Feeds

Info chief prescribes shock therapy for health dept

Scathing judgement on junior doc debacle

Top three mobile application threats

The Information Commissioner’s Office has slated the Department of Health over a data protection debacle that saw Doctor’s intimate personal details plastered over the web.

The security breach on the Medical Training Application Service (MTAS) website, which the ICO became aware of in May, meant junior doctor’s personal data, down to their religious beliefs and sexual orientation, could be accessed by visitors to the site.

In a humiliating move the DoH will have to sign a formal undertaking “to comply with the principles of the data protection Act.” Failure to comply will mean further enforcement action, including prosecutions, said the ICO.

Given that, as of next year, the government is prepared to back prison terms for officials who screw up on protecting personal data, the DoH better get its act together. It's unlikely to inspire customer patients confidence in the NHS' various other IT wheezes.

On a more mundane level, the DoH has been told to encrypt any personal data on its website “which could cause distress to individuals if disclosed.” It must also carry out regular penetration and vulnerability testing on developing apps, and staff must be trained on the Data Protecton Act.

The security breach was just one element of debacle surrounding the online application scheme, which threw the whole UK junior doctor community into chaos. The online system was supposed to match applicants to training places, but was deemed a woeful failure, in large part because it required everyone to apply for places at the same time. As the closing date drew near the system ground to a halt – and not just because all and sundry were able to ogle the more intimate details of junior doctors’ lives.

Former DoH boss Patricia Hewitt finally switched off the life support for the system in May. A revamped system should be in place for 2009.®

Top three mobile application threats

More from The Register

next story
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Lavabit loses contempt of court appeal over protecting Snowden, customers
Judges rule complaints about government power are too little, too late
Don't let no-hire pact suit witnesses call Steve Jobs a bullyboy, plead Apple and Google
'Irrelevant' character evidence should be excluded – lawyers
EFF: Feds plan to put 52 MILLION FACES into recognition database
System would identify faces as part of biometrics collection
Record labels sue Pandora over vintage song royalties
Companies want payout on recordings made before 1972
Edward Snowden on his Putin TV appearance: 'Why all the criticism?'
Denies Q&A cameo was meant to slam US, big-up Russia
Ex-Tony Blair adviser is new top boss at UK spy-hive GCHQ
Robert Hannigan to replace Sir Iain Lobban in the autumn
Judge halts spread of zombie Nortel patents to Texas in Google trial
Epic Rockstar patent war to be waged in California
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
APPLE FAILS to ditch class action suit over ebook PRICE-FIX fiasco
Do not pass go, do cough (up to) $840m in damages
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.