World

NHS Trust Apologises After 10 Staff Accessed Noah Woods' Records Without Permission

Elena MarquezPublished 7d ago3 min readBased on 5 sources
Reading level
NHS Trust Apologises After 10 Staff Accessed Noah Woods' Records Without Permission
Photo by RDNE Stock project on Pexels

East Suffolk and North Essex NHS Foundation Trust has apologised after ten employees accessed the medical records of three-year-old Noah Woods without authorisation after his disappearance in Suffolk. The ten are off duty.

The trust said the ten were removed from active duty or suspended while investigations conclude, with disciplinary action being explored. It reported the access to the Information Commissioner's Office, the UK body that oversees data privacy. Deputy chief medical officer Dr Martin Mansfield is identified as the trust spokesperson in the case, according to reporting by The Guardian.

The trust said it apologised unreservedly to Noah's family for the extra anguish caused by the breach, as reported by Sky News. Its position is set out in a document titled "Media statement: Unauthorised access to patient records" published on esneft.nhs.uk. The identification of the organisation as East Suffolk and North Essex NHS Foundation Trust was reported by Express.

Noah became separated from a relative after visiting the playground in Merriam Close, Brantham, on the afternoon of 15 September. More than 1,300 members of the public joined the search. Met Police divers recovered his body from Decoy Pond on the afternoon of 16 September. He was found dead in a pond in Brantham after going missing from the playground.

Suffolk police said his death was not being treated as suspicious. An inquest heard that he escaped from the park through a gap in the fence. The inquest was opened and adjourned in Ipswich on Friday.

NHS England chief executive Sir Jim Mackey said NHS staff would be suspended immediately if found snooping on patients' records for unauthorised reasons.

The broader context here is access control in large clinical record systems. Each view leaves a trace in a log, like a library stamp, so checks can catch misuse after the event. Prevention rests on role-based permissions and deterrence. What will matter next is whether the investigation finds curiosity-driven access or further sharing, and what the regulator concludes about organisational controls.