July 9, 2026: Around 150 women who used maternity services at NHS Forth Valley are learning that a hospital employee downloaded their details from the maternity system and emailed the spreadsheet to a personal inbox—not an NHS account. The health board confirmed the breach to the Falkirk Herald; the UK Information Commissioner's Office is making enquiries.
What happened
The incident centres on the women and children's unit at Forth Valley Royal Hospital in Larbert. NHS Forth Valley said a member of staff transferred a spreadsheet containing an extract of maternity-system data to a personal email address.
The board's public statement is careful: most rows were "unidentifiable," but some lines clearly related to women who had accessed local maternity services. Patients who received letters signed by director of midwifery Mairi McDermid were told the document involved roughly 150 people.
One affected new mother told the Herald the spreadsheet reportedly held her full name, date of birth, address, NHS number, pregnancy treatment details, and how many children she has. She was told the employee was a fully qualified NHS staff member, not a junior—accessing and exporting this class of data to personal email is deliberately difficult inside NHS systems, which is why insiders treat it as a serious GDPR breach.
What data was exposed
Fields varied by patient, but reporting and patient accounts converge on:
- Full names
- Dates of birth
- Postcodes and addresses
- NHS numbers
- Maternity treatment and pregnancy-care details
- Number of children (in at least some rows)
That is special-category health data under UK GDPR—exactly the kind of record you do not want sitting in a personal Gmail or Outlook folder.
What NHS Forth Valley says happened next
The spokesperson said there is no evidence the file was shared more widely "at this stage." The employee told investigators they have deleted the data. NHS Forth Valley also said it cannot say with complete certainty whether copies still exist or were forwarded elsewhere—the hedge matters if you are one of the 150 women notified.
The board contacted affected patients directly and reported the incident to the ICO. NHS Forth Valley told the Herald it also reported the matter to Police Scotland; local officers said they had no knowledge of the case when the newspaper asked. The health board declined to say whether anyone was suspended or facing disciplinary action.
Who is at risk
Anyone who received a letter from NHS Forth Valley about this breach should assume their maternity-care metadata may have left the controlled hospital environment—even if the board believes the personal email copy is gone.
Maternity records are uniquely sensitive: they can reveal pregnancy timing, complications, family size, and postcode-level location. That combination is useful for targeted fraud, stalking, or social-engineering calls pretending to be midwifery follow-up.
What you should do
- Read any NHS Forth Valley letter carefully and keep a copy of what fields they say were involved in your case.
- Be sceptical of unexpected calls or texts referencing your pregnancy, birth, or postnatal appointments—verify through the hospital switchboard or NHS 24, not a number in the message.
- Watch for identity fraud tied to your NHS number or address; report suspicious credit or benefits activity promptly.
- Ask NHS Forth Valley what safeguards changed—personal-email export of maternity extracts should be technically blocked, not merely discouraged.
Regulator response
An ICO spokesperson told the Falkirk Herald: "We have received a report from NHS Forth Valley and are making enquiries." That is early-stage regulatory attention, not a final enforcement outcome—but it signals the board's own admission met the threshold for ICO review.
Canonical record
BreachHistory entry: NHS Forth Valley 2026 maternity spreadsheet breach.
Source: Falkirk Herald (published 9 July 2026).