batamon-real-estate-assistant

Singapore Data Privacy Lapse: National Cancer Centre Email Exposes 467 Recipients’ Details

The e-mail sent on Sept 18 was an invitation to an NCCS event. Instead of using the BCC function to send the e-mail, which keeps recipients hidden, the CC function was used. ST PHOTO: KUA CHEE SIONG
The e-mail sent on Sept 18 was an invitation to an NCCS event. Instead of using the BCC function to send the e-mail, which keeps recipients hidden, the CC function was used. ST PHOTO: KUA CHEE SIONG
batamon-admin-executive

Administrative error revealed email addresses and some workplaces linked to hereditary cancer condition.

A routine event invitation from Singapore’s national cancer center has triggered a privacy investigation after recipients could see identifying information belonging to hundreds of others associated with a hereditary cancer condition.

Email Exposes Hundreds of Recipient Addresses
The National Cancer Centre Singapore (NCCS) apologized after an email sent on September 18 exposed recipient email addresses because the CC function was used instead of BCC. NCCS described the incident in a follow-up email as an administrative error affecting email addresses.

Invitation Linked Recipients to Hereditary Cancer Event
The email invited recipients to a Living with HBOC event scheduled for October 31. HBOC refers to hereditary breast and ovarian cancer syndrome. Because recipients could see other email addresses, names could be identifiable, while workplace domains also revealed some recipients’ employers. The invitation was sent to individuals associated with the condition through NCCS.

NCCS Says No NRIC or Phone Numbers Exposed
Chong said the lapse exposed email addresses but did not reveal NRIC numbers, phone numbers, or other personal data. NCCS later contacted recipients and asked them to delete the original invitation from their inboxes and trash folders, not circulate it further, and avoid using or saving the email addresses contained in the message. One recipient told The Straits Times that the email was recalled about two and a half hours after being sent.

Recipient Raises Concerns Over Sensitive Information
One affected recipient told The Straits Times that the visible email domains included companies, foreign embassies, and schools, and expressed concern that the mailing list connected identifiable individuals with hereditary cancer screening or counseling. The recipient also raised concerns about possible future consequences involving employment or insurance. These concerns were expressed by the recipient and have not been reported as having resulted in any confirmed harm.

PDPC Investigates as NCCS Reviews Processes
NCCS reported the incident to the Ministry of Health and the Personal Data Protection Commission (PDPC) and said it was reviewing internal processes to prevent a recurrence. The PDPC separately confirmed that it was aware of the incident and had begun an investigation. NCCS also said it had contacted recipients to provide support and address their concerns.

The NCCS incident shows how a simple administrative email error can expose information linked to sensitive healthcare circumstances. For Singaporeans, the PDPC investigation will determine how the case is handled under the country’s data protection framework. For Indonesians following healthcare and privacy developments in neighboring Singapore, the case also provides a regional example of the risks involved when sensitive patient communications are improperly distributed.

Sources: Straits Times (2026) , Mothership (2026)

Keywords: NCCS Email Lapse, Singapore Data Privacy, National Cancer Centre Singapore, HBOC Singapore, Patient Data Exposure, PDPC Investigation

Share this news:

edg-travel

Also worth reading