UK: HIV charity has ‘sensitive’ health data stolen
George House Trust, a UK HIV charity, has notified service users that sensitive personal health data may have been stolen following a breach of Beacon CRM, a platform used by more than 1,000 charities and non-profits.
Why this matters: HIV status is about as sensitive as personal information gets. People who shared it with a charity did so because they needed support, not because they consented to it ending up in a breach. The Beacon CRM incident means this is not an isolated failure at one organization — the same exposure likely hit hundreds of other charities, each holding their own category of vulnerable people and private details. When a shared platform goes down, the damage fans out in ways no single charity can control or even fully know. The people affected here had no say in which software their charity chose.
Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.