Skip to content
NHS Tayside reveals HUNDREDS of data breaches in two years

NHS Tayside reveals HUNDREDS of data breaches in two years

Thecourier September 16, 2026

Hundreds of NHS Tayside data breaches have been confirmed in the past 18 months, with the number reaching its highest level in five years.

The health board came under fire after it was revealed that an investigation was launched into claims that staff were caught snooping on Minnie Merriman’s medical records.

The nine-year-old schoolgirl was found injured in Arbroath and was transported to Ninewells Hospital, where she later died.

NHS Tayside contacted every employee to remind them of their responsibilities and the strict codes of conduct around accessing patients’ medical records.

The Courier has reported a string of data breaches involving the health board in recent years, including 381 errors that were flagged in 2023-24.

Highest NHS Tayside data breach figures in five years

A Freedom of Information request to NHS Tayside found that more than 800 data breaches were logged in 2025 and until August 2026.

Of this number, 446 have been confirmed.

This is the highest figure in five years , with 272 breaches in 2022-23 and 246 logged in 2021-22.

In 2025, 472 data breaches were reported, with 348 confirmed.

Between January and August 2026, 360 breaches were reported. Just under 100 of these have been confirmed.

NHS Tayside has been criticised for several high-profile data leaks, including the victims of disgraced ex-Dundee doctor Sam Eljamel, whose personal data was shared.

The health board apologised to 132 patients for the error.

In 2024, parents of P1 pupils at a Broughty Ferry school said they were “furious” after an NHS worker lost documents containing their children’s personal information.

‘Lessons are not being learned by NHS Tayside

Commenting on the figures, Mid Scotland and Fife MSP Murdo Fraser said: “These figures revealed by the Courier today are shocking.

“To have hundreds of data breaches over two years suggests that lessons are not being learned by NHS Tayside.”

NHS Tayside chief executive Nicky Connor faced questions the repeated data breaches at the public inquiry looking at the Eljamel scandal.

This included the details of patients operated on by Eljamel being sent to The Courier in error .

Ms Connor told the inquiry the health board had an “absolute commitment” to information governance.

She said: “Patients and the public should expect from us that we are keeping their information safe.”

Ms Connor said the board has put an action plan in place to ensure it learns from data breaches.

Reported data breaches ‘treated with utmost seriousness’

A spokesperson for NHS Tayside said: “Maintaining the confidentiality and security of patient information is a fundamental responsibility for NHS Tayside, and we treat all reported information governance incidents with the utmost seriousness.

NHS Tayside has continued to strengthen staff awareness and training on the safe handling of information.

“This has contributed to increased reporting of potential breaches and concerns, which reflects a positive reporting culture and improved awareness among staff of their responsibilities around appropriate, role-based access to information.

“Increased reporting does not necessarily indicate an increase in inappropriate access or misuse of patient information.”

are currently disabled as they require cookies and it appears you've opted out of cookies on this site. To participate in the conversation, please adjust your cookie preferences in order to enable .

Extracted Entities

Attack Types (1)

Companies (1)

Domains (1)