BreachExchange mailing list archives

List of health service security blunders exposed


From: Jon Turner <jjturner () gmail com>
Date: Thu, 12 Mar 2009 09:20:54 +0000

http://www.thisisgloucestershire.co.uk/gloucestershireheadlines/List-health-service-security-blunders-exposed/article-764649-detail/article.html

DOZENS of patients' confidential details have been lost or mislaid by health
service staff in Gloucester- shire, it has been revealed.

An Echo Freedom of Information request has uncovered 34 separate incidents
in which important patient data has gone missing in Gloucestershire since
December 2007.

The list includes the loss of a laptop containing details of 50 medical
trial patients.

On another occasion, a confidential health record about a baby was found on
the floor of an administration office.

Other incidents include a private report which was emailed to the wrong
address and patient details that were sent to a nursery by accident.

Coun Andrew Gravells, chairman of the Health Overview and Scrutiny Committee
at Gloucestershire County Council, promised to look into the incidents.

He said: "The security of our personal medical records must be safeguarded
at all times and I know that this is something that the NHS takes very
seriously in Gloucestershire.

"The scrutiny committee meets later this week and I will raise these issues
there.

"We need to be assured that measures are in place to ensure a reduction in
the number of these types of incidents."

The list came to light when Gloucestershire Primary Care Trust and
Gloucestershire Hospitals NHS Foundation Trust replied to an FOI inquiry.

The same request was sent to every council in the county, but none reported
any security slips in the past five years.

A PCT spokeswoman on behalf of both trusts said health chiefs supported an
atmosphere of transparency at work and encouraged staff to report any
incidents of data loss, however small.

She said: "NHS Gloucestershire takes issues of patient information security
extremely seriously.

"All staff receive guidance regarding transferring data and ensuring that
information remains secure.

"We recognise the importance of continually reviewing our procedures to
maintain security of patient information, particularly in view of the
thousands of patient records dealt with by staff every day.

"We recognise the importance of learning from any incident."
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)

CREDANT Technologies, a leader in data security, offers advanced data encryption solutions.
Protect sensitive data on desktops, laptops, smartphones and USB sticks transparently 
across your enterprise to ensure regulatory compliance.
http://www.credant.com/stopdataloss

Current thread: