Skip to content
Tuesday 1 September 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE · FR
MorningWire

European business, markets and politics

FTSE 100
10,789.28
-0.32%
DAX
25,970.11
-1.10%
CAC 40
8,301.85
-0.39%
STOXX 50
6,368.98
-0.80%
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
More
GermanyFranceEU InstitutionsCompetitionPublic AffairsBankingTechnologyEnergy
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Regulation
  • Politics
  • Opinion
  • DE
Monday 09 May 2016 11:30 am

NHS fined £180k for data breach that leaked HIV clinic patient identities

By: Lynsey Barber

Add as a preferred source on Google

The NHS has been fined thousands of pounds for revealing the identities of hundreds of patients of a London HIV clinic because of an email error.

A newsletter from a sexual health clinic in Soho was sent out to more than 700 users of an HIV service last year with patient email addresses and full names in the "cc" rather than "bcc" field. All but a few of those signed up to the newsletter are living with HIV.

The Information Commissioner's Office has fined the Chelsea and Westminster Hospital NHS Trust, which runs the clinic, £180,000 for seriously breaching the data protection act, but also found it wasn't the first time the mistake had happened, citing a similar incident in 2010.

Read more: I would trust Google with my personal data more than the NHS

“People’s use of a specialist service at a sexual health clinic is clearly sensitive personal data. The law demands this type of information is handled with particular care following clear rules, and put simply, this did not happen," said Information Commissioner Christopher Graham.

“It is clear that this breach caused a great deal of upset to the people affected. The clinic served a small area of London, and we know that people recognised other names on the list, and feared their own name would be recognised too. That our investigation found this wasn’t the first mistake of this type by the Trust only adds to what was a serious breach of the law.”

The NHS must report all breaches to the data regulator, which has the powers to fine organisations up to £500,000. It last week fined an NHS Trust in Blackpool £185,000 for posting the private information of thousands of staff online.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech

Trending Articles

  • Vodafone and Deliveroo look to patch up Reform ties after Yusuf prison threats

  • Jaguar reveals the Type 01’s screen-free interior

  • Trio of firms poised to quit London Stock Exchange as exodus gathers pace

  • As it happened: FTSE 100 slides as bound rout deepens; Oil jumps as Trump vows more strikes on Iran

  • Green activists want to take Polanski down a dark road

More from Morning Wire

  • Cabenuva demonstrates superiority to daily oral therapy in adolescents living with HIV, as ViiV Healthcare highlights new long-acting injectable data at AIDS 2026

    Business Wire
  • ViiV Healthcare to present phase IIIb data comparing Dovato with Biktarvy in treatment-naïve adults; alongside INSTI-powered long-acting injectable innovation at AIDS 2026

    Business Wire
  • U.S. FDA approves ViiV Healthcare’s Tivicay PD, helping close a critical HIV treatment gap for young children

    Business Wire
  • Grindr for Equality Commits to Connecting 10M to HIV Prevention by 2028

    Business Wire
  • NHS data counters claims that £330m Palantir deal has led to ‘no improvement’

    Tech
    Brit are seeking financial support from the ‘Bank of Mum and Dad’ to afford private healthcare.
  • Ignore Palantir’s political opponents and look at the data: this technology helps patients

    Opinion
    NHS logo on a white surface with visible water droplets, blue and white branding
  • Leeds NHS Innovation to Accelerate Global Adoption of AI-enabled Pathology for Cancer Diagnostics Through Epredia Partnership

    Business Wire
  • Curaleaf Launches Free CPD-Accredited Platform to Close Medical Cannabis Training Gap for UK Healthcare Professionals

    Business Wire
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • EU Institutions
  • Europe

Business

  • Markets
  • Business
  • Economy
  • Regulation
  • Competition
  • Public Affairs

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook