Over 200 NHS staff have been sacked and around 2,000 others sanctioned for inappropriately accessing patient records in the past five years. NHS England is launching a campaign to warn staff about the consequences of unauthorized access.

Patient data privacy is a critical concern, and breaches by healthcare staff erode public trust and can lead to significant legal and regulatory repercussions for healthcare providers.
Hundreds of NHS staff have been sacked and around 2,000 others sanctioned for inappropriately viewing patient records over the past five years, according to a report by HSJ. NHS England has launched a campaign to remind staff that accessing patient records without a legitimate reason can lead to serious professional consequences, including disciplinary action, dismissal, referral to a professional regulator, or even criminal prosecution in the most severe cases.
Sir Jim Mackey, NHS England Chief Executive, described unauthorized access to records as a "disgraceful breach of patients' trust" and stated that there is "no place in the NHS" for staff who misuse patient information. Access to records should typically be linked to a legitimate work purpose, such as providing direct care or supporting a clinical service, and must comply with UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018. The Royal College of Nursing (RCN) also highlighted that while curiosity or concern for a patient's well-being might be understandable, these do not provide a legitimate reason to access confidential records. Breaches can lead to disciplinary action regardless of professional registration, as NHS employers across the UK have policies governing record access.
Pick the topics you care about. Get only what matters, on your cadence.