NHS staff accessed thousands of patient records they had no reason to see
A joint Sky News and Health Service Journal investigation has found thousands of cases where NHS staff potentially looked at the medical records of patients they were not treating, including victims of the Nottingham attacks. The mother of one victim called it sickening.

Why it matters
What this means for organisations holding critical data
A joint Sky News and Health Service Journal investigation has found thousands of cases where NHS staff potentially looked at the medical records of patients they were not treating, including victims of the Nottingham attacks. The mother of one victim called it sickening.
What happened
A joint investigation by Sky News and the Health Service Journal has found thousands of cases in which NHS staff potentially accessed the medical records of patients they had nothing to do with treating.
The pattern the reporting describes is not a criminal gang breaking in from outside. It is people already inside the system, already holding valid credentials, opening records they had no clinical reason to open. Among the cases are victims of the Nottingham attacks, victims of a knife attack and people injured in a train crash.
Emma Webber, whose son Barnaby was killed in the Nottingham attacks, told Sky News the discovery was "sickening". Another bereaved father described the behaviour as morbid curiosity. Both were told that people employed to care for patients had looked at their family's most private information as though it were entertainment.
Why this is a different kind of breach
Most breaches we write about are loud. Systems stop, files are encrypted, a criminal group posts a countdown. This one is silent.
- Nothing was hacked. Every access used a legitimate account with legitimate rights.
- Nothing broke. No service went down, so no incident bridge opened and no engineer was paged.
- Nothing was stolen in the usual sense. The harm is that a stranger read something that belonged to a grieving family.
- The only trace is an audit log line that looks exactly like ordinary clinical work, unless somebody checks it against who was actually treating that patient.
That last point is the whole problem. Clinical systems are built to be permissive on purpose, because a clinician in an emergency must never be blocked by a permission prompt. The trade that healthcare makes is broad access now, scrutiny afterwards. When the scrutiny afterwards is not actually carried out, broad access is all that is left.
The legal position is not ambiguous
Under section 170 of the Data Protection Act 2018 it is a criminal offence to knowingly or recklessly obtain or disclose personal data without the consent of the organisation holding it. The Information Commissioner has prosecuted health and care workers for looking at records out of curiosity, and convictions have followed. It is also a disciplinary matter and, for registered professionals, a fitness to practise matter.
So this is not a grey area that needs new law. It is an existing offence that goes undetected because detection depends on somebody choosing to look.
The Firevault view
Mark Fermor of Firevault said: "We spend most of our time talking about attackers who want to destroy data. This story is about people who simply wanted to read it. Both are failures of control, and both come back to the same question: can you prove, beyond argument, who touched a record and when? If the answer depends on a log file that sits on the same estate as everything else, and that an administrator could edit, then you do not have proof. You have a claim."
We will be direct about what our own technology does and does not solve here, because the alternative is marketing pretending to be security.
Offline Secure Storage® does not stop a nurse in Nottingham opening a record in a live clinical system. Nothing air gapped can, because the record has to be reachable for care to happen. Confidentiality inside a running system is the job of identity, least privilege, break glass workflows and monitoring.
What offline protection does solve is the layer underneath: the evidence. Access logs are the only witness in a case like this. If those logs live on the same network as the accounts being investigated, they are as amendable as anything else on that network. A privileged insider who can read a record can often also reach the trail that records the reading.
Held on immutable, physically disconnected storage, the audit trail becomes something an insider cannot rewrite, an administrator cannot purge and a regulator can rely on. That is the difference between suspecting misuse and proving it.
What healthcare organisations should do now
- Audit proactively, not reactively. Compare record access against documented care relationships on a routine schedule, rather than waiting for a family to complain.
- Put friction where curiosity lives. Opening a record outside your own care team should require a stated reason, logged at the moment of access, with the individual named.
- Treat high profile patients as a standing control, not an exception. Where a name is in the news, apply enhanced monitoring by default.
- Protect the evidence. Move access and authentication logs to storage that is immutable and offline, so the trail survives both malice and tidy-up.
- Rehearse the disclosure. Families found out through journalists. An organisation that cannot say who saw a record within days should assume it will be asked in public.
Related reading
- Offline Secure Storage® explained
- Containment blueprint CP-02
- Find the right instance with the OSS Concierge
Source: Sky News, reporting jointly with the Health Service Journal.
How Firevault would handle this
A recovery copy an attacker cannot reach
Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.






