NHS staff have been warned they face immediate suspension if they are caught inappropriately accessing patient information.
NHS CEO Sir Jim Mackey wrote to NHS Trust leaders, saying: "We have seen too many cases of people abusing that trust, and enough is enough.
"If someone is suspected of snooping, we cannot leave them in post with access to patients' records while an investigation takes days or weeks.
"From now on, we will expect them to be suspended and have their access to NHS systems cut off immediately, while the facts are established."
This urgent intervention follows a Sky News investigation exposing the scale of the problem in the health service.
Southport attack survivor Leanne Lucas had her medical records inappropriately accessed and was not told by the hospital until two years after the breach.
Responding to the move, she told Sky News: "I'm really pleased to see that people in these positions have listened to us and they're taking it seriously".
She added that she would like to see more detail about the changes, and in the future there needs to be "more staff training, more accountability".
"I think suspension, whilst there's an investigation, is step number one, but there's a lot more policies and procedures that need to be looked into," she said.
"Just take my case, for example, how you deliver this information to the victim? I'm not sure what change is being done there."
In June we reported that a three-year-old who was attacked by a crocodile after being pushed into a reptile enclosure had their records inappropriately accessed by NHS staff.
We have uncovered thousands of cases investigated by NHS Trusts in the past five years, but very few are referred to the Information Commissioner's Office and most staff are given minor sanctions such as verbal or written warnings.
Sky News also revealed that staff working for the Ministry of Justice inappropriately accessed court records relating to the Southport attack, and Nottingham University Hospital's maternity data error that has wiped their ability to find out who accessed patient records between 2011 and 2022.
Read more from Sky News:
A&E overcrowding linked to deaths
NHS breaches 'the tip of the iceberg'
Victims have welcomed the intervention by NHS England but say far more still needs to be done to make sure that patients' most sensitive information can remain safe
The high-profile data breaches involving the victims and survivors of the Nottingham and Southport attacks made stark headlines, prompting Sir Jim Mackey to act.
It is a recognition that people who have been through the most harrowing nightmare are being forced to relive their ordeal again and again by NHS staff satisfying their own "morbid curiosity".
But the Sky News investigation found it was not just high-profile cases. We found thousands of cases, many involving ordinary patients.
Our research uncovered 2,914 data breach cases investigated by NHS Trusts since 2021. Of these only 409 data breach cases were referred to the ICO by NHS Trusts.
Some 67% of data breach cases in NHS Trusts result in a minor sanction such as informal, verbal or written warning or no further action.
Of the 134 who responded to our Freedom of Information requests, only 54 said they routinely looked for potential breaches.
(c) Sky News 2026: NHS staff face immediate suspension for 'snooping' on patient medical data

Glasgow City Council 'pauses' plan to fire and rehire more than 23,000 workers
Met Police should investigate itself over arrest of 'Putney pusher' suspect, watchdog says
Girl, 16, killed after being hit by taxi in London named by police
Noah Woods died after getting out of play area through 'gap in the fence', inquest hears
Man jailed for ramming tractor into Middlesbrough house in revenge attack on rival
Three jailed over trafficking stolen devices as part of UK's 'largest mobile phone smuggling network'





