One simple ask: A cancer patient's fight to see her own medical notes
Glenda Foster had surgery for breast cancer in October 2023. She has spent months trying to see the full audit trail of her own medical notes, but multiple requests, a regulator's ruling and a solicitor's letter have got her no closer to an answer.
Glenda Foster, 73, from Ipswich, underwent breast cancer surgery in October 2023. Since the spring of this year, she has had one particular, persistent request of her NHS Trust: to see the audit trail behind two entries recorded by breast care nurses on the Somerset Cancer Register, the digital system used to log her care in the run-up to that surgery.
"I have requested they provide audit trails that record who made a change, what was changed and when," Ms Foster wrote in her original request to East Suffolk and North Essex NHS Foundation Trust (ESNEFT), submitted on 27 April 2026.
More than two years after her surgery, she was seeking what she believed was a straightforward account of her own data, something she says she is legally entitled to as a matter of course under the UK GDPR and the Data Protection Act 2018.
Months of back and forth
Under data protection law, organisations generally have one calendar month to respond to a subject access request. Ms Foster's case would run for nearly three months before reaching its disputed conclusion.
The first response arrived on 26 May, a month after her request. It came not as the detailed record she had asked for, but as a screenshot of a summary audit log: seven logged actions against one entry, from 28 September 2023, and two against another, from 23 October 2023 — inserts and updates, timestamped to the minute, but without any detail of what had actually been written or changed.
Ms Foster wrote back to the Trust's Information Governance team to say this had not answered her request. A lengthy exchange followed through June, during which, she says, a follow-up asking for the same information was treated as a new request rather than a continuation of her original one. She also approached the Trust's Patient Advice and Liaison Service (PALS), which directed her to the general medical records portal — a system she says cannot be used to obtain the type of audit trail she needed. "PALS have been worse than useless," she says.
By 18 June, having received no fuller response, she complained to the Information Commissioner's Office (ICO), which opened a case, and separately requested an internal review from the Trust. On 25 June, ESNEFT sent a further response as part of that review: screenshots of the notes for both dates, and a statement that "these entries have not been amended or updated since creation." Ms Foster maintained this still fell short of what she had asked for. The Trust concluded its internal review on 17 July, considering her request now fully answered.
What the audit trail shows – and what it doesn't
At the heart of Ms Foster's frustration is a distinction that has run through the entire process: the difference between a log of when something was entered or updated on the system, and a record of what was actually written, or changed, each time.
The audit log the Trust provided shows the former and nothing more. For the first date, it records six actions within the same minute — one initial entry and five updates — followed by a further entry logged 25 minutes later. For the second, one entry and one update, three minutes apart. What, if anything, those updates actually changed has not, on the evidence available, been disclosed to Ms Foster at any stage.
Full paper printouts of the notes for both dates, considerably longer documents than the single-page screenshots the Trust had provided, were separately obtained by Ms Foster and shown to this publication. They confirm that the clinical record for each date runs to substantially more than what she was sent.
Ms Foster believes the gap points to something more troubling. "It is illegal to alter notes with the intention of falsification," she says, and has said she believes her notes may have been "doctored" — a claim the Trust disputes, and which nothing in the material seen by this publication proves either way. What is clear is that the specific information she originally asked for, a record of what, if anything, was changed in each entry, does not appear to have been provided.
The regulator's view
The ICO investigated Ms Foster's complaint and, on 14 July, issued what it called an "educational outcome" to the Trust regarding its handling of the request, before declining to take further action.

In a decision letter dated 3 August, the ICO was careful to define the limits of that outcome. It had "not examined the records held by the Trust", it told Ms Foster, "and are therefore not in a position to determine what information is held or what should be disclosed in response to your request." Nor, it said, did its decision "mean the ICO has concluded that the Trust has complied with data protection law in every respect" — only that no further regulatory action would be taken.
For Ms Foster, the outcome amounted to little. "They will not reopen my case because they have written to the hospital and given them education on what they should do," she says. "What a joke!" Reflecting on the process as a whole. "So much for the law."
Where things stand
Ms Foster has since instructed solicitors, who have separately pressed the Trust for the same audit trail information on her behalf. "I do not need their reassurances regarding any notes," she said. "I just want the notes."
ESNEFT's interim chief executive, Adrian Marr, said: "We are in contact with Ms Foster's solicitor to provide more context about the information we have already shared with her. The Trust has also asked for more details about Ms Foster's concerns so we can help her further and work towards a resolution."
The Trust said it had reviewed its handling of the requests made on 27 April and 10 June, and was satisfied that it had provided information to Ms Foster within the statutory timescale on both occasions, treating the two dates as separate requests, each answered within a month. Ms Foster disputes that characterisation, viewing the 10 June exchange as a continuation of her original request rather than a new one.
Asked what she wants to happen next, Ms Foster said: "It shouldn't happen, and if it has, those responsible should be taken to task" — and, she hopes, it will not happen to someone else.
The bottom line
Ms Foster's dispute over one audit trail may look, at first glance, like a narrow, technical matter. But it touches on a wider principle: patients who have questions about the care they received, whether for peace of mind or because they are weighing a formal complaint or litigation, are entitled to see their own records in full, within a reasonable time. Where that access is delayed, partial or contested, patients are left in limbo, regulators can offer little beyond words of guidance, and the only remaining route is often a legal one.
More than three months after her original request, and just over a week after the ICO closed her case, Glenda Foster still does not have the answer she first asked for in April. "I just want the notes," she says. It is hard to argue that is an unreasonable place to start.
Don't forget: If you enjoy our content, please add Ipswich.co.uk as a "preferred source" on Google so you can easily find more of the content you value.
This article cost us ~£351 to produce
It's free for you to read thanks to the generous support of our partners. Please support us by supporting them.
Below the line