Singapore cancer centre put 467 hereditary-cancer patients in CC instead of BCC

20.09.2026 10 min 23

On the evening of Friday 18 September the National Cancer Centre Singapore (NCCS) emailed an invitation to its "Living with HBOC" event, a session for people with hereditary breast and ovarian cancer syndrome, to 467 addresses. The addresses went into the CC field instead of BCC, so every recipient could see everyone else. Where an address contains a name or a company domain, it also shows who the person is and where they work. About two and a half hours later NCCS sent a second email asking recipients to delete the first one and not to save or pass on the list. It has apologised, reported itself to the Ministry of Health and to the Personal Data Protection Commission (PDPC), and the PDPC says it is investigating.

In brief

  • What leaked, by NCCS's own account: email addresses only. No NRIC numbers, phone numbers or diagnoses. The subject line does the rest: being on that list says you or someone close to you carries a mutation linked to hereditary cancer.
  • Why it cuts deeper than an ordinary CC slip: HBOC is inherited. Each child of a carrier has a 50% chance of having the same mutation, so the list points at recipients' children, siblings and parents as well.
  • No hacker was needed. Unlike the extortion attack on Poland's MyDr records system, this was one wrong field in an email client. The UK regulator calls failure to use BCC one of the top breaches reported to it every year, and the PDPC put "use BCC" in its own checklist in 2017.
  • If you were on a list like this: do not reply to all, keep the organisation's notice, ask in writing what exactly was visible, and move medical correspondence off your work address. The checklist is below.

What 467 people could see

The event is scheduled for 31 October, 10am to 12.30pm, invitation only, with a talk and workshops for people living with HBOC and their families. The invitation went to the NCCS mailing list of people associated with the condition. One recipient told The Straits Times the visible addresses were "too numerous to count" and guessed at more than 500; NCCS later put the figure at 467. Many people use firstname.lastname addresses, and some use their work email, so a stranger on the list ends up with a full name and an employer next to a genetic diagnosis. Chong Pang Boon, NCCS chief operating officer and data protection officer, called it an administrative error: "Apart from email addresses, no NRIC numbers, phone numbers or other personal data were revealed." The follow-up email asked recipients to delete the invitation, empty the trash and not circulate the addresses. NCCS says it has contacted recipients to offer support, and that it is "thoroughly reviewing our internal processes to ensure that this does not happen again".

467email addresses visible to every recipient of the invitation
~2.5 hbetween the invitation and the email asking people to delete it
50%chance that each child of a BRCA carrier inherits the mutation
S$1 millionor 10% of Singapore turnover: the maximum PDPA fine since October 2022

Why an email address is medical data here

HBOC is usually caused by inherited changes in the BRCA1 or BRCA2 genes. According to the US National Cancer Institute, more than 60% of women who inherit a harmful BRCA change develop breast cancer in their lifetime, against about 13% in the general population; the ovarian cancer risk is 39% to 58% for BRCA1 and 13% to 29% for BRCA2, against 1.1%. Men carry and pass on the same mutations and have a higher risk of prostate and breast cancer. A person is on the NCCS list because they have the syndrome, are being tested for it, or care for someone who has it. That is why one recipient told The Straits Times that people they had never met now know about their genetic condition, and raised the two things carriers worry about most: employers and insurers. The worry has a technical side too. A work mailbox belongs to the employer, its administrators can read it, and a message headed "Living with HBOC" in the corporate mail archive is not something a patient chose to disclose. And because the mutation is hereditary, a name on the list is a hint about that person's children and parents, who never received any email at all.

A mistake regulators see every week

In April 2024 the UK Information Commissioner, John Edwards, wrote that failure to use BCC correctly "is one of the top data breaches reported to us every year" and that health organisations kept making "mistakes that are clear and easy to avoid". His office has fined three of them for exactly this. Singapore's PDPC published a guide on preventing accidental disclosure in January 2017; item 9 of its checklist reads: "Ensure all emails sent externally to a group of recipients have the recipients' email addresses placed in 'bcc' fields." Since 1 October 2022 the PDPC can fine an organisation up to S$1 million, or 10% of its annual turnover in Singapore if that turnover exceeds S$10 million. Its largest penalty to date is also the closest precedent: in January 2019 it fined SingHealth S$250,000 and its IT provider IHiS S$750,000 over the 2018 hack of 1.5 million patient records. NCCS is a SingHealth institution.

OrganisationYearWhat went outAddressesOutcome
HIV Scotland2021Email to patient advocates, CC field105, 65 with names£10,000 fine (ICO)
Tavistock and Portman NHS Trust2022Art competition for gender clinic patients, To field1,781£78,400 fine (ICO)
Central YMCA2024HIV support programme, CC field264, 166 identifiable£7,500 fine and reprimand (ICO)
National Cancer Centre Singapore2026Hereditary cancer event invitation, CC field467PDPC investigating

If your address was on a list like this

The organisation will ask you to delete the email. Do that, but not before you have done a few other things. The steps apply to any country and any sender, from a clinic to a school.

  • Do not use Reply all. Your reply goes to every address on the list and confirms that yours is live.
  • Note the date, the subject line and what was visible in the recipient field, and keep the sender's notification email. This is your evidence if you complain later.
  • Ask the sender in writing what exactly was exposed, who received it and whether the regulator was notified.
  • If you used a work address, switch medical correspondence to a personal one. Your employer's IT staff can read the work mailbox.
  • Expect phishing that refers to the event or the "incident". Check the sender's domain and do not open attachments or "secure links" you did not ask for.
  • If the answers do not satisfy you, complain to the data protection authority: the PDPC in Singapore, the ICO in the UK, your national authority under the GDPR.
What is not confirmed: NCCS has not said how many of the 467 are patients, how many are relatives and how many are carers or earlier attendees; its statement speaks of email addresses only, and names and employers were visible only where the address itself contained them. The PDPC has given no timeline and has not said whether a financial penalty is on the table. NCCS has not said whether the 31 October event will go ahead as planned or whether the mailing list is now handled through a bulk-mail tool rather than a mail client.

What happens next

Singapore has required organisations to notify the PDPC of significant data breaches since 2021, and NCCS did so on its own. The investigation will look at whether the centre had reasonable arrangements to prevent the error: a policy that says BCC is not a policy if one person sending to 467 addresses on a Friday evening can still pick the wrong field. The usual fixes are cheap. Mailing-list tools send one message per recipient; mail servers can be told to hold any outgoing message with more than a handful of external addresses in To or CC; and a group of undisclosed recipients, which the PDPC guide recommended nine years ago, costs nothing. The British cases suggest the penalty, if any, will be modest and the reprimand public. For the 467 people on the list, the practical damage is done and cannot be recalled by a second email; what they can control is what happens with their address from here.

What exactly did NCCS expose?
The email addresses of 467 people invited to its "Living with HBOC" event, placed in the CC field so every recipient could see them. NCCS says no NRIC numbers, phone numbers or other data were included. Where an address contains a name or a company domain, recipients could also see the person's name and employer.
Is an email address really medical data?
On its own, no. In this context, yes: the invitation went only to people associated with hereditary breast and ovarian cancer syndrome, so the list itself discloses a genetic condition. Because the mutation is inherited, it also points at the recipients' children and parents.
Can NCCS be fined?
The PDPC is investigating. Since October 2022 it can impose up to S$1 million, or 10% of annual turnover in Singapore for larger organisations. In 2019 it fined SingHealth and IHiS a combined S$1 million over the hack of 1.5 million patient records. NCCS is part of SingHealth. British fines for comparable CC and BCC errors have ranged from £7,500 to £78,400.
I received an email like this. Should I delete it as asked?
Yes, but first note the date, the subject and what was visible, keep the organisation's notification, and do not reply to all. If you used a work address, move medical correspondence to a personal one. You can complain to the data protection authority if the organisation's answers are unsatisfactory.
How do organisations avoid this?
Send mass mailings through a tool that delivers one message per recipient, or to a group of undisclosed recipients; configure the mail server to hold outgoing messages with many external addresses in To or CC; and train staff. The PDPC's 2017 guide on accidental disclosure lists BCC for group emails as a basic control.

singaporedata breachmedical dataemailpersonal dataprivacyhealthcarepatientshereditary cancergeneticshuman errorpdparegulatorsfinesukphishingdata protection

Read also