NHS investigation probes unauthorised access to deceased teenager’s medical records

Emily Watson, Health Editor
5 Min Read
⏱️ 4 min read

Scope of the Investigation

Three nursing staff members are currently under formal scrutiny after an initial review found no legitimate medical reason for viewing Oliver’s records. A physician who no longer works for the trust has chosen to refer himself directly to the General Medical Council, while a fourth employee is being examined separately. The trust has announced a “thorough investigation” and emphasised that reaching conclusions would be premature until all enquiries are completed.

Oliver’s Case and Its Significance

At the centre of the controversy, a mother’s heartbreak deepens as new evidence emerges that at least five Bristol Foundation NHS Trust staffers accessed her son’s medical records without proper authority shortly after his death in 2016, prompting a formal inquiry into what happened to the sensitive files. Oliver McGowan, an autistic teenager with epilepsy, died in 2016 at Southmead Hospital, a leading hospital centre in Bristol, after receiving anti‑psychotic medication that his family insisted ought not to be administered. His mother, Paula McGowan, learned that dozens of individuals—including clinicians and administrators—had gained access to his records within months of his passing, and that approximately 37 separate views occurred, with hundreds of pages inspected and several documents printed out. While the majority of access was justified by complaints, legal actions, and the coroner’s inquest, the three nursing staff members flagged because they never dealt with Oliver personally remain under investigation.

Oliver’s Case and Its Significance

Broader NHS Record Breach Landscape

Across the nation, the problem of accidental or unlawful disclosure of patient data has grown alarmingly. Last month, an investigation published by Health Services Journal revealed that 214 NHS employees had lost their jobs and roughly 2,000 had been sanctioned for inappropriate viewing of sensitive data over the previous five years alone. In July, Sir Jim Mackey, head of NHS England, delivered a stark warning that staff could face termination or even imprisonment for such breaches. The trust’s response underscores how far behind public expectations are regarding the protection of private health information.

Technical Realities Behind the Access Risks

Medical records are among the most protected forms of personal data, containing everything from laboratory results and prescription histories to detailed clinical notes and safeguarding reports. Because there is no single NHS‑wide electronic record system, individual hospitals, GP practices, and specialist clinics each manage their own repositories and decide who may see what. Under normal circumstances, professionals need quick, authorised access during emergencies, but that privilege must be exercised strictly and documented. The IT team will organise a review of current access protocols to close gaps, ensuring that any future query is routed through proper channels. Audit logs in most infrastructure should capture every view, download, and print event, providing an immutable trail for regulators and oversight bodies alike.

Technical Realities Behind the Access Risks

What’s Being Done Now

The trust has formally referred itself to the Information Commissioner’s Office, pledging full cooperation as part of its remedial measures. Professor Steve Hams, chief nursing and improvement officer, stressed that every patient and family deserves assurance that their private information will be treated with care, respect, and confidentiality. Should misconduct be confirmed, the organisation has pledged appropriate disciplinary action, which may include dismissal or criminal prosecution. Meanwhile, the trust continues to scan other cases involving former staff to determine whether their handling of Oliver’s file was truly permissible.

Why it Matters

The case of Oliver McGowan illustrates how quickly a seemingly routine request—an inquiry into a loved one’s medical history—can spiral into weeks of unauthorised exposure when institutional safeguards fail. When confidential files containing treatment details, mental health histories, and personal safeguarding notes fall into the wrong hands, the human cost is profound: families experience betrayal, patients suffer further distress, and the broader credibility of the NHS is undermined. Ensuring that records remain secure requires constant vigilance, robust governance, and accountability across every level of care delivery.

Share This Article
Emily Watson is an experienced health editor who has spent over a decade reporting on the NHS, public health policy, and medical breakthroughs. She led coverage of the COVID-19 pandemic and has developed deep expertise in healthcare systems and pharmaceutical regulation. Before joining The Update Desk, she was health correspondent for BBC News Online.
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 The Update Desk. All rights reserved.
Terms of Service Privacy Policy