NHS to face compulsory data protection audits
Government minister sets out plans for more pro-active approach to NHS data protection.

The NHS could soon face compulsory data protection audits, as the Government pushes ahead with plans to improve the health service's handling of patient data.
The plans were outlined by Simon Hughes, minister of state for justice and civil liberties, during an address earlier this week at the Information Commissioner's Office's (ICO) Data Protection Practitioner Conference.
Hughes, who only took up his current Government role two months ago, said the NHS is being targeted because of the large amounts of sensitive data it regularly handles.
"We have recently conducted a consultation on extending the ICO's powers of compulsory audit to NHS bodies. This requires secondary legislation which we plan to introduce before the summer recess so that the power can come into effect by the autumn," said Hughes.
"We have chosen the NHS as it is one of the largest data controllers in the UK, processing huge amounts of sensitive personal data on a daily basis."
The practice could also be extended to other industries, added Hughes, depending on how its work with the NHS goes.
"We will work closely with the ICO to monitor the effectiveness of these powers before considering whether we might extend them to other sectors that process large amounts of personal data in their day-to-day business," he continued.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The news will be music to the ears of data protection and privacy experts who have regularly rounded on the NHS for its haphazard approach to information security.
In recent years, this has resulted in various NHS Trusts being subjected to massive fines from the ICO for data protection breaches, with Brighton and Sussex University Hospitals NHS Trust receiving a record 325,000 penalty in June 2012.
At present, the onus is on organisations that suffer data breaches to report them to the ICO, so the introduction of compulsory audits could result in a marked uptick in the number uncovered.
Hughes also used his presentation to outline other changes to data protection enforcement the Government is mulling over, including the introduction of tougher sanctions against organisations that breach the Data Protection Act.
Companies that infringe on the Data Protection Act can find themselves subjected to fines of up to 500,000.
However, the introduction of custodial sentences for Data Protection Act rule breakers has also recently been mooted.
"Serious misuse of personal data by any sector causes significant distress and damage to ordinary citizens and undermines public trust in public institutions and business which in turn can undermine economic growth," said Hughes.
"That is why in the last few weeks we have begun to review the sanctions available for breaches of the Act so we can decide whether to increase the penalties as the law permits."
-
Windows 10: Six essential steps IT teams should take over the next two months
Industry Insights With Windows 10 support ending soon, IT leaders must act now to mitigate risk
-
New chapter, same partners: Keeping the channel aligned with change
Industry Insights How to maintain strong channel partnerships amid evolving strategies and market change
-
‘A huge national security risk’: Thousands of government laptops, tablets, and phones are missing and nowhere to be found
News A freedom of information disclosure shows more than 2,000 government-issued phones, tablets, and laptops have been lost or stolen, prompting huge cybersecurity concerns.
-
23andMe 'failed to take basic steps' to safeguard customer data
News The ICO has strong criticism for the way the genetic testing company responded to a 2023 breach.
-
Two more NHS Trusts have been hit with cyber attacks – here’s what we know so far
News A flaw in a third-party device management tool appears to be the source of the incident
-
NHS England launches cyber charter to shore up vendor security practices
News Voluntary charter follows a series of high-profile ransomware attacks
-
NHS supplier hit with £3m fine for security failings that led to attack
News Advanced Computer Software Group lacked MFA, comprehensive vulnerability scanning and proper patch management
-
The UK cybersecurity sector is worth over £13 billion, but experts say there’s huge untapped potential if it can overcome these hurdles
Analysis A new report released by the DSIT revealed the UK’s cybersecurity sector generated £13.2 billion over the last year
-
Cyber attack delayed cancer treatment at NHS hospital
News A cyber attack at Wirral University Teaching Hospital in 2024 delayed critical cancer treatment for patients, documents show.
-
"Thinly spread": Questions raised over UK government’s latest cyber funding scheme
The funding will go towards bolstering cyber skills, though some industry experts have questioned the size of the price tag