Three sorts of people go looking in medical records they have no business in:
- Creeps. They think they know you. A date, an ex’s new partner, a neighbour, the church friends of your parents. A conversation may have been perfectly pleasant right up until they mentioned that they’d read your medical notes…
- Voyeurs. Repugnant voyeurism – something about you caught their attention…
- Ghouls. Something terrible happened to you, and they wanted to know the details…
Whichever one you may have experienced, however it felt, the rules are the same.
You aren’t alone.
The Health Service Journal has described abuse of access as “a worrying trend” that you may unwillingly have become part of. The trend has been there for decades, what’s new is finding out about it.
Patients are able to ask and find out who looked
Hospitals and GP practices log who opens which records, and when. Anyone who looks up a patient is supposed to be able to say why if they’re asked. “I wanted something to talk about on a second date” is not a valid reason. Neither is curiosity.
Accessing a record without a legitimate reason can be a criminal offence, and the Information Commissioner does prosecute. But in practice most cases never go near a court, and it’s worth knowing that in both directions. You are not setting out to ruin anybody by asking a question, there’s unlikely to be an immediate dramatic action, but what it can do is make sure that any “inappropriate access” exists on a record somewhere, and that somebody may have to account for their actions.
The NHS is, at last, is being forced to admit a problem. In July 2026 the head of NHS England told staff that looking at records out of curiosity is “wholly unacceptable, a disgraceful breach of patient trust and against the law”. That applies to your records. You do not have to be famous, or the victim of anything newsworthy, for that to apply. It’s ordinary cases that make up nearly all of the abuses that the NHS never looks into.
What actually happens. It varies enormously.
At one end, Nottingham University Hospitals dismissed 11 members of staff and took action against 14 more when more than 90 people opened the records of the victims of the 2023 attacks. Those included doctors, nurses and administrative staff, and the hospital referred people on to the professional regulators, the ICO and the police. The families had to learn about it from a newspaper. 24 actions taken out of 90 people who looked.
In the middle, prosecutions happen but tend to be modest – a former midwifery assistant who looked at 29 people’s records was fined a little over £1700.
And at the other end, nothing at all. When around ten ambulance service staff appear to have looked at the records of the Southport victims, the decision was taken not to tell the patients and not to discipline anyone. Another hospital simply covered it up. Sometimes a hospital denies any problem, but some institutions are slowly learning. Ministers offered platitudes but said nothing substantive about change.
That range is the honest picture. The cases at the good end got there because those victims would not let it drop. You can make your own choices about what’s right for you – no one else gets to decide that (including us – every patient gets to make the right decision for them).
Start with one letter
Not every organisation logs everything. Not every organisation will tell the truth the first time. Not every member of staff uses their own login. It may still be worth doing, if only so that the next person they get curious about isn’t starting from nothing.
Write to the Chief Executive of the Hospital (or care provider) and the Caldicott Guardian, and copy the National Data Guardian.
- The Chief Executive, because a letter addressed to the top of an organisation is much harder to resolve quietly than one that only ever reaches the people whose job it is to hide any problems.
- The Caldicott Guardian, whose whole role is protecting patient confidentiality inside that organisation.
- The National Data Guardian, who won’t take up your individual case, but does watch how often this is happening across the country and supports Caldicott Guardians in their work. Your letter becomes part of a national picture, and seeing that picture is how things can change.
Ask them:
- Do you record every access to patient records held on your systems? [yes/no]
- Was my record accessed in [give the month(s)]? If so, on what dates, and from where?
- Which department, team or service made each access?
- What was the legitimate reason for each of those accesses?
- If any access had no legitimate reason, what will you do about it, and when will you tell me the outcome?
If it’s true, you may want to add: “I was not receiving care from your organisation at the time, and I’m not aware of any clinical reason for anyone to have opened my record.”
We have a template letter which can be adapted.
They may try to fob you off or just ignore you
Here’s what tends to come back, and what you can say.
- “All accesses were in the course of direct care.” Ask them to set out the episode of care, and the dates it covers. If they can’t match each access to care they were actually providing, it wasn’t. One definition of doing direct care is when you’d see that person in your consultation room and understand why they’re involved.
- “We can’t tell you who accessed it – that’s their personal data.” Then ask which department.
Withholding somebody’s identity is a balancing exercise, not a blanket rule, and it has to be done properly for each piece of information. “Which team” is a very long way short of “which person” – much less weight on their side of the scales, exactly as much on yours. There is rarely a good reason not to tell you that an access came from, say, the switchboard, or a ward you have never set foot on, or the department your ex works in.
Often the department is the answer. If you’ve never been treated by that service, and your ex’s new partner works there, everyone reading this already knows what happened. Ask for it, and if they still say no, ask them to put in writing why even that is too much. Coverups hate writing things down.
- “It’s been dealt with internally.” Ask what that means. Ask whether it was reported to the ICO. Ask whether anyone was referred to a professional regulator. Ask for it in writing. Because it might just be a vague warning that was never recorded anywhere.
- You may get nothing at all.
If they don’t give you the list of who has accessed your record, then make it formal. Write again and say: “Please treat this as a specific Subject Access Request under the UK GDPR.“ Those words start a one-month clock, and if they miss it you can complain to the ICO. You lose nothing by having tried the polite version first.
A Duty of Candor is coming
From 2027 public bodies owe a statutory duty of candour under the Hillsborough Law – a legal obligation to be straight with inquiries and investigations, with criminal penalties for those who aren’t.
So it’s fair to ask, when the hospital has responded, whether the answer you’ve been given is the one they would be content to repeat to an inquiry. Organisations that were previously happy to mislead an individual are considerably less relaxed about contradicting themselves later when it has material consequences. That’ll probably not be in your case, but they don’t know that in advance. (Any hospitals or IG professionals reading this should think about their answers now).
Other regulators
The ICO – the Information Commissioner’s Office is the regulator, and the body that brings prosecutions. Worth a complaint when a hospital stalls, refuses, or gives an answer that doesn’t add up.
The General Medical Council or Nursing Midwifery Council – patients involved can refer a registered clinician yourself. The issue is confidentiality and probity: opening a record with no clinical relationship, but you will need some evidence of that access first.
But be aware: not everyone who works in the NHS is a professional with a regulator. Doctors and nurses are. Receptionists, administrators, porters, and many agency staff do not – they can resign and take a job down the road with nothing following them. That’s a real gap, and you may get dropped into it. This is why the employer and the ICO matter so much: sometimes an employment record and a report to the data regulator are the only things that will exist. The hospital, the ICO and the NHS more generally all considers the hospital the victim as it is the employer and data controller – as the patient and human victim, you are usually left in the dark.
The CQC – hospitals owe a duty of candour: they are supposed to tell you when something has gone wrong. Being kept in the dark is itself something you can report.
GP records
Your GP records, prescriptions, diagnoses, and medical notes, are becoming increasingly widely available from outside your GP practice in hospitals, pharmacies and elsewhere. If it was your GP record, the trail is usually easier to reach. Patients at some GPs can see how your record has been accessed through your practice’s online services. If not, ask the GP practice manager to check the audit log and tell you what it says about accesses from outside the practice. They can, and most will. They wont know which are legitimate, but you can help them with that.
More on how to check: https://medconfidential.org/for-patients/your-records/
Records held nationally
Your Summary Care Record can be seen from anywhere in England, and GP Connect lets organisations outside your practice into your GP record.
NHS England is the data controller for access via national systems – not your GP, not the hospital. It holds those logs. If you want to know who looked at your record through a national system, NHS England is who you ask, and you can make a Subject Access Request to it directly. (from April 2027 NHS England will become the Department of Health and the responsible individual will become the Secretary of State)
What comes back is the organisation, and the date and time. Not the person. That refusal is a choice, made centrally, and made repeatedly. It isn’t a technical limitation and it has never been properly explained. The NHS now telld its own staff that inappropriate access to records is against the law, yet the same NHS declines to give patients the one fact that would let them do anything about it. Both of those cannot be right.
Some evidence is better than none
A partial answer – a date, a department, a confirmation that somebody opened your record when nobody had any business doing so – is still more than you had, and it’s often enough for someone else to act on. If you know how someone found out something they shouldn’t have known, it means you don’t have to worry about other ways they may have known. This lack of trust in honest friends is one of the most toxic consequences of breaches of trust in these systems, and a consequence the NHS cares nothing about at all.
Patients sometimes have to ask more than once. You may have to push for things the care provider would rather not disclose, and be told no before you’re told yes. That isn’t you being difficult; it’s how these organisations operate because sometimes a coverup works (it’s why they do them). You alone get to decide how long you keep chasing answers.
If somebody has been through your medical records because they were curious about you, you are entitled to know, and you are entitled to have it taken seriously.
