NHS trust and local council hit back at ICO fines
Public sector organisations dispute cases that netted the data protection watchdog £415,000.
A local council and a NHS Trust have come out fighting after being hit with data breach fines totalling 415,000 by the Information Commissioner's Office (ICO).
As reported by IT Pro last week, Brighton and Sussex University Hospitals NHS Trust received a record 325,000 fine after personal details belonging to thousands of staff and patients were found on hard drives sold via an internet auction site.
It is a matter of frank surprise that we still do not know why they have imposed such an extraordinary fine, despite repeated attempts to find out.
In a statement, the ICO said the size of the fine was in direct proportion to the "scale and gravity" of the breach.
The trust has since confirmed to IT Pro that it plans to appeal against the judgement because it cannot afford to pay.
"We arranged for an experienced NHS IT service provider to safely dispose of our redundant hard drives and acted swiftly to recover those that their sub-contractor placed on eBay. No sensitive data has entered the public domain," said Duncan Selbie, chief executive of Brighton and Sussex University Hospitals Trust, in a statement.
"We reported all of this voluntarily to the ICO who told me last summer that this was not a case worthy of a fine, [so] it is a matter of frank surprise that we still do not know why they have imposed such an extraordinary fine, despite repeated attempts to find out."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Earlier today, the ICO announced that Telford and Wrekin Council had been fined 90,000 after confidential details about four vulnerable children were disclosed during two similar data breaches.
The first took place in March 2011, when a member of the council's staff accidentally sent findings from a social care assessment to a child's sibling instead of their mother.
It also included details of another child who had made a serious, unspecified allegation against another youngster.
-
Morgan Stanley research warns AI is having a huge impact on jobsNews Analysis of five sectors highlights an "early warning sign" of AI’s impact on jobs
-
AI is “forcing a fundamental shift” in data privacy and governanceNews Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up
-
NHS supplier DXS International confirms cyber attack – here’s what we know so farNews The NHS supplier says front-line clinical services are unaffected
-
LastPass hit with ICO fine after 2022 data breach exposed 1.6 million users – here’s how the incident unfoldedNews The impact of the LastPass breach was felt by customers as late as December 2024
-
23andMe 'failed to take basic steps' to safeguard customer dataNews The ICO has strong criticism for the way the genetic testing company responded to a 2023 breach.
-
Two more NHS Trusts have been hit with cyber attacks – here’s what we know so farNews A flaw in a third-party device management tool appears to be the source of the incident
-
NHS England launches cyber charter to shore up vendor security practicesNews Voluntary charter follows a series of high-profile ransomware attacks
-
NHS supplier hit with £3m fine for security failings that led to attackNews Advanced Computer Software Group lacked MFA, comprehensive vulnerability scanning and proper patch management
-
Cyber attack delayed cancer treatment at NHS hospitalNews A cyber attack at Wirral University Teaching Hospital in 2024 delayed critical cancer treatment for patients, documents show.
-
Alder Hey Children’s Hospital confirms hackers gained access to patient data through digital gateway serviceNews Europe’s busiest children’s hospital confirmed attackers were able to steal data from a compromised digital gateway service