NHS maternity records belonging to thousands of women have been lost during what the health service describes as routine IT work, triggering a police investigation and raising serious questions about how sensitive patient information is handled across one of the world’s largest public healthcare systems.
The lost data relates to maternity services and includes information about pregnant women and new mothers, some of whom may have been receiving care for high-risk pregnancies. Police have been notified of the incident and officers are now assessing its impact, the BBC understands.
What happened
The records went missing during routine IT maintenance work at an NHS trust, according to a senior source who spoke to the BBC on condition of anonymity because they were not authorised to discuss the incident publicly. The nature of the IT work — whether it involved moving data between systems, a software update, or something else — has not been disclosed publicly, and it is not yet clear how many individual patients are affected.
What is known is that the information lost was sensitive: maternity records routinely contain details about a woman’s pregnancy, medical history, birth plan, and sometimes information about her partner or family. When that kind of data goes missing, the consequences can be deeply personal as well as clinical.
Why it matters
Patient data in the NHS is protected by law. The UK’s data protection framework, backed by sensitive health provisions in the NHS Constitution and common law duties of confidentiality, places a high bar on anyone holding that information. When records are lost — whether through accident, human error, or a technical failure — it is not just a technical glitch but a potential breach of legal and ethical obligations to the people whose information has been affected.
Maternity data is particularly sensitive. The period around pregnancy and birth is a time when many women are at their most vulnerable, and the idea that their records might be lost — or worse, accessed by someone they did not intend — can cause real distress. For some, the information involved may relate to terminations, complications, or mental health concerns they shared with their care team in confidence.
ADVERTISEMENT
There is also a wider systemic question. The NHS has spent years digitising its records, moving from paper folders to electronic patient record systems. The ambition has been to make care safer and more joined-up, but digitisation also concentrates risk: a single IT incident at one trust can expose large volumes of sensitive information very quickly. The more the NHS relies on digital systems, the more the consequences of any failure are amplified.
What happens next
Police are assessing the incident, and the Information Commissioner’s Office — the UK’s data regulator — may also become involved depending on what is found. The trust involved is likely to conduct an internal investigation, and individual patients who have been affected are expected to be notified.
For the government and the NHS, the incident lands at an awkward moment. Year after year, cybersecurity and data protection feature prominently in NHS IT strategy documents, and trusts are required to meet standards set out by NHS England and the Department of Health. Whether those standards were met in this case will be a central question for any investigation that follows.
The key thing to watch now is how quickly the trust can establish the scale of what was lost, whether the data can be recovered, and whether any of it has ended up in the wrong hands. Patients affected by the incident are likely to want answers — and those answers may take some time to emerge.
























We do not allow links of any sort in comments. No SPAM whatsoever. On topic comments only.