top of page

Eleven years of maternity records lost, one missed setting, and why patients should hold their own copy

Writer: Maria Sergeeva
Maria Sergeeva
1 day ago
5 min read
A routine IT task at Nottingham University Hospitals overwrote a maternity database covering 2011 to 2022. Here is what happened, why it matters more at this trust than anywhere else, and what it taught us about building HDA.

On 18 August 2026, a single missed setting during routine IT work overwrote a maternity database containing 11 years of patient records. It happened at Nottingham University Hospitals NHS Trust (NUH), the trust at the centre of the largest maternity scandal in NHS history.

This story touches two things we care about at Health Data Avatar. The first is the argument I have been making for almost 10 years: patients should hold and control their own health data alongside the institutions. ALL THEIR DATA The second is something about building HDA that I don't talk about enough, which explain why, while vibecoders ship within weeks, we have been so slow and so careful.

What happened


Staff were creating a copy of a radiotherapy database for reporting purposes. They used a set of pre-written computer instructions that had previously been used for a different hospital system. One setting that should have been changed was missed, so the process ran on the maternity database instead.


The database held the records of women and babies cared for between September 2011 and November 2022 (it came from Medway, the trust's previous maternity system). The trust says it has restored the clinical information needed for care, including notes, observations and test results. Current maternity patients were not affected.


What the trust has not been able to restore is the complete history of who viewed those records. In most cases, it may now be unable to confirm whether a particular person looked at a particular woman's maternity record during those 11 years.


Nottinghamshire Police was told about the incident on 4 September and officers attended the trust on 7 September. (That is 17 days after the error, for anyone keeping count.)


Why the access history matters at this trust


In June, a landmark review found that more than 500 mothers and babies at NUH suffered potentially avoidable harm or died because of "deeply embedded systemic failures". Nottinghamshire Police is running Operation Perth, its investigation into deaths and injuries related to maternity care at Nottingham City Hospital and Queen's Medical Centre. Last year, a separate police probe into a missing data file holding the details of hundreds of maternity cases concluded that it was most likely deleted intentionally or maliciously.


So in Nottingham, the record of who looked at what belongs to the evidence trail for families who are still waiting for answers.


The police say no crime has been identified so far. They are awaiting analysis of the digital process that was used, and a copy of the database, before any further recovery attempts. The overall impact on Operation Perth is still being assessed. A missing access log is not proof that anyone viewed records improperly (and nobody has claimed it is). It does mean that if the question is ever asked, the answer may no longer exist.


The Nottingham Maternity Family Group, which represents many of the families affected by the wider scandal, called the incident "extremely unnerving". In their statement, they said families who have already endured preventable harm and bereavement should not also have to worry about the security of the records of their experiences. They added that each new incident compounds their trauma and further erodes their trust in the trust.


I keep coming back to that statement. It says in a few lines what I have been trying to explain for a decade.


It keeps happening


Nottingham is not an exception, and maternity data has been the casualty before. In December 2023, NHS England issued a national patient safety alert because the Euroking maternity system, used by at least 15 trusts, was overwriting existing records and storing and displaying safeguarding information incorrectly. The alert warned that this could lead to incorrect management of a pregnancy.


Records can also be split rather than lost. Primary Care Support England documents a real case where a patient who had recently moved was registered with a GP without anyone checking their existing NHS number, so they were given a second one. Their medical history ended up divided across two records, which led to incorrect prescriptions and delayed referrals because clinicians could not see the full picture. In another real case, a duplicate number allowed a parent to move children without social services being alerted, because the safeguarding flags were attached to the original number.


Healthcare is one of the most regulated sectors there is, and it keeps showing us that regulation does not make a system immune to data loss.


Why HDA has been so slow (and why I would do almost the same again)


Almost 1.5 years ago, we let real patients start using HDA. It was foolishly early (I knew it then and I know it now), but we wanted to build with feedback from people actually managing their health, rather than from our assumptions about them.


From that moment, every single update took longer and required extra effort. Once people started trusting us with years of their health history, we could not risk exposing it to a vulnerability or losing a single data point. HDA is privacy-first by design, which means we take full responsibility for every line of code that touches your data. That is the opposite of vibe-coded software, where nobody quite knows what is happening with the data. With a team of two, it made us slower than we wanted to be. (It is also why our beta has stayed capped at 200 testers while the waitlist keeps growing.)


Medical records are not always the source of truth


Lost audit trails and split records are institutional failures. There is a quieter failure inside the records themselves. Doctors' notes quite often contain errors, assumptions or plain medical gaslighting written down as fact. A symptom you described in detail becomes "anxiety". A medication you stopped because of side effects appears as "non-compliance".


That is why HDA lets you add context and notes to every uploaded document, and stores information with layers of connected context. Your record should hold your side of the story too.


The data belongs to the person who lives with the consequences


When an institution loses or damages a record, it files an incident report, strengthens its controls and apologises (Nottingham has done all three). The person whose records are gone, split or wrong is the one whose health may depend on them for decades: at the next pregnancy, at a child's diagnosis, or in an investigation into what went wrong. It is their data.


Only patients and carers see their health 24/7, and only they carry their history across every GP, hospital and country. That is why I believe patients should hold every piece of their health record themselves, in a complete copy that no one else's routine IT work can erase. Hospitals will still keep their records, and they should. The patient's copy is the one that doesn't depend on a setting someone forgot to change.


If you were cared for at NUH between 2011 and 2022.. You have the right to request a copy of your records from the trust. A subject access request is free in most cases, and the trust normally has one month to respond. If you have questions about Operation Perth, the police have asked families to contact the Operation Perth team directly.

And if you weren't cared for there, when did you last ask for yours?

Sources


 
 
 

Comments


Want Our News Delivered To You?

Get HDA Updates. No Spam. Unsubscribe At Any Time.

bottom of page