An NHS hard drive that turned up on eBay was found to contain patient data despite having supposedly been wiped.
The Dudley Group of Hospitals NHS Trust claimed that it was unaware of how the hard drive containing details of cancer patients found its way onto the auction website, as it was supposed to have been overwritten by private contractors.
"There is an ongoing investigation into this incident involving very senior people and we are looking at possible loopholes in the system," said the trust in a statement.
"There is no record of this machine going through the systems that Siemens has in place for disposing of equipment. We cannot have something like this happening again."
A spokesman for the Trust said that it is trying to trace the route the drive took to eBay, which includes "the possibility of theft".
The discovery was made as part of a research project sponsored by BT, which aims to highlight the problem of personal data falling into the wrong hands.
BT buys hundreds of second-hand hard drives each year from different sources and passes them on to the University of Glamorgan. Researchers then search the drives to try and reconstruct the data.
The NHS Trust pays Siemens Medical Solutions to dispose of old IT systems under a Private Finance Initiative deal, and the work is sub-contracted to Computer Disposals.
Drives holding information should be overwritten at least three times to meet government standards.
The Trust and Siemens have now put forward recommendations to prevent confidential information being leaked in future.
A meeting of the Trust board is expected to authorise the use of a degausser to ensure that drives are wiped before they leave hospital premises.
Alongside the data from the hospital trust, the hard drive also contained financial information, company records, North Sea drilling information from Texas-based Marathon Oi, and paedophile material which has been handed to police.
Other parts of the scheme are broadly on track, but software delays mean care records will be four years late, says NAO 16 May 2008
Computing’s web seminars on managing risk answered your questions to help make sure your company is not headed for disaster 15 May 2008Advertising Marketplace
- Enterprise Accounting Solutions
- Business Intelligence Solutions
- Enterprise Content Management (ECM)
- Supply Chain Management
- Enterprise Resource Planning (ERP)
- Project Management Solutions
- Customer Relationship Management (CRM)
- Security Solutions
- Systems Management
- Networking and Communications Solutions




