Back to BlogMicrosoft 365 Tips

Microsoft Purview Compliance for NHS Data: Protect Patient Records in 2026

7 September 2026 6 min read
Photo by Albert Stoynov on Unsplash

Why Microsoft Purview Matters for NHS Compliance in 2026

If you work in healthcare IT or are moving into it from a clinical background, you've probably heard the phrase "patient data breach" and felt your stomach tighten. The NHS processes 100 million patient records daily. One misconfigured SharePoint folder, one forgotten email with a discharge summary, one unencrypted USB drive can trigger the Information Commissioner's Office (ICO) to investigate and fine your trust.

Microsoft Purview isn't a silver bullet. But it is the practical tool that stops you from having to manually audit every email, document, and Teams conversation your organisation stores. It finds sensitive data automatically, classifies it, and enforces policies that keep it where it should be.

This article walks you through what Purview actually does for NHS data compliance, how it fits into the Data Protection Act 2018 and GDPR landscape, and why learning it in 2026 is becoming non-negotiable for anyone supporting Microsoft 365 in healthcare.

Understanding Microsoft Purview: Core Components

Microsoft Purview is a single platform that combines three separate compliance and governance functions:

Data Catalog: A searchable, governed inventory of all your data assets. In an NHS trust with dozens of departments, hundreds of SharePoint sites, and thousands of Teams channels, you probably don't know where all sensitive data actually lives. Purview's data map discovers it automatically.

Data Governance: Policy controls that tag and protect sensitive information. You can automatically label NHS patient identifiable information (PII) such as NHS numbers, postcodes linked to health conditions, or genetic data, then enforce rules: "this file cannot leave Teams," "this folder requires encryption at rest," "this content expires after 10 years."

Compliance Manager: A dashboard showing your current compliance posture against GDPR, UK Data Protection Act, NHS Digital Data Security and Protection Toolkit (DSPT), and other frameworks. It shows you gaps and recommends actions to close them.

For an NHS trust moving from fragmented compliance checking to something automated and visible, Purview consolidates what used to be three or four different tools.

GDPR and NHS Data Protection: Why Purview Fits

The General Data Protection Regulation (GDPR) applies to every NHS trust processing EU residents' data (which includes overseas renal units, patient records from EU mobile workers, and data transfers to research partners abroad). The UK Data Protection Act 2018 applies domestically and mirrors most GDPR principles.

Both frameworks demand:

  • Data inventory and transparency: You must know what personal data you hold and where it lives
  • Lawful basis and consent: You cannot process patient data without explicit justification
  • Data subject rights: Patients have the right to access, correct, and delete their data
  • Privacy by design: Data protection must be built into systems, not bolted on afterwards
  • Incident reporting: A data breach affecting patient records must be reported to the ICO within 72 hours
  • Purview addresses each one:

    Inventory and transparency: The data map automatically crawls your Microsoft 365 environment and creates a searchable catalogue. You can run reports showing exactly which teams, SharePoint sites, and mailboxes contain patient identifiable information.

    Lawful basis enforcement: Sensitivity labels (part of Purview) can be applied automatically when NHS numbers, DOBs, or medical record codes are detected. Policies then restrict who can access, share, or export those files. This creates an audit trail proving you're processing data lawfully.

    Data subject rights: When a patient requests their records, Purview's search and export capabilities help you find their data across disconnected systems in days instead of weeks. The labelling system also flags data marked for deletion (like session notes after statutory retention expires), making GDPR compliance auditable.

    Privacy by design: Purview policies execute automatically without waiting for human decision. A label can be applied the moment a document is uploaded, encryption enforced without asking, and suspicious sharing attempts blocked instantly.

    Incident reporting: When Purview detects unauthorised access attempts or bulk downloads of sensitive files, it logs them. This creates the evidence you need to determine whether a "near miss" becomes a reportable breach.

    Real-World NHS Compliance Scenarios

    Scenario 1: Accidental Patient Data in a Public SharePoint Site

    A junior administrator in community nursing creates a SharePoint site to share discharge summaries with GP practices. She forgets to restrict permissions. For three days, anyone with the link can download unencrypted files containing 200 patient names, postcodes, and diagnoses.

    Without Purview: The breach is discovered by accident during a routine audit three months later. By then, the data has potentially been shared, and the trust must notify 200 patients and file a mandatory breach report.

    With Purview: Sensitivity labels are automatically applied when the files are uploaded (because they contain NHS numbers and diagnoses). The policy flags "public site + NHS data" as a violation within minutes. An alert goes to the data governance team, and permissions are restricted before unauthorised access occurs.

    Scenario 2: Retention Overrun

    Patient psychotherapy notes are legally required to be deleted seven years after discharge. A mental health trust stores these in a SharePoint document library but has no systematic deletion process. After 10 years, thousands of files remain accessible, violating the Data Protection Act principle that personal data should not be retained longer than necessary.

    Without Purview: The trust discovers the problem during an ICO inspection and faces a formal warning or fine.

    With Purview: Sensitivity labels include automatic retention policies. Files older than seven years are flagged for deletion and quarantined. The trust can audit and approve bulk deletion, demonstrating active compliance.

    Scenario 3: GDPR Data Subject Access Requests (SARs)

    A patient requests all records held about them. The trust must collate data from Epic (the clinical system), Office 365 (emails and documents), SharePoint (referral letters), and Teams (clinical meeting notes). Manual collation takes four weeks and risks missing data.

    With Purview: A search runs across all systems simultaneously, returns all instances of the patient's NHS number or name, and exports them in a structured format. Turnaround drops from four weeks to five days. The trust meets the legal 30-day deadline comfortably and reduces administrative burden.

    Getting Purview Running in Your NHS Trust

    Step 1: Audit Your Current State

    Understand what data you're holding, where it's stored, and what compliance frameworks apply to you. If you're new to healthcare IT, this alone is humbling. Most NHS trusts discover they're storing data they didn't know they had.

    Step 2: Implement Sensitivity Labels

    Start simple. Create labels for "NHS Patient Data," "Staff Personal Data," and "Non-Sensitive." Configure automatic labelling based on keyword matching (NHS numbers, postcodes, ICD-10 codes). Test on a pilot department first.

    Step 3: Enable Data Loss Prevention (DLP) Policies

    Once labels are in place, create policies: "NHS Patient Data cannot be shared outside the organisation," "NHS Patient Data cannot be downloaded to USB," "Unlabelled sensitive files cannot be shared in Teams." Policies start in "audit mode" (logging only) before enforcement.

    Step 4: Map Your Data with the Data Catalog

    Run the automated data discovery. You'll be surprised what it finds. Review results with department heads to ensure classifications are accurate.

    Step 5: Monitor and Respond

    Use Compliance Manager's dashboard to track your GDPR and Data Protection Act posture. Review violation logs weekly. Adjust policies based on actual usage patterns.

    The work is not trivial. But in 2026, NHS trusts without this level of automation are running unacceptable compliance and reputational risk. A single large breach can cost an organisation GBP 2 million in fines and recovery, plus months of regulatory scrutiny.

    Why This Matters for Your IT Career in Healthcare

    If you're moving from nursing, physiotherapy, or another clinical role into healthcare IT, Purview knowledge is now a differentiator. Most entry-level IT support roles focus on hardware, passwords, and ticketing. But NHS trusts are actively hiring people who can bridge clinical knowledge and technical compliance.

    A healthcare IT support professional who understands both GDPR and Purview is worth more and more as healthcare IT matures. You speak both languages: what clinicians need (easy access to patient data) and what compliance requires (governed, auditable access).

    If you're considering a move into healthcare IT and want to understand Microsoft 365 compliance from the ground up, the Microsoft 365 Administrator Programme covers Purview, sensitivity labels, and real-world governance scenarios. It's designed specifically for career changers and healthcare professionals, with flexible weekend-only schedules.

    Frequently asked questions

    What's the difference between Purview and Data Loss Prevention (DLP)?

    Data Loss Prevention (DLP) is one component of Purview that blocks specific actions based on policy rules (e.g. preventing a file containing an NHS number from being emailed externally). Purview is the broader platform that includes DLP, plus data discovery, sensitivity labelling, compliance reporting, and retention management. DLP is the enforcement tool; Purview is the entire governance framework.

    Do NHS trusts legally need Purview to be compliant?

    No, there is no legal requirement to use Purview specifically. However, NHS trusts must demonstrate compliance with GDPR, the Data Protection Act, and the NHS Digital Data Security and Protection Toolkit (DSPT), which all require data inventory, access controls, and retention management. Purview is the most cost-effective way to automate these requirements at scale, but trusts can achieve compliance using other tools or manual processes (though this is increasingly rare and risky.

    How quickly can Purview detect a data breach?

    Purview can detect policy violations (unauthorised sharing, suspicious downloads, bulk file access) in real time, often within minutes of the action. However, detection depends on the policies you've configured. If you haven't set a label or DLP rule for a particular data type, Purview won't flag it. This is why the audit and labelling phases are critical.

    Will Purview slow down end users in Teams or SharePoint?

    No, Purview runs in the background and does not significantly impact performance. Sensitivity labelling is applied automatically or as users tag documents manually, adding only a few seconds to the save process. DLP policies are evaluated server-side, so they do not degrade client-side performance.

    What happens if we're not ready for Purview yet?

    Start with sensitivity labels and audit mode (logging only, no enforcement). This gives you time to understand your data landscape and train staff without disrupting workflows. Move policies to enforcement mode once your team is confident that rules are accurate and do not block legitimate clinical work.

    Ready to start your IT career?

    SmoothOps 365 runs live instructor-led training every Saturday and Sunday. 3 months. 50 contact hours. Keep your job while you train.