NHS suspends staff over suspected patient data snooping
There have been too many cases of staff abusing patient trust, and enough is enough, the head of the NHS in England says.
Source: BBC Health · September 26, 2026 at 7:32 AM · AI-assisted report
Single-source
KUALA LUMPUR, 26 SEPTEMBER 2026 —
NHS England Imposes Zero-Tolerance Policy on Staff Snooping, Suspending Suspects and Locking Them Out of Systems
Market Impact
NHS England will immediately suspend any staff member suspected of unlawfully accessing patient records and lock them out of all NHS computer systems, including remote access, as part of a sweeping "zero-tolerance" crackdown announced by Chief Executive Sir Jim Mackey. The policy, ordered in a letter to every NHS trust, follows a surge in high-profile cases of unauthorized record viewing, including those involving victims of violent attacks and a child injured in a zoo incident.
The move shows growing public outrage over repeated breaches of patient confidentiality, with at least 214 NHS staff dismissed and 2,000 sanctioned over the past five years for snooping on sensitive medical data. Mackey’s directive—described as "hardline"—comes amid mounting pressure after investigations revealed staff accessing records out of personal curiosity, including those of high-profile patients, relatives, ex-partners, and even deceased individuals.
The NHS will also launch a national campaign to reinforce staff responsibilities and the severe consequences of unlawful access, which can lead to criminal charges and career-ending penalties.
The policy shift follows a series of scandals, including the unauthorized access to records of Nottingham and Southport attack victims, a child injured in a crocodile enclosure at a Cambridgeshire zoo, and most recently, the medical files of an 18-year-old who died in 2016.
Bristol Foundation NHS Trust confirmed it is investigating whether five staff members at Southmead Hospital accessed the records of Oliver McGowan, an autistic teenager whose death in 2016 was ruled a tragedy. His mother, Paula McGowan, told the BBC she was "deeply concerned and hurt" by the breach and demanded stronger enforcement.
Mackey’s letter, obtained by the BBC, states that patient records contain "some of the most private information people will ever share" and warns that unauthorized access will no longer be tolerated. "Anyone who thinks they can satisfy their curiosity by looking at a patient’s record should know this: they will be found out, they may lose their career, and could end up with a criminal record," he said.
The NHS acknowledged that its fragmented IT systems—with GP practices, hospitals, and clinics maintaining separate records—complicate oversight, though audit trails should theoretically track unauthorized access.
The crackdown follows a 2023 Health Services Journal investigation revealing that curiosity-driven snooping was a recurring issue, with staff accessing records of acquaintances, ex-partners, and even strangers. In 2023, a Cambridgeshire NHS consultant faced disciplinary action after viewing the medical history of a woman linked to his ex-boyfriend. Bristol NHS Foundation Trust, while declining to comment further until its investigation concludes, emphasized that unauthorized access is a "serious breach of trust."
McGowan welcomed the NHS’s commitment but stressed the need for "meaningful action." "Medical records contain deeply personal information about people and their families," she said. "Accessing them without a legitimate clinical or professional reason is a serious breach of trust and must have consequences." The policy takes effect immediately, with trusts required to enforce suspensions and system locks without delay.
The NHS has not specified how it will verify unauthorized access claims, though internal audits and whistleblower reports have previously exposed systemic weaknesses. With public trust in healthcare data protection at an all-time low, the zero-tolerance approach marks a rare instance of direct accountability—though critics argue deeper reforms to IT governance and staff training are still needed to prevent future breaches.