Mamata Banerjee is demanding answers about the disclosure of her medical records, while Daiwa Securities and Osaka Metropolitan University report separate data and systems incidents.
Two different questions about sensitive information are drawing scrutiny: who authorized the release of a politician’s medical records in West Bengal, and what happened to data held by organizations affected by separate technology incidents in Japan. The available reporting offers specific details, but it does not establish that all information at issue was publicly disclosed or misused.
In West Bengal, Mamata Banerjee’s lawyer sent an email notice seeking explanations from officials at SSKM Hospital, the Bangur Institute and the state Health Department over how Banerjee’s 2021 medical records reached Suvendu Adhikari and were made public, The Telegraph reported October 5. The notice asks whether Banerjee consented to the release, whether a court order authorized it and whether the documents circulated were originals.
The Statesman reported that the notice also calls for an inquiry into possible alteration or manipulation of the records and cites India’s Digital Personal Data Protection Act, 2023. The published accounts do not provide the records themselves, establish how they were obtained, or report a response from the named institutions addressing the notice’s questions. Those gaps leave the central accountability issue unresolved: what authority, if any, permitted access and disclosure.
Adhikari, who has made the records public, responded that Banerjee was “making a mistake” by pursuing the matter, The Statesman reported. He warned that additional X-ray and MRI reports could be released and asked the Health Department to forward her complaint to him. The threat of further disclosure underscores why the questions of consent, authorization and record integrity matter; it does not, on its own, establish whether the initial release was lawful or how the documents were handled.
A separate incident at Japanese securities firm Daiwa Securities involves records held by a contractor. Nikkei Asia reported that unauthorized access took place at Scala Communications between October 2 and October 3. The potential exposure covers about 220,000 records, including names, email addresses and account numbers for roughly 110,000 customers.
As of October 5, Daiwa had not confirmed that the information was publicly disseminated or that unauthorized transactions occurred, according to ASCII.jp. The company said the exposed data alone could not be used to access securities accounts or conduct online trades. That distinction is material: a potential exposure is not proof of public circulation, account access or financial loss. The reported intrusion occurred at the contractor, not Daiwa’s own systems.
At Osaka Metropolitan University, a separate system failure has disrupted campus operations. The university said its medical school hospital’s electronic medical records were unaffected and clinical care continued normally, Sankei Shimbun reported. Classes across the university were suspended through October 8, with reopening planned for October 9.
Some reports have described the university disruption as a suspected ransomware attack and cited a possible leak of personal information. But the available confirmed information here does not establish the cause or verify a number of people whose data may have been affected. The university’s statement about unaffected hospital records and continuing care should not be stretched into a conclusion about every campus system or whether other data was involved.
Across the three cases, the evidentiary lines are different. Banerjee’s notice poses questions officials have yet to answer; Daiwa has acknowledged contractor-side unauthorized access while disputing what the exposed data could enable; and Osaka Metropolitan University has confirmed disruption while saying hospital records were not affected. Further conclusions depend on records, investigation results and direct answers from the institutions responsible.

