The situation
Real talk: your medical history is supposed to be one of the most private things about you. That’s why it’s so alarming that the family of Oliver McGowan, an 18-year-old who died at Southmead Hospital in 2016, recently discovered his digital medical files were likely accessed by NHS staff for no legitimate reason—even years after he passed away.
His mother, Paula McGowan, shared that she’s "deeply concerned and hurt" after being told at least five staff members at the Bristol Foundation NHS Trust may have snooped through Oliver’s records as recently as this year. Three nurses are currently under formal investigation, and a doctor who left the trust has self-referred to the medical regulator. Another staff member is also being looked into.
The scope of the issue
It’s not just a one-off. After the family requested an audit, they found that a massive 38 people had accessed Oliver’s records since his death, with hundreds of items viewed and dozens printed. While some of that was standard procedure for legal and coroner-related stuff, the stuff that wasn't is super sketchy. One nurse reportedly told investigators they just had a 'general interest' in the case.
This is part of a much bigger problem. A report this month found that over the last five years, at least 214 NHS staff have been fired and around 2,000 sanctioned for snooping on patient data. It's giving major breach of trust, and honestly, the vibes are off.
Why it matters
NHS England has been crystal clear: accessing patient records without a valid reason is illegal and "a disgraceful breach of patients' trust." As our data moves more and more into the cloud, experts—including Oliver's father, Tom—are calling for way tighter security to prevent staff from using their access for personal curiosity. The trust says they are taking the investigation "extremely seriously" and will hold staff accountable if misconduct is found. For families like the McGowans, though, the damage is already done.






