Analysis of the ESCC–NHS Operational Pattern and Public Interest Implications in the Handling of Medical Data
1. Introduction
This analysis examines an event documented through two official Statements of Witness issued by East Sussex County Council (ESCC), signed by Mark Jobling (Investigations Officer) and Mandy Covey (Medical Secretary, NHS – Hurstwood Park Hospital). The statements describe a sequence of actions that highlight procedural weaknesses, unauthorised access to medical data, informal exchanges of sensitive information, and improper role conduct within the cooperation between a local authority and an NHS facility.
The elements identified suggest a potential operational pattern of public interest, as they concern the protection of medical data, public‑sector governance, and citizen safeguards within the UK regulatory framework (Data Protection Act 2018, GDPR, NHS governance, Caldicott Principles).
2. Access to NHS Medical Data Without a Clear Legal Basis
From Mandy Covey’s testimony, a critical point emerges:
“At this point I checked the electronic records for Mr Gresta…” (MC SOW)
No formal request, Caldicott Guardian authorisation, legal basis, cooperation protocol with ESCC, or clinical supervision is mentioned. The access to medical records occurred solely upon the request of a Council Investigations Officer, not for clinical or treatment‑related purposes.
In the absence of a documented legal basis and a formal data‑sharing protocol, this access constitutes a governance concern and a potential unlawful processing activity under GDPR and the Data Protection Act 2018.
3. Exchange of Sensitive Information Outside a Formal Framework
From Jobling’s testimony:
“On the 18th of May 2022 I attended Hurstwood Park Hospital… where I spoke to Mandy Covey.” (MJ SOW)
And from Covey’s testimony:
“I was contacted by Mark Jobling… I met with Mark Jobling… I was informed that Mark was conducting a Criminal Investigation…” (MC SOW)
The following scenario emerges:
- an ESCC employee physically enters an NHS hospital;
- a medical secretary accesses a patient’s clinical records;
- the secretary provides assessments on clinical documentation;
- the secretary produces a formal statement for a criminal investigation.
No data‑sharing protocols, NHS DPO authorisations, Caldicott Guardian involvement, or clinical/legal supervision are referenced. This informal exchange of sensitive data is incompatible with GDPR principles of minimisation, accountability and lawful processing, as well as NHS governance standards.
4. Clinical Judgements Made by Non‑Clinical Personnel
Covey states:
“Upon viewing this letter I immediately drew the conclusion that it was not genuine.” “I am willing to attend Court to give evidence if required.” (MC SOW)
A Medical Secretary is not authorised to:
- make clinical assessments,
- authenticate or invalidate medical documents,
- compare clinical letters for evidential purposes,
- participate in criminal investigations as a clinical expert,
- provide medical opinions to external bodies.
The testimony shows an improper overlap between administrative duties and clinical evaluation, creating risks for evidential reliability and procedural correctness.
5. Data‑Handling and Documentation Issues by Stephanie Tuohy
ESCC documentation reveals concerns regarding the handling of documents and personal data by Stephanie Tuohy, Blue Badge Issues Assistant. Key observations include:
- absence of structured document‑verification procedures;
- lack of traceability in document‑handling stages;
- no formal validation protocol;
- informal practices inconsistent with minimisation and accuracy principles;
- indicators of potential bias in preliminary assessment.
These issues suggest data‑handling practices not fully aligned with GDPR, the Data Protection Act 2018, or operational best practice for the Blue Badge Team.
6. Critical Issues in the Mobility Assessment Report Prepared by Ann Longden
The Mobility Assessment Report prepared by Ann Longden, Mobility Assessment Report Officer, contains several elements that raise concerns regarding professional and procedural standards.
6.1 Presence of Personal Opinions
The report includes statements resembling personal opinions not supported by:
- objective measurements,
- validated clinical tools,
- verifiable documentary evidence.
Personal opinions in administrative documents used for decisions affecting citizen rights represent a procedural weakness.
6.2 Judgements on the Work of Other Professionals
The report contains passages that comment on or reinterpret the work of:
- medical specialists,
- physiotherapists,
- General Practitioners,
- clinical consultants.
A Mobility Assessment Officer is not authorised to:
- reinterpret diagnoses,
- dispute clinical evaluations,
- attribute intentions or motivations to clinicians,
- assess the quality of medical documentation.
These actions constitute an improper overlap of roles.
6.3 Indicators of Bias
The report shows potential bias, including:
- subjective interpretations of the applicant’s behaviour,
- conclusions unsupported by measurable data,
descriptions inconsistent with functional‑assessment standards.
6.4 Structural Weaknesses
The report demonstrates:
- lack of internal coherence,
- absence of references to standardised assessment tools,
- non‑technical language,
omission of essential elements for a complete functional assessment.
6.5 Public Interest Relevance
These weaknesses affect the quality of mobility assessments and the protection of citizens relying on such documents for access to essential services.
7. A Possible Consolidated Operational Pattern
The testimonies and documents analysed show a process that is:
- rapid,
- informal,
- undocumented,
- lacking explicit protocols,
- lacking formal authorisations,
- lacking clinical and data‑protection oversight.
The ease with which ESCC accessed NHS data, NHS personnel provided sensitive information, and non‑clinical staff produced clinical‑style assessments suggests an operational pattern rather than an isolated incident.
8. Targeted GDPR Removals in Search Engines
For queries containing the names:
- Mark Jobling
- Mandy Covey
- Ann Longden
- Stephanie Tuohy
Google displays:
“Some results may have been removed under data protection law in Europe.”
This message appears when Google receives removal requests under Article 17 GDPR. These removals are targeted and limited to personal content, not to public‑interest material or documented operational patterns.
Some requests may originate from unrelated homonyms. However, the documented issues concern the protection of medical data belonging to third‑party citizens, and selective use of the right to erasure cannot override public‑interest considerations.
9. Conclusions: Why This Analysis Is in the Public Interest
This analysis is in the public interest because it:
- documents weaknesses in NHS medical‑data protection;
- highlights informal exchanges of sensitive data between ESCC and NHS;
- shows improper role conduct and lack of supervision;
- identifies data‑handling issues by Stephanie Tuohy;
- identifies bias and professional weaknesses in Ann Longden’s report;
- suggests a consolidated operational pattern;
- notes targeted GDPR removals that do not affect public‑interest content;
- contributes to transparency and accountability of public bodies;
aligns with the UK’s open justice principles.
.