Skip to main content
Least Privilege Won't Stop Your Snooping ProblemBreach & Risk Assessment
5 min readFor IT Security and Risk Teams

Least Privilege Won't Stop Your Snooping Problem

The Conventional Wisdom

Ask any healthcare IT security team how they prevent unauthorized data access, and you'll hear the same checklist: role-based access controls, multi-factor authentication, and least-privilege policies. Lock down the technical perimeter, audit the logs, and you've addressed your insider threat.

The NHS recently issued guidance following this exact playbook. After 11 staff were dismissed and 14 given warnings for unlawfully accessing records of victims of the 2023 Nottingham knife attacks, the response was predictable: implement technical controls, enforce least privilege, and flag incidents in real-time through electronic patient record systems.

It's a sensible response. It's also incomplete.

Why It's Incomplete

Technical controls don't stop curiosity. They make unauthorized access harder to execute and easier to detect, but they don't address why healthcare workers with legitimate system access choose to abuse it.

Consider the NHS incidents. These weren't external attackers breaching the perimeter. They were credentialed staff with legitimate reasons to access patient record systems. A former healthcare worker at a private London hospital attempted to access and sell the medical records of the Princess of Wales. Around 40 staff at a Cambridgeshire hospital accessed records of a seriously injured child without good reason.

In each case, the technical controls worked as designed. The staff had access. The systems granted it. The problem wasn't a misconfigured role or a missing MFA prompt. The problem was intent.

You can enforce least privilege until every nurse needs approval to view a medication list, and you'll still face the same risk: authorized users making unauthorized decisions. Monitoring catches violations after they happen. By the time your audit flags the access, the breach of patient trust has already occurred.

The Evidence

The pattern across healthcare data breaches shows that technical controls are necessary but not sufficient. The ICO's formal caution for the London hospital worker and the NHS terminations in Nottingham both followed the same sequence: legitimate access, illegitimate use, post-incident detection.

Your electronic patient record system can flag incidents in real-time, as the NHS guidance suggests. That's valuable for limiting damage. But real-time detection still means the first unauthorized access succeeds. The patient's record has been viewed. The trust has been broken. The GDPR breach has occurred, triggering your 72-Hour Notification obligation to the supervisory authority.

The NHS guidance identifies the legal consequences: staff face reporting to the ICO and police for potential criminal prosecution, loss of employment, and removal of professional accreditation. But legal deterrence assumes rational actors who weigh consequences before acting. The Nottingham incident involved 25 staff members. The Cambridgeshire case involved 40. These weren't isolated lapses in judgment. They were collective failures of professional boundaries.

When dozens of staff at a single organization make the same unauthorized access decision, your problem isn't technical architecture. It's organizational culture.

What to Do Instead

Start with the technical controls the NHS recommends. Role-based access, MFA, and least privilege are essential. But don't stop there.

Build access justification into your workflow. Before a user can view a record outside their assigned cases, require them to document the clinical reason. This isn't about creating friction for the sake of it. It's about forcing a conscious decision. The moment between "I wonder what happened" and "I'm going to look" is where you need to intervene. A justification prompt creates that pause.

Make access visible to patients. The GDPR grants data subjects the Right to be Informed about processing activities. Extend that principle to access logs. Send patients a quarterly summary of who accessed their records and why. When staff know that patients will see their name on an access list, the calculus changes. You're no longer relying on fear of getting caught. You're making the patient a stakeholder in their own data protection.

Train on scenarios, not policies. Your staff already know that unauthorized access is illegal. The NHS campaign slogan "don't let curiosity kill your career" makes that clear. What they need is practice recognizing the boundary between legitimate need and curiosity. Use case studies from actual incidents. Walk through the Nottingham scenario: a high-profile case in your community, a patient who isn't under your care, a colleague who mentions they looked at the record. What do you do?

Implement Break-Glass Access with real accountability. Emergency access overrides are necessary in healthcare. But every break-glass event should trigger an automatic review within 24 hours, not a quarterly audit. Assign a named individual to verify the clinical justification and document the outcome. If you can't justify the access to a peer reviewer the next day, you shouldn't have accessed the record.

When the Conventional Wisdom Is Right

Technical controls matter enormously when you're dealing with external threats, compromised credentials, or privilege escalation attacks. If an attacker gains access to your network, least privilege and role-based access controls limit the blast radius. MFA prevents credential stuffing. Real-time monitoring catches anomalous behavior.

The NHS has spent years focused on ransomware, supply-chain attacks like the one that hit Synnovis, and nation-state activity. That focus is appropriate. External threats target healthcare organizations precisely because patient data is, as ICO CEO Paul Arnold noted, some of the most sensitive information a person owns.

As the NHS pushes ahead with wider electronic patient record rollout and initiatives like the Federated Data Platform designed to make patient data more shareable across trusts, technical controls become even more critical. You need strong authentication, granular access policies, and comprehensive audit trails to manage data sharing at scale.

But don't confuse external threat mitigation with insider risk management. The controls that stop an attacker from moving laterally through your network won't stop a curious staff member from looking up a neighbor's record. For that, you need culture, visibility, and accountability that extends beyond your security operations center.

The NHS is right to warn staff about criminal prosecution and career consequences. They're right to mandate technical controls. They're just not addressing the harder question: why do authorized users choose to become unauthorized accessors? Until you answer that, your least-privilege policy is just documentation for the post-incident report.

You Might Also Like