NHS England has announced a new crackdown on staff who access patient medical records without proper authorization, introducing immediate suspension and temporary removal of system access for those suspected of “snooping.” The directive, issued by NHS chief executive Sir Jim Mackey, comes amid increasing concern over breaches of patient confidentiality in several high-profile cases.

Sir Jim emphasized that patient records contain some of the most sensitive personal information and warned that inappropriate access would no longer be tolerated. “Enough is enough,” he said, urging NHS trusts to adopt a zero-tolerance approach and promptly suspend any employees suspected of unauthorized record viewing while investigations are carried out. Suspended staff will also have their access to NHS systems revoked immediately to prevent further breaches.

This crackdown follows a series of incidents where NHS workers viewed medical records without clinical justification. Among these were cases involving the 2023 Nottingham stabbings, where 98 staff accessed the victims’ records but only 42 had legitimate reasons. Eleven staff were subsequently dismissed for inappropriate access. Similar breaches occurred during the 2024 Southport stabbing attacks and involved victims’ families who have described the violations as a gross invasion of privacy.

Other notable privacy breaches include the improper access of a three-year-old boy’s medical records after he was pushed into a crocodile enclosure at a Cambridgeshire zoo and inquiries into staff accessing the records of the Princess of Wales during her private hospital treatment in 2024. In the latter case, three employees at the London Clinic faced investigation for unauthorized access.

Since 2020, more than 200 NHS employees have been dismissed and around 2,000 sanctioned for snooping, with a range of penalties including suspension and final written warnings. The Health Service Journal and media freedom of information requests show that some individuals viewed dozens or even hundreds of patient records, sometimes using information in inappropriate ways such as sharing details on social media platforms.

In response to these concerns, NHS trusts will increase system monitoring and auditing to detect suspicious access patterns. The move aims to improve accountability and allow for swift action when breaches occur. Offending staff will also be reported to professional regulators, potentially barring them from future practice.

While the Information Commissioner’s Office acknowledges these incidents as serious, it maintains that such behavior is rare and does not reflect the conduct of the vast majority of healthcare professionals who respect patient confidentiality. MPs and health officials, however, suggest that existing figures may underrepresent the true scale of the problem.

Overall, the NHS leadership is working to restore patient trust by reinforcing the importance of data protection and imposing stricter penalties on staff who violate confidentiality protocols.