NHS Tayside Data Breach: Minnie Merriman Medical Records

NHS Tayside probes unauthorised access to patient medical records

NHS Tayside is currently investigating a significant data breach involving unauthorised access to the medical records of Minnie Merriman, a nine-year-old patient who died at Ninewells Hospital in Dundee. This NHS Tayside data breach has raised serious concerns about insider threats and the handling of sensitive patient information within clinical environments.

Details of the NHS Tayside Data Breach

The incident came to light in the aftermath of Minnie Merriman’s tragic death on 3 August 2026. Police found her seriously injured at the Elliot Industrial Estate in Arbroath, after which she was transported to Ninewells Hospital, Dundee, where she sadly died. A 35-year-old man known to Minnie was later charged with her murder, though this criminal case is separate from the data protection investigation.

According to NHS Tayside, the alleged data breach involved inappropriate access to Minnie’s medical records by staff within a clinical area. Reports from multiple UK media outlets suggest the breach may have involved either a single staff member or multiple members of staff, but the exact number has not been confirmed by the board. The core allegation is that staff viewed the child’s electronic medical records without a legitimate clinical need or authorisation.

  • Date of breach: Alleged to have occurred between 3 and 6 August 2026, following Minnie’s hospital admission and subsequent death
  • Location: Clinical area within Ninewells Hospital, NHS Tayside
  • Nature of breach: Inappropriate insider access to patient record(s)
  • Current status: Under investigation by NHS Tayside, with possible notification to the Information Commissioner’s Office (ICO) pending outcome

Timeline of Key Events

  • 3 August 2026: Minnie Merriman found injured and taken to hospital, where she died
  • 5 August 2026: Suspect charged with murder in an unrelated criminal case
  • 6 August 2026: First reports surface that NHS Tayside is investigating a data breach involving Minnie’s records
  • 7 August 2026: BBC Scotland News confirms NHS Tayside is investigating the circumstances of the alleged breach

As of 7 August 2026, NHS Tayside has not confirmed whether the incident has been formally reported to the ICO. No disciplinary actions or outcomes have yet been announced.

Technical Context: How the Breach Occurred

While NHS Tayside has not disclosed the specific software involved, it is known that the board uses InterSystems TrakCare as its patient administration and electronic patient record (EPR) platform across its hospitals, including Ninewells. TrakCare provides authenticated user access and records detailed audit logs of all access events, which are designed to support detection of inappropriate access.

The alleged incident centres on an insider threat, where one or more staff members used their legitimate credentials to view a patient record without a clinical purpose. This form of breach does not involve external attackers or the use of hacking tools, but rather the misuse of internal privileges by authorised users. Such activity is often only detectable through regular review of audit logs and monitoring for access patterns that deviate from normal clinical practice.

  • System affected: Likely InterSystems TrakCare EPR (not officially confirmed)
  • Access method: Authenticated staff user(s) in a clinical area
  • Detection: Presumably via audit logs or whistleblowing, though NHS Tayside has not detailed how the breach was identified

At this stage, no technical indicators of compromise (such as IP addresses, file hashes or domains) have been published. The investigation is focused on internal access rather than system exploitation or malware.

Regulatory and Organisational Response

NHS Tayside has stated that any data protection breach would be recorded, investigated and, where appropriate, reported to the ICO under the UK General Data Protection Regulation (GDPR). The board has not commented on specific staffing matters or potential disciplinary actions. The Information Commissioner’s Office guidance makes it clear that accessing patient records out of curiosity or without a lawful purpose is a breach of data protection law and must be taken seriously by healthcare organisations.

The ICO’s sector guidance for healthcare emphasises the need for organisations to monitor and audit user access to patient records actively, and to act promptly in the event of inappropriate access. NHS Tayside’s public statements align with this approach, but it remains to be seen what findings and actions will result from their investigation.

Why This Data Breach Matters

This NHS Tayside data breach highlights the persistent risk posed by insiders within healthcare environments, especially where staff have access to highly sensitive and personal information. The incident demonstrates that even robust technical controls can be circumvented if internal access is not properly monitored and policed. For UK organisations, including those outside the NHS, the case underscores the importance of:

  • Strict role-based access controls on personal and sensitive data
  • Comprehensive audit logging and proactive review of access records
  • Clear policies and incident response procedures for data breaches, including reporting to the ICO where required

Healthcare data remains a high-value target for both external and internal actors. Ensuring that only those with a legitimate need can access patient information is essential for maintaining public trust and complying with legal obligations under the Data Protection Act 2018 and UK GDPR.

Practical Steps for UK Organisations

Organisations should take the following steps in light of the NHS Tayside data breach event:

  • Review and tighten access controls for all staff handling personal data
  • Ensure audit logs are enabled on all systems managing sensitive records
  • Regularly monitor and review audit logs for signs of inappropriate access
  • Maintain a clear, documented process for investigating and reporting data breaches

These measures are particularly important for any organisation processing health or other sensitive personal data, regardless of size or sector.

Originally reported by bbc.co.uk.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call