Blog

NI records inappropriate access to patient data

Northern Ireland health and social care trusts have recorded in the region of 40 incidents of unauthorised access to patients’ electronic health records (EHRs) since the the halth record system encompass went live.

A number of the cases have met the threshold for referral to the Information Commissioner.

The figures were revealed by Northern Ireland Health Minister Mike Nesbitt during a written questions session of the Assembly.

He said no breaches of UK GDPR were identified during the training phase of the Epic-based encompass system as the training environments did not contain live patient data.

However, following encompass go‑live, the five health and care trusts have reported incidents of inappropriate access to patient information on encompass.

Since encompass went live at Belfast Health and Social Care Trust in June 2024, there have been 16 documented incidents involving staff accessing patient records without appropriate authorisation or legitimate clinical reason.

The Northern Health and Social Care Trust has reported eight incidents of inappropriate access to patient data since the introduction of encompass in November 2024, and the Western Health and Social Care Trust reported two incidents of inappropriate access within the encompass system that met the threshold for referral to the Information Commissioner since the introduction of encompass in May 2025.

The encompass system went live at South Eastern Health and Social Care Trust in November 2023.

The Trust reported nine incidents of unauthorised access in 2024/25 and fewer than five incidents in 2025/26. The Southern Health and Social Care Trust has reported fewer than five incidents of unauthorised access to patient information since the introduction of encompass in May 2025.

Potential or suspected data protection incidents are not consistently recorded as a separate reporting category and may not be recorded as distinct incidents unless a breach is subsequently confirmed. 

The information was provided by individual Trusts and differences in local systems, categorisation and reporting arrangements mean that the information may not be directly comparable across organisations.

Minister Nesbitt said all incidents are subject to local investigation and, where appropriate, disciplinary action.

“In all cases where inappropriate access to patient records is identified and confirmed, incidents are investigated locally in line with established information governance procedures. Where staff are found to have accessed information inappropriately, they are subject to Trust HR processes and disciplinary action in accordance with relevant policies, up to and including dismissal,” Minister Nesbitt said.

“Where required under UK GDPR, incidents are reported to the Information Commissioner’s Office, either at the point of identification or following completion of local investigation processes.”

He said Health and Social Care organisations have a range of safeguards and controls in place to protect patient information and prevent unauthorised access to records.

These include staff contractual obligations, mandatory information governance and data protection training for staff, role-based access controls, user authentication systems, and audit logs of access to patient records.

Staff are instructed that access to records is permitted only where there is a legitimate care, administrative or business need.