News

Unauthorised access of patient records

NHS England outlines expectations for NHS organisations when staff are suspected of accessing patient records without justification.

Publication date: 25 September 2026

Today (25 September) NHS England has written a follow up letter to NHS trust leaders reinforcing a zero-tolerance approach to the unauthorised, inappropriate and unjustifiable access of confidential patient information.

In the letter, Sir Jim Mackey, chief executive officer, NHS England states that accessing patient records without a legitimate reason is unlawful, undermines patient and public trust, and will, in almost all cases, constitute gross misconduct.

Alongside the letter, guidance has been issued that advises trusts to act immediately when staff are suspected of accessing patient records without proper justification. 

The guidance has been issued by the director general for people at Department of Health and Social Care (DHSC). NHS chief people officers (CPOs) will want to review if there are implications for local HR/people policies and staff communications on this issue, alongside the other asks in the letter.

Next steps

Employers will have existing local policies and protocols for dealing with issues of misconduct and potential gross misconduct. If, in light of this guidance, a local policy or protocol needs adjusting, employers should discuss the changes with their local trade union representatives.