---
title: "NHS staff accessed thousands of patient records… | Firevault"
description: "A joint Sky News and Health Service Journal investigation has found thousands of cases where NHS staff potentially looked at the medical records of patients…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/nhs-patient-records-snooping-sky-hsj-investigation-2026#webpage",
      "url": "https://fire-vault.com/news/nhs-patient-records-snooping-sky-hsj-investigation-2026",
      "name": "NHS staff accessed thousands of patient records…",
      "description": "A joint Sky News and Health Service Journal investigation has found thousands of cases where NHS staff potentially looked at the medical records of patients…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/news/nhs-patient-records-snooping-sky-hsj-investigation-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/nhs-patient-records-snooping-sky-hsj-investigation-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/nhs-patient-records-snooping-sky-hsj-investigation-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "NHS staff accessed thousands of patient records they had no reason to see",
          "item": "https://fire-vault.com/news/nhs-patient-records-snooping-sky-hsj-investigation-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "NHS staff accessed thousands of patient records they had no reason to see",
      "description": "A joint Sky News and Health Service Journal investigation has found thousands of cases where NHS staff potentially looked at the medical records of patients they were not treating, including victims of the Nottingham attacks. The mother of one victim called it sickening.",
      "url": "https://fire-vault.com/news/nhs-patient-records-snooping-sky-hsj-investigation-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/nhs-patient-records-snooping-sky-hsj-investigation-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/nhs-patient-records-snooping-sky-hsj-investigation-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/images/news/nhs-patient-records-snooping-sky-hsj-investigation-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/images/news/nhs-patient-records-snooping-sky-hsj-investigation-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-08T12:00:00+00:00",
      "dateModified": "2026-09-08T12:55:58.065368+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/nhs-patient-records-snooping-sky-hsj-investigation-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Insider Threat",
      "wordCount": 839,
      "keywords": "Insider Threat, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "## What happened A joint investigation by [Sky News](https://news.sky.com/video/its-sickening-mother-of-nottingham-attack-victim-on-nhs-data-breach-13583096) and the Health Service Journal has found thousands of cases in which NHS staff potentially accessed the medical records of patients they had nothing to do with treating. The pattern the reporting describes is not a criminal gang breaking in f",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What did the Sky News and Health Service Journal investigation find?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "It found thousands of recorded cases across NHS trusts where staff potentially accessed the medical records of patients they had no part in treating. The cases include high profile victims of violent crime and major incidents, whose records appear to have been opened out of curiosity rather than clinical need."
          }
        },
        {
          "@type": "Question",
          "name": "Is looking at a patient record without a reason against the law?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Under section 170 of the Data Protection Act 2018 it is a criminal offence to knowingly or recklessly obtain or disclose personal data without the consent of the data controller. The Information Commissioner has prosecuted health and care staff for exactly this, and it is also a disciplinary matter and a professional registration matter."
          }
        },
        {
          "@type": "Question",
          "name": "Why do access controls fail to stop this?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Clinical systems are deliberately permissive so that care is never delayed in an emergency. Most staff can open most records, and the control is retrospective auditing rather than prevention. Where auditing is not reviewed routinely, or where alerts are not tuned, snooping is only discovered when somebody complains."
          }
        },
        {
          "@type": "Question",
          "name": "How is insider snooping different from a ransomware attack?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A ransomware attack is loud and destroys or withholds availability. Insider snooping is silent and attacks confidentiality alone. Nothing is encrypted, nothing stops working, and the only evidence is an audit trail entry that looks like ordinary clinical use unless somebody compares it against who was actually caring for the patient."
          }
        },
        {
          "@type": "Question",
          "name": "Can offline storage prevent staff snooping on live records?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No, and it would be wrong to claim otherwise. Offline Secure Storage protects the integrity and survival of data, not the day to day confidentiality of a live clinical system. What it does protect is the audit evidence itself, so that the record of who opened what cannot be altered or deleted by anyone inside the estate."
          }
        },
        {
          "@type": "Question",
          "name": "What should NHS organisations do first?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Three things. Review access audit logs proactively against care relationships rather than waiting for a complaint. Apply break glass workflows so that opening a record outside a care team requires a stated reason. Hold access logs on immutable, offline protected storage so the evidence stands up to scrutiny and cannot be quietly amended."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Breaking News Updated as information becomes available 

Overview

What happenedWhy this is a different kind of …The legal position is not ambiguousThe Firevault viewWhat healthcare organisations sh…Related readingMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Insider Threat · 8 September 2026 · Breaking 

# NHS staff accessed thousands of patient records they had no reason to see

A joint Sky News and Health Service Journal investigation has found thousands of cases where NHS staff potentially looked at the medical records of patients they were not treating, including victims of the Nottingham attacks. The mother of one victim called it sickening.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

5 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fnhs-patient-records-snooping-sky-hsj-investigation-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fnhs-patient-records-snooping-sky-hsj-investigation-2026&text=NHS%20staff%20accessed%20thousands%20of%20patient%20records%20they%20had%20no%20reason%20to%20see%0A%0AA%20joint%20Sky%20News%20and%20Health%20Service%20Journal%20investigation%20has%20found%20thousands%20of%20cases%20where%20NHS%20staff%20potentially%20looked%20at%20the%20medical%20records%20of%20patients%20they%20were%20not%20treating%2C%20including%20victims%20of%20the%20Nottingham%20attacks.%20The%20mother%20of%20one%20victim%20called%20it%20sickening.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fnhs-patient-records-snooping-sky-hsj-investigation-2026)[](mailto:?subject=NHS%20staff%20accessed%20thousands%20of%20patient%20records%20they%20had%20no%20reason%20to%20see&body=A%20joint%20Sky%20News%20and%20Health%20Service%20Journal%20investigation%20has%20found%20thousands%20of%20cases%20where%20NHS%20staff%20potentially%20looked%20at%20the%20medical%20records%20of%20patients%20they%20were%20not%20treating%2C%20including%20victims%20of%20the%20Nottingham%20attacks.%20The%20mother%20of%20one%20victim%20called%20it%20sickening.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fnhs-patient-records-snooping-sky-hsj-investigation-2026)

![A darkened hospital office at night with one screen showing an open patient record and a warning alert.](/images/news/nhs-patient-records-snooping-sky-hsj-investigation-2026.jpg)

A darkened hospital office at night with one screen showing an open patient record and a warning alert.

Why it matters

## What this means for organisations holding critical data

A joint Sky News and Health Service Journal investigation has found thousands of cases where NHS staff potentially looked at the medical records of patients they were not treating, including victims of the Nottingham attacks. The mother of one victim called it sickening.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [Why this is a different kind of …](#section-1)
3.  03 [The legal position is not ambiguous](#section-2)
4.  04 [The Firevault view](#section-3)
5.  05 [What healthcare organisations sh…](#section-4)

**On this page**[What happened](#section-0)[Why this is a different kind of …](#section-1)[The legal position is not ambiguous](#section-2)[The Firevault view](#section-3)[What healthcare organisations sh…](#section-4)

## What happened

A joint investigation by [Sky News](https://news.sky.com/video/its-sickening-mother-of-nottingham-attack-victim-on-nhs-data-breach-13583096) and the Health Service Journal has found thousands of cases in which NHS staff potentially accessed the medical records of patients they had nothing to do with treating.

The pattern the reporting describes is not a criminal gang breaking in from outside. It is people already inside the system, already holding valid credentials, opening records they had no clinical reason to open. Among the cases are victims of the Nottingham attacks, victims of a knife attack and people injured in a train crash.

Emma Webber, whose son Barnaby was killed in the Nottingham attacks, told Sky News the discovery was "sickening". Another bereaved father described the behaviour as morbid curiosity. Both were told that people employed to care for patients had looked at their family's most private information as though it were entertainment.

## Why this is a different kind of breach

Most breaches we write about are loud. Systems stop, files are encrypted, a criminal group posts a countdown. This one is silent.

-   Nothing was hacked. Every access used a legitimate account with legitimate rights.
-   Nothing broke. No service went down, so no incident bridge opened and no engineer was paged.
-   Nothing was stolen in the usual sense. The harm is that a stranger read something that belonged to a grieving family.
-   The only trace is an audit log line that looks exactly like ordinary clinical work, unless somebody checks it against who was actually treating that patient.

That last point is the whole problem. Clinical systems are built to be permissive on purpose, because a clinician in an emergency must never be blocked by a permission prompt. The trade that healthcare makes is broad access now, scrutiny afterwards. When the scrutiny afterwards is not actually carried out, broad access is all that is left.

## The legal position is not ambiguous

Under section 170 of the Data Protection Act 2018 it is a criminal offence to knowingly or recklessly obtain or disclose personal data without the consent of the organisation holding it. The Information Commissioner has prosecuted health and care workers for looking at records out of curiosity, and convictions have followed. It is also a disciplinary matter and, for registered professionals, a fitness to practise matter.

So this is not a grey area that needs new law. It is an existing offence that goes undetected because detection depends on somebody choosing to look.

## The Firevault view

Mark Fermor of Firevault said: "We spend most of our time talking about attackers who want to destroy data. This story is about people who simply wanted to read it. Both are failures of control, and both come back to the same question: can you prove, beyond argument, who touched a record and when? If the answer depends on a log file that sits on the same estate as everything else, and that an administrator could edit, then you do not have proof. You have a claim."

We will be direct about what our own technology does and does not solve here, because the alternative is marketing pretending to be security.

[Offline Secure Storage](/offline-secure-storage)® does not stop a nurse in Nottingham opening a record in a live clinical system. Nothing air gapped can, because the record has to be reachable for care to happen. Confidentiality inside a running system is the job of identity, least privilege, break glass workflows and monitoring.

What offline protection does solve is the layer underneath: the evidence. Access logs are the only witness in a case like this. If those logs live on the same network as the accounts being investigated, they are as amendable as anything else on that network. A privileged insider who can read a record can often also reach the trail that records the reading.

Held on immutable, [physically disconnected storage](/storage), the audit trail becomes something an insider cannot rewrite, an administrator cannot purge and a regulator can rely on. That is the difference between suspecting misuse and proving it.

## What healthcare organisations should do now

1.  Audit proactively, not reactively. Compare record access against documented care relationships on a routine schedule, rather than waiting for a family to complain.
2.  Put friction where curiosity lives. Opening a record outside your own care team should require a stated reason, logged at the moment of access, with the individual named.
3.  Treat high profile patients as a standing control, not an exception. Where a name is in the news, apply enhanced monitoring by default.
4.  Protect the evidence. Move access and authentication logs to storage that is immutable and offline, so the trail survives both malice and tidy-up.
5.  Rehearse the disclosure. Families found out through journalists. An organisation that cannot say who saw a record within days should assume it will be asked in public.

## Related reading

-   [Offline Secure Storage® explained](/how-it-works/offline-secure-storage)
-   [Containment blueprint CP-02](/control-blueprints/cp-02)
-   [Find the right instance with the OSS Concierge](/find-my-oss)

Source: [Sky News](https://news.sky.com/video/its-sickening-mother-of-nottingham-attack-victim-on-nhs-data-breach-13583096), reporting jointly with the Health Service Journal.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)[

![Quinn Emanuel and McDermott breached as law firms become the soft route to client data](/images/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026.jpg)

Breach Analysis 

### Quinn Emanuel and McDermott breached as law firms become the soft route to client data

Two more major US law firms have disclosed social engineering breaches, joining Herbert Smith Freehills Kramer, Goodwin Procter and WilmerHale. One compromised user account was enough.

8 Sept 2026 4 min 







](/news/law-firms-quinn-emanuel-mcdermott-data-breaches-2026)[

![Mathspace breach exposes more than one million students, staff and parents](/images/news/mathspace-data-breach-one-million-students-2026.jpg)

Breach Analysis 

### Mathspace breach exposes more than one million students, staff and parents

An unpatched self-hosted reporting system gave attackers seventeen days inside Mathspace, exposing names and email addresses for 1,079,819 people across Australia and New Zealand.

8 Sept 2026 4 min 







](/news/mathspace-data-breach-one-million-students-2026)[

![UK Lords Call for AI 'Kill Switch' Powers in Cyber Security and Resilience Bill](/images/news/lords-ai-kill-switch-powers-uk.jpg)

Artificial intelligence 

### UK Lords Call for AI 'Kill Switch' Powers in Cyber Security and Resilience Bill

A cross-party group of peers has proposed powers that would let the British government deactivate powerful AI systems and switch off data centres if the technology poses a threat to national security. The amendment puts control, not just containment, at the centre of UK cyber resilience.

2 Sept 2026 5 min 







](/news/lords-call-ai-kill-switch-powers-uk-cyber-resilience-bill)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. New research shows no hacking was required: server-side marketing API keys sat in the public JavaScript of all three airport websites, unrotated, for more than four years.

27 Aug 2026 8 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)