.jpg)
.jpg)
North West Ambulance Service took almost two months to tell victims of the Southport attack that their medical records may have been accessed without any clinical justification, a delay that families and their lawyers have condemned as inexcusable. The trust has confirmed it is formally investigating up to ten members of staff over the unauthorised access, but the admission has reopened a wound that survivors of one of the most harrowing crimes in recent British history believed had already been inflicted once, by NHS staff elsewhere, and was now being repeated.
The chronology sits at the heart of the criticism. NWAS identified concerns about the access internally, yet a decision was taken by the trust's data security lead that it was not appropriate to inform the patients affected at that stage. Only weeks later, following further scrutiny, did the trust move to contact families. Chief executive Salman Desai has since said the trust had identified concerns about potential inappropriate access to patient records and was formally investigating, adding that it would contact families and patients as inquiries progressed and was deeply sorry for the distress caused. No member of staff has yet been formally disciplined, though the trust says it intends to strengthen its internal processes.
The nature of what was accessed makes the delay harder to defend. These were not routine administrative files but the treatment records of people who had just survived a mass stabbing, patients whose injuries, in some cases, were sustained while trying to protect children. Solicitors acting for several of those affected have described the pattern of access as evidence of a deeper institutional problem rather than isolated curiosity. One called it a culture of snooping that has now surfaced repeatedly across the health service. A father of one of the injured, a girl who was thirteen at the time of the attack, said the discovery amounted to a complete breach of trust at the family's darkest hour and accused some staff of acting out of morbid curiosity rather than duty.
This is not an isolated case. In May, University Hospitals of Liverpool Group admitted that forty-eight staff at Aintree Hospital, where many of those injured were treated in July 2024, had looked at victims' records with no legitimate reason. Leanne Lucas, the dance instructor who survived the attack and was treated at Aintree, said she was devastated by that breach and described the second revelation as insult added to injury. The recurrence across two separate NHS organisations tied to the same tragedy points to something beyond individual misconduct. It suggests that access controls around high-profile patients remain porous almost everywhere they are tested, and that staff curiosity about newsworthy cases continues to override professional boundaries even after repeated warnings.
The wider pattern reinforces that reading. Cambridge University Hospitals is investigating after around forty staff accessed the records of a three-year-old boy injured in a widely reported incident, while Nottingham University Hospitals dismissed eleven staff and disciplined fourteen more for similar conduct earlier this year. The Information Commissioner's Office has confirmed it is aware of the NWAS case and is assessing whether a criminal investigation into breaches of data protection law is warranted, and says it is working with NHS England and the National Data Guardian on the sector's wider record.
For NHS leaders already managing workforce strain and public confidence pressures, these incidents carry a cost beyond regulatory exposure. Every unauthorised look at a patient's file is a small, discrete failure, but the accumulation of such failures around a single tragedy erodes something harder to repair: the assumption that when people are at their most vulnerable, the health service is a place where their privacy is protected rather than a source of curiosity for its own staff. Rebuilding that assumption will require more than warning letters and unfulfilled promises of stronger HR processes. It will require trusts to demonstrate, with evidence rather than reassurance, that access to sensitive records is monitored in real time and that breaches are reported to those affected within days, not months.