NHS boss says staff suspected of snooping on patients’ records should be suspended immediately

NHS staff suspected of snooping on patients’ medical records should be suspended immediately and barred from using health service computers, the head of NHS England has said.
Jim Mackey urged NHS England’s 205 health trusts to pursue a “zero tolerance” approach to staff who are suspected of inappropriately accessing records.
He called for a “hardline” stance towards anyone found to have accessed patients’ notes or medical histories without a clinical justification.
His intervention comes amid growing concern that staff sometimes use their position to view medical records but rarely face any meaningful penalty for doing so.
Mackey said on Friday: “Patient records contain some of the most private information people will ever share.We have seen too many cases of people abusing that trust and enough is enough.”
He wrote to all trusts demanding that they routinely implement what NHS England called a “crackdown” on breaching patients’ confidential data.
The problem has gained attention after reports that NHS staff illicitly accessed medical records of victims of the attacks by Valdo Calocane in Nottingham in 2023 and stabbings by Axel Rudakubana in Southport in 2024, among other high-profile incidents.
Mackey said: “If someone is suspected of snooping we cannot leave them in post with access to patients’ records while an investigation takes days or weeks. From now on we will expect them to be suspended and have their access to NHS systems cut off immediately, while the facts are established.”
That should happen already, but rarely does so in practice.
He added: “Anyone who thinks they can satisfy their curiosity by looking at a patient’s record should know this: they will be found out, they may lose their career and could end up with a criminal record.”
Since 2020, more than 200 NHS staff in England have been dismissed and 2,000 others sanctioned for snooping on patients’ records, an investigation by Sky News and the Health Service Journal found this month.
One employee was sacked after viewing up to 179 people’s records, another had accessed their spouse’s details in a “potential domestic violence situation”, and others had shared information they had gathered in WhatsApp groups.
Responses by 140 trusts to freedom of information requests by the media outlets showed that 214 staff were dismissed, three suspended and 540 given a final written warning over the last five years.
The Liberal Democrat MP Layla Moran, who chairs the health and social care select committee, has warned that official numbers for staff accessing patients’ records illegally under the Data Protection Act were likely to be “canaries in the coal mine”.
However, Paul Arnold, the chief executive of the Information Commissioner’s Office (ICO), the data watchdog, said in June that “inappropriate access is rare and does not represent the behaviour of the vast majority of healthcare staff who take their duty of confidentiality extremely seriously”.
Bristol NHS foundation trust has apologised to Paula and Tom McGowan for staff snooping on the medical records of their son Oliver, who died in 2016 aged 18. At least five members of staff, including three nurses and a doctor, accessed his records without permission.
Gillian Merron, a health minister, disclosed in July that health service bodies reported 1,445 cases of inappropriate access to the ICO between 2019 and 2025.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.