Medical Records: Data Protection

(asked on 20th March 2026) - View Source

Question to the Department of Health and Social Care:

To ask the Secretary of State for Health and Social Care, what technical controls are in place within NHS patient record systems to prevent employees from accessing the records of family members without clinical need; and whether patients can request that named individuals be proactively blocked from accessing their records.


Answered by
Zubir Ahmed Portrait
Zubir Ahmed
Parliamentary Under-Secretary (Department of Health and Social Care)
This question was answered on 30th March 2026

There are systems and safeguards in place to keep patient information secure and confidential.

The National Health Service prioritises security and privacy in its handling of personal data. NHS systems operate Role Based Access Controls. This means only appropriate health and care staff can access the medical records they need to see to carry out their role in delivering care. Robust governance processes are required to ensure organisations comply with data protection law, and that access to personal data is necessary and appropriate.

All staff accessing systems which contain personal data are bound by their contract of employment and their professional codes of conduct.

There is currently no way to block named individuals from accessing the health records of family members. However, all access is audited and care settings can see which patient records their staff have accessed. This audit report can be used to investigate complaints or to perform proactive monitoring for inappropriate usage.

There is a policy allowing patients to request that access to their demographic record is restricted. This is to protect the location of patients who may be at risk. It ensures that information like the patient’s address cannot be easily accessed by any healthcare professional other than the patient’s general practice. Further information on this can be found at the following link:

https://digital.nhs.uk/services/personal-demographics-service/restricting-access-to-a-patients-demographic-record

Reticulating Splines