Merseyside health authority gives away staff data
Union calls for investigation
Posted in Government, 11th December 2007 17:29 GMT
Join our expert panel in discussing application security
Sefton Primary Care Trust has sent thousands of staff records to four organisations it is refusing to name.
Staff details including dates of birth, national insurance numbers, pensions and salary details were sent accidentally to four separate organisations. Sefton PCT will not name the four companies, which were bidding for work with the trust, because of "commercial confidentiality". The four companies were bidding for work within Sefton's Sexual Health Department.
Dr Leigh Griffin, chief executive of Sefton PCT, has written to all staff apologising for the gaffe. More from the BBC here.
Union Unite is calling for an investigation and recommending members change their passwords and check all bank accounts.
Unite's national officer for health, Kevin Coyne, said: "This is a clear breach of the data protection law and if it was an accident, an inquiry must be launched into how and why such sensitive information was passed on to so many external organisations."
Dr Griffin said in a statement: “I am treating this incident extremely seriously and I am confident that we have acted swiftly to protect our staff.
We have had assurances from all the organisations who were wrongly sent the information that it was promptly destroyed."
Griffin sadi the information did not include any financial information.®
See what The Register's experts have to say on application security


The future of SaaS and IT infrastructure management
Solving on-premise email challenges with on-demand services
The business case for application security
Reducing messaging and web security costs with managed services

Win a Samsung C6625!
Is your cameraphone an oxymoron?
Reg Mobile and Wireless newsletter is go! go! go!
Sign up, sign up for The Register IT security newsletter