A London gender identity clinic has accidentally exposed the email addresses of almost 2,000 people in a data breach. The Charing Cross Gender Identity Clinic sent patients an email about an art competition, with hundreds of recipients copied into the message rather than using the blind carbon copy (BCC) function.
The clinic later attempted to recall the email, but the error had already been noticed. The Tavistock and Portman NHS Foundation Trust, which runs the clinic, has launched an investigation. Two separate emails were sent, with roughly 900 people copied into each.
One patient, Jessie, told the BBC she was angry about the incident, saying it could out someone, especially as the clinic treats transgender people. A spokesman for the trust said: "We are currently investigating a data security incident. This incident involved an email from our patient and public involvement team regarding an art project. Unfortunately, due to an error, the email addresses of some of those we are inviting to participate were not hidden and therefore visible to all." The trust said it is reporting the breach to the Information Commissioner's Office (ICO) and treating it as a serious incident.
An ICO spokeswoman said: "Tavistock and Portman NHS Foundation Trust has made us aware of an incident and we will assess the information provided."
The incident echoes a 2016 case in which an NHS trust was fined £180,000 after a sexual health centre leaked the details of nearly 800 patients who had attended HIV clinics. In that case, the 56 Dean Street clinic had sent a group email without using the BCC function. That incident took place before the introduction of the General Data Protection Regulation (GDPR), which allows organisations to be fined up to €20 million or 4% of their annual global turnover.



