NHS HEAD WARNS STAFF OF SACK AND PRISON FOR UNLAWFUL RECORD ACCESS
Sir Jim Mackey, head of the NHS, has warned staff that unauthorised access to patient records will result in dismissal or criminal prosecution. Sir Jim described such access undertaken for personal reasons or curiosity as "wholly unacceptable, a disgraceful breach of patient trust and against the law". NHS England has launched a campaign to educate staff on what constitutes unlawful access, the impact on patients, and career consequences. The warning follows several instances of staff being dismissed after accessing medical records of victims involved in high-profile crimes, including the Nottingham attacks.
NHS England has published new guidance for all NHS organisations on preventing, monitoring and investigating unauthorised access to patient data. The guidance identifies different types of unlawful access and sets out employer responsibilities, which include potential reporting to the Information Commissioner's Office, police and professional regulators. Where unlawful access is identified, both the ICO and police retain the power to pursue criminal prosecution, whilst professional regulators can end careers. Employers have been advised to implement technical controls including role-based access restrictions, multi-factor authentication and systems that limit sensitive information access to staff who require it for their role.
Some newer electronic patient record systems can identify unlawful access in real time and flag suspicious activity for investigation. NHS England has instructed organisations to conduct regular audits of access patterns according to their IT infrastructure capabilities. The guidance specifies that monitoring approaches should protect patient information without impeding staff from performing their duties.