
NHS Forth Valley, the health board serving the area between Edinburgh and Glasgow, is investigating after a staff member sent a spreadsheet containing maternity patient data to a personal email account, exposing information tied to approximately 150 women who had contact with the board’s maternity services.
The exposed information varied by patient but included names, dates of birth, addresses or postcodes, NHS numbers, treatment details from their pregnancies and, for some, the number of children they had. NHS Forth Valley said the majority of the spreadsheet’s contents were not identifiable, but that some lines of data referred to specific patients.
A health board spokesperson said an internal investigation began after the employee transferred the extract from the maternity system to a personal account. NHS Forth Valley said there is no evidence the information was shared further, and that the employee has advised the data was deleted.
The board’s characterization of the employee has shifted since the breach came to light: a letter sent to affected patients and signed by director of midwifery Mairi McDermid described the employee as a fully qualified NHS staff member rather than a junior one, while the health board later stated specifically that the person involved was not a clinical staff member.
The board has notified the women affected directly, along with the UK Information Commissioner’s Office and Police Scotland. One of the women affected said the breach left her with significant concerns about patient confidentiality and data security. She said the spreadsheet reportedly included her full name, date of birth, address, NHS number, details of treatments she received during her pregnancy and information about how many children she has, and that she was told the document held personal information on around 150 patients. She said she was advised that accessing and sending this type of data to a personal email account is difficult to do and is considered a serious breach of data protection rules. She added that the employee had reportedly said the information was taken for analytical purposes, but that NHS Forth Valley could not say with certainty whether copies of the document still existed or whether it had been shared elsewhere, and that the exposure had left her anxious about her private details being in the public domain.
NHS Forth Valley said the matter had been reported to Police Scotland, though local officers said they had no knowledge of the incident. The health board declined to say whether the staff member involved had been suspended or whether disciplinary action had been taken. An Information Commissioner’s Office spokesperson said the regulator had received a report from NHS Forth Valley and was making inquiries.
Under the General Data Protection Regulation and the Data Protection Act 2018, organizations are required to follow six basic data protection principles, including ensuring that personal data is processed in a manner that ensures appropriate security.
Beyond the maternity incident, NHS Forth Valley has recorded 249 data breaches since January 2023, with fewer than five staff members disciplined as a result, according to figures the board provided in response to a freedom of information request. The board declined to give further detail on the disciplinary cases, saying doing so could risk identifying the individuals involved.
The UK Information Commissioner’s Office, the regulator tasked with enforcing data protection law, has said patient data is highly sensitive and that health boards are legally required to protect it or face sanctions.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543