NHS England has introduced a “zero-tolerance” policy across all health trusts, including those serving Chichester and West Sussex, following a series of high-profile data breaches. Under the new mandate, any member of staff suspected of “snooping” on patient records must be suspended immediately while investigations are carried out.
The directive was issued on 25 September 2026 in a formal letter to all 205 NHS trust leaders from Sir Jim Mackey, NHS England’s national director of elective recovery. The instruction marks a significant shift in disciplinary procedures, as some trusts previously treated suspension as a last resort during the initial stages of a probe.
The mandate applies to University Hospitals Sussex NHS Foundation Trust, which operates St Richard’s Hospital in Chichester. It requires that any employee suspected of unauthorised access must have their technical access to NHS computer systems cut off instantly to prevent further potential breaches.
National security concerns
The move follows several serious incidents involving the medical records of victims from high-profile tragedies. This includes reports of illicit access to the health records of victims of the 2023 Nottingham attacks and the 2024 Southport stabbings.
NHS England has clarified that curiosity is no longer a legitimate defence for accessing patient files. Any access without a genuine clinical or administrative reason is now to be treated as gross misconduct. The Information Commissioner’s Office (ICO) has previously warned that such actions are not merely a workplace disciplinary issue but can constitute a criminal offence under data protection laws.
According to NHS Employers, trusts are also expected to refer staff who are dismissed for snooping to their respective professional regulators. This could lead to individuals being struck off and barred from working in the healthcare sector in the future.
Advice for patients
The NHS has sought to reassure patients that digital logs now track every search and view on electronic health record systems. These audit trails allow investigators to see exactly who has accessed a file and when the access occurred.
Patients who are concerned that their privacy may have been compromised have the right to request an “audit trail” of their own records from their healthcare provider. This applies to both hospital records and GP surgery files, as the mandate covers the broader NHS workforce across England.
While the policy focuses on immediate suspension, the legal status of the staff members remains that of an investigation; a suspension is a neutral act designed to protect data integrity and does not automatically imply a finding of guilt before the internal process is complete.
