Legitimate Relationship Auditor
Job summary
We are seeking an experienced, motivated, and detail-oriented Legitimate Relationship Auditor to join our Information Governance team on a 3-year fixed-term contract.
This exciting role offers the opportunity to play a key part in ensuring patient confidentiality and maintaining public trust by providing assurance that electronic patient records are accessed appropriately across the organisation.
Working closely with Information Governance, Digital, Clinical, and Operational teams, you will lead and support legitimate relationship auditing activities, investigate potential inappropriate access to records, and contribute to the continual improvement of privacy and data protection controls.
What We Offer
- Flexible hybrid working arrangements with a combination of remote and on-site working.
- Opportunities for professional development and specialist training.
- A supportive and collaborative team environment.
- The opportunity to make a real difference in protecting patient confidentiality and improving information governance standards.
If you are passionate about information governance, data protection, and ensuring the highest standards of confidentiality within healthcare, we would welcome your application.
Apply today and help us safeguard patient information while supporting high-quality care.
Interviews commencing 7th September 2026.
Main duties of the job
- Undertake proactive and reactive legitimate relationship audits across electronic patient record systems.
- Investigate potential inappropriate access to confidential patient information.
- Analyse and interpret complex audit data, identifying trends and areas of concern.
- Produce comprehensive reports and recommendations for management and governance groups.
- Support compliance with UK GDPR, Data Protection legislation, the NHS Confidentiality Code of Practice, and organisational policies.
- Liaise with clinical and non-clinical staff regarding audit findings and investigations.
- Contribute to training, awareness, and the development of audit processes and procedures.
- Work collaboratively with internal stakeholders to strengthen information governance assurance.
About us
Working for our organisation
At UHSussex, diversity is our strength, and we want you to feel included to help us always deliver Excellent Care Everywhere, as shown in our Outstanding for Caring CQC rating. Your uniqueness and experiences will be part of our creative and innovative community where everyone is encouraged to succeed. We have a range of staff networks to help break down barriers, and can offer abuddy to help new members settle in. We're proud to be a Disability Confident Employer (Level 3) and a Veteran Aware Trust.
Candidate Pack
Job description
Job responsibilities
This vacancy is advertised as a time-limited opportunity is expected to be undertaken on a secondment basis for internal applicants.
Before applying, internal colleagues must discuss the opportunity with their current line manager to confirm whether they can be released from their substantive role if successful.Release to undertake a secondment is not automatic and must be agreed between the colleague, their current line manager, and the recruiting line manager.
You will have:
- Experience working within Information Governance, Data Protection, Clinical Systems Auditing, or a related field.
- Knowledge of NHS information governance requirements and confidentiality principles.
- Strong analytical and investigative skills with excellent attention to detail.
- Experience of handling sensitive and confidential information appropriately.
- Excellent written and verbal communication skills.
- The ability to interpret data and present findings clearly to a range of audiences.
- Strong organisational skills and the ability to manage competing priorities.
Experience of working with electronic patient record systems and audit tools within an NHS environment would be advantageous.
Please note: This role does not meet the minimum criteria for visa sponsorship under the current UK immigration rules, which set specific salary and skill thresholds. As such, we are unable to provide sponsorship for this post. Applicants will therefore need to already have the right to work in the UK to be considered. We include this information at the outset to provide clarity and avoid unnecessary inconvenience for applicants.
If you do not meet the sponsorship requirements, and you are applying using a Graduate visa as your right to work, you must have a minimum of 18 months remaining on your visa at time of application.
Person Specification
Experience/ Qualifications
- Degree-level qualification in a relevant discipline (Information Governance, IT, Informatics, Law, Finance Services) or equivalent extensive experience.
- Evidence of continuous professional development in data protection, auditing, or information security.
- Evidence of continuous professional development in data protection, auditing, or information security.
Skills
- Deep understanding of data protection legislation, including UK GDPR, Data Protection Act 2018, and the Caldicott Principles, DSP Toolkit, Role Based Access Control (RBAC) methodology.
- Advanced spreadsheet skills (e.g., Excel VLOOKUPs, pivot tables) to parse large data sets.
- Transferable sector specific skills in the private or public sector.
- Technical knowledge of Role-Based Access Control (RBAC) systems and audit trail generation.
- In-depth knowledge of the NHS Code of Practice: Confidentiality and national anti-snooping directives.
- Transferable sector specific skills in the private or public sector.
People Management and Development
- Take professional responsibility for own continuous development, maintaining an up-to-date knowledge of UK GDPR amendments, evolving case law, and shifting NHS England information governance directives.
Specific Requirements
- Significant experience undertaking information governance, compliance, audit, information security or data protection activities within a large and complex organisation.
- Experience conducting investigations, analysing audit trails and presenting findings to managers and senior stakeholders.
Freedom to Act
- Works independently within broad occupational policies and professional standards.
- Exercises judgement in determining the seriousness of suspected breaches, the investigative approach required, and whether issues warrant escalation to senior management, HR or external regulators.
- Experience setting up local auditing priorities and workflow boundaries when national policies leave room for interpretation.
Equality, Diversity, and Inclusion
- Evidence of having championed diversity in previous roles (as appropriate to role).
- Evidence of having undertaken own development to improve understanding of equalities issues
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.
Employer details
Employer name
University Hospitals Sussex NHS Foundation Trust (279)
Address
Trust Wide and Home Working Available
Worthing
BN11 2DH
United Kingdom
Employer's website
https://www.uhsussex.nhs.uk/