NHS Trust leaves medical data at bus stop
Yet another NHS organisation has been rapped by the ICO for losing sensitive data.
Royal Wolverhampton Hospitals NHS Trust has been found in breach of the Data Protection Act after leaving a CD at a bus stop.
The CD, which contained scans of 112 patient records from the Intensive Care Unit of New Cross Hospital's Heart and Lung Unit, was found at a bus stop near the hospital.
The Information Commissioner's Office (ICO) was informed that the CD had neither password protection. Nor was it encrypted.
In an investigation into the incident, neither the ICO nor even the Trust were able to establish where the CD had come from or why it had been made.
"The fact that this information was several years old is of no consequence patients' personal data should always be handled in accordance with the Data Protection Act," said Mick Gorrill, head of enforcement at the ICO.
The trust has agreed to take remedial measures to ensure a similar incident does not reoccur.
The NHS is now infamous for misplacing sensitive data. In May, it emerged more than 1,000 data breaches involving personal data had been reported to the ICO, with the NHS ranked as a top offender.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
To date, no financial penalty has been levied on the organisation. The trust has not issued any statement following its censure by the ICO, but in its own annual accounts it admitted to nine data loss incidents in the 2009-2010 financial year. None, though, qualified as "Serious Untoward Incidents", in NHS parlance.
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
The business guide to Windows 11In-depth As Windows 10's mainstream support ends, it's time for businesses who have yet to upgrade to take a second look at Windows 11
-
Document management systems (DMS) in the AI era: How to choose the right solution to create a trusted foundation for your businessSupported In the AI era, documents are no longer just records — they’re strategic assets. A modern DMS provides the secure, intelligent foundation firms need to harness AI, ensure compliance, and build lasting digital confidence
-
Thousands of exposed civil servant passwords are up for grabs onlineNews While the password security failures are concerning, they pale in comparison to other nations
-
Gen Z has a cyber hygiene problemNews A new survey shows Gen Z is far less concerned about cybersecurity than older generations
-
Passwords are a problem: why device-bound passkeys can be the future of secure authenticationIndustry insights AI-driven cyberthreats demand a passwordless future…
-
LastPass just launched a tool to help security teams keep tabs on shadow IT risksNews Companies need to know what apps their employees are using, so LastPass made a browser extension to help
-
The NCSC wants you to start using password managers and passkeys – here’s how to choose the best optionsNews New guidance from the NCSC recommends using passkeys and password managers – but how can you choose the best option? ITPro has you covered.
-
23andMe 'failed to take basic steps' to safeguard customer dataNews The ICO has strong criticism for the way the genetic testing company responded to a 2023 breach.
-
Two more NHS Trusts have been hit with cyber attacks – here’s what we know so farNews A flaw in a third-party device management tool appears to be the source of the incident
-
NHS England launches cyber charter to shore up vendor security practicesNews Voluntary charter follows a series of high-profile ransomware attacks
