The National Cancer Centre Singapore (NCCS) has apologised after an email invitation intended for 467 people was mistakenly sent with recipients’ email addresses visible to one another, raising concerns over the privacy of individuals linked to a hereditary cancer condition.
The email was sent on Sept. 18 as an invitation to an NCCS event for people living with hereditary breast and ovarian cancer (HBOC) syndrome and their loved ones. Instead of placing recipients in the blind carbon copy, or BCC, field, the centre used the regular carbon copy, or CC, function.
That meant recipients could see the email addresses of other people on the mailing list. In some cases, the addresses also revealed the organisations where recipients worked, potentially allowing others to infer their connection to hereditary cancer screening or counselling.
NCCS chief operating officer and data protection officer Chong Pang Boon described the incident as an administrative error. He said no NRIC numbers, phone numbers or other personal data were disclosed apart from the email addresses.
The centre said it had contacted recipients to offer support and address concerns. It also asked recipients to delete the original email and not circulate, use or save the addresses contained in it.
The incident is particularly sensitive because HBOC is an inherited condition commonly associated with mutations in genes such as BRCA1 and BRCA2. People with certain inherited mutations can face increased risks of several cancers.
NCCS said it has reported the incident to Singapore’s Ministry of Health and the Personal Data Protection Commission (PDPC), while reviewing its internal processes to prevent a similar mistake from happening again. The PDPC has confirmed that it is investigating the incident.
The case highlights how even a simple email-setting mistake can become a significant privacy issue when a mailing list is connected to sensitive medical information. Although the centre said no medical records or other listed personal identifiers were exposed, the visible addresses themselves could reveal a recipient’s association with a hereditary cancer programme.
The bigger question now is what further action may follow from the investigation — and whether the incident will lead to tighter safeguards for communications involving sensitive healthcare information.