Case Library / Physical Social Engineering (Tailgating & Baiting) / Doorstep Dispensaree: Unsecured Patient Records Found in a Pharmacy's Back Yard Trigger the ICO's First GDPR Fine (2019)

Doorstep Dispensaree: Unsecured Patient Records Found in a Pharmacy's Back Yard Trigger the ICO's First GDPR Fine (2019)

An MHRA search warrant unrelated to data protection stumbled on an estimated ~500,000 (later found to be far fewer) care-home patients' hard-copy prescription and NHS records left rotting in unlocked crates, bin bags and a cardboard box in the open rear yard of a London pharmacy supplier, triggering the ICO's first-ever GDPR fine.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Doorstep Dispensaree Ltd, a London-based pharmacy wholesaler that MHRA/ICO's original estimate said supplied medicines to about 78 care homes (a figure later found by the First-tier Tribunal to be an overstatement: DDL's actual dispensing contracts covered no more than 27 care homes as of July 2018, falling to 15 by September 2019), was found to have stored hundreds of thousands of hard-copy patient documents (an MHRA estimate later substantially revised down on appeal), consisting of names, addresses, dates of birth, NHS numbers, medical information and prescriptions dated June 2016 to June 2018, in unlocked crates, disposal bags and a cardboard box in the open rear yard of its premises at 75-79 Masons Avenue, Harrow (the company traded from the Edgware/Burnt Oak Broadway area of North-West London). The exposure was discovered on 24 July 2018 when the Medicines and Healthcare products Regulatory Agency (MHRA) executed a search warrant at the site for an unrelated medicines-regulation investigation and found 47 stacked unlocked crates plus disposal bags/boxes of paperwork, some of it visibly water-damaged or mouldy, none marked as confidential waste. MHRA alerted the Information Commissioner's Office (ICO) on 31 July 2018. Following an information notice, a notice of intent, and written submissions, the ICO issued Doorstep Dispensaree a Monetary Penalty Notice of £275,000 and an Enforcement Notice on 17 December 2019, the first fine ever issued by the UK ICO under the GDPR/Data Protection Act 2018, for breaches of Articles 5(1)(f) and 5(1)(e) (integrity/confidentiality and storage-limitation principles), 24(1) (controller responsibility) and 32(1)-(2) (security of processing), plus defective privacy notices under Articles 13-14. The company challenged the penalty; the First-tier Tribunal in 2021 found the true document count was far smaller than MHRA's initial ~500,000 estimate and cut the fine to £92,000 while upholding the Enforcement Notice, a result subsequently affirmed on further appeal by the Upper Tribunal (2023) and the Court of Appeal (9 December 2024).

How the Attack Worked

This was not an attacker-executed social engineering operation but a records-security failure that created a live social-engineering/identity-theft exposure risk of the kind the "discarded/insecurely stored physical records" variant is meant to illustrate. Doorstep Dispensaree Ltd, a London pharmacy wholesaler that MHRA/ICO's original estimate said supplied medicines to roughly 78 care homes (a figure the First-tier Tribunal later found was overstated: DDL's actual dispensing contracts covered no more than 27 care homes as of July 2018, falling to 15 by September 2019), accumulated years of hard-copy paperwork (dated between June 2016 and June 2018) covering dispensing and prescription records for elderly, vulnerable care-home residents. Instead of destroying this paperwork as confidential waste or storing it under lock and access control, the company (and/or its waste-disposal contractor, Joogee Pharma Limited, a licensed waste-disposal firm the Court of Appeal confirmed was wholly owned by the same sole director/shareholder as Doorstep Dispensaree, Sanjay Budhdeo, rather than an independent outside vendor) left the documents piled in the open rear yard/courtyard of its premises: 47 stacked unlocked crates, two disposal bags, and a cardboard box, none marked "confidential waste," some visibly soaking wet or mouldy from prolonged exposure to the weather. The documents contained patients' full names, home addresses, dates of birth, NHS numbers, medical information, and prescription details, exactly the kind of special-category personal data that enables identity theft, medical-identity fraud, and highly convincing pretexting/impersonation attacks against vulnerable elderly individuals or their families. The exposure was discovered not by the company or a whistleblower but by sheer coincidence: the UK Medicines and Healthcare products Regulatory Agency (MHRA) executed an unrelated search warrant at the premises (75-79 Masons Avenue, Harrow, Middlesex) on 24 July 2018 as part of a separate criminal investigation into the company's medicines-handling practices, and in doing so physically found the unsecured records in the yard.

The Lure & the Tell

There was no deceptive lure in the conventional social-engineering sense: no attacker crafted a pretext to obtain the records. The "tell" that exposed the failure was entirely incidental: MHRA investigators executing a search warrant for an unrelated medicines-regulation matter physically walked into the rear yard and found stacks of unlocked crates and bags of patient paperwork sitting in the open, some already water-damaged, none marked as confidential waste. MHRA notified the ICO of what it had found on 31 July 2018, which opened the data-protection investigation. In effect, the "tell" was simply that unsecured, undisposed sensitive records left in a publicly accessible outdoor space are trivially discoverable by regulators in this case, but just as easily by anyone with casual physical access, which is the core lesson of this variant.

Outcome

The ICO issued a Monetary Penalty Notice of £275,000 and an accompanying Enforcement Notice against Doorstep Dispensaree Ltd on 17 December 2019, the first fine issued by the UK ICO under the GDPR/Data Protection Act 2018 (the notice was formally announced/published around 19-20 December 2019). The Enforcement Notice required the company to appoint an information governance lead/DPO, roll out mandatory staff training, and bring its privacy notices and retention/destruction policies into compliance within three months. Separately, the MHRA's own criminal medicines investigation into the company concluded on 26 November 2019 with no further action for insufficient evidence of a reasonable prospect of conviction. Doorstep Dispensaree appealed the MPN; the First-tier Tribunal (18 August 2021) found the true audited scale of exposed documents was materially smaller than MHRA's original ~500,000 estimate (accepting figures in the tens of thousands, with roughly 53,871 documents containing special-category data) and reduced the fine to £92,000 while upholding the Enforcement Notice in full. Doorstep Dispensaree continued appealing; the Upper Tribunal ([2023] UKUT 132 (AAC)) and then the Court of Appeal (9 December 2024, [2024] EWCA Civ 1515) both rejected the company's further challenges, finally settling the case at a £92,000 fine plus the Enforcement Notice, over five years after the original discovery. Companies House records show Doorstep Dispensaree Limited is now in liquidation.

Why It Matters

This case is the canonical UK/EU example that GDPR "appropriate technical and organisational security measures" obligations apply just as much to paper records as to digital systems, and that basic physical security failures (unlocked, unmarked, weather-exposed storage of sensitive health data) can trigger the same scale of regulatory penalty as a cyberattack. It also established that a data controller cannot discharge its security obligations merely by pointing to a waste-disposal contractor, here a commonly-owned firm rather than an arm's-length vendor: the ICO and tribunals held Doorstep Dispensaree, not the contractor, primarily liable as the controller. For social-engineering and physical-security education specifically, the case demonstrates the upstream failure mode this repository's "discarded/insecurely stored physical records" variant targets: troves of names, NHS numbers, addresses and medical/prescription detail sitting in publicly accessible outdoor space are exactly the raw material used downstream for identity theft, targeted phishing/vishing, and impersonation scams against elderly and vulnerable people (and their families), even though in this instance the exposure was caught by a regulator before any known criminal exploitation occurred. The five-year appeal saga (2019 ICO fine to 2024 Court of Appeal) also became a leading precedent on burden of proof and evidentiary standards in UK data-protection appeals more broadly.

Defenses

Basic controls that would have prevented this: locked/access-controlled storage for hard-copy patient records; use of certified confidential-waste destruction rather than ad hoc disposal via a third-party processor; a documented, GDPR-compliant records retention and destruction policy (Article 5(1)(e)); a Data Protection Officer/Information Governance lead; up-to-date, non-template privacy notices (Articles 13-14); and periodic internal audits of physical document handling akin to those applied to digital systems. The ICO's Enforcement Notice specifically ordered Doorstep Dispensaree to appoint an information governance lead, introduce mandatory staff training, and update policies within three months. The case is widely cited as the regulatory baseline showing that GDPR "security of processing" duties (Art. 5(1)(f), 24(1), 32) apply equally to paper records as to IT systems, and that outsourcing disposal to a waste contractor does not shift controller liability.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Waste-stream targeting: this incident had no attacker, but the exposure risk it created matches a well-documented pattern in which opportunistic actors (dumpster divers, casual trespassers, or waste-industry insiders) scout pharmacy, healthcare, or care-home waste streams specifically because they are likely to contain high-value special-category data such as NHS numbers and prescription details, rather than searching at random.
Countering Stage 1: Businesses cannot control which categories of waste attract opportunistic scouting, so the realistic control is not hiding that pharmacy/care-home waste is high-value, but ensuring it never reaches an unsecured state in the first place, the control addressed at Stage 2.
2
Physical acquisition: with the crates, disposal bags, and cardboard box left unlocked, unmarked as confidential waste, and sitting in an open rear yard accessible from neighboring residential property, anyone with casual physical access, not just the MHRA investigators who actually found them, could have walked away with documents undetected.
Countering Stage 2: Locked, access-controlled storage for hard-copy patient records and certified confidential-waste destruction with a documented chain of custody (exactly what the ICO's Enforcement Notice and Article 5(1)(e)/32 required here) would have prevented casual physical access entirely.
3
Data extraction and victim profiling: names, addresses, dates of birth, NHS numbers, and prescription/medical details on the recovered paperwork would typically let an opportunistic actor build ready-made victim dossiers, and cross-referencing against the fact the records trace to care-home patients would likely flag the group as disproportionately elderly and vulnerable, a profile associated with higher susceptibility to fraud and lower likelihood of quickly detecting misuse.
Countering Stage 3: Data minimization and a documented retention/destruction schedule mean sensitive documents are pulped or shredded soon after they stop being needed, rather than accumulating for two years, which shrinks both the volume and the age of any data available for profiling.
4
Pretext construction: accurate personal and medical details of this kind are the raw material commonly used to build convincing impersonation pretexts, for example posing as the pharmacy, a GP surgery, or NHS services and citing a victim's real prescription or NHS number to establish false legitimacy on a call or letter.
Countering Stage 4: Patient and care-home staff education that a pharmacy, GP surgery, or NHS body will never need to 'confirm' a full NHS number, address, or prescription detail that the recipient already provided, plus caller-verification protocols on the pharmacy/care-home side, blunts pretexts built on stolen record fragments.
5
Contact and exploitation: consistent with known elder-fraud patterns, such a pretext would typically be used to contact victims or their families by phone, mail, or door-to-door visit to extract further sensitive data (banking details, one-time passcodes) or directly initiate fraud, such as unauthorized prescription redemption or benefit/identity-theft applications in the victim's name.
Countering Stage 5: Family/caregiver awareness training for elderly and vulnerable individuals about vishing and mail fraud, combined with a policy of verifying any unexpected medical or billing contact via a known callback number, reduces the odds a well-informed pretext leads to further data or money being handed over.
6
Monetization and objective completion: the end state this kind of exposure enables is durable identity-theft/fraud value, cashing out via fraudulent credit or loan applications, medical-identity fraud, or resale of the profiled records on fraud forums, though in this specific case no such downstream criminal exploitation has been publicly confirmed, since the records were discovered and seized by a regulator before any known misuse.
Countering Stage 6: Prompt, accurate breach notification, undermined here by the fact the controller could not even confirm how many people were affected, plus bank/credit fraud-alert monitoring for known-affected individuals, is the last practical backstop once profiled data is already circulating.
Quick Facts
Victim
Doorstep Dispensaree Ltd (UK pharmacy/medicines supplier to care homes); indirectly, an estimated tens of thousands of care-home residents whose NHS and prescription records were exposed
Location
Harrow / Edgware, North-West London, United Kingdom
Date
2018-07-24 (MHRA search warrant); 2019-12-17 (ICO Monetary Penalty Notice)
Impact
Initial ICO Monetary Penalty Notice: £275,000 (issued 17 December 2019, reduced by the Commissioner from an original Notice of Intent figure of £400,000 in light of the company's financial position). On appeal, the First-tier Tribunal (18 August 2021) reduced the fine further to £92,000 after finding the actual audited document count (roughly 73,719 total documents seized, of which the tribunal found approximately 66,000 contained personal data: about 12,491 personal-data-only plus roughly 53,871 special-category/medical data documents, figures that reflect some internal rounding in the tribunal's own arithmetic) was far below the MHRA's original estimate of ~500,000; the Enforcement Notice was upheld in full. The Upper Tribunal ([2023] UKUT 132 (AAC)) and the Court of Appeal (9 December 2024, [2024] EWCA Civ 1515) both dismissed Doorstep Dispensaree's further appeals, leaving the £92,000 fine and Enforcement Notice standing. No customer/patient financial loss has been publicly attributed to this specific cache of exposed records; the company (Doorstep Dispensaree Limited, Companies House no. 09634666) is now shown as in liquidation.
Status
Confirmed
Case Type
Real-World Incident
Sector
Healthcare
Related

Related Cases

Rapid7 'Blank Badge' Physical Penetration Test: Tailgating, Door-Reciprocity, and a Fake New-Employee Help-Desk Pretext

A Rapid7 penetration tester tailgated into a client's building using door-holding reciprocity and a cloned-looking badge, rode an elevator up…

Incident 2018Read →

Yujing Zhang Mar-a-Lago Intrusion

A Chinese national talked her way past three layers of Mar-a-Lago's Secret Service and club-staff checkpoints using a false pool…

Incident 2019Read →

New Jersey Life-Insurance-Beneficiary Pretexting of Elderly Widows/Widowers

An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their…

Incident 2020Read →