The London Clinic: Ex-healthcare worker tried to leak Princess Kate’s medical records for cash

The London Clinic: Ex-healthcare worker tried to leak Princess Kate’s medical records for cash

Former Healthcare Worker Cautioned for Misusing Princess of Wales’s Medical Records

A former healthcare worker at London’s The London Clinic has been formally cautioned by the Information Commissioner’s Office (ICO) for the deliberate misuse of Princess of Wales Kate Middleton’s private medical records, including an attempt to disclose them for financial gain.

The ICO launched a criminal investigation in March 2024 after the clinic reported a breach involving unauthorized access to Kate’s records. The princess had been a patient at the private hospital in January 2024, undergoing abdominal surgery and remaining hospitalized for 13 days. Her cancer diagnosis, detected during the procedure, was later disclosed publicly in March 2024.

The ICO determined that the former employee reportedly a nurse violated Section 170(5) of the Data Protection Act 2018 by exploiting highly sensitive medical data. While the worker was struck off from their professional register, the ICO concluded that a formal caution was the appropriate enforcement action, citing no evidence of broader organizational failings at the clinic.

Ian Hulme, the ICO’s executive director for regulatory supervision, emphasized that the case underscored the importance of safeguarding patient trust. The London Clinic stated that the incident was isolated and that no regulatory breaches by the hospital were identified.

Kate Middleton announced her cancer remission in January 2025 and has since resumed royal duties.

Source: https://www.independent.co.uk/news/uk/crime/kate-middleton-cancer-data-breach-b2997532.html

The London Clinic cybersecurity rating report: https://www.rankiteo.com/company/the-london-clinic

"id": "THE1781706793",
"linkid": "the-london-clinic",
"type": "Breach",
"date": "3/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1 (Princess of Wales Kate '
                                              'Middleton)',
                        'industry': 'Healthcare',
                        'location': 'London, UK',
                        'name': 'The London Clinic',
                        'type': 'Healthcare Provider'}],
 'attack_vector': 'Insider Threat',
 'data_breach': {'data_exfiltration': 'Attempted (for financial gain)',
                 'number_of_records_exposed': '1',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (cancer diagnosis, medical '
                                        'history)',
                 'type_of_data_compromised': 'Medical records, personally '
                                             'identifiable information (PII)'},
 'date_detected': '2024-03',
 'description': 'A former healthcare worker at London’s The London Clinic has '
                'been formally cautioned by the Information Commissioner’s '
                'Office (ICO) for the deliberate misuse of Princess of Wales '
                'Kate Middleton’s private medical records, including an '
                'attempt to disclose them for financial gain.',
 'impact': {'brand_reputation_impact': 'Yes',
            'data_compromised': 'Medical records, including sensitive health '
                                'information',
            'identity_theft_risk': 'High'},
 'investigation_status': 'Concluded',
 'lessons_learned': 'Importance of safeguarding patient trust and protecting '
                    'sensitive medical data from insider threats.',
 'motivation': 'Financial gain',
 'post_incident_analysis': {'corrective_actions': 'Former employee struck off '
                                                  'professional register; no '
                                                  'broader organizational '
                                                  'failings identified',
                            'root_causes': 'Unauthorized access by insider '
                                           'with malicious intent'},
 'references': [{'source': 'Information Commissioner’s Office (ICO)'}],
 'regulatory_compliance': {'legal_actions': 'Formal caution issued by ICO',
                           'regulations_violated': ['Section 170(5) of the '
                                                    'Data Protection Act 2018'],
                           'regulatory_notifications': 'Yes (ICO '
                                                       'investigation)'},
 'response': {'containment_measures': 'Former employee struck off professional '
                                      'register',
              'law_enforcement_notified': 'Yes (ICO)'},
 'threat_actor': 'Former healthcare worker (nurse)',
 'title': 'Former Healthcare Worker Cautioned for Misusing Princess of Wales’s '
          'Medical Records',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Unauthorized access to medical records'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.