Healthcare Worker Cautioned After Attempting to Sell Princess Catherine's Medical Records

A former healthcare worker at the London Clinic has been cautioned by the Information Commissioner's Office (ICO) after attempting to sell Princess Catherine's private medical records from her January 2024 abdominal surgery, according to BBC News and The Guardian.
The individual — described by the ICO as a former member of staff — accessed Catherine's medical notes while she was a patient at the private Harley Street hospital and subsequently offered the information for financial gain. The Sydney Morning Herald characterised the material as "highly sensitive personal information." No buyer was publicly identified, and it is not confirmed whether a sale was completed.
The ICO had opened its investigation into potential unauthorised access at the London Clinic in March 2024, according to Reuters, weeks after Catherine's admission became public. That timeline placed the regulatory probe squarely within the period when public and media speculation about her condition was at its most intense — a context that would have made her records commercially valuable to tabloid or paparazzi networks.
A caution under UK data protection law is a formal regulatory outcome, not a criminal conviction, but it is recorded and can affect future employment. The ICO issues cautions where it finds evidence of a breach but judges a prosecution disproportionate or where the individual accepts responsibility. In this case, the outcome stops short of criminal charges under the Computer Misuse Act or the Data Protection Act 2018, both of which carry custodial sentences for deliberate, unauthorised access to personal data for commercial purposes.
The London Clinic, one of London's most prominent independent hospitals with a long-standing association with royal and high-profile patients, said at the time of the March 2024 ICO referral that it took patient confidentiality "extremely seriously." The incident nonetheless raises pointed questions about insider-threat controls in private healthcare settings — particularly the adequacy of role-based access restrictions on electronic patient records. In major NHS trusts, audit trails on high-profile admissions are routinely tightened; the same protocols are not uniformly mandated in the independent sector.
The broader data governance picture here is worth unpacking. The ICO's mandate under the UK GDPR and the Data Protection Act 2018 covers both the organisation holding the data and the individuals who misuse it. The caution of an individual worker does not preclude separate regulatory action against the London Clinic itself — the ICO can still assess whether the hospital's technical and organisational measures were sufficient to prevent the breach. No finding against the institution has been announced as of 18 June 2026.
For royal protection officers and the broader security apparatus around the Prince and Princess of Wales, the case crystallises a category of vulnerability that physical security cannot address: the data perimeter around medical and personal records held by third-party providers. Catherine's 2024 hospitalisation was already the subject of significant public conjecture, and the attempt to monetise her records — whatever the ultimate diagnosis — fits the pattern of intrusion that led to the Leveson inquiry a decade earlier.
The caution closes the immediate regulatory chapter but leaves open the question of institutional accountability at the London Clinic.


