All the latest UK technology news, reviews and analysis

East Surrey Hospital lost details of 800 patients on unencrypted USB stick

by Dan Worth

03 Oct 2011

Comment: 1

  • Tweet this

News has emerged that East Surrey Hospital lost the details of 800 patients stored on an unencrypted USB stick in 2010, in yet another data protection blunder by the NHS.

The incident came to light in the Surrey and Sussex Healthcare NHS Trust's annual report for 2010-2011, seen by local paper Crawley Observer, which also revealed nine other "near misses" where information was lost but later recovered.

V3 contacted Surrey and Sussex Healthcare NHS Trust for comment on the matter but had not received a reply at the time of publication.

The Information Commissioner's Office (ICO) was informed of the incident last year, and a spokesperson said that the Trust was reprimanded over the incidents, although no formal action was taken.

"The ICO warned the organisation that its policy covering the storage and use of personal data must be followed by staff, and the Trust must make sure staff are aware of the policy and are appropriately trained on how to follow it," the spokesperson said.

"The Trust was also warned that any repetition of such an incident may result in formal regulatory action."

Grant Taylor, UK vice president at security firm Cryptzone, described the loss as an "utter disgrace" that highlights poor data protection practices in the NHS.

"Had this been a private company, rather than an NHS Trust, the organisation would have been publicly censured and a large fine levied under the Data Protection Act," he said.

"The fact that this is a government agency that has experienced a total of 10 data loss incidents - and one where the data was not recovered - is highly questionable."

The NHS has one of the worst records for data handling. Recent losses include details on eight million patients on a laptop that was stolen, and 1.6 million details sent to a landfill site on a CD.

Despite this record, no NHS body has been fined by the ICO, although the watchdog revealed last week that more penalty notices are to be issued in the near future.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Related jobs

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

37%

0%

10%

53%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Technischer Consultant

Ihre Aufgaben Sie sind zuständig für die Beratung...

MS Visual Basic Programmierer

***MS Visual Basic Programmierer mit Oracle DB-Erfahrung...

IT Business Analyst

IT Business Analyst Location: London, but...

Senior Software Developer

Senior Software Developer Company overview...

To send to more than one email address, simply separate each address with a comma.