Brighton and Sussex University Hospitals NHS Trust has been served with a Civil Monetary Penalty (CMP) of £325,000 following a serious breach of the Data Protection Act (DPA), the Information Commissioner’s Office (ICO) said today.
It comes after the discovery of highly sensitive personal data belonging to tens of thousands of patients and staff – found on hard drives sold on an Internet auction site in October and November 2010.
The data included
- Patients’ medical conditions and treatments
- Disability living allowance forms and children’s reports.
- Documents containing staff details such as National Insurance numbers, home addresses, ward and hospital IDs, and information referring to criminal convictions and suspected offenses.
The data breach occurred when an individual engaged by the Trust’s IT service provider, Sussex Health Informatics Service (HIS), was tasked to destroy approximately 1000 hard drives held in a room accessed by key code at Brighton General Hospital in September and October 2010. A data recovery company bought four hard drives from a seller on an Internet auction site in December 2010, who had purchased them from the individual.
Although the ICO was assured that only these four hard drives were affected, in April 2011 a university contacted them and advise that one of their students had purchased hard drives via an Internet auction site. An examination of the drives established that they contained data which belonged to the Trust.
The ICO’s Deputy Commissioner and Director of Data Protection David Smith said:
“The amount of the CMP issued in this case reflects the gravity and scale of the data breach. It sets an example for all organisations – both public and private – of the importance of keeping personal information secure. That said, patients of the NHS in particular rely on the service to keep their sensitive personal details secure. In this case, the Trust failed significantly in its duty to its patients, and also to its staff.”
The Trust has now committed to providing a secure central store for hard drives and other media, reviewing the process for vetting potential IT suppliers, obtaining the services of a fully accredited ISO 27001 IT waste disposal company, and making progress towards central network access.
Link to article on the ICO webpage: http://www.ico.gov.uk/news/latest_news/2012/nhs-trust-fined-325000-following-data-breach-affecting-thousands-of-patients-and-staff-01062012.aspx