← Back

NHS Data Breach History

Government
Website

The National Health Service (NHS) is the publicly funded healthcare system of the United Kingdom.

This page shows all data breaches of NHS. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.

6Total breaches
25.2MRecords breached
August 2026Last breach
51 AI Breach Risk score High

Data Breach Timeline — All NHS Breaches

NHS Data Breach Summary

This page tracks the NHS data breach history and cybersecurity incidents affecting NHS. BreachHistory currently indexes 6 publicly disclosed or catalogued incidents spanning 2010 through 2026, with approximately 25.2 million records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.

The NHS breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed.

Largest NHS Data Breaches

The largest indexed incidents include the 2011 — NHS: A laptop holding the unencrypted records of eight…, the 2011 — NHS: Lost / stolen device, 8,300,000 records, and the 2010 — NHS: A laptop holding the unencrypted records of eight…. Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by NHS or a regulator. Below is the list of large data breaches:

What Information Was Exposed?

Depending on the incident, exposed data may include names, health and medical (PHI) records, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.

NHS Data Breach 2026

At the time of this update, BreachHistory catalogues 1 2026 incident related to NHS. Most recent entry: 2026 NHS — admits transplant patient data sent over unencrypted pagers (BBC investigation). New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.

What To Do If You Were Affected

If you believe your account may have been involved in a NHS data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.

This NHS breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.

Report a breach for this company