Hospital Worker Cautioned for Trying to Sell Princess of Wales's Medical Records

Hospital Worker Cautioned for Trying to Sell Princess of Wales's Medical Records
A former employee at London Clinic, a private hospital, has been formally cautioned by the UK's data protection regulator after attempting to sell the Princess of Wales's private medical records for money. The attempt was reported in mid-June 2026, according to LBC and Manx Radio.
The breach happened in January 2024. The Princess was staying at the London Clinic after abdominal surgery. At some point, a staff member accessed her medical notes without permission. The Information Commissioner's Office — the government body that oversees how organizations handle personal data — launched a criminal investigation in March 2024, per LBC.
What a caution means
A caution is a formal legal penalty. It means the worker admitted to wrongdoing and accepted this consequence instead of going to trial. A caution appears on a person's criminal record and can affect their future job prospects. The information regulator has the authority to issue cautions under laws that protect data and prevent unauthorized computer access. Accessing someone's medical records without permission is a crime that can result in fines or, in serious cases, prison time. The decision to caution rather than prosecute will likely be questioned by data protection experts and patient rights groups.
Why the timing matters
The Princess had not yet made her cancer diagnosis public when this breach occurred. She announced it in March 2024 — the same month the investigation began. During her hospital stay and recovery, media attention was intense and full of speculation. The London Clinic is chosen by high-profile patients precisely because it promises strict privacy. When a staff member breaches that trust — and tries to make money from it — it raises serious questions about how well the hospital protects patient information.
How patient records are supposed to be protected
Under UK data protection law, hospital staff can only access patient records they need for their job. A doctor treating the Princess would look at her surgical records, but a staff member from the billing department should not. Hospitals use computer systems designed to flag suspicious activity when someone accesses records they shouldn't. Whether these safeguards failed, were bypassed, or simply weren't acted on fast enough is unclear from the public information released.
The bigger picture
The UK's data protection authority has faced criticism for not being tough enough on big data breaches. It often issues warnings or fines instead of bringing criminal charges. A caution is technically a criminal decision, but it avoids a court case. Since someone apparently tried to sell the Princess's records to a buyer, some legal experts will question whether the case warranted a full prosecution in the public interest.
For the London Clinic itself, this is a serious reputational blow. Private hospitals sell themselves on one thing: they keep patient secrets. The hospital faced questions when word of the breach first emerged in early 2024. Now that a regulator has officially confirmed what happened, the spotlight intensifies. Whether the clinic has since overhauled its data security systems is a question for the hospital to answer, not something the public record shows.
The case also reflects a wider issue in healthcare. People who can access patient records — especially those of famous or wealthy people — have a financial incentive to sell them. Digital systems make it easier to copy records, but they should also leave traces of who accessed what. That a staff member was willing to try this, and that someone was willing to buy the information, shows that legal penalties so far have not fully stopped this kind of crime.


