In short
A Sky News/Health Service Journal investigation into NHS staff accessing patients’ private medical records without authorization, including victims of the Nottingham and Southport terror attacks and other high-profile people. The episode argues this is widespread, often under-detected, and can enable voyeurism, intimidation, and coercive control.
Guests and backgrounds
Zoe Tidman (Senior Correspondent, Health Service Journal) and Ashish Joshi (Sky Health Correspondent). They discuss reporting findings and NHS/ICO responses.
Key claims
More than 2,900 cases investigated in five years; 214 dismissals; 54 of 134 trusts said they actively checked; many breaches only surface via complaints or leaks. ICO prosecutions are rare (one since 2023 mentioned). System access is broad across networks.
Notable examples
Dr Sanjoy Kumar’s daughter Grace (Nottingham) whose records were accessed; “Jane,” whose GP-held records were accessed by a hospital consultant ex-partner, causing fear and alleged intimidation; a secretary accessing 100+ records.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOTrust Broken: A Father's Pain
0:46 to 1:30
Dr. Sanjoy Kumar discusses the violation of privacy after losing his daughter in a terror attack.
“Electoral Dysfunction, wherever you get your podcasts.”
Case Studies of Privacy Breaches
1:31 to 4:12
Exploration of multiple cases where NHS staff accessed private medical records.
“She says a man she was dating was passed information from her medical records by his ex-partner, a hospital doctor.”
The Nottingham and Southport Killings
4:13 to 5:24
An overview of the major incidents leading to privacy concerns in NHS.
“or unless there are clever journalists like Zoe who are digging around trying to find out what sort of breaches of data there have been.”
Consequences of Medical Record Breaches
5:25 to 7:34
Discussion on the repercussions faced by NHS staff accessing patient records.
“You know, accessing someone, and I hate the word data.”
Victims' Experiences: Jane's Story
7:35 to 9:33
Detailed account of a woman named Jane whose medical records were accessed without consent.
“In fact, I understand she was promoted later.”
The Struggles for Patients to Seek Justice
9:34 to 11:28
Challenges faced by victims in reporting breaches and seeking accountability.
“and you know don't get sacked they're still working today.”
Systemic Issues in NHS Record Access
11:29 to 12:37
Analysis of how the NHS handles access to medical records and the issues it presents.
“perpetrator and they said action was taken but no one was sacked so i think that just kind of summarises, you know, it's known to happen, but is it taken seriously?”
Calls for Better Data Protection
12:38 to 14:00
Discussion on the need for improved data security and privacy measures in the NHS.
“I think most people presume that it's, you know, the GP that is sitting right in front of you when you go into that meeting.”
Medical Records and Privacy Breaches
14:00 to 15:51
Discussion on the accessibility of medical records and the breaches occurring due to lack of oversight.
“who are actively treating you have access to your records.”
Motivations Behind Data Breaches
15:51 to 18:10
Exploration of various motivations for NHS staff accessing patient records without consent.
“I mean, what have you discovered about the motivation for this sort of breach of privacy?”
Show all 13 chapters
Role of the Information Commissioner's Office
18:10 to 19:45
Overview of the Information Commissioner's Office and its handling of data breach cases.
“But a lot of the time, there's kind of just informal conversations with the trust.”
Potential Changes in NHS Data Management
19:45 to 20:58
Discussion on potential improvements and the importance of securing NHS patient records.
“But now the red flags are if it can't keep our data safe with the system it has in place already, what safeguards are there for a future system?”
Public Awareness and Patient Rights
20:58 to 22:00
Encouragement for individuals to understand their rights regarding medical records and access.
“but at least, you know, when you were speaking to Dr Kumar, I mean, he laid it bare.”
Transcript
Automatic transcript. May contain errors.0:02Sky News, the full story first.
0:12A Sky News investigation has exposed the extent to which NHS staff are accessing patients' most private information. They're medical right-hards. This is why.
0:26The most excruciating period of politics that I can ever remember. I have to say as a government minister, never quite sure what the cabinet office did, but just hold meetings. It has gone down like a bucket of sick. I kind of thought that decades of experience meant that you weren't swallowing this vapid... Oh, blimey! Hello and welcome to Electoral Dysfunction with me, Beth Rigby. Me, Ruth Davidson. Me, Harriet Harman. And me, Jess Phillips. Electoral Dysfunction, wherever you get your podcasts.
0:59You tell a doctor things you might not wish to tell another soul. You therefore expect them to stay private. For Dr Sanjoy Kumar, that trust was broken after his daughter Grace was killed in the Nottingham attacks and her medical records subsequently accessed. With all of everything and the news that we'd had to put up with, with the loss of our daughter, the pain, the anguish. And it's that grain of salt that you can pick up and put it into the wounds. Of course, it would be easy to assume this is only happening in high-profile cases. Not a bit of it. Take Jane. She says a man she was dating was passed information from her medical records by his ex-partner, a hospital doctor.
1:44I couldn't believe it. And it was like being hunted. It was horrible. My knees were shaking together. It was really chilling. Our analysis found more than 2 ,900 cases were investigated by the NHS in five years. 214 people were dismissed. But with some trusts still not routinely checking for inappropriate access, the true scale is likely to be much, much greater. I spoke to Zoe Tidman, Senior Correspondent at the Health Service Journal, and Sky's Health Correspondent, Ashish Joshi. Zoe, Ashish, look, a lot of what we are going to be discussing will sound familiar because it is familiar to the public.
2:23This is a story that is going to take us from Nottingham to Southport via the palace. I mean, Ashish, just explain. These are big moments, seared in our memory, horrific attacks in Nottingham when you had three people who were killed in what we now know is a senseless attack, stabbed to death. We had the Southport killings, again, another senseless attack. And you have members of the royal family who have had their records breached because we associate high-profile celebrities, people in the public eye, having to guard their personal details, and then finding out later that either through really poor journalism or just for no other reason than just voyeuristic pleasure have had their records accessed.
3:12We know about these incidents. They've unfolded in front of us and they're part of what we remember over the last few years as absolutely horrific incidents. I mean, I think I'm right in saying Southport was where this began for you, wasn't it? Yeah, and it came out as kind of accidentally as well. So it was because the trust had accidentally published a board paper which revealed that these privacy breaches had taken place. So no one had known about them for two years. came out accidentally. We went to report it and the trust hadn't told the victims because they're worried about the impact. So yeah, it does make you worry kind of how much more this goes on.
3:51And one of those victims that Zoe's talking about is a 13-year-old girl. And it's important, that was great journalism from the HSJ, something published in the public domain that shouldn't have been. And really, that's what goes to the heart of the problem, is you will never know that this has happened to you unless it slips out into the public domain or unless there are clever journalists like Zoe who are digging around trying to find out what sort of breaches of data there have been. It's like the case that we're going to talk about with Gracie. Her father, her mother, they would never have known that this had happened to them had it not been for the subsequent investigations into those deaths.
4:31It's something that happens all the time, all too frequently, and you'll never know about it unless you find out about it. that there were people within the NHS accessing the medical records of those who died in Nottingham, those who were injured and who were hurt and who died in Southport, members of the royal family. Look, I think there is probably a little bit of everyone that can maybe understand, to a tiny extent, the curiosity that might exist about incidents involving high-profile figures. But as you've been discovering, Ashish, it's not just people who are on the front page. No, no, it's not.
5:06Of the thousands and thousands of cases, maybe a dozen or so will be a high profile case. And we're not justifying it. We're not excusing it. But we can say if something, there is a new story which is dominating headlines, there might be somebody who thinks, oh, let me just find out a little more about it. That is a gross violation in itself. And it should never, ever, ever happen. And we don't justify it. But it's happening to ordinary people. You know, accessing someone, and I hate the word data. For me, data is switch off. You know, it's, who cares about data? What is it, your national insurance number?
5:43Is it your telephone number? No, it's your most intimate personal medical details. And when that is accessed by a complete stranger, that's a gross violation. And it happens to ordinary people. One woman who was brave enough to share her story with us, I think in the report we call her Jane. So I'll call her Jane just so you can follow the thread on this story. Jane, we spoke to. Jane had been recently bereaved. She'd lost her husband. Some time had passed and she met someone else and she wanted to continue dating. What she didn't know was that this would turn into an absolute nightmare, not because of her new partner, because of her partner's ex-partner who happened to be a consultant in a Cambridgeshire hospital trust.
6:26That consultant accessed Jane's most private records records that weren't even shared with the hospital directly by Jane but records which were held by Jane's GP to what end well Jane had been sharing her details with her GP to help her deal with her bereavement and everything else some really personal records and this ex-partner who was a consultant contacted Jane made it very clear she had access to Jane's medical records and made her feel very, very uncomfortable. It was almost like being stalked. It sounds like intimidation. It does exactly that. And Jane was terrified at first thinking, oh, my God, this is a hospital consultant.
7:08Right. So she's clearly a very bright woman who has access to my records. If she's breached my medical records, what else might she do? Right. So all of these thoughts are going through your mind thinking, you know, my information is being held by someone who shouldn't be holding my information, someone who obviously has an interest in my new relationship with her ex-partner. Think about it. So you join the dots. And this is what Jane was doing. She contacted the trust. The trust investigated. Nothing happened to the consultant. In fact, I understand she was promoted later. But, you know, I mean, she carried on with her career.
7:44Jane clearly distressed, wanted to take further action and get this. She approached the information Commissioner's Office and she due process wants a full investigation into what was happening and why her medical records have been breached. You know why she wasn't able to take it any further? Go on. She was told that the data did not belong to her. So therefore, she was not the victim in all of this. It was the hospital trusts who were the victims because their data had been breached. Look Zoe, clearly this can happen to any one of us that have records accessible through the NHS. So how often is this happening?
8:23I think this is the really worrying thing, is that we don't know. And a bit like with Jane here, it's up to the patient to find out and then complain. So I think to talk about our investigation, to caveat, people have said it's the tip of the iceberg. This is what we know about. So we looked into how many cases are known by the NHS to have happened over the past five years and what happens. and we found that about 2 ,000-odd cases, about 200 staff had been sacked, three had been suspended, and then 500 final written warnings, the vast majority, all lesser warnings. So that's verbal warnings, a lot of informal action, which can range from counselling, training, etc., or nothing at all.
9:11So headline figure is, you know, a lot of the time it's a slap on the wrist. some of those cases will be staff looking at their own medical records which again isn't really acceptable but from kind of our case studies that we've spoken to and Southport we know that there are times where staff have just viewed voyeuristically other people's records and you know don't get sacked they're still working today. I think their investigation also found that since 2023 there's been one prosecution only one prosecution since 2023.
9:53The most excruciating period of politics that I can ever remember. I have to say, as a government minister, never quite sure what the Cabinet Office did, but just hold meetings. It has gone down like a bucket of sick. I kind of thought that decades of experience meant that you weren't swallowing this vapid... Oh, blimey! Hello and welcome to Electoral Dysfunction with me, Beth Rigby. Me, Ruth Davidson. Me, Harriet Harman. And me, Jess Phillips. Electoral Dysfunction, wherever you get your podcasts.
10:30Given what happened in Southport, how candid have NHS trusts been with your investigation? Not massively, to put it lightly. I think there's kind of a train of thought that will it do the patients more harm than good to know that their records have been breached. But I think from what we've seen when you talk to the patients and the victims and the families, it's horrible. And they don't know kind of what it's being used for. Is it being used to get details to sell to the press? Is it being used for intimidation? One case we found was a potential domestic abuse case. it was kind of buried in a public document that we found that there was a staff member whose spouse was also a staff member at a hospital in a trust in leeds and had been viewing their records and it said it was part of an ongoing domestic abuse i asked the trust what happened to the alleged perpetrator and they said action was taken but no one was sacked so i think that just kind of summarises, you know, it's known to happen, but is it taken seriously?
11:42Information is power, right? So if that power is being used for coercive control, that's where the domestic abuse comes from. Essentially, family members, if you have a large family and you've fallen out with a family member and that family member works for a trust and they can access all of your medical records. It's as simple as that. It's one click and they're into your medical records. But as part of your investigation, I mean, there were NHS trusts that didn't respond. Dozens didn't respond. And their stated reason was what? Some said they didn't hold the information. Some honestly just didn't reply to their freedom of information requests.
12:20So I think we got 140 trusts. 134 trusts replied, and only 54 of those 134 said they actively looked for breaches. So whatever the figure is today that you guys have identified, the true figure is guaranteed to be significantly higher. 100%. Much, much bigger. Who then can actually see our medical records? I think most people presume that it's, you know, the GP that is sitting right in front of you when you go into that meeting. It is the consultant who is managing your care when you are on their ward. But it sounds like it might be rather broader than that. Yeah, it will be the local health network.
12:57So it won't be a trust in the north of England can share or automatically shares information with the trust in the south of England. So thankfully, it isn't that joined up yet. But the trusts are big. They'll include community practices, clinics, dentists, GPs, all of them sharing the same network in that local community. So somebody in a GP surgery will have access to medical records in a hospital and trust under that patient. The last case that was prosecuted by the ICO was a secretary who accessed over 100 records. A secretary? Yeah. Why would a secretary need to have access to someone's medical records?
13:40Is the system just set up the way it is? Blanket access to anyone and everyone because it's easier that way? Yes. So you might be in a hospital being treated by a consultant who might need to see a radiographer who then sees a community pharmacist. They will all need access, right? So this is what we've been trying to get our head around. So how do you design a system where only the medical staff who are actively treating you have access to your records. That's quite difficult to implement, right? So when we're looking at how do you make the system better, a ward sister should not be accessing medical records for somebody being treated in ICU, for example, right?
14:18But it's that open. The system is that open. Anyone like Zoe is saying this was a case of a secretary accessing medical records. Yeah, there are some systems. When we were asking kind of when was the last time you checked for an appropriate access, what audits have you taken, Some of them said they have kind of automatic software where, say, if a secretary accessed someone in a different part of the hospital, it would flag. But a lot of them don't. Some of them are looking into that more now. However, a lot of them just said, we check when we get a complaint, which, again, the onus is on the patient.
14:51And it's kind of when it gets to that point that the patient is aware that their information's been shared or they've been contacted. But the argument is, the argument from the victims is, The NHS staff who are accessing these medical records are aware that they are breaching data compliance, right? They're aware. But because they're not threatened with instant dismissal, i.e., the punishment has got to fit the crime, right? If they think they're just going to get a verbal warning, they're going to carry on doing it. Or might not get caught. Yeah, or might not get caught. There's one suggestion that every time your medical records are accessed, it should flag up on the NHS app.
15:26So Neil Paterson has his NHS app. Bing, your records have been accessed 134 times over the last five weeks, but I haven't been to hospital. There's no ongoing inquiry. Why are people accessing my medical records? But this costs money, this takes investment. You know, these are big, big changes. All of which begs the question, why on earth are people looking at other people's medical records? I mean, we talked about Jane and potential campaign of intimidation there, but that seems to be pretty unique. I mean, what have you discovered about the motivation for this sort of breach of privacy? There's such a huge range.
16:06I think Dr Kumar said, you know, it's the worst of human nature. This is Grace O'Malley-Kum. Yeah. Kind of just morbid curiosity. A lot of it, you've got staff who are accessing. We found one member of staff who'd accessed 179 records. Like, that's just being nosy. but then you've got other ones who are using it for more kind of sinister reasons you're trying to sell that information for example but i would argue that they're probably in the minority because they are they're doing it knowing that they're doing something illegal which ultimately could lead to a much bigger sanction other people you know like zoe's saying morbid curiosity but it's a huge violation it's like somebody being in your home or going through your your intimate belongings a complete stranger imagine how a burglary victim must feel you're you're violated right and that's what it is if someone's going through you know mourning a death and then finding out that somebody else is accessing their information i can't imagine what that must feel like i think a lot of the time people don't know why and that's the scary thing so you know a lot of these attack victims who know that their records have been accessed they don't know why Is it nosiness, which still isn't unacceptable, or is it sinister reasons?
17:26Where is the information commissioner's office in all of this? They're the ones who are supposed to be gatekeeping this, aren't they? So when NHS England did a really stark warning after the Nottingham Southport breaches became known and said, staff need to be aware, you could go to prison for this, you could get sacked. But does that happen? No. And there's no prosecutions that have happened. So Paul Arnold said in your interview... That's the ICO, the Information Commissioner's Office. ...that prosecutions are reserved for the most serious cases. And so much of this that we know is kind of just, you know, nosiness.
18:03It doesn't reach their threshold. So the Information Commissioner's Office, stuff has to be known, stuff has to get reported to them. But a lot of the time, there's kind of just informal conversations with the trust. I was fascinated with the ICO's role with the Southport data breach. So in that breach, the trust decided initially not to tell the victims that their data had been breached. The ICO knew about it. And I kept trying to ask, I was like, so you knew about this and you were happy with the victims not being informed? And the response was, we were happy with the information provided by the trust.
18:44so it does seem so much of this is kind of just up to the trust still. We are moving in a direction now of single patient record. Not all these disparate groups of information and data dotted around various sites. We're going to have all of our medical information in one place. Do not tell me that this is not going to happen more often if information is more easily accessible. That's the aim, that's the ambition. But this is also a potentially good moment for a reset. If you're going to introduce a countrywide system, which is what we all want, right? I don't want to go to another hospital to be told by a consultant, we can't access your records from, you know.
19:25I'll tell you this, yesterday, literally yesterday, I had to go from one part of a hospital with a hard copy of the letter that he had just written to take it to another consultant in another part of the same hospital. I'd be surprised if they're not still using fax machines as well. Look, we want technology. We want to embrace technology. We want a joined-up system because we want better care, right? Essentially, this is about the NHS providing the best care possible. But now the red flags are if it can't keep our data safe with the system it has in place already, what safeguards are there for a future system?
19:59How do you make it future-proof? How do you make it secure? But it is a good opportunity. If you're going to overhaul and redesign the NHS's software, you've got to build in these safeguards. And Zoe, what should someone do if they think for whatever reason that this has happened to them, beyond, of course, getting in touch with you two? Yeah, there's subject access requests where you can put in a request to the hospital and say, I want information about who's accessed my records. And people have said that they think that will happen a lot more now. There's that awareness, because I don't, it seemed a bit of an open secret in the NHS this was happening, but I don't know whether patients and the public knew just how much.
20:40Look, I get, I think people will be listening to this and they'll be getting annoyed and they'll be getting grumpy that, you know, personal information has been accessed. I'm not sure that everyone will immediately understand just how painful, how hurtful an act like this has been, but at least, you know, when you were speaking to Dr Kumar, I mean, he laid it bare. And I urge anyone who hasn't already to watch that interview, to see that interview, and you will see just how distressing it is for a family to learn that their loved one's information has been accessed. The thought that went through my head when I was listening to him is, why would somebody do that?
21:19For some complete stranger to pick up Grace's records and what? Discuss them with their friends and family at tea time, at dinner time, share them on a WhatsApp group? What is the point? Why do you do that? And look at the distress you cause for these families. And the worry is that if people think that, you know, people can just view anything, that it could actually stop people from being honest and frank and coming forwards. So there's that kind of risk there. This is information you might not even share with your own family. Yeah. Of course. Well, look, let's see what happens with single patient records and indeed with those NHS trusts that have yet to respond.
21:56Great work both. Zoe, Ashi, thanks very much. Thank you. That is your lot. But before we go, we have had this from NHS England. All NHS trusts are required to maintain audit logs of access to patient information as well as having controls in place to prevent and identify unauthorised access and must take action in cases where staff have abused the trust of patients by accessing personal records without good reason. Anyway, do let us know what you think. The email address, as always, why at sky.uk. We're back to more.
22:31I'm Sam Cotes. And I'm Anne McElvoy. Britain has a new Prime Minister and every day from 7.45am we'll help you make sense to the day ahead in just 20 minutes. That means taking you inside Westminster with our forensic insight, sharp analysis and the stories behind the headlines. From the battles in Parliament to the conversations shaping government. We'll set you up each morning for the day ahead in British politics. Hit follow and listen to Politics at Sam and Anne's wherever you get your podcasts.
From the publisher
Imagine your child has been the victim of a terror attack. Then imagine the most intimate details of their injuries being viewed and shared without your permission or knowledge.
A Sky News and Health Service Journal investigation has uncovered the extent to which NHS staff are accessing patients’ medical records.
High profile cases include the victims of the Nottingham and Southport attacks. But information was also accessed to carry out coercive control and domestic abuse.
Niall Paterson speaks to Sky’s health correspondent, Ashish Joshi, and Zoe Tidman – senior correspondent for the Health Service Journal.
NHS England has issued a response to the investigation, saying: “All NHS trusts are required to maintain audit logs of access to patient information as well as having controls in place to prevent and identify unauthorised access – and must take action in cases where staff have abused the trust of patients by accessing personal records without good reason.”
Have you got a question for Niall? Email us: why@sky.uk




