[If you’ve seen media coverage and want to help in knowing out how to see who’s been creeping on your records, we have a page to help you find out]
NHS England has changed its mind, and decided you’ll still be in the dark about what one victim called “repugnant voyeurism” into your medical notes. Ministers promised you’d control your data; what was announced with such fanfare as protecting patients has quietly become its opposite. Promises keep getting broken.
The guidance that is supposed to stop unlawful access now gives creeps, voyeurs and ghouls more excuses to look. Easier for them to look, easier for hospitals to cover it up, and not at all easier for you to know anything happened.
The “illegal snooping” problem (for which the official euphemism is “inappropriate access”), if anything, has worsened – and the institutional instinct to cover it up is now well evidenced. Hospital staff with no reason to look accessed the records of terrorism victims in Nottingham and in Southport; in the Southport case the trust concealed it until journalists found the paperwork — after the Public Inquiry had closed, and without telling the Inquiry. A stalker working at Addenbrooke’s read the GP notes of their victim. Creepy single doctors look up the records of women they date.
The one person who is in all the appointments is the patient themselves. The hospital and national NHS have incomplete information; the creeps exploit the gap that a patient-visible audit trail would close. Much of the complexity and justification can be removed with a simple question: if the patient could see everywhere their record was accessed in the App, would this explanation be entirely reasonable to them? Would they still have creeped knowing the patient would see the access? The remedy is not complicated: show patients who has accessed their record.
That a surgeon can, in legitimate cases, clinically audit how their surgeries turned out over time is what separates a learning system from the Bristol heart scandal. But it needs to be reasonable, and patients shouldn’t have to share their full medical notes with a doctor they’ll never see again solely because the doctor wants to take a look.
If someone wearing an NHS badge with their name and job role couldn’t sit next to your hospital bed and explain what they were doing with access to your record and why, and you’d let them carry on, then it should be no different at the far end of a computer screen. The new guidance is now too wide because the creeps hid between the honest staff and NHS England has no way to tell the difference.
Not all the criticism of the versions is fair – the argument that a patient campaigning for better care for others has no right to privacy from any staff in the NHS working on that topic seems creepily close to the inappropriate behaviour the guidance was designed to ban. Sometimes creeps doth object too much.
In effect the new guidance is about giving more power to the Department of Health in England and no information to patients. Transparency would empower patients and disempower NHS England’s meeting rooms, so of course they blanket refuse to do anything that helps patients. As long as NHSE refuses to show patients that audit trail, NHSE can just send bullying letters to hospitals and claim their job is done. In 2024 the Department of Health in England considered informing patients and decided against, recording at item 6.7.4 of the National Data Guardian’s annual report that it would be too “technically and legally” complex (but the tech can do it already).
medConfidential expected NHSE would have handled all the complexities – complexities they’d have known about if they had cared enough about patients or doctors to seek external input (either time). The contrast and disconnect are vast to those who provide direct care to patients (and the patients themselves). None of the tensions can be resolved via a diktat emerging from a Gray meeting room which cares more about covering up past its own missteps than about helping patients or the front line. When writing the original guidance, the soon-to-be-abolished NHSE failed to think about how hospitals and doctors actually work, and didn’t bother to write any of the details down. As Gill Kernick puts it in her exploration of the systemic failures behind Grenfell: “‘The point is not to see where people went wrong, but [to see] why what they did made sense’… Without this perspective, we cannot learn.” DH/E does not wish to learn.
Abstract guidance on patient notes, or any other data, will mirror the abstract legalese of cuckooland until each patient can see the evidence base of who read their notes. Patients should be able to see accesses in the NHS App, especially for national services which are controlled by the same organisation that runs the app. The vast swathe of abuses of national systems remains almost entirely hidden because NHS England refuses to help patients at every turn. Responsibility for this lies with the leadership of the “Privacy, Transparency, and Trust” directorate (which delivers on zero of the three).
Parts of the guidance may have been better in one version or the other. When the process has the rigour of a chimp with a dartboard, “they can hit bullseye” is not a defence of a process – it’s simply an admission there isn’t one.
They expect to continue to make similar decisions about how your Single Palantir Record can be used – however they want, keeping you in the dark – satisfying the Department of Health in England’s politics of the hour, not serving NHS patients.
===
Find out what happens next: Sign up for our newsletter (we don’t email often) or get small frequent updates via Substack — free to follow, and we are grateful to all those who can donate to help more of this work.
