By Charlotte Webster-
The Department of Health in Northern Ireland is facing renewed scrutiny following confirmation that the region’s flagship digital patient records system has been affected by incidents of inappropriate access to confidential patient information, raising fresh concerns about data security and accountability across the health service.
The Encompass system, introduced as a major step forward in modernising healthcare records, was promoted as providing the highest standards of confidentiality and security for sensitive patient information. However, officials have now acknowledged that unauthorised access to patient records is suspected to have occurred across all Northern Ireland health trusts, undermining assurances given when the system was introduced.
The Department of Health has confirmed that disciplinary action may be taken against staff found to have accessed patient information without a legitimate clinical or professional reason. Investigations are underway to establish the scale of the inappropriate access, identify those responsible, and determine whether existing safeguards were breached.
The revelations have prompted questions about the effectiveness of monitoring mechanisms within the new digital records platform. While electronic health record systems are designed to improve patient care by allowing authorised clinicians to access information quickly and efficiently, they also require rigorous oversight to prevent misuse of highly sensitive personal data.
Encompass, which began its phased rollout across Northern Ireland in 2024, was presented as a transformative programme intended to replace fragmented paper-based records with a single, integrated digital system. Health officials argued that the platform would improve patient safety, enhance communication between healthcare providers, and strengthen the protection of confidential information through advanced access controls and audit capabilities.
The confirmation of suspected unauthorised access has nevertheless sparked concerns over whether those protections have been sufficient in practice. Investigators are examining audit logs and other system records to determine the extent of the breaches and whether any patient information was viewed or accessed inappropriately. The findings are expected to inform any disciplinary proceedings as well as potential changes to governance and staff training.
The latest disclosure comes at a time when the security of digital health systems is under increasing public and regulatory scrutiny. Healthcare organisations continue to balance the benefits of instant access to medical information with the responsibility to safeguard the privacy of millions of patients whose records contain some of the most sensitive personal data held by public bodies.
Health authorities have emphasised that only authorised access for legitimate clinical or operational purposes is permitted under the Encompass system, warning that any misuse of patient records constitutes a serious breach of professional standards and may result in disciplinary action. As investigations continue, there are likely to be renewed calls for greater transparency, stronger oversight and clearer assurances that patient confidentiality remains fully protected within Northern Ireland’s evolving digital healthcare infrastructure.



