Skip to content

This Site is Intended for Healthcare Professionals Only

Search AI Powered

Latest Stories

Submit Guest Post

NHS England issues guidance on unlawful access to patient records

Healthcare professionals warned that curiosity-driven snooping is a criminal offence that can lead to prosecution, dismissal, and regulatory erasure

NHS England issues guidance on unlawful access to patient records

NHS England guidance cautions health and care staff that accessing patient records without legitimate clinical or operational need is illegal.

iStock

Key Summary

  • Accessing patient files without a clinical need is a criminal offence under UK data law.
  • Breaches can lead to police prosecution, immediate job dismissal, and loss of professional registration.
  • Viewing records remains fully permitted for direct patient care, clinical audits, and formal training.

NHS England has issued stern guidance to healthcare staff across the UK, warning that unlawfully accessing patient records out of personal curiosity or convenience is a criminal offence that can result in prosecution and end professional careers.


The guidance, titled Stopping unlawful access to records guidance for health and care professionals, clarifies the legal, ethical, and regulatory boundaries governing electronic health record systems.

With integrated electronic patient record (EPR) systems making patient data more accessible across primary, secondary, and community care, NHS England cautioned that staff must only view records when there is a clear, legitimate work purpose and they are using no more information than reasonably necessary.

Accessing records for personal reasons - such as checking medical notes of family, friends, colleagues, public figures, or past patients without a clinical need - breaches the Data Protection Act 2018 and Computer Misuse Act 1990.

The guidance warns that offenders risk employer disciplinary action, summary dismissal, regulatory sanction, and referral to the Information Commissioner’s Office (ICO) or the police.

The document also provides reassurance regarding valid, non-direct care access. Staff are permitted to access records for authorised activities including:

  • Reflective Practice: Reviewing outcomes of care in which a clinician or their team was directly involved to support mandatory professional development.
  • Clinical Audit & Governance: Accessing records to review local safety, conduct morbidity reviews, or assist medical examiners.
  • Complaints & Investigations: Evaluating records to resolve formal patient complaints or support safety investigations.
  • Supervised Training: Allowing trainees, students, and educators to access relevant cases as part of structured learning placements.

Accidental access - such as mistyping a patient identifier or system glitches - will not be treated as unlawful provided the user ceases reviewing the record immediately and notifies their IT and Information Governance teams.

What does it mean for pharmacy?

  • For Community Pharmacists & Technicians: With expanded access to GP Connect, summary care records (SCR), and shared care records under Pharmacy First and clinical services, pharmacy teams must ensure they only open patient files during active consultations, dispensing checks, or structured reviews - never for informal checks on colleagues or acquaintances.
  • For Hospital & Primary Care Network (PCN) Pharmacists: Routine clinical audits and discharge medication reconciliations remain lawful, but clinicians must adhere to local information governance procedures and refrain from following patient journeys once pharmaceutical care is formally handed over, unless required for formal reflective practice.
  • For Regulated Professionals: Professional regulators, including the General Pharmaceutical Council (GPhC), view unlawful data access as serious professional misconduct, meaning an information governance breach can trigger fitness-to-practise proceedings alongside statutory legal penalties.