Data Breach at the YMCA
The Central YMCA sent an email to individuals participating in a programme for people living with HIV. They used “CC” rather than “BCC”, revealing the email addresses to all recipients. 166 individuals could be identified or potentially identified from their email address. As a result, it could be inferred that these individuals were likely to be living with HIV. The Central YMCA was issued with a fine of £7,500 and issued with a reprimand.

Sadly, we hear about this every day. Fortis DPC has always advocated using specialist mailing tools rather than email for large scale messaging. Failing to use “BCC” is all too common and we hear of it constantly. This could have easily been avoided with simple guidance and staff training.