Five NHS bodies breach Data Protection Act
The ICO finds five NHS bodies recently breached the Data Protection Act, as the health service is called on to up its security game.


The Information Commissioner's Office (ICO) has called on the NHS to do more to protect patient information, following a slew of breaches at the health service.
The ICO discovered five health organisations had breached the Data Protection Act, all of which had not taken "appropriate steps" to secure sensitive personal information."
Information commissioner Christopher Graham said the NHS needed to initiate a "culture change" if security was to be improved.
"Recent incidents such as the loss of laptops at NHS North Central London - which we are currently investigating - suggest that the security of data remains a systemic problem," Graham said.
"The policies and procedures may already be in place but the fact is that they are not being followed on the ground."
In one of the five breaches discovered by the ICO, Ipswich Hospital NHS Trust lost 29 patient records after a member of staff took them home to update a training log and then misplaced them.
In another, Dunelm Medical Practice in Durham sent discharge letters about two patients' routine operations to the wrong recipient, after an employee entered the fax number incorrectly.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The NHS has suffered numerous data breaches in the past, losing devices in public spaces such as a car park and a bus stop.
Reports last month indicated an NHS laptop containing 8.6 million medical records had gone missing.
"We fully support the information commissioner's call for improvement in local NHS practice in relation to preserving patient confidentiality," a Department of Health spokesperson said.
"There is absolutely no excuse for breaches leading to the loss of sensitive and personal data. Encrypting information held on portable devices such as laptops and memory sticks is just as important as avoiding public conversations about patients' details."
The NHS has signed a deal with Zscaler to implement at cloud security product within the health service, IT Pro revealed last week.
Tom Brewster is currently an associate editor at Forbes and an award-winning journalist who covers cyber security, surveillance, and privacy. Starting his career at ITPro as a staff writer and working up to a senior staff writer role, Tom has been covering the tech industry for more than ten years and is considered one of the leading journalists in his specialism.
He is a proud alum of the University of Sheffield where he secured an undergraduate degree in English Literature before undertaking a certification from General Assembly in web development.
-
The UK’s science funding agency is being bombarded with cyber attacks
News Government bodies face increasing threats from state-sponsored espionage groups
-
CrowdStrike announces integration with Nvidia Enterprise AI Factory
News Organizations can now leverage CrowdStrike protection within Nvidia Enterprise AI Factory deployments
-
NHS leaders are keen to adopt new digital tools, but IT can't solve problems on its own
A survey of healthcare decision-makers finds they believe IoT devices and electronic health recording could help them reach more patients quicker
-
How a paperless approach cut wasted staff hours at Bradford Teaching Hospitals Trust
Case study Through DrDoctor’s digital portal for patient appointments and advice, the Rheumatology team at Bradford Teaching Hospitals NHS Foundation Trust has dramatically cut
-
Healthcare’s next chapter
whitepaper Revolutionizing how you care with EPR experts you can trust
-
How digital experience management helped an NHS trust improve productivity
Case study Princess Alexandra Hospital NHS Trust used digital experience management to cut device failure and restore time to clinicians
-
Will the NHS Federated Data Platform transform UK healthcare?
In-depth Plans to create a data platform in partnership with the private sector could revolutionize NHS treatment, but concerns over data privacy and security are festering
-
NHS IT issues costing doctors more than 13 million hours annually
News Doctors warn that ageing IT infrastructure is impacting patient care and clinical outcomes
-
Automation is helping the NHS clear its patient backlog, but not as quickly as expected
Analysis The healthcare service's big bet on robotic process automation is making 'impactful' but slow progress
-
DHSC sets out ambitious targets for NHS App by 2023, beyond
News Ongoing NHS digitisation efforts will form backbone of the new system