Recurring concern

Unreliable authentication and attribution controls for patient-record changes

Pin Get email alerts Request correction

First reported 12 Dec 2017•Latest report 18 Jul 2024

Definition

What this concern includes

Includes failures of authentication, account-sharing prevention, session-locking, user attribution, access restriction or auditability controls where they directly affect who can access or alter patient records, including incorrect patient attribution or shared live log-ins.

Not included

  • Excludes general incompleteness, illegibility or inaccuracy of patient records where no authentication, attribution or access-control failure is identified.
  • Excludes failures to review or act on accurate records after access and authorship controls have operated reliably.
  • Excludes generic electronic-record availability, interoperability or clinical-alert failures that do not concern authentication or attribution of record changes.
  • Excludes physical access controls and non-clinical records unless the assertion specifically concerns authenticated access to and attribution of patient-record changes.
Reports
2

Distinct published reports

Individual concerns
2

A report can raise multiple concerns

Date range
2017–2024

First to latest report issue date

Stated actions
0

Described in published responses

Reports over time

Reports over time

Reports about this concern issued each year.

* 2026 is projected from reports observed to 7 Sep 2026.

Most frequent recipients

Most frequent recipients

Reports about this concern sent to each recipient.

Care Quality Commission1
East London NHS Foundation Trust1
Isle of Wight NHS Trust1
St Mary's Hospital, Isle of Wight1

Concerns and responses across reports

Only concerns grouped under this recurring concern are included. Select any concern, action or position to view the source wording.

  1. Inner North London

    AI-generated summary

    Anna Vivien Elliott · Prevention of Future Deaths report

    This summary was generated using AI from the published report. Please read the original report for the complete account.

    Report summary

    Anna Vivien Elliott, who had severe recurrent depression with psychotic features and autism spectrum disorder, was detained under the Mental Health Act after having thoughts and plans to end her life. She was found deceased in her room on 24 November 2021 after safe and supportive observations were missed and her safety plan was ended without an adequate risk assessment. Concerns included inadequate handover and staffing, missed and falsified observation records, poor record keeping, and uncertainty about the management of safety plans.

    Read the report on judiciary.uk

    Source evidence

    How this individual concern was interpreted

    PFD Monitor created a concise, searchable interpretation from the report wording shown below.

    PFD Monitor interpretation

    Failure to keep patient records accurate and correctly attributed

    Wider context from the report

    “Concern 1 There were issues with record keeping across the board. Including, a telephone call from Anna’s mother reporting concerning messages was not recorded or passed on; an entry relating to a different patient was recorded in Anna’s records; staff were sharing log on details or not logging off from their account (also raising data protection concerns); and the written handover document was inadequate, failing to record vital information. ”

    Source location

    Anna Vivien Elliott · Prevention of Future Deaths report
    Page 2 · concerns

    Open source report
  2. Isle of Wight

    AI-generated summary

    Joseph Peter Dunne · Prevention of Future Deaths report

    This summary was generated using AI from the published report. Please read the original report for the complete account.

    Report summary

    Joseph Peter Dunne, aged 58, was discharged from hospital on 14 July 2015 after presenting with pain and feeling unwell, and was later found collapsed at home on 16 July 2015. He became unresponsive while using the toilet and was pronounced dead at 3.20 p.m.; the medical cause of death was peritonitis due to a perforated duodenal ulcer. The report raises concerns about Information Governance breaches that allowed clinical records, including an abnormal D-dimer result, to be deleted or altered and not seen by treating clinicians.

    Read the report on judiciary.uk

    Source evidence

    How this individual concern was interpreted

    PFD Monitor created a concise, searchable interpretation from the report wording shown below.

    PFD Monitor interpretation

    Failure to prevent incorrectly authenticated or attributed access to and alteration of patient medical records

    Wider context from the report

    “1. I am concerned that there are clear breaches in Information Governance protocols. It is clear that there are IG issues which allow one Clinician to make entries or delete information from a patient’s medical records, when they are not correctly logged in to the database, or are doing so under a colleague’s log-in (which remains live after they've walked away from the computer terminal). Matters are compounded inasmuch as these edits are then found to be invisible to those clinicians who are actually treating the patient, and are only ascertainable when an IT audit trail is undertaken. It should not be possible for Doctor A to be able to access records made by Doctor B and to alter those medical records. ”

    Source location

    Joseph Peter Dunne · Prevention of Future Deaths report
    Page 3 · concerns

    Open source report
Back to top

Data last updated 7 September 2026