Back to Blog

200 NHS Staff Sacked for Snooping on Patient Records

Sep 09, 2026
200 NHS Staff Sacked for Snooping on Patient Records

The NHS Confederation's findings, published September 8, landed without much fanfare, but the number is worth sitting with: over 200 NHS staff sacked, and more than 2,000 sanctioned, for viewing patient records they had no business looking at.

That's not a rogue-employee story. That's a systemic access control problem, and it's exactly the kind of problem that exists quietly in private clinics too.

The difference is that NHS trusts, under sustained regulatory pressure, now audit this stuff. Many private clinics don't.

Why private clinics should read NHS data breach news

The temptation is to treat NHS data scandals as NHS problems. Different org, different scale, different rules. But UK GDPR applies to every data controller processing personal health data, and private clinics are data controllers. Article 5(1)(f) of UK GDPR requires that personal data is "processed in a manner that ensures appropriate security... including protection against unauthorised or unlawful processing". That's not aspirational language. The Information Commissioner's Office treats it as a minimum standard.

The ICO's enforcement record bears this out. In 2024, the ICO fined a private psychological therapy service, Opus 2 International, for failing to protect patient data after a ransomware attack. The fine was £80,000, which for a mid-sized clinic would be genuinely damaging. The ICO's published criteria for determining fines include whether the controller had "appropriate technical measures" in place. Audit logs are a technical measure. Role-based access is a technical measure. If you can't demonstrate either, you're exposed.

The specific risk: who can see what in your practice management system

The NHS snooping cases mostly involve staff accessing records of celebrities, neighbours, relatives, or colleagues out of curiosity. Private clinics face the same risk. A receptionist who used to know a patient personally. A practitioner who's curious about a colleague's treatment history. A junior member of staff with admin rights they were given during a busy onboarding week and never had reviewed.

Most clinic software gives administrators sweeping access by default. That's practical at setup, and completely wrong six months later when you have a team of eight.

Ask yourself three questions:

  • Can you pull a report right now showing which staff members accessed which patient records in the last 30 days?
  • Do your reception staff have read access to clinical notes, or only to booking and payment data?
  • When did you last review who has admin-level rights in your practice management system?

If any of those questions made you pause, you have a gap. Not a catastrophic one, but a real one.

What "appropriate access controls" actually means in practice

Role-based access control (RBAC) is the standard approach. The idea is simple: staff only see the data their role requires. A receptionist needs appointment history and contact details. A practitioner needs clinical notes for their own patients. A practice manager might need financial summaries without needing full clinical record access. An external accountant needs nothing except what you explicitly export for them.

This sounds like an IT project. It's mostly a 90-minute admin job if your software supports it.

HealSuite's permissions system lets you set access by role, so you can stop receptionists seeing clinical notes and stop practitioners seeing records for patients they're not treating. Worth turning on if you haven't. But whatever platform you're using, check whether it has audit logging, meaning timestamped records of who accessed which patient file and when. That log is what you'd produce if the ICO came knocking.

If your current software has no audit log, that is genuinely a problem worth escalating to your software provider or flagging as a migration reason.

The staff angle: this isn't just a technical fix

Access controls are one layer. Staff behaviour is another. The NHS cases show that even in organisations with explicit data policies and mandatory training, people still access records out of curiosity. Private clinics often have weaker policies and less formal training, which makes the risk higher, not lower.

Your staff privacy policy needs to spell out that accessing patient records without a clinical or administrative reason is a disciplinary matter. Not "may be a disciplinary matter". Is. The policy should be signed at onboarding, reviewed annually, and referenced in your employment contracts.

This matters legally because under UK GDPR, if a staff member causes a breach through deliberate misuse, your liability depends partly on whether you took reasonable steps to prevent it. A signed policy and documented training helps demonstrate that you did.

Practical steps for this week

You don't need a consultant or a six-month project. Here's what you can do before Friday:

First, log into your practice management system and check what roles exist and which staff members are in each role. Look specifically for anyone with admin rights who doesn't need them.

Second, check whether your system has an audit log and, if so, whether it's turned on and how far back it goes. If it's off or unavailable, contact your provider today.

Third, pull your current staff list and compare it against active user accounts in your system. Leavers often retain access for weeks after they've left. This is one of the most common GDPR gaps and one of the most easily closed.

Fourth, add a standing item to your next team meeting: "who has access to patient data, and do they need it?" Fifteen minutes, once a year, is enough to catch most drift.

The record-keeping obligation

One more thing, and it's often missed. UK GDPR requires data controllers to maintain a Record of Processing Activities (ROPA). If you're processing sensitive health data, and you are, yours needs to cover what data you hold, where it's stored, who has access, how long you keep it, and what legal basis you rely on.

The ICO has a template on their website. It's not complicated. Most clinics either don't have one or have one that's three years out of date. An outdated ROPA doesn't automatically mean a fine, but it makes everything harder if a complaint is made against you, because it signals to investigators that data governance isn't something you actively manage.

The NHS Confederation findings are a reminder that data snooping happens in organisations with dedicated compliance teams and mandatory annual training. Private clinics don't have that infrastructure. The response to that gap isn't panic. It's spending a few hours this week making sure your access controls are set correctly and your documentation is current. Most of the risk here is preventable, and the preventable part doesn't require a big budget.

Ready to modernise your practice?

Join thousands of UK healthcare professionals using HealSuite to manage their clinics.

Enquire now