Princess Kate was the victim of a serious privacy breach when a former employee at her London hospital attempted to sell her confidential medical records, UK regulators have confirmed.
On Wednesday, June 17, the Information Commissioner’s Office (ICO), the United Kingdom’s privacy and data watchdog, issued a formal caution to a now-former healthcare worker at the London Clinic after determining the individual had deliberately misused the princess’ highly sensitive personal information and offered to disclose it for financial gain. The breach was first reported by the hospital in March 2024.
The ICO launched a full criminal investigation under Section 170(5) of the Data Protection Act 2018, which covers the unlawful obtaining and disclosure of medical information without consent. Following its review, the agency concluded: “The conduct involved the deliberate misuse of highly sensitive personal information and an offer to disclose it for financial gain, representing a clear breach of trust.”
According to a report The Guardian published Wednesday, June 17, Kate had been a patient at the London Clinic in January 2024, spending nearly two weeks there following planned abdominal surgery for an undisclosed condition. The following month, she revealed that cancer had been discovered during postoperative tests.
The ICO’s executive director for regulatory supervision, Ian Hulme, addressed the seriousness of the violation. “People should be able to trust that the personal information they’re giving to healthcare settings is safe and protected from exploitation,” he said, per the report. “When this trust is broken, it’s right that the law allows us to take action.”
The London Clinic maintained that the incident was isolated and that the hospital itself bore no institutional responsibility. “We are pleased our work with the ICO has brought this sad and isolated incident to a conclusion,” a spokesperson said, according to the outlet. “There were no regulatory breaches by the hospital.”
Per the report, the ICO also examined whether any broader organizational failings at the healthcare facility warranted further action, before ultimately concluding there were none that met the threshold for regulatory enforcement.