Feeds

Lost mental hospital memory stick had health records

Idiots have taken over the asylum

SANS - Survey on application security programs

A USB memory stick containing personal information on patients and staff at a secure hospital near Falkirk has been found in a car park outside an Asda store in nearby Stenhousemuir.

Data on the unencrypted device included names, addresses and (worse still) medical records of patients. A member of staff at the Tryst Park unit at Bellsdyke Hospital has been suspended over the incident, the BBC reports. The unit treats patients with severe mental health problems.

A spokeswoman for NHS Forth Valley said: "We are very concerned to learn of this incident and are looking into it as a matter of urgency. We have clear policies in place on the safe use of portable data devices.

"We can confirm a member of staff has been suspended in connection with this incident."

The memory stick, which was found by a 12-year-old boy, has been returned to the Trust, which last month admitted it had lost records of patients under treatment by its audiology department in a incident blamed on a computer failure.

Security firm Check Point said that the lost of the unencrypted memory stick shows many organisations are still failing to apply the lessons of the many data breaches that have happened in the past two and half years.

“This incident shows yet again why data on USB drives must be encrypted at all times," said Nick Lowe, Check Point’s head of Western European sales. "Guidelines and security policies don’t stop devices being lost or misplaced.

“The only way to protect data is to use mandatory encryption whenever data is moved or copied, and to ensure that users can’t turn off, disable or work around that protection." ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
prev story

Whitepapers

Designing a defence for mobile apps
In this whitepaper learn the various considerations for defending mobile applications; from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.