NHS laptop with 8.6 million medical records missing
The NHS could be in for another data loss nightmare after a laptop goes missing.
A laptop containing 8.6 million medical records has gone missing from an NHS building in London, according to a report.
The computer was lost three weeks ago but police were only informed this week, according to The Sun.
The laptop was reportedly unencrypted and contained sensitive details on 8.63 million people. It also held records of 18 million hospital visits, operations and procedures.
The Information Commissioner's Office (ICO) confirmed it is looking into the issue.
"Any allegation that sensitive personal information has been compromised is concerning and we will now make enquiries to establish the full facts of this alleged data breach," an ICO spokesperson told IT Pro.
Data lost did not include names, but gender, age and ethnic details were held on the laptop. Other data included details of cancer, HIV, mental illness and abortions.
The device was one of 20 that went missing from a store room at NHS North Central London. Eight have been recovered, with searches for the other 12 ongoing.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"When a machine contains highly sensitive information on literally millions of patients, not securing the data on it by any means possible isn't just careless: it's sheer negligence," said Chris McIntosh of ViaSat UK.
"The ICO has proven several times that it is willing to impose civil penalties on public sector organisations. It is to be hoped that the ICO acts swiftly and decisively to pass a strong message in this case and that, more importantly, the data on the laptop itself doesn't end up in the wrong hands."
Nick Lowe, head of sales in Western Europe for security firm Check Point, said the new case again highlighted the need for organisations to better secure their hardware.
"The scale of this potential data loss drives home just how essential it is to have mandatory, strong encryption on all sensitive, personal on laptops and portable storage devices even if those devices are stored in supposedly secure areas within buildings," Lowe said.
"Data security is still being mostly left to chance."
The NHS has come under the data security spotlight numerous times in recent years, thanks to repeated device losses.
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
AI is “forcing a fundamental shift” in data privacy and governanceNews Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up
-
Fears over “AI model collapse” are fueling a shift to zero trust data governance strategiesNews Gartner warns of "model collapse" as AI-generated data proliferates – and says organizations need to beware
-
NHS supplier DXS International confirms cyber attack – here’s what we know so farNews The NHS supplier says front-line clinical services are unaffected
-
Two more NHS Trusts have been hit with cyber attacks – here’s what we know so farNews A flaw in a third-party device management tool appears to be the source of the incident
-
NHS England launches cyber charter to shore up vendor security practicesNews Voluntary charter follows a series of high-profile ransomware attacks
-
NHS supplier hit with £3m fine for security failings that led to attackNews Advanced Computer Software Group lacked MFA, comprehensive vulnerability scanning and proper patch management
-
Tech leaders worry AI innovation is outpacing governanceNews Business execs have warned the current rate of AI innovation is outpacing governance practices.
-
Cyber attack delayed cancer treatment at NHS hospitalNews A cyber attack at Wirral University Teaching Hospital in 2024 delayed critical cancer treatment for patients, documents show.


