The NHS is once again under scrutiny for inappropriate access to patient records — and this time the scale is impossible to ignore. Recent reporting shows 214 NHS staff dismissed and around 2,000 sanctioned for wrongful access since 2022¹. York and Scarborough Teaching Hospitals have also admitted they under‑reported their own incidents, revising their figures to 29 cases since 2021, with 10 referred to the ICO².
Recently, ITV News has now brought the issue into mainstream public attention, reporting multiple dismissals for unlawful access linked to the Nottingham attacks³. This reinforces what many of us in primary care have known for years: inappropriate access is not rare, not theoretical, and not confined to hospitals.
Primary care may face particular vulnerabilities because:
- More staff have access.
- More roles require non‑clinical access.
- More patients are personally known to staff.
- Systems are shared across PCNs and federations.
Many information governance professionals believe inappropriate access is most likely, least visible, and hardest to prevent using traditional methods.
Why Primary Care Is Uniquely Vulnerable
1. High numbers of staff with broad access
Receptionists, secretaries, care coordinators, pharmacists, PCN clinicians, social prescribers, and admin teams all legitimately access records daily. The sheer volume creates a wide attack surface.
2. Frequent non‑clinical reasons for access
General practice routinely accesses records for:
- Recalls
- QOF
- Summarising new patient notes
- Medication queries
- Referrals
- Complaints
- Insurance reports
All legitimate — but they create audit noise, making inappropriate access harder to spot.
3. Community proximity
Staff often know patients socially. The ICO has warned of a “worrying trend” of curiosity‑based snooping across the NHS². In primary care, this risk is amplified.
4. Cultural norms
Many practices historically operated on trust:
“If you’re in the building, you’re trusted to access records.”
That culture is no longer sustainable.
Why Traditional Warnings Do Not Work
Every practice manager knows the pattern:
- You train staff.
- You warn staff.
- You remind staff.
- You repeat confidentiality modules.
- You emphasise “only access if necessary.”
And still, audits show:
- Curiosity about a neighbour
- Interest in a local incident
- Checking a friend’s appointment
- Looking at a staff member’s record
- Accessing a patient in the news
This is not a training failure — it is a behavioural reality. Human curiosity is powerful, and warnings alone do not change behaviour.
A Reality Often Missed: Practice Managers Also Need to Access Records
One aspect rarely acknowledged in national guidance is that practice managers themselves often need to access patient records — and not for clinical reasons.
In primary care operations, a manager may need to open a record to:
- oversee an incident or complaint.
- verify details when responding to a patient query.
- check workflow trends or patterns.
- review how a process has been managed.
- ensure a referral or communication has been completed.
- investigate a potential system error or data quality issue.
None of this is nosey. None of it is inappropriate. It is simply part of running a safe, accountable practice.
Yet these managerial accesses look identical to “non‑clinical access” in an audit log. And months later, when an ICB or ICO asks:
“Why did the practice manager access this record on that date?”
The honest answer is often:
- to resolve a query,
- to check a workflow,
- to oversee an incident,
- to ensure something had been done correctly.
But reconstructing the exact reason months later is extremely difficult. Primary care workflows are fast‑moving, high‑volume, and often reactive. Managers deal with dozens of issues a day — many of which never generate a formal note.
This is the tension national bodies underestimate:
Legitimate access in primary care is broad, frequent, and often operational rather than clinical — yet retrospective justification is expected.
Patients are absolutely right to demand confidentiality. But the operational reality is far more complex than guidance suggests.
The National Crackdown: What’s New and Why It Matters
NHS England has now made inappropriate access a zero‑tolerance offence, with staff facing dismissal and, in serious cases, criminal investigation. The latest guidance encourages:
- Mandatory audits
- Real‑time monitoring where available
- Role‑based access controls
- Multi‑factor authentication
- Reporting to the ICO and police for unlawful access
This is not optional. It represents a sector‑wide shift in governance expectations⁴.
What This Means for GP Practices
1. Monthly audit logs will become standard
ICBs are already moving toward proactive audits. Practices must be able to justify every access, including admin access.
2. Role‑based access will tighten
Providers like EMIS, System One and Medicus may restrict:
- Reception visibility
- PCN staff access
- Ability to open full records without a clinical task.
3. Staff will need clearer, documented justification
Practices must define:
- What counts as legitimate access?
- Which roles can perform which tasks?
- How admin staff should record justification
- How to respond to audit queries
4. Disciplinary processes must be robust
The era of “a quiet word” is over. NHS England expects:
- Formal warnings
- Dismissal where appropriate
- Referral to regulators
- ICO notification
- Police involvement for criminal breaches
5. Patients will increasingly request access logs
Patients are becoming aware of their rights. Expect more SARs asking:
“Who has accessed my record and why?”
Practices must be ready to respond.
The Non‑Obvious Impact: A Cultural Shift
The biggest change is psychological. Staff now know every click is logged, audited, and attributable. This is far more effective than any confidentiality training.
Primary care is moving from:
Trust‑based access → Audit‑based access
This is a fundamental shift in how practices operate.
What Practice Managers Should Do Now
- Define role‑based access for every staff group.
- Update confidentiality training with real case examples.
- Implement monthly audits and document outcomes.
- Create a “legitimate access” policy for admin and PCN staff.
- Prepare a patient‑facing explanation of how access is monitored.
- Review EMIS/System One, Medicus permissions to reduce unnecessary visibility
These steps protect patients, staff, and the practice itself.
Conclusion: Primary Care Must Lead the Way
The national enquiry has exposed a system‑wide problem — but primary care is where the solution must be strongest. With broad access, community proximity, and complex workflows, GP practices face the highest risk and the greatest scrutiny.
The message from NHS England is clear:
“Don’t let curiosity kill your career.”
For practice managers, this is not just a compliance issue — it is a core governance responsibility.
References
- BMJ – Hundreds of NHS staff disciplined for inappropriate access to patient records since 2022.
- Yorkshire Post – York and Scarborough Teaching Hospitals reveal under‑reported cases of unlawful record access; ICO warns of rising curiosity‑based snooping.
- ITV News Central – NHS trust fires staff for inappropriate access to medical records of Nottingham attack victims.
- NHS England – Records Management Code of Practice; Data Security and Protection Toolkit; national guidance on inappropriate access and zero‑tolerance policy.
0 Comments