NHS Staff Face Immediate Suspension for Patient Record Snooping
New 'zero-tolerance' policy targets unauthorized access to sensitive data following multiple breaches.
The National Health Service (NHS) in the UK has implemented a stringent new policy mandating the immediate suspension of staff suspected of snooping on patient records. This crackdown, aimed at curbing privacy breaches, also includes the swift revocation of computer access for those under investigation.
The move follows a series of high-profile incidents, including over 50 staff members being sanctioned for accessing records related to victims of the Southport and Nottingham attacks last year. Sir Jim Mackey, NHS England's chief executive, is directing trusts to suspend employees promptly rather than waiting for the conclusion of investigations.
Suspicious activity will be identified through routine monitoring and audits of NHS systems, which track who accesses patient information and when. The new directive emphasizes that anyone found to be accessing records out of curiosity, without a legitimate medical reason, will face serious consequences. These can include loss of their professional license, regulatory action that could prevent future practice, and potentially criminal charges.
"Patient records contain some of the most private information people will ever share," Sir Jim Mackey stated. "We have seen too many cases of people abusing that trust, and enough is enough. If someone is suspected of snooping, we cannot leave them in post with access to patients’ records while an investigation takes days or weeks. From now on, we will expect them to be suspended and have their access to NHS systems cut off immediately, while the facts are established."
Over the past five years, approximately 214 NHS staff have been dismissed, and around 2,000 have faced sanctions for unauthorized access to sensitive patient data. Among those disciplined were eleven staff members at Nottingham University Hospitals NHS Trust, including doctors, who were fired for unlawfully accessing the medical records of victims from the Nottingham attack in June 2023. An additional 12 received final written warnings, and two were given first written warnings.
At the University Hospitals of more than 48 members of staff faced action for similar breaches related to the Southport attack victims' medical records. The former member of staff at the London Clinic who attempted to sell sensitive information about the Princess of Wales also highlighted the ongoing concerns regarding patient confidentiality.