25 Aug 2010
The Information Commissioner’s Office (ICO) has found Royal Wolverhampton Hospitals NHS Trust to be in breach of the Data Protection Act (DPA) following the loss of more than 100 patient records.
An unencrypted CD lacking even basic password protection and containing the sensitive medical records of 112 patients was found at a bus stop near the hospital.
Mick Gorrill, head of enforcement at the ICO, said: "The fact that this information was several years old is of no consequence – patients’ personal data should always be handled in accordance with the Data Protection Act. I am pleased that the Trust has agreed to take remedial steps to ensure such an incident does not happen again."
Mark Fullbrook, UK and Ireland director at Privileged Identity Management and information security expert at Cyber-Ark, said: "With the ICO yet to use its powers to issue heavy fines to organisations in breach of the DPA, the Royal Wolverhampton Hospitals NHS Trust should count itself very lucky.
"What is particularly disappointing in this case is that, with so many better-enabled devices and means of storing information, should this highly sensitive information have really been held and transported by CD? The Trust could not even explain how and why an unprotected CD with patient records was produced in the first place."
The Trust has agreed to sign a formal undertaking agreeing that it will follow DPA guidelines in future. Compliance with the Trust’s policies on data protection and records management will also be regularly monitored.
With staff who know best it is impossible to prevent information being copied onto a disc - remove disc copying drives and they will bring their own portable drives, either disc copying drives or USB flash drives.
Removing USB ports and having read only optical disc drives is the only low level option.
Top this with punitive financial penalties for both miscreants and managers might help.
Posted by: Ben 26 Aug 2010
Have your say on this article
Newsletters
Latest stories from Storage
Latest videos
You may also like
Storage jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?