New NHS guidance on unlawfully accessing patient records
NHS England Chief Executive, Sir Jim Mackey, has recently written to all trust leaders, calling on them to take a renewed and robust approach to preventing unlawful access to patient records – warning that such breaches undermine patient trust and cause unnecessary harm and distress.
New guidance for staff, information governance (IG) professionals and patients has been published, which all NHS staff need to be aware of. Non-compliance with the guidance risks disciplinary action, dismissal, professional regulatory referral and even criminal prosecution.
What guidance has been published?
Three guidance documents have been published by NHS Digital on preventing unlawful access to records – one for health and care professionals, one for IG professionals and one for patients and service users.
What does the guidance say?
The key message is that accessing patient records out of curiosity or for personal reasons is illegal and causes real harm to patients. The guidance is clear that everyone working in health and care has a professional and legal responsibility to protect people’s confidential information.
Accessing records without an appropriate and approved work reason is both unethical and illegal, and could result in disciplinary action or a referral to the staff member’s professional regulator. In some cases, breaches may be reported to the Information Commissioner’s Office (ICO) or the police, both of whom have the power to pursue a criminal prosecution.
Accessing a record by accident will not amount to unlawful access, however, any such mistakes should be reported as soon as possible.
What counts as unlawful access to patient records?
The guidance identifies several distinct types of unlawful access that NHS staff should be aware of:
1. Personal or professional curiosity
This occurs when someone views a record out of curiosity and not because they need to for their job, and may involve accessing the records of friends, family or colleagues, individuals of local or national media interest, or patients seen in the past without a valid reason.
Personal or professional curiosity is never a legitimate excuse, and whilst there may be no malicious intent, such actions are a severe breach of confidentiality, privacy and trust and will often cause significant distress for the impacted patient.
2. Unlawful access for personal use
This occurs when someone accesses records for a personal reason, which is not part of their job. A common example is when staff members access their own records to check their notes or test results, or access the records of friends or family members (with their permission) to give a second opinion on their care.
Staff may assume this is harmless, but even if the records are their own or they have the permission of the person whose records they are, this is still unlawful, because there is no legitimate professional reason to access the record. Staff wishing to access their own records should do so through the NHS App or online patient access services.
3. Unlawful access with malicious intent
In some cases, unlawful access can involve malicious intent, such as intent to cause harm, including stalking, harassment or causing distress to individuals.
4. Unlawful access for incompatible purposes
This occurs when someone is allowed to access an individual's record for one reason, for example to provide care, but then uses it for a different work task they are not permitted to use it for.
Staff who hold more than one role in an organisation must only use their access under the role and purpose that the organisation has approved, and should not use direct care access routes to support non-direct care activities, for example, complaints management, legal defence, HR or disciplinary activity. Staff should always check with their organisation before using records for a new purpose.
The legal framework
The guidance sits within a broader legal and regulatory framework.
- The UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018 include particular requirements relating to lawful processing, security, accountability and criminal offences for the unlawful obtaining of personal data.
- The Computer Misuse Act 1990 includes criminal offences for unauthorised access to computer systems, which may apply in cases of unlawful access.
- The common law duty of confidentiality requires that confidential patient information is only accessed and used where there is a valid legal basis such as consent.
- The Caldicott Principles define how confidential information should be used and accessed, including ensuring access is justified, necessary and proportionate.
- Professional and organisations standards from bodies such as the GMC and NMC also apply, including codes of conduct and professional regulatory requirements.
Preventing unlawful access
The guidance for IG professionals makes clear that culture and awareness play a key role in preventing unlawful access to records. Training, changing culture and raising awareness is likely to be a multi-team responsibility, requiring input from the Board, senior leadership, the Data Protection Officer (DPO), communications, HR and learning and development teams.
The need for strong and clear policies is emphasised, which must be shared with all staff who have access to health records. Having the right technical controls in place will also help to stop people accessing a record when they shouldn’t and can also discourage it where blocking access is not possible or practical.
Monitoring unlawful access
Staff should be under no illusions about detection. Electronic health and care record systems keep a log of who has searched and accessed which record, and audits of access are routinely carried out. Access that seems unusual or has no clear reason will be investigated. Accessing health and care records is part of a staff member's role, and there should be no expectation that this activity is private.
Furthermore, patients and service users can request information about who has accessed and contributed to their health record by making a subject access request, meaning they can review who has accessed their own record and report anything unfamiliar to the organisation for investigation.
The range of monitoring flags organisations are advised to look out for is wide, and includes a staff member accessing their own record, the record of someone who has died, an historic or long-term inactive record, multiple records with the same surname, the record of a colleague, or the record of a person related to them.
The consequences of unlawfully accessing patient records are serious
Accessing records unlawfully could lead to dismissal from employment for gross misconduct and being reported to a professional regulator. Accessing patient records out of curiosity or for personal reasons is illegal and a criminal offence – people who have done this have been prosecuted by the ICO and the police under the Data Protection Act 2018 and the Computer Misuse Act 1990. Committing such offences can result in fines and prison sentences, as well as a criminal record.
Reporting obligations
If a staff member thinks that someone has looked at a record when they should not have, the guidance directs them to report it straight away in line with organisational data breach reporting procedures. If a staff member has concerns about unlawful access to records, they should speak to their line manager, DPO, information governance team, Caldicott Guardian, safeguarding lead or a Freedom to Speak Up guardian.
Key takeaways for NHS staff on accessing patient records
- Only access patient records where there is a clear and legitimate reason connected to your role. Curiosity, however well-intentioned, is never sufficient justification.
- Do not access your own records or those of friends and family, even with their permission. Use the NHS App or online patient access services for your own records instead.
- If you hold more than one role, only use the access appropriate to the specific role and purpose your organisation has approved for the task in hand. If in doubt, check with your organisation before proceeding.
- If you access a record by mistake, report this to your organisation as soon as possible. Accidental access will not amount to unlawful access, but prompt reporting is essential.
- If you suspect a colleague has accessed records unlawfully, report it immediately in line with your organisation's data breach reporting procedures.
- Understand that audit logs are kept and access is routinely reviewed. Unusual or unexplained access will be investigated, regardless of seniority.
- In addition, if patients and service users are worried about who has looked at their records, the guidance encourages them to speak to the organisation giving them care, to contact the organisation’s Patient Advice and Liaison Service (PALS) or to speak to the organisation’s DPO, IG team or Caldicott Guardian.
- Be aware of the full range of consequences: unlawful access can lead to dismissal, referral to professional regulators, ICO enforcement, police investigation, criminal prosecution, fines and imprisonment.
Trusts have been directed by Sir Jim Mackey to disseminate the guidance to all staff and to adopt a "tough approach" where records are accessed without a legitimate reason. Investing in training and awareness remains the most effective way to ensure staff understand their obligations and the serious consequences of inappropriately accessing patient records. Browne Jacobson has a team of specialist healthcare and employment lawyers who can support your organisation with this – please do not hesitate to get in touch.
Contact
Nicola Evans
Partner
Nicola.Evans@brownejacobson.com
+44 (0)330 045 2962