Help protect children from gaming harms.

Take our survey

Please or to access all these features

AIBU?

Share your dilemmas and get honest opinions from other Mumsnetters.

Another Data breach by NHS staff!

47 replies

Netcurtainnelly · Yesterday 11:23

Another data breach by NHS staff😕

https://news.sky.com/story/investigation-into-claims-nhs-staff-accessed-medical-records-of-schoolgirl-who-died-on-camping-trip-13570614

Why dont people learn, and stop being so bloody nosy. They are risking their jobs . Why? 🤔

OP posts:
SerendipityJane · Yesterday 11:29

Netcurtainnelly · Yesterday 11:23

Another data breach by NHS staff😕

https://news.sky.com/story/investigation-into-claims-nhs-staff-accessed-medical-records-of-schoolgirl-who-died-on-camping-trip-13570614

Why dont people learn, and stop being so bloody nosy. They are risking their jobs . Why? 🤔

Well the average payout per breach is less than 1p per person per item.

If your data gets published or misused then the golden rule is to learn to whistle.

palepeony · Yesterday 11:31

Pure nosiness

Netcurtainnelly · Yesterday 11:54

Aren't they worried about losing their jobs.

OP posts:
MissMoneyFairy · Yesterday 11:58

Netcurtainnelly · Yesterday 11:54

Aren't they worried about losing their jobs.

Who cares if they do, they know the risk and consequences.

WineCharm · Yesterday 12:00

More worried about Palantir access which we can't opt out of, never consented to, and have no idea where this data is going and for what purpose. It seems the NHS can do as they like with our info with no recourse. I've opted out of the NHS.

Netcurtainnelly · Yesterday 12:03

MissMoneyFairy · Yesterday 11:58

Who cares if they do, they know the risk and consequences.

Agree, I'm just surprised they are prepared to risk their jobs over it? You needoneybto live.

OP posts:
Netcurtainnelly · Yesterday 12:04

Need money .

OP posts:
Persephonia1966 · Yesterday 12:04

MissMoneyFairy · Yesterday 11:58

Who cares if they do, they know the risk and consequences.

Well they presumably should care

Somersetbaker · Yesterday 12:05

Netcurtainnelly · Yesterday 12:04

Need money .

Which the gutter press provides, because the a large part of the public think they have a right to know all the details.

Paganpentacle · Yesterday 12:15

WineCharm · Yesterday 12:00

More worried about Palantir access which we can't opt out of, never consented to, and have no idea where this data is going and for what purpose. It seems the NHS can do as they like with our info with no recourse. I've opted out of the NHS.

It wasn't the NHS that decided to give all our data to Palantir though was it?

WineCharm · Yesterday 12:16

Paganpentacle · Yesterday 12:15

It wasn't the NHS that decided to give all our data to Palantir though was it?

https://www.reuters.com/world/uk/britains-nhs-grant-palantir-contractors-unlimited-access-patient-data-ft-reports-2026-05-11/

Paganpentacle · Yesterday 12:23

The Palantir contract was granted by the government.

WineCharm · Yesterday 12:26

Paganpentacle · Yesterday 12:23

The Palantir contract was granted by the government.

NHS is run and owned by the government. That is what 'state run' means.

So, if the NHS is beholden to the government, does it matter that it was one organisation over the other who allowed access?

The end result is still the same.

Weird argument to try to stand on but the information is there for you. Take it or leave it.

frazzled1 · Yesterday 12:26

https://justtreatment.org/gp-letter?fbclid=IwY2xjawTWEwRwZG9mAWV4dG4DYWVtAjEwAGJyaWQRMUxsODdzU0VxNWE5NDFJUTBzcnRjBmFwcF9pZBAyMjIwMzkxNzg4MjAwODkyAAEe0VV4SPiUu4JxaAnaXeJ21-Fq024bqcT0cUaegDCMJ0uxao9RbxT38CSArj4_aem_90CsL2Rq6Ii4cr0xHsMpNQ

Toolkit to write to your GP to object to them sharing your data with Palantir's Federated Data Platform (FDP). I'm giving it a go.

Why is my GP data relevant?
There is currently a lack of clarity regarding how GP practice and patient data is being used in Palantir's FDP. Initially, the government stated that GP data would not be included in the FDP. However, recent developments indicate that GP data is being transferred onto the FDP by Integrated Care Boards (ICBs).
What can writing to my GP achieve?
As it stands, GPs are official 'data controllers', meaning they can control how data flows into other parts of the health system, and can therefore prevent GP patient data from entering Palantir's FDP*.

GP Letter Toolkit — Just Treatment

https://justtreatment.org/gp-letter?fbclid=IwY2xjawTWEwRwZG9mAWV4dG4DYWVtAjEwAGJyaWQRMUxsODdzU0VxNWE5NDFJUTBzcnRjBmFwcF9pZBAyMjIwMzkxNzg4MjAwODkyAAEe0VV4SPiUu4JxaAnaXeJ21-Fq024bqcT0cUaegDCMJ0uxao9RbxT38CSArj4_aem_90CsL2Rq6Ii4cr0xHsMpNQ

Passaggressfedup · Yesterday 12:26

The NHS is the biggest employer in Europe. There's bound to be a few idiots who think it's permitted despite the training or think nobody will find out.

Catza · Yesterday 13:00

I don't understand this alleged data breach. Who accessed her records?
She was taken to a hospital where she was treated. Should they not have access to her records? Or was it the killer who accessed records? Zero clarity in the article as to who accessed what and where and how it contributed to her death.

Paganpentacle · Yesterday 13:03

WineCharm · Yesterday 12:26

NHS is run and owned by the government. That is what 'state run' means.

So, if the NHS is beholden to the government, does it matter that it was one organisation over the other who allowed access?

The end result is still the same.

Weird argument to try to stand on but the information is there for you. Take it or leave it.

Weird of you also but there you go.
Government grants contracts.
Not 'the nhs' or 'the army'.

WineCharm · Yesterday 13:05

Paganpentacle · Yesterday 13:03

Weird of you also but there you go.
Government grants contracts.
Not 'the nhs' or 'the army'.

Uh, are you feeling scrappy today? Might I suggest you go for a run to release some negativity? I have nothing further to comment to you regarding this so wishing you a long, healthy and happy life.

SuePer · Yesterday 13:08

I don't understand how anyone in the NHS can access private medical info. Surely it's not too hard to have records only accessible via certain passcodes or whatever.

That said obviously people should not snoop but fgs NHS tighten up your IT systems.

Paganpentacle · Yesterday 13:12

WineCharm · Yesterday 13:05

Uh, are you feeling scrappy today? Might I suggest you go for a run to release some negativity? I have nothing further to comment to you regarding this so wishing you a long, healthy and happy life.

No.
I didn't start scrapping?
I'm here at work.
NHS (not government - there's a difference)

Dancingsquirrels · Yesterday 13:16

Catza · Yesterday 13:00

I don't understand this alleged data breach. Who accessed her records?
She was taken to a hospital where she was treated. Should they not have access to her records? Or was it the killer who accessed records? Zero clarity in the article as to who accessed what and where and how it contributed to her death.

She was admitted to hospital, then died

I'd assume some people had legitimate reason to access the poor girl's records while they were trying to save her life. And then other nosy staff also looked at them, probably after she died. That's the data breach

No suggestion that the data breach contributed to her death. Think you've misunderstood that bit?

Agree with OP, I don't understand how this just keeps on happening. Perhaps there should be more naming and shaming of the guilty parties, in addition to losing their jobs?

randomchap · Yesterday 13:19

SuePer · Yesterday 13:08

I don't understand how anyone in the NHS can access private medical info. Surely it's not too hard to have records only accessible via certain passcodes or whatever.

That said obviously people should not snoop but fgs NHS tighten up your IT systems.

Every single NHS IT system I've worked with, and there's been loads, are auditable. They also all have specific permissions associated with job roles/positions, limiting what you can access to what you need to access.

The IT dept will be able to see what records you have accessed. If you don't have a reason for accessing a specific record, then you risk your job.

If I'm not involved in patient X's care, or admin, then I shouldn't access their record.

SuePer · Yesterday 13:22

'If I'm not involved in patient X's care, or admin, then I shouldn't access their record'

Yes obviously but surely that should read 'If I'm not involved in patient X's care, or admin, then I can't access their record'

Why are NHS IT systems so open to everyone in the organisation?!

Rinoachicken · Yesterday 13:23

Catza · Yesterday 13:00

I don't understand this alleged data breach. Who accessed her records?
She was taken to a hospital where she was treated. Should they not have access to her records? Or was it the killer who accessed records? Zero clarity in the article as to who accessed what and where and how it contributed to her death.

The only staff who should be accessing her medical records are staff who are directly providing care to her and where it is necessary for that care for them to do so.

Anytime someone accesses a patient record that is digitally recorded.

In this instance a member or members of staff who were not involved in her care accessed her records out of nosiness (to find out her cause of death, her injuries etc).

It is an immediate sackable offense which is drummed into you throughout your training and employment. There have been a few high profile cases of it recently and there has been a push (within my Trust anyway) on reminding staff of the seriousness and the consequences.

Theres no suggestion it contributed to her death.

Theres no excuse for it, ever, and you can’t turn around in a NHS building, as a member of staff, without seeing the warnings due to the recent spate high profile cases. So no member of staff can claim they didn’t know.

Another Data breach by NHS staff!
Another Data breach by NHS staff!
Another Data breach by NHS staff!
yetnothername · Yesterday 13:26

Rinoachicken · Yesterday 13:23

The only staff who should be accessing her medical records are staff who are directly providing care to her and where it is necessary for that care for them to do so.

Anytime someone accesses a patient record that is digitally recorded.

In this instance a member or members of staff who were not involved in her care accessed her records out of nosiness (to find out her cause of death, her injuries etc).

It is an immediate sackable offense which is drummed into you throughout your training and employment. There have been a few high profile cases of it recently and there has been a push (within my Trust anyway) on reminding staff of the seriousness and the consequences.

Theres no suggestion it contributed to her death.

Theres no excuse for it, ever, and you can’t turn around in a NHS building, as a member of staff, without seeing the warnings due to the recent spate high profile cases. So no member of staff can claim they didn’t know.

It's not strictly true that "The only staff who should be accessing her medical records are staff who are directly providing care to her and where it is necessary for that care for them to do so.".

Lots of admin staff need to access health records to complete their work without ever providing direct care.