National Cancer Centre Exposes 467 Email Addresses in Privacy Lapse — And the Data Revealed Could Be More Sensitive Than It Looks

Business

National Cancer Centre Exposes 467 Email Addresses in Privacy Lapse — And the Data Revealed Could Be More Sensitive Than It Looks

A simple email mistake at Singapore’s National Cancer Centre has triggered a privacy investigation after the email addresses of 467 recipients were inadvertently exposed to one another — in a mailing connected to a hereditary cancer condition.

The National Cancer Centre Singapore (NCCS) apologised on Sept. 19 after an invitation to its “Living with Hereditary Breast and Ovarian Cancer” event was mistakenly sent with recipients’ email addresses visible to everyone on the distribution list.

NCCS said the incident was caused by an administrative error and stressed that no NRIC numbers, telephone numbers or other personal data were revealed in the email, apart from the email addresses themselves. The centre said it had notified the Ministry of Health and Singapore’s Personal Data Protection Commission (PDPC), and was reviewing its internal processes.

But the incident has attracted heightened concern because the email was not an ordinary mailing list.

The invitation was for an event involving people with Hereditary Breast and Ovarian Cancer (HBOC) syndrome and their loved ones. HBOC is an inherited condition associated with an increased risk of certain cancers and can affect both women and men.

What happened?

According to reports, the invitation was sent on Sept. 18 to people associated with NCCS’ HBOC programme.

Instead of concealing the recipients from one another using the blind-carbon-copy function, the recipients were reportedly placed in the visible CC field.

That meant people receiving the invitation could see the email addresses of other invitees.

The Straits Times reported that some recipients’ names and, in certain cases, workplaces could also potentially be identified from the information associated with their email addresses. Mothership likewise reported that some recipients were concerned that workplace domains could reveal where individuals worked.

NCCS subsequently sent a follow-up message asking recipients to delete the original email, including from their trash folders, and not to circulate or retain the exposed email addresses, according to the reports.

NCCS said it had contacted affected recipients to provide support and address their concerns.

“We apologise for any anxiety this may have caused,” NCCS chief operating officer and data protection officer Chong Pang Boon said, according to CNA.

Why the email exposure is raising bigger privacy questions

The immediate technical error involved email addresses, but the context of the mailing makes the incident particularly sensitive.

Someone receiving the message could potentially infer that another recipient had a connection to an event specifically concerning hereditary breast and ovarian cancer.

That does not necessarily mean that every recipient was a patient or had the condition themselves: the event was also open to loved ones. But the mailing list itself was associated with people connected to the HBOC programme, making the unintended disclosure potentially sensitive.

The Straits Times reported concerns from recipients that the disclosure could allow people they did not know to associate them with a hereditary cancer condition.

NCCS, however, has specifically stated that the exposed information consisted of email addresses and that other listed personal information such as NRIC numbers and phone numbers was not disclosed.

Singapore’s data watchdog is investigating

The Personal Data Protection Commission has confirmed that it is investigating the incident.

That investigation is important because Singapore’s Personal Data Protection Act requires organisations to put in place reasonable security arrangements to prevent unauthorised access, disclosure and other risks involving personal data.

Under Singapore’s data-breach notification framework, organisations must assess whether a breach is notifiable. A breach can trigger notification obligations when it is likely to cause significant harm to individuals or is considered to be of significant scale.

The PDPC’s guidance states that a breach affecting 500 or more individuals meets the prescribed significant-scale threshold. This incident involved 467 recipients, which is below that particular numerical threshold, although the PDPC can still assess the circumstances and whether other notification criteria apply.

Therefore, it would be premature to describe the incident as a confirmed PDPA violation or to predict what enforcement action, if any, will follow.

The regulator’s investigation will determine the relevant facts.

NCCS promises a review

NCCS said it takes personal-data protection seriously and is conducting a review of its internal processes following the incident.

The centre’s published patient information also states that it respects patient privacy and confidentiality and that medical records are kept confidential, subject to circumstances permitted by law and healthcare operations.

The email incident did not involve the disclosure of medical records, according to NCCS. Instead, the issue concerned the unintended exposure of recipients’ email addresses.

Still, the episode highlights how a basic administrative mistake can create a significant privacy problem when a mailing list itself is connected to sensitive healthcare information.

The bigger lesson for healthcare data

The incident comes as Singapore’s privacy regulator continues to emphasise that organisations need safeguards not only against sophisticated cyberattacks but also against ordinary operational mistakes.

In a 2026 advisory, the PDPC highlighted common data-protection lapses and stressed the importance of reviewing policies and practices, implementing controls and reducing the risk of human error.

For healthcare organisations, the stakes can be especially high because seemingly ordinary information — such as an email address — can become sensitive when combined with the context in which it was collected or disclosed.

In the NCCS case, the central question now is not simply how an email was sent with visible recipients.

It is whether the safeguards surrounding a highly sensitive healthcare mailing were adequate, what corrective measures will be implemented, and whether the PDPC’s investigation finds any breach of Singapore’s data-protection obligations.

For now, NCCS has apologised, affected recipients have been contacted, and the regulator’s investigation remains ongoing.

More in Asia

See all in Asia