---
title: Secure Clinic responds to recent NHS data breaches
description: Secure Clinic explains their response to recent NHS data breaches, and how we will keep your data safe from snoopers.
image: https://secure.clinic/hubfs/Spying.jpeg
---

[Skip to content](https://secure.clinic/blog/secure-clinic-responds-to-recent-nhs-data-breaches#main-content)

[![White logo - no background-1](https://secure.clinic/hs-fs/hubfs/White%20logo%20-%20no%20background-1.png?width=3149&height=946&name=White%20logo%20-%20no%20background-1.png)Homepage](https://secure.clinic/)

- [Features](https://secure.clinic/features)
- [Security](https://secure.clinic/security)
- [Pricing](https://secure.clinic/pricing)
- [Blog](https://secure.clinic/blog)
- [Contact Us](https://secure.clinic/contact-us)

[Get started](https://secure.clinic/get-started)

- [Features](https://secure.clinic/features)
- [Security](https://secure.clinic/security)
- [Pricing](https://secure.clinic/pricing)
- [Blog](https://secure.clinic/blog)
- [Contact Us](https://secure.clinic/contact-us)

[Get started](https://secure.clinic/get-started)

![](https://secure.clinic/hs-fs/hubfs/Spying.jpeg?width=1000&height=665&name=Spying.jpeg)

data security new feature data breaches

# Secure Clinic responds to recent NHS data breaches

![Rory](https://secure.clinic/hs-fs/hubfs/FDA6F227-2C0D-4B1A-8036-721651072235.jpg?width=48&height=48&name=FDA6F227-2C0D-4B1A-8036-721651072235.jpg)

 Rory

October 7, 2026

**Secure Clinic introduces new features to protect the data of your high profile clients.**

 

Like many people we have been troubled to read repeated recent stories of NHS staff members inappropriately accessing the medical records of high profile patients.  Whilst motivated by curiosity rather than malice, these internal data breaches have huge consequences for the affected patients, for the organisations protecting data and for the staff members in question. 

To stop your clinic being the next headline we are launching **record protection** in Secure Clinic. This can be applied to any patient that you consider high profile, restricting their data to a named group of clinicians. This article covers why we built it, and how it works.

## What's been happening in the NHS

In May 2026, Nottingham University Hospitals NHS Trust confirmed that 11 members of staff had been dismissed, and action taken against 14 more, for inappropriately accessing the medical records of Ian Coates, Grace O'Malley-Kumar and Barnaby Webber, who were killed in the 2023 Nottingham attacks. The staff involved included doctors, nurses and administrative colleagues, and the Trust informed both the ICO and the police.1

It was not an isolated case. An audit at University Hospitals of Liverpool Group found that 48 staff had accessed the records of victims of the 2024 Southport attack without good reason.2 The breach was found by a routine internal audit, the ICO was notified in August 2024, and the patients themselves were reportedly only told almost two years later.3 In June, Cambridge University Hospitals referred itself to the ICO after around 40 staff opened the record of a three-year-old boy injured in a zoo incident.4

This is not only an NHS problem. In June, the ICO cautioned a former healthcare worker at the private London Clinic, under section 170 of the Data Protection Act 2018, for deliberately misusing the Princess of Wales's records and offering to disclose them for financial gain. The ICO found no wider information security failings at the clinic, which is a reminder that a well-run organisation can still have one person act badly.5

### NHS England responds

In July, NHS England launched a national campaign warning staff that unlawful access can end in dismissal, regulator referral or prison, under the slogan "let curiosity kill your career". Its accompanying guidance asks employers to use role-based controls, to limit access to very sensitive information to those who must see it, and to use multi-factor authentication.6 In September, a further letter from the NHS England chief executive told trusts to suspend suspected snoopers immediately, and to restrict access to the relevant records when high-profile incidents occur locally.7

> Secure Clinic already protected your data with:
> 
> - Role based controls - separate administrators from clinical data.
> - Multi factor authentication - users login with their face, fingerprint or password & mobile device.
> 
> This update adds the required ability to limit very sensitive information to those who must see it.

## Why this matters to a small clinic

You might reasonably think this is a large-hospital issue. In practice, small teams have their own versions of it. A patient may be a neighbour, a local councillor, a teacher at the school your receptionist's children attend, or even one of your colleagues.  

> Secure Clinic's record protection is also an added layer of defence for those clinics handling the data of celebrities, politically exposed people and other high profile clients.

The legal position is the same whatever your size. Knowingly or recklessly obtaining personal data without the controller's consent is a criminal offence under section 170 of the Data Protection Act 2018.9 The Caldicott Principles, published by the National Data Guardian, say access to confidential information should be on a strict need-to-know basis, and specifically mention access controls as a way to achieve it.10 And UK GDPR requires appropriate security measures to protect the personal data you hold.11 A policy that says "don't look" is a start. A system that enforces it, and records what happens when someone tries, is much better evidence that you took your duties seriously.

## Introducing record protection

![Screenshot showing record protection in Secure Clinic - a user is explaining their reason for accessing a high profile user's record.](https://secure.clinic/hs-fs/hubfs/Screenshot%202026-10-07%20at%2012.50.58.png?width=1488&height=1202&name=Screenshot%202026-10-07%20at%2012.50.58.png)You can now protect any patient's record by restricting the people who are allowed to open it. Everyone else is handled in one of two ways, which you choose per record:

- **Strict:** anyone not on the list cannot open the record at all.
- **Flexible:** anyone not on the list must type a reason before they can open it. Once they have, they can open that record for the rest of their session.

Flexible mode is what hospitals call "breaking the glass". It exists because there are legitimate situations where someone outside the usual circle needs to see a record, such as covering a colleague's patient or dealing with an urgent issue. The point is that the access is deliberate, and recorded.

### Everything is logged for your clinic managers

When someone breaks the glass, the reason they typed is written to that patient's audit history, encrypted like the rest of the record.  This is available 24/7 to managers to review.  In the 2024 Southport data breach, this is how the violation was detected and stopped.

![A screenshot showing the logging of a protected records access in Secure Clinic](https://secure.clinic/hs-fs/hubfs/Screenshot%202026-10-07%20at%2012.54.22.png?width=902&height=428&name=Screenshot%202026-10-07%20at%2012.54.22.png)

### Respond in real time to breaches

You can also set up the protection to immediately email clinic managers in the event of a record being accessed via a 'break glass'.  This means that any data breach can be caught early whilst it is small and containable.

## Getting started

Record protection is available from next week.  Once you log in you will receive a notification inviting you to explore the feature.

#### References

1. Nottingham University Hospitals NHS Trust, ["Nottingham Hospitals confirms first outcomes of inappropriate access investigations"](https://www.nuh.nhs.uk/news/nottingham-hospitals-confirms-first-outcomes-of-inappropriate-access-investigations-11027); see also Local Government Lawyer, ["NHS trust dismisses 11 staff members over Nottingham attack victims' records"](https://www.localgovernmentlawyer.co.uk/employment/395-employment-news/100582-nhs-trust-dismisses-11-staff-members-over-nottingham-attack-victims-records) (21 May 2026)
2. ITV News, ["North West Ambulance Service investigating if staff accessed Southport victims records"](https://www.itv.com/news/granada/2026-07-15/ambulance-trust-investigating-if-staff-accessed-southport-victims-records) (15 July 2026)
3. BBC News, "Southport victims' medical records illegally accessed by 48 NHS staff members" (15 May 2026), summarised by [Freevacy](https://www.freevacy.com/news/bbc-news/southport-victims-medical-records-illegally-accessed-by-48-nhs-staff-members/7384)
4. ITV News Anglia, ["Investigation launched after medical records of boy hurt in crocodile pit accessed by 40 NHS staff"](https://www.itv.com/news/anglia/2026-06-26/probe-after-nhs-staff-accessed-medical-details-of-boy-hurt-in-crocodile-pit) (26 June 2026)
5. Information Commissioner's Office, "Former healthcare worker cautioned over access to Princess of Wales' medical records" (17 June 2026), summarised by [Freevacy](https://www.freevacy.com/news/ico/former-healthcare-worker-cautioned-over-access-to-princess-of-wales-medical-records/7479)
6. NHS England, ["NHS warns 'snooping' staff face sack or prison for inappropriate access of patient data"](https://www.england.nhs.uk/2026/07/snooping-staff-face-sack-prison-inappropriate-access-patient-data/) (July 2026)
7. Healthcare Leader, ["NHS staff snooping on patient records to face suspension, chief says"](https://healthcareleadernews.com/news/nhs-staff-snooping-on-patient-records-to-face-suspension-chief-says/)
8. Cybernews, ["Insider threat: NHS staff warned they'll be fired or even jailed for accessing patient records illegally"](https://cybernews.com/security/nhs-united-kingdom-staff-patient-data-access/)
9. Legislation.gov.uk, [Data Protection Act 2018, section 170: "Unlawful obtaining etc of personal data"](https://www.legislation.gov.uk/ukpga/2018/12/section/170)
10. National Data Guardian, ["The Caldicott Principles"](https://www.gov.uk/government/publications/the-caldicott-principles)
11. Information Commissioner's Office, ["Integrity and confidentiality (security)"](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/the-principles/integrity-and-confidentiality-security/)

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fsecure.clinic%2Fblog%2Fsecure-clinic-responds-to-recent-nhs-data-breaches><https://twitter.com/intent/tweet?url=https%3A%2F%2Fsecure.clinic%2Fblog%2Fsecure-clinic-responds-to-recent-nhs-data-breaches><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fsecure.clinic%2Fblog%2Fsecure-clinic-responds-to-recent-nhs-data-breaches><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Fsecure.clinic%2Fblog%2Fsecure-clinic-responds-to-recent-nhs-data-breaches>[mailto:https%3A%2F%2Fsecure.clinic%2Fblog%2Fsecure-clinic-responds-to-recent-nhs-data-breaches](mailto:https%3A%2F%2Fsecure.clinic%2Fblog%2Fsecure-clinic-responds-to-recent-nhs-data-breaches)

## Keep reading

### [![](https://secure.clinic/hs-fs/hubfs/national-cancer-institute-NFvdKIhxYlU-unsplash.jpg?width=5184&height=3456&name=national-cancer-institute-NFvdKIhxYlU-unsplash.jpg) GDPR compliance data security GDPR in plain English: What UK practitioners actually need to do](https://secure.clinic/blog/gdpr-plain-english-uk-independent-practitioners)

[![White logo - no background](https://secure.clinic/hs-fs/hubfs/White%20logo%20-%20no%20background.png?width=200&height=60&name=White%20logo%20-%20no%20background.png "White logo - no background")](https://secure.clinic/)

- [Features](https://secure.clinic/features)
- [Security](https://secure.clinic/security)
- [Product Documentation](https://help.secure.clinic/)
- [Server Status](https://status.secure.clinic/)
- [Blog](https://secure.clinic/blog)
- [Contact Us](https://secure.clinic/contact-us)
- [Privacy](https://secure.clinic/privacy)

Secure Clinic Ltd.

UK Limited Company 15050934  
71-75 Shelton Street, Covent Garden, London

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Rory",
    "url" : "https://secure.clinic/blog/author/rory"
  },
  "dateModified" : "2026-10-07T12:05:09.566Z",
  "datePublished" : "2026-10-07T12:05:09.000Z",
  "headline" : "Secure Clinic responds to recent NHS data breaches",
  "image" : [ "https://secure.clinic/hubfs/Spying.jpeg" ],
  "mainEntityOfPage" : {
    "@id" : "https://secure.clinic/blog/secure-clinic-responds-to-recent-nhs-data-breaches",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://secure.clinic/hubfs/Color%20logo%20with%20background.svg"
    },
    "name" : "Secure Clinic Ltd"
  }
}
```