Hospital faces £375,000 ICO fine after data sold on eBay

By Derek du Preez

16 Jan 2012

Comments: 4

Nurses at NHS hospital

The Information Commissioner's Office (ICO) is considering hitting a hospital with its heaviest fine to date following the theft of unencrypted hard drives from the Brighton and Sussex General in September 2010.

According to the Argus newspaper, 232 hard drives were stolen, out of 1,000 that were to be decommissioned.

Further reading

The hard drives were stolen by a contractor, and some of them subsequently turned up for sale on auction site eBay.

The BBC has reported that the Information Commissioner was considering levying £375,000 on the hospital.

The hospital has said it will challenge the proposed penalty.

This move follows the ICO's commitment earlier this month to focus its data protection work on the health and criminal justice sectors.

The ICO was granted the power to issue fines of up to £500,000 for breaches of the Data Protection Act in April 2010, but the penalties had been relatively minor until recently.

This appears to be changing though; just four weeks ago, it issued a fine to Powys County Council of £130,000 – its biggest fine to date – for failing to protect the personal data of vulnerable young people.

Reader comments

Contractor prosecuted?

They haven't named the contractor or whether they were prosecuted for the 'crime'. Were they WEEE compliant?

Posted by: Ray Bugg  17 Jan 2012

The government fines the government

If it weren't so sickening it'd be funny - how many kicks in the teeth for the taxpayer?

Kicking #1: ordinary tax payers have their data compromised by the NHS, a public sector organisation.

Kicking #2: the NHS gets fined by a public sector quango for the data breach. The taxpayer picks up the bill.

Kicking #3: hospital services deteriorate as vital cash is lost to fines. Maybe someone dies because doctors and nurses are being laid off.

Kicking #4: the taxpayer picks up two sets of legal bills as the government effectively sues itself.

You could not make it up - staggeringly, utterly pathetic. The ICO's decision to 'focus on the health and criminal justice sectors' adds up to a decision to back off industry - the one place that might be able to afford to pay the fines.

Posted by: Jamal Housseini  16 Jan 2012

Right attitude, wrong penalty

I think the ICO is absolutely right to take the Hospital to task for this. It's totally unacceptable to make this kind of mistake. However, fining the Hospital just doesn't help. They are already stretched and will be forced to cut further corners - and the public end up paying the fine. Sack the Executive responsible, no bonus, no payoff, just dimissal for gross misconduct.

Posted by: Eddie Humphries  16 Jan 2012

Scure the hard drives if not used

Sadly there are too many unused hard drives laying around that should be in use, securely locked away or decomissioned/wiped.

shamless plug: www.bustadrive.com, cheapest solution for onsite destruction, £249.00.

Posted by: Alan  16 Jan 2012

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

  • Digg
  • Tweet

Newsletters

Sign up for our FREE newsletters

Technology Patent Wars

Large companies such as Microsoft, Facebook and Google have been hoovering up technology patents recently. Is this stifling innovation?

88 %

4 %

8 %