Wealth Hacks & Passive Income · Tyler Moss · 25 September 2026

NHS to immediately suspend staff over medical record snooping

NHS to immediately suspend staff over medical record snooping

NHS staff in England who are suspected of snooping on a patient medical record without a valid reason will be immediately suspended and locked out of NHS computer systems under a new zero-tolerance crackdown ordered by NHS England to protect patient privacy. Chief executive Sir Jim Mackey has told every trust to introduce the measures at once after high-profile breaches involving attack victims and other patients.

Key Takeaways

Why is the NHS cracking down on medical record access now?

The policy follows a series of high-profile incidents. Those include cases involving the records of victims of the Nottingham and Southport attacks, and a child injured in a crocodile enclosure in Cambridgeshire.

This week, Bristol NHS Foundation Trust said it had launched an internal investigation after it emerged that the medical records of an 18-year-old had been accessed years after his death. That teenager was Oliver McGowan, who was autistic and had epilepsy and died in 2016 after being prescribed anti-psychotic medication at Southmead Hospital in Bristol.

His mother, Paula McGowan, told the BBC she was "deeply concerned and hurt" and called for the NHS to do more. Channel 4 News reported that after she requested information about his records, she was told dozens of people had accessed his data since he died. She was separately told that at least five Southmead staff may have accessed his records without permission as recently as this year.

Sir Jim Mackey said patient records hold some of the most private information people will ever share. "We have seen too many cases of people abusing that trust, and enough is enough," he said, warning that those who look out of curiosity "will be found out, they may lose their career and could end up with a criminal record."

What happens to staff suspected of snooping?

Under the new rules, staff under suspicion face immediate suspension. They are also locked out of NHS computer systems so they cannot keep viewing confidential records, including from home.

NHS England describes the stance as a "hardline" part of a wider crackdown. That includes a national campaign to remind staff of their responsibilities and the serious consequences of unlawful access.

An investigation for the Health Services Journal this month found that at least 214 NHS staff have lost their jobs, and around 2,000 have been sanctioned, for snooping on sensitive patient data over the past five years. In some cases, staff were curious about a high-profile patient and wanted to know more about their condition or care.

Other staff have been struck off after looking up the records of relations, acquaintances and ex-partners without authorisation. In 2023, an NHS consultant in Cambridgeshire was investigated by the General Medical Council after accessing the health history of a woman who had started dating the doctor's ex-boyfriend.

Bristol NHS Foundation Trust said it was undertaking a "thorough investigation" into the McGowan case and that it would be "inappropriate to reach conclusions before those enquiries are complete." Paula McGowan welcomed the national commitment but said it must be followed by "meaningful action," arguing that accessing records without a legitimate clinical or professional reason is a serious breach of trust.

How do NHS systems track who viewed a medical record?

There is no single NHS-wide electronic record system that every member of staff can access. Instead, GP practices, hospitals and specialist clinics maintain their own records and decide who can view particular information.

IT systems keep an audit trail that should show exactly who accessed a patient's records and when. That logging underpins investigations when a medical record appears to have been opened without a clinical need.

According to BBC News reporting, the suspension-and-lockout order has gone to every trust in England so protections against data breaches can be strengthened immediately. For more BlasterPost coverage in this section, browse our Wealth Hacks & Passive Income category hub.

McGowan said medical records contain deeply personal information about people and their families. Accessing them without a legitimate reason, she argued, must have consequences. NHS leaders say the same: curiosity is not a defence, and unlawful viewing of a medical record can end a career and lead to criminal sanctions.

Patients and families watching the Bristol investigation—and the wider England-wide crackdown—will be looking for proof that audit logs, suspensions and professional regulators work together in practice, not only in policy statements. The test now is whether trusts act at once when suspicion arises, and whether unlawful access of any medical record is treated as the serious breach NHS England says it is.

What did the Oliver McGowan medical record case show?

Oliver McGowan died a decade ago, yet questions about who later opened his file have become a flashpoint for the wider debate. Paula McGowan said she was deeply concerned and hurt when she learned of the access pattern, and she urged meaningful action rather than statements alone.

Channel 4 News said she was told dozens of people had accessed his data since he died. The BBC separately reported that at least five members of staff at Southmead Hospital may have accessed his records without permission as recently as this year. Bristol NHS Foundation Trust has stressed that its enquiries are ongoing and that conclusions should wait until they finish.

The national order from Sir Jim Mackey is designed to stop further viewing the moment suspicion arises. Immediate suspension plus a computer lockout is meant to protect every medical record still held on trust systems, not only celebrity or news-related cases.

For patients, the practical message is that curiosity-driven access is now framed as career-ending behaviour. For trusts, the instruction is clear: do not wait for a full investigation to finish before removing system access when snooping is suspected.

← Open in blast feed