NHS warns ‘snooping’ staff face sack or prison for inappropriate access of patient data

By Published On: July 13, 2026Last Updated: August 26, 2026
NHS warns ‘snooping’ staff face sack or prison for inappropriate access of patient data

NHS staff who access patient records without a legitimate reason face dismissal or prison under a new crackdown on unlawful access.

NHS chief executive Sir Jim Mackey issued the warning as NHS England launched a campaign setting out the consequences of viewing medical records for personal reasons or out of curiosity.

It follows several incidents in which staff were dismissed for accessing the records of victims of high-profile crimes, including the Nottingham attacks.

 

Sir Jim said: “Anyone considering accessing records for personal reasons or out of curiosity should be in no doubt they could be putting their career at risk, and may face disciplinary action, dismissal, referral to the regulator or even time in prison.”

He said most NHS staff handled information responsibly, but inappropriate access by a small number of employees had undermined patient trust and caused additional distress to families.

NHS England has also issued guidance to NHS organisations on preventing and monitoring unauthorised access, as well as investigating and reporting incidents.

The guidance describes the different forms unlawful access can take and makes clear that employers may report incidents to the Information Commissioner’s Office (ICO), police and professional regulators.

The ICO and police can pursue criminal prosecutions, while professional regulators can remove someone’s accreditation and prevent them from continuing to work in their profession.

Organisations are also advised on how to use monitoring systems and regular audits, depending on the IT systems they have in place.

Some newer electronic patient record systems may be able to identify possible unlawful activity in real time and create alerts when suspicious access patterns are detected.

Employers are being asked to put suitable technical safeguards in place without preventing staff from carrying out their duties.

These measures include role-based controls, which restrict the information staff can view according to their job, and multi-factor authentication, which requires more than one form of identity verification.

The guidance says access to particularly sensitive information should also be limited to staff who need it to carry out their role.

The campaign launched with screensavers on staff computers and posters across NHS organisations urging employees to protect patient privacy, respect confidentiality and not to “let curiosity kill your career”.

Paul Arnold, ICO chief executive officer, said: “Having the ability to view a record is not the same as having a legitimate need to do so.

“Every member of staff has a personal responsibility to respect that boundary, and every patient has a right to expect that they will.

“Staff who breach that trust face serious consequences: loss of employment, removal of professional accreditation and criminal prosecution.”

Smartphone on a desk displaying a doctor with a stethoscope for telemedicine.UK health startup selected for San Francisco accelerator
Lab technician in teal gloves draws liquid into a syringe over a rack of test tubes.Ebola vaccine developed in eight weeks set for UK trials