NUH’s account identifies a missed setting in reused computer instructions as the cause. BBC News also reports that the maternity database was overwritten during routine technical work after a setting that should have been changed was missed. That reporting supports the basic sequence, although it does not constitute an independent technical investigation of the failure.
The incident offers a concrete reason to examine two separate parts of database administration: how a maintenance process establishes its target before execution, and what an organization actually means when it declares information recovered.
NUH’s Medway overwrite began with a missed target setting
The intended task was to create a copy of a radiotherapy database for reporting. Staff used pre-written computer instructions that had previously been used for a different hospital system. According to NUH, a setting needed to be changed before the process ran, but that change was missed.
The process consequently ran against the maternity database rather than the radiotherapy database, overwriting it. The Nottingham Post reports the same explanation, explicitly attributing the account of the missed setting and wrong database to the Trust.
The published explanation establishes the immediate cause, but it does not disclose the instructions, the setting’s name, or the database operation that performed the overwrite. It would therefore be premature to describe this as a particular scripting error, a defective database command, or a failure of a named software product. Medway identifies the previous maternity system in NUH’s account; it does not establish the underlying database engine or operating system.
NUH describes the incident as human error during a routine technical task. That is an explanation of the initiating mistake, rather than a complete account of the surrounding safeguards. The public statement does not identify what permissions, approvals, target checks, or recovery protections existed before the operation.
The supported administrative lesson is narrower and more useful than blaming automation generally: a reused procedure’s target is part of its correctness. Instructions that were suitable for one hospital system were unsafe for this task without a configuration change. Previous successful use did not establish that the next execution would affect the intended database.
Restored clinical information does not mean Medway was fully restored
The affected database contained maternity information relating to women and babies who received care between September 2011 and November 2022. It was the Trust’s previous maternity database, rather than its current maternity system.
NUH says testing has shown that the information needed to support patient care has been restored. It specifically identifies clinical notes, observations, test results, and other information recorded as part of a person’s care. That assurance should accompany any description of the overwrite: reporting the incident simply as the permanent loss of 11 years of maternity records would misrepresent the recovery outcome.
The unresolved loss concerns the history showing who viewed those records. NUH says it has not restored that history completely and may, in most cases, be unable to confirm whether a particular person viewed a maternity record between September 2011 and November 2022.
These are different kinds of information with different uses:
| Information | Status described by NUH | Practical consequence |
|---|---|---|
| Historical clinical information needed for patient care | Restored, based on the Trust’s testing to date | Notes, observations, test results, and other care information remain available. |
| Historical records of who viewed maternity information | Not completely restored | In most cases, the Trust may be unable to confirm whether a particular person viewed a record during the affected period. |
| Information about current maternity patients | Not affected | NUH says current maternity care has not been affected. |
An access audit trail records viewing activity. Its purpose differs from that of the clinical information being viewed: one describes a person’s care, while the other helps establish who accessed the record. Restoring the first does not recreate the second.
NUH says it worked with external specialists and examined other sources of information to recover as much data as possible. The statement does not explain the backup architecture or why the remaining history could not be fully recovered. It consequently provides no basis for claiming that backups were absent, that a particular backup product failed, or that audit information was deliberately excluded from protection.
For administrators, the recovery result suggests a specific review question: does a restoration exercise validate access history separately from the main records? That is an inference from the differing outcomes here, not a finding about how NUH previously tested its recovery arrangements.
Missing Medway access history limits accountability without proving misuse
NUH states that no patient information was accessed or used inappropriately as a result of this incident. The published account describes an accidental overwrite, not a cyberattack or an unauthorized-access event.
That statement has a particular scope. It concerns inappropriate access arising from the overwrite incident; it does not resolve every possible question about who viewed historical maternity records. The Trust’s separate warning is that the incomplete history may prevent it from answering those retrospective questions.
The loss of an access record is not evidence that someone improperly viewed the associated clinical information. Equally, the restored availability of that clinical information cannot establish who previously viewed it. Keeping those propositions separate avoids both overstating the incident and understating what remains missing.
NUH says it notified the Information Commissioner’s Office within the required reporting timeframe. It also notified Nottinghamshire Police, which is assessing whether the loss has any impact on Operation Perth. The Trust’s statement describes an assessment, not a finding that the investigation has been impaired.
There is therefore a meaningful accountability consequence even alongside the assurance about current care: some historical access questions may no longer be answerable from the recovered information. The available evidence does not establish the outcome of any particular patient inquiry or police assessment.
NUH’s recovery response leaves the technical remedies unspecified
The Trust says the issue was escalated within minutes of being identified. That establishes the speed of escalation after discovery; it does not establish how long the erroneous operation ran or how quickly the overwrite itself was detected.
NUH also says it completed a full patient safety incident investigation and strengthened its technical controls and processes to prevent a recurrence. Its public statement does not describe those changes. Administrators cannot safely treat this announcement as evidence that any particular approval gate, permission change, or database-target check has been implemented.
Andy Callow, NUH’s chief digital and information officer, apologized for the concern and distress caused to affected women and families. “The information needed to support patient care has been restored,” he said, while acknowledging that the historical viewing record had not been fully restored.
That qualified account is more informative than a single declaration that recovery succeeded or failed. NUH reports a successful outcome for care-related information and an incomplete outcome for access history. An incident report that preserves both results gives readers a more accurate understanding of what remains possible.
The next substantive updates would be any change in the recoverability of the historical access information and the outcome of the police impact assessment. Neither can be inferred from the completion of NUH’s internal investigation.
Database teams should review targeting and recovery as separate controls
Administrators responsible for reusable database maintenance procedures should use this incident to review target selection and recovery acceptance criteria separately. The published facts support those review priorities, but they do not supply a product-specific remediation procedure or establish that another organization has the same weakness.
The first review concerns execution: how does the organization establish which database a reused process will affect before allowing it to run? The second concerns recovery: which information must remain available afterward for the organization to continue care or business operations and answer questions about historical access? NUH’s experience shows why a positive answer to one recovery requirement cannot stand in for all the others.
The practical takeaways are specific:
- Treat the intended database and the settings that select it as execution-critical parts of any reused maintenance procedure.
- Review how an incorrect target would be detected before a consequential operation, rather than assuming that previously used instructions are suitable for their next task.
- Assess the recoverability of access history separately from the recoverability of the records it describes.
- Record restoration outcomes by information type, so that “clinical information restored” does not become an unsupported claim of complete database recovery.
- Keep incident communications scoped to the evidence: an accidental overwrite, incomplete historical audit recovery, and unaffected current services are distinct findings.
For affected women and families, the immediate distinction is equally important. NUH says clinical information needed for care remains available, but a request to establish whether a named person viewed a historical maternity record may not be answerable. The statement does not establish that every such inquiry will fail, nor that all access history has been lost.
The lasting administrative consequence of the Medway overwrite is a narrower definition of recovery success. NUH has restored the information it says is needed for patient care while remaining unable to reconstruct the complete history of who viewed it. Database teams reviewing their own procedures should make both the intended execution target and the required recovery evidence explicit before the next routine copy operation runs.