Last updated 2 weeks ago
A healthcare worker at a United Kingdom National Health Service (NHS) hospital attempted to sell the medical records of Catherine, Princess of Wales. The incident was publicly disclosed in July 2026, following an investigation by the Information Commissioner's Office (ICO). No specific discovery date or number of affected records was provided in the article.
The breach involved an insider threat: a hospital employee accessed and attempted to sell the royal patient's medical records. The attack vector was insider misuse of authorized access. The data compromised included the Princess of Wales's medical records. The threat actor was an unnamed healthcare worker.
The ICO issued a caution to the healthcare worker but did not pursue criminal prosecution. The case was handled under the United Kingdom's data protection regulations. No further post-incident details, such as litigation or remediation milestones, were reported.
Insider attempted to sell medical records of Catherine, Princess of Wales
This incident underscores the critical need for healthcare organizations to implement robust insider threat detection and access controls. The NHS should enforce strict least-privilege access to sensitive patient records, particularly for high-profile individuals, and deploy user behavior analytics to flag anomalous access patterns. Additionally, regular security awareness training emphasizing the legal and professional consequences of unauthorized data access is essential.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor