All the latest UK technology news, reviews and analysis

ICO raps Manchester hospital and London Ambulance Service after major data breaches

by Dan Worth

07 Sep 2011

Be the first to comment

  • Tweet this
An ambulance in central london

The Information Commissioner's Office (ICO) has chastised a Manchester hospital and the London Ambulance Service for failing to make staff aware of data protection guidelines after the loss of sensitive information on patients.

A student on placement at the University Hospital of South Manchester put details of 87 patients on an unencrypted USB stick for research purposes, but the device was lost when the student moved to another placement in December 2010.

An ICO investigation discovered the hospital assumed the student had received data protection training at medical school, and did not therefore provide training during an induction course.

The hospital has agreed to change its policies to ensure that personal information accessed by staff working at the hospital is kept secure.

Sally Anne Poole, acting head of enforcement at the ICO, said that the case underlines the need for healthcare providers to inform staff of all necessary data protection policies.

"Medics handle some of the most sensitive personal information possible and it is vital they understand the need to keep it secure at all times, especially when they are completing placements at several health organisations," she said.

"NHS bodies have a duty to make sure that staff - permanent and temporary - understand their responsibilities on day one in the job."

Meanwhile, the London Ambulance Service has signed an undertaking with the ICO after a contractor breached the Data Protection Act when a personal laptop containing information on 2,664 patients was stolen from his home.

The Service has agreed to change its policies so that all staff know that personal devices must not be used to store sensitive information.

Poole said that both cases highlight a continuing need for the ICO to liaise with public health organisation to make them aware of their data protection obligations.

"We will continue to work with healthcare bodies and education providers to make sure data protection training is a mandatory part of people's education," she added.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

12%

56%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Project Manager - Credit Risk - Finance IT - Investment Bank

Project Manager - Credit Risk - Finance IT - Investment...

Infrastructure Configuration Manager/Analyst/Data Modeler/IB

Infrastructure Configuration Manager/Analyst/Data Modeler...

Lead Perl Developer, Apache, SQL, Unix/Linux, INVESMENT BANK

Lead Perl Developer, Apache, SQL, Unix/Linux, Shell Scripting...

Perl Developer, Web and JEE App Servers, INVESTMENT BANK

**Perl /Java Developer, Web/ JEE application servers...

To send to more than one email address, simply separate each address with a comma.