Back to Explorer
UK GDPRHealthcare

NHS Highland

Data Breach

Authority

ICO

Country

United Kingdom

Date Issued

March 8, 2023

Industry

Healthcare

Summary

NHS Highland was formally reprimanded for inadvertently disclosing the personal email addresses of 37 individuals likely accessing HIV services by using CC instead of BCC in an email, exposing sensitive health information and compromising individual privacy.

Violation Types

Data BreachTransparencySecurity

Articles Violated

Avoid enforcement risk with automated compliance

IQWorks helps organizations automate UK GDPR compliance before regulators come knocking.

Talk to an Expert