When the Rules for Looking Are Harder to Write Than the Rules for Storing
- 19 hours ago
- 3 min read

A junior doctor in Nottingham logs into a records system to check on a patient she is not treating, a friend of a friend, because she is worried and wants reassurance. Whether that click is a disciplinary offence, a criminal one, or simply an act of misplaced concern depends, as of this week, on a distinction NHS England has spent the past six weeks trying to draw with a precision the English language does not naturally offer. In July, chief executive Sir Jim Mackey told staff that accessing patient records out of personal curiosity was unacceptable and unlawful, warning of dismissal or prosecution. The message followed the dismissal of eleven staff at Nottingham University Hospitals for looking at the records of people killed by Valdo Calocane, a case that made the abstract principle of confidentiality feel immediate and punishable. Now, after representations from the British Medical Association, NHS England has amended its guidance, listing education, training, complaint resolution and reflective practice as legitimate grounds for access, and setting out a five-part test of purpose, necessity, proportionality, patient expectation and organisational policy.
The amendment reads as a concession to reality rather than a change of principle. A blanket deterrent aimed at snooping risks catching the ordinary business of clinical supervision, audit and teaching, all of which require staff to look at records belonging to patients they are not directly treating. NHS England's difficulty in July was not that it lacked conviction about what constitutes wrongdoing, but that it had not yet built the administrative apparatus to distinguish wrongdoing from legitimate practice at the scale the NHS actually operates. Six weeks and one BMA intervention later, it is still working that distinction out in public.
This matters well beyond the immediate question of staff discipline, because it sits underneath every claim currently being made about the future of NHS data. The Federated Data Platform, built with Palantir, has been sold to trusts and to the public on the premise that centralising and structuring patient data will make care safer and more efficient, provided the governance around who can see what is sound. The same premise underpins ambient voice technology in consultations, AI-assisted triage in the Advice and Guidance referral scheme, and every subsequent pitch from a health-tech vendor promising insight from aggregated patient records. Each of those systems depends on a working definition of legitimate access that can be encoded, audited and enforced. If NHS England needed a public U-turn to settle what counts as legitimate access for an individual clinician glancing at a single record, the confidence being extended to platforms making thousands of automated access and triage decisions a day deserves rather more scrutiny than it has so far received.
There is also a trust dimension that outlasts any one policy document. Sarah Woolnough of the King's Fund was right last month to say that patients need confidence their most sensitive information will stay private, and the Nottingham dismissals showed what happens when that confidence is broken by an individual member of staff. But confidence works in both directions. Clinicians who fear disciplinary exposure for the ordinary mechanics of training and audit will either stop doing that work properly or find informal workarounds that leave no auditable trail at all, which is a worse outcome for patient safety than the problem the original warning was meant to solve. Getting the definition of legitimate purpose right is not a bureaucratic footnote to the crackdown on snooping. It is the condition on which the crackdown can be enforced fairly and the wider data infrastructure trusted at all.
None of this diminishes the seriousness of what happened in Nottingham, or the case for firm sanctions against genuine abuse. It does suggest that NHS England arrived at its July warning with the punitive half of the policy better developed than the permissive half, and has spent August catching up. As the health service leans further into platforms that promise to manage access at industrial scale, that sequencing, deterrence first, definition second, is the pattern worth watching for next time.



