NHS staff suspected of snooping on patients’ medical records will now be suspended immediately and locked out of hospital computer systems, under a new “zero-tolerance crackdown” ordered by the head of NHS England.
Sir Jim Mackey wrote to all 205 NHS trusts in England on Friday, telling them to stop waiting for investigations to finish before acting. Anyone suspected of inappropriately accessing patient files should be suspended and cut off from NHS systems straight away, including remote access from home, he said.
“Patient records contain some of the most private information people will ever share,” Mackey said. “We have seen too many cases of people abusing that trust, and enough is enough.”
He didn’t hold back on the consequences either, warning: “Anyone who thinks they can satisfy their curiosity by looking at a patient’s record should know this: they will be found out, they may lose their career and could end up with a criminal record.”
Why now?
The move, first reported by the BBC and confirmed by the Guardian, Sky News and others, follows several high-profile cases of staff illegally accessing records. These include the medical files of victims of the 2023 Nottingham attacks carried out by Valdo Calocane, and the 2024 Southport stabbings committed by Axel Rudakubana, as well as those of a boy injured in a crocodile enclosure incident in Cambridgeshire in June.
This week, Bristol NHS Foundation Trust launched an internal investigation after it emerged that the records of Oliver McGowan, an autistic teenager who died in 2016 aged 18, had been accessed by staff years after his death. At least five staff members, including three nurses and a doctor, are said to have viewed his file without permission, some as recently as this year.
His mother, Paula McGowan, told the BBC she was “deeply concerned and hurt” and called on the NHS to do more to tackle the problem.
How big is the problem?
An investigation by Sky News and the Health Service Journal this month found that more than 200 NHS staff in England have been dismissed and around 2,000 sanctioned for snooping on patient records since 2020. Responses from 140 trusts showed 214 staff were dismissed, three suspended and 540 given a final written warning over the past five years.
Some cases involved curiosity about high-profile patients’ conditions, while others saw staff looking up the records of relatives, ex-partners or acquaintances without any clinical reason. In 2023, an NHS consultant in Cambridgeshire was investigated by the General Medical Council after accessing the health history of a woman who had started dating the doctor’s ex-partner.
Health and social care committee chair Layla Moran, a Liberal Democrat MP, has described the official figures as “canaries in the coal mine”. Meanwhile, the Information Commissioner’s Office’s chief executive, Paul Arnold, said in June that “inappropriate access is rare and does not represent the behaviour of the vast majority of healthcare staff”, even though health bodies reported 1,445 cases of inappropriate access to the ICO between 2019 and 2025.
What happens now
NHS England says the suspension policy is part of a wider effort that will also include a national campaign reminding staff of their responsibilities. Trusts are now expected to build the immediate suspension approach into their routine procedures, rather than treating it as a last resort once an investigation concludes. There is no single NHS-wide records system, so individual trusts and GP practices will still be responsible for enforcing the crackdown on their own networks.
Nocturnal





