Dozens of NHS staff improperly accessed the medical records of Southport attack victims.

University Hospitals of Liverpool Group (UHLG) has been accused of a cover-up because it did not tell victims that their records had been accessed by 48 staff members without justification.

Bosses then chose not to dismiss the 48 members of staff, but instead subjected them to a range of disciplinary action from “informal counselling to a final written warning”.

Leanne Lucas, the dance teacher who survived the attack by Axel Rudakubana, said she was “devastated and horrified” by the breach of privacy.

Rudakubana murdered Alice da Silva Aguiar, nine, Elssie Dot Stancombe, seven, and Bebe King, six, at Ms Lucas’s Taylor Swift-themed dance class on July 29, 2024, and attempted to kill 10 others. Some of the injured were treated at Aintree Hospital, Liverpool.

An information-access audit carried out by the trust in the days following the incident showed 48 staff accessed the records of the victims without good reason, the Health Service Journal (HSJ) reports.

Despite the trust reporting the breach in August 2024, it did not tell the victims because of the “psychological impact”.

‘Devastated and horrified’

Ms Lucas, who organised the dance class and now campaigns against knife crime, said: “I am absolutely devastated and horrified that my privacy has been invaded when I was at my most vulnerable.

“Nothing will take away my gratitude to the staff who saved my life, but 48 people not involved in my care abused their position of trust to access the files of victims who have suffered unspeakable trauma.”

She added: “The decision to keep this from me for almost two years is a new low. I am speaking out as I want this scandal and the attempted cover-up by senior management exposed for what it is.”

Nicola Brook, a legal director at Broudie Jackson Canter, who represent three survivors including Ms Lucas at the Southport Inquiry, said the breach was “truly unbelievable”.

She added: “This is more than a few bad apples, when it was 48 different members of staff… That speaks to a culture and one that will only change if there are real consequences for those responsible.”

James Sumner, UHLG’s chief executive, said the trust had made the decision not to inform the patients involved after “taking into consideration the potential psychological impact it may have upon them at the time”.

He said: “We are sincerely sorry for any distress that may have been caused to the patients that were under our care and who trusted us to look after them when they were most vulnerable.

“Breaches of patient confidentiality are inexcusable and undermine the hard work of those teams who sought to provide the highest standard of care to these patients after they experienced such traumatic and life-changing events.

“Staff who were found to access patient records were subject to HR disciplinary processes.”

‘Fully transparent about action taken’

Mr Sumner added that the trust had “notified the relevant regulators and professional bodies”, including the Information Commissioner’s Office and was “fully transparent about any findings and actions taken”.

An ICO spokesman said: “People need to trust that their medical information is safe and only available to healthcare staff who need to use it.

“Anyone inappropriately accessing information in this way may face disciplinary action or even criminal prosecution in some cases.

“UHLG spoke with us after identifying alleged inappropriate access to medical records by staff, and we provided support to the trust as it carried out its internal investigations and disciplinary processes.

“We don’t intend to start a criminal investigation into anyone for breaking data protection law at this time but we always keep this under review should new information emerge.

“This is a wider issue across the health sector that we are working to address.”