Ethical Innovations: Embracing Ethics in Technology

Ethical Innovations: Embracing Ethics in Technology

Menu▾

NHS Staff Snooped on Dead Teen's Records for Years

Bristol NHS Foundation Trust has launched an investigation after discovering that the medical records of Oliver McGowan, an 18-year-old autistic man who died in 2016, were accessed hundreds of times years after his death. An audit requested by Oliver's parents found 653 instances of his records being viewed or printed, with dozens of current and former NHS staff members identified in the logs. A doctor no longer employed by the trust accessed the records without a legitimate reason in March and self-referred to the General Medical Council, while four current employees remain under investigation. Oliver's mother, Paula McGowan, condemned the unauthorised access as a horrific violation of her late son's privacy and dignity. The trust has apologised to Oliver's family for the distress caused and made a precautionary referral to the Information Commissioner's Office as enquiries continue.

The case follows other high-profile incidents where NHS staff improperly accessed the records of victims from the Nottingham and Southport attacks and a child injured in a crocodile enclosure in Cambridgeshire. An investigation by the Health Services Journal found that at least 214 NHS staff have lost their jobs and around 2,000 have been sanctioned for snooping on sensitive patient data over the past five years.

NHS England's chief executive Sir Jim Mackey has issued a zero-tolerance directive requiring all 205 health trusts in England to suspend any staff member suspected of improperly accessing patient medical records while investigations proceed. The policy mandates immediate removal of computer system access for suspected individuals, rather than allowing them to remain in position during lengthy investigations. Mackey emphasized that unauthorized access to patient records will result in job loss and potential criminal charges.

The NHS does not operate a single electronic record system accessible to all staff. Instead, individual organizations such as GP practices, hospitals, and specialist clinics maintain their own records and control who can view specific information. Audit trails within these systems are designed to track exactly who accesses a patient's records and when.

Health service bodies reported 1,445 cases of inappropriate data access to the Information Commissioner's Office between 2019 and 2025. While the Information Commissioner's Office chief executive Paul Arnold stated that inappropriate access remains rare among the vast majority of healthcare workers who maintain proper confidentiality standards, Liberal Democrat MP Layla Moran warned these numbers likely represent only a fraction of actual incidents.

The new measures include a national campaign to remind staff of their responsibilities and the serious outcomes of unlawful access to confidential data. NHS England stated that the hardline approach reflects the need to restore public confidence in the protection of patient information.

Oliver McGowan, who was autistic and had epilepsy, died after being prescribed anti-psychotic medication at Southmead Hospital in Bristol, despite warnings from his family. His parents campaigned for changes, leading to mandatory training for NHS staff on caring for patients with autism and learning disabilities. An independent review commissioned by the NHS concluded his death was potentially avoidable, though an inquest found the medication was appropriately prescribed.

Paula McGowan, who has become a patient safety campaigner, received an OBE in 2021 for her work improving care for autistic people and those with learning disabilities. She welcomed the NHS's commitment to addressing the issue but stressed that it must be followed by meaningful action, describing unauthorized access to medical records as a serious breach of trust that must carry real consequences.

Original Sources/Tags: bbc.co.uk, bbc.co.uk, channel4.com, independent.co.uk, bbc.co.uk, independent.co.uk, theguardian.com, independent.co.uk, (nhs), (bristol), (hospital), (foundation), (trust), (general), (medical), (council), (information), (office), (tom), (england), (sir), (health), (services), (nottingham), (southport), (cambridgeshire), (investigation), (records), (teenager), (access), (nursing), (inquiries), (evidence), (doctor), (case), (distress), (death), (data), (complaints), (legal), (proceedings), (inquest), (doctors), (nurses), (nurse), (files), (drugs), (patients), (disability), (shift), (digital), (platforms), (risk), (controls), (unacceptable), (disgraceful), (breach), (trust), (law), (criminal), (prosecution), (july), (warning), (prison), (breaches), (victims), (attacks), (sanctioned), (patient)

Real Value Analysis

The article offers no actionable information for a normal person. It reports a specific investigation into past data breaches at one hospital trust but provides no steps a reader can take to protect their own data, check whether their records have been accessed, or file a complaint. The resources mentioned, such as the Information Commissioner’s Office and the General Medical Council, are real, but the article does not explain how an ordinary patient would contact them or what to expect from the process. There is nothing a reader can do or try based on this story alone.

The article lacks educational depth. It presents surface facts about who accessed the records, how many items were viewed, and which staff are under investigation, but it does not explain the systems that allowed the access, the legal definition of a legitimate reason, or how NHS audit trails work. The statistics cited, such as the 38 people who accessed the data or the 214 staff dismissed nationally over five years, appear without context about how those numbers were gathered or what they represent as a proportion of total staff. The reasoning behind the breach and the safeguards that failed are not explored, so the reader learns what happened but not why or how to prevent it.

Personal relevance is limited for most readers. The case concerns a specific teenager who died in 2016 and a particular trust in Bristol. While patient data privacy affects everyone who uses the NHS, the article does not connect the events to the reader’s own situation. It does not explain what rights a patient has over their records, how to request an access log, or what to do if they suspect misuse. The information remains distant and tied to a rare, high‑profile case rather than everyday health decisions.

The article does not serve a strong public service function. It informs the public that a breach occurred and that authorities are responding, which is a basic watchdog role, but it offers no safety guidance, no warning signs to watch for, and no instructions for responsible action. It recounts a story without providing context that would help the public act, such as how to complain about a trust’s data handling or how to verify that a hospital has improved its controls. The piece exists mainly to report the event rather than to equip the reader.

No practical advice is given. The article contains no steps, tips, or recommendations that an ordinary reader could follow. Even if it had included advice, such as checking your own record access history, the NHS does not currently provide a simple self‑service tool for that, so the guidance would be unrealistic for most people. The absence of any actionable suggestion means the reader cannot apply the information to their own life.

Long‑term impact is absent. The article focuses on a short‑lived news event and a historical case. It does not help a person plan ahead, improve habits, or avoid future problems. There is no discussion of systemic changes being made, no timeline for reforms, and no way for the reader to track whether the trust implements better controls. The benefit ends when the story is read.

Emotionally, the article may create worry or helplessness about the security of personal health data without offering a constructive response. The language describing the parents’ distress and the use of words like “snooping” and “disgraceful” can amplify fear that records are vulnerable, but the piece provides no calm perspective or practical way to channel that concern. It risks leaving the reader feeling exposed rather than informed.

The language is largely factual and not driven by clickbait tactics. It avoids exaggerated headlines or repeated dramatic claims. However, the word “snooping” in the final paragraph frames a serious legal violation as casual curiosity, which slightly sensationalizes the behavior and may downplay the criminal nature of the offense. The article does not overpromise or rely on shock to maintain attention, but it also does not use its platform to educate.

The article misses several chances to teach or guide. It presents a clear problem — unauthorized access to sensitive records — but fails to provide steps for patients to protect themselves, examples of how to request an audit trail, context about data protection rights under UK law, or a way for the reader to learn more about NHS data governance. A person who wants to understand the issue better could compare independent accounts from the Health Services Journal, the ICO, and patient advocacy groups, examine patterns in how trusts report breaches, and consider general principles of data minimization and consent. These approaches rely on basic reasoning and publicly available information rather than on any single source.

To protect your own health data in any system, start by asking your provider what access controls are in place and whether you can receive a log of who has viewed your record. If a breach is reported, request written confirmation of what data was involved and what remedial steps are being taken. Keep a personal record of key medical decisions and medications so you can spot inconsistencies if records are altered or misused. When choosing a healthcare provider, consider their history of data incidents and whether they publish transparency reports. Build a simple contingency plan by knowing how to contact the relevant regulator — in the UK, the Information Commissioner’s Office — and what information you need to submit a complaint. Universal safety principles apply: limit the personal information you share to what is necessary, verify the identity of anyone requesting health data, and regularly review permissions on any digital health apps or portals you use. These habits reduce risk regardless of the specific institution involved.

Bias analysis

The text says staff "may have viewed his records inappropriately." The phrase "may have" casts doubt on whether the access happened at all. The word "inappropriately" is vague and does not name the wrongdoing as a violation or a crime. This wording helps the trust by making the breach sound uncertain and less serious.

The trust said it is "deeply sorry for any distress caused." The phrase "for any distress" does not apologize for the act of looking at the records. It apologizes only for the feelings that resulted. This wording helps the trust look caring while it avoids admitting fault for the breach itself.

The text says "Three nursing staff are now under formal investigation." This passive voice hides who started the investigation. It does not say if the trust, the police, or a regulator ordered it. The text also says a case "is being reviewed separately." This passive voice hides who is doing the review. These choices help the trust avoid naming the authority that is holding it to account.

The final paragraph uses the word "snooping" to describe staff accessing data. This word suggests idle curiosity rather than a serious abuse of power. It frames a legal violation as a minor act of nosiness. This wording helps minimize the crime and makes the staff actions sound less malicious than they are.

The text states "Most access was appropriate and linked to complaints, legal proceedings and the coroner’s inquest." The word "most" minimizes the number of improper views by comparing them to a larger group of proper ones. It does not say who decided what counts as appropriate. This framing helps the trust make the breach look smaller and more controlled than the raw numbers suggest.

The text reports "One nurse reportedly wanted to view the files out of a general interest." The word "reportedly" turns a serious allegation into an unconfirmed rumor. The phrase "general interest" makes a privacy violation sound like harmless curiosity. This wording helps the nurse by providing a benign motive that the text does not prove.

NHS England calls the breach "wholly unacceptable, a disgraceful breach of patients’ trust." These are strong moral words. But the spokesman then says staff "could face" discipline or prosecution. The phrase "could face" reveals that no action is certain. The gap between the harsh language and the weak promise helps NHS England look tough without committing to real consequences.

The text cites "at least two hundred fourteen" staff fired and "around two thousand" sanctioned. The phrases "at least" and "around" show the numbers are estimates. The text presents these rough figures as solid proof of a pattern. This use of imprecise data helps the story look authoritative while hiding the uncertainty of the count.

Tom McGowan warns that "the shift to digital, cloud‑based platforms has increased the risk of unauthorised access." This claim blames the technology for the human choice to open a file. It suggests the system made the breach inevitable. This framing helps the trust by moving responsibility away from the managers who set the access controls.

The trust says it "voluntarily referred itself to the Information Commissioner’s Office." The word "voluntarily" makes a legal duty sound like a generous choice. It hides the fact that the trust likely had no option but to report the breach. This wording helps the trust look transparent and proactive rather than forced to comply.

Emotion Resonance Analysis

The text carries a heavy mix of emotions that shape how the reader understands the story. Sadness is the strongest feeling, shown through the death of Oliver McGowan, an autistic teenager who died after being given medicine his family warned against. The sadness grows deeper when his mother, Paula McGowan, says she is deeply hurt and deeply disappointed, because private family details about her son were seen by people who had no right to look. This sadness helps the reader feel how much pain the family is in and makes the breach of records feel more serious than just a small mistake.

Anger also appears, especially in the words used to describe what happened. The phrase “wholly unacceptable, a disgraceful breach” shows anger from NHS England, and the warning that staff could be sacked or sent to prison adds more anger. The word “snooping” makes the staff actions sound sneaky and wrong, which makes the reader feel upset. This anger pushes the reader to agree that the actions were bad and that punishment is needed.

Fear is another emotion that shows up. Tom McGowan warns that digital and cloud-based systems have increased the risk of unauthorized access, which makes the reader worried about their own medical records. The idea that so many people accessed Oliver’s data, with six hundred thirty seven items viewed and sixty seven printed, creates fear that this could happen to anyone. This fear helps the reader understand why tighter controls are needed and why the issue matters beyond just one family.

Disappointment is clear in Paula McGowan’s words. She says she is deeply disappointed, which shows that she trusted the hospital to protect her son’s information, and that trust was broken. This disappointment helps the reader see the betrayal of trust and makes the story feel personal, not just a news report.

Pride appears in a small way when the trust says it voluntarily referred itself to the Information Commissioner’s Office. The word “voluntarily” tries to show pride in doing the right thing, but it also sounds like the trust is trying to look good instead of just following the law. This pride is meant to help the trust seem responsible, but it can also make the reader feel that the trust is hiding behind words.

Guilt is hidden in the text too. The trust says it is deeply sorry for any distress caused, which tries to show guilt without saying it did something wrong. The phrase “for any distress” makes the apology sound soft, as if the trust is sorry for feelings but not for the act itself. This guilt helps the trust look sorry, but it also makes the reader feel that the apology is not strong enough.

The writer uses special tools to make these emotions stronger. Repeating words like “deeply sorry” and “deeply hurt” makes the feelings feel bigger. Telling the personal story of Oliver and his parents makes the reader care more about the issue. Comparing the case to other high-profile incidents, like the Nottingham and Southport attacks, makes the problem seem wider and more serious. Making the punishment sound extreme, with words like “sack” and “prison,” makes the reader feel that the actions were very bad.

These emotions guide the reader’s reaction by creating sympathy for the family, causing worry about data safety, building a sense of trust in the need for change, and inspiring action to fix the problem. The sadness and anger make the reader feel that the breach was wrong, the fear makes the reader worry about their own records, and the disappointment makes the reader feel that trust was broken. Together, these feelings push the reader to agree that the system needs to change and that staff who break the rules should be punished.

Cookie settings
X
This site uses cookies to offer you a better browsing experience.
You can accept them all, or choose the kinds of cookies you are happy to allow.
Privacy settings
Choose which cookies you wish to allow while you browse this website. Please note that some cookies cannot be turned off, because without them the website would not function.
Essential
To prevent spam this site uses Google Recaptcha in its contact forms.

This site may also use cookies for ecommerce and payment systems which are essential for the website to function properly.
Google Services
This site uses cookies from Google to access data such as the pages you visit and your IP address. Google services on this website may include:

- Google Maps
Data Driven
This site may use cookies to record visitor behavior, monitor ad conversions, and create audiences, including from:

- Google Analytics
- Google Ads conversion tracking
- Facebook (Meta Pixel)