A doctor disclosed private medical information after they took a phone call while examining a patient.

The Office of the Data Protection Authority (ODPA) in Guernsey said ‘identifying details and sensitive health information’ about someone else were overheard as the call was made.

The ODPA said the breach created a ‘risk of distress and loss of privacy’ for the person affected and said the healthcare provider involved reminded the doctor about their data protection duties.

The watchdog added the provider had arranged additional staff training. It recommended training be given to new staff and refreshed annually in a bid to prevent similar incidents in the future.

Data protection commissioner Brent Homan said: ‘Breaches are not just about records, but include overheard conversations.’

Sign up for all of the latest stories

Start your day informed with Metro’s News Updates newsletter or get Breaking News alerts the moment it happens.

It comes despite the ODPA reporting a fall in the number of serious data breaches in Guernsey in the second quarter of 2026.

The authority said it was notified of 49 breaches between April and June.

Of these, four were classed as high-risk, down from seven the previous quarter.

A further 10 cases were eventually found not to meet the threshold of a reportable breach.

The figures follow statistics released in June, which showed high-risk incidents had fallen from 12 to seven in the first three months of the year.

Homan said: ‘It is encouraging to see high-risk breach incident reports decline for a second quarter.

‘When organisations report breaches, they not only fulfill an important legal obligation but can benefit from our office’s expertise in mitigating any harmful effects of a security incident.’

The most commonly reported breach involved emails being sent to the wrong person.

Across the UK, more than 1,400 serious patient data breaches have been recorded across the NHS over the past few years, a Freedom of Information request by the Health Service Journal found.

Recently, one included an ‘urgent’ investigation which was launched after 40 staff members accessed files about a young boy who was attacked by a crocodile and taken to Addenbrooke’s Hospital.

Cambridge University Hospitals said in June that they were looking into why so many people accessed the victim’s records, and has referred itself to the Information Commissioner’s Office.

They said: ‘We have strict policies in place to safeguard patient data and we take any breach extremely seriously.

‘Where any member of staff is found to have accessed patient records without legitimate clinical or operational reasons we take robust disciplinary action, including dismissal.

‘As part of our response to any breach, we notify both the ICO and apologise to patients and their families affected.’

Comment now
Comments

Add Metro as a Preferred Source on Google
Add as preferred source