ICO Cautions Worker Over Kate Records
Coverage from The Guardian, RadarOnline, and others

The UK Information Commissioner’s Office formally cautioned a former London Clinic healthcare worker after finding deliberate misuse of highly sensitive medical information linked to the Princess of Wales and an offer to disclose it for financial gain.
The ICO found no wider hospital failings requiring regulatory enforcement, while the NHS has responded to similar unauthorized-access cases with stronger staff warnings, auditing guidance and technical controls. The developments underscore the continuing challenge of protecting patient records from trusted insiders.
The story has sharpened from a general pattern of insider misuse into a specific enforcement outcome: the ICO formally cautioned a former London Clinic worker under the Data Protection Act after finding deliberate misuse for financial gain. The NHS response is also more explicit, shifting from general warnings to concrete operational guidance and controls.
The story has broadened from a single high-profile ICO caution into a wider UK health-data privacy enforcement and response pattern. NHS guidance and monitoring measures now make the issue feel operationally active, not just a one-off regulatory case.
