68 published accounts of health data sold or shared without consent from 50 countries and territories
Sold or shared, as we file it: the record or health data was sold, shared with marketers or other parties, or published without consent.
Published October 2024 to October 2026, found in sources in 24 languages: 68 of all 442 cases. By region, 9 in Africa, 14 in the Americas, 13 in Asia, 22 in Europe, 9 in the Middle East and 1 in Oceania. Of these, a regulator or court decided 41, the organization involved admitted 1 and 26 are allegations not decided. The sources: 19 decisions by regulators and ombudsmen, 3 court judgments and 46 reports by edited news outlets. 20 decisions are known to us from a news report of it. The list last changed on October 4, 2026.
Each case is filed under one kind of problem when it is written, by the rule above; the cases here are the ones filed under it. These cases are not a sample: they show what is published and findable, not how common sales and sharing of health data are.
Each case's id links its line on Real cases, the one address to cite. Every case, every kind of problem, by country: Real cases.
By month and region
all cases that monthcases filed as sold or shareda month not yet overevery panel on the same scale, 0 to 15 cases a month
Africa47 cases, 25 countries and territoriesAmericas89 cases, 29 countries and territoriesAsia76 cases, 25 countries and territoriesEurope187 cases, 47 countries and territoriesMiddle East25 cases, 13 countries and territoriesOceania18 cases, 6 countries and territories
Each bar counts the cases whose source was published that month, October 2024 to October 2026, by region. Pick a kind of problem to see its share of each bar. Counts show what was published and what our searches found, not how often problems happen. October 2026 runs only to October 3, 2026, the newest source date, so its bars are drawn as outlines. Every case as a spreadsheet (CSV).
See the numbers
Cases filed as sold or shared, by month of the source and by region
Month
Africa
Americas
Asia
Europe
Middle East
Oceania
All
October 2024
0
1
0
2
1
0
4
November 2024
0
0
0
1
0
0
1
December 2024
0
1
1
1
0
0
3
January 2025
0
0
0
0
0
0
0
February 2025
0
0
0
0
1
0
1
March 2025
0
0
1
0
0
0
1
April 2025
0
1
3
1
0
0
5
May 2025
0
0
1
2
0
0
3
June 2025
0
0
1
1
0
0
2
July 2025
1
1
0
0
0
0
2
August 2025
0
1
1
0
0
0
2
September 2025
0
2
1
4
0
0
7
October 2025
0
0
1
1
0
0
2
November 2025
0
0
0
1
0
0
1
December 2025
1
0
0
1
0
0
2
January 2026
1
1
0
1
0
0
3
February 2026
2
0
0
2
2
0
6
March 2026
0
0
0
0
0
1
1
April 2026
0
1
0
1
0
0
2
May 2026
0
1
0
0
2
0
3
June 2026
0
1
2
2
2
0
7
July 2026
0
2
0
0
0
0
2
August 2026
2
1
1
0
0
0
4
September 2026
2
0
0
0
1
0
3
October 2026 (so far)
0
0
0
1
0
0
1
All
9
14
13
22
9
1
68
Cases filed as sold or shared, by how settled they are and by region
How settled
Africa
Americas
Asia
Europe
Middle East
Oceania
All
A regulator or court decided
2
9
6
20
4
0
41
The organization admitted the problem
1
0
0
0
0
0
1
Alleged, not decided
6
5
7
2
5
1
26
All
9
14
13
22
9
1
68
Cases filed as sold or shared, by kind of source and by region
Italy's data protection authority found a health data company treated records of about one million GP patients as anonymous when they were personal, processing them without legal basis or patient notice; identifiers of 3,370 patients also slipped through.
After a citizen complained, the Personal Data Protection Authority found a medical centre had emailed information and a document about his medical tests to his employer without valid prior consent or legal basis, and fined it 1,000 dinars.
A civil society leader says the terms of the health data sharing agreement are opaque and asks the ministry to publish them, including whether data sent abroad is anonymised or individual clinical records, and how long it is kept.
An investigative outlet found that a regional authority published online a named list of disabled people holding taxi licences, revealing health information about each person, while the national data protection regulator remains frozen.
A clinic emailed a patient's complete record, covering about fifteen years, to prosecutors without her consent, her representative's approval or a court order. The national health regulator found this broke health law and fined the clinic.
Eswatini signed a US health funding agreement that, under the wider scheme, trades funding for access to pathogen samples and surveillance data. Critics warned the deal could expose the country's health data to abuse.
People close to a military-guarded public hospital in Sagaing Region say staff notify the army when emergency patients arrive, and treatment waits until soldiers and police have checked them, so patient details reach security forces first.
A man brought to a hospital under guard says staff passed his test results to the officers holding him and never gave or explained them to him. He also says the hospital recorded him under another name.
A federal regulator, joined by two states, alleges a telehealth company passed customers' health information to advertising platforms through customer lists and website tracking, despite privacy promises. The case is pending in federal court.
The paper reports that a woman says a health worker disclosed confidential health information about her, and it spread among people around her. A doctor quoted in the piece says confidentiality breaches happen.
Health insurers and their industry union told insured people not to use a non-insurer claims platform, saying its access to patients' medical data breaks the personal data protection law and delays approvals for treatment.
Staff at a public hospital copied patients' identity and contact details from the hospital information system and passed them to unlicensed insurance claims firms for commission. Health Ministry inspectors dismissed staff and suspended a doctor; a criminal investigation continues.
Prosecutors charged two men with paying cryptocurrency for a file of about 20,000 hospital patients' visit and health records stolen by hackers, then advertising hospital data for sale on a messaging app. Prosecutors asked for heavy sentences.
A doctor published a patient's photograph, taken in connection with her care, on social media and advertising platforms without her consent. The Court of Appeals found this disclosed confidential medical information and imposed a fine.
While on sick leave and about to leave a public primary care centre, a doctor viewed 1,231 patients' files in its records system and used their contacts to email and text them. The regulator fined the doctor 1,153 euros.
Officials discussed a person's health history and private life at a press conference. Specialists interviewed said this breached confidentiality standards for health information.
A national cybersecurity notice listed 71 apps breaking personal data rules, including several medical and health apps. Violations included giving personal data to third parties without separate consent, no way to withdraw consent, and missing encryption.
Two television channels broadcast images of a person's medical prescriptions taken from a confidential case file. The constitutional court ruled this violated his privacy, ordered every image removed and made the channels liable for damages.
Security sources told the outlet that hospitals and clinics in Houthi-held areas were linked to a new security unit and pressed to hand over daily details of patients and cases, building a health database on residents.
Callers told the paper that hospital booking lines, staffed from outside the kingdom, asked for ID numbers, birth dates and full patient details before sending them to an app. Security specialists warned of leak and misuse risks.
An unplanned inspection by the Vologda regional health ministry found that the head of an ambulance service had passed data on patients it carried to third parties. He was dismissed and the material was sent to oversight bodies.
Sensitive details from a woman's health record reached third parties without her consent. The data protection regulator found the hospital and her health insurer at fault and ordered five corrective measures, including staff training and stronger confidentiality.
After a South Australian patient spoke publicly about her care, the state health minister's office shared confidential details about her with journalists, the opposition claimed. She says she did not consent.
A Kinshasa outlet reports that Congo joined 14 African countries in US health deals that tie funding to expanded health data systems and fast reporting, while critics warn of lost control over health data and public trust.
A former employee copied every patient's contact details and medical file and used them to invite patients to a competing clinic. The clinic then failed to answer the regulator, which fined it.
A member of parliament's health committee confirmed a security council letter asking medical universities for patients' records after the January protests. He said the health ministry objected in confidential correspondence, citing patient confidentiality.
Doctors' software gathered patients' health data, such as prescriptions and sick leave, with identifiers that allowed care pathways to be traced. The court agreed the data were not anonymous and rejected the company's challenge to an 800,000 euro fine.
BBC reported that a gendarmerie press release quoted a medical certificate from a test that police had ordered on a person in custody, including what it found.
Reports cited by the outlet say security officers checked hospital records of discharged patients and pressed medical staff to report certain patients, and many people avoided hospitals for fear of arrest.
A patient said on television that her discharge record was wrong. A hospital director responded on air with her health details. The data protection commission fined the hospital 10,000 leva, rejecting its consent argument.
The outlet reports that a public hospital published photos of patients undergoing scans, some partly undressed and recognisable, in political messaging. Lawyers and health workers say this breaks the health law's confidentiality rules; no explanation was given.
The regulator found a staff member recorded a patient during treatment and the hospital showed the footage on its screens as promotion. It could not prove consent, so it must pay Sh500,000 and delete the adverts.
An insurer asked for five years of records, to go to the patient first for review. The surgery emailed 23 years straight to the insurer. The patient said their payout was cut. The ICO issued a reprimand.
Reporting a health ministry statement, the outlet says a five-year US funding memorandum includes an agreement to share national health data and biological samples, which the government says will follow national data protection rules.
The national hospital sent an adult patient's sensitive health information to a primary care clinic she was not registered with. The data protection authority ruled the disclosure unlawful; the hospital said it regretted the mistake.
A patient learned during a court case that a hospital report about them had reached third parties. The regulator found the hospital's security manager had copied the electronic record and emailed it to police. The court upheld that finding.
A public hospital released a statement giving health details of a named patient. Lawyers said this broke the patient confidentiality article of the Health Services Act, which allows disclosure only with written consent, a court order or a legal duty.
A complaint said a group of care facilities put a patient's name, photo and care details on its website as a success story. The regulator found the same had happened to 150 patients without valid written authorization.
Reporters found private clinics and health insurers collecting sensitive health and personal data without consent and using it beyond care. Misuse led to one patient's suspension from work and to marketing harassment; regulators fined the sector over four million soles.
A man complained that two doctors issued certificates about his past care to his former wife without his knowledge or consent. The regulator found they processed his health data with no legal basis and reprimanded both.
A doctor's secretary looked up a patient's GeSY account and phoned his father, listed as next of kin, to confirm a booking. The regulator ruled that number was not an alternative contact and reprimanded the doctor.
The national health directorate told government hospitals that pharmaceutical sales representatives may no longer photograph prescriptions, patient information or hospital documents, and warned of legal action against anyone who breaks the rule.
Experts said two regions gave a research project access to 3.65 million people's hospital records without first assessing data protection risks. A regional director said the analysis perhaps should have been done. The regulator opened an inquiry.
Acting on one person's complaint, the data protection authority found that a closing clinic handed clinical files to another clinic without consent or notice, and that both lacked safeguards. It warned both and ordered proof of compliance.
During a workplace illness review, a health insurer sent a patient's complete record, including sensitive test results, to four managers at the patient's employer. The data protection regulator sanctioned the insurer, saying the disclosure had no necessity or relevance.
Patients described being phoned with sales offers soon after hospital discharge. A security expert found patient names, phone numbers and medical history sold cheaply on a messaging app. Some hospitals stayed silent about attacks, the report says.
Following a complaint, the regulator learned that several health facilities sent patient samples abroad for lab work, sharing sensitive personal data. It issued an alert reminding providers that patient consent is required.
The state found a health information website sent identifiers and the titles of articles readers viewed to advertisers, ignored opt-out requests, and ran a consent banner that did not stop tracking. It paid $1.55 million.
Two adult patients said clinics posted images or livestreamed their consultations for promotion without clear consent; one learned colleagues had seen the video. A city health department head condemned the practice, citing confidentiality rules.
A worker was sent by their employer to a medical facility. The facility gave the employer, including the HR department, full consultation notes with past medical history, assuming consent. The regulator found the disclosure unlawful.
Patients left anonymous negative reviews online. Medical practices replied in public, naming the patients and disclosing details from their records. The state regulator listed these among cases where it imposed fines in 2024.
A patient seeking urgent treatment saw a clinician who looked in the national electronic record, learned of a sensitive entry and refused even a basic exam. The patient has sued for discrimination; advocates say any doctor can see everything.
Reporters found some hospital staff and outside contractors selling patients' names, addresses and phone numbers to private companies, about 50 yuan per record. A patient described being contacted by a company that already knew her private details.
The Malaysian Medical Council found a doctor guilty of posting a complainant's personal information on a clinic's Facebook page without written consent, failing to protect patient confidentiality, and suspended the doctor for two years.
The Malaysian Medical Council found a doctor guilty of posting a patient's personal and medical information on a social media account without written consent, against a promise not to reveal it, and issued a reprimand.
The Malaysian Medical Council found a doctor guilty of disclosing a complainant's medical report, without consent, in an affidavit filed in court proceedings against the complainant, and issued a reprimand.
The clinic's director published a patient's X-ray image on her personal social media page. On the patient's complaint, the data protection regulator found the clinic processed health data unlawfully, issued a warning and ordered the post removed.
The regulator's administrator began a second round of payments, over $2.6 million, to customers of an online counseling service. Under a 2023 order, the company paid $7.8 million for sharing email addresses and health questionnaire answers with advertisers.
A relative complained that a hospital head described a patient's health in a live interview with a news site. The commission found this broke the personal data law; the hospital head was warned and the press council asked to review.
A patient sought damages after a doctor published before-and-after photos in a hospital magazine. The appeal court found a confidentiality breach; the Court of Cassation held that patient consent, including implied consent, can lift the duty of secrecy.
Three senior doctors at a Seoul hospital gave drug company staff patients' prescription records, more than 17,000 entries, at the company's request. A court fined the doctors and the hospital's operator for failing to prevent it.
A patient complained that her doctor posted photos taken during her care on his social media page. The regulator ruled that keeping them up after she withdrew consent was unlawful and ordered his consent forms rewritten.
Minas Gerais consumer authority Procon fined a pharmacy chain over stores requiring customers' CPF at the counter. The decision warned hidden profiling of purchases could expose medicine records, for example to insurers refusing cover.
During a civil case he brought against a patient, a doctor passed her medical data to an outside expert without asking her. The tribunal found confidentiality was breached and reprimanded him.
Doctors and clinics posted patients' photos, videos and record details on social media pages. The health ministry referred 333 pages to prosecutors, who blocked them, and cases went to courts and the medical council.
Clinic staff shared a woman's personal and medical details with an outside organisation, which then called and messaged her. The Constitutional Court ruled her privacy was violated and ordered the clinic to apologise publicly and investigate its staff.
People who had been treated at a public hospital received election text messages from a doctor there who was a candidate. He could not show how he got their numbers; the regulator fined him 15,000 euros.
After inspecting eight research projects using health information, the data protection authority gave serious criticism: the university had several times passed personal data on without the required permission and supervised partners poorly. The university said it takes the criticism seriously.