Illustration of a hospital IT data loss incident in which 11 years of maternity record viewing history was erased by human error

Human Error at Nottingham NHS Trust Erases 11 Years of Maternity Record Viewing History

Created on 24 September, 2026IT News • 4 minutes read

A human error during routine IT work on a radiotherapy database copy erased 11 years of maternity record viewing history at Nottingham University Hospitals NHS Trust.

Nottingham University Hospitals NHS Trust (NUH) has confirmed the loss of 11 years of maternity record viewing history, caused by a "human error" during routine technical work while staff were creating a copy of a radiotherapy database for reporting purposes. The incident occurred on August 18 and was disclosed in a blog post published Monday.


What Nottingham University Hospitals Lost


Nottingham University Hospitals NHS Trust (NUH) has lost data covering an 11-year span of viewing history for its maternity records. The English hospital trust attributed the loss to a mistake made inside its IT department, describing it as the outcome of a "human error" during routine technical work.


According to the trust's blog post, published Monday and first spotted by The Register, the work being carried out at the time of the incident was the creation of a copy of a radiotherapy database for reporting purposes.



The incident at a glance



  • Organisation: Nottingham University Hospitals NHS Trust (NUH)

  • Data affected: viewing history for maternity records

  • Time span lost: 11 years

  • Date of incident: August 18

  • Stated cause: "human error" during routine technical work

  • Technical context: creating a copy of a radiotherapy database for reporting purposes

  • Disclosure: a blog post published Monday



Routine Work, Outsized Consequences


The trust's own framing places the failure squarely in the mundane part of IT operations rather than in anything exotic. Copying a database for reporting is a routine administrative task — the kind of job that rarely attracts scrutiny until it goes wrong.



The problem is "the result of human error" during routine technical work while "creating a copy of a radiotherapy database for reporting purposes."



That description matters because it points to a familiar pattern in healthcare IT: the most damaging data losses are frequently not the product of sophisticated intrusion, but of ordinary operational work executed without sufficient safeguards.



The Radiotherapy and Maternity Puzzle


The trust's stated cause and the affected dataset sit in different clinical domains. The error is described as occurring during work on a radiotherapy database copy, while the data lost concerns the viewing history of maternity records. The statement quoted in coverage does not explain how the two are linked.


That gap leaves several questions unanswered for anyone trying to reconstruct the blast radius of the incident:



  • Which systems stored the maternity viewing history, and how were they reachable from the radiotherapy reporting workflow?

  • Whether the viewing history was held in a shared reporting environment, a common data platform, or a copy that spanned both services.

  • Whether any portion of the 11-year span can be reconstructed from secondary logs elsewhere in the estate.

  • Whether the loss is permanent or recoverable from backups.



Why Viewing History Is Not a Minor Dataset


It is tempting to treat an access log as metadata of secondary importance. In a hospital context, that assumption is dangerous. Viewing history answers a question that clinical records themselves cannot: who looked at this record, and when.



  • Accountability: audit trails establish which staff members accessed a patient's maternity record.

  • Patient trust: maternity data is among the most sensitive categories of health information, and patients may have specific expectations about who can see it.

  • Governance and compliance: access records underpin internal investigations, information-governance reviews, and regulatory scrutiny of how health data is handled.

  • Incident response: without a reliable access history, it becomes harder to scope any potential unauthorised access, past or future.


An erased trail does not create a breach by itself — but it removes the evidence base that would be used to prove one did not occur.



The Human Layer of Health IT Security


The NUH incident is a reminder that the human operator remains the least predictable component of any system. Controls that protect against external attackers — network segmentation, perimeter defences, monitoring — do not automatically protect against an internal action performed in good faith.


The recurring lessons for IT teams operating sensitive datasets are consistent:



  • Least privilege by default: routine reporting tasks should not have the reach to delete or overwrite production history.

  • Separation of copies from source: reporting environments should be logically or physically isolated from the systems they mirror.

  • Reversibility: destructive operations should be soft-deletes with a recovery window, not immediate, irreversible writes.

  • Change discipline: even "routine" technical work on clinical databases benefits from peer review and documented rollback plans.

  • Audit the auditors: logging systems themselves need protection, because the access log is often the last line of evidence.



What Happens Next


NUH has characterised the event as human error and disclosed it publicly through its blog. The open questions now concern recovery and remediation rather than attribution: whether the 11 years of viewing history can be restored, what compensating oversight is being applied to maternity records in the meantime, and what procedural changes follow.


For other trusts and health IT operators, the value of the disclosure lies in its ordinariness. The failure did not require a novel attack technique — only a routine operation that was allowed to touch data it should not have been able to destroy.



Key Takeaways



  • NUH lost 11 years of maternity record viewing history; the trust says the cause was "human error."

  • The incident occurred on August 18 during routine technical work creating a copy of a radiotherapy database for reporting purposes.

  • The disclosure came via a trust blog post published Monday and was spotted by The Register.

  • The trust has not explained, in the quoted statement, how radiotherapy reporting work intersected with maternity access logs.

  • Access history is a governance asset, not metadata: losing it erodes the ability to audit who viewed sensitive patient records.