.png)
.png)
Rebecca Matthews found out the hard way that a subject access request can feel less like paperwork and more like a diagnosis. The maternity safety campaigner submitted hers to Oxford University Hospitals NHS Foundation Trust expecting a routine disclosure. What came back showed senior doctors, midwives and clerical staff had viewed her confidential notes despite having no role in her care, some of them never having treated her at all. She has described the discovery as winding her. The trust's interim chief executive has confirmed an investigation into potential inappropriate access to her electronic patient record remains ongoing.
Her case would be troubling on its own. It is more troubling for what it confirms about a pattern that has been building across the health service for months. More than ninety members of hospital staff accessed the records of the three victims of the 2023 Nottingham stabbings after their deaths, prompting disciplinary action and dismissals earlier this year. At Liverpool University Hospitals, an internal audit identified dozens of suspicious accesses to the care records of Southport attack victims, with several staff leaving the trust before the investigation concluded. In June, Cambridge University Hospitals referred itself to the Information Commissioner's Office after discovering that around forty staff had viewed the medical file of a three year old injured in a widely reported crocodile attack, most with no plausible clinical reason to do so. A separate freedom of information request has surfaced eighteen further cases of wrongful access at the trust running York, Scarborough and Bridlington hospitals over five years.
What links these episodes is not malice on an industrial scale but something closer to a governance blind spot. Electronic patient record systems log every search and access, and organisations are expected to audit that activity routinely, yet in trust after trust the breaches surfaced only after a family complaint, a subject access request or a self-referral rather than through proactive detection. The infrastructure to catch this exists. The institutional will to use it consistently, evidently, has not kept pace with the sensitivity of what is being recorded.
NHS England's response has been to treat this as a service-wide failure rather than a series of local ones. In July, chief executive Sir Jim Mackey warned that staff who access records without a legitimate reason face dismissal or prison, and the organisation issued fresh guidance directing trust boards to strengthen monitoring and adopt a tougher disciplinary posture. The Information Commissioner's Office has gone further, warning that recent high-profile cases point to a worrying trend requiring a serious response across the healthcare sector rather than isolated lapses.
That framing matters for how the service should now respond. A crackdown pitched at individual curiosity, however sternly worded, will not fix systems that only flag unauthorised access after the fact. The technical capability for real-time alerts exists in some modern platforms, but adoption across England's fragmented trust landscape remains uneven, and the guidance issued so far leans on staff training and audit rather than mandating the kind of proactive monitoring that might have caught these cases before families found out through a data request rather than a phone call.
For NHS leaders already managing waiting lists, workforce shortfalls and the rollout of the Federated Data Platform, this adds a further test of institutional credibility at a moment when public trust in how the health service handles data is already under strain. Patients are being asked to accept ever greater digital integration of their records on the promise that this makes care safer and more efficient. Every case like Matthews's, or the Nottingham families before her, chips away at the premise that the system built to protect that information can be relied upon to do so without being asked.