LIVE · cybersecurity feed
Live wire
data breachmedium

Scot NHS trust probes access to medical records of 9-year-old girl after man arrested on suspicion of murder

NHS Tayside is investigating an alleged data breach involving the medical records of a nine-year-old girl who died earlier this week. The breach reportedly occurred at Ninewells Hospital, where staff may have accessed the child's file without authorization or clinical need. A man has been arrested and charged in connection with the girl's death.

zeroday.news ·

NHS Tayside is investigating an alleged data breach involving the medical records of nine-year-old Minnie Merriman, who died earlier this week. The investigation centers on whether staff at Ninewells Hospital in Dundee improperly accessed her file without authorization or clinical necessity.

Minnie Merriman was publicly identified on Wednesday, following the arrest of a 35-year-old man in connection with her death. The man, who police state was known to the child, appeared in Forfar Sheriff Court on August 5, where he made no plea and was remanded in custody.

The alleged breach reportedly occurred in a clinical area where staff access patient information. NHS Tayside confirmed it is investigating the circumstances and stated that any data protection breach would be recorded, investigated, and, if appropriate, reported to the Information Commissioner’s Office (ICO). The trust declined to comment on the nature of the accessed data or specific staffing matters.

Minnie Merriman was discovered with serious injuries at approximately 00:02 on Monday, August 3, in the Elliot Industrial Estate. She was subsequently transported to Ninewells Hospital, where she later succumbed to her injuries. Police Scotland has indicated they are not seeking additional individuals in connection with her death.

Medical records in the UK are safeguarded under the UK GDPR, as outlined in the Data Protection Act 2018, in addition to common law confidentiality rules. NHS staff are permitted to access patient information only when there is a legitimate clinical or work-related requirement.

Minnie's family, from West Yorkshire and who were camping nearby, are receiving specialist support. In a statement released via Police Scotland, the family expressed their devastation over the loss of their "beloved, absolutely incredible, beautiful and brave Minnie Moo," requesting privacy during this difficult time.

Detective Inspector Mike Ness of Police Scotland’s major investigation team stated that their thoughts are with everyone affected, particularly Minnie's family. He added that a police presence would remain in the area as inquiries continue and urged anyone with concerns or information to contact Police Scotland, quoting incident number 0008 of Monday, August 3, 2026.

data breachhealthcareprivacyunauthorized accessmurder investigation
ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

ai

OpenAI pledges to add Astra security as Anthropic loosens Fable's leash

Or how I learned to stop worrying and love dangerous AI

ai

AI chat bots are sliding into League of Legends friend requests

Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?

security

Meta ordered to pay $942 million over harm to children

A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.

breachcritical

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

icshigh

Ex-NSA Chief Urges Disconnecting Water Controllers from Internet

Following suspected cyberattacks on water systems across at least 12 US states, likely perpetrated by Iran, a former NSA chief has strongly advised that industrial control systems like programmable logic controllers (PLCs) should not be connected to the internet. He emphasized the need for higher cybersecurity standards to defend these critical infrastructure components, noting that Iranian actors have a history and capability for such attacks.