News: 1710948621

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

London Clinic probes claim staffer tried to peek at Princess Kate's records

(2024/03/20)


The London Clinic where the Princess of Wales had surgery at the start of this year says it is investigating claims that an employee had tried to access her medical records.

Reports of the breach suggest one member of staff at the famous hospital was caught attempting to [1]view notes for Kate Middleton , the future Queen of the United Kingdom. The princess had abdominal surgery at the start of this year and her prolonged recovery has led to all sorts of conspiracy theories.

Al Russell, CEO at the London Clinic, which is known for discreetly treating members of the royal family, as well as senior politicians and celebrities, issued a [2]statement on the company website :

Everyone at the London Clinic is acutely aware of our individual, professional, ethical and legal duties with regard to patient confidentiality. We take enormous pride in the outstanding care and discretion we aim to deliver for all our patients that put their trust in us every day.

We have systems in place to monitor management of patient information and, in the case of any breach, all appropriate investigatory, regulatory and disciplinary steps will be taken. There is no place at our hospital for those who intentionally breach the trust of any of our patients or colleagues.

The Information Commissioner's Office, the local data protection regulator, confirmed to The Register in a [3]statement : "We can confirm that we have received a breach report and are assessing the information provided."

The breach only pertains to Middleton, yet the International Association of Privacy Professionals Joe Jones, director of research and insights, highlighted that access to someone's personal data doesn't mean an employee has the "necessary permissions and legal right to access and share that data."

[4]Britain enters period of mourning as Greggs unable to process payments

[5]Crowning glory of GOV.UK websites updated, sparking frontend upgrades

[6]What Mary, Queen of Scots, can teach today’s cybersec royalty

[7]Rest in peace, Queen Elizabeth II – Britain's first high-tech monarch

[8]Prince Philip, inadvertent father of the Computer Misuse Act, dies aged 99

"Although the reported breach relates to only one individual, the magnitude and accelerated proliferation of potentially harmful, and perhaps even defamatory conjecture associated with unlawful disclosure of sensitive personal data compounds the seriousness of the reported breach," he added.

Her operation took place in mid-January, according to Kensington Palace, where Kate and Prince William live. She was discharged on January 29 following a 13 night stay.

[9]

Yet the princess's prolonged absence from public life since has led to all sorts of rumor and speculation about the true state of her health. Fears - among some - were stoked further when she released a digitally doctored photo of her with her children on Mothering Sunday.

[10]

All was proved well at the weekend when a healthy looking Kate was spotted at a farm shop doing a spot of shopping.

Zut alors. Those bloody people on the interwebs. ®

Get our [11]Tech Resources



[1] https://www.mirror.co.uk/news/royals/major-kate-middleton-security-breach-32393601

[2] https://www.thelondonclinic.co.uk/media-hub/press-enquiries

[3] https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/03/ico-statement-in-response-to-reports-of-data-breach-at-the-london-clinic/

[4] https://www.theregister.com/2024/03/20/greggs_payments_meltdown/

[5] https://www.theregister.com/2024/02/22/logowatch_tudor_crown_gov_uk/

[6] https://www.theregister.com/2023/02/20/opinion_column_mary_queen_of_scots/

[7] https://www.theregister.com/2022/09/08/queen_elizabeth_dies/

[8] https://www.theregister.com/2021/04/09/prince_philip_obituary/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfsWJsPRXf4mTLB9h6sCcAAAAIU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfsWJsPRXf4mTLB9h6sCcAAAAIU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://whitepapers.theregister.com/



Hard to fight the feeling that had this been a regular person

Anonymous Coward

fuck all would have been done.

"not being able buy a meat pie with a credit card"

Furious Reg reader John

"not being able buy a meat pie with a credit card" - I don't think Paul Kunert has ever been to a Greggs, given they don't sell meat pies even when their credit card payment system is working.

Re: "not being able buy a meat pie with a credit card"

mobailey

I counted 3.14 pieces of meat in my Steak Bake.

Korev

The Information Commissioner's Office, the local data protection regulator, confirmed to The Register in a statement: "We can confirm that we have received a breach report and are assessing the information provided."

Is this really a breach? Everything I've read said that the staff member tried to access the records and nothing suggests they were successful. It appears that the clinic has the systems in place to prevent unauthorised access to records which is a good thing.

Tom Chiverton 1

No member of medical staff should have even been trying without good reason. This is basic training level stuff.

Would the logs have been audited for a Normy being treated? This isn't a Normy hospital, maybe it's SOP to cross check access attempts with staff who have a need to know...

hoola

Maybe even more basic, staff will be assigned to wards or maybe even patients. If someone attempts to look at records that are outside their remit the access is flagged.

hoola

Also one has to speculate as to what actually happened.

Given the amazing integrity of our newspapers there is also the possibility the member of staff was approached by a reporter and offered money.

Maybe I am just a cynical old fart!

Anonymous Coward

When I worked at RBS (which owns Coutts), I'd heard that looking at the Queen's account without good reason was considered a sackable offence; not sure how true it was, but I never dug into anyone's account details on the systems to test the theory...

Wally Dug

I worked for a competitor bank and everything was audited, so if an investigation took place, they could see who (or more accurately, what logged-in staff member - if someone left their system without locking it...) searched, when it was searched and exactly what was searched. And, yes, for certain high profile accounts, it was a sackable offence (this was the early 1990s, so not even a faint smell of GDPR).

A young man wrote to Mozart and said:

Q: "Herr Mozart, I am thinking of writing symphonies. Can you give me any
suggestions as to how to get started?"
A: "A symphony is a very complex musical form, perhaps you should begin with
some simple lieder and work your way up to a symphony."
Q: "But Herr Mozart, you were writing symphonies when you were 8 years old."
A: "But I never asked anybody how."