Most stories about medical data being exposed involve somebody breaking in. This one does not. Every case behind England's new rule involved a member of staff who was supposed to have a login, using it to read a record that was none of their business.
The new rule
NHS England's chief executive, Sir Jim Mackey, has written to every trust ordering an immediate change: staff suspected of looking at patient records without a valid reason are to be suspended straight away and locked out of NHS computer systems, including from home. Suspicion, not proof, is now the trigger — the point being to stop further access while an investigation runs. A national campaign will remind staff what the rules are and what breaking them costs.
Mackey's framing was that patient records hold some of the most private information people ever share, that too many people have abused that trust, and that anyone who thinks they can satisfy their curiosity this way should expect to be found out, to risk their career, and possibly to end up with a criminal record.
The scale behind the announcement
An investigation by the Health Services Journal this month found that over five years at least 214 NHS staff lost their jobs and around 2,000 were sanctioned for snooping on patient data. The pattern is mundane and human rather than criminal in the usual sense: curiosity about a high-profile patient, or looking up relatives, acquaintances and ex-partners. In one 2023 case, a consultant in Cambridgeshire was investigated by the General Medical Council after accessing the health history of a woman who had started dating the doctor's ex-boyfriend.
The trigger for the crackdown was a run of high-profile incidents — records relating to the Nottingham and Southport attack victims, and to a child injured in a crocodile enclosure in Cambridgeshire. This week Bristol Foundation NHS Trust opened an internal investigation after the records of an 18-year-old were accessed years after his death. His mother, Paula McGowan, told the BBC she was deeply concerned and hurt, and called for the NHS to do more.
Why it was possible at all
There is no single NHS-wide record system everyone can reach. GP practices, hospitals and specialist clinics each keep their own records and decide who may see what — and every one of those systems keeps an audit trail showing exactly who opened a record and when. The information to catch this has always existed. What was missing was the habit of looking at it, and a consequence quick enough to matter.
That is the useful distinction between this and the FBI breach we covered this week. There, an outsider exploited a flaw in cloud software. Here, nothing was broken at all — the system worked exactly as designed, for people who had every right to log in and no right to look.
What it means in Bangladesh
Insider access is the harder problem, and Bangladesh has built almost no defence against it. Hospital information systems at public and private hospitals, the DGHS dashboards, diagnostic-centre databases and the health records attached to NID all run on the same assumption the NHS just abandoned: that a staff member with a valid login is a staff member with a valid reason. In a country where a celebrity's diagnosis or a politician's test result is a saleable commodity, that assumption is expensive.
Three things are worth doing, and none require new legislation. Turn on and retain audit logging in every hospital information system — most products already have it, switched off or overwritten weekly to save space, and a log nobody keeps is the same as no log. Run a monthly exception report instead of waiting for a complaint: same surname as the staff member, records opened outside that department's patient list, any access to a record flagged high-profile. And write the consequence into the employment contract in plain language before an incident, not after, because the deterrent in England is not the technology — it is that every member of staff now knows exactly what happens. A patient in Bangladesh currently has no way to ask who has read their file, and until they do, the honest position is that nobody is watching.




