NHS Snooping Crackdown: Suspension Is the Easy Part

Back in June I wrote about three hospital trusts where dozens of staff had looked at the records of patients who happened to be in the news: the Southport victims treated at Aintree, the Nottingham stabbing victims, and the three-year-old injured at a zoo near Huntingdon who was taken to Addenbrooke’s. What struck me most at the time was how differently each trust dealt with its own staff. Nottingham dismissed eleven people. Aintree dismissed nobody, with outcomes ranging from informal counselling to final written warnings. I called it a lottery, and argued that the NHS had a culture problem rather than a training gap.

This morning NHS England announced what it is calling a zero-tolerance approach. Staff suspected of looking at patient records without a legitimate reason will now be suspended immediately, their system access will be removed while the matter is investigated, and registered professionals will be referred to their regulator. Sir Jim Mackey, the NHS chief executive, put it plainly: “Patient records contain some of the most private information people will ever share. We have seen too many cases of people abusing that trust, and enough is enough.”

I welcome it. A single national starting point goes some way towards fixing the inconsistency I complained about in June. But having spent a fair amount of time reading access audit reports in my DPO role, I think the announcement leaves some of the harder questions unanswered.

This has been building since the summer

Today’s news didn’t come out of nowhere. In July NHS England warned that “snooping” staff could face the sack or prison, and launched a campaign of posters and screensavers telling people to “let curiosity kill your career”. It also issued guidance to trusts on preventing and monitoring unauthorised access. What has changed is that the warning now comes with a defined first step, and the list of cases behind it has grown to include Oliver McGowan and the Princess of Wales alongside the victims I wrote about in June.

You have to catch people first

Immediate suspension is only a deterrent if staff believe they will be caught. A lot of snooping comes to light in fairly haphazard ways: a patient or family asking who has looked at their record, a colleague mentioning something they had no business knowing, or a journalist making enquiries. In the high-profile cases trusts tend to go looking, because they know those records will attract attention. For the ordinary patient whose ex-partner works at the hospital, or whose neighbour is on the admin team, there may be nobody looking at all.

The July guidance recommends proactive monitoring, and many of the newer electronic patient record systems can flag unusual access as it happens. Recommending it is a long way from every trust having it switched on, properly tuned, and someone actually working through the alerts on a Monday morning. If I sat on a trust board and read today’s news, my first question wouldn’t be about our suspension policy. It would be how we would actually know.

Suspicion needs a quick, fair triage

The word in today’s announcement that makes me slightly uneasy is “suspected”. Access monitoring throws up a lot of noise. A nurse covering another ward, a medical secretary catching up on letters, a clinical coder working through a backlog, a pharmacist checking a prescription. Any of these can look odd in an audit log and turn out to be entirely legitimate once someone asks a couple of sensible questions.

If an alert on its own becomes grounds for suspension, two things will follow. Innocent staff will be sent home, which is distressing for them and costly for wards that are already stretched. And the monitoring will lose credibility with the workforce, who will come to see it as something to fear rather than something that protects patients. What’s needed is a fast, consistent check between the alert and the suspension, carried out by someone who understands how clinical and admin staff really use the system. Suspension is meant to be a neutral act, but few people on the receiving end experience it that way, and the NHS needs its staff to trust the process if it wants this to work.

Consistency at the start, lottery at the finish?

My complaint in June was mainly about outcomes. Suspending everyone at the outset is consistent, and that is a good thing. But whether a healthcare assistant at one trust is dismissed while someone at another trust gets a final written warning for much the same behaviour is decided at the end of the process, by local disciplinary panels working to local policies. Nothing I have seen today explains how that part will be made fairer. Without it, we could end up with a uniformly tough first step and the same lottery at the finish.

This isn’t just an NHS issue

Curiosity doesn’t stop at the hospital door. Councils hold social care files, housing records and information about vulnerable adults. Police forces, schools, HR departments and insurers all hold records that people would be mortified to see passed around. In my experience the NHS is further ahead than many of these organisations simply by having usable audit trails. Plenty of case management and HR systems log access poorly, or log it and nobody ever looks.

So if you are responsible for sensitive records in any sector, today’s announcement is a useful prompt. Could you tell me who has looked at a particular record in the last six months? Does anyone review access routinely, or only when there has been a complaint? And if you found something tomorrow, do you know what you would do, and would you do the same thing the next time it happened?

Where culture comes back in

I still think the lasting fix is cultural, and I won’t repeat the argument I made in June. Tougher sanctions help set the tone, but they work best in teams where managers talk openly about confidentiality and staff understand why it matters, not just that there is a rule. Immediate suspension sends a strong message. Whether it changes behaviour will depend on two things: staff believing they will be caught, and staff believing they will be treated fairly and consistently when they are.

Share the Post:
Helen Molyneux, founder of Cambridge Risk Solutions, ISO 22301 and ISO 27001 Lead Auditor

Helen Molyneux is the founder and director of Cambridge Risk Solutions. A certified Lead Auditor for ISO 22301 and ISO 27001, she has spent nearly two decades helping organisations across the public and private sectors build genuine resilience — not just documented compliance. She writes from practice, not theory.

Work with us →