Scottish NHS trainers to boost security after breach
NHS Education for Scotland promises the ICO that it will encrypt its laptops and mobile devices, after thousands of records were lost.

NHS Education for Scotland (NES) will improve its data security, after an unencrypted laptop was stolen that contained the personal information of more than 6,000 medical training applicants.
NES informed the Information Commissioner's Office (ICO) about the breach in late 2008. It resulted in the loss of names, addresses, phone numbers, summaries, as well as the equality and diversity monitoring information of the applicants.
The details were in a SQL database file, and was going be used to test a development version of a medical recruitment website.
The data was not encrypted, as the laptop wasn't intended to be taken off NES premises, and not considered a mobile device' at the time.
As a result, NES has signed an undertaking with the ICO, which among with other demands promised it would encrypt mobile devices and make staff aware of personal data policies.
"Safeguarding sensitive personal information is an important principle of the Data Protection Act," said Ken MacDonald, the assistant information commissioner for Scotland, in a statement.
He added: "This case serves as a reminder that all organisations and their executive teams need to ensure that data protection is treated as an important part of corporate governance."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
Nearly half of enterprises aren't prepared for quantum cybersecurity threats
News Most businesses haven't even started transitioning to post-quantum cryptography, research shows
-
What businesses need to know about the General-Purpose AI Code of Practice
News General-purpose AI model providers will face heightened scrutiny
-
23andMe 'failed to take basic steps' to safeguard customer data
News The ICO has strong criticism for the way the genetic testing company responded to a 2023 breach.
-
Two more NHS Trusts have been hit with cyber attacks – here’s what we know so far
News A flaw in a third-party device management tool appears to be the source of the incident
-
NHS England launches cyber charter to shore up vendor security practices
News Voluntary charter follows a series of high-profile ransomware attacks
-
NHS supplier hit with £3m fine for security failings that led to attack
News Advanced Computer Software Group lacked MFA, comprehensive vulnerability scanning and proper patch management
-
Cyber attack delayed cancer treatment at NHS hospital
News A cyber attack at Wirral University Teaching Hospital in 2024 delayed critical cancer treatment for patients, documents show.
-
Alder Hey Children’s Hospital confirms hackers gained access to patient data through digital gateway service
News Europe’s busiest children’s hospital confirmed attackers were able to steal data from a compromised digital gateway service
-
Major incident declared as Merseyside hospitals hit by cyber attack
News The incident, which has led to cancelled appointments, is just the latest in a series of attacks on healthcare organizations
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data