NHS Data Breach Crisis Revealed as Only 400 of Almost 3,000 Cases Reached Privacy Watchdog
An investigation found wide differences in how NHS trusts monitor patient records

NHS trusts investigated 2,914 data-breach cases since 2021, but only 409 were referred to the Information Commissioner's Office (ICO), according to an investigation by Sky News and the Health Service Journal.
Only 54 of 134 NHS organisations responding to Freedom of Information requests said they routinely searched patient records for potential breaches. The finding raises questions about how consistently unauthorised access is detected across the health service.
The figures do not mean all 2,914 cases should have been reported to the ICO. Organisations must assess the risk posed by each breach before deciding whether notification is required. The findings come after high-profile cases involving NHS staff accessing records linked to victims of the Nottingham attacks, the Southport stabbings and the Bedford train crash.
NHS Trusts Vary In Monitoring Patient Records
The Sky News and HSJ investigation found that 67 per cent of the data-breach cases resulted in an informal or written warning, or no further action.
NHS systems record who has accessed patient information, allowing trusts to identify unusual or unauthorised activity. NHS England says trusts are required to maintain audit logs and have controls to prevent and identify inappropriate access.

Dr Sanjoy Kumar, whose son was killed in the 2023 Nottingham attack, warned that the NHS faces a 'tsunami' of privacy breaches unless monitoring is strengthened, according to Sky News.
A separate BBC investigation showed how one incident can affect large numbers of patients. At Somerset NHS Foundation Trust, a worker accessed records belonging to up to 200 people between 2017 and 2023 and shared a screenshot of one patient's record with their partner. The incident was reported to the ICO and police, while the worker received a conditional caution after resigning before disciplinary action.
Not Every Data Breach Must Be Reported
The 409 referrals cannot be treated as a measure of how many of the 2,914 cases should have been reported to the ICO.
Under UK data protection rules, organisations must assess whether a personal data breach is likely to pose a risk to people's rights and freedoms. Where the threshold is met, the ICO says the breach must generally be reported without undue delay and, where feasible, within 72 hours of the organisation becoming aware of it. Breaches that do not meet the reporting threshold still have to be documented.
Health information is classed as special category data because of its sensitive nature. Unauthorised access to patient records can constitute a personal data breach, requiring organisations to assess the potential risk to affected individuals.
The distinction means the investigation does not establish that NHS trusts failed to notify the ICO when legally required. However, the variation in monitoring practices indicates that trusts do not all use the same approach to identifying potential inappropriate access.
NHS Strengthens Rules On Unauthorised Access
The findings come as NHS England has increased its focus on preventing unlawful access to patient records.
Guidance issued in July warned staff that accessing medical records without a legitimate reason could lead to disciplinary action, dismissal or criminal consequences. It also called for organisations to have arrangements for monitoring access and investigating suspected unlawful activity.
The investigation highlights the difference between breaches identified by NHS organisations and those ultimately referred to the privacy regulator, while the Somerset case demonstrates how a single incident can involve records belonging to hundreds of patients.
© Copyright IBTimes 2026. All rights reserved.
























