Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Former London Clinic Employee Cautioned for Attempting to Sell Princess Catherine's Medical Records

What Happened
A former employee at the London Clinic attempted to access and sell the medical records of Catherine, Princess of Wales, while she was recovering from abdominal surgery at the facility in early 2024. The UK's Information Commissioner's Office opened a criminal investigation in March 2024 after the attempted breach was reported. As of this week, the ICO closed the case with a formal caution issued to the unnamed individual.
The ICO described the conduct plainly: "deliberate misuse of highly sensitive personal information and an offer to disclose it for financial gain," according to BBC News.
The Caution, Not a Conviction
A caution in the UK legal system is NOT a criminal conviction. It is a formal acknowledgment of wrongdoing accepted voluntarily by the individual, typically used for lower-level offenses where prosecution is deemed disproportionate. The ICO's executive director for regulatory supervision, Ian Hulme, said the caution was "the appropriate and proportionate enforcement response."
Critics of that outcome have a fair argument: a deliberate attempt to sell a patient's private medical records for financial gain is not a minor lapse in judgment. It was calculated. Whether a caution adequately deters similar behavior at other private medical facilities is a genuine open question.
The counterpoint, and it matters, is that the ICO found no evidence of wider systemic failures at the London Clinic and no regulatory breaches by the hospital itself. The incident appears to have been isolated to one individual acting alone. Escalating every single-actor breach to full prosecution, regardless of outcome, would not necessarily make patient data more secure.
The Hospital's Position
The London Clinic, which describes itself as the UK's largest independent private hospital and is located near Regent's Park in central London, said it cooperated with the ICO throughout the investigation. A hospital spokesperson told BBC News: "We are pleased our work with the ICO has brought this sad and isolated incident to a conclusion. There were no regulatory breaches by the hospital."
The hospital's framing — "sad and isolated" — is accurate insofar as the ICO's own findings support it. No broader organizational failures were identified.
Why Patient Privacy Norms Matter Beyond Royalty
The public interest in this case runs deeper than celebrity. Catherine's medical records are sensitive not because of her title but because every patient's records are sensitive. The principle is the same whether the patient is a princess or a postal worker.
Ian Hulme's statement gets this right: "People should be able to trust that the personal information they're giving to healthcare settings is safe and protected from exploitation. When this trust is broken, it's right that the law allows us to take action."
The UK's Data Protection Act and GDPR-derived framework give the ICO authority to caution, fine, or refer for prosecution. In this case, the ICO chose the lightest available tool. Whether that is the right calibration, given that this wasn't an accidental data exposure but an active attempt to profit from a patient's private health information, is a policy question the ICO has answered but not necessarily settled.
What Remains Unresolved
The ICO did not publicly name the former employee, which is standard practice for cautions in the UK. That anonymity means the individual could, in theory, seek employment in another healthcare setting. Whether the caution triggers any mandatory reporting to professional medical or administrative licensing bodies, and whether the person held any such licensure, has not been addressed in available reporting.
A caution closes the ICO's file. It does not automatically close the door on future access to patient data.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.