A hospital doctor in Cambridge used NHS medical records systems to access and share highly sensitive information about a woman who had started dating her ex-boyfriend, despite not being involved in her care. The victim described feeling “violated” after learning that the consultant at Addenbrooke’s hospital had viewed her GP records multiple times and relayed intimate details to her ex-partner.
The woman, who has chosen to remain anonymous, said the doctor accessed her records seven times in August and September last year, using the hospital’s Epic system and then GP Connect to read notes about a family tragedy and her children’s health. The doctor later claimed she had obtained the information from friends or acquaintances, leaving the victim and her sister fearing that close friends had betrayed them.
An audit requested by the victim revealed the unauthorised access. Addenbrooke’s initially denied that staff could access GP Connect via Epic, but later acknowledged the flaw. Dr Nicola Byrne, the NHS national data guardian for England, called the breach “absolutely unacceptable” and said it was the first such case to come to her attention, though she warned others may be occurring.
Sam Smith of health data privacy group MedConfidential described the incident as evidence of a systemic problem, stating: “If you’re registered with the NHS in England, this could happen to you.” The case has raised concerns about the security of patient data and the potential for any doctor to misuse their access for personal reasons.



