Investigation finds NHS staff accessed records of terror victims and abuse targets
Cases involving Nottingham and Southport victims put local access controls, audit logs and enforcement of patient confidentiality under renewed scrutiny.
Sensitive records accessed without a care reason
A joint Sky News and Health Service Journal investigation has found that NHS employees accessed patient records without a legitimate clinical reason, including records belonging to victims of the Nottingham and Southport attacks. The reporting also identified cases in which access to medical information was connected to coercive control and domestic abuse. These are not abstract cyber intrusions: the alleged misuse involved insiders able to view highly sensitive information through systems provided for patient care.
NHS England’s response said trusts are required to keep audit logs showing who accessed patient information, maintain controls capable of preventing or detecting improper access and act when staff misuse their privileges. That response establishes the expected control framework but does not resolve whether safeguards were applied consistently in the cases uncovered, how quickly suspicious access was detected or what disciplinary and legal consequences followed.
Why insider access is especially damaging
Medical records can contain details about injuries, treatment, mental health, family circumstances and communications with clinicians. For victims of mass violence, unauthorised viewing compounds trauma and can undermine confidence that seeking treatment will remain confidential. In coercive-control cases, access may also expose locations, appointments or other information capable of being used to intimidate a victim. The public-interest issue is therefore both privacy and personal safety.
The official governance standard is unambiguous about the importance of protection. Guidance issued by the health secretary says NHS England should maintain high standards of information governance, technical safeguards and transparency. It also requires clear accountability for information risk and recognises health information as protected under data-protection law and the common-law duty of confidentiality. A 2026 Health Bill fact sheet says restructuring digital functions does not relax existing access and security rules.
Audit trails must lead to action
Audit logs are valuable only when organisations review them, identify unusual behaviour and escalate findings promptly. A technically complete record of access does little for patients if investigations begin months later or sanctions vary sharply between trusts. The cases reported by Sky News therefore raise operational questions about monitoring thresholds, staffing, notification of affected patients and whether trusts share lessons when the same type of misuse occurs elsewhere.
The immediate next step is to determine the scale and disposition of the identified cases: which accesses lacked a care purpose, whether information left NHS systems, and what remedial action was taken. Regulators and ministers may also face pressure to publish comparable trust-level data. The available evidence supports the finding of improper access cases and the applicable safeguards, but it does not justify assuming that every access resulted in disclosure outside the health service.