World

Healthcare Worker Cautioned After Attempting to Sell Princess Catherine's Medical Records

Elena MarquezPublished 2month ago4 min readBased on 5 sources
Reading level
Healthcare Worker Cautioned After Attempting to Sell Princess Catherine's Medical Records

Healthcare Worker Cautioned After Attempting to Sell Princess Catherine's Medical Records

A former employee at the London Clinic has been formally cautioned by the UK's Information Commissioner's Office (ICO) after trying to sell Princess Catherine's private medical records from her abdominal surgery in January 2024, according to BBC News and The Guardian.

The former staff member accessed Catherine's medical notes while she was treated at the private Harley Street hospital and then offered them for sale. The Sydney Morning Herald described the material as "highly sensitive personal information." No confirmed buyer has been publicly named, and it remains unclear whether a sale actually took place.

The ICO began investigating unauthorised access at the London Clinic in March 2024, according to Reuters, weeks after Catherine's hospital admission became known to the public. This timing mattered: the weeks after her admission saw intense media and public speculation about her condition — exactly the environment that would make her records valuable to tabloid outlets or celebrity photographers.

What is a formal caution?

A caution under UK data protection law is not a criminal conviction. Instead, it's an official regulatory penalty — recorded on file and potentially affecting future employment. The ICO issues cautions when evidence shows a breach of data law but prosecutors judge criminal charges unnecessary or the person accepts responsibility. In this case, no charges were brought under the Computer Misuse Act or the Data Protection Act 2018, both of which can lead to jail time for deliberately accessing personal data for money.

The London Clinic, a prominent private hospital long associated with treating royals and other high-profile patients, said it took patient confidentiality "extremely seriously" when the ICO referred the case in March 2024. Yet the incident raises serious questions about how private hospitals protect electronic records from staff members with access. In large NHS hospitals (the state-run system), monitoring of high-profile patient admissions is routinely tightened — with digital logs tracking who views what. Private hospitals don't face the same mandated controls.

The institutional question

The ICO's authority under UK data protection law covers both the organisation storing the data and employees who misuse it. A caution of an individual worker doesn't stop the ICO from investigating whether the London Clinic itself had adequate safeguards. Think of it this way: the hospital could still face separate regulatory findings about whether its technical and organisational protections were strong enough to prevent the breach in the first place. As of June 18, 2026, no finding against the institution has been publicly announced.

For the security teams protecting the Prince and Princess of Wales, this case highlights a vulnerability that guards and cameras cannot address: the data perimeter around medical records held by third parties. Catherine's 2024 hospitalisation was already the subject of intense public guessing, and someone's attempt to profit from her records — regardless of what her diagnosis was — echoes the privacy breaches that prompted the Leveson inquiry into media conduct more than a decade ago.

The formal caution closes the immediate regulatory action, but questions about the hospital's institutional responsibility remain open.