Information Commissioner's Office
Nurse prosecuted for inappropriately accessing patient records
A former nurse at Southport and Ormskirk Hospital NHS Trust has been prosecuted for accessing patients’ medical records without authorisation.
Clare Lawson who had been a staff nurse on the hospital’s Rehabilitation Ward since October 2011 had accessed patients’ medical records outside of her role.
The Court heard that Ms Lawson had inappropriately accessed the records – including maternity and paediatric records - of five patients, 17 times.
She also accessed a further 109 records of 18 patients of which one was a child. The activity occurred between 2014 and 2016.
It was also heard that Ms Lawson made multiple accesses to the records of some of these individuals including the blood results of a friend 44 times after they had been discharged, as well as foetal scans of another patient.
She was dismissed by the Trust in September 2017 for gross misconduct and has been referred to the Nursing and Midwifery Council.
Ms Lawson, of Southport appeared before magistrates in Bootle on 24 September and admitted unlawfully obtaining and disclosing personal data, in breach of s55 of the Data Protection Act 1998. She was fined £400 and was also ordered to pay costs of £364.08 and a victim surcharge of £40.
ICO Director of Investigations, Steve Eckersley, said:
”This abuse of a position of trust has caused significant distress to a number of people. The laws on data protection are there for a reason and people have the right to know their highly sensitive personal information will be treated with appropriate privacy and respect.
“The ICO will continue to take action against those who abuse their position and potentially jeopardise the important relationship of trust and confidentiality between patients and the NHS.”
Notes to editors
- The Information Commissioner’s Office upholds information rights in the public interest, promoting openness by public bodies and data privacy for individuals.
- The ICO has specific responsibilities set out in the Data Protection Act 2018, the General Data Protection Regulation, the Freedom of Information Act 2000, Environmental Information Regulations 2004 and Privacy and Electronic Communications Regulations 2003.
- The ICO can take action to change the behaviour of organisations and individuals that collect, use and keep personal information. This includes criminal prosecution, non-criminal enforcement and audit.
- A limited number of civil and criminal enforcement cases – including this case - are still being dealt with under the provisions of the Data Protection Act 1998 because of the date the breach of the legislation occurred.
- Criminal prosecution penalties are set by the courts and not the ICO.
- To report a concern to the ICO telephone our helpline 0303 123 1113 or go to ico.org.uk/concerns.
Latest News from
Information Commissioner's Office
The ICO and the Financial Conduct Authority (FCA) sign updated Memorandum of Understanding19/02/2019 12:20:00
The ICO and the Financial Conduct Authority (FCA) have signed an updated Memorandum of Understanding.
Consultation – 'Openness by design' – our draft access to information strategy18/02/2019 09:10:00
Every year, more and more people ask us to independently review decisions made by public authorities about their requests for information under the Freedom of Information Act or the Environmental Information Regulations.
Blog: Advancing the adtech debate from a data protection perspective13/02/2019 09:10:00
Simon McDougall, Executive Director for Technology Policy and Innovation, invites adtech industry stakeholders to a fact-finding forum.
Housing developer fined for ignoring data request08/02/2019 16:20:00
Organisations have been reminded they could face a criminal prosecution if they fail to respect the public’s legal right to access their personal information.
Blog: Show you mean business by paying the Data Protection Fee08/02/2019 12:20:00
Paul Arnold, ICO Deputy Chief Executive explains to small businesses why they need to pay the data protection fee.
ICO to audit data protection practices at Leave.EU and Eldon Insurance after fining both companies for unlawful marketing messages01/02/2019 15:20:00
The Information Commissioner’s Office (ICO) has issued fines totalling £120,000 to an EU referendum campaign and an insurance company for serious breaches of electronic marketing laws and is set to review how both are complying with data protection laws.
Blog: ICO regulatory sandbox31/01/2019 13:20:00
In November the ICO published an analysis of the call for views on our proposed regulatory sandbox.
ICO celebrates the success of innovative data protection projects on Data Protection Day 201928/01/2019 15:20:00
Innovative data protection projects funded by the ICO are making a real difference to public trust and confidence in privacy issues.