World

Former London Clinic Worker Cautioned Over Attempt to Sell Princess of Wales's Medical Records

Elena MarquezPublished 2month ago4 min readBased on 4 sources
Reading level
Former London Clinic Worker Cautioned Over Attempt to Sell Princess of Wales's Medical Records

Former London Clinic Worker Cautioned Over Attempt to Sell Princess of Wales's Medical Records

A former healthcare worker has been cautioned by the Information Commissioner's Office (ICO) after attempting to sell the Princess of Wales's private medical records for financial gain, LBC and Manx Radio reported on 17 June 2026.

The breach dates to January 2024, when the Princess was a patient at the London Clinic — a private hospital in central London — following abdominal surgery. At least one member of staff accessed her medical notes without authorisation during that admission, according to Yahoo News Australia and the Belfast Telegraph. The ICO launched a criminal investigation in March 2024 into the unlawful obtaining and disclosure of that information, per LBC.

A caution — in English and Welsh law — is a formal admission of guilt accepted as an alternative to prosecution. It sits on a criminal record and can affect future employment. The ICO has the power to issue cautions under the Computer Misuse Act 1990 and the Data Protection Act 2018, which incorporates the UK GDPR. Unauthorised access to medical records held in a clinical system is a criminal offence under section 55 of the DPA, carrying a fine or — in aggravated cases involving intent to sell — potential custodial sentences on indictment. That the regulator settled on a caution rather than pursuing a full prosecution will likely draw scrutiny from data-protection practitioners and patient-rights advocates alike.

The episode landed at an acutely sensitive moment. The Princess had not yet publicly disclosed her cancer diagnosis, which came in March 2024, and the period of her hospitalisation and recovery was subject to intense media speculation. The London Clinic is routinely used by high-profile patients precisely because of the confidentiality standards it is expected to uphold. A breach of that expectation by a staff member — and the attempt to monetise it — puts the institution's internal access-control architecture under the microscope.

Under UK GDPR and the NHS's own Caldicott principles, access to patient records is governed by a minimum-necessary standard: clinical staff are authorised only to view records directly relevant to their role in a patient's care. Auditing systems are supposed to flag anomalous access patterns in near real-time. Whether those controls failed, were overridden, or simply were not acted upon quickly enough is a question the ICO's investigation presumably addressed — though the published outcome of a caution does not, by convention, detail the full procedural findings.

The broader regulatory picture here is worth noting. The ICO has faced persistent criticism for under-enforcement on high-profile data breaches, often opting for reprimands and civil monetary penalties rather than criminal referrals. A caution in this case is, technically, a criminal disposal — but one that stops short of a court. For a breach that involved an apparent attempt to sell records to a third party, some legal observers will ask whether the public-interest threshold for prosecution was properly weighed.

For the London Clinic, the reputational exposure is considerable. Private hospitals market themselves on discretion. The institution faced immediate questions in early 2024 when reports of the attempted access first surfaced; the ICO's formal conclusion now places those events in a defined legal register. What internal disciplinary action the clinic took — and whether its data governance frameworks have since been updated — remains a matter of institutional accountability rather than public record.

The case also feeds into a wider conversation about celebrity and high-value patients in healthcare settings. The commercial incentive to obtain and sell such information is not new, but digital record systems have both centralised access and, in theory, made audit trails more robust. That a staff member was apparently willing to act on that incentive — and that a buyer or intermediary was sought — points to a market for this kind of data that regulatory deterrence has not fully extinguished.