What Happens When NHS Staff Are Suspected of Snooping on Patient Records?
This guide covers the new zero-tolerance approach to NHS staff who access patient records without a legitimate reason, what immediate suspension involves, and how the latest figures show the scale of the problem.
A zero-tolerance shift
NHS England’s chief executive, Jim Mackey, has told health trusts that staff suspected of snooping on patient records should be suspended immediately and have their access to NHS systems cut off. He urged the 205 health trusts in England to pursue what he called a “zero tolerance” approach.
The reasoning is straightforward. If someone is suspected of looking at records they have no business seeing, leaving them in post while an investigation takes days or weeks creates more risk. Mackey said the expectation now is that suspected staff are suspended and barred from using health service computers while the facts are established.
Suspension in this context is precautionary. It is not a verdict. The aim is to protect patients and preserve evidence while a fair investigation follows.
What counts as snooping
NHS records contain highly sensitive personal information, including diagnoses, prescriptions, test results, and mental health history. Staff are allowed to view them only when there is a legitimate clinical or administrative reason.
Snooping happens when someone looks at a record out of curiosity or for personal reasons, not as part of their job. That could mean checking the file of a neighbour, a colleague, a public figure, or a family member. It can also involve looking up records for gossip or voyeurism.
Because the breach is about motivation as much as access, employers need to investigate each case before deciding what happened.
What the numbers show
The problem is not hypothetical. An investigation by Sky News and the Health Service Journal found that since 2020 more than 200 NHS staff in England have been dismissed for snooping on patient records, and a further 2,000 have been sanctioned in some other way.
Health minister Gillian Merron has disclosed that health service bodies reported 1,445 cases of inappropriate access to the Information Commissioner’s Office between 2019 and 2025.
At the same time, the Information Commissioner’s Office chief executive, Paul Arnold, has said that inappropriate access is rare and does not represent the behaviour of the vast majority of healthcare staff, who take confidentiality seriously.
Together those figures suggest a persistent minority problem, not a system-wide culture of curiosity.
Why immediate action matters
Patient confidentiality is a cornerstone of NHS care. People need to trust that intimate details of their health will not be read by strangers.
Unauthorised access is also a data breach under data protection law. It can trigger regulatory action, disciplinary proceedings, and dismissal, and it damages public confidence in the health service.
The decision to suspend suspected staff immediately sends a clear signal that snooping will be treated as a serious disciplinary matter. It also puts the burden on employers to act quickly rather than letting investigations drag on while the person under suspicion still has access to records.
The approach balances two concerns: protecting patient data from the moment a concern arises, and ensuring staff are not judged before a proper investigation takes place.