Singapore cancer centre put 467 hereditary-cancer patients in CC instead of BCC
On the evening of Friday 18 September the National Cancer Centre Singapore (NCCS) emailed an invitation to its "Living with HBOC" event, a session for people with hereditary breast and ovarian cancer syndrome, to 467 addresses. The addresses went into the CC field instead of BCC, so every recipient could see everyone else. Where an address contains a name or a company domain, it also shows who the person is and where they work. About two and a half hours later NCCS sent a second email asking recipients to delete the first one and not to save or pass on the list. It has apologised, reported itself to the Ministry of Health and to the Personal Data Protection Commission (PDPC), and the PDPC says it is investigating.
In brief
- What leaked, by NCCS's own account: email addresses only. No NRIC numbers, phone numbers or diagnoses. The subject line does the rest: being on that list says you or someone close to you carries a mutation linked to hereditary cancer.
- Why it cuts deeper than an ordinary CC slip: HBOC is inherited. Each child of a carrier has a 50% chance of having the same mutation, so the list points at recipients' children, siblings and parents as well.
- No hacker was needed. Unlike the extortion attack on Poland's MyDr records system, this was one wrong field in an email client. The UK regulator calls failure to use BCC one of the top breaches reported to it every year, and the PDPC put "use BCC" in its own checklist in 2017.
- If you were on a list like this: do not reply to all, keep the organisation's notice, ask in writing what exactly was visible, and move medical correspondence off your work address. The checklist is below.
What 467 people could see
The event is scheduled for 31 October, 10am to 12.30pm, invitation only, with a talk and workshops for people living with HBOC and their families. The invitation went to the NCCS mailing list of people associated with the condition. One recipient told The Straits Times the visible addresses were "too numerous to count" and guessed at more than 500; NCCS later put the figure at 467. Many people use firstname.lastname addresses, and some use their work email, so a stranger on the list ends up with a full name and an employer next to a genetic diagnosis. Chong Pang Boon, NCCS chief operating officer and data protection officer, called it an administrative error: "Apart from email addresses, no NRIC numbers, phone numbers or other personal data were revealed." The follow-up email asked recipients to delete the invitation, empty the trash and not circulate the addresses. NCCS says it has contacted recipients to offer support, and that it is "thoroughly reviewing our internal processes to ensure that this does not happen again".
Why an email address is medical data here
HBOC is usually caused by inherited changes in the BRCA1 or BRCA2 genes. According to the US National Cancer Institute, more than 60% of women who inherit a harmful BRCA change develop breast cancer in their lifetime, against about 13% in the general population; the ovarian cancer risk is 39% to 58% for BRCA1 and 13% to 29% for BRCA2, against 1.1%. Men carry and pass on the same mutations and have a higher risk of prostate and breast cancer. A person is on the NCCS list because they have the syndrome, are being tested for it, or care for someone who has it. That is why one recipient told The Straits Times that people they had never met now know about their genetic condition, and raised the two things carriers worry about most: employers and insurers. The worry has a technical side too. A work mailbox belongs to the employer, its administrators can read it, and a message headed "Living with HBOC" in the corporate mail archive is not something a patient chose to disclose. And because the mutation is hereditary, a name on the list is a hint about that person's children and parents, who never received any email at all.
A mistake regulators see every week
In April 2024 the UK Information Commissioner, John Edwards, wrote that failure to use BCC correctly "is one of the top data breaches reported to us every year" and that health organisations kept making "mistakes that are clear and easy to avoid". His office has fined three of them for exactly this. Singapore's PDPC published a guide on preventing accidental disclosure in January 2017; item 9 of its checklist reads: "Ensure all emails sent externally to a group of recipients have the recipients' email addresses placed in 'bcc' fields." Since 1 October 2022 the PDPC can fine an organisation up to S$1 million, or 10% of its annual turnover in Singapore if that turnover exceeds S$10 million. Its largest penalty to date is also the closest precedent: in January 2019 it fined SingHealth S$250,000 and its IT provider IHiS S$750,000 over the 2018 hack of 1.5 million patient records. NCCS is a SingHealth institution.
| Organisation | Year | What went out | Addresses | Outcome |
|---|---|---|---|---|
| HIV Scotland | 2021 | Email to patient advocates, CC field | 105, 65 with names | £10,000 fine (ICO) |
| Tavistock and Portman NHS Trust | 2022 | Art competition for gender clinic patients, To field | 1,781 | £78,400 fine (ICO) |
| Central YMCA | 2024 | HIV support programme, CC field | 264, 166 identifiable | £7,500 fine and reprimand (ICO) |
| National Cancer Centre Singapore | 2026 | Hereditary cancer event invitation, CC field | 467 | PDPC investigating |
If your address was on a list like this
The organisation will ask you to delete the email. Do that, but not before you have done a few other things. The steps apply to any country and any sender, from a clinic to a school.
- Do not use Reply all. Your reply goes to every address on the list and confirms that yours is live.
- Note the date, the subject line and what was visible in the recipient field, and keep the sender's notification email. This is your evidence if you complain later.
- Ask the sender in writing what exactly was exposed, who received it and whether the regulator was notified.
- If you used a work address, switch medical correspondence to a personal one. Your employer's IT staff can read the work mailbox.
- Expect phishing that refers to the event or the "incident". Check the sender's domain and do not open attachments or "secure links" you did not ask for.
- If the answers do not satisfy you, complain to the data protection authority: the PDPC in Singapore, the ICO in the UK, your national authority under the GDPR.
What happens next
Singapore has required organisations to notify the PDPC of significant data breaches since 2021, and NCCS did so on its own. The investigation will look at whether the centre had reasonable arrangements to prevent the error: a policy that says BCC is not a policy if one person sending to 467 addresses on a Friday evening can still pick the wrong field. The usual fixes are cheap. Mailing-list tools send one message per recipient; mail servers can be told to hold any outgoing message with more than a handful of external addresses in To or CC; and a group of undisclosed recipients, which the PDPC guide recommended nine years ago, costs nothing. The British cases suggest the penalty, if any, will be modest and the reprimand public. For the 467 people on the list, the practical damage is done and cannot be recalled by a second email; what they can control is what happens with their address from here.
What exactly did NCCS expose?
Is an email address really medical data?
Can NCCS be fined?
I received an email like this. Should I delete it as asked?
How do organisations avoid this?
• National Cancer Centre e-mail lapse allegedly exposes patients' details including names, workplaces - The Straits Times
• National Cancer Centre 'deeply sorry' after email error exposes details of more than 460 patients - AsiaOne
• Names, workplaces of patients with hereditary cancer allegedly exposed in 'administrative error' - Mothership
• Information Commissioner: persistent sensitive information breaches failing people living with HIV - ICO
• A new GDPR fine and a new ICO enforcement approach (Tavistock and Portman) - Local Government Lawyer
• Guide to preventing accidental disclosure when processing and sending personal data (PDF) - PDPC
• Singapore: increased financial penalties under the PDPA now in effect - DLA Piper
• Fine of $1,000,000 imposed on SingHealth and IHiS for breach of the PDPA - CNP Law
• Hereditary Breast and Ovarian Cancer Syndrome - MD Anderson Cancer Center
• BRCA gene changes: cancer risk and genetic testing - National Cancer Institute