Decrypted | Insights from Virtru to Unlock New Ideas

Protecting Patient Trust: How NHS Leaders Can Enforce Policy Automatically

Written by Editorial Team | Oct 5, 2026, 5:34:19 PM

"We are appalled that this happened. Unauthorised access to court files is completely unacceptable."

That's what the Ministry of Justice said after staff at His Majesty's Courts and Tribunals Service inappropriately accessed court files belonging to Southport attack victims, survivors, and their families. Not once, but across multiple staff members. Not a cyber attack or a technical failure; staff with legitimate access used it to view data they had no reason to see.

The same pattern appeared at Liverpool hospital. Nearly 50 staff members inappropriately accessed the medical records of Southport victims treated at Aintree Hospital. North West Ambulance Service launched an investigation after staff potentially accessed victim records as well.

There's a better approach. Instead of hoping people do or can  follow policy, you can embed the policy directly into the data itself. The policy enforces automatically, regardless of who accesses it or where it's stored. That fundamentally changes your position.

The Scale You're Managing, and a Near Impossible Job

There are ~1.5 million people working in the NHS. Hundreds to thousands in your trust alone. Many have legitimate access to patient records. A junior administrator needs to pull files. A consultant needs to review a case. A manager needs to check staffing schedules. A clinician needs to provide care.

You have policies. Good policies. Clear policies. But so often, you must rely on the good judgement of thousands of people, every single day, every single shift, to follow them flawlessly. And sometimes, good people make mistakes. 

Then, you face:

  • Regulatory investigation. The ICO gets involved. You file breach reports. You prove compliance if you can.

  • Reputational damage. Victims go to the press. Local media covers it. Trust in your organization drops.

  • Litigation. Affected individuals sue. You settle. You pay.

  • Staff consequences. People get dismissed. Some face criminal charges. Your organisation becomes the story, all for a moment of genuine human error or poor judgement.

And the hardest part: you knew this could happen. You had a policy, but perhaps not the tools to enforce it.

The Enforcement Challenge: Why Scale Makes It Hard

You're a good leader. Your policies are good. Your team is made of good people. You simply may not have the tools to catch every mistake or every inappropriate action.

You could be relying on enforcement after access happens. A staff member accesses a record they shouldn't. You catch it (if you catch it). You investigate. You discipline. The damage is done. The data is already viewed. The victim is already impacted.

What you actually need is enforcement before access happens. Build a system where inappropriate access simply cannot occur. Not because people are well-intentioned or compliant, but because the system doesn't allow it.

That's not a new technology problem. That's a policy enforcement problem.

Give Them Virtru: The Tool That Protects Your People and Your Patient’s Data

The solution is straightforward: embed your security rules directly into the data itself. When security lives only on your network, it stops working the moment data leaves. But when protection is embedded in each file, email, or data object your rules stay in effect everywhere the data goes: cloud services, partner organisations, personal devices, anywhere.

The real advantage: this streamlines workflows instead of slowing them down. Clinicians get instant access to what they need. The system makes smart decisions automatically, legitimate access flows smoothly, inappropriate access is blocked silently. Your staff can be more productive. Your data stays protected.

With Virtru, here's what that looks like in practice:

High-profile incident data. You know certain patient records are vulnerable to inappropriate access, perhaps victims of crime or other high-profile cases. With Virtru, the system applies automatic restrictions: only staff with documented clinical need during their shift, on managed NHS devices, can access them. A staff member tries to access outside those parameters? Access denied. The legitimate clinician who needs the record gets it instantly. No exceptions. No judgement calls. No waiting.

Accidental misshare. A clinician attaches discharge summaries to an email. They accidentally include records for another patient or additional addressees. With Virtru, the email is automatically encrypted. The clinician doesn't notice any difference in their workflow; it happens seamlessly. If sent to the wrong person, you can revoke access. The recipient tries to open it? Can't. The file is locked.

Unauthorised forwarding. A staff member shares a patient record with someone who shouldn't have it. With Virtru, you see it happen in real time. You revoke access before it's viewed. You have a complete audit trail showing exactly who did what and when.

Partner data exchange. You need to send records to social services or another NHS trust. With Virtru, the file travels encrypted. The recipient accesses it through a secure portal. No login required. No complex onboarding. When the clinical episode ends, access automatically expires. No manual revocation needed. No forgotten access lingering for months. Your partners get seamless, secure access without adding friction to care coordination.

What This Gives You

Compliance you can prove. Every access attempt, successful or denied, is logged. You have evidence showing your policy was enforced. When regulators ask, you have documented evidence. You show them the data.

Incident response that works. If a breach occurs, you don't spend days investigating. You have real-time visibility: who accessed what, when, from where. You respond in minutes, not weeks.

Staff protection. Your people have clear guardrails implemented for them. Inappropriate access becomes technically impossible; not a personal choice or a moment of weakness. Staff are less exposed to mistakes or errors of judgement, this protects your staff as much as it protects your data. 

Victim protection. Patient data stays protected. Unauthorised access doesn't happen. If something is attempted, you catch it instantly and revoke access before harm occurs.

Start Now

This isn't about perfect security. It's about not having to rely on perfect human behaviour, it’s about protecting your teams and protecting your data.

Virtru Gateway

Automatically secure sensitive data domain-wide using security rules you set—shared via email, unprotected endpoints, and SaaS apps like Salesforce and Zendesk without disrupting workflows.

Start with your highest-risk data: safeguarding records, mental health data, records tied to high-profile incidents. Protect Mark these as sensitive and set automatic access controls. Your team gains visibility. Your policy actually works without slowing down clinicians.

Virtru Email

Email is your highest-risk channel. Most clinicians we have worked with adopt it within days, it's a single-click toggle in Outlook or Gmail. No training. No disruption.

Virtru Collaborate

Enable secure collaboration on sensitive documents using Virtru Collaborate. Team members work together on protected files with real-time control over who can access, edit, or share. Revoke access instantly if someone leaves the project.

Virtru Secure Share

Sending data to partners or other trusts? Use Secure Share for encrypted, secure exchange. Access automatically expires when the clinical episode ends. No manual revocation needed.

Across all products, Virtru Control Center shows you complete visibility: who accessed what, when, from where, and every action taken. Identify people who shouldn't have access. See it all in one dashboard.

The Outcome

You move from hoping your policy is followed to knowing it's enforced.

"Completely unacceptable" was what the MOJ said about unauthorised access. They meant it. Your patients deserve the same commitment. Staff deserve clear, enforced boundaries, along with guardrails for natural mistakes, not punishment for being human. 

You deserve to lead with confidence, using tools that propel the mission of privacy and care. 

Ready to explore how this works for your organisation? Start with a conversation about your highest-risk data and current challenges. We'll identify the quickest wins and build a plan.