HIV charity warns users after database vendor breach

George House Trust warned users their health information may have been stolen in a breach of a charity database platform used by more than 1,000 organizations.

MedRisk Staff
By
2 Min Read

A Manchester charity for people living with HIV has told its users that “sensitive and personal” health information may have fallen into the hands of hackers.

George House Trust, which has supported thousands of people with HIV since 1985, said in an email seen by the BBC that the material had been downloaded but not published, and that there was no sign of misuse. Addresses, emails, telephone numbers, and notes on users’ engagement with the charity were on the affected database.

The incident traces back to Beacon, a supplier whose database platform serves more than a thousand UK charities. The company says the breach occurred at the end of July, that external experts were brought in immediately, and that it is helping every organization affected; up to 1,500 charities may be caught up in the incident.

George House Trust learned about the compromise from Beacon on August 3 but waited about three weeks before notifying users, saying it wanted a fuller understanding of the situation first.

The episode is a reminder that a single supplier compromise can ripple across hundreds of charities holding sensitive health data. Organizations that manage HIV-related records should pressure vendors on incident timelines, verify what data is stored on shared platforms, and rehearse their own notification plans before a breach forces the issue.

Share This Article