Ten staff members at East Suffolk and North Essex NHS Foundation Trust (ESNEFT) have been suspended or removed from active duty following an investigation into unauthorised access to the medical records of a deceased toddler.
The trust confirmed that the breach involved the digital files of three-year-old Noah Woods, who was found dead in Decoy Pond, Brantham, on 16 September 2026. The unauthorised access is reported to have occurred between 15 September and 16 September, leading the trust’s information governance team to conduct a full audit of the electronic record system.
Dr Martin Mansfield, Deputy Chief Medical Officer and Caldicott Guardian at ESNEFT, has issued an unreserved apology to the family of Noah Woods. He confirmed that the trust has taken “immediate steps” to secure the records and prevent further unauthorised access while formal disciplinary proceedings are explored.
The internal investigation was triggered on 17 September, shortly after the high-profile nature of the case became apparent. The trust has formally notified the Information Commissioner’s Office (ICO) of the breach, which may lead to further regulatory action or fines under data protection laws.
The removal of the ten staff members follows a national directive from NHS England Chief Executive Sir Jim Mackey, who recently warned of immediate consequences for any staff found “snooping” on patient records. Sir Jim stated that such actions undermine public trust and that the NHS would maintain a zero-tolerance approach to privacy violations.
An inquest into the death of Noah Woods was opened on 25 September, where it was heard that the circumstances of his death are still subject to further post-mortem investigation. The toddler’s death in the Suffolk village had prompted a significant emergency services response.
According to ITV News, the trust has not disclosed the specific job roles of the ten staff members involved, nor whether they were clinical or administrative personnel.
ESNEFT, which manages Colchester and Ipswich hospitals alongside several community sites, stated that it remains committed to the highest standards of data security and that all staff are regularly trained on their legal obligations regarding patient confidentiality. Under the Data Protection Act, the unauthorised accessing of personal data without a legitimate clinical or administrative reason can be a criminal offence.





