NHS Staff Sacked for Patient Record Access | The Daily Round
The UK’s fastest-growing news and insight platform for the care sector.

Looking for something specific? Try a search…

UK News

Latest Health & Social Care News

Stay up to date with the latest health and social care news from across the UK. From breaking stories and sector developments to the people, organisations and issues making the news.

More than 200 NHS staff sacked for inappropriately accessing patient records

Image for illustrative purposes only and may not depict the people, service or location featured in this article.

More than 200 NHS employees have been sacked for inappropriately accessing confidential patient records over the past five years, as an investigation raises concerns that many more cases could be going undetected.

Around 2,000 other members of staff have faced sanctions after accessing records without a legitimate reason, according to an investigation by the Health Service Journal and Sky News involving data from 140 NHS trusts.

The findings provide one of the clearest pictures yet of inappropriate access to patient information across the health service and come just two months after NHS England launched a national crackdown warning employees not to allow curiosity to end their careers.

Cases uncovered by the investigation include an employee who was dismissed after accessing as many as 179 patient records without a legitimate reason. Another involved somebody accessing the records of their spouse in what was described as a potential domestic violence situation.

There were also examples of patient information being shared through WhatsApp group chats.

The findings are particularly concerning because they may represent only a proportion of the inappropriate access taking place.

At least a quarter of the trusts included in the investigation had not carried out recent or proactive audits specifically designed to identify staff accessing records without a legitimate reason.

That raises an important question about how effectively inappropriate access can be detected when nobody has complained and the employee involved has not otherwise drawn attention to their actions.

Digital patient records can create an audit trail showing who has accessed information and when. NHS trusts are required to maintain logs of access to patient information and have controls intended to prevent and identify unauthorised activity.

However, NHS England acknowledged earlier this year that organisations needed to strengthen the way inappropriate access was prevented and monitored.

In July, it issued new guidance to NHS organisations alongside a national staff campaign carrying the message: “Don’t let curiosity kill your career.”

NHS England chief executive Sir Jim Mackey warned that looking at medical records for personal reasons or simply out of curiosity was unacceptable, breached patients’ trust and could be unlawful.

Staff found to have accessed information without a legitimate reason can face disciplinary action or dismissal. Cases can also be referred to professional regulators, the Information Commissioner’s Office or the police, with criminal prosecution possible in some circumstances.

The rules do not prevent NHS employees from accessing records when there is a legitimate work-related reason for doing so.

Patient information may lawfully need to be accessed for purposes extending beyond direct treatment, including clinical audits, quality improvement, investigations, complaints, education and training, mortality reviews and other legitimate operational activities.

The crucial distinction is whether an employee has a genuine reason connected with their work to view the information.

Having technical access to a patient’s record does not automatically give somebody permission to look at it.

That distinction becomes particularly important within the NHS because medical records can contain some of the most private information a person will ever disclose, including diagnoses, treatments and other details about their health and personal circumstances.

Patients have little practical choice but to entrust that information to healthcare services when they seek treatment.

The Information Commissioner’s Office has previously warned that unauthorised access is therefore more than a technical breach of data protection rules because of the potential consequences for patients and their families.

Concerns surrounding inappropriate access have intensified following several high-profile incidents.

NHS England’s crackdown was launched after cases in which staff were dismissed for accessing the medical records of victims of high-profile crimes despite having no legitimate reason to view them.

Other recent cases have demonstrated how information can move beyond NHS systems once it has been accessed.

At Somerset NHS Foundation Trust, for example, an employee was found to have accessed up to 200 patient records without permission over several years. Documents subsequently revealed that a screenshot of a patient’s medical record had been shared with the employee’s partner.

The latest investigation suggests the issue extends considerably beyond a small number of highly publicised incidents.

Layla Moran, chair of the House of Commons Health and Social Care Committee, described the findings as a stark picture and stressed the importance of protecting the security of personal and medical information.

NHS England’s new guidance asks organisations to consider stronger technical controls alongside staff education and auditing.

These can include restricting access according to an employee’s role, limiting particularly sensitive information to people who genuinely require it and using multi-factor authentication.

Some newer electronic patient record systems can also potentially identify suspicious activity in real time, allowing unusual patterns of access to be flagged for investigation.

Technology, however, is only one part of protecting patient confidentiality.

The latest figures show that hundreds of employees have already faced serious consequences after crossing the boundary between having the ability to view a record and having a legitimate reason to do so.

The bigger concern raised by the investigation is what happens when that boundary is crossed but nobody is actively looking for it.

More than 200 dismissals demonstrate that NHS organisations are taking action when inappropriate access is identified. But with at least a quarter of trusts reportedly lacking recent or proactive audits for such breaches, the true scale of patient record snooping remains difficult to establish.

For patients, confidentiality is one of the foundations on which healthcare depends. People need to be able to tell doctors, nurses and other professionals deeply personal information without wondering who else within a large healthcare organisation might decide to look.

The NHS message to its workforce is now unequivocal: access to a patient’s record must be based on need, not curiosity.

Stay informed with the stories shaping health and social care.

Register with The Daily Round for the latest sector news, inspections & reports, wellbeing content, workforce insights, expert features and practical updates—delivered free to your inbox.

Posted by:
M Ramalani
Editorial Assistant – The Daily Round

Everything You Need. In Bite-Sized Updates

Busy day? We’ve got you covered. Get FREE daily news, practical insights, opportunities and wellbeing content, carefully curated for busy health and social care professionals. Just enter your details below to get The Daily Briefing delivered straight to your inbox.

Your Information
Your Interests
By subscribing, you agree to receive emails from The Daily Round, including news, updates and other relevant communications. Your information will be processed in accordance with our Privacy Policy and Terms of Use. You can unsubscribe at any time.

Sign up to our daily briefing

You can unsubscribe at any time. Please refer to our Policies for more information.

Everything You Need. In Bite-Sized Updates

Busy day? We’ve got you covered. Get FREE daily news, practical insights, opportunities and wellbeing content, carefully curated for busy health and social care professionals. Just enter your details below to get The Daily Briefing delivered straight to your inbox.

Your Information
Your Interests
By subscribing, you agree to receive emails from The Daily Round, including news, updates and other relevant communications. Your information will be processed in accordance with our Privacy Policy and Terms of Use. You can unsubscribe at any time.