What Uber’s GDPR €825 Million Fine...
A recent €825 million GDPR fine against Uber has put automated decision making firmly in the spotlight. This article looks...
Read MoreA recent healthcare data breach has highlighted how protecting sensitive patient information depends not only on technology, but also on the everyday decisions made by healthcare professionals.
According to a recent BBC report, a doctor disclosed confidential medical information about one patient while taking a telephone call during another patient’s examination. The conversation, which included identifying details and sensitive health information, was overheard by people who had no legitimate reason to receive it.
The incident was reported to Guernsey’s Office of the Data Protection Authority (ODPA), which warned that the disclosure created a risk of distress and loss of privacy for the individual concerned.
When cyber security in healthcare is discussed, attention understandably tends to focus on ransomware, phishing attacks, compromised systems and malicious threat actors.
However, this incident demonstrates a broader point. Protecting healthcare information also relies heavily on people, processes and organisational culture.
The ODPA received 49 breach reports between April and June 2026, with four assessed as high risk. Emails being sent to incorrect recipients remained the most commonly reported type of breach. The regulator specifically noted that data breaches are not limited to lost records or compromised computer systems, but can also include conversations being overheard.
For healthcare organisations, this is particularly important because patient information can contain some of the most sensitive categories of personal data.
Strong technical controls are therefore only one part of an effective security programme. Staff awareness, regular training, clear procedures and an organisational understanding of when and where sensitive information can be discussed are equally important.
Following the incident, the healthcare provider reminded the doctor involved of their data protection responsibilities and arranged additional training. The ODPA also recommended that this training should be provided to new staff and refreshed annually.
The relationship between cyber security and patient safety is becoming increasingly difficult to separate.
Modern healthcare depends on digital systems to access medical records, communicate clinical information, manage appointments, support diagnoses and coordinate treatment. When the confidentiality, integrity or availability of those systems and the information within them is compromised, the consequences can extend beyond regulatory compliance.
NHS England’s Digital Clinical Safety Strategy recognises this connection, describing digital clinical safety as both ensuring that technologies used within healthcare are safe and using those technologies to improve patient safety. It also identifies cyber security, information governance, interoperability and data quality as interconnected elements of a safer digital healthcare environment.
This means cyber resilience cannot be considered solely an IT responsibility. It must form part of the wider approach to clinical governance, organisational resilience and patient safety.
The Cyber Security and Business Resilience (CSBR) is a non-partisan, not-for-profit policy centre that brings together practitioners, policymakers and researchers to develop practical, evidence-led responses to cyber security and business resilience challenges. AJC’s Adrian Jolly is Chairman of the CSBR, reflecting the close connection between AJC’s work and the wider policy discussion around cyber security and resilience.
These issues will be explored further at the upcoming CSBR virtual roundtable, Cyber Security and Patient Safety in the NHS, taking place on 16 September 2026 from 2 pm to 4 pm.
The event will bring together discussion on the growing relationship between cyber security, resilience and patient safety, considering the challenges facing the NHS and what needs to be done to strengthen security across healthcare environments.
As healthcare becomes increasingly digital, incidents like this serve as an important reminder that cyber security is ultimately about protecting people. Building a resilient NHS requires more than secure technology. It also requires effective processes, strong organisational awareness and a workforce that understands its role in protecting patient information and patient safety.
Join the discussion and register for the Cyber Security and Patient Safety in the NHS roundtable here:
Sources:
https://www.bbc.co.uk/news/articles/c4gqz7vrr60o
Image accreditation: A.C. (February 2023) from Unsplash.com+. Last accessed on 8 September 2026. Available at: https://unsplash.com/photos/a-person-in-a-blue-shirt-and-white-gloves-holding-a-cell-phone-xbn8tgEG3-g
A recent €825 million GDPR fine against Uber has put automated decision making firmly in the spotlight. This article looks...
Read MoreWindows 11 version 26H2 is expected later in 2026, bringing changes to recovery, resilience and the Windows update experience. This...
Read MoreIn this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...
Read More