Insider curiosity has cost ten employees at an English hospital trust their active duties. East Suffolk and North Essex NHS Foundation Trust said the staff were removed from duty or suspended while it runs an urgent investigation into unauthorized access to the digital medical records of Noah Woods, a three-year-old who went missing in Brantham, Suffolk, on September 15 and was found dead the following day.
Dr Martin Mansfield, the trust’s deputy chief medical officer, called any unauthorized access to patient data “completely unacceptable” and said disciplinary action would follow where warranted. The trust apologized unreservedly to the family.
The disclosure lands alongside a national push. Sir Jim Mackey, chief executive of NHS England, wrote to every trust on Friday demanding stronger measures against staff who browse records out of curiosity, warning that anyone caught could lose a career and pick up a criminal record.
Snooping by insiders is one of the most persistent risks in healthcare, and it rarely needs malware. It surfaces after high-profile deaths, celebrity admissions and workplace disputes, when staff with legitimate system credentials look up records they have no clinical reason to see. Detection depends on audit logging that flags access by people outside the care team, alerts on record views tied to news events, and a culture where staff report colleagues instead of covering for them.
What providers on both sides of the Atlantic can copy
Run dormant access reviews, alert when an account opens a record outside its assigned department, and pair every sensitive-record search with a business justification prompt. The trust is supporting the family while it works out how many records were exposed and who looked at them.