NHS Launches Crackdown on Staff Snooping on Patient Records
New policy mandates immediate suspension and access removal for staff suspected of unauthorized record access.
The National Health Service (NHS) has initiated a stringent 'zero-tolerance crackdown' targeting staff suspected of improperly accessing patient records, a response to a series of high-profile privacy breaches. Under the new policy, any NHS staff member found to be snooping on patient data will be immediately suspended, and their access to NHS computer systems will be revoked.
This directive comes after over 50 staff members faced repercussions for accessing the records of victims involved in the Southport and Nottingham attacks in the past year. NHS England's chief executive, Sir Jim Mackey, is urging trusts to promptly suspend individuals under suspicion while investigations are underway, rather than awaiting the investigation's conclusion.
Suspicious activity will be identified through routine monitoring and audits of NHS systems, which track who accesses patient information and when. The new measures could lead to doctors, nurses, and other healthcare professionals losing their licenses and facing regulatory actions that may permanently prevent them from practicing.
"Patient records contain some of the most private information people will ever share," Sir Jim Mackey stated. "We have seen too many cases of people abusing that trust, and enough is enough. If someone is suspected of snooping, we cannot leave them in post with access to patients’ records while an investigation takes days or weeks. From now on, we will expect them to be suspended and have their access to NHS systems cut off immediately, while the facts are established. Anyone who thinks they can satisfy their curiosity by looking at a patient’s record should know this: they will be found out, they may lose their career, and could end up with a criminal record."
Over the past five years, approximately 214 NHS staff have lost their jobs, and around 2,000 have been sanctioned for snooping on sensitive patient data. Among those disciplined were eleven members of staff, including doctors, at Nottingham University Hospitals NHS Trust, who were dismissed for unlawfully accessing the medical records of victims of the Nottingham attack. Twelve other staff members received final written warnings, and two received first written warnings.
Additionally, 48 staff members at University Hospitals faced action for accessing the medical records of victims of the Southport attack without proper authorization. This crackdown follows an incident in June where a former member of staff at the London Clinic was found to have attempted to sell sensitive information about the Princess of Wales, who was a patient there.
The NHS has previously implemented measures to combat unauthorized access, including a national campaign to remind staff of their responsibilities and the issuance of guidance to NHS organizations on preventing, monitoring, investigating, and reporting unlawful access.