Recent reports have highlighted the importance of robust information governance, strong organisational culture and effective oversight across NHS organisations. NHS England has commissioned an independent investigation following allegations that staff at a large NHS trust inappropriately accessed the medical records of victims of the 2024 Southport tragedy. The investigation will examine the circumstances surrounding the incident, the organisation’s response and whether appropriate governance processes were followed.

Protecting Patient Confidentiality

Patient confidentiality is a cornerstone of healthcare. NHS organisations hold significant volumes of sensitive personal information and must ensure access to patient records is limited to those with a legitimate clinical or operational need. While the vast majority of staff handle patient information appropriately, incidents involving unauthorised access can have serious consequences and risk undermining public trust.

Governance and Accountability

Reports suggest NHS England officials raised concerns about governance arrangements, organisational culture and the handling of communications following the incident. The case serves as a reminder of the need for strong governance frameworks and clear assurance that:

  • Information governance controls are effective.
  • Access to sensitive records is appropriately monitored.
  • Incidents are identified and escalated promptly.
  • Reporting requirements are met.
  • Lessons learned are embedded across the organisation.
Managing Information Governance Risks

Information governance is about more than technology. Organisations must also address the human and cultural factors that can contribute to inappropriate access to information.

Effective risk management should include:

  • Clear policies and procedures.
  • Regular staff training and awareness.
  • Audit trails and access monitoring.
  • Robust incident investigation processes.
  • Effective escalation and reporting arrangements.
  • Board-level oversight of information governance risks.
The Value of Independent Assurance

Independent assurance helps boards and senior leaders gain confidence that information governance arrangements are working effectively and that risks are being managed appropriately.

Internal audit can provide assurance over:

  • Information governance frameworks.
  • Data access controls.
  • Incident management processes.
  • Regulatory compliance.
  • Board reporting arrangements.
  • Organisational culture and accountability.
How TIAA Can Help

TIAA supports NHS organisations through internal audit, governance reviews, risk management and assurance services. Our healthcare specialists work with boards and executive teams to strengthen information governance controls, assess key risks and provide independent assurance that governance arrangements remain effective.

As scrutiny around data protection, transparency and accountability continues to grow, independent assurance can help organisations protect patient trust and demonstrate that appropriate safeguards are in place.

Source – Exclusive: Blindsided NHSE bosses to launch snooping probe | HSJ Local | Health Service Journal