Please or to access all these features

AIBU?

Share your dilemmas and get honest opinions from other Mumsnetters.

Another Data breach by NHS staff!

73 replies

Netcurtainnelly · 07/08/2026 11:23

Another data breach by NHS staff😕

https://news.sky.com/story/investigation-into-claims-nhs-staff-accessed-medical-records-of-schoolgirl-who-died-on-camping-trip-13570614

Why dont people learn, and stop being so bloody nosy. They are risking their jobs . Why? 🤔

OP posts:
Thread gallery
5
turniplegs · 27/09/2026 18:41

Do the NHS provide initial, explcit training to all new staff on this? In Education, for example, we get repeated training sessions on safeguarding, because it's so important, and have to carry out online assessments annually to prove we understand it. It's drummed in constantly. Is this the same in the NHS, with regards to patient privacy?

Netcurtainnelly · 27/09/2026 19:36

Rinoachicken · 27/09/2026 18:31

And so many - 10 members of staff! I was shocked at how many thought this was ok and that they would get away with it.

Me too.

OP posts:
Rinoachicken · 27/09/2026 21:11

turniplegs · 27/09/2026 18:41

Do the NHS provide initial, explcit training to all new staff on this? In Education, for example, we get repeated training sessions on safeguarding, because it's so important, and have to carry out online assessments annually to prove we understand it. It's drummed in constantly. Is this the same in the NHS, with regards to patient privacy?

Edited

Yep - and you have to redo it every couple of years - it’s mandatory training.

Gettingbysomehow · 28/09/2026 03:33

Why? Every single one of us knows we'll get sacked for it. Its in the yearly compulsory training.

IceCreamCone543 · 28/09/2026 03:46

It just makes me wonder how many other people are having their records viewed (when they shouldn't) without ever knowing... Nothing surprises me anymore but the individuals involved with this should all lose their jobs. I suspect they won't and the usual line/s will be used.

Lucyintheskywithnoidea · 28/09/2026 05:34

turniplegs · 27/09/2026 18:41

Do the NHS provide initial, explcit training to all new staff on this? In Education, for example, we get repeated training sessions on safeguarding, because it's so important, and have to carry out online assessments annually to prove we understand it. It's drummed in constantly. Is this the same in the NHS, with regards to patient privacy?

Edited

Absolutely, I don’t think anyone working in the nhs could claim that they didn’t know that accessing records for someone that they aren’t directly involved with is wrong. We are all well aware that it’s audited so the people doing it know that they will be caught which is baffling.

randomchap · 28/09/2026 05:37

IceCreamCone543 · 28/09/2026 03:46

It just makes me wonder how many other people are having their records viewed (when they shouldn't) without ever knowing... Nothing surprises me anymore but the individuals involved with this should all lose their jobs. I suspect they won't and the usual line/s will be used.

https://www.bbc.co.uk/news/articles/cjr4v9g14vygo

If you're caught then you'll be suspended immediately

Stock image of a nurse holding a tablet computer presumably containing medical records.

NHS staff suspected of snooping on patient data to face immediate suspension

There have been too many cases of staff abusing patient trust, and enough is enough, the head of the NHS in England says.

https://www.bbc.co.uk/news/articles/cjr4v9g14vygo

LindorDoubleChoc · 28/09/2026 06:10

Absolutely sickening! How stupid can a person be? To me it's akin to those hideous police who take pictures of dead bodies and share them in WhatsApp groups.

They should be sacked, named and shamed. Have their private information out in the world for everyone to see.

cossette · 28/09/2026 07:02

My then 16 year old daughter was being seen in the NHS service I worked for in an admin capacity. She had forgotten when her next appointment was. 3 mouse clicks and I could have found the information but I would have put my job at high risk. I phoned the team she was involved with and enquired like any other parent - I did not access her records. I can't understand how any member of NHS staff don't understand the rules around data access.

Rinoachicken · 28/09/2026 08:31

You’re not even allowed to access you’re OWN records - it’s impossible to not know that it’s not allowed and I seriously do not know WTF is wrong with these people and what is going on in their head.

They could be the most incredible surgeon in the land I don’t care - sack them.

weareallqueens · 28/09/2026 09:12

Rinoachicken · 27/09/2026 18:31

And so many - 10 members of staff! I was shocked at how many thought this was ok and that they would get away with it.

I think it’s pretty obvious why they thought it was ok - they’re done it before or been aware of others doing it before.

I worked for an energy supplier 25 years ago and even then it was made absolutely clear to us that you were not permitted to access someone’s electricity account unless you were directly dealing with it, with a clear digital footprint left by anyone who accessed it. Surely that should be the case in the NHS?

Lolarose20 · 28/09/2026 09:20

weareallqueens · 28/09/2026 09:12

I think it’s pretty obvious why they thought it was ok - they’re done it before or been aware of others doing it before.

I worked for an energy supplier 25 years ago and even then it was made absolutely clear to us that you were not permitted to access someone’s electricity account unless you were directly dealing with it, with a clear digital footprint left by anyone who accessed it. Surely that should be the case in the NHS?

It is the case

CossyBunt · 28/09/2026 09:21

WineCharm · 07/08/2026 12:00

More worried about Palantir access which we can't opt out of, never consented to, and have no idea where this data is going and for what purpose. It seems the NHS can do as they like with our info with no recourse. I've opted out of the NHS.

You’re missing the point, go and start a thread about Palantir if you want. This thread is about arseholes who work in the NHS who cannot control their voyeuristic impulses and violate people’s right to privacy.

You can bet the local union reps phone is red hot as we speak. No doubt they were snooping because their mental health was in a bad place, blah blah and THEY must have their names kept confidential and not revealed publicly due to impact on their mental wellbeing. Never mind the disrespect, harm and violation caused to the ACTUAL victims in all of this.

How could this happen in the ‘envy of the world’ service?

CossyBunt · 28/09/2026 09:23

Also clearly a lot of thickos working in the NHS. They must KNOW they cannot do this but cannot resist the urge to snoop.

SleeplessRoads · 28/09/2026 09:34

SuePer · 07/08/2026 13:22

'If I'm not involved in patient X's care, or admin, then I shouldn't access their record'

Yes obviously but surely that should read 'If I'm not involved in patient X's care, or admin, then I can't access their record'

Why are NHS IT systems so open to everyone in the organisation?!

How do you determine who needs to see my record.

If my next door neighbour is the receptionist at my local GP, I don’t want her digging through my records to see what’s going on with my fertility treatment, but equally acknowledge she might need to access them at some point so is able to access them.

When I am rushed to A&E in an ambulance, I want all relevant professionals to be able to see my medical history urgently and without seeking approval - so then every A&E professional needs access to everyone’s records as I could be taken to any hospital.

After my visit, someone needs to code the treatment I have, so I imagine everyone working in the coding team at that trust has access to every patients records who walk in the building. There’s so many more admin and back office people who also might have cause to access these records.

Now I have a huge pool of people who might have reason to access my records, but who don’t necessarily have a requirement to today. If I was in a national news story their nosiness might get the better of them and they would have a look despite access being limited to relevant people.

These people need to be made an example of and sacked, and that’s the only way to really control the issue. We should be able to trust our healthcare providers and so any breach of that trust should be stamped out hard.

Greenpeanutsnail · 28/09/2026 09:36

The morality of snooping aside, I’m amazed that people would want to risk their jobs, especially when there’s been a lot in the press about this and there are likely to be more checks made on the access to records of high profile patients.

I don’t work for the NHS, but I do have access to a very sensitive database. It has been drummed into us countless times that if we look up someone without legitimate reason, we will lose our jobs and face prosecution. There’s just no way I would risk losing my job and getting a criminal record to have a peek as to what Betsy down the road is up to. (Obviously I wouldn’t look anyway.)

InveterateWineDrinker · 28/09/2026 09:51

Sadly it doesn't surprise me one bit. I've worked in the NHS in commercial roles and I have been consistently amazed by the number of people there who genuinely believe that they are exempt from whichever law they find inconvenient simply because they work for the sacred NHS.

Lolarose20 · 28/09/2026 13:24

I would say in general its normally ignorance rather than selling it on

Theres a weigh up between locking information down, and having it viewable

Historically for example my mh trust, the mh trusts next door, the physical hospital, the GPs, the community teams are all on different systems. This is really frustrating if you are a patient because none of them "talk to each other" so some of the systems were merged.

Lolarose20 · 28/09/2026 13:36

I'd be a good example of who might need to access records.

I used to live on the border so while my gp and normal team was one trust, my nearest a+e worked for a completely different trust. Ive previously been in a situation where ive been in an ambulance begging them to take me to a further away hospital so they could see all my notes

Equally when I was hospital my notes would have been accessed by all sorts because I went in via a+e, went to several wards, got transferred hospital but also was seen by multiple teams in the hospital eg imaging, bloods, salt, physio etc

I have a role where I would have access to mental health notes to every single person in my county which is needed. When I need to access something the system is unsure of, it asks me why.

Every single click i make is recorded and can be used in investigations. While paper notes were open to less people, they had no audit trail.

While the system notices odd patterns, it cant automatically recognise whos your neighbour, cousin or high-school enemy. We have previously put flags on highprofile patients that question everyone accessing

Lolarose20 · 28/09/2026 13:39

If anyone is worried about a specific person accessing your notes, ask.

Ive frequently checked audit trails to make sure things are proper.

Sometimes it might be recorded that there is an access but it can be part of report running (if I run a report on how long wait times are for example or how many contacts a clinician has had then initially it would look like i have individually accessed each patient rather than used reporting software)

guinnessguzzler · 28/09/2026 13:43

I agree, OP, I find it genuinely astounding to the point if literally not being able to comprehend it. Like, no matter how much you want to know about whatever case, why is it worth it to risk everything you've worked for? In some of the higher profile cases I have wondered whether staff were being approached by journalists with offers of payment. That seems a bit far-fetched but I can't understand what goes through someone's mind when they do this. Even if you don't care about the morality, privacy, dignity etc, surely it's not worth the risk of losing your job. People really are strange.

LondonPapa · 28/09/2026 13:55

SerendipityJane · 07/08/2026 11:29

Well the average payout per breach is less than 1p per person per item.

If your data gets published or misused then the golden rule is to learn to whistle.

How odd. I was part of a data breach of employee details and due to the impact it had on my subsequent employment thanks to how identifiable it all was, I got a payout of significantly more than 1p. More towards the ££££ end rather than P end!

SerendipityJane · 28/09/2026 16:29

LondonPapa · 28/09/2026 13:55

How odd. I was part of a data breach of employee details and due to the impact it had on my subsequent employment thanks to how identifiable it all was, I got a payout of significantly more than 1p. More towards the ££££ end rather than P end!

If only I had used the word average so as not to look silly.

New posts on this thread. Refresh page
Swipe left for the next trending thread