The details of 18,000 people in Wales who tested positive for coronavirus were leaked publicly due to human error. On August 12, the information was published on the Public Health Wales website, where it was exposed for several hours before being removed.

Public Health Wales chief executive Tracey Cooperissued a public apology for the leak and sought to reassure the public that steps have been taken to prevent a similar incident in the future.
The data, which involved personal details of 18,105 Welsh residents who had tested positive for coronavirus between February and August this year, including 2,800 people from Gwent, was visible for around 20 hours before being taken down from the site.
The agency has received eight recommendations for actions to prevent such a breach in the future, which it has fully accepted.
These recommendations include measures for regular process audits, accountability for information processing, and regular review of pandemic and whether adequate resources are available for this purpose.

The research was conducted by Darren Lloyd, head of information governance at NHS Wales Informatics Service, and John Sweeney, information sharing and governance manager at NHS Wales.
"We continue to work to ensure that our people, who have the greatest responsibility to meet the demands of the pandemic, receive the support and resources they need," the agency said.
There is no evidence at this stage that the data was used for malicious purposes. However, anyone who is concerned that their data or that of their family members may have been compromised and would like advice should read the ‘frequently asked questions’ at www.phw.nhs.wales and then email PHW.data@wales.nhs .uk if they have any further questions.
