 NHS staff had lost their jobs and around 2,000 had been sanctioned for snooping on sensitive patient data over the past five years.
Some cases involved staff accessing the records of high-profile patients because they were curious about their condition or care.
Others involved medical records belonging to relatives, acquaintances and former partners being accessed without authorisation. Some staff were subsequently struck off.
In 2023, an NHS consultant in Cambridgeshire was investigated by the General Medical Council after accessing the health history of a woman who had started dating the doctor’s ex-boyfriend.
There is no single electronic NHS record system that every member of staff can access.
Instead, GP practices, hospitals and specialist clinics maintain their own records and control which staff can view particular information.
These IT systems keep an audit trail designed to show who accessed a patient’s records and when, allowing organisations to investigate potential breaches.
Paula McGowan, whose autistic son Oliver died in 2016, was told that at least five staff members at Southmead Hospital may have accessed his records without permission as recently as this year.
Bristol NHS Foundation Trust said it was undertaking a “thorough investigation” and that it would be “inappropriate to reach conclusions before those enquiries are complete”.
McGowan welcomed the NHS’s commitment to tackling inappropriate access but said it must now be followed by “meaningful action”.
She added: “Medical records contain deeply personal information about people and their families.
“Accessing them without a legitimate clinical or professional reason is a serious breach of trust and must have consequences.”








