The Department of Health has said disciplinary action could follow after it was confirmed there has been over 40 incidents of “inappropriate access to patient information” in Northern Ireland’s new £400m digital healthcare records system.
The Encompass system promised streamlined access to patient records for medical professionals, reducing paperwork for both patients and staff and saving time and money within the health service.
Its rollout began in late 2023 after seven years of planning, and was completed across all health trust areas in the north by May of last year.
Health service documentation advising patients on the new system states staff “will only access your information on a strict ‘need to know’ basis or when they are involved in your period of care”.
It adds staff would “ensure that all personal data is treated with the highest possible levels of confidentiality”.
However, the health minister Mike Nesbitt has admitted that alleged unauthorised access has occurred across all trust areas since its introduction.
Staff at Newry’s Daisy Hill Hospital celebrate Encompass going live in the Southern Trust last year
It is the latest controversy to hit Encompass after Mr Nesbitt was forced to apologise in June when it emerged thousands of patient referral letters went missing in the system, including ‘red flag’ cases that should be treated with the highest priority.
Encompass’ £400m price tag was also reported by the Irish News as being £100m over its projected initial cost.
Responding this week to a written question from DUP MLA Paul Frew, the minister said that since ‘going live’, “HSC Trusts have reported incidents of inappropriate access to patient information on Encompass,” adding: “Not all such incidents meet the threshold for a notifiable UK GDPR breach.”
The Belfast Trust had the highest number of reported incidents of staff accessing patient records “without appropriate authorisation or legitimate clinical reason” since Encompass went live there in 2024.
In the South Eastern Trust there were nine reported incidents of unauthorised access in 2024/25 and a figure fewer than five in 2025/26.
Eight incidents were reported in the Northern Trust area, while in the Western Trust, two incidents of data being accessed “met the threshold for referral to the Information Commissioner” since Encompass was introduced in the trust in May 2025.
The Southern Trust, meanwhile, reported fewer than five incidents
The Department of Health has told the Irish News it is aware of a “small number of investigations” into suspected unauthorised access of patient data.
Health minister Mike Nesbitt has revealed details of suspected data breaches in the new Encompass system PICTURE: PA (Liam McBurney/PA)
“Any investigations will be handled by the relevant HSC Trust with potential consequent disciplinary action a matter for them consistent with their policies and procedures,” a spokesperson said.
They continued: “All HSC staff are contractually obligated to ensure that personal data is treated with the highest levels of confidentiality and staff adhere to the HSC Code of Practice and common law Duty of Confidentiality.
“Procedures are also in place to deal with any suspected data security breach. Registered health and care professionals must also comply with professional duties of conduct and are subject to regulatory authority.”
Encompass has safety features including the ability to generate reports on any inappropriate access to patient data.
It also has a “dedicated Information Governance Advisory Council”, made up of representatives from across the health service, Department of Health, patient representatives, and observers from the Information Commissioners Office.
“Considerable effort has been made to protect information and ensure those using the encompass system access only the information they require to do their work,” the spokesperson added.

