NHS Tayside Probes Unauthorized Record Access
A Scottish health trust is investigating reports that staff improperly accessed the medical files of a recently deceased child.
A high-profile investigation is underway at NHS Tayside following reports of an internal data breach involving the medical records of a nine-year-old girl. The incident centers on activity at Ninewells Hospital in Dundee, where allegations suggest that staff members may have viewed sensitive patient files without a legitimate clinical justification or professional requirement.
Unauthorized Access at Ninewells Hospital
The investigation was initiated after the child, identified as Minnie Merriman, was named publicly for the first time on Wednesday. The disclosure of her identity followed a legal proceeding involving a 35-year-old man who was charged in connection with her death. Reports indicate that the potential breach occurred within a clinical environment where hospital personnel typically interact with patient data systems.
Governance and Reporting Protocols
NHS Tayside has acknowledged the situation, stating that it is reviewing the circumstances surrounding the alleged unauthorized viewing of the records. The organization maintains strict protocols regarding the handling of patient information, which is protected by the Data Protection Act 2018 and broader common law confidentiality requirements.
NHS Tayside is currently investigating the circumstances of an alleged data breach which happened in a working clinical area where staff access patient information. As a matter of governance, any data protection breach would be recorded and investigated by NHS Tayside and, where appropriate, reported to the Information Commissioner’s Office (ICO). It would not be appropriate for us to comment further on individual staffing matters.
— A spokesperson for NHS Tayside
Legal Context of the Incident
The investigation follows a tragic event that began on August 3, 2026. Police Scotland reported that Minnie Merriman was discovered with serious injuries at the Elliot Industrial Estate at approximately 0002 hours. She was transported to Ninewells Hospital, where she subsequently died. A 35-year-old man, who police noted was known to the child, appeared at Forfar Sheriff Court on August 5, where he was remanded in custody without entering a plea.
Data Protection Standards
Under current regulations, including the confidentiality standards mandated for the NHS, staff access is strictly limited to cases where there is a clear work-related or clinical necessity. The trust has not disclosed specific details regarding the volume or nature of the records accessed, nor have they provided information regarding the specific staff members involved.
Implications for Patient Privacy
This incident underscores the persistent challenge of maintaining data integrity within large, complex healthcare organizations. For patients and their families, the unauthorized access of medical records represents a significant violation of trust and privacy, particularly during periods of extreme vulnerability. As healthcare trusts increasingly rely on centralized digital record systems, the ability to monitor and audit internal access becomes critical to preventing misuse by those with authorized system credentials.
Sources
- The Register Original source
- confidentiality Also reporting
Continue Reading
Mac Crypto Drainer Uses ClickFix Tactics
A newly identified Go-based malware targets macOS users by leveraging social engineering to steal credentials and crypto assets.
Ransomware Operations Surge in July
Ransomware incident counts climbed in July as attackers shifted focus toward financial, technology, and healthcare sectors.
H1 2026 Attack Chains Bypass Trust
Recent investigations reveal how attackers leverage legitimate accounts and blockchain data to execute sophisticated financial fraud.